CVE Database

39369+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-24760
8.8 HIGH

mailcow is a dockerized email package, with multiple containers linked in one bridged network. A security vulnerability has been identified in mailcow affecting versions < …

Feb 2, 2024
CVE-2024-24757
7.6 HIGH

open-irs is an issue response robot that reponds to issues in the installed repository. The `.env` file was accidentally uploaded when working with git actions. …

Feb 2, 2024
CVE-2024-24470
8.8 HIGH

Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the update_post.php component.

Feb 2, 2024
CVE-2024-24161
7.5 HIGH

MRCMS 3.0 contains an Arbitrary File Read vulnerability in /admin/file/edit.do as the incoming path parameter is not filtered.

Feb 2, 2024
CVE-2024-23831
7.5 HIGH

LedgerSMB is a free web-based double-entry accounting system. When a LedgerSMB database administrator has an active session in /setup.pl, an attacker can trick the admin …

Feb 2, 2024
CVE-2024-22107
7.2 HIGH

An issue was discovered in GTB Central Console 15.17.1-30814.NG. The method systemSettingsDnsDataAction at /opt/webapp/src/AppBundle/Controller/React/SystemSettingsController.php is vulnerable to command injection via the /old/react/v1/api/system/dns/data endpoint. An authenticated …

Feb 2, 2024
CVE-2023-6387
7.5 HIGH

A potential buffer overflow exists in the Bluetooth LE HCI CPC sample application in the Gecko SDK which may result in a denial of service …

Feb 2, 2024
CVE-2023-51838
7.5 HIGH

Ylianst MeshCentral 1.1.16 suffers from Use of a Broken or Risky Cryptographic Algorithm.

Feb 2, 2024
CVE-2023-47568
8.8 HIGH

A SQL injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to inject malicious …

Feb 2, 2024
CVE-2023-47564
8.0 HIGH

An incorrect permission assignment for critical resource vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow authenticated users to read …

Feb 2, 2024
CVE-2023-47562
7.4 HIGH

An OS command injection vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow authenticated users to execute commands via a …

Feb 2, 2024
CVE-2023-39297
8.8 HIGH

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute …

Feb 2, 2024
CVE-2020-29504
7.4 HIGH

Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain a Missing Required Cryptographic Step Vulnerability.

Feb 2, 2024
CVE-2023-38273
7.5 HIGH

IBM Cloud Pak System 2.3.1.1, 2.3.2.0, and 2.3.3.7 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. …

Feb 2, 2024
CVE-2023-47142
7.5 HIGH

IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 could allow an attacker on the organization's local network to escalate their privileges due to unauthorized …

Feb 2, 2024
CVE-2024-0269
8.3 HIGH

ManageEngine ADAudit Plus versions 7270 and below are vulnerable to the Authenticated SQL injection in File-Summary DrillDown. This issue has been fixed and released in …

Feb 2, 2024
CVE-2024-0253
8.3 HIGH

ManageEngine ADAudit Plus versions 7270 and below are vulnerable to the Authenticated SQL injection in home Graph-Data.

Feb 2, 2024
CVE-2023-6676
8.8 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in National Keep Cyber Security Services CyberMath allows Cross Site Request Forgery.This issue affects CyberMath: from v1.4 before v1.5.

Feb 2, 2024
CVE-2024-1201
7.8 HIGH

Search path or unquoted item vulnerability in HDD Health affecting versions 4.2.0.112 and earlier. This vulnerability could allow a local attacker to store a malicious …

Feb 2, 2024
CVE-2024-23895
8.2 HIGH

A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting …

Feb 2, 2024
CVE-2024-0338
7.3 HIGH

A buffer overflow vulnerability has been found in XAMPP affecting version 8.2.4 and earlier. An attacker could execute arbitrary code through a long file debug …

Feb 2, 2024
CVE-2023-39611
7.5 HIGH

An issue in Software FX Chart FX 7 version 7.0.4962.20829 allows attackers to enumerate and read files from the local filesystem by sending crafted web …

Feb 2, 2024
CVE-2024-22851
7.5 HIGH

Directory Traversal Vulnerability in LiveConfig before v.2.5.2 allows a remote attacker to obtain sensitive information via a crafted request to the /static/ endpoint.

Feb 2, 2024
CVE-2023-48645
7.8 HIGH

An issue was discovered in the Archibus app 4.0.3 for iOS. It uses a local database that is synchronized with a Web central server instance …

Feb 2, 2024
CVE-2024-24524
8.8 HIGH

Cross Site Request Forgery (CSRF) vulnerability in flusity-CMS v.2.33, allows remote attackers to execute arbitrary code via the add_menu.php component.

Feb 2, 2024
CVE-2020-24682
7.2 HIGH

Unquoted Search Path or Element vulnerability in B&R Industrial Automation Automation Studio, B&R Industrial Automation NET/PVI allows Target Programs with Elevated Privileges.This issue affects Automation …

Feb 2, 2024
CVE-2024-21860
8.2 HIGH

in OpenHarmony v4.0.0 and prior versions allow an adjacent attacker arbitrary code execution in any apps through use after free.

Feb 2, 2024
CVE-2024-21780
7.5 HIGH

Stack-based buffer overflow vulnerability exists in HOME SPOT CUBE2 V102 and earlier. Processing a specially crafted command may result in a denial of service (DoS) …

Feb 2, 2024
CVE-2021-22282
8.3 HIGH

Improper Control of Generation of Code ('Code Injection') vulnerability in B&R Industrial Automation Automation Studio allows Local Execution of Code.This issue affects Automation Studio: from …

Feb 2, 2024
CVE-2020-24681
8.2 HIGH

Incorrect Permission Assignment for Critical Resource vulnerability in B&R Industrial Automation Automation Studio allows Privilege Escalation.This issue affects Automation Studio: from 4.6.0 through 4.6.X, from …

Feb 2, 2024
CVE-2023-46045
7.8 HIGH

Graphviz 2.36.0 through 9.x before 10.0.1 has an out-of-bounds read via a crafted config6a file. NOTE: exploitability may be uncommon because this file is typically …

Feb 2, 2024
CVE-2023-38019
8.1 HIGH

IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially …

Feb 2, 2024
CVE-2024-22319
8.1 HIGH

IBM Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, 8.11.1 and 8.12.0.1 is susceptible to remote code execution attack via JNDI injection when passing an …

Feb 2, 2024
CVE-2024-22903
8.8 HIGH

Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the deleteUpdateAPK function.

Feb 2, 2024
CVE-2024-22900
8.8 HIGH

Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the setNetworkCardInfo function.

Feb 2, 2024
CVE-2024-22899
8.8 HIGH

Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the syncNtpTime function.

Feb 2, 2024
CVE-2024-22779
8.8 HIGH

Directory Traversal vulnerability in Kihron ServerRPExposer v.1.0.2 and before allows a remote attacker to execute arbitrary code via the loadServerPack in ServerResourcePackProviderMixin.java.

Feb 2, 2024
CVE-2024-21399
8.3 HIGH

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Feb 2, 2024
CVE-2023-50326
7.5 HIGH

IBM PowerSC 1.3, 2.0, and 2.1 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force …

Feb 2, 2024
CVE-2024-22016
7.8 HIGH

In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an authorized user can write directly to the Scada directory. This may allow privilege …

Feb 2, 2024
CVE-2024-24756
7.5 HIGH

Crafatar serves Minecraft avatars based on the skin for use in external applications. Files outside of the `lib/public/` directory can be requested from the server. …

Feb 1, 2024
CVE-2024-21852
8.8 HIGH

In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an attacker can supply a malicious configuration file by utilizing a Zip Slip vulnerability …

Feb 1, 2024
CVE-2023-6221
7.7 HIGH

The cloud provider MachineSense uses for integration and deployment for multiple MachineSense devices, such as the programmable logic controller (PLC), PumpSense, PowerAnalyzer, FeverWarn, and others …

Feb 1, 2024
CVE-2023-49610
8.1 HIGH

MachineSense FeverWarn Raspberry Pi-based devices lack input sanitization, which could allow an attacker on an adjacent network to send a message running commands or could …

Feb 1, 2024
CVE-2023-49115
7.5 HIGH

MachineSense devices use unauthenticated MQTT messaging to monitor devices and remote viewing of sensor data by users.

Feb 1, 2024
CVE-2023-47867
8.8 HIGH

MachineSense FeverWarn devices are configured as Wi-Fi hosts in a way that attackers within range could connect to the device's web services and compromise the …

Feb 1, 2024
CVE-2023-36496
7.7 HIGH

Delegated Admin Privilege virtual attribute provider plugin, when enabled, allows an authenticated user to elevate their permissions in the Directory Server.

Feb 1, 2024
CVE-2023-47257
8.1 HIGH

ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages.

Feb 1, 2024
CVE-2024-24570
8.2 HIGH

Statamic is a Laravel and Git powered CMS. HTML files crafted to look like jpg files are able to be uploaded, allowing for XSS. This …

Feb 1, 2024
CVE-2023-6078
8.8 HIGH

An OS Command Injection vulnerability exists in BIOVIA Materials Studio products from Release BIOVIA 2021 through Release BIOVIA 2023. Upload of a specially crafted perl …

Feb 1, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.