CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-26585
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tls: fix race between tx work scheduling and socket close Similarly to previous commit, the …

Feb 21, 2024
CVE-2024-26584
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: tls: handle backlogging of crypto requests Since we're setting the CRYPTO_TFM_REQ_MAY_BACKLOG flag on our …

Feb 21, 2024
CVE-2024-26583
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tls: fix race between async notify and socket close The submitting thread (one which called …

Feb 21, 2024
CVE-2023-33843
5.4 MEDIUM

IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering …

Feb 21, 2024
CVE-2024-24837
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Frédéric GILLES FG PrestaShop to WooCommerce, Frédéric GILLES FG Drupal to WordPress, Frédéric GILLES FG Joomla to WordPress.This issue …

Feb 21, 2024
CVE-2024-24802
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in John Tendik JTRT Responsive Tables.This issue affects JTRT Responsive Tables: from n/a through 4.1.9.

Feb 21, 2024
CVE-2024-24798
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in SoniNow Team Debug.This issue affects Debug: from n/a through 1.10.

Feb 21, 2024
CVE-2023-52442
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate session id and tree id in compound request `smb2_get_msg()` in smb2_get_ksmbd_tcon() and smb2_check_user_session() …

Feb 21, 2024
CVE-2024-25905
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Mondula GmbH Multi Step Form.This issue affects Multi Step Form: from n/a through 1.7.18.

Feb 21, 2024
CVE-2024-25904
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in David Stockl TinyMCE and TinyMCE Advanced Professsional Formats and Styles.This issue affects TinyMCE and TinyMCE Advanced Professsional Formats and …

Feb 21, 2024
CVE-2024-24876
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Janis Elsts Admin Menu Editor.This issue affects Admin Menu Editor: from n/a through 1.12.

Feb 21, 2024
CVE-2024-24872
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Themify Themify Builder.This issue affects Themify Builder: from n/a through 7.0.5.

Feb 21, 2024
CVE-2024-24849
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Mark Stockton Quicksand Post Filter jQuery Plugin.This issue affects Quicksand Post Filter jQuery Plugin: from n/a through 3.1.1.

Feb 21, 2024
CVE-2024-1081
6.4 MEDIUM

The 3D FlipBook – PDF Flipbook WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bookmark feature in all versions up …

Feb 21, 2024
CVE-2024-0593
5.3 MEDIUM

The Simple Job Board plugin for WordPress is vulnerable to unauthorized access of data| due to insufficient authorization checking on the fetch_quick_job() function in all …

Feb 21, 2024
CVE-2023-42953
5.5 MEDIUM

A permissions issue was addressed with additional restrictions. This issue is fixed in tvOS 17.1, watchOS 10.1, macOS Sonoma 14.1, iOS 17.1 and iPadOS 17.1. …

Feb 21, 2024
CVE-2023-42952
4.4 MEDIUM

The issue was addressed with improved checks. This issue is fixed in iOS 17.1 and iPadOS 17.1, macOS Ventura 13.6.3, macOS Sonoma 14.1, macOS Monterey …

Feb 21, 2024
CVE-2023-42951
4.3 MEDIUM

The issue was addressed with improved handling of caches. This issue is fixed in iOS 17.1 and iPadOS 17.1. A user may be unable to …

Feb 21, 2024
CVE-2023-42946
5.5 MEDIUM

This issue was addressed with improved redaction of sensitive information. This issue is fixed in tvOS 17.1, watchOS 10.1, macOS Sonoma 14.1, iOS 17.1 and …

Feb 21, 2024
CVE-2023-42945
5.5 MEDIUM

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.1. An app may gain unauthorized access to Bluetooth.

Feb 21, 2024
CVE-2023-42889
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.1, macOS Monterey 12.7.1, macOS Ventura 13.6.1. An app may be …

Feb 21, 2024
CVE-2023-42878
5.5 MEDIUM

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in watchOS 10.1, macOS Sonoma 14.1, iOS 17.1 …

Feb 21, 2024
CVE-2023-42877
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.1, macOS Monterey 12.7.1, macOS Ventura 13.6.1. An app may be …

Feb 21, 2024
CVE-2023-42860
5.5 MEDIUM

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.1, macOS Monterey 12.7.1, macOS Ventura 13.6.1. An app may …

Feb 21, 2024
CVE-2023-42859
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.1, macOS Monterey 12.7.1, macOS Ventura 13.6.1. An app may be …

Feb 21, 2024
CVE-2023-42858
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.1, macOS Monterey 12.7.1, macOS Ventura 13.6.1. An app may be …

Feb 21, 2024
CVE-2023-42855
4.6 MEDIUM

This issue was addressed with improved state management. This issue is fixed in iOS 17.1 and iPadOS 17.1. An attacker with physical access may be …

Feb 21, 2024
CVE-2023-42853
5.5 MEDIUM

A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.1, macOS Monterey 12.7.1, macOS Ventura 13.6.1. An app may …

Feb 21, 2024
CVE-2023-42843
4.3 MEDIUM

An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS …

Feb 21, 2024
CVE-2023-42840
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.1, macOS Monterey 12.7.1, macOS Ventura 13.6.1. An app may be …

Feb 21, 2024
CVE-2023-42839
5.5 MEDIUM

This issue was addressed with improved state management. This issue is fixed in tvOS 17.1, watchOS 10.1, macOS Sonoma 14.1, iOS 17.1 and iPadOS 17.1. …

Feb 21, 2024
CVE-2023-42836
5.3 MEDIUM

A logic issue was addressed with improved checks. This issue is fixed in iOS 17.1 and iPadOS 17.1, macOS Ventura 13.6.3, macOS Sonoma 14.1, macOS …

Feb 21, 2024
CVE-2023-42834
5.5 MEDIUM

A privacy issue was addressed with improved handling of files. This issue is fixed in watchOS 10.1, macOS Sonoma 14.1, macOS Monterey 12.7.2, macOS Ventura …

Feb 21, 2024
CVE-2023-42823
5.5 MEDIUM

The issue was resolved by sanitizing logging This issue is fixed in watchOS 10.1, macOS Sonoma 14.1, tvOS 17.1, macOS Monterey 12.7.1, iOS 16.7.2 and …

Feb 21, 2024
CVE-2024-22235
6.7 MEDIUM

VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'.

Feb 21, 2024
CVE-2024-25151
5.4 MEDIUM

The Calendar module in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack …

Feb 21, 2024
CVE-2024-1676
5.4 MEDIUM

Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security …

Feb 21, 2024
CVE-2024-1672
5.4 MEDIUM

Inappropriate implementation in Content Security Policy in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass content security policy via a crafted HTML …

Feb 21, 2024
CVE-2024-1671
6.5 MEDIUM

Inappropriate implementation in Site Isolation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass content security policy via a crafted HTML page. …

Feb 21, 2024
CVE-2024-1562
5.3 MEDIUM

The WooCommerce Google Sheet Connector plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the execute_post_data function …

Feb 21, 2024
CVE-2024-1501
4.7 MEDIUM

The Database Reset plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.22. This is due to missing …

Feb 21, 2024
CVE-2024-1108
6.5 MEDIUM

The Plugin Groups plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the admin_init() function in all …

Feb 21, 2024
CVE-2024-0407
6.5 MEDIUM

Certain HP Enterprise LaserJet, and HP LaserJet Managed Printers are potentially vulnerable to information disclosure, when connections made by the device back to services enabled …

Feb 21, 2024
CVE-2023-50923
4.3 MEDIUM

In QUIC in RFC 9000, the Latency Spin Bit specification (section 17.4) does not strictly constrain the bit value when the feature is disabled, which …

Feb 21, 2024
CVE-2024-26140
4.6 MEDIUM

com.yetanalytics/lrs is the Yet Analytics Core LRS Library. Prior to version 1.2.17 of the LRS library and version 0.7.5 of SQL LRS, a maliciously crafted …

Feb 20, 2024
CVE-2024-25428
6.5 MEDIUM

SQL Injection vulnerability in MRCMS v3.1.2 allows attackers to run arbitrary system commands via the status parameter.

Feb 20, 2024
CVE-2023-6936
5.3 MEDIUM

In wolfSSL prior to 5.6.6, if callback functions are enabled (via the WOLFSSL_CALLBACKS flag), then a malicious TLS client or network attacker can trigger a …

Feb 20, 2024
CVE-2021-29038
6.3 MEDIUM

Liferay Portal 7.2.0 through 7.3.5, and older unsupported versions, and Liferay DXP 7.3 before fix pack 1, 7.2 before fix pack 17, and older unsupported …

Feb 20, 2024
CVE-2023-49034
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in ProjeQtOr 11.0.2 allows a remote attacker to execute arbitrary code via a crafted script to thecheckvalidHtmlText function in the …

Feb 20, 2024
CVE-2023-46967
6.1 MEDIUM

Cross Site Scripting vulnerability in the sanitize function in Enhancesoft osTicket 1.18.0 allows a remote attacker to escalate privileges via a crafted support ticket.

Feb 20, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.