CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-52481
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: arm64: errata: Add Cortex-A520 speculative unprivileged load workaround Implement the workaround for ARM Cortex-A520 erratum …

Feb 29, 2024
CVE-2023-52478
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: HID: logitech-hidpp: Fix kernel crash on receiver USB disconnect hidpp_connect_event() has *four* time-of-check vs time-of-use …

Feb 29, 2024
CVE-2023-52477
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: hub: Guard against accesses to uninitialized BOS descriptors Many functions in drivers/usb/core/hub.c and drivers/usb/core/hub.h …

Feb 29, 2024
CVE-2023-52476
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: perf/x86/lbr: Filter vsyscall addresses We found that a panic can occur when a vsyscall is …

Feb 29, 2024
CVE-2023-47874
5.4 MEDIUM

Missing Authorization vulnerability in Perfmatters.This issue affects Perfmatters: from n/a through 2.1.6.

Feb 29, 2024
CVE-2024-1435
5.3 MEDIUM

Insertion of Sensitive Information Into Sent Data vulnerability in tainacan Tainacan tainacan.This issue affects Tainacan: from n/a through <= 0.20.6.

Feb 29, 2024
CVE-2024-1341
4.9 MEDIUM

The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's advanced_iframe shortcode in all versions up to, and including, 2024.1 …

Feb 29, 2024
CVE-2023-51696
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in СleanTalk - Anti-Spam Protection Spam protection, Anti-Spam, FireWall by CleanTalk.This issue affects Spam protection, Anti-Spam, FireWall by CleanTalk: from …

Feb 29, 2024
CVE-2023-51531
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Thrive Themes Thrive Automator.This issue affects Thrive Automator: from n/a through 1.17.

Feb 29, 2024
CVE-2023-51530
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in GS Plugins Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation.This issue affects Logo Slider …

Feb 29, 2024
CVE-2023-51529
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in HasThemes HT Mega – Absolute Addons For Elementor.This issue affects HT Mega – Absolute Addons For Elementor: from n/a …

Feb 29, 2024
CVE-2023-51528
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Senol Sahin AI Power: Complete AI Pack – Powered by GPT-4.This issue affects AI Power: Complete AI Pack – …

Feb 29, 2024
CVE-2024-0689
4.4 MEDIUM

The Custom Field Suite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a meta import in all versions up to, and including, 2.6.4 …

Feb 29, 2024
CVE-2021-39090
5.9 MEDIUM

IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.6.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable …

Feb 29, 2024
CVE-2023-51802
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in the Simple Student Attendance System v.1.0 allows a remote attacker to execute arbitrary code via a crafted payload to …

Feb 29, 2024
CVE-2023-51800
5.4 MEDIUM

Cross Site Scripting (XSS) vulnerability in School Fees Management System v.1.0 allows a remote attacker to execute arbitrary code via a crafted payload to the …

Feb 29, 2024
CVE-2023-38367
6.5 MEDIUM

IBM Cloud Pak Foundational Services Identity Provider (idP) API (IBM Cloud Pak for Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, …

Feb 29, 2024
CVE-2023-27545
4.0 MEDIUM

IBM Watson CloudPak for Data Data Stores information disclosure 4.6.0 allows web pages to be stored locally which can be read by another user on …

Feb 29, 2024
CVE-2024-27517
5.4 MEDIUM

Webasyst 2.9.9 has a Cross-Site Scripting (XSS) vulnerability, Attackers can create blogs containing malicious code after gaining blog permissions.

Feb 29, 2024
CVE-2024-27092
5.4 MEDIUM

Hoppscotch is an API development ecosystem. Due to lack of validation for fields like Label (Edit Team) - TeamName, bad actors can send emails with …

Feb 29, 2024
CVE-2024-27083
4.3 MEDIUM

Flask-AppBuilder is an application development framework, built on top of Flask. A Cross-Site Scripting (XSS) vulnerability has been discovered on the OAuth login page. An …

Feb 29, 2024
CVE-2024-26473
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in SocialMediaWebsite v1.0.1 allows attackers to inject malicious JavaScript into the web browser of a victim via the poll …

Feb 29, 2024
CVE-2024-26472
6.1 MEDIUM

KLiK SocialMediaWebsite version 1.0.1 from msaad1999 has a reflected cross-site scripting (XSS) vulnerability which may allow remote attackers to execute arbitrary JavaScript in the web …

Feb 29, 2024
CVE-2024-26471
5.4 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in zhimengzhe iBarn v1.5 allows attackers to inject malicious JavaScript into the web browser of a victim via the …

Feb 29, 2024
CVE-2024-26462
5.5 MEDIUM

Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/kdc/ndr.c.

Feb 29, 2024
CVE-2024-26458
5.3 MEDIUM

Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.

Feb 29, 2024
CVE-2024-26132
4.0 MEDIUM

Element Android is an Android Matrix Client. A third-party malicious application installed on the same phone can force Element Android, version 0.91.0 through 1.6.12, to …

Feb 29, 2024
CVE-2024-25932
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Manish Kumar Agarwal Change Table Prefix change-table-prefix allows Cross Site Request Forgery.This issue affects Change Table Prefix: from n/a …

Feb 29, 2024
CVE-2024-25931
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Heureka Group Heureka.This issue affects Heureka: from n/a through 1.0.8.

Feb 29, 2024
CVE-2024-25930
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Nuggethon Custom Order Statuses for WooCommerce.This issue affects Custom Order Statuses for WooCommerce: from n/a through 1.5.2.

Feb 29, 2024
CVE-2024-25831
5.4 MEDIUM

F-logic DataCube3 Version 1.0 is affected by a reflected cross-site scripting (XSS) vulnerability due to improper input sanitization. An authenticated, remote attacker can execute arbitrary …

Feb 29, 2024
CVE-2024-25712
6.1 MEDIUM

http-swagger before 1.2.6 allows XSS via PUT requests, because a file that has been uploaded (via httpSwagger.WrapHandler and *webdav.memFile) can subsequently be accessed via a …

Feb 29, 2024
CVE-2024-24708
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in W3speedster W3SPEEDSTER.This issue affects W3SPEEDSTER: from n/a through 7.19.

Feb 29, 2024
CVE-2024-24701
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Native Grid LLC A no-code page builder for beautiful performance-based content.This issue affects A no-code page builder for beautiful …

Feb 29, 2024
CVE-2024-24155
6.5 MEDIUM

Bento4 v1.5.1-628 contains a Memory leak on AP4_Movie::AP4_Movie, parsing tracks and added into m_Tracks list, but mp42aac cannot correctly delete when we got an no …

Feb 29, 2024
CVE-2024-24150
6.5 MEDIUM

A memory leak issue discovered in parseSWF_TEXTRECORD in libming v0.4.8 allows attackers to cause a denial of service via a crafted SWF file.

Feb 29, 2024
CVE-2024-24149
6.5 MEDIUM

A memory leak issue discovered in parseSWF_GLYPHENTRY in libming v0.4.8 allows attackers to cause a denial of service via a crafted SWF file.

Feb 29, 2024
CVE-2024-24147
6.5 MEDIUM

A memory leak issue discovered in parseSWF_FILLSTYLEARRAY in libming v0.4.8 allows attackers to cause s denial of service via a crafted SWF file.

Feb 29, 2024
CVE-2024-24146
6.5 MEDIUM

A memory leak issue discovered in parseSWF_DEFINEBUTTON in libming v0.4.8 allows attackers to cause s denial of service via a crafted SWF file.

Feb 29, 2024
CVE-2024-23946
5.3 MEDIUM

Possible path traversal in Apache OFBiz allowing file inclusion. Users are recommended to upgrade to version 18.12.12, that fixes the issue.

Feb 29, 2024
CVE-2024-23519
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in M&S Consulting Email Before Download.This issue affects Email Before Download: from n/a through 6.9.7.

Feb 29, 2024
CVE-2024-22936
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability in Parents & Student Portal in Genesis School Management Systems in Genesis AIMS Student Information Systems v.3053 allows remote attackers to …

Feb 29, 2024
CVE-2024-22251
5.9 MEDIUM

VMware Workstation and Fusion contain an out-of-bounds read vulnerability in the USB CCID (chip card interface device). A malicious actor with local administrative privileges on …

Feb 29, 2024
CVE-2024-21726
6.5 MEDIUM

Inadequate content filtering leads to XSS vulnerabilities in various components.

Feb 29, 2024
CVE-2024-21725
6.1 MEDIUM

Inadequate escaping of mail addresses lead to XSS vulnerabilities in various components.

Feb 29, 2024
CVE-2024-21724
6.1 MEDIUM

Inadequate input validation for media selection fields lead to XSS vulnerabilities in various extensions.

Feb 29, 2024
CVE-2024-21723
4.3 MEDIUM

Inadequate parsing of URLs could result into an open redirect.

Feb 29, 2024
CVE-2024-21722
6.3 MEDIUM

The MFA management features did not properly terminate existing user sessions when a user's MFA methods have been modified.

Feb 29, 2024
CVE-2024-20344
5.3 MEDIUM

A vulnerability in system resource management in Cisco UCS 6400 and 6500 Series Fabric Interconnects that are in Intersight Managed Mode (IMM) could allow an …

Feb 29, 2024
CVE-2024-20294
6.6 MEDIUM

A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to …

Feb 29, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.