CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-1085
7.8 HIGH

A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_setelem_catchall_deactivate() function checks whether the catch-all …

Jan 31, 2024
CVE-2024-0589
5.4 MEDIUM

Cross-site scripting (XSS) vulnerability in the entry overview tab in Devolutions Remote Desktop Manager 2023.3.36 and earlier on Windows allows an attacker with access to …

Jan 31, 2024
CVE-2023-7043
3.3 LOW

Unquoted service path in ESET products allows to drop a prepared program to a specific location and run on boot with the NT AUTHORITY\NetworkService permissions.

Jan 31, 2024
CVE-2024-23507
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through …

Jan 31, 2024
CVE-2024-22305
7.5 HIGH

Authorization Bypass Through User-Controlled Key vulnerability in ali Forms Contact Form builder with drag & drop for WordPress – Kali Forms.This issue affects Contact Form …

Jan 31, 2024
CVE-2024-22290
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in AboZain,O7abeeb,UnitOne Custom Dashboard Widgets allows Cross-Site Scripting (XSS).This issue affects Custom Dashboard Widgets: from n/a through 1.3.1.

Jan 31, 2024
CVE-2024-22287
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Luděk Melichar Better Anchor Links allows Cross-Site Scripting (XSS).This issue affects Better Anchor Links: from n/a through 1.7.5.

Jan 31, 2024
CVE-2024-1099
3.5 LOW

A vulnerability was found in Rebuild up to 3.5.5. It has been classified as problematic. Affected is the function getFileOfData of the file /filex/read-raw. The …

Jan 31, 2024
CVE-2024-1098
4.3 MEDIUM

A vulnerability was found in Rebuild up to 3.5.5 and classified as problematic. This issue affects the function QiniuCloud.getStorageFile of the file /filex/proxy-download. The manipulation …

Jan 31, 2024
CVE-2023-50357
5.4 MEDIUM

A cross site scripting vulnerability in the AREAL SAS Websrv1 ASP website allows a remote low-privileged attacker to gain escalated privileges of other non-admin users.

Jan 31, 2024
CVE-2023-50356
6.5 MEDIUM

SSL connections to some LDAP servers are vulnerable to a man-in-the-middle attack due to improper certificate validation in AREAL Topkapi Vision (Server). This allows a …

Jan 31, 2024
CVE-2023-44313
7.6 HIGH

Server-Side Request Forgery (SSRF) vulnerability in Apache ServiceComb Service-Center. Attackers can obtain sensitive server information through specially crafted requests.This issue affects Apache ServiceComb before 2.1.0(include). …

Jan 31, 2024
CVE-2023-44312
5.8 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor in Apache ServiceComb Service-Center.This issue affects Apache ServiceComb Service-Center before 2.1.0 (include). Users are recommended to upgrade …

Jan 31, 2024
CVE-2024-23775
7.5 HIGH

Integer Overflow vulnerability in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2, allows attackers to cause a denial of service (DoS) via mbedtls_x509_set_extension().

Jan 31, 2024
CVE-2024-23170
5.5 MEDIUM

An issue was discovered in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2. There was a timing side channel in RSA private operations. This …

Jan 31, 2024
CVE-2024-1012
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Wanhu ezOFFICE 11.1.0. This issue affects some unknown processing of the file defaultroot/platform/bpm/work_flow/operate/wf_printnum.jsp. The …

Jan 31, 2024
CVE-2024-0836
4.3 MEDIUM

The WordPress Review & Structure Data Schema Plugin – Review Schema plugin for WordPress is vulnerable to unauthorized modification of data due to a missing …

Jan 31, 2024
CVE-2024-22236
3.3 LOW

In Spring Cloud Contract, versions 4.1.x prior to 4.1.1, versions 4.0.x prior to 4.0.5, and versions 3.1.x prior to 3.1.10, test execution is vulnerable to …

Jan 31, 2024
CVE-2023-3934

Rejected reason: Please discard this CVE, we are not using this anymore. The vulnerability turned out to be a non-security issue

Jan 31, 2024
CVE-2024-0914
5.9 MEDIUM

A timing side-channel vulnerability has been discovered in the opencryptoki package while processing RSA PKCS#1 v1.5 padded ciphertexts. This flaw could potentially enable unauthorized RSA …

Jan 31, 2024
CVE-2024-1069
7.2 HIGH

The Contact Form Entries plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation on the 'view_page' function in versions up …

Jan 31, 2024
CVE-2023-31505
7.2 HIGH

An arbitrary file upload vulnerability in Schlix CMS v2.2.8-1, allows remote authenticated attackers to execute arbitrary code and obtain sensitive information via a crafted .phtml …

Jan 31, 2024
CVE-2023-2439
6.4 MEDIUM

The UserPro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'userpro' shortcode in versions up to, and including, 5.1.5 due to insufficient …

Jan 31, 2024
CVE-2024-23745
9.8 CRITICAL

In Notion Web Clipper 1.0.3(7), a .nib file is susceptible to the Dirty NIB attack. NIB files can be manipulated to execute arbitrary commands. Additionally, …

Jan 31, 2024
CVE-2024-22569
5.4 MEDIUM

Stored Cross-Site Scripting (XSS) vulnerability in POSCMS v4.6.2, allows attackers to execute arbitrary code via a crafted payload to /index.php?c=install&m=index&step=2&is_install_db=0.

Jan 31, 2024
CVE-2024-23834
6.3 MEDIUM

Discourse is an open-source discussion platform. Improperly sanitized user input could lead to an XSS vulnerability in some situations. This vulnerability only affects Discourse instances …

Jan 30, 2024
CVE-2024-1077
8.8 HIGH

Use after free in Network in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit heap corruption via a malicious file. (Chromium …

Jan 30, 2024
CVE-2024-1060
8.8 HIGH

Use after free in Canvas in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Jan 30, 2024
CVE-2024-1059
8.8 HIGH

Use after free in Peer Connection in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML …

Jan 30, 2024
CVE-2023-51204

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not …

Jan 30, 2024
CVE-2023-51202

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not …

Jan 30, 2024
CVE-2023-51198

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not …

Jan 30, 2024
CVE-2023-51197

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not …

Jan 30, 2024
CVE-2024-24567
4.8 MEDIUM

Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. Vyper compiler allows passing a value in builtin raw_call even if the call …

Jan 30, 2024
CVE-2024-24558
8.2 HIGH

TanStack Query supplies asynchronous state management, server-state utilities and data fetching for the web. The `@tanstack/react-query-next-experimental` NPM package is vulnerable to a cross-site scripting vulnerability. …

Jan 30, 2024
CVE-2023-5389
9.1 CRITICAL

An attacker could potentially exploit this vulnerability, leading to the ability to modify files on Honeywell Experion ControlEdge VirtualUOC and ControlEdge UOC . This exploit …

Jan 30, 2024
CVE-2024-24556
7.2 HIGH

urql is a GraphQL client that exposes a set of helpers for several frameworks. The `@urql/next` package is vulnerable to XSS. To exploit this an …

Jan 30, 2024
CVE-2024-23841
8.2 HIGH

apollo-client-nextjs is the Apollo Client support for the Next.js App Router. The @apollo/experimental-apollo-client-nextjs NPM package is vulnerable to a cross-site scripting vulnerability. To exploit this …

Jan 30, 2024
CVE-2024-21388
6.5 MEDIUM

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

Jan 30, 2024
CVE-2024-1036
7.3 HIGH

A vulnerability was found in openBI up to 1.0.8 and classified as critical. This issue affects the function uploadIcon of the file /application/index/controller/Screen.php of the …

Jan 30, 2024
CVE-2024-24565
5.7 MEDIUM

CrateDB is a distributed SQL database that makes it simple to store and analyze massive amounts of data in real-time. There is a COPY FROM …

Jan 30, 2024
CVE-2024-23840
5.5 MEDIUM

GoReleaser builds Go binaries for several platforms, creates a GitHub release and then pushes a Homebrew formula to a tap repository. `goreleaser release --debug` log …

Jan 30, 2024
CVE-2024-23838
7.5 HIGH

TrueLayer.NET is the .Net client for TrueLayer. The vulnerability could potentially allow a malicious actor to gain control over the destination URL of the HttpClient …

Jan 30, 2024
CVE-2024-23825
3.0 LOW

TablePress is a table plugin for Wordpress. For importing tables, TablePress makes external HTTP requests based on a URL that is provided by the user. …

Jan 30, 2024
CVE-2024-23647
6.5 MEDIUM

Authentik is an open-source Identity Provider. There is a bug in our implementation of PKCE that allows an attacker to circumvent the protection that PKCE …

Jan 30, 2024
CVE-2023-6258
8.1 HIGH

A security vulnerability has been identified in the pkcs11-provider, which is associated with Public-Key Cryptography Standards (PKCS#11). If exploited successfully, this vulnerability could result in …

Jan 30, 2024
CVE-2023-46231
6.8 MEDIUM

In Splunk Add-on Builder versions below 4.1.4, the application writes user session tokens to its internal log files when you visit the Splunk Add-on Builder …

Jan 30, 2024
CVE-2023-46230
8.2 HIGH

In Splunk Add-on Builder versions below 4.1.4, the app writes sensitive information to internal log files.

Jan 30, 2024
CVE-2024-22200
3.3 LOW

vantage6-UI is the User Interface for vantage6. The docker image used to run the UI leaks the nginx version. To mitigate the vulnerability, users can …

Jan 30, 2024
CVE-2024-22193
3.5 LOW

The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). There are no checks on whether …

Jan 30, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.