CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-1767
6.4 MEDIUM

The Blocksy theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocks in all versions up to, and including, 2.0.26 due to …

Mar 9, 2024
CVE-2024-1320
6.5 MEDIUM

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'offline_status' parameter in all versions up …

Mar 9, 2024
CVE-2024-1125
5.4 MEDIUM

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on …

Mar 9, 2024
CVE-2024-1124
4.3 MEDIUM

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized email sending due to a missing capability check on the …

Mar 9, 2024
CVE-2024-1123
6.5 MEDIUM

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

Mar 9, 2024
CVE-2024-28180
4.3 MEDIUM

Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards. An attacker could send a JWE containing compressed …

Mar 9, 2024
CVE-2024-28176
4.9 MEDIUM

jose is JavaScript module for JSON Object Signing and Encryption, providing support for JSON Web Tokens (JWT), JSON Web Signature (JWS), JSON Web Encryption (JWE), …

Mar 9, 2024
CVE-2024-28122
6.8 MEDIUM

JWX is Go module implementing various JWx (JWA/JWE/JWK/JWS/JWT, otherwise known as JOSE) technologies. This vulnerability allows an attacker with a trusted public key to cause …

Mar 9, 2024
CVE-2024-28753
6.5 MEDIUM

RaspAP (aka raspap-webgui) through 3.0.9 allows remote attackers to read the /etc/passwd file via a crafted request.

Mar 9, 2024
CVE-2023-32264
5.8 MEDIUM

CWE-1385 vulnerability in OpenText Documentum D2 affecting versions16.5.1 to CE 23.2. The vulnerability could allow upload arbitrary code and execute it on the client's computer.

Mar 8, 2024
CVE-2022-43855
6.2 MEDIUM

IBM SPSS Statistics 26.0, 27.0.1, and 28.0 IO Module could allow a local user to create multiple files that could exhaust the file handles capacity …

Mar 8, 2024
CVE-2024-21901
4.7 MEDIUM

A SQL injection vulnerability has been reported to affect myQNAPcloud. If exploited, the vulnerability could allow authenticated administrators to inject malicious code via a network. …

Mar 8, 2024
CVE-2024-21900
4.3 MEDIUM

An injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute commands via …

Mar 8, 2024
CVE-2023-47221
5.5 MEDIUM

A path traversal vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow authenticated administrators to read the contents of unexpected …

Mar 8, 2024
CVE-2023-34980
5.9 MEDIUM

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute …

Mar 8, 2024
CVE-2023-32969
4.9 MEDIUM

A cross-site scripting (XSS) vulnerability has been reported to affect Network & Virtual Switch. If exploited, the vulnerability could allow authenticated administrators to inject malicious …

Mar 8, 2024
CVE-2024-2319
5.4 MEDIUM

Cross-Site Scripting (XSS) vulnerability in the Django MarkdownX project, affecting version 4.0.2. An attacker could store a specially crafted JavaScript payload in the upload functionality …

Mar 8, 2024
CVE-2024-2318
4.3 MEDIUM

A vulnerability was found in ZKTeco ZKBio Media 2.0.0_x64_2024-01-29-1028. It has been classified as problematic. Affected is an unknown function of the file /pro/common/download of …

Mar 8, 2024
CVE-2024-2316
4.3 MEDIUM

A vulnerability has been found in Bdtask Hospital AutoManager up to 20240227 and classified as problematic. This vulnerability affects unknown code of the file /billing/bill/edit/ …

Mar 8, 2024
CVE-2024-2298
4.3 MEDIUM

The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the atkp_import_product() function in …

Mar 8, 2024
CVE-2024-1851
6.3 MEDIUM

The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the atkp_create_list() function in …

Mar 8, 2024
CVE-2024-27612
6.2 MEDIUM

Numbas editor before 7.3 mishandles editing of themes and extensions.

Mar 8, 2024
CVE-2024-1987
6.4 MEDIUM

The WP-Members Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.4.9.1 …

Mar 8, 2024
CVE-2024-2283
6.3 MEDIUM

A vulnerability classified as critical has been found in boyiddha Automated-Mess-Management-System 1.0. Affected is an unknown function of the file /member/view.php. The manipulation of the …

Mar 8, 2024
CVE-2024-2281
6.3 MEDIUM

A vulnerability was found in boyiddha Automated-Mess-Management-System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/index.php of the …

Mar 8, 2024
CVE-2024-2277
4.3 MEDIUM

A vulnerability was found in Bdtask G-Prescription Gynaecology & OBS Consultation Software 1.0 and classified as problematic. Affected by this issue is some unknown functionality …

Mar 8, 2024
CVE-2024-26309
5.3 MEDIUM

Archer Platform 6.x before 6.14 P2 HF2 (6.14.0.2.2) contains a sensitive information disclosure vulnerability. An unauthenticated attacker could potentially obtain access to sensitive information via …

Mar 8, 2024
CVE-2024-25848
5.9 MEDIUM

In the module "Ever Ultimate SEO" (everpsseo) <= 8.1.2 from Team Ever for PrestaShop, a guest can perform SQL injection in affected versions.

Mar 8, 2024
CVE-2024-23297
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in iOS 17.4 and iPadOS 17.4, tvOS 17.4, watchOS 10.4. A malicious application may …

Mar 8, 2024
CVE-2024-23295
5.5 MEDIUM

A permissions issue was addressed to help ensure Personas are always protected. This issue is fixed in visionOS 1.1. An unauthenticated user may be able …

Mar 8, 2024
CVE-2024-23293
4.6 MEDIUM

This issue was addressed through improved state management. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. …

Mar 8, 2024
CVE-2024-23290
5.5 MEDIUM

A logic issue was addressed with improved restrictions. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. …

Mar 8, 2024
CVE-2024-23287
5.5 MEDIUM

A privacy issue was addressed with improved handling of temporary files. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, watchOS …

Mar 8, 2024
CVE-2024-23285
5.5 MEDIUM

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sonoma 14.4. An app may be able to create symlinks …

Mar 8, 2024
CVE-2024-23284
6.5 MEDIUM

A logic issue was addressed with improved state management. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS …

Mar 8, 2024
CVE-2024-23283
5.5 MEDIUM

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, macOS Monterey …

Mar 8, 2024
CVE-2024-23281
5.5 MEDIUM

This issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.4. An app may be able to access sensitive user …

Mar 8, 2024
CVE-2024-23280
6.5 MEDIUM

An injection issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, …

Mar 8, 2024
CVE-2024-23279
5.5 MEDIUM

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma 14.4. An app may be …

Mar 8, 2024
CVE-2024-23277
5.9 MEDIUM

The issue was addressed with improved checks. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. An attacker in a privileged …

Mar 8, 2024
CVE-2024-23275
4.7 MEDIUM

A race condition was addressed with additional validation. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may …

Mar 8, 2024
CVE-2024-23273
4.3 MEDIUM

This issue was addressed through improved state management. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. Private Browsing …

Mar 8, 2024
CVE-2024-23272
5.5 MEDIUM

A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An attacker may …

Mar 8, 2024
CVE-2024-23269
5.5 MEDIUM

A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS …

Mar 8, 2024
CVE-2024-23267
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be …

Mar 8, 2024
CVE-2024-23266
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be …

Mar 8, 2024
CVE-2024-23264
5.5 MEDIUM

A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS …

Mar 8, 2024
CVE-2024-23263
6.5 MEDIUM

A logic issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, …

Mar 8, 2024
CVE-2024-23260
5.5 MEDIUM

This issue was addressed by removing additional entitlements. This issue is fixed in macOS Sonoma 14.4. An app may be able to access user-sensitive data.

Mar 8, 2024
CVE-2024-23259
6.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. …

Mar 8, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.