CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-44379
6.1 MEDIUM

baserCMS is a website development framework. Prior to version 5.0.9, there is a cross-site scripting vulnerability in the site search feature. Version 5.0.9 contains a …

Feb 22, 2024
CVE-2024-26445
6.1 MEDIUM

flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/delete_place.php

Feb 22, 2024
CVE-2024-26351
6.1 MEDIUM

flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/update_place.php

Feb 22, 2024
CVE-2024-26349
4.3 MEDIUM

flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/delete_translation.php

Feb 22, 2024
CVE-2024-25876
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in the Header module of Enhavo CMS v0.13.1 allows attackers to execute arbitrary web scripts or HTML via a crafted …

Feb 22, 2024
CVE-2024-25875
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in the Header module of Enhavo CMS v0.13.1 allows attackers to execute arbitrary web scripts or HTML via a crafted …

Feb 22, 2024
CVE-2024-25874
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability in the New/Edit Article module of Enhavo CMS v0.13.1 allows attackers to execute arbitrary web scripts or HTML via a …

Feb 22, 2024
CVE-2024-25873
5.4 MEDIUM

Enhavo v0.13.1 was discovered to contain an HTML injection vulnerability in the Author text field under the Blockquote module. This vulnerability allows attackers to execute …

Feb 22, 2024
CVE-2024-26578
5.9 MEDIUM

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1. Repeated submission during registration resulted …

Feb 22, 2024
CVE-2024-23349
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1. XSS attack when user enters …

Feb 22, 2024
CVE-2023-29179
6.5 MEDIUM

A null pointer dereference in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, Fortiproxy version 7.2.0 through 7.2.4, 7.0.0 through 7.0.10 …

Feb 22, 2024
CVE-2024-26491
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in the Addon JD Flusity 'Media Gallery with description' module of flusity-CMS v2.33 allows attackers to execute arbitrary web scripts …

Feb 22, 2024
CVE-2024-26490
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability in the Addon JD Simple module of flusity-CMS v2.33 allows attackers to execute arbitrary web scripts or HTML via a …

Feb 22, 2024
CVE-2024-26489
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in the Addon JD Flusity 'Social block links' module of flusity-CMS v2.33 allows attackers to execute arbitrary web scripts or …

Feb 22, 2024
CVE-2024-1053
4.3 MEDIUM

The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'email' action …

Feb 22, 2024
CVE-2024-0903
5.4 MEDIUM

The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Feb 22, 2024
CVE-2024-26484
6.1 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the Edit Content Layout module of Kirby CMS v4.1.0 allows attackers to execute arbitrary web scripts or HTML …

Feb 22, 2024
CVE-2024-26481
4.7 MEDIUM

Kirby CMS v4.1.0 was discovered to contain a reflected self-XSS vulnerability via the URL parameter.

Feb 22, 2024
CVE-2024-25801
6.1 MEDIUM

SKINsoft S-Museum 7.02.3 allows XSS via the filename of an uploaded file. Unlike in CVE-2024-25802, the attack payload is in the name (not the content) …

Feb 22, 2024
CVE-2023-4895
4.3 MEDIUM

An issue has been discovered in GitLab EE affecting all versions starting from 12.0 to 16.7.6, all versions starting from 16.8 before 16.8.3, all versions …

Feb 22, 2024
CVE-2024-1525
5.3 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions …

Feb 22, 2024
CVE-2024-0861
4.3 MEDIUM

An issue has been discovered in GitLab EE affecting all versions starting from 16.4 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions …

Feb 22, 2024
CVE-2023-6477
6.7 MEDIUM

An issue has been discovered in GitLab EE affecting all versions starting from 16.5 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions …

Feb 22, 2024
CVE-2024-26148
6.1 MEDIUM

Querybook is a user interface for querying big data. Prior to version 3.31.1, there is a vulnerability in Querybook's rich text editor that enables users …

Feb 21, 2024
CVE-2024-23654
4.1 MEDIUM

discourse-ai is the AI plugin for the open-source discussion platform Discourse. Prior to commit 94ba0dadc2cf38e8f81c3936974c167219878edd, interactions with different AI services are vulnerable to admin-initiated SSRF …

Feb 21, 2024
CVE-2024-26311
5.7 MEDIUM

Archer Platform 6.x before 6.14 P2 HF1 (6.14.0.2.1) contains a reflected XSS vulnerability. A remote authenticated malicious Archer user could potentially exploit this by tricking …

Feb 21, 2024
CVE-2024-26310
4.3 MEDIUM

Archer Platform 6.8 before 6.14 P2 (6.14.0.2) contains an improper access control vulnerability. A remote authenticated malicious user could potentially exploit this to gain access …

Feb 21, 2024
CVE-2023-6640
6.5 MEDIUM

Malformed S2 Nonce Get Command Class packets can be sent to crash PC Controller v5.54.0 and earlier.

Feb 21, 2024
CVE-2023-6533
6.5 MEDIUM

Malformed Device Reset Locally Command Class packets can be sent to the controller, causing the controller to assume the end device has left the network. …

Feb 21, 2024
CVE-2024-25381
6.1 MEDIUM

There is a Stored XSS Vulnerability in Emlog Pro 2.2.8 Article Publishing, due to non-filtering of quoted content.

Feb 21, 2024
CVE-2024-22473
6.8 MEDIUM

TRNG is used before initialization by ECDSA signing driver when exiting EM2/EM3 on Virtual Secure Vault (VSE) devices. This defect may allow Signature Spoofing by …

Feb 21, 2024
CVE-2024-1707
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in GARO WALLBOX GLB+ T2EV7 0.5. This affects an unknown part of the file /index.jsp#settings of …

Feb 21, 2024
CVE-2024-26145
6.5 MEDIUM

Discourse Calendar adds the ability to create a dynamic calendar in the first post of a topic on Discourse. Uninvited users are able to gain …

Feb 21, 2024
CVE-2024-25898
6.1 MEDIUM

A XSS vulnerability was found in the ChurchCRM v.5.5.0 functionality, edit your event, where malicious JS or HTML code can be inserted in the Event …

Feb 21, 2024
CVE-2024-25896
5.3 MEDIUM

ChurchCRM 5.5.0 EventEditor.php is vulnerable to Blind SQL Injection (Time-based) via the EID POST parameter.

Feb 21, 2024
CVE-2024-25895
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in ChurchCRM 5.5.0 allows remote attackers to inject arbitrary web script or HTML via the type parameter of /EventAttendance.php

Feb 21, 2024
CVE-2024-1705
5.6 MEDIUM

A vulnerability was found in Shopwind up to 4.6. It has been rated as critical. This issue affects the function actionCreate of the file /public/install/controllers/DefaultController.php …

Feb 21, 2024
CVE-2024-1704
5.5 MEDIUM

A vulnerability was found in ZhongBangKeJi CRMEB 5.2.2. It has been declared as critical. This vulnerability affects the function save/delete of the file /adminapi/system/crud. The …

Feb 21, 2024
CVE-2024-26138
5.3 MEDIUM

The XWiki licensor application, which manages and enforce application licenses for paid extensions, includes the document `Licenses.Code.LicenseJSON` that provides information for admins regarding active licenses. …

Feb 21, 2024
CVE-2024-26133
5.5 MEDIUM

EventStoreDB (ESDB) is an operational database built to store events. A vulnerability has been identified in the projections subsystem in versions 20 prior to 20.10.6, …

Feb 21, 2024
CVE-2024-25288
4.9 MEDIUM

SLIMS (Senayan Library Management Systems) 9 Bulian v9.6.1 is vulnerable to SQL Injection via pop-scope-vocabolary.php.

Feb 21, 2024
CVE-2024-25117
6.8 MEDIUM

php-svg-lib is a scalable vector graphics (SVG) file parsing/rendering library. Prior to version 0.5.2, php-svg-lib fails to validate that font-family doesn't contain a PHAR url, …

Feb 21, 2024
CVE-2024-20325
5.1 MEDIUM

A vulnerability in the Live Data server of Cisco Unified Intelligence Center could allow an unauthenticated, local attacker to read and modify data in a …

Feb 21, 2024
CVE-2024-1702
6.3 MEDIUM

A vulnerability was found in keerti1924 PHP-MYSQL-User-Login-System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /edit.php. The …

Feb 21, 2024
CVE-2024-22220
6.3 MEDIUM

An issue was discovered in Terminalfour 7.4 through 7.4.0004 QP3 and 8 through 8.3.19, and Formbank through 2.1.10-FINAL. Unauthenticated Stored Cross-Site Scripting can occur, with …

Feb 21, 2024
CVE-2024-1701
5.3 MEDIUM

A vulnerability has been found in keerti1924 PHP-MYSQL-User-Login-System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /edit.php. …

Feb 21, 2024
CVE-2024-1700
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in keerti1924 PHP-MYSQL-User-Login-System 1.0. Affected is an unknown function of the file /signup.php. The manipulation of …

Feb 21, 2024
CVE-2023-49100
4.4 MEDIUM

Trusted Firmware-A (TF-A) before 2.10 has a potential read out-of-bounds in the SDEI service. The input parameter passed in register x1 is not validated well …

Feb 21, 2024
CVE-2022-45179
5.4 MEDIUM

An issue was discovered in LIVEBOX Collaboration vDesk through v031. A basic XSS vulnerability exists under the /api/v1/vdeskintegration/todo/createorupdate endpoint via the title parameter and /dashboard/reminders. …

Feb 21, 2024
CVE-2022-45169
5.4 MEDIUM

An issue was discovered in LIVEBOX Collaboration vDesk through v031. A URL Redirection to an Untrusted Site (Open Redirect) can occur under the /api/v1/notification/createnotification endpoint, …

Feb 21, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.