CVE Database

4811+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-27307
3.8 LOW

Improper buffer restrictions in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable information disclosure via …

Feb 14, 2024
CVE-2023-27303
3.8 LOW

Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable information disclosure via …

Feb 14, 2024
CVE-2023-27300
3.8 LOW

Improper buffer restrictions in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable information disclosure via …

Feb 14, 2024
CVE-2023-26596
2.5 LOW

Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable denial of service …

Feb 14, 2024
CVE-2023-26592
3.8 LOW

Deserialization of untrusted data in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable a denial …

Feb 14, 2024
CVE-2023-26591
2.0 LOW

Unchecked return value in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an unauthenticated user to potentially enable denial of service …

Feb 14, 2024
CVE-2023-20570
3.3 LOW

Insufficient verification of data authenticity in the configuration state machine may allow a local attacker to potentially load arbitrary bitstreams.

Feb 13, 2024
CVE-2024-23801
3.3 LOW

A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions), Tecnomatix Plant Simulation V2302 (All versions < V2302.0007). The affected applications contain a …

Feb 13, 2024
CVE-2024-23800
3.3 LOW

A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions), Tecnomatix Plant Simulation V2302 (All versions < V2302.0007). The affected applications contain a …

Feb 13, 2024
CVE-2024-23799
3.3 LOW

A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions), Tecnomatix Plant Simulation V2302 (All versions < V2302.0007). The affected applications contain a …

Feb 13, 2024
CVE-2024-22043
3.3 LOW

A vulnerability has been identified in Parasolid V35.0 (All versions < V35.0.251), Parasolid V35.1 (All versions < V35.1.170). The affected applications contain a null pointer …

Feb 13, 2024
CVE-2024-1454
3.4 LOW

The use-after-free vulnerability was found in the AuthentIC driver in OpenSC packages, occuring in the card enrolment process using pkcs15-init when a user or administrator …

Feb 12, 2024
CVE-2024-23760
2.7 LOW

Cleartext Storage of Sensitive Information in Gambio 4.9.2.0 allows attackers to obtain sensitive information via error-handler.log.json and legacy-error-handler.log.txt under the webroot.

Feb 12, 2024
CVE-2021-4437
3.5 LOW

A vulnerability, which was classified as problematic, has been found in dbartholomae lambda-middleware frameguard up to 1.0.4. Affected by this issue is some unknown functionality …

Feb 12, 2024
CVE-2024-22226
3.3 LOW

Dell Unity, versions prior to 5.4, contain a path traversal vulnerability in its svc_supportassist utility. An authenticated attacker could potentially exploit this vulnerability, to gain …

Feb 12, 2024
CVE-2024-1433
3.1 LOW

A vulnerability, which was classified as problematic, was found in KDE Plasma Workspace up to 5.93.0. This affects the function EventPluginsManager::enabledPlugins of the file components/calendar/eventpluginsmanager.cpp …

Feb 11, 2024
CVE-2023-45718
3.9 LOW

Sametime is impacted by a failure to invalidate sessions. The application is setting sensitive cookie values in a persistent manner in Sametime Web clients. When …

Feb 9, 2024
CVE-2023-45716
1.7 LOW

Sametime is impacted by sensitive information passed in URL.

Feb 9, 2024
CVE-2024-1246
2.0 LOW

Concrete CMS in version 9 before 9.2.5 is vulnerable to reflected XSS via the Image URL Import Feature due to insufficient validation of administrator provided …

Feb 9, 2024
CVE-2024-1245
2.4 LOW

Concrete CMS version 9 before 9.2.5 is vulnerable to stored XSS in file tags and description attributes since administrator entered file attributes are not sufficiently …

Feb 9, 2024
CVE-2024-1247
2.0 LOW

Concrete CMS version 9 before 9.2.5 is vulnerable to stored XSS via the Role Name field since there is insufficient validation of administrator provided data …

Feb 9, 2024
CVE-2024-24776
3.1 LOW

Mattermost fails to check the required permissions in the POST /api/v4/channels/stats/member_count API resulting in channel member counts being leaked to a user without permissions.

Feb 9, 2024
CVE-2024-24774
3.4 LOW

Mattermost Jira Plugin handling subscriptions fails to check the security level of an incoming issue or limit it based on the user who created the …

Feb 9, 2024
CVE-2024-23319
3.5 LOW

Mattermost Jira Plugin fails to protect against logout CSRF allowing an attacker to post a specially crafted message that would disconnect a user's Jira connection …

Feb 9, 2024
CVE-2024-0628
3.8 LOW

The WP RSS Aggregator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.23.5 via the RSS feed …

Feb 7, 2024
CVE-2024-1269
2.4 LOW

A vulnerability has been found in SourceCodester Product Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /supplier.php. The …

Feb 7, 2024
CVE-2024-1267
3.5 LOW

A vulnerability, which was classified as problematic, has been found in CodeAstro Restaurant POS System 1.0. Affected by this issue is some unknown functionality of …

Feb 7, 2024
CVE-2024-1266
2.4 LOW

A vulnerability classified as problematic was found in CodeAstro University Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /st_reg.php …

Feb 7, 2024
CVE-2024-1265
2.4 LOW

A vulnerability classified as problematic has been found in CodeAstro University Management System 1.0. Affected is an unknown function of the file /att_add.php of the …

Feb 7, 2024
CVE-2024-1258
3.1 LOW

A vulnerability was found in Juanpao JPShop up to 1.5.02. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of …

Feb 6, 2024
CVE-2024-1257
3.5 LOW

A vulnerability was found in Jspxcms 10.2.0. It has been classified as problematic. Affected is an unknown function of the file /ext/collect/find_text.do. The manipulation leads …

Feb 6, 2024
CVE-2024-1256
3.5 LOW

A vulnerability was found in Jspxcms 10.2.0 and classified as problematic. This issue affects some unknown processing of the file /ext/collect/filter_text.do. The manipulation leads to …

Feb 6, 2024
CVE-2024-1048
3.3 LOW

A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CVE-2019-14865, grub2-set-bootflag will create a temporary file with the new grubenv …

Feb 6, 2024
CVE-2024-24940
2.8 LOW

In JetBrains IntelliJ IDEA before 2023.3.3 path traversal was possible when unpacking archives

Feb 6, 2024
CVE-2024-24939
3.3 LOW

In JetBrains Rider before 2023.3.3 logging of environment variables containing secret values was possible

Feb 6, 2024
CVE-2024-20828
2.4 LOW

Improper authorization verification vulnerability in Samsung Internet prior to version 24.0 allows physical attackers to access files downloaded in SecretMode without proper authentication.

Feb 6, 2024
CVE-2024-20810
3.3 LOW

Implicit intent hijacking vulnerability in Smart Suggestions prior to SMR Feb-2024 Release 1 allows local attackers to get sensitive information.

Feb 6, 2024
CVE-2024-1075
3.7 LOW

The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to maintenance mode bypass and information disclosure in all versions up to, …

Feb 5, 2024
CVE-2024-24807
2.7 LOW

Sulu is a highly extensible open-source PHP content management system based on the Symfony framework. There is an issue when inputting HTML into the Tag …

Feb 5, 2024
CVE-2024-24559
3.7 LOW

Vyper is a Pythonic Smart Contract Language for the EVM. There is an error in the stack management when compiling the `IR` for `sha3_64`. Concretely, …

Feb 5, 2024
CVE-2024-24861
3.3 LOW

A race condition was found in the Linux kernel's media/xc4000 device driver in xc4000 xc4000_get_frequency() function. This can result in return value overflow issue, possibly …

Feb 5, 2024
CVE-2015-10129
3.7 LOW

A vulnerability was found in planet-freo up to 20150116 and classified as problematic. Affected by this issue is some unknown functionality of the file admin/inc/auth.inc.php. …

Feb 4, 2024
CVE-2024-1215
3.5 LOW

A vulnerability was found in SourceCodester CRUD without Page Reload 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality …

Feb 3, 2024
CVE-2024-23553
3.0 LOW

A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform exists due to missing a specific http header attribute.

Feb 2, 2024
CVE-2024-1194
3.3 LOW

A vulnerability classified as problematic has been found in Armcode AlienIP 2.41. Affected is an unknown function of the component Locate Host Handler. The manipulation …

Feb 2, 2024
CVE-2024-1193
3.3 LOW

A vulnerability was found in Navicat 12.0.29. It has been rated as problematic. This issue affects some unknown processing of the component MySQL Conecction Handler. …

Feb 2, 2024
CVE-2024-1190
3.3 LOW

A vulnerability was found in Global Scape CuteFTP 9.3.0.3 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation of the …

Feb 2, 2024
CVE-2024-1188
3.3 LOW

A vulnerability, which was classified as problematic, was found in Rizone Soft Notepad3 1.0.2.350. Affected is an unknown function of the component Encryption Passphrase Handler. …

Feb 2, 2024
CVE-2024-1187
3.3 LOW

A vulnerability, which was classified as problematic, has been found in Munsoft Easy Outlook Express Recovery 2.0. This issue affects some unknown processing of the …

Feb 2, 2024
CVE-2024-24560
3.7 LOW

Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine. When calls to external contracts are made, we write the input buffer starting …

Feb 2, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.