CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-22938
7.8 HIGH

Insecure Permissions vulnerability in BossCMS v.1.3.0 allows a local attacker to execute arbitrary code and escalate privileges via the init function in admin.class.php component.

Jan 30, 2024
CVE-2024-22682

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not …

Jan 30, 2024
CVE-2024-1026
3.5 LOW

A vulnerability was found in Cogites eReserv 7.7.58 and classified as problematic. This issue affects some unknown processing of the file front/admin/config.php. The manipulation of …

Jan 30, 2024
CVE-2024-1024
3.5 LOW

A vulnerability has been found in SourceCodester Facebook News Feed Like 1.0 and classified as problematic. This vulnerability affects unknown code of the component New …

Jan 30, 2024
CVE-2023-5372
7.2 HIGH

The post-authentication command injection vulnerability in Zyxel NAS326 firmware versions through V5.21(AAZF.15)C0 and NAS542 firmware versions through V5.21(ABAG.12)C0 could allow an authenticated attacker with administrator …

Jan 30, 2024
CVE-2023-51982
9.8 CRITICAL

CrateDB 5.5.1 is contains an authentication bypass vulnerability in the Admin UI component. After configuring password authentication and_ Local_ In the case of an address, …

Jan 30, 2024
CVE-2023-51843
8.2 HIGH

react-dashboard 1.4.0 is vulnerable to Cross Site Scripting (XSS) as httpOnly is not set.

Jan 30, 2024
CVE-2023-51837
9.8 CRITICAL

Ylianst MeshCentral 1.1.16 is vulnerable to Missing SSL Certificate Validation.

Jan 30, 2024
CVE-2023-51813
6.5 MEDIUM

Cross Site Request Forgery (CSRF) vulnerability in Free Open-Source Inventory Management System v.1.0 allows a remote attacker to execute arbitrary code via the staff_list parameter …

Jan 30, 2024
CVE-2023-37571
6.1 MEDIUM

Softing TH SCOPE through 3.70 allows XSS.

Jan 30, 2024
CVE-2024-23829
6.5 MEDIUM

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Security-sensitive parts of the Python HTTP parser retained minor differences in allowable character sets, …

Jan 29, 2024
CVE-2024-23334
5.9 MEDIUM

aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. When using aiohttp as a web server and configuring static routes, it is necessary …

Jan 29, 2024
CVE-2024-1022
2.4 LOW

A vulnerability, which was classified as problematic, was found in CodeAstro Simple Student Result Management System 5.6. This affects an unknown part of the file …

Jan 29, 2024
CVE-2024-1021
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Rebuild up to 3.5.5. Affected by this issue is the function readRawText of the …

Jan 29, 2024
CVE-2024-1020
3.5 LOW

A vulnerability classified as problematic was found in Rebuild up to 3.5.5. Affected by this vulnerability is the function getStorageFile of the file /filex/proxy-download. The …

Jan 29, 2024
CVE-2023-4554
4.9 MEDIUM

Improper Restriction of XML External Entity Reference vulnerability in OpenText AppBuilder on Windows, Linux allows Server Side Request Forgery, Probe System Files. AppBuilder's XML processor …

Jan 29, 2024
CVE-2023-4553
5.3 MEDIUM

Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows Probe System Files. AppBuilder configuration files are viewable by unauthenticated users. This issue affects …

Jan 29, 2024
CVE-2023-4552
5.5 MEDIUM

Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows Probe System Files. An authenticated AppBuilder user with the ability to create or manage …

Jan 29, 2024
CVE-2023-4551
7.2 HIGH

Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows OS Command Injection. The AppBuilder's Scheduler functionality that facilitates creation of scheduled tasks is …

Jan 29, 2024
CVE-2023-4550
7.5 HIGH

Improper Input Validation, Files or Directories Accessible to External Parties vulnerability in OpenText AppBuilder on Windows, Linux allows Probe System Files. An unauthenticated or authenticated …

Jan 29, 2024
CVE-2023-49038
7.2 HIGH

Command injection in the ping utility on Buffalo LS210D 1.78-0.03 allows a remote authenticated attacker to inject arbitrary commands onto the NAS as root.

Jan 29, 2024
CVE-2024-24141
9.8 CRITICAL

Sourcecodester School Task Manager App 1.0 allows SQL Injection via the 'task' parameter.

Jan 29, 2024
CVE-2024-24140
7.2 HIGH

Sourcecodester Daily Habit Tracker App 1.0 allows SQL Injection via the parameter 'tracker.'

Jan 29, 2024
CVE-2024-24139
7.2 HIGH

Sourcecodester Login System with Email Verification 1.0 allows SQL Injection via the 'user' parameter.

Jan 29, 2024
CVE-2024-24136
6.1 MEDIUM

The 'Your Name' field in the Submit Score section of Sourcecodester Math Game with Leaderboard v1.0 is vulnerable to Cross-Site Scripting (XSS) attacks.

Jan 29, 2024
CVE-2024-22570
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in /install.php?m=install&c=index&a=step3 of GreenCMS v2.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

Jan 29, 2024
CVE-2024-1018
2.4 LOW

A vulnerability classified as problematic has been found in PbootCMS 3.2.5-20230421. Affected is an unknown function of the file /admin.php?p=/Area/index#tab=t2. The manipulation of the argument …

Jan 29, 2024
CVE-2023-51842
7.5 HIGH

An algorithm-downgrade issue was discovered in Ylianst MeshCentral 1.1.16.

Jan 29, 2024
CVE-2023-51840
9.8 CRITICAL

DoraCMS 2.1.8 is vulnerable to Use of Hard-coded Cryptographic Key.

Jan 29, 2024
CVE-2023-51839
9.1 CRITICAL

DeviceFarmer stf v3.6.6 suffers from Use of a Broken or Risky Cryptographic Algorithm.

Jan 29, 2024
CVE-2024-24135
6.1 MEDIUM

Product Name and Product Code in the 'Add Product' section of Sourcecodester Product Inventory with Export to Excel 1.0 are vulnerable to XSS attacks.

Jan 29, 2024
CVE-2024-24134
4.8 MEDIUM

Sourcecodester Online Food Menu 1.0 is vulnerable to Cross Site Scripting (XSS) via the 'Menu Name' and 'Description' fields in the Update Menu section.

Jan 29, 2024
CVE-2024-23940
7.8 HIGH

Trend Micro uiAirSupport, included in the Trend Micro Security 2023 family of consumer products, version 6.0.2092 and below is vulnerable to a DLL hijacking/proxying vulnerability, …

Jan 29, 2024
CVE-2024-1017
5.3 MEDIUM

A vulnerability was found in Gabriels FTP Server 1.2. It has been rated as problematic. This issue affects some unknown processing. The manipulation of the …

Jan 29, 2024
CVE-2023-30970
6.5 MEDIUM

Gotham Table service and Forward App were found to be vulnerable to a Path traversal issue allowing an authenticated user to read arbitrary files on …

Jan 29, 2024
CVE-2023-22836
3.5 LOW

In cases where a multi-tenant stack user is operating Foundry’s Linter service, and the user changes a group name from the default value, the renamed …

Jan 29, 2024
CVE-2024-1016
5.3 MEDIUM

A vulnerability was found in Solar FTP Server 2.1.1/2.1.2. It has been declared as problematic. This vulnerability affects unknown code of the component PASV Command …

Jan 29, 2024
CVE-2024-23828
8.8 HIGH

Nginx-UI is a web interface to manage Nginx configurations. It is vulnerable to an authenticated arbitrary command execution via CRLF attack when changing the value …

Jan 29, 2024
CVE-2024-1011
4.3 MEDIUM

A vulnerability classified as problematic was found in SourceCodester Employee Management System 1.0. This vulnerability affects unknown code of the file delete-leave.php of the component …

Jan 29, 2024
CVE-2024-1010
3.5 LOW

A vulnerability classified as problematic has been found in SourceCodester Employee Management System 1.0. This affects an unknown part of the file edit-profile.php. The manipulation …

Jan 29, 2024
CVE-2024-1009
7.3 HIGH

A vulnerability was found in SourceCodester Employee Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Jan 29, 2024
CVE-2024-0788
6.6 MEDIUM

SUPERAntiSpyware Pro X v10.0.1260 is vulnerable to kernel-level API parameters manipulation and Denial of Service vulnerabilities by triggering the 0x9C402140 IOCTL code of the saskutil64.sys …

Jan 29, 2024
CVE-2023-40551
5.1 MEDIUM

A flaw was found in the MZ binary format in Shim. An out-of-bounds read may occur, leading to a crash or possible exposure of sensitive …

Jan 29, 2024
CVE-2023-40550
5.5 MEDIUM

An out-of-bounds read flaw was found in Shim when it tried to validate the SBAT information. This issue may expose sensitive data during the system's …

Jan 29, 2024
CVE-2023-40549
6.2 MEDIUM

An out-of-bounds read flaw was found in Shim due to the lack of proper boundary verification during the load of a PE binary. This flaw …

Jan 29, 2024
CVE-2023-40546
6.2 MEDIUM

A flaw was found in Shim when an error happened while creating a new ESL variable. If Shim fails to create the new variable, it …

Jan 29, 2024
CVE-2023-1705
8.4 HIGH

Missing Authorization vulnerability in Forcepoint F|One SmartEdge Agent on Windows (bgAutoinstaller service modules) allows Privilege Escalation, Functionality Bypass.This issue affects F|One SmartEdge Agent: before 1.7.0.230330-554.

Jan 29, 2024
CVE-2024-23827
9.8 CRITICAL

Nginx-UI is a web interface to manage Nginx configurations. The Import Certificate feature allows arbitrary write into the system. The feature does not check if …

Jan 29, 2024
CVE-2024-23826
6.8 MEDIUM

spbu_se_site is the website of the Department of System Programming of St. Petersburg State University. Before 2024.01.29, when uploading an avatar image, an authenticated user …

Jan 29, 2024
CVE-2024-23822
5.4 MEDIUM

Thruk is a multibackend monitoring webinterface. Prior to 3.12, the Thruk web monitoring application presents a vulnerability in a file upload form that allows a …

Jan 29, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.