CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-52590
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ocfs2: Avoid touching renamed directory if parent does not change The VFS will not be …

Mar 6, 2024
CVE-2023-52589
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: rkisp1: Fix IRQ disable race issue In rkisp1_isp_stop() and rkisp1_csi_disable() the driver masks the …

Mar 6, 2024
CVE-2023-52587
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: IB/ipoib: Fix mcast list locking Releasing the `priv->lock` while iterating the `priv->multicast_list` in `ipoib_mcast_join_task()` opens …

Mar 6, 2024
CVE-2023-52585
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix possible NULL dereference in amdgpu_ras_query_error_status_helper() Return invalid error code -EINVAL for invalid block …

Mar 6, 2024
CVE-2023-52583
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ceph: fix deadlock or deadcode of misusing dget() The lock order is incorrect between denty …

Mar 6, 2024
CVE-2024-1989
6.4 MEDIUM

The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Sassy_Social_Share' shortcode in all versions …

Mar 6, 2024
CVE-2024-1771
4.3 MEDIUM

The Total theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the total_order_sections() function in all versions …

Mar 6, 2024
CVE-2024-1760
4.3 MEDIUM

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and …

Mar 6, 2024
CVE-2023-49977
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into …

Mar 6, 2024
CVE-2023-49976
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into …

Mar 6, 2024
CVE-2023-49974
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into …

Mar 6, 2024
CVE-2023-49973
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into …

Mar 6, 2024
CVE-2023-49971
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into …

Mar 6, 2024
CVE-2024-27278
5.4 MEDIUM

OpenPNE Plugin "opTimelinePlugin" 1.2.11 and earlier contains a cross-site scripting vulnerability. On the site which uses the affected product, when a user configures the profile …

Mar 6, 2024
CVE-2024-24785
5.4 MEDIUM

If errors returned from MarshalJSON methods contain user controlled data, they may be used to break the contextual auto-escaping behavior of the html/template package, allowing …

Mar 5, 2024
CVE-2024-24783
5.9 MEDIUM

Verifying a certificate chain which contains a certificate with an unknown public key algorithm will cause Certificate.Verify to panic. This affects all crypto/tls clients, and …

Mar 5, 2024
CVE-2023-48644
6.1 MEDIUM

An issue was discovered in the Archibus app 4.0.3 for iOS. There is an XSS vulnerability in the create work request feature of the maintenance …

Mar 5, 2024
CVE-2023-45290
6.5 MEDIUM

When parsing a multipart form (either explicitly with Request.ParseMultipartForm or implicitly with Request.FormValue, Request.PostFormValue, or Request.FormFile), limits on the total size of the parsed form …

Mar 5, 2024
CVE-2023-45289
4.3 MEDIUM

When following an HTTP redirect to a domain which is not a subdomain match or exact match of the initial domain, an http.Client does not …

Mar 5, 2024
CVE-2024-1901
4.3 MEDIUM

Denial of service in PAM password rotation during the check-in process in Devolutions Server 2023.3.14.0 allows an authenticated user with specific PAM permissions to make …

Mar 5, 2024
CVE-2024-1900
5.5 MEDIUM

Improper session management in the identity provider authentication flow in Devolutions Server 2023.3.14.0 and earlier allows an authenticated user via an identity provider to stay …

Mar 5, 2024
CVE-2024-1898
4.3 MEDIUM

Improper access control in the notification feature in Devolutions Server 2023.3.14.0 and earlier allows a low privileged user to change notifications settings configured by an …

Mar 5, 2024
CVE-2024-25615
5.3 MEDIUM

An unauthenticated Denial-of-Service (DoS) vulnerability exists in the Spectrum service accessed via the PAPI protocol in ArubaOS 8.x. Successful exploitation of this vulnerability results in …

Mar 5, 2024
CVE-2024-25614
5.5 MEDIUM

There is an arbitrary file deletion vulnerability in the CLI used by ArubaOS. Successful exploitation of this vulnerability results in the ability to delete arbitrary …

Mar 5, 2024
CVE-2023-26282
4.2 MEDIUM

IBM Watson CP4D Data Stores 4.6.0 through 4.6.3 could allow a user with physical access and specific knowledge of the system to modify files or …

Mar 5, 2024
CVE-2023-25681
5.3 MEDIUM

LDAP users on IBM Spectrum Virtualize 8.5 which are configured to require multifactor authentication can still authenticate to the CIM interface using only username and …

Mar 5, 2024
CVE-2022-22399
5.4 MEDIUM

IBM Aspera Faspex 5.0.0 and 5.0.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow …

Mar 5, 2024
CVE-2024-27931
5.8 MEDIUM

Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. Insufficient validation of parameters in `Deno.makeTemp*` APIs would allow for creation of files outside …

Mar 5, 2024
CVE-2024-27564
5.8 MEDIUM

pictureproxy.php in the dirk1983 mm1.ltd source code f9f4bbc allows SSRF via the url parameter. NOTE: the references section has an archived copy of pictureproxy.php from …

Mar 5, 2024
CVE-2024-27563
5.3 MEDIUM

A Server-Side Request Forgery (SSRF) in the getFileFromRepo function of WonderCMS v3.1.3 allows attackers to force the application to make arbitrary requests via injection of …

Mar 5, 2024
CVE-2022-46088
6.1 MEDIUM

Online Flight Booking Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the feedback form.

Mar 5, 2024
CVE-2024-27627
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability exists in SuperCali version 1.1.0, allowing remote attackers to execute arbitrary JavaScript code via the email parameter in the …

Mar 5, 2024
CVE-2024-27625
4.8 MEDIUM

CMS Made Simple Version 2.2.19 is vulnerable to Cross Site Scripting (XSS). This vulnerability resides in the File Manager module of the admin panel. Specifically, …

Mar 5, 2024
CVE-2024-27623
5.9 MEDIUM

CMS Made Simple version 2.2.19 is vulnerable to Server-Side Template Injection (SSTI). The vulnerability exists within the Design Manager, particularly when editing the Breadcrumbs.

Mar 5, 2024
CVE-2024-2188
6.1 MEDIUM

Cross-Site Scripting (XSS) vulnerability stored in TP-Link Archer AX50 affecting firmware version 1.0.11 build 2022052. This vulnerability could allow an unauthenticated attacker to create a …

Mar 5, 2024
CVE-2023-45600
5.6 MEDIUM

A CWE-613 “Insufficient Session Expiration” vulnerability in the web application, due to the session cookie “sessionid” lasting two weeks, facilitates session hijacking attacks against victims. …

Mar 5, 2024
CVE-2023-45599
5.5 MEDIUM

A CWE-646 “Reliance on File Name or Extension of Externally-Supplied File” vulnerability in the “iec61850” functionality of the web application allows a remote authenticated attacker …

Mar 5, 2024
CVE-2023-45598
5.3 MEDIUM

A CWE-425 “Direct Request ('Forced Browsing')” vulnerability in the “measure” functionality of the web application allows a remote unauthenticated attacker to access confidential measure information. …

Mar 5, 2024
CVE-2023-45597
5.9 MEDIUM

A CWE-1236 “Improper Neutralization of Formula Elements in a CSV File” vulnerability in the “file_configuration” functionality of the web application (concerning the function “export_file”) allows …

Mar 5, 2024
CVE-2023-45596
5.3 MEDIUM

A CWE-425 “Direct Request ('Forced Browsing')” vulnerability in the “file_configuration” functionality of the web application allows a remote unauthenticated attacker to access confidential configuration files. …

Mar 5, 2024
CVE-2023-45595
5.9 MEDIUM

A CWE-434 “Unrestricted Upload of File with Dangerous Type” vulnerability in the “file_configuration” functionality of the web application allows a remote authenticated attacker to upload …

Mar 5, 2024
CVE-2023-45594
6.8 MEDIUM

A CWE-552 “Files or Directories Accessible to External Parties” vulnerability in the embedded Chromium browser allows a physical attacker to arbitrarily download/upload files to/from the …

Mar 5, 2024
CVE-2023-45593
6.8 MEDIUM

A CWE-184 “Incomplete List of Disallowed Inputs” vulnerability in the embedded Chromium browser (concerning the handling of alternative URLs, other than “ http://localhost” ) allows …

Mar 5, 2024
CVE-2023-45592
6.8 MEDIUM

A CWE-250 “Execution with Unnecessary Privileges” vulnerability in the embedded Chromium browser (due to the binary being executed with the “--no-sandbox” option and with root …

Mar 5, 2024
CVE-2022-48630
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: crypto: qcom-rng - fix infinite loop on requests not multiple of WORD_SZ The commit referenced …

Mar 5, 2024
CVE-2022-48629
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: crypto: qcom-rng - ensure buffer for generate is completely filled The generate function in struct …

Mar 5, 2024
CVE-2024-26337
4.3 MEDIUM

swftools v0.9.2 was discovered to contain a segmentation violation via the function s_font at swftools/src/swfc.c.

Mar 5, 2024
CVE-2024-26335
5.5 MEDIUM

swftools v0.9.2 was discovered to contain a segmentation violation via the function state_free at swftools/src/swfc-history.c.

Mar 5, 2024
CVE-2024-26334
6.2 MEDIUM

swftools v0.9.2 was discovered to contain a segmentation violation via the function compileSWFActionCode at swftools/lib/action/actioncompiler.c.

Mar 5, 2024
CVE-2024-26333
5.5 MEDIUM

swftools v0.9.2 was discovered to contain a segmentation violation via the function free_lines at swftools/lib/modules/swfshape.c.

Mar 5, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.