CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-5680
5.3 MEDIUM

If a resolver cache has a very large number of ECS records stored for the same name, the process of cleaning the cache database node …

Feb 13, 2024
CVE-2024-1160
5.4 MEDIUM

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Icon Link in all versions up to, and including, …

Feb 13, 2024
CVE-2024-1159
6.4 MEDIUM

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 4.8.0 …

Feb 13, 2024
CVE-2024-1157
5.4 MEDIUM

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's button URL in all versions up to, and including, …

Feb 13, 2024
CVE-2023-6072
4.6 MEDIUM

A cross-site scripting vulnerability in Trellix Central Management (CM) prior to 9.1.3.97129 allows a remote authenticated attacker to craft CM dashboard internal requests causing arbitrary …

Feb 13, 2024
CVE-2023-48364
6.5 MEDIUM

A vulnerability has been identified in OpenPCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC BATCH V9.1 (All versions < V9.1 SP2 UC05), SIMATIC …

Feb 13, 2024
CVE-2023-48363
6.5 MEDIUM

A vulnerability has been identified in OpenPCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC BATCH V9.1 (All versions < V9.1 SP2 UC05), SIMATIC …

Feb 13, 2024
CVE-2023-6815
6.5 MEDIUM

Incorrect Privilege Assignment vulnerability in Mitsubishi Electric Corporation MELSEC iQ-R Series Safety CPU R08/16/32/120SFCPU all versions and MELSEC iQ-R Series SIL2 Process CPU R08/16/32/120PSFCPU all …

Feb 13, 2024
CVE-2024-25914
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Photoboxone SMTP Mail.This issue affects SMTP Mail: from n/a through 1.3.20.

Feb 13, 2024
CVE-2024-21491
5.9 MEDIUM

Versions of the package svix before 1.17.0 are vulnerable to Authentication Bypass due to an issue in the verify function where signatures of different lengths …

Feb 13, 2024
CVE-2024-25643
4.3 MEDIUM

The SAP Fiori app (My Overtime Request) - version 605, does not perform the necessary authorization checks for an authenticated user which may result in …

Feb 13, 2024
CVE-2024-24741
4.3 MEDIUM

SAP Master Data Governance for Material Data - versions 618, 619, 620, 621, 622, 800, 801, 802, 803, 804, does not perform necessary authorization check …

Feb 13, 2024
CVE-2024-22129
5.4 MEDIUM

SAP Companion - version <3.1.38, has a URL with parameter that could be vulnerable to XSS attack. The attacker could send a malicious link to …

Feb 13, 2024
CVE-2024-24742
4.1 MEDIUM

SAP CRM WebClient UI - version S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, WEBCUIF 701, WEBCUIF 731, WEBCUIF 746, WEBCUIF 747, WEBCUIF …

Feb 13, 2024
CVE-2024-24740
5.3 MEDIUM

SAP NetWeaver Application Server (ABAP) - versions KERNEL 7.53, KERNEL 7.54, KERNEL 7.77, KERNEL 7.85, KERNEL 7.89, KERNEL 7.93, KERNEL 7.94, KRNL64UC 7.53, under certain …

Feb 13, 2024
CVE-2024-24739
6.3 MEDIUM

SAP Bank Account Management (BAM) allows an authenticated user with restricted access to use functions which can result in escalation of privileges with low impact …

Feb 13, 2024
CVE-2023-50358
5.8 MEDIUM

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands …

Feb 13, 2024
CVE-2023-47218
5.8 MEDIUM

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands …

Feb 13, 2024
CVE-2024-22128
4.7 MEDIUM

SAP NWBC for HTML - versions SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, does not sufficiently …

Feb 13, 2024
CVE-2024-22126
6.1 MEDIUM

The User Admin application of SAP NetWeaver AS for Java - version 7.50, insufficiently validates and improperly encodes the incoming URL parameters before including them …

Feb 13, 2024
CVE-2023-52060
4.3 MEDIUM

A Cross-Site Request Forgery (CSRF) in Gestsup v3.2.46 allows attackers to arbitrarily edit user profile information via a crafted request.

Feb 13, 2024
CVE-2023-52059
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability in Gestsup v3.2.46 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description …

Feb 13, 2024
CVE-2023-49339
6.5 MEDIUM

Ellucian Banner 9.17 allows Insecure Direct Object Reference (IDOR) via a modified bannerId to the /StudentSelfService/ssb/studentCard/retrieveData endpoint.

Feb 13, 2024
CVE-2024-25112
5.5 MEDIUM

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A denial-of-service was found in Exiv2 …

Feb 12, 2024
CVE-2024-24826
5.5 MEDIUM

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in …

Feb 12, 2024
CVE-2023-52430
6.1 MEDIUM

The caddy-security plugin 1.1.20 for Caddy allows reflected XSS via a GET request to a URL that contains an XSS payload and begins with either …

Feb 12, 2024
CVE-2023-28018
5.5 MEDIUM

HCL Connections is vulnerable to a denial of service, caused by improper validation on certain requests. Using a specially-crafted request an attacker could exploit this …

Feb 12, 2024
CVE-2024-1459
5.3 MEDIUM

A path traversal vulnerability was found in Undertow. This issue may allow a remote attacker to append a specially-crafted sequence to an HTTP request for …

Feb 12, 2024
CVE-2024-1250
6.5 MEDIUM

An issue has been discovered in GitLab EE affecting all versions starting from 16.8 before 16.8.2. When a user is assigned a custom role with …

Feb 12, 2024
CVE-2022-22506
4.6 MEDIUM

IBM Robotic Process Automation 21.0.2 contains a vulnerability that could allow user ids may be exposed across tenants. IBM X-Force ID: 227293.

Feb 12, 2024
CVE-2024-22230
6.4 MEDIUM

Dell Unity, versions prior to 5.4, contains a Cross-site scripting vulnerability. An authenticated attacker could potentially exploit this vulnerability, stealing session information, masquerading as the …

Feb 12, 2024
CVE-2024-22221
4.5 MEDIUM

Dell Unity, versions prior to 5.4, contains SQL Injection vulnerability. An authenticated attacker could potentially exploit this vulnerability, leading to exposure of sensitive information.

Feb 12, 2024
CVE-2024-0169
5.7 MEDIUM

Dell Unity, version(s) 5.3 and prior, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A low privileged attacker with remote …

Feb 12, 2024
CVE-2022-34311
4.3 MEDIUM

IBM CICS TX Standard and Advanced 11.1 could allow a user with physical access to the web browser to gain access to the user's session …

Feb 12, 2024
CVE-2022-34309
5.9 MEDIUM

IBM CICS TX Standard and Advanced 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force …

Feb 12, 2024
CVE-2022-38714
4.9 MEDIUM

IBM DataStage on Cloud Pak for Data 4.0.6 to 4.5.2 stores sensitive credential information that can be read by a privileged user. IBM X-Force ID: …

Feb 12, 2024
CVE-2022-34310
5.9 MEDIUM

IBM CICS TX Standard and Advanced 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force …

Feb 12, 2024
CVE-2024-25360
5.3 MEDIUM

A hidden interface in Motorola CX2L Router firmware v1.0.1 leaks information regarding the SystemWizardStatus component via sending a crafted request to device_web_ip.

Feb 12, 2024
CVE-2024-0421
5.3 MEDIUM

The MapPress Maps for WordPress plugin before 2.88.16 is affected by an IDOR as it does not ensure that posts to be retrieve via an …

Feb 12, 2024
CVE-2024-0420
5.4 MEDIUM

The MapPress Maps for WordPress plugin before 2.88.15 does not sanitize and escape the map title when outputting it back in the admin dashboard, allowing …

Feb 12, 2024
CVE-2024-0250
6.1 MEDIUM

The Analytics Insights for Google Analytics 4 (AIWP) WordPress plugin before 6.3 is vulnerable to Open Redirect due to insufficient validation on the redirect oauth2callback.php …

Feb 12, 2024
CVE-2024-0248
4.3 MEDIUM

The EazyDocs WordPress plugin before 2.4.0 re-introduced CVE-2023-6029 (https://wpscan.com/vulnerability/7a0aaf85-8130-4fd7-8f09-f8edc929597e/) in 2.3.8, allowing any authenticated users, such as subscriber to delete arbitrary posts, as well as …

Feb 12, 2024
CVE-2023-7233
4.8 MEDIUM

The GigPress WordPress plugin through 2.3.29 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Feb 12, 2024
CVE-2023-6591
4.8 MEDIUM

The Popup Box WordPress plugin before 20.9.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Feb 12, 2024
CVE-2023-6501
4.3 MEDIUM

The Splashscreen WordPress plugin through 0.20 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged …

Feb 12, 2024
CVE-2023-6499
5.4 MEDIUM

The lasTunes WordPress plugin through 3.6.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow …

Feb 12, 2024
CVE-2023-6082
5.4 MEDIUM

The chartjs WordPress plugin through 2023.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Feb 12, 2024
CVE-2023-6081
5.4 MEDIUM

The chartjs WordPress plugin through 2023.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Feb 12, 2024
CVE-2023-6681
5.3 MEDIUM

A vulnerability was found in JWCrypto. This flaw allows an attacker to cause a denial of service (DoS) attack and possible password brute-force and dictionary …

Feb 12, 2024
CVE-2024-1062
5.5 MEDIUM

A heap overflow flaw was found in 389-ds-base. This issue leads to a denial of service when writing a value larger than 256 chars in …

Feb 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.