CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-41165
4.8 MEDIUM

An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.38 before 3.7.39, 3.10.0 through 3.11.26 before 3.11.27, 4.0 through 4.3.21 before 4.3.22, and …

Feb 29, 2024
CVE-2023-38372
5.9 MEDIUM

An unauthorized attacker who has obtained an IBM Watson IoT Platform 1.0 security authentication token can use it to impersonate an authorized platform user. IBM …

Feb 29, 2024
CVE-2023-37495
5.9 MEDIUM

Internet passwords stored in Person documents in the Domino® Directory created using the "Add Person" action on the People & Groups tab in the Domino® …

Feb 29, 2024
CVE-2023-27151
6.1 MEDIUM

openCRX 5.2.0 was discovered to contain an HTML injection vulnerability for Search Criteria-Activity Number (in the Saved Search Activity) via the Name, Description, or Activity …

Feb 29, 2024
CVE-2023-25926
5.5 MEDIUM

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML …

Feb 29, 2024
CVE-2022-36677
6.1 MEDIUM

Obsidian Mind Map v1.1.0 allows attackers to execute arbitrary code via a crafted payload injected into an uploaded document.

Feb 29, 2024
CVE-2024-26146
5.3 MEDIUM

Rack is a modular Ruby web server interface. Carefully crafted headers can cause header parsing in Rack to take longer than expected resulting in a …

Feb 29, 2024
CVE-2024-26141
5.8 MEDIUM

Rack is a modular Ruby web server interface. Carefully crafted Range headers can cause a server to respond with an unexpectedly large response. Responding with …

Feb 29, 2024
CVE-2024-25126
5.3 MEDIUM

Rack is a modular Ruby web server interface. Carefully crafted content type headers can cause Rack’s media type parser to take much longer than expected, …

Feb 29, 2024
CVE-2024-26559
5.3 MEDIUM

An issue in uverif v.2.0 allows a remote attacker to obtain sensitive information.

Feb 28, 2024
CVE-2024-25579
6.8 MEDIUM

OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent attacker with an administrative privilege to execute arbitrary OS commands by sending a …

Feb 28, 2024
CVE-2024-22532
6.5 MEDIUM

Buffer Overflow vulnerability in XNSoft NConvert 7.163 (for Windows x86) allows attackers to cause a denial of service via crafted xwd file.

Feb 28, 2024
CVE-2024-21798
4.8 MEDIUM

ELECOM wireless LAN routers contain a cross-site scripting vulnerability. Assume that a malicious administrative user configures the affected product with specially crafted content. When another …

Feb 28, 2024
CVE-2023-5617
5.3 MEDIUM

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.6, including 9.5.x and 8.3.x, display the version of Tomcat when a server error …

Feb 28, 2024
CVE-2024-26450
5.4 MEDIUM

An issue exists within Piwigo before v.14.2.0 allowing a malicious user to take over the application. This exploit involves chaining a Cross Site Request Forgery …

Feb 28, 2024
CVE-2024-25868
6.1 MEDIUM

A Cross Site Scripting (XSS) vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary code via the membershipType …

Feb 28, 2024
CVE-2023-45873
6.5 MEDIUM

An issue was discovered in Couchbase Server through 7.2.2. A data reader may cause a denial of service (application exist) because of the OOM killer.

Feb 28, 2024
CVE-2023-25922
4.3 MEDIUM

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 allows the attacker to upload or transfer files of dangerous types that can …

Feb 28, 2024
CVE-2024-27285
5.4 MEDIUM

YARD is a Ruby Documentation tool. The "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate …

Feb 28, 2024
CVE-2024-25435
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in Md1health Md1patient v2.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the …

Feb 28, 2024
CVE-2024-25202
6.1 MEDIUM

Cross Site Scripting vulnerability in Phpgurukul User Registration & Login and User Management System 1.0 allows attackers to run arbitrary code via the search bar.

Feb 28, 2024
CVE-2023-52048
4.7 MEDIUM

RuoYi v4.7.8 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /system/notice/.

Feb 28, 2024
CVE-2024-27948
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in bytesforall Atahualpa.This issue affects Atahualpa: from n/a through 3.7.24.

Feb 28, 2024
CVE-2023-51692
4.3 MEDIUM

Missing Authorization vulnerability in CusRev Customer Reviews for WooCommerce.This issue affects Customer Reviews for WooCommerce: from n/a through 5.38.1.

Feb 28, 2024
CVE-2023-51533
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Ecwid Ecommerce Ecwid Ecommerce Shopping Cart.This issue affects Ecwid Ecommerce Shopping Cart: from n/a through 6.12.4.

Feb 28, 2024
CVE-2024-27103
6.1 MEDIUM

Querybook is a Big Data Querying UI. When a user searches for their queries, datadocs, tables and lists, the search result is marked and highlighted, …

Feb 28, 2024
CVE-2024-21749
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Atakan Au 1 click disable all.This issue affects 1 click disable all: from n/a through 1.0.1.

Feb 28, 2024
CVE-2024-0560
6.3 MEDIUM

A vulnerability was found in 3Scale, when used with Keycloak 15 (or RHSSO 7.5.0) and superiors. When the auth_type is use_3scale_oidc_issuer_endpoint, the Token Introspection policy …

Feb 28, 2024
CVE-2023-52226
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Advanced Flamingo.This issue affects Advanced Flamingo: from n/a through 1.0.

Feb 28, 2024
CVE-2023-52223
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in MailerLite MailerLite – WooCommerce integration.This issue affects MailerLite – WooCommerce integration: from n/a through 2.0.8.

Feb 28, 2024
CVE-2023-51683
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Easy PayPal & Stripe Buy Now Button.This issue affects Easy PayPal & Stripe Buy Now Button: from …

Feb 28, 2024
CVE-2023-51681
6.5 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Duplicator Duplicator – WordPress Migration & Backup Plugin.This issue affects Duplicator – WordPress Migration & Backup Plugin: from n/a …

Feb 28, 2024
CVE-2024-24705
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Octa Code Accessibility.This issue affects Accessibility: from n/a through 1.0.6.

Feb 28, 2024
CVE-2024-24702
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Matt Martz & Andy Stratton Page Restrict.This issue affects Page Restrict: from n/a through 2.5.5.

Feb 28, 2024
CVE-2023-6917
6.0 MEDIUM

A vulnerability has been identified in the Performance Co-Pilot (PCP) package, stemming from the mixed privilege levels utilized by systemd services associated with PCP. While …

Feb 28, 2024
CVE-2024-1965
6.5 MEDIUM

Server-Side Request Forgery vulnerability in Haivision's Aviwest Manager and Aviwest Steamhub. This vulnerability could allow an attacker to enumerate internal network configuration without the need …

Feb 28, 2024
CVE-2024-1808
6.4 MEDIUM

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'su_qrcode' shortcode in all versions up …

Feb 28, 2024
CVE-2024-26016
4.3 MEDIUM

A low privilege authenticated user could import an existing dashboard or chart that they do not have access to and then modify its metadata, thereby …

Feb 28, 2024
CVE-2024-24779
5.0 MEDIUM

Apache Superset with custom roles that include `can write on dataset` and without all data access permissions, allows for users to create virtual datasets to …

Feb 28, 2024
CVE-2024-24773
4.9 MEDIUM

Improper parsing of nested SQL statements on SQLLab would allow authenticated users to surpass their data authorization scope. This issue affects Apache Superset: before 3.0.4, …

Feb 28, 2024
CVE-2024-24772
4.3 MEDIUM

A guest user could exploit a chart data REST API and send arbitrary SQL statements that on error could leak information from the underlying analytics …

Feb 28, 2024
CVE-2024-27315
4.3 MEDIUM

An authenticated user with privileges to create Alerts on Alerts & Reports has the capability to generate a specially crafted SQL statement that triggers an …

Feb 28, 2024
CVE-2024-1861
4.3 MEDIUM

The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan plugin for WordPress is vulnerable to unauthorized modification of data due …

Feb 28, 2024
CVE-2024-1860
6.5 MEDIUM

The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan plugin for WordPress is vulnerable to unauthorized modification of data due …

Feb 28, 2024
CVE-2024-1719
4.3 MEDIUM

The Easy PayPal & Stripe Buy Now Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.3 …

Feb 28, 2024
CVE-2024-22459
6.8 MEDIUM

Dell ECS, versions 3.6 through 3.6.2.5, and 3.7 through 3.7.0.6, and 3.8 through 3.8.0.4 versions, contain an improper access control vulnerability. A remote high privileged …

Feb 28, 2024
CVE-2024-1954
6.3 MEDIUM

The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and …

Feb 28, 2024
CVE-2024-1791
6.4 MEDIUM

The CodeMirror Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Code Mirror block in all versions up to, and including, 1.2.4 …

Feb 28, 2024
CVE-2024-1566
6.5 MEDIUM

The Redirects plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save function in all versions …

Feb 28, 2024
CVE-2024-1516
5.3 MEDIUM

The WP eCommerce plugin for WordPress is vulnerable to unauthorized arbitrary post creation due to a missing capability check on the check_for_saas_push() function in all …

Feb 28, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.