CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-28216
5.4 MEDIUM

nGrinder before 3.5.9 allows an attacker to obtain the results of webhook requests due to lack of access control, which could be the cause of …

Mar 7, 2024
CVE-2024-1761
6.4 MEDIUM

The WP Chat App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget/block in all versions up to, and including, 3.6.1 …

Mar 7, 2024
CVE-2024-1460
5.6 MEDIUM

MSI Afterburner v4.6.5.16370 is vulnerable to a Kernel Memory Leak vulnerability by triggering the 0x80002040 IOCTL code of the RTCore64.sys driver. The handle to the …

Mar 7, 2024
CVE-2024-1443
4.4 MEDIUM

MSI Afterburner v4.6.5.16370 is vulnerable to a Denial of Service vulnerability by triggering the 0x80002000 IOCTL code of the RTCore64.sys driver. The handle to the …

Mar 7, 2024
CVE-2024-24389
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in XunRuiCMS up to v4.6.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into …

Mar 7, 2024
CVE-2022-46089
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in the add-airline form of Online Flight Booking Management System v1.0 allows attackers to execute arbitrary web scripts or HTML …

Mar 7, 2024
CVE-2024-1299
6.5 MEDIUM

A privilege escalation vulnerability was discovered in GitLab affecting versions 16.8 prior to 16.8.4 and 16.9 prior to 16.9.2. It was possible for a user …

Mar 7, 2024
CVE-2023-51281
5.4 MEDIUM

Cross Site Scripting vulnerability in Customer Support System v.1.0 allows a remote attacker to escalate privileges via a crafted script firstname, "lastname", "middlename", "contact" and …

Mar 7, 2024
CVE-2023-49987
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability in the component /management/term of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via …

Mar 7, 2024
CVE-2023-49986
4.7 MEDIUM

A cross-site scripting (XSS) vulnerability in the component /admin/parent of School Fees Management System 1.0 allow attackers to execute arbitrary web scripts or HTML via …

Mar 7, 2024
CVE-2024-2236
5.9 MEDIUM

A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead …

Mar 6, 2024
CVE-2024-28111
6.5 MEDIUM

Canarytokens helps track activity and actions on a network. Canarytokens.org supports exporting the history of a Canarytoken's incidents in CSV format. The generation of these …

Mar 6, 2024
CVE-2024-27915
6.8 MEDIUM

Sulu is a PHP content management system. Starting in verson 2.2.0 and prior to version 2.4.17 and 2.5.13, access to pages is granted regardless of …

Mar 6, 2024
CVE-2024-27288
6.3 MEDIUM

1Panel is an open source Linux server operation and maintenance management panel. Prior to version 1.10.1-lts, users can use Burp to obtain unauthorized access to …

Mar 6, 2024
CVE-2024-27287
6.5 MEDIUM

ESPHome is a system to control your ESP8266/ESP32 for Home Automation systems. Starting in version 2023.12.9 and prior to version 2024.2.2, editing the configuration file …

Mar 6, 2024
CVE-2024-24766
6.2 MEDIUM

CasaOS-UserService provides user management functionalities to CasaOS. Starting in version 0.4.4.3 and prior to version 0.4.7, the Casa OS Login page disclosed the username enumeration …

Mar 6, 2024
CVE-2023-50167
5.4 MEDIUM

Pega Platform from 7.1.7 to 23.1.1 is affected by an XSS issue with editing/rendering user html content.

Mar 6, 2024
CVE-2024-2215
6.1 MEDIUM

A cross-site request forgery (CSRF) vulnerability in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers to connect to an attacker-specified TCP or Unix socket URL, …

Mar 6, 2024
CVE-2024-28174
5.8 MEDIUM

In JetBrains TeamCity before 2023.11.4 presigned URL generation requests in S3 Artifact Storage plugin were authorized improperly

Mar 6, 2024
CVE-2024-28173
4.3 MEDIUM

In JetBrains TeamCity between 2023.11 and 2023.11.4 custom build parameters of the "password" type could be disclosed

Mar 6, 2024
CVE-2024-28162
4.2 MEDIUM

In Jenkins Delphix Plugin 3.0.1 through 3.1.0 (both inclusive) a global option for administrators to enable or disable SSL/TLS certificate validation for Data Control Tower …

Mar 6, 2024
CVE-2024-28161
5.3 MEDIUM

In Jenkins Delphix Plugin 3.0.1, a global option for administrators to enable or disable SSL/TLS certificate validation for Data Control Tower (DCT) connections is disabled …

Mar 6, 2024
CVE-2024-28159
4.3 MEDIUM

A missing permission check in Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier allows attackers with Item/Read permission to trigger a build.

Mar 6, 2024
CVE-2024-28158
4.3 MEDIUM

A cross-site request forgery (CSRF) vulnerability in Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier allows attackers to trigger a build.

Mar 6, 2024
CVE-2024-28156
5.4 MEDIUM

Jenkins Build Monitor View Plugin 1.14-860.vd06ef2568b_3f and earlier does not escape Build Monitor View names, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by …

Mar 6, 2024
CVE-2024-28155
4.3 MEDIUM

Jenkins AppSpider Plugin 1.0.16 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to obtain information about available …

Mar 6, 2024
CVE-2024-28154
6.5 MEDIUM

Jenkins MQ Notifier Plugin 1.4.0 and earlier logs potentially sensitive build parameters as part of debug information in build logs by default.

Mar 6, 2024
CVE-2024-28153
5.4 MEDIUM

Jenkins OWASP Dependency-Check Plugin 5.4.5 and earlier does not escape vulnerability metadata from Dependency-Check reports, resulting in a stored cross-site scripting (XSS) vulnerability.

Mar 6, 2024
CVE-2024-28152
6.3 MEDIUM

In Jenkins Bitbucket Branch Source Plugin 866.vdea_7dcd3008e and earlier, except 848.850.v6a_a_2a_234a_c81, when discovering pull requests from forks, the trust policy "Forks in the same account" …

Mar 6, 2024
CVE-2024-28151
4.3 MEDIUM

Jenkins HTML Publisher Plugin 1.32 and earlier archives invalid symbolic links in report directories on agents and recreates them on the controller, allowing attackers with …

Mar 6, 2024
CVE-2024-28150
4.7 MEDIUM

Jenkins HTML Publisher Plugin 1.32 and earlier does not escape job names, report names, and index page titles shown as part of the report frame, …

Mar 6, 2024
CVE-2024-28149
6.5 MEDIUM

Jenkins HTML Publisher Plugin 1.16 through 1.32 (both inclusive) does not properly sanitize input, allowing attackers with Item/Configure permission to implement cross-site scripting (XSS) attacks …

Mar 6, 2024
CVE-2024-20346
5.4 MEDIUM

A vulnerability in the web-based management interface of Cisco AppDynamics Controller could allow an authenticated, remote attacker to perform a reflected cross-site scripting (XSS) attack …

Mar 6, 2024
CVE-2024-20345
6.5 MEDIUM

A vulnerability in the file upload functionality of Cisco AppDynamics Controller could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected …

Mar 6, 2024
CVE-2024-20336
6.5 MEDIUM

A vulnerability in the web-based user interface of Cisco Small Business 100, 300, and 500 Series Wireless APs could allow an authenticated, remote attacker to …

Mar 6, 2024
CVE-2024-20335
6.5 MEDIUM

A vulnerability in the web-based management interface of Cisco Small Business 100, 300, and 500 Series Wireless APs could allow an authenticated, remote attacker to …

Mar 6, 2024
CVE-2024-20301
6.2 MEDIUM

A vulnerability in Cisco Duo Authentication for Windows Logon and RDP could allow an authenticated, physical attacker to bypass secondary authentication and access an affected …

Mar 6, 2024
CVE-2024-20292
4.4 MEDIUM

A vulnerability in the logging component of Cisco Duo Authentication for Windows Logon and RDP could allow an authenticated, local attacker to view sensitive information …

Mar 6, 2024
CVE-2023-50740
5.3 MEDIUM

In Apache Linkis <=1.4.0, The password is printed to the log when using the Oracle data source of the Linkis data source module. We recommend …

Mar 6, 2024
CVE-2024-25103
6.3 MEDIUM

This vulnerability exists in AppSamvid software due to the usage of vulnerable and outdated components. An attacker with local administrative privileges could exploit this by …

Mar 6, 2024
CVE-2024-2211
4.6 MEDIUM

Cross-Site Scripting stored vulnerability in Gophish affecting version 0.12.1. This vulnerability could allow an attacker to store a malicious JavaScript payload in the campaign menu …

Mar 6, 2024
CVE-2024-26627
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: core: Move scsi_host_busy() out of host lock for waking up EH handler Inside scsi_eh_wakeup(), …

Mar 6, 2024
CVE-2024-26626
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ipmr: fix kernel panic when forwarding mcast packets The stacktrace was: [ 86.305548] BUG: kernel …

Mar 6, 2024
CVE-2024-26623
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: pds_core: Prevent race issues involving the adminq There are multiple paths that can result in …

Mar 6, 2024
CVE-2023-52607
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: powerpc/mm: Fix null-pointer dereference in pgtable_cache_add kasprintf() returns a pointer to dynamically allocated memory which …

Mar 6, 2024
CVE-2023-52606
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: powerpc/lib: Validate size for vector operations Some of the fp/vmx code in sstep.c assume a …

Mar 6, 2024
CVE-2023-52597
4.0 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KVM: s390: fix setting of fpc register kvm_arch_vcpu_ioctl_set_fpu() allows to set the floating point control …

Mar 6, 2024
CVE-2023-52596
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sysctl: Fix out of bounds access for empty sysctl registers When registering tables to the …

Mar 6, 2024
CVE-2023-52595
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: rt2x00: restart beacon queue when hardware reset When a hardware reset is triggered, all …

Mar 6, 2024
CVE-2023-52593
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: wfx: fix possible NULL pointer dereference in wfx_set_mfp_ap() Since 'ieee80211_beacon_get()' can return NULL, 'wfx_set_mfp_ap()' …

Mar 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.