CVE Database

39369+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-40265
8.8 HIGH

An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911. It allows authenticated remote code execution via file upload.

Feb 8, 2024
CVE-2023-27001
8.8 HIGH

An issue discovered in Egerie Risk Manager v4.0.5 allows attackers to bypass the signature mechanism and tamper with the values inside the JWT payload resulting …

Feb 8, 2024
CVE-2023-25365
7.8 HIGH

Cross Site Scripting vulnerability found in October CMS v.3.2.0 allows local attacker to execute arbitrary code via the file type .mp3

Feb 8, 2024
CVE-2024-23756
7.5 HIGH

The HTTP PUT and DELETE methods are enabled in the Plone official Docker version 5.2.13 (5221), allowing unauthenticated attackers to execute dangerous actions such as …

Feb 8, 2024
CVE-2024-23660
7.5 HIGH

The Binance Trust Wallet app for iOS in commit 3cd6e8f647fbba8b5d8844fcd144365a086b629f, git tag 0.0.4 misuses the trezor-crypto library and consequently generates mnemonic words for which the …

Feb 8, 2024
CVE-2024-1329
7.7 HIGH

HashiCorp Nomad and Nomad Enterprise 1.5.13 up to 1.6.6, and 1.7.3 template renderer is vulnerable to arbitrary file write on the host as the Nomad …

Feb 8, 2024
CVE-2024-0242
7.3 HIGH

Under certain circumstances IQ Panel4 and IQ4 Hub panel software prior to version 4.4.2 could allow unauthorized access to settings.

Feb 8, 2024
CVE-2024-22795
7.0 HIGH

Insecure Permissions vulnerability in Forescout SecureConnector v.11.3.06.0063 allows a local attacker to escalate privileges via the Recheck Compliance Status component.

Feb 8, 2024
CVE-2023-47020
8.8 HIGH

Multiple Cross-Site Request Forgery (CSRF) chaining in NCR Terminal Handler v.1.5.1 allows privileges to be escalated by an attacker through a crafted request involving user …

Feb 8, 2024
CVE-2024-24878
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marco Almeida | Webdados Portugal CTT Tracking for WooCommerce portugal-ctt-tracking-woocommerce.This issue affects Portugal …

Feb 8, 2024
CVE-2024-24877
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magic Hills Pty Ltd Wonder Slider Lite allows Reflected XSS.This issue affects Wonder …

Feb 8, 2024
CVE-2024-24113
8.8 HIGH

xxl-job =< 2.4.1 has a Server-Side Request Forgery (SSRF) vulnerability, which causes low-privileged users to control executor to RCE.

Feb 8, 2024
CVE-2024-1150
7.8 HIGH

Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on Unix allows File Manipulation through Snow Update Packages.This issue affects Inventory Agent: through …

Feb 8, 2024
CVE-2024-1149
7.8 HIGH

Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on MacOS, Snow Software Inventory Agent on Windows, Snow Software Inventory Agent on Linux …

Feb 8, 2024
CVE-2024-0985
8.0 HIGH

Late privilege drop in REFRESH MATERIALIZED VIEW CONCURRENTLY in PostgreSQL allows an object creator to execute arbitrary SQL functions as the command issuer. The command …

Feb 8, 2024
CVE-2024-24881
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc …

Feb 8, 2024
CVE-2024-24879
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yannick Lefebvre Link Library allows Reflected XSS.This issue affects Link Library: from n/a …

Feb 8, 2024
CVE-2023-6519
7.5 HIGH

Exposure of Data Element to Wrong Session vulnerability in Mia Technology Inc. MİA-MED allows Read Sensitive Strings Within an Executable.This issue affects MİA-MED: before 1.0.7.

Feb 8, 2024
CVE-2023-6518
7.5 HIGH

Plaintext Storage of a Password vulnerability in Mia Technology Inc. MİA-MED allows Read Sensitive Strings Within an Executable.This issue affects MİA-MED: before 1.0.7.

Feb 8, 2024
CVE-2023-6517
7.5 HIGH

Exposure of Sensitive Information Due to Incompatible Policies vulnerability in Mia Technology Inc. MİA-MED allows Collect Data as Provided by Users.This issue affects MİA-MED: before …

Feb 8, 2024
CVE-2023-6515
8.8 HIGH

Authorization Bypass Through User-Controlled Key vulnerability in Mia Technology Inc. MİA-MED allows Authentication Abuse.This issue affects MİA-MED: before 1.0.7.

Feb 8, 2024
CVE-2024-23452
7.5 HIGH

Request smuggling vulnerability in HTTP server in Apache bRPC 0.9.5~1.7.0 on all platforms allows attacker to smuggle request. Vulnerability Cause Description: The http_parser does not …

Feb 8, 2024
CVE-2024-24350
8.8 HIGH

File Upload vulnerability in Software Publico e-Sic Livre v.2.0 and before allows a remote attacker to execute arbitrary code via the extension filtering component.

Feb 8, 2024
CVE-2024-24806
7.3 HIGH

libuv is a multi-platform support library with a focus on asynchronous I/O. The `uv_getaddrinfo` function in `src/unix/getaddrinfo.c` (and its windows counterpart `src/win/getaddrinfo.c`), truncates hostnames to …

Feb 7, 2024
CVE-2024-23769
7.3 HIGH

Improper privilege control for the named pipe in Samsung Magician PC Software 8.0.0 (for Windows) allows a local attacker to read privileged data.

Feb 7, 2024
CVE-2024-24824
8.8 HIGH

Graylog is a free and open log management platform. Starting in version 2.0.0 and prior to versions 5.1.11 and 5.2.4, arbitrary classes can be loaded …

Feb 7, 2024
CVE-2024-20290
7.5 HIGH

A vulnerability in the OLE2 file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on …

Feb 7, 2024
CVE-2024-20255
8.2 HIGH

A vulnerability in the SOAP API of Cisco Expressway Series and Cisco TelePresence Video Communication Server could allow an unauthenticated, remote attacker to conduct a …

Feb 7, 2024
CVE-2023-43017
8.2 HIGH

IBM Security Verify Access 10.0.0.0 through 10.0.6.1 could allow a privileged user to install a configuration file that could allow remote access. IBM X-Force ID: …

Feb 7, 2024
CVE-2023-32330
7.5 HIGH

IBM Security Verify Access 10.0.0.0 through 10.0.6.1 uses insecure calls that could allow an attacker on the network to take control of the server. IBM …

Feb 7, 2024
CVE-2023-32328
7.5 HIGH

IBM Security Verify Access 10.0.0.0 through 10.0.6.1 uses insecure protocols in some instances that could allow an attacker on the network to take control of …

Feb 7, 2024
CVE-2024-22012
7.8 HIGH

there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional …

Feb 7, 2024
CVE-2024-24771
7.7 HIGH

Open Forms allows users create and publish smart forms. Versions prior to 2.2.9, 2.3.7, 2.4.5, and 2.5.2 contain a non-exploitable multi-factor authentication weakness. Superusers who …

Feb 7, 2024
CVE-2024-25201
7.5 HIGH

Espruino 2v20 (commit fcc9ba4) was discovered to contain an Out-of-bounds Read via jsvStringIteratorPrintfCallback at src/jsvar.c.

Feb 7, 2024
CVE-2024-25200
7.5 HIGH

Espruino 2v20 (commit fcc9ba4) was discovered to contain a Stack Overflow via the jspeFactorFunctionCall at src/jsparse.c.

Feb 7, 2024
CVE-2024-1118
8.8 HIGH

The Podlove Subscribe button plugin for WordPress is vulnerable to UNION-based SQL Injection via the 'button' attribute of the podlove-subscribe-button shortcode in all versions up …

Feb 7, 2024
CVE-2023-51437
7.4 HIGH

Observable timing discrepancy vulnerability in Apache Pulsar SASL Authentication Provider can allow an attacker to forge a SASL Role Token that will pass signature verification. …

Feb 7, 2024
CVE-2024-24311
7.5 HIGH

Path Traversal vulnerability in Linea Grafica "Multilingual and Multistore Sitemap Pro - SEO" (lgsitemaps) module for PrestaShop before version 1.6.6, a guest can download personal …

Feb 7, 2024
CVE-2024-24304
7.5 HIGH

In the module "Mailjet" (mailjet) from Mailjet for PrestaShop before versions 3.5.1, a guest can download technical information without restriction.

Feb 7, 2024
CVE-2024-24810
8.2 HIGH

WiX toolset lets developers create installers for Windows Installer, the Windows installation engine. The .be TEMP folder is vulnerable to DLL redirection attacks that allow …

Feb 7, 2024
CVE-2024-22022
8.8 HIGH

Vulnerability CVE-2024-22022 allows a Veeam Recovery Orchestrator user that has been assigned a low-privileged role to access the NTLM hash of the service account used …

Feb 7, 2024
CVE-2024-24680
7.5 HIGH

An issue was discovered in Django 3.2 before 3.2.24, 4.2 before 4.2.10, and Django 5.0 before 5.0.2. The intcomma template filter was subject to a …

Feb 6, 2024
CVE-2024-24577
8.6 HIGH

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality …

Feb 6, 2024
CVE-2024-24575
7.5 HIGH

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality …

Feb 6, 2024
CVE-2024-22520
8.2 HIGH

An issue discovered in Dronetag Drone Scanner 1.5.2 allows attackers to impersonate other drones via transmission of crafted data packets.

Feb 6, 2024
CVE-2024-22519
8.2 HIGH

An issue discovered in OpenDroneID OSM 3.5.1 allows attackers to impersonate other drones via transmission of crafted data packets.

Feb 6, 2024
CVE-2023-45735
8.0 HIGH

A potential attacker with access to the Westermo Lynx device may be able to execute malicious code that could affect the correct functioning of the …

Feb 6, 2024
CVE-2023-38579
8.0 HIGH

The cross-site request forgery token in the request may be predictable or easily guessable allowing attackers to craft a malicious request, which could be triggered …

Feb 6, 2024
CVE-2024-22515
8.8 HIGH

Unrestricted File Upload vulnerability in iSpyConnect.com Agent DVR 5.1.6.0 allows attackers to upload arbitrary files via the upload audio component.

Feb 6, 2024
CVE-2024-22514
8.8 HIGH

An issue discovered in iSpyConnect.com Agent DVR 5.1.6.0 allows attackers to run arbitrary files by restoring a crafted backup file.

Feb 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.