CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-23677
4.3 MEDIUM

In Splunk Enterprise versions below 9.0.8, the Splunk RapidDiag utility discloses server responses from external applications in a log file.

Jan 22, 2024
CVE-2024-23676
4.6 MEDIUM

In Splunk versions below 9.0.8 and 9.1.3, the “mrollup” SPL command lets a low-privileged user view metrics on an index that they do not have …

Jan 22, 2024
CVE-2024-23675
6.5 MEDIUM

In Splunk Enterprise versions below 9.0.8 and 9.1.3, Splunk app key value store (KV Store) improperly handles permissions for users that use the REST application …

Jan 22, 2024
CVE-2023-47141
5.3 MEDIUM

IIBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user with CONNECT privileges to cause a denial of …

Jan 22, 2024
CVE-2023-24135
7.8 HIGH

Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a command injection vulnerability in the function formWriteFacMac. This vulnerability allows attackers to execute arbitrary …

Jan 22, 2024
CVE-2023-7194
6.1 MEDIUM

The Meris WordPress theme through 1.1.2 does not sanitise and escape some parameters before outputting them back in the page, leading to Reflected Cross-Site Scripting …

Jan 22, 2024
CVE-2023-7170
6.1 MEDIUM

The EventON-RSVP WordPress plugin before 2.9.5 does not sanitise and escape some parameters before outputting it back in the page, leading to a Reflected Cross-Site …

Jan 22, 2024
CVE-2023-7082
7.2 HIGH

The Import any XML or CSV File to WordPress plugin before 3.7.3 accepts all zip files and automatically extracts the zip file into a publicly …

Jan 22, 2024
CVE-2023-6626
4.8 MEDIUM

The Product Enquiry for WooCommerce WordPress plugin before 3.1 does not sanitise and escape some of its settings, which could allow high privilege users such …

Jan 22, 2024
CVE-2023-6625
4.3 MEDIUM

The Product Enquiry for WooCommerce WordPress plugin before 3.1 does not have a CSRF check in place when deleting inquiries, which could allow attackers to …

Jan 22, 2024
CVE-2023-6456
4.8 MEDIUM

The WP Review Slider WordPress plugin before 13.0 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Jan 22, 2024
CVE-2023-6447
5.3 MEDIUM

The EventPrime WordPress plugin before 3.3.6 lacks authentication and authorization, allowing unauthenticated visitors to access private and password protected Events by guessing their numeric id/event …

Jan 22, 2024
CVE-2023-6384
4.3 MEDIUM

The WP User Profile Avatar WordPress plugin before 1.0.1 does not properly check for authorisation, allowing authors to delete and update arbitrary avatar

Jan 22, 2024
CVE-2023-6290
4.8 MEDIUM

The SEOPress WordPress plugin before 7.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Jan 22, 2024
CVE-2023-47747
5.3 MEDIUM

IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.1, 10.5, and 11.1 could allow an authenticated user with CONNECT privileges to cause …

Jan 22, 2024
CVE-2023-47158
5.3 MEDIUM

IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1 and 11.5 could allow an authenticated user with CONNECT privileges to cause …

Jan 22, 2024
CVE-2023-47152
5.9 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to an insecure cryptographic algorithm and to information disclosure in stack …

Jan 22, 2024
CVE-2023-27859
6.5 MEDIUM

IBM Db2 10.1, 10.5, and 11.1 could allow a remote user to execute arbitrary code caused by installing like named jar files across multiple databases. …

Jan 22, 2024
CVE-2024-0606
6.1 MEDIUM

An attacker could execute unauthorized script on a legitimate site through UXSS using window.open() by opening a javascript URI leading to unauthorized actions within the …

Jan 22, 2024
CVE-2024-0605
7.5 HIGH

Using a javascript: URI with a setTimeout race condition, an attacker can execute unauthorized scripts on top origin sites in urlbar. This bypasses security measures, …

Jan 22, 2024
CVE-2024-0430
5.5 MEDIUM

IObit Malware Fighter v11.0.0.1274 is vulnerable to a Denial of Service vulnerability by triggering the 0x8001E00C IOCTL code of the ImfHpRegFilter.sys driver.

Jan 22, 2024
CVE-2023-50308
6.5 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5 under certain circumstances could allow an authenticated user to the database to cause …

Jan 22, 2024
CVE-2023-48118
9.8 CRITICAL

SQL Injection vulnerability in Quest Analytics LLC IQCRM v.2023.9.5 allows a remote attacker to execute arbitrary code via a crafted request to the Common.svc WSDL …

Jan 22, 2024
CVE-2023-47746
5.3 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow an authenticated user with CONNECT privileges to cause …

Jan 22, 2024
CVE-2023-45193
5.9 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 federated server is vulnerable to a denial of service when a specially crafted …

Jan 22, 2024
CVE-2024-0784
6.3 MEDIUM

A vulnerability was found in hongmaple octopus 1.0. It has been classified as critical. Affected is an unknown function of the file /system/role/list. The manipulation …

Jan 22, 2024
CVE-2024-0783
6.3 MEDIUM

A vulnerability was found in Project Worlds Online Admission System 1.0 and classified as critical. This issue affects some unknown processing of the file documents.php. …

Jan 22, 2024
CVE-2024-0204
9.8 CRITICAL

Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the administration portal.

Jan 22, 2024
CVE-2022-45795

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jan 22, 2024
CVE-2022-45792
7.8 HIGH

Project files may contain malicious contents which the software will use to create files on the filesystem. This allows directory traversal and overwriting files with …

Jan 22, 2024
CVE-2022-45791

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jan 22, 2024
CVE-2022-45790
8.6 HIGH

The Omron FINS protocol has an authenticated feature to prevent access to memory regions. Authentication is susceptible to bruteforce attack, which may allow an adversary …

Jan 22, 2024
CVE-2024-0782
3.5 LOW

A vulnerability has been found in CodeAstro Online Railway Reservation System 1.0 and classified as problematic. This vulnerability affects unknown code of the file pass-profile.php. …

Jan 22, 2024
CVE-2024-0781
3.5 LOW

A vulnerability, which was classified as problematic, was found in CodeAstro Internet Banking System 1.0. This affects an unknown part of the file pages_client_signup.php. The …

Jan 22, 2024
CVE-2024-0778
8.0 HIGH

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in Uniview ISC 2500-S up to 20210930. Affected by this …

Jan 22, 2024
CVE-2024-22895
8.8 HIGH

DedeCMS 5.7.112 has a File Upload vulnerability via uploads/dede/module_upload.php.

Jan 22, 2024
CVE-2024-0706

Rejected reason: ***REJECT*** This was a false positive report.

Jan 22, 2024
CVE-2023-44395
4.9 MEDIUM

Autolab is a course management service that enables instructors to offer autograded programming assignments to their students over the Web. Path traversal vulnerabilities were discovered …

Jan 22, 2024
CVE-2020-36772
4.4 MEDIUM

CloudLinux CageFS 7.0.8-2 or below insufficiently restricts file paths supplied to the sendmail proxy command. This allows local users to read and write arbitrary files …

Jan 22, 2024
CVE-2020-36771
7.8 HIGH

CloudLinux CageFS 7.1.1-1 or below passes the authentication token as a command line argument. In some configurations this allows local users to view the authentication …

Jan 22, 2024
CVE-2024-22233
7.5 HIGH

In Spring Framework versions 6.0.15 and 6.1.2, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) …

Jan 22, 2024
CVE-2024-0775
6.7 MEDIUM

A use-after-free flaw was found in the __ext4_remount in fs/ext4/super.c in ext4 in the Linux kernel. This flaw allows a local user to cause an …

Jan 22, 2024
CVE-2023-52354
7.5 HIGH

chasquid before 1.13 allows SMTP smuggling because LF-terminated lines are accepted.

Jan 22, 2024
CVE-2017-20189
9.8 CRITICAL

In Clojure before 1.9.0, classes can be used to construct a serialized object that executes arbitrary code upon deserialization. This is relevant if a server …

Jan 22, 2024
CVE-2024-22113
6.1 MEDIUM

Open redirect vulnerability in Access analysis CGI An-Analyzer released in 2023 December 31 and earlier allows a remote unauthenticated attacker to redirect users to arbitrary …

Jan 22, 2024
CVE-2024-21484
7.5 HIGH

Versions of the package jsrsasign before 11.0.0 are vulnerable to Observable Discrepancy via the RSA PKCS1.5 or RSAOAEP decryption process. An attacker can decrypt ciphertexts …

Jan 22, 2024
CVE-2023-47352
8.8 HIGH

Technicolor TC8715D devices have predictable default WPA2 security passwords. An attacker who scans for SSID and BSSID values may be able to predict these passwords.

Jan 22, 2024
CVE-2024-23771
9.8 CRITICAL

darkhttpd before 1.15 uses strcmp (which is not constant time) to verify authentication, which makes it easier for remote attackers to bypass authentication via a …

Jan 22, 2024
CVE-2024-23770
5.5 MEDIUM

darkhttpd through 1.15 allows local users to discover credentials (for --auth) by listing processes and their arguments.

Jan 22, 2024
CVE-2024-23768
8.8 HIGH

Dremio before 24.3.1 allows path traversal. An authenticated user who has no privileges on certain folders (and the files and datasets in these folders) can …

Jan 22, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.