CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-0478
6.3 MEDIUM

A vulnerability was found in code-projects Fighting Cock Information System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/pages/edit_chicken.php. …

Jan 13, 2024
CVE-2024-0477
6.3 MEDIUM

A vulnerability has been found in code-projects Fighting Cock Information System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/action/update-deworm.php. …

Jan 13, 2024
CVE-2024-0476
2.4 LOW

A vulnerability, which was classified as problematic, was found in Blood Bank & Donor Management 1.0. This affects an unknown part of the file request-received-bydonar.php. …

Jan 13, 2024
CVE-2023-52289
7.5 HIGH

An issue was discovered in the flaskcode package through 0.0.8 for Python. An unauthenticated directory traversal, exploitable with a POST request to a /update-resource-data/<file_path> URI …

Jan 13, 2024
CVE-2023-52288
7.5 HIGH

An issue was discovered in the flaskcode package through 0.0.8 for Python. An unauthenticated directory traversal, exploitable with a GET request to a /resource-data/<file_path>.txt URI …

Jan 13, 2024
CVE-2023-51071
6.5 MEDIUM

An access control issue in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to arbitrarily disable the SMB service on a …

Jan 13, 2024
CVE-2023-51070
7.5 HIGH

An access control issue in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to arbitrarily adjust sensitive SMB settings on the …

Jan 13, 2024
CVE-2023-51068
5.4 MEDIUM

An authenticated reflected cross-site scripting (XSS) vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 allows attackers to execute arbitrary javascript on a victim's browser …

Jan 13, 2024
CVE-2023-51067
6.1 MEDIUM

An unauthenticated reflected cross-site scripting (XSS) vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 allows attackers to execute arbitrary javascript on a victim's browser …

Jan 13, 2024
CVE-2023-51066
8.8 HIGH

An authenticated remote code execution vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows attackers to arbitrarily execute commands.

Jan 13, 2024
CVE-2023-51065
7.5 HIGH

Incorrect access control in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to obtain system backups and other sensitive information from …

Jan 13, 2024
CVE-2023-51064
6.1 MEDIUM

QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 was discovered to contain a DOM Based reflected XSS vulnerability within the component qnme-ajax?method=tree_table.

Jan 13, 2024
CVE-2023-51063
8.8 HIGH

QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 was discovered to contain a DOM Based Reflected Cross Site Scripting (XSS) vulnerability within the component …

Jan 13, 2024
CVE-2023-51062
5.3 MEDIUM

An unauthenticated log file read in the component log-smblog-save of QStar Archive Solutions RELEASE_3-0 Build 7 Patch 0 allows attackers to disclose the SMB Log …

Jan 13, 2024
CVE-2023-51805
6.5 MEDIUM

SQL Injection vulnerability in TDuckCLoud tduck-platform v.4.0 allows a remote attacker to obtain sensitive information via the getFormKey parameter in the search function of FormDataMysqlService.java …

Jan 13, 2024
CVE-2023-51804
7.5 HIGH

An issue in rymcu forest v.0.02 allows a remote attacker to obtain sensitive information via manipulation of the HTTP body URL in the com.rymcu.forest.web.api.common.UploadController file.

Jan 13, 2024
CVE-2023-46943
9.1 CRITICAL

An issue was discovered in NPM's package @evershop/evershop before version 1.0.0-rc.8. The HMAC secret used for generating tokens is hardcoded as "secret". A weak HMAC …

Jan 13, 2024
CVE-2023-46942
7.5 HIGH

Lack of authentication in NPM's package @evershop/evershop before version 1.0.0-rc.8, allows remote attackers to obtain sensitive information via improper authorization in GraphQL endpoints.

Jan 13, 2024
CVE-2023-33472
8.8 HIGH

An issue was discovered in Scada-LTS v2.7.5.2 build 4551883606 and before, allows remote attackers with low-level authentication to escalate privileges, execute arbitrary code, and obtain …

Jan 13, 2024
CVE-2023-50072
5.4 MEDIUM

A Stored Cross-Site Scripting (XSS) vulnerability exists in OpenKM version 7.1.40 (dbb6e88) With Professional Extension that allows an authenticated user to upload a note on …

Jan 13, 2024
CVE-2024-22142
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozmoslabs Profile Builder Pro allows Reflected XSS.This issue affects Profile Builder Pro: from …

Jan 13, 2024
CVE-2024-22137
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MailMunch Constant Contact Forms by MailMunch allows Stored XSS.This issue affects Constant Contact …

Jan 13, 2024
CVE-2024-0475
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in code-projects Dormitory Management System 1.0. Affected by this issue is some unknown functionality of …

Jan 13, 2024
CVE-2024-23301
5.5 MEDIUM

Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers to gain access to system secrets otherwise only readable …

Jan 12, 2024
CVE-2024-0474
7.3 HIGH

A vulnerability classified as critical was found in code-projects Dormitory Management System 1.0. Affected by this vulnerability is an unknown functionality of the file login.php. …

Jan 12, 2024
CVE-2024-0230
2.4 LOW

A session management issue was addressed with improved checks. This issue is fixed in Magic Keyboard Firmware Update 2.0.6. An attacker with physical access to …

Jan 12, 2024
CVE-2023-48166
7.5 HIGH

A directory traversal vulnerability in the SOAP Server integrated in Atos Unify OpenScape Voice V10 before V10R3.26.1 allows a remote attacker to view the contents …

Jan 12, 2024
CVE-2024-21639
5.3 MEDIUM

CEF (Chromium Embedded Framework ) is a simple framework for embedding Chromium-based browsers in other applications. `CefLayeredWindowUpdaterOSR::OnAllocatedSharedMemory` does not check the size of the shared …

Jan 12, 2024
CVE-2024-0473
6.3 MEDIUM

A vulnerability classified as critical has been found in code-projects Dormitory Management System 1.0. Affected is an unknown function of the file comment.php. The manipulation …

Jan 12, 2024
CVE-2024-0472
3.5 LOW

A vulnerability was found in code-projects Dormitory Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file …

Jan 12, 2024
CVE-2023-49647
8.8 HIGH

Improper access control in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows before version 5.16.10 may allow an …

Jan 12, 2024
CVE-2022-4962
4.3 MEDIUM

A vulnerability was found in Apollo 2.0.0/2.0.1 and classified as problematic. Affected by this issue is some unknown functionality of the file /users of the …

Jan 12, 2024
CVE-2024-21655
4.3 MEDIUM

Discourse is a platform for community discussion. For fields that are client editable, limits on sizes are not imposed. This allows a malicious actor to …

Jan 12, 2024
CVE-2024-21654
4.8 MEDIUM

Rubygems.org is the Ruby community's gem hosting service. Rubygems.org users with MFA enabled would normally be protected from account takeover in the case of email …

Jan 12, 2024
CVE-2024-0471
6.3 MEDIUM

A vulnerability was found in code-projects Human Resource Integrated System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file …

Jan 12, 2024
CVE-2024-0470
6.3 MEDIUM

A vulnerability was found in code-projects Human Resource Integrated System 1.0. It has been classified as critical. This affects an unknown part of the file …

Jan 12, 2024
CVE-2024-0469
6.3 MEDIUM

A vulnerability was found in code-projects Human Resource Integrated System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Jan 12, 2024
CVE-2024-0468
6.3 MEDIUM

A vulnerability has been found in code-projects Fighting Cock Information System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Jan 12, 2024
CVE-2023-51698
9.6 CRITICAL

Atril is a simple multi-page document viewer. Atril is vulnerable to a critical Command Injection Vulnerability. This vulnerability gives the attacker immediate access to the …

Jan 12, 2024
CVE-2023-49801
4.2 MEDIUM

Lif Auth Server is a server for validating logins, managing information, and account recovery for Lif Accounts. The issue relates to the `get_pfp` and `get_banner` …

Jan 12, 2024
CVE-2023-49099
3.1 LOW

Discourse is a platform for community discussion. Under very specific circumstances, secure upload URLs associated with posts can be accessed by guest users even when …

Jan 12, 2024
CVE-2023-49098
3.5 LOW

Discourse-reactions is a plugin that allows user to add their reactions to the post. Data about a user's reaction notifications could be exposed. This vulnerability …

Jan 12, 2024
CVE-2023-48297
8.6 HIGH

Discourse is a platform for community discussion. The message serializer uses the full list of expanded chat mentions (@all and @here) which can lead to …

Jan 12, 2024
CVE-2023-42463
7.4 HIGH

Wazuh is a free and open source platform used for threat prevention, detection, and response. This bug introduced a stack overflow hazard that could allow …

Jan 12, 2024
CVE-2024-22206
9.0 CRITICAL

Clerk helps developers build user management. Unauthorized access or privilege escalation due to a logic flaw in auth() in the App Router or getAuth() in …

Jan 12, 2024
CVE-2024-0467
3.5 LOW

A vulnerability, which was classified as problematic, was found in code-projects Employee Profile Management System 1.0. Affected is an unknown function of the file edit_position_query.php. …

Jan 12, 2024
CVE-2010-10011
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in Acritum Femitter Server 1.04. Affected is an unknown function. The manipulation leads to path traversal. …

Jan 12, 2024
CVE-2024-0466
5.5 MEDIUM

A vulnerability, which was classified as critical, has been found in code-projects Employee Profile Management System 1.0. This issue affects some unknown processing of the …

Jan 12, 2024
CVE-2024-0465
3.5 LOW

A vulnerability classified as problematic was found in code-projects Employee Profile Management System 1.0. This vulnerability affects unknown code of the file download.php. The manipulation …

Jan 12, 2024
CVE-2024-0464
6.3 MEDIUM

A vulnerability classified as critical has been found in code-projects Online Faculty Clearance 1.0. This affects an unknown part of the file delete_faculty.php of the …

Jan 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.