CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-20724
5.5 MEDIUM

Substance3D - Painter versions 9.1.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Feb 15, 2024
CVE-2024-20722
5.5 MEDIUM

Substance3D - Painter versions 9.1.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Feb 15, 2024
CVE-2023-4538
6.2 MEDIUM

The database access credentials configured during installation are stored in a special table, and are encrypted with a shared key, same among all Comarch ERP …

Feb 15, 2024
CVE-2024-24256
5.9 MEDIUM

SQL Injection vulnerability in Yonyou space-time enterprise information integration platform v.9.0 and before allows an attacker to obtain sensitive information via the gwbhAIM parameter in …

Feb 15, 2024
CVE-2024-21727
6.1 MEDIUM

XSS vulnerability in DP Calendar component for Joomla.

Feb 15, 2024
CVE-2024-0708
5.3 MEDIUM

The Landing Page Cat – Coming Soon Page, Maintenance Page & Squeeze Pages plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions …

Feb 15, 2024
CVE-2023-46596
5.1 MEDIUM

Improper input validation in Algosec FireFlow VisualFlow workflow editor via Name, Description and Configuration File field in version A32.20, A32.50, A32.60 permits an attacker to …

Feb 15, 2024
CVE-2022-23093
6.5 MEDIUM

ping reads raw IP packets from the network to process responses in the pr_pack() function. As part of processing a response ping has to reconstruct …

Feb 15, 2024
CVE-2022-23091
4.0 MEDIUM

A particular case of memory sharing is mishandled in the virtual memory system. This is very similar to SA-21:08.vm, but with a different root cause. …

Feb 15, 2024
CVE-2024-25940
6.3 MEDIUM

`bhyveload -h <host-path>` may be used to grant loader access to the <host-path> directory tree on the host. Affected versions of bhyveload(8) do not make …

Feb 15, 2024
CVE-2024-25559
4.7 MEDIUM

URL spoofing vulnerability exists in a-blog cms Ver.3.1.0 to Ver.3.1.8. If an attacker sends a specially crafted request, the administrator of the product may be …

Feb 15, 2024
CVE-2022-23089
4.7 MEDIUM

When dumping core and saving process information, proc_getargv() might return an sbuf which have a sbuf_len() of 0 or -1, which is not properly handled. …

Feb 15, 2024
CVE-2024-26263
5.3 MEDIUM

EBM Technologies RISWEB's specific URL path is not properly controlled by permission, allowing attackers to browse specific pages and query sensitive data without login.

Feb 15, 2024
CVE-2024-25620
6.4 MEDIUM

Helm is a tool for managing Charts. Charts are packages of pre-configured Kubernetes resources. When either the Helm client or SDK is used to save …

Feb 15, 2024
CVE-2022-48220
6.4 MEDIUM

Potential vulnerabilities have been identified in certain HP Desktop PC products using the HP TamperLock feature, which might allow intrusion detection bypass via a physical …

Feb 14, 2024
CVE-2022-48219
6.4 MEDIUM

Potential vulnerabilities have been identified in certain HP Desktop PC products using the HP TamperLock feature, which might allow intrusion detection bypass via a physical …

Feb 14, 2024
CVE-2024-1471
5.9 MEDIUM

An HTML injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application could modify Repository parameters, which could lead …

Feb 14, 2024
CVE-2023-49721
6.7 MEDIUM

An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident attacker to bypass Secure Boot.

Feb 14, 2024
CVE-2023-48733
6.7 MEDIUM

An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure Boot.

Feb 14, 2024
CVE-2024-25618
4.2 MEDIUM

Mastodon is a free, open-source social network server based on ActivityPub. Mastodon allows new identities from configured authentication providers (CAS, SAML, OIDC) to attach to …

Feb 14, 2024
CVE-2024-25617
5.3 MEDIUM

Squid is an open source caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Collapse of Data into Unsafe Value …

Feb 14, 2024
CVE-2024-25300
4.8 MEDIUM

A cross-site scripting (XSS) vulnerability in Redaxo v5.15.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name …

Feb 14, 2024
CVE-2024-0011
4.3 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the Captive Portal feature of Palo Alto Networks PAN-OS software enables execution of malicious JavaScript (in the context …

Feb 14, 2024
CVE-2024-0010
4.3 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect portal feature of Palo Alto Networks PAN-OS software enables execution of malicious JavaScript (in the context …

Feb 14, 2024
CVE-2024-0009
6.3 MEDIUM

An improper verification vulnerability in the GlobalProtect gateway feature of Palo Alto Networks PAN-OS software enables a malicious user with stolen credentials to establish a …

Feb 14, 2024
CVE-2024-0008
6.6 MEDIUM

Web sessions in the management interface in Palo Alto Networks PAN-OS software do not expire in certain situations, making it susceptible to unauthorized access.

Feb 14, 2024
CVE-2024-0007
6.8 MEDIUM

A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a malicious authenticated read-write administrator to store a JavaScript payload using the web …

Feb 14, 2024
CVE-2024-24966
6.2 MEDIUM

When LDAP remote authentication is configured on F5OS, a remote user without an assigned role will be incorrectly authorized. Note: Software versions which have reached …

Feb 14, 2024
CVE-2024-23976
6.0 MEDIUM

When running in Appliance mode, an authenticated attacker assigned the Administrator role may be able to bypass Appliance mode restrictions utilizing iAppsLX templates on a …

Feb 14, 2024
CVE-2024-23607
5.5 MEDIUM

A directory traversal vulnerability exists in the F5OS QKView utility that allows an authenticated attacker to read files outside the QKView directory. Note: Software versions …

Feb 14, 2024
CVE-2024-21782
6.7 MEDIUM

BIG-IP or BIG-IQ Resource Administrators and Certificate Managers who have access to the secure copy (scp) utility but do not have access to Advanced shell …

Feb 14, 2024
CVE-2024-25226
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in Simple Admin Panel App v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected …

Feb 14, 2024
CVE-2024-25225
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability in Simple Admin Panel App v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected …

Feb 14, 2024
CVE-2024-25224
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability in Simple Admin Panel App v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected …

Feb 14, 2024
CVE-2024-25221
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in Task Manager App v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into …

Feb 14, 2024
CVE-2024-25219
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in Task Manager App v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into …

Feb 14, 2024
CVE-2024-25218
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in Task Manager App v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into …

Feb 14, 2024
CVE-2024-25208
5.4 MEDIUM

Barangay Population Monitoring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Add Resident function at /barangay-population-monitoring-system/masterlist.php. This vulnerabiity allows attackers …

Feb 14, 2024
CVE-2024-25207
5.4 MEDIUM

Barangay Population Monitoring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Add Resident function at /barangay-population-monitoring-system/masterlist.php. This vulnerabiity allows attackers …

Feb 14, 2024
CVE-2023-5122
5.0 MEDIUM

Grafana is an open-source platform for monitoring and observability. The CSV datasource plugin is a Grafana Labs maintained plugin for Grafana that allows for retrieving …

Feb 14, 2024
CVE-2023-46186
5.3 MEDIUM

IBM Jazz for Service Management 1.1.3.20 could allow an unauthorized user to obtain sensitive file information using forced browsing due to improper access controls. IBM …

Feb 14, 2024
CVE-2023-41252
6.5 MEDIUM

Out-of-bounds read in some Intel(R) QAT software drivers for Windows before version QAT1.7-W-1.11.0 may allow an authenticated user to potentially enable denial of service via …

Feb 14, 2024
CVE-2023-41231
6.7 MEDIUM

Incorrect default permissions in some ACAT software maintained by Intel(R) before version 2.0.0 may allow an authenticated user to potentially enable escalation of privilege via …

Feb 14, 2024
CVE-2023-41091
6.7 MEDIUM

Uncontrolled search path for some Intel(R) MPI Library Software before version 2021.11 may allow an authenticated user to potentially enable escalation of privilege via local …

Feb 14, 2024
CVE-2023-40161
6.6 MEDIUM

Improper access control in some Intel Unite(R) Client software before version 4.2.35041 may allow an authenticated user to potentially enable escalation of privilege via local …

Feb 14, 2024
CVE-2023-40156
6.7 MEDIUM

Uncontrolled search path element in some Intel(R) SSU software before version 3.0.0.2 may allow an authenticated user to potentially enable escalation of privilege via local …

Feb 14, 2024
CVE-2023-40154
6.7 MEDIUM

Incorrect default permissions in the Intel(R) SUR for Gameplay Software before version 2.0.1901 may allow privillaged user to potentially enable escalation of privilege via local …

Feb 14, 2024
CVE-2023-39932
6.7 MEDIUM

Uncontrolled search path in the Intel(R) SUR for Gameplay Software before version 2.0.1901 may allow a privillaged user to potentially enable escalation of privilege via …

Feb 14, 2024
CVE-2023-39432
6.7 MEDIUM

Improper access control element in some Intel(R) Ethernet tools and driver install software, before versions 28.2, may allow an authenticated user to potentially enable escalation …

Feb 14, 2024
CVE-2023-38566
6.7 MEDIUM

Uncontrolled search path in some Intel(R) ISPC software before version 1.21.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

Feb 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.