CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-21430
5.7 MEDIUM

Windows USB Attached SCSI (UAS) Protocol Remote Code Execution Vulnerability

Mar 12, 2024
CVE-2024-21429
6.8 MEDIUM

Windows USB Hub Driver Remote Code Execution Vulnerability

Mar 12, 2024
CVE-2024-21408
5.5 MEDIUM

Windows Hyper-V Denial of Service Vulnerability

Mar 12, 2024
CVE-2024-20671
5.5 MEDIUM

Microsoft Defender Security Feature Bypass Vulnerability

Mar 12, 2024
CVE-2024-1304
6.3 MEDIUM

Cross-site scripting vulnerability in Badger Meter Monitool that affects versions up to 4.6.3 and earlier. This vulnerability allows a remote attacker to send a specially …

Mar 12, 2024
CVE-2024-1303
6.5 MEDIUM

Incorrectly limiting the path to a restricted directory vulnerability in Badger Meter Monitool that affects versions up to 4.6.3 and earlier. This vulnerability allows an …

Mar 12, 2024
CVE-2024-2394
4.7 MEDIUM

A vulnerability was found in SourceCodester Employee Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Mar 12, 2024
CVE-2024-21761
4.3 MEDIUM

An improper authorization vulnerability [CWE-285] in FortiPortal version 7.2.0, and versions 7.0.6 and below reports may allow a user to download other organizations reports via …

Mar 12, 2024
CVE-2024-1227
6.5 MEDIUM

An open redirect vulnerability, the exploitation of which could allow an attacker to create a custom URL and redirect a legitimate page to a malicious …

Mar 12, 2024
CVE-2023-41842
6.7 MEDIUM

A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allows a privileged attacker to execute unauthorized code or commands via specially crafted command …

Mar 12, 2024
CVE-2024-2393
6.3 MEDIUM

A vulnerability was found in SourceCodester CRUD without Page Reload 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Mar 12, 2024
CVE-2024-2049
6.5 MEDIUM

Server-Side Request Forgery (SSRF) in Citrix SD-WAN Standard/Premium Editions on or after 11.4.0 and before 11.4.4.46 allows an attacker to disclose limited information from the …

Mar 12, 2024
CVE-2024-21483
4.6 MEDIUM

A vulnerability has been identified in SENTRON 7KM PAC3120 AC/DC (7KM3120-0BA01-1DA0) (All versions >= V3.2.3 < V3.2.4 only when manufactured between LQN231003... and LQN231215... ( …

Mar 12, 2024
CVE-2023-45793
5.5 MEDIUM

A vulnerability has been identified in Siveillance Control (All versions >= V2.8 < V3.1.1). The affected product does not properly check the list of access …

Mar 12, 2024
CVE-2023-4731
4.3 MEDIUM

The LadiApp plugn for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the init_endpoint() function hooked via 'init' in …

Mar 12, 2024
CVE-2023-4729
4.3 MEDIUM

The LadiApp plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the publish_lp() function hooked via an AJAX …

Mar 12, 2024
CVE-2023-4728
4.3 MEDIUM

The LadiApp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the publish_lp() function hooked via an …

Mar 12, 2024
CVE-2023-4629
4.3 MEDIUM

The LadiApp plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the save_config() function in versions up to, …

Mar 12, 2024
CVE-2023-4628
4.3 MEDIUM

The LadiApp plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the ladiflow_save_hook() function in versions up to, …

Mar 12, 2024
CVE-2023-4627
4.3 MEDIUM

The LadiApp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_config() function in versions up …

Mar 12, 2024
CVE-2023-4626
4.3 MEDIUM

The LadiApp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ladiflow_save_hook() function in versions up …

Mar 12, 2024
CVE-2024-2371
6.2 MEDIUM

Information exposure vulnerability in Korenix JetI/O 6550 affecting firmware version F208 Build:0817. The SNMP protocol uses plaintext to transfer data, allowing an attacker to intercept …

Mar 12, 2024
CVE-2024-27279
6.5 MEDIUM

Directory traversal vulnerability exists in a-blog cms Ver.3.1.x series Ver.3.1.9 and earlier, Ver.3.0.x series Ver.3.0.30 and earlier, Ver.2.11.x series Ver.2.11.59 and earlier, Ver.2.10.x series Ver.2.10.51 …

Mar 12, 2024
CVE-2024-26005
4.8 MEDIUM

An unauthenticated remote attacker can gain service level privileges through an incomplete cleanup during service restart after a DoS.

Mar 12, 2024
CVE-2024-26000
5.9 MEDIUM

An unauthenticated remote attacker can read memory out of bounds due to improper input validation in the MQTT stack. The brute force attack is not …

Mar 12, 2024
CVE-2024-25997
5.3 MEDIUM

An unauthenticated remote attacker can perform a log injection due to improper input validation. Only a certain log file is affected.

Mar 12, 2024
CVE-2024-25996
5.3 MEDIUM

An unauthenticated remote attacker can perform a remote code execution due to an origin validation error. The access is limited to the service user.

Mar 12, 2024
CVE-2024-25994
5.3 MEDIUM

An unauthenticated remote attacker can upload a arbitrary script file due to improper input validation. The upload destination is fixed and is write only.

Mar 12, 2024
CVE-2024-1328
6.4 MEDIUM

The Newsletter2Go plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style’ parameter in all versions up to, and including, 4.0.14 due to …

Mar 12, 2024
CVE-2024-0906
5.3 MEDIUM

The f(x) Private Site plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.1 via the API. This …

Mar 12, 2024
CVE-2024-24964
6.3 MEDIUM

Improper access control vulnerability exists in the resident process of SKYSEA Client View versions from Ver.11.220 prior to Ver.19.2. If this vulnerability is exploited, an …

Mar 12, 2024
CVE-2024-21584
6.1 MEDIUM

Pleasanter 1.3.49.0 and earlier contains a cross-site scripting vulnerability. If an attacker tricks the user to access the product with a specially crafted URL and …

Mar 12, 2024
CVE-2023-49453
6.1 MEDIUM

Reflected cross-site scripting (XSS) vulnerability in Racktables v0.22.0 and before, allows local attackers to execute arbitrary code and obtain sensitive information via the search component …

Mar 12, 2024
CVE-2024-26521
4.8 MEDIUM

HTML Injection vulnerability in CE Phoenix v1.0.8.20 and before allows a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information via a …

Mar 12, 2024
CVE-2023-6814
5.6 MEDIUM

Insertion of Sensitive Information into Log File vulnerability in Hitachi Cosminexus Component Container allows local users to gain sensitive information.This issue affects Cosminexus Component Container: …

Mar 12, 2024
CVE-2024-28163
5.3 MEDIUM

Under certain conditions, Support Web Pages of SAP NetWeaver Process Integration (PI) - versions 7.50, allows an attacker to access information which would otherwise be …

Mar 12, 2024
CVE-2024-27902
5.4 MEDIUM

Applications based on SAP GUI for HTML in SAP NetWeaver AS ABAP - versions 7.89, 7.93, do not sufficiently encode user-controlled inputs, resulting in Cross-Site …

Mar 12, 2024
CVE-2024-27900
4.3 MEDIUM

Due to missing authorization check, attacker with business user account in SAP ABAP Platform - version 758, 795, can change the privacy setting of job …

Mar 12, 2024
CVE-2024-25645
5.3 MEDIUM

Under certain condition SAP NetWeaver (Enterprise Portal) - version 7.50 allows an attacker to access information which would otherwise be restricted causing low impact on …

Mar 12, 2024
CVE-2024-25644
5.3 MEDIUM

Under certain conditions SAP NetWeaver WSRM - version 7.50, allows an attacker to access information which would otherwise be restricted, causing low impact on Confidentiality …

Mar 12, 2024
CVE-2024-22133
4.6 MEDIUM

SAP Fiori Front End Server - version 605, allows altering of approver details on the read-only field when sending leave request information. This could lead …

Mar 12, 2024
CVE-2024-28120
6.5 MEDIUM

codeium-chrome is an open source code completion plugin for the chrome web browser. The service worker of the codeium-chrome extension doesn't check the sender when …

Mar 11, 2024
CVE-2024-27938
5.3 MEDIUM

Postal is an open source SMTP server. Postal versions less than 3.0.0 are vulnerable to SMTP Smuggling attacks which may allow incoming e-mails to be …

Mar 11, 2024
CVE-2024-27297
6.3 MEDIUM

Nix is a package manager for Linux and other Unix systems. A fixed-output derivations on Linux can send file descriptors to files in the Nix …

Mar 11, 2024
CVE-2024-25854
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in Sourcecodester Insurance Management System 1.0 allows attackers to run arbitrary code via the Subject and Description fields when submitting …

Mar 11, 2024
CVE-2024-1645
4.3 MEDIUM

The Mollie Forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the exportRegistrations function in all …

Mar 11, 2024
CVE-2024-1400
4.3 MEDIUM

The Mollie Forms plugin for WordPress is vulnerable to unauthorized post or page duplication due to a missing capability check on the duplicateForm function in …

Mar 11, 2024
CVE-2024-2357
6.5 MEDIUM

The Libreswan Project was notified of an issue causing libreswan to restart under some IKEv2 retransmit scenarios when a connection is configured to use PreSharedKeys …

Mar 11, 2024
CVE-2024-28198
4.6 MEDIUM

OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. By manually manipulating http requests when using the draw.io integration it …

Mar 11, 2024
CVE-2024-27237
5.5 MEDIUM

In wipe_ns_memory of nsmemwipe.c, there is a possible incorrect size calculation due to a logic error in the code. This could lead to local information …

Mar 11, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.