CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-23441
5.5 MEDIUM

Vba32 Antivirus v3.36.0 is vulnerable to a Denial of Service vulnerability by triggering the 0x2220A7 IOCTL code of the Vba32m64.sys driver.

Jan 29, 2024
CVE-2024-1008
4.7 MEDIUM

A vulnerability was found in SourceCodester Employee Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Jan 29, 2024
CVE-2024-1007
6.3 MEDIUM

A vulnerability was found in SourceCodester Employee Management System 1.0. It has been classified as critical. Affected is an unknown function of the file edit_profile.php. …

Jan 29, 2024
CVE-2024-1006
7.3 HIGH

A vulnerability was found in Shanxi Diankeyun Technology NODERP up to 6.0.2 and classified as critical. This issue affects some unknown processing of the file …

Jan 29, 2024
CVE-2024-1005
5.3 MEDIUM

A vulnerability has been found in Shanxi Diankeyun Technology NODERP up to 6.0.2 and classified as critical. This vulnerability affects unknown code of the file …

Jan 29, 2024
CVE-2024-1004
7.2 HIGH

A vulnerability, which was classified as critical, was found in Totolink N200RE 9.3.5u.6139_B20201216. This affects the function loginAuth of the file /cgi-bin/cstecgi.cgi. The manipulation of …

Jan 29, 2024
CVE-2024-1003
7.2 HIGH

A vulnerability, which was classified as critical, has been found in Totolink N200RE 9.3.5u.6139_B20201216. Affected by this issue is the function setLanguageCfg of the file …

Jan 29, 2024
CVE-2023-7204
7.5 HIGH

The WP STAGING WordPress Backup plugin before 3.2.0 allows access to cache files during the cloning process which provides

Jan 29, 2024
CVE-2023-7200
6.1 MEDIUM

The EventON WordPress plugin before 4.4.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Jan 29, 2024
CVE-2023-7199
5.3 MEDIUM

The Relevanssi WordPress plugin before 4.22.0, Relevanssi Premium WordPress plugin before 2.25.0 allows any unauthenticated user to read draft and private posts via a crafted …

Jan 29, 2024
CVE-2023-7089
5.4 MEDIUM

The Easy SVG Allow WordPress plugin through 1.0 does not sanitize uploaded SVG files, which could allow users with a role as low as Author …

Jan 29, 2024
CVE-2023-7074
8.8 HIGH

The WP SOCIAL BOOKMARK MENU WordPress plugin through 1.2 does not have CSRF check in place when updating its settings, which could allow attackers to …

Jan 29, 2024
CVE-2023-6946
8.8 HIGH

The Autotitle for WordPress plugin through 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

Jan 29, 2024
CVE-2023-6633
4.3 MEDIUM

The Site Notes WordPress plugin through 2.0.0 does not have CSRF checks in some of its functionalities, which could allow attackers to make logged in …

Jan 29, 2024
CVE-2023-6530
5.4 MEDIUM

The TJ Shortcodes WordPress plugin through 0.1.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where …

Jan 29, 2024
CVE-2023-6503
5.4 MEDIUM

The WP Plugin Lister WordPress plugin through 2.1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which …

Jan 29, 2024
CVE-2023-6391
8.8 HIGH

The Custom User CSS WordPress plugin through 0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make …

Jan 29, 2024
CVE-2023-6390
8.8 HIGH

The WordPress Users WordPress plugin through 1.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

Jan 29, 2024
CVE-2023-6389
6.1 MEDIUM

The WordPress Toolbar WordPress plugin through 2.2.6 redirects to any URL via the "wptbto" parameter. This makes it possible for unauthenticated attackers to redirect users …

Jan 29, 2024
CVE-2023-6279
7.1 HIGH

The Woostify Sites Library WordPress plugin before 1.4.8 does not have authorisation in an AJAX action, allowing any authenticated users, such as subscriber to update …

Jan 29, 2024
CVE-2023-6278
6.1 MEDIUM

The Biteship: Plugin Ongkos Kirim Kurir Instant, Reguler, Kargo WordPress plugin before 2.2.25 does not sanitise and escape the biteship_error and biteship_message parameters before outputting …

Jan 29, 2024
CVE-2023-6165
4.8 MEDIUM

The Restrict Usernames Emails Characters WordPress plugin before 3.1.4 does not sanitise and escape some of its settings, which could allow high privilege users such …

Jan 29, 2024
CVE-2023-5956
4.8 MEDIUM

The Wp-Adv-Quiz WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Jan 29, 2024
CVE-2023-5943
4.8 MEDIUM

The Wp-Adv-Quiz WordPress plugin before 1.0.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Jan 29, 2024
CVE-2023-5124
4.8 MEDIUM

The Page Builder: Pagelayer WordPress plugin before 1.8.0 doesn't prevent attackers with administrator privileges from inserting malicious JavaScript inside a post's header or footer code, …

Jan 29, 2024
CVE-2023-40548
7.4 HIGH

A buffer overflow was found in Shim in the 32-bit system. The overflow happens due to an addition operation involving a user-controlled value parsed from …

Jan 29, 2024
CVE-2024-23747
7.5 HIGH

The Moderna Sistemas ModernaNet Hospital Management System 2024 is susceptible to an Insecure Direct Object Reference (IDOR) vulnerability. This vulnerability resides in the system's handling …

Jan 29, 2024
CVE-2024-22559
5.4 MEDIUM

LightCMS v2.0 is vulnerable to Cross Site Scripting (XSS) in the Content Management - Articles field.

Jan 29, 2024
CVE-2024-1015
9.8 CRITICAL

Remote command execution vulnerability in SE-elektronic GmbH E-DDC3.3 affecting versions 03.07.03 and higher. An attacker could send different commands from the operating system to the …

Jan 29, 2024
CVE-2024-1014
6.2 MEDIUM

Uncontrolled resource consumption vulnerability in SE-elektronic GmbH E-DDC3.3 affecting versions 03.07.03 and higher. An attacker could interrupt the availability of the administration panel by sending …

Jan 29, 2024
CVE-2024-1002
7.2 HIGH

A vulnerability classified as critical was found in Totolink N200RE 9.3.5u.6139_B20201216. Affected by this vulnerability is the function setIpPortFilterRules of the file /cgi-bin/cstecgi.cgi. The manipulation …

Jan 29, 2024
CVE-2024-1001
7.2 HIGH

A vulnerability classified as critical has been found in Totolink N200RE 9.3.5u.6139_B20201216. Affected is the function main of the file /cgi-bin/cstecgi.cgi. The manipulation leads to …

Jan 29, 2024
CVE-2024-1000
7.2 HIGH

A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216. It has been rated as critical. This issue affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi. The …

Jan 29, 2024
CVE-2024-0999
7.2 HIGH

A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216. It has been declared as critical. This vulnerability affects the function setParentalRules of the file /cgi-bin/cstecgi.cgi. The …

Jan 29, 2024
CVE-2024-0998
7.2 HIGH

A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216. It has been classified as critical. This affects the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi. The manipulation …

Jan 29, 2024
CVE-2024-0997
7.2 HIGH

A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216 and classified as critical. Affected by this issue is the function setOpModeCfg of the file /cgi-bin/cstecgi.cgi. The …

Jan 29, 2024
CVE-2023-29055
7.5 HIGH

In Apache Kylin version 2.0.0 to 4.0.3, there is a Server Config web interface that displays the content of file 'kylin.properties', that may contain serverside …

Jan 29, 2024
CVE-2023-5378
8.8 HIGH

Improper Input Validation vulnerability in MegaBIP and already unsupported SmodBIP software allows for Stored XSS.This issue affects SmodBIP in all versions and MegaBIP in versions …

Jan 29, 2024
CVE-2023-46838
7.5 HIGH

Transmit requests in Xen's virtual network protocol can consist of multiple parts. While not really useful, except for the initial part any of them may …

Jan 29, 2024
CVE-2024-23792
5.3 MEDIUM

When adding attachments to ticket comments, another user can add attachments as well impersonating the orginal user. The attack requires a logged-in other user to …

Jan 29, 2024
CVE-2024-23791
4.9 MEDIUM

Insertion of debug information into log file during building the elastic search index allows reading of sensitive information from articles.This issue affects OTRS: from 7.0.X …

Jan 29, 2024
CVE-2024-23790
3.5 LOW

Improper Input Validation vulnerability in the upload functionality for user avatars allows functionality misuse due to missing check of filetypes. This issue affects OTRS: from …

Jan 29, 2024
CVE-2024-0212
8.1 HIGH

The Cloudflare Wordpress plugin was found to be vulnerable to improper authentication. The vulnerability enables attackers with a lower privileged account to access data from …

Jan 29, 2024
CVE-2023-46050

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not …

Jan 29, 2024
CVE-2023-45932

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not …

Jan 29, 2024
CVE-2023-45921

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not …

Jan 29, 2024
CVE-2023-45916

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not …

Jan 29, 2024
CVE-2024-24736
7.5 HIGH

The POP3 service in YahooPOPs (aka YPOPs!) 1.6 allows a remote denial of service (reboot) via a long string to TCP port 110, a related …

Jan 29, 2024
CVE-2024-0996
7.2 HIGH

A vulnerability classified as critical has been found in Tenda i9 1.0.0.9(4122). This affects the function formSetCfm of the file /goform/setcfm of the component httpd. …

Jan 29, 2024
CVE-2024-0995
7.2 HIGH

A vulnerability was found in Tenda W6 1.0.0.9(4122). It has been rated as critical. Affected by this issue is the function formwrlSSIDset of the file …

Jan 29, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.