CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-43820
8.8 HIGH

A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the wLogTitlesPrevValueLen field of a DPS file. A remote, unauthenticated …

Jan 18, 2024
CVE-2023-43819
8.8 HIGH

A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the InitialMacroLen field of a DPS file. A remote, unauthenticated …

Jan 18, 2024
CVE-2023-43818
8.8 HIGH

A buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open …

Jan 18, 2024
CVE-2023-43817
7.5 HIGH

A buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft version 2 when parsing the wMailContentLen field of a DPS file. An anonymous attacker …

Jan 18, 2024
CVE-2023-43816
6.3 MEDIUM

A buffer overflow vulnerability exists in Delta Electronics Delta Industrial Automation DOPSoft version 2 when parsing the wKPFStringLen field of a DPS file. An anonymous …

Jan 18, 2024
CVE-2023-43815
7.1 HIGH

A buffer overflow vulnerability exists in Delta Electronics Delta Industrial Automation DOPSoft version 2 when parsing the wScreenDESCTextLen field of a DPS file. An anonymous …

Jan 18, 2024
CVE-2024-22418
6.5 MEDIUM

Group-Office is an enterprise CRM and groupware tool. Affected versions are subject to a vulnerability which is present in the file upload mechanism of Group …

Jan 18, 2024
CVE-2024-22415
7.3 HIGH

jupyter-lsp is a coding assistance tool for JupyterLab (code navigation + hover suggestions + linters + autocompletion + rename) using Language Server Protocol. Installations of …

Jan 18, 2024
CVE-2024-22404
4.1 MEDIUM

Nextcloud files Zip app is a tool to create zip archives from one or multiple files from within Nextcloud. In affected versions users can download …

Jan 18, 2024
CVE-2024-22402
5.4 MEDIUM

Nextcloud guests app is a utility to create guest users which can only see files shared with them. In affected versions users were able to …

Jan 18, 2024
CVE-2024-22401
4.1 MEDIUM

Nextcloud guests app is a utility to create guest users which can only see files shared with them. In affected versions users could change the …

Jan 18, 2024
CVE-2023-51258
5.5 MEDIUM

A memory leak issue discovered in YASM v.1.3.0 allows a local attacker to cause a denial of service via the new_Token function in the modules/preprocs/nasm/nasm-pp:1512.

Jan 18, 2024
CVE-2023-51217
8.8 HIGH

An issue discovered in TenghuTOS TWS-200 firmware version:V4.0-201809201424 allows a remote attacker to execute arbitrary code via crafted command on the ping page component.

Jan 18, 2024
CVE-2023-47092

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not …

Jan 18, 2024
CVE-2024-22403
3.0 LOW

Nextcloud server is a self hosted personal cloud system. In affected versions OAuth codes did not expire. When an attacker would get access to an …

Jan 18, 2024
CVE-2024-22400
3.1 LOW

Nextcloud User Saml is an app for authenticating Nextcloud users using SAML. In affected versions users can be given a link to the Nextcloud server …

Jan 18, 2024
CVE-2024-22213
0.0 NONE

Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. In affected versions users could be …

Jan 18, 2024
CVE-2024-22419
7.3 HIGH

Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine. The `concat` built-in can write over the bounds of the memory buffer that …

Jan 18, 2024
CVE-2024-22212
9.6 CRITICAL

Nextcloud Global Site Selector is a tool which allows you to run multiple small Nextcloud instances and redirect users to the right server. A problem …

Jan 18, 2024
CVE-2023-49943
5.4 MEDIUM

Zoho ManageEngine ServiceDesk Plus MSP before 14504 allows stored XSS (by a low-privileged technician) via a task's name in a time sheet.

Jan 18, 2024
CVE-2023-34348
7.5 HIGH

AVEVA PI Server versions 2023 and 2018 SP3 P05 and prior contain a vulnerability that could allow an unauthenticated user to remotely crash the PI …

Jan 18, 2024
CVE-2023-31274
5.3 MEDIUM

AVEVA PI Server versions 2023 and 2018 SP3 P05 and prior contain a vulnerability that could allow an unauthenticated user to cause the PI Message …

Jan 18, 2024
CVE-2024-22819
8.8 HIGH

FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/email/email_templets_update.

Jan 18, 2024
CVE-2024-22818
8.8 HIGH

FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerbility via /system/site/filterKeyword_save

Jan 18, 2024
CVE-2024-22817
8.8 HIGH

FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/email/email_conf_updagte

Jan 18, 2024
CVE-2024-22603
8.8 HIGH

FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/links/add_link

Jan 18, 2024
CVE-2024-22601
8.8 HIGH

FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/score/scorerule_save

Jan 18, 2024
CVE-2023-28901
5.3 MEDIUM

The Skoda Automotive cloud contains a Broken Access Control vulnerability, allowing remote attackers to obtain recent trip data, vehicle mileage, fuel consumption, average and maximum …

Jan 18, 2024
CVE-2023-28900
5.3 MEDIUM

The Skoda Automotive cloud contains a Broken Access Control vulnerability, allowing to obtain nicknames and other user identifiers of Skoda Connect service users by specifying …

Jan 18, 2024
CVE-2024-22699
8.8 HIGH

FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/admin/update_group_save.

Jan 18, 2024
CVE-2024-0607
6.6 MEDIUM

A flaw was found in the Netfilter subsystem in the Linux kernel. The issue is in the nft_byteorder_eval() function, where the code iterates through a …

Jan 18, 2024
CVE-2024-0409
7.8 HIGH

A flaw was found in the X.Org server. The cursor code in both Xephyr and Xwayland uses the wrong type of private at creation. It …

Jan 18, 2024
CVE-2024-0408
5.5 MEDIUM

A flaw was found in the X.Org server. The GLX PBuffer code does not call the XACE hook when creating the buffer, leaving it unlabeled. …

Jan 18, 2024
CVE-2024-22593
8.8 HIGH

FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/admin/add_group_save

Jan 18, 2024
CVE-2024-22592
8.8 HIGH

FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/user/group_update

Jan 18, 2024
CVE-2024-22591
8.8 HIGH

FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/user/group_save.

Jan 18, 2024
CVE-2024-22568
8.8 HIGH

FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/score/del.

Jan 18, 2024
CVE-2024-22549
5.4 MEDIUM

FlyCms 1.0 is vulnerable to Cross Site Scripting (XSS) in the email settings of the website settings section.

Jan 18, 2024
CVE-2024-22548
5.4 MEDIUM

FlyCms 1.0 is vulnerable to Cross Site Scripting (XSS) in the system website settings website name section.

Jan 18, 2024
CVE-2023-7153
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Macroturk Software and Internet Technologies Macro-Bel allows Reflected XSS.This issue affects Macro-Bel: before …

Jan 18, 2024
CVE-2023-40052
7.5 HIGH

This issue affects Progress Application Server (PAS) for OpenEdge in versions 11.7 prior to 11.7.18, 12.2 prior to 12.2.13, and innovation releases prior to 12.8.0 …

Jan 18, 2024
CVE-2023-40051
9.1 CRITICAL

This issue affects Progress Application Server (PAS) for OpenEdge in versions 11.7 prior to 11.7.18, 12.2 prior to 12.2.13, and innovation releases prior to 12.8.0. …

Jan 18, 2024
CVE-2021-33631
5.5 MEDIUM

Integer Overflow or Wraparound vulnerability in openEuler kernel on Linux (filesystem modules) allows Forced Integer Overflow.This issue affects openEuler kernel: from 4.19.90 before 4.19.90-2401.3, from …

Jan 18, 2024
CVE-2021-33630
5.5 MEDIUM

NULL Pointer Dereference vulnerability in openEuler kernel on Linux (network modules) allows Pointer Manipulation. This vulnerability is associated with program files net/sched/sch_cbs.C. This issue affects …

Jan 18, 2024
CVE-2024-22317
9.1 CRITICAL

IBM App Connect Enterprise 11.0.0.1 through 11.0.0.24 and 12.0.1.0 through 12.0.11.0 could allow a remote attacker to obtain sensitive information or cause a denial of …

Jan 18, 2024
CVE-2024-0669
6.3 MEDIUM

A Cross-Frame Scripting vulnerability has been found on Plone CMS affecting verssion below 6.0.5. An attacker could store a malicious URL to be opened by …

Jan 18, 2024
CVE-2023-5806
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mergen Software Quality Management System allows SQL Injection.This issue affects Quality …

Jan 18, 2024
CVE-2023-51464
5.4 MEDIUM

Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to …

Jan 18, 2024
CVE-2023-51463
5.4 MEDIUM

Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a …

Jan 18, 2024
CVE-2024-0580
6.5 MEDIUM

Omission of user-controlled key authorization in the IDMSistemas platform, affecting the QSige product. This vulnerability allows an attacker to extract sensitive information from the API …

Jan 18, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.