CVE Database

39369+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-1036
7.3 HIGH

A vulnerability was found in openBI up to 1.0.8 and classified as critical. This issue affects the function uploadIcon of the file /application/index/controller/Screen.php of the …

Jan 30, 2024
CVE-2024-23838
7.5 HIGH

TrueLayer.NET is the .Net client for TrueLayer. The vulnerability could potentially allow a malicious actor to gain control over the destination URL of the HttpClient …

Jan 30, 2024
CVE-2023-6258
8.1 HIGH

A security vulnerability has been identified in the pkcs11-provider, which is associated with Public-Key Cryptography Standards (PKCS#11). If exploited successfully, this vulnerability could result in …

Jan 30, 2024
CVE-2023-46230
8.2 HIGH

In Splunk Add-on Builder versions below 4.1.4, the app writes sensitive information to internal log files.

Jan 30, 2024
CVE-2024-21649
8.8 HIGH

The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). Prior to 4.2.0, authenticated users could …

Jan 30, 2024
CVE-2024-1035
7.3 HIGH

A vulnerability has been found in openBI up to 1.0.8 and classified as critical. This vulnerability affects the function uploadIcon of the file /application/index/controller/Icon.php. The …

Jan 30, 2024
CVE-2024-1019
8.6 HIGH

ModSecurity / libModSecurity 3.0.0 to 3.0.11 is affected by a WAF bypass for path-based payloads submitted via specially crafted request URLs. ModSecurity v3 decodes percent-encoded …

Jan 30, 2024
CVE-2024-1034
7.3 HIGH

A vulnerability, which was classified as critical, was found in openBI up to 1.0.8. This affects the function uploadFile of the file /application/index/controller/File.php. The manipulation …

Jan 30, 2024
CVE-2024-1032
7.3 HIGH

A vulnerability classified as critical was found in openBI up to 1.0.8. Affected by this vulnerability is the function testConnection of the file /application/index/controller/Databasesource.php of …

Jan 30, 2024
CVE-2024-22523
7.5 HIGH

Directory Traversal vulnerability in Qiyu iFair version 23.8_ad0 and before, allows remote attackers to obtain sensitive information via uploadimage component.

Jan 30, 2024
CVE-2024-1061
8.6 HIGH

The 'HTML5 Video Player' WordPress Plugin, version < 2.5.25 is affected by an unauthenticated SQL injection vulnerability in the 'id' parameter in the 'get_view' function.

Jan 30, 2024
CVE-2023-6942
7.5 HIGH

Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation EZSocket versions 3.0 to 5.92, GT Designer3 Version1(GOT1000) versions 1.325P and prior, GT Designer3 Version1(GOT2000) …

Jan 30, 2024
CVE-2023-36260
7.5 HIGH

An issue was discovered in the Feed Me plugin 4.6.1 for Craft CMS. It allows remote attackers to cause a denial of service (DoS) via …

Jan 30, 2024
CVE-2024-21488
7.3 HIGH

Versions of the package network before 0.7.0 are vulnerable to Arbitrary Command Injection due to use of the child_process exec function without input sanitization. If …

Jan 30, 2024
CVE-2024-21840
7.9 HIGH

Incorrect Default Permissions vulnerability in Hitachi Storage Plug-in for VMware vCenter allows local users to read and write specific files. This issue affects Hitachi Storage …

Jan 30, 2024
CVE-2024-22938
7.8 HIGH

Insecure Permissions vulnerability in BossCMS v.1.3.0 allows a local attacker to execute arbitrary code and escalate privileges via the init function in admin.class.php component.

Jan 30, 2024
CVE-2023-5372
7.2 HIGH

The post-authentication command injection vulnerability in Zyxel NAS326 firmware versions through V5.21(AAZF.15)C0 and NAS542 firmware versions through V5.21(ABAG.12)C0 could allow an authenticated attacker with administrator …

Jan 30, 2024
CVE-2023-51843
8.2 HIGH

react-dashboard 1.4.0 is vulnerable to Cross Site Scripting (XSS) as httpOnly is not set.

Jan 30, 2024
CVE-2023-4551
7.2 HIGH

Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows OS Command Injection. The AppBuilder's Scheduler functionality that facilitates creation of scheduled tasks is …

Jan 29, 2024
CVE-2023-4550
7.5 HIGH

Improper Input Validation, Files or Directories Accessible to External Parties vulnerability in OpenText AppBuilder on Windows, Linux allows Probe System Files. An unauthenticated or authenticated …

Jan 29, 2024
CVE-2023-49038
7.2 HIGH

Command injection in the ping utility on Buffalo LS210D 1.78-0.03 allows a remote authenticated attacker to inject arbitrary commands onto the NAS as root.

Jan 29, 2024
CVE-2024-24140
7.2 HIGH

Sourcecodester Daily Habit Tracker App 1.0 allows SQL Injection via the parameter 'tracker.'

Jan 29, 2024
CVE-2024-24139
7.2 HIGH

Sourcecodester Login System with Email Verification 1.0 allows SQL Injection via the 'user' parameter.

Jan 29, 2024
CVE-2023-51842
7.5 HIGH

An algorithm-downgrade issue was discovered in Ylianst MeshCentral 1.1.16.

Jan 29, 2024
CVE-2024-23940
7.8 HIGH

Trend Micro uiAirSupport, included in the Trend Micro Security 2023 family of consumer products, version 6.0.2092 and below is vulnerable to a DLL hijacking/proxying vulnerability, …

Jan 29, 2024
CVE-2024-23828
8.8 HIGH

Nginx-UI is a web interface to manage Nginx configurations. It is vulnerable to an authenticated arbitrary command execution via CRLF attack when changing the value …

Jan 29, 2024
CVE-2024-1009
7.3 HIGH

A vulnerability was found in SourceCodester Employee Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Jan 29, 2024
CVE-2023-1705
8.4 HIGH

Missing Authorization vulnerability in Forcepoint F|One SmartEdge Agent on Windows (bgAutoinstaller service modules) allows Privilege Escalation, Functionality Bypass.This issue affects F|One SmartEdge Agent: before 1.7.0.230330-554.

Jan 29, 2024
CVE-2024-1006
7.3 HIGH

A vulnerability was found in Shanxi Diankeyun Technology NODERP up to 6.0.2 and classified as critical. This issue affects some unknown processing of the file …

Jan 29, 2024
CVE-2024-1004
7.2 HIGH

A vulnerability, which was classified as critical, was found in Totolink N200RE 9.3.5u.6139_B20201216. This affects the function loginAuth of the file /cgi-bin/cstecgi.cgi. The manipulation of …

Jan 29, 2024
CVE-2024-1003
7.2 HIGH

A vulnerability, which was classified as critical, has been found in Totolink N200RE 9.3.5u.6139_B20201216. Affected by this issue is the function setLanguageCfg of the file …

Jan 29, 2024
CVE-2023-7204
7.5 HIGH

The WP STAGING WordPress Backup plugin before 3.2.0 allows access to cache files during the cloning process which provides

Jan 29, 2024
CVE-2023-7074
8.8 HIGH

The WP SOCIAL BOOKMARK MENU WordPress plugin through 1.2 does not have CSRF check in place when updating its settings, which could allow attackers to …

Jan 29, 2024
CVE-2023-6946
8.8 HIGH

The Autotitle for WordPress plugin through 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

Jan 29, 2024
CVE-2023-6391
8.8 HIGH

The Custom User CSS WordPress plugin through 0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make …

Jan 29, 2024
CVE-2023-6390
8.8 HIGH

The WordPress Users WordPress plugin through 1.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

Jan 29, 2024
CVE-2023-6279
7.1 HIGH

The Woostify Sites Library WordPress plugin before 1.4.8 does not have authorisation in an AJAX action, allowing any authenticated users, such as subscriber to update …

Jan 29, 2024
CVE-2023-40548
7.4 HIGH

A buffer overflow was found in Shim in the 32-bit system. The overflow happens due to an addition operation involving a user-controlled value parsed from …

Jan 29, 2024
CVE-2024-23747
7.5 HIGH

The Moderna Sistemas ModernaNet Hospital Management System 2024 is susceptible to an Insecure Direct Object Reference (IDOR) vulnerability. This vulnerability resides in the system's handling …

Jan 29, 2024
CVE-2024-1002
7.2 HIGH

A vulnerability classified as critical was found in Totolink N200RE 9.3.5u.6139_B20201216. Affected by this vulnerability is the function setIpPortFilterRules of the file /cgi-bin/cstecgi.cgi. The manipulation …

Jan 29, 2024
CVE-2024-1001
7.2 HIGH

A vulnerability classified as critical has been found in Totolink N200RE 9.3.5u.6139_B20201216. Affected is the function main of the file /cgi-bin/cstecgi.cgi. The manipulation leads to …

Jan 29, 2024
CVE-2024-1000
7.2 HIGH

A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216. It has been rated as critical. This issue affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi. The …

Jan 29, 2024
CVE-2024-0999
7.2 HIGH

A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216. It has been declared as critical. This vulnerability affects the function setParentalRules of the file /cgi-bin/cstecgi.cgi. The …

Jan 29, 2024
CVE-2024-0998
7.2 HIGH

A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216. It has been classified as critical. This affects the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi. The manipulation …

Jan 29, 2024
CVE-2024-0997
7.2 HIGH

A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216 and classified as critical. Affected by this issue is the function setOpModeCfg of the file /cgi-bin/cstecgi.cgi. The …

Jan 29, 2024
CVE-2023-29055
7.5 HIGH

In Apache Kylin version 2.0.0 to 4.0.3, there is a Server Config web interface that displays the content of file 'kylin.properties', that may contain serverside …

Jan 29, 2024
CVE-2023-5378
8.8 HIGH

Improper Input Validation vulnerability in MegaBIP and already unsupported SmodBIP software allows for Stored XSS.This issue affects SmodBIP in all versions and MegaBIP in versions …

Jan 29, 2024
CVE-2023-46838
7.5 HIGH

Transmit requests in Xen's virtual network protocol can consist of multiple parts. While not really useful, except for the initial part any of them may …

Jan 29, 2024
CVE-2024-0212
8.1 HIGH

The Cloudflare Wordpress plugin was found to be vulnerable to improper authentication. The vulnerability enables attackers with a lower privileged account to access data from …

Jan 29, 2024
CVE-2024-24736
7.5 HIGH

The POP3 service in YahooPOPs (aka YPOPs!) 1.6 allows a remote denial of service (reboot) via a long string to TCP port 110, a related …

Jan 29, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.