CVE Database

39369+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-22593
8.8 HIGH

FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/admin/add_group_save

Jan 18, 2024
CVE-2024-22592
8.8 HIGH

FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/user/group_update

Jan 18, 2024
CVE-2024-22591
8.8 HIGH

FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/user/group_save.

Jan 18, 2024
CVE-2024-22568
8.8 HIGH

FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/score/del.

Jan 18, 2024
CVE-2023-40052
7.5 HIGH

This issue affects Progress Application Server (PAS) for OpenEdge in versions 11.7 prior to 11.7.18, 12.2 prior to 12.2.13, and innovation releases prior to 12.8.0 …

Jan 18, 2024
CVE-2024-0648
7.3 HIGH

A vulnerability has been found in Yunyou CMS up to 2.2.6 and classified as critical. This vulnerability affects unknown code of the file /app/index/controller/Common.php. The …

Jan 17, 2024
CVE-2023-6549
8.2 HIGH KEV

Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and Out-Of-Bounds Memory …

Jan 17, 2024
CVE-2024-22715
8.8 HIGH

Stupid Simple CMS <=1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin-edit.php.

Jan 17, 2024
CVE-2024-20272
7.3 HIGH

A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to upload arbitrary files to an affected system …

Jan 17, 2024
CVE-2022-41990
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Vinoj Cardoza 3D Tag Cloud allows Stored XSS.This issue affects 3D Tag Cloud: from n/a through 3.8.

Jan 17, 2024
CVE-2024-0646
7.0 HIGH

An out-of-bounds memory write flaw was found in the Linux kernel’s Transport Layer Security functionality in how a user calls a function splice with a …

Jan 17, 2024
CVE-2024-0396
7.1 HIGH

In Progress MOVEit Transfer versions released before 2022.0.10 (14.0.10), 2022.1.11 (14.1.11), 2023.0.8 (15.0.8), 2023.1.3 (15.1.3), an input validation issue was discovered. An authenticated user can …

Jan 17, 2024
CVE-2023-5041
8.8 HIGH

The Track The Click WordPress plugin before 0.3.12 does not properly sanitize query parameters to the stats REST endpoint before using them in a database …

Jan 17, 2024
CVE-2024-0645
7.3 HIGH

Buffer overflow vulnerability in Explorer++ affecting version 1.3.5.531. A local attacker could execute arbitrary code via a long filename argument by monitoring Structured Exception Handler …

Jan 17, 2024
CVE-2023-52285
7.5 HIGH

ExamSys 9150244 allows SQL Injection via the /Support/action/Pages.php s_score2 parameter.

Jan 17, 2024
CVE-2023-51741
7.5 HIGH

This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to transmission of authentication credentials in plaintext over the network. A remote attacker could exploit …

Jan 17, 2024
CVE-2023-51740
7.5 HIGH

This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to transmission of authentication credentials in plaintext over the network. A remote attacker could exploit …

Jan 17, 2024
CVE-2024-0405
7.2 HIGH

The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin, version 1.5.3, is vulnerable to Post-Authenticated SQL Injection via multiple JSON parameters in the /wp-json/burst/v1/data/compare endpoint. …

Jan 17, 2024
CVE-2024-22409
7.5 HIGH

DataHub is an open-source metadata platform. In affected versions a low privileged user could remove a user, edit group members, or edit another user's profile …

Jan 16, 2024
CVE-2024-22408
7.6 HIGH

Shopware is an open headless commerce platform. The implemented Flow Builder functionality in the Shopware application does not adequately validate the URL used when creating …

Jan 16, 2024
CVE-2024-22191
7.3 HIGH

Avo is a framework to create admin panels for Ruby on Rails apps. A stored cross-site scripting (XSS) vulnerability was found in the key_value field …

Jan 16, 2024
CVE-2024-20952
7.4 HIGH

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are …

Jan 16, 2024
CVE-2024-20932
7.5 HIGH

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are …

Jan 16, 2024
CVE-2024-20924
7.6 HIGH

Vulnerability in Oracle Audit Vault and Database Firewall (component: Firewall). Supported versions that are affected are 20.1-20.9. Difficult to exploit vulnerability allows high privileged attacker …

Jan 16, 2024
CVE-2024-20918
7.4 HIGH

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are …

Jan 16, 2024
CVE-2024-20916
8.3 HIGH

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management). The supported version that is affected is 13.5.0.0. Easily …

Jan 16, 2024
CVE-2024-0603
7.3 HIGH

A vulnerability classified as critical has been found in ZhiCms up to 4.0. This affects an unknown part of the file app/plug/controller/giftcontroller.php. The manipulation of …

Jan 16, 2024
CVE-2024-0519
8.8 HIGH KEV

Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted …

Jan 16, 2024
CVE-2024-0518
8.8 HIGH

Type confusion in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Jan 16, 2024
CVE-2024-0517
8.8 HIGH

Out of bounds write in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

Jan 16, 2024
CVE-2023-21901
7.4 HIGH

Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 8.0.7, 8.0.8, …

Jan 16, 2024
CVE-2023-6336
7.2 HIGH

Improper Link Resolution Before File Access ('Link Following') vulnerability in HYPR Workforce Access on MacOS allows User-Controlled Filename.This issue affects Workforce Access: before 8.7.

Jan 16, 2024
CVE-2023-5097
7.0 HIGH

Improper Input Validation vulnerability in HYPR Workforce Access on Windows allows Path Traversal.This issue affects Workforce Access: before 8.7.

Jan 16, 2024
CVE-2024-0200
7.2 HIGH

An unsafe reflection vulnerability was identified in GitHub Enterprise Server that could lead to reflection injection. This vulnerability could lead to the execution of user-controlled …

Jan 16, 2024
CVE-2024-23347
7.8 HIGH

Prior to v176, when opening a new project Meta Spark Studio would execute scripts defined inside of a package.json file included as part of that …

Jan 16, 2024
CVE-2024-22628
7.2 HIGH

Budget and Expense Tracker System v1.0 is vulnerable to SQL Injection via /expense_budget/admin/?page=reports/budget&date_start=2023-12-28&date_end=

Jan 16, 2024
CVE-2024-22627
7.2 HIGH

Complete Supplier Management System v1.0 is vulnerable to SQL Injection via /Supply_Management_System/admin/edit_distributor.php?id=.

Jan 16, 2024
CVE-2024-22626
7.2 HIGH

Complete Supplier Management System v1.0 is vulnerable to SQL Injection via /Supply_Management_System/admin/edit_retailer.php?id=.

Jan 16, 2024
CVE-2024-22625
7.2 HIGH

Complete Supplier Management System v1.0 is vulnerable to SQL Injection via /Supply_Management_System/admin/edit_category.php?id=.

Jan 16, 2024
CVE-2023-22514
7.8 HIGH

This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.14 of Sourcetree for Mac and Sourcetree for Windows. This RCE (Remote Code …

Jan 16, 2024
CVE-2023-22512
7.5 HIGH

This High severity DoS (Denial of Service) vulnerability was introduced in version 5.6.0 of Confluence Data Center and Server. With a CVSS Score of 7.5, …

Jan 16, 2024
CVE-2024-0578
8.8 HIGH

A vulnerability classified as critical has been found in Totolink LR1200GB 9.1.0u.6619_B20230130. Affected is the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi. The manipulation of the …

Jan 16, 2024
CVE-2024-0577
8.8 HIGH

A vulnerability was found in Totolink LR1200GB 9.1.0u.6619_B20230130. It has been rated as critical. This issue affects the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi. The …

Jan 16, 2024
CVE-2024-0576
8.8 HIGH

A vulnerability was found in Totolink LR1200GB 9.1.0u.6619_B20230130. It has been declared as critical. This vulnerability affects the function setIpPortFilterRules of the file /cgi-bin/cstecgi.cgi. The …

Jan 16, 2024
CVE-2023-6373
8.8 HIGH

The ArtPlacer Widget WordPress plugin before 2.20.7 does not sanitize and escape the "id" parameter before submitting the query, leading to a SQLI exploitable by …

Jan 16, 2024
CVE-2023-5922
7.5 HIGH

The Royal Elementor Addons and Templates WordPress plugin before 1.3.81 does not ensure that users accessing posts via an AJAX action (and REST endpoint, currently …

Jan 16, 2024
CVE-2023-4797
7.2 HIGH

The Newsletters WordPress plugin before 4.9.3 does not properly escape user-controlled parameters when they are appended to SQL queries and shell commands, which could enable …

Jan 16, 2024
CVE-2023-4703
7.5 HIGH

The All in One B2B for WooCommerce WordPress plugin through 1.0.3 does not properly validate parameters when updating user details, allowing an unauthenticated attacker to …

Jan 16, 2024
CVE-2023-4536
8.8 HIGH

The My Account Page Editor WordPress plugin before 1.3.2 does not validate the profile picture to be uploaded, allowing any authenticated users, such as subscriber …

Jan 16, 2024
CVE-2023-45235
8.3 HIGH

EDK2's Network Package is susceptible to a buffer overflow vulnerability when handling Server ID option from a DHCPv6 proxy Advertise message. This vulnerability can be …

Jan 16, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.