CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-0381
6.4 MEDIUM

The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the use of the 'tag' attribute in the wprm-recipe-name, wprm-recipe-date, and …

Jan 18, 2024
CVE-2023-6970
6.1 MEDIUM

The WP Recipe Maker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘Referer' header in all versions up to, and including, 9.1.0 …

Jan 18, 2024
CVE-2023-6958
6.4 MEDIUM

The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 9.1.0 …

Jan 18, 2024
CVE-2023-6816
9.8 CRITICAL

A flaw was found in X.Org server. Both DeviceFocusEvent and the XIQueryPointer reply contain a bit for each logical button currently down. Buttons can be …

Jan 18, 2024
CVE-2024-0655
5.5 MEDIUM

A vulnerability has been found in Novel-Plus 4.3.0-RC1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /novel/bookSetting/list. The …

Jan 18, 2024
CVE-2023-48359
4.4 MEDIUM

In autotest driver, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with …

Jan 18, 2024
CVE-2023-48358
4.4 MEDIUM

In drm driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Jan 18, 2024
CVE-2023-48357
4.4 MEDIUM

In vsp driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Jan 18, 2024
CVE-2023-48356
4.4 MEDIUM

In jpg driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Jan 18, 2024
CVE-2023-48355
4.4 MEDIUM

In jpg driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Jan 18, 2024
CVE-2023-48354
5.5 MEDIUM

In telephone service, there is a possible improper input validation. This could lead to local information disclosure with no additional execution privileges needed

Jan 18, 2024
CVE-2023-48353
4.4 MEDIUM

In vsp driver, there is a possible use after free due to a logic error. This could lead to local denial of service with System …

Jan 18, 2024
CVE-2023-48352
5.5 MEDIUM

In phasecheckserver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with …

Jan 18, 2024
CVE-2023-48351
5.5 MEDIUM

In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Jan 18, 2024
CVE-2023-48350
5.5 MEDIUM

In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Jan 18, 2024
CVE-2023-48349
5.5 MEDIUM

In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Jan 18, 2024
CVE-2023-48348
5.5 MEDIUM

In video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with …

Jan 18, 2024
CVE-2023-48347
5.5 MEDIUM

In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with …

Jan 18, 2024
CVE-2023-48346
5.5 MEDIUM

In video decoder, there is a possible improper input validation. This could lead to local denial of service with no additional execution privileges needed

Jan 18, 2024
CVE-2023-48345
5.5 MEDIUM

In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with …

Jan 18, 2024
CVE-2023-48344
5.5 MEDIUM

In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with …

Jan 18, 2024
CVE-2023-48343
5.5 MEDIUM

In video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with …

Jan 18, 2024
CVE-2023-48342
4.4 MEDIUM

In media service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Jan 18, 2024
CVE-2023-48341
5.5 MEDIUM

In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with …

Jan 18, 2024
CVE-2023-48340
5.5 MEDIUM

In video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with …

Jan 18, 2024
CVE-2023-48339
4.4 MEDIUM

In jpg driver, there is a possible missing permission check. This could lead to local information disclosure with System execution privileges needed

Jan 18, 2024
CVE-2024-0654
5.3 MEDIUM

A vulnerability, which was classified as problematic, was found in DeepFaceLab pretrained DF.wf.288res.384.92.72.22. Affected is an unknown function of the file mainscripts/Util.py. The manipulation leads …

Jan 18, 2024
CVE-2024-0652
3.5 LOW

A vulnerability was found in PHPGurukul Company Visitor Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality …

Jan 18, 2024
CVE-2024-0651
6.3 MEDIUM

A vulnerability was found in PHPGurukul Company Visitor Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Jan 18, 2024
CVE-2023-6184
5.0 MEDIUM

Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting

Jan 18, 2024
CVE-2021-4433
5.3 MEDIUM

A vulnerability was found in Karjasoft Sami HTTP Server 2.0. It has been classified as problematic. Affected is an unknown function of the component HTTP …

Jan 18, 2024
CVE-2024-23525
6.5 MEDIUM

The Spreadsheet::ParseXLSX package before 0.30 for Perl allows XXE attacks because it neglects to use the no_xxe option of XML::Twig.

Jan 18, 2024
CVE-2024-22416
9.6 CRITICAL

pyLoad is a free and open-source Download Manager written in pure Python. The `pyload` API allows any API call to be made using GET requests. …

Jan 18, 2024
CVE-2024-0650
4.3 MEDIUM

A vulnerability was found in Project Worlds Visitor Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file …

Jan 18, 2024
CVE-2023-6340
5.5 MEDIUM

SonicWall Capture Client version 3.7.10, NetExtender client version 10.2.337 and earlier versions are installed with sfpmonitor.sys driver. The driver has been found to be vulnerable …

Jan 18, 2024
CVE-2024-0649
6.3 MEDIUM

A vulnerability was found in ZhiHuiYun up to 4.4.13 and classified as critical. This issue affects the function download_network_image of the file /app/Http/Controllers/ImageController.php of the …

Jan 17, 2024
CVE-2024-0648
7.3 HIGH

A vulnerability has been found in Yunyou CMS up to 2.2.6 and classified as critical. This vulnerability affects unknown code of the file /app/index/controller/Common.php. The …

Jan 17, 2024
CVE-2024-22414
6.5 MEDIUM

flaskBlog is a simple blog app built with Flask. Improper storage and rendering of the `/user/<user>` page allows a user's comments to execute arbitrary javascript …

Jan 17, 2024
CVE-2024-22410
3.3 LOW

Creditcoin is a network that enables cross-blockchain credit transactions. The Windows binary of the Creditcoin node loads a suite of DLLs provided by Microsoft at …

Jan 17, 2024
CVE-2023-6549
8.2 HIGH KEV

Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and Out-Of-Bounds Memory …

Jan 17, 2024
CVE-2023-5914
5.4 MEDIUM

Cross-site scripting (XSS)

Jan 17, 2024
CVE-2023-6548
5.5 MEDIUM KEV

Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with …

Jan 17, 2024
CVE-2023-48858
6.1 MEDIUM

A Cross-site scripting (XSS) vulnerability in login page php code in Armex ABO.CMS 5.9 allows remote attackers to inject arbitrary web script or HTML via …

Jan 17, 2024
CVE-2023-44077
9.8 CRITICAL

Studio Network Solutions ShareBrowser before 7.0 on macOS mishandles signature verification, aka PMP-2636.

Jan 17, 2024
CVE-2024-0647
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in Sparksuite SimpleMDE up to 1.11.2. This affects an unknown part of the component iFrame Handler. …

Jan 17, 2024
CVE-2023-7031
5.7 MEDIUM

Insecure Direct Object Reference vulnerabilities were discovered in the Avaya Aura Experience Portal Manager which may allow partial information disclosure to an authenticated non-privileged user. …

Jan 17, 2024
CVE-2022-42884
5.4 MEDIUM

Missing Authorization vulnerability in ThemeinProgress WIP Custom Login.This issue affects WIP Custom Login: from n/a through 1.2.7.

Jan 17, 2024
CVE-2024-22715
8.8 HIGH

Stupid Simple CMS <=1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin-edit.php.

Jan 17, 2024
CVE-2024-22714
6.1 MEDIUM

Stupid Simple CMS <=1.2.4 is vulnerable to Cross Site Scripting (XSS) in the editing section of the article content.

Jan 17, 2024
CVE-2022-41790
4.3 MEDIUM

Missing Authorization vulnerability in CodePeople WP Time Slots Booking Form.This issue affects WP Time Slots Booking Form: from n/a through 1.1.76.

Jan 17, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.