CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-0596
5.3 MEDIUM

The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check …

Feb 10, 2024
CVE-2024-0595
4.3 MEDIUM

The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the …

Feb 10, 2024
CVE-2024-1405
4.3 MEDIUM

A vulnerability was found in Linksys WRT54GL 4.30.18. It has been classified as problematic. This affects an unknown part of the file /wlaninfo.htm of the …

Feb 10, 2024
CVE-2023-45698
4.8 MEDIUM

Sametime is impacted by lack of clickjacking protection in Outlook add-in. The application is not implementing appropriate protections in order to protect users from clickjacking …

Feb 10, 2024
CVE-2023-45696
4.0 MEDIUM

Sametime is impacted by sensitive fields with autocomplete enabled in the Legacy web chat client. By default, this allows user entered data to be stored …

Feb 10, 2024
CVE-2023-28077
4.4 MEDIUM

Dell BSAFE SSL-J, versions prior to 6.5, and versions 7.0 and 7.1 contain a debug message revealing unnecessary information vulnerability. This may lead to disclosing …

Feb 10, 2024
CVE-2024-25109
6.5 MEDIUM

ManageWiki is a MediaWiki extension allowing users to manage wikis. Special:ManageWiki does not escape escape interface messages on the `columns` and `help` keys on the …

Feb 9, 2024
CVE-2024-24828
6.6 MEDIUM

pkg is tool design to bundle Node.js projects into an executables. Any native code packages built by `pkg` are written to a hardcoded directory. On …

Feb 9, 2024
CVE-2024-23323
4.3 MEDIUM

Envoy is a high-performance edge/middle/service proxy. The regex expression is compiled for every request and can result in high CPU usage and increased request latency …

Feb 9, 2024
CVE-2024-21624
5.7 MEDIUM

nonebot2 is a cross-platform Python asynchronous chatbot framework written in Python. This security advisory pertains to a potential information leak (e.g., environment variables) in instances …

Feb 9, 2024
CVE-2024-1404
4.3 MEDIUM

A vulnerability was found in Linksys WRT54GL 4.30.18 and classified as problematic. Affected by this issue is some unknown functionality of the file /SysInfo.htm of …

Feb 9, 2024
CVE-2023-6935
5.9 MEDIUM

wolfSSL SP Math All RSA implementation is vulnerable to the Marvin Attack, new variation of a timing Bleichenbacher style attack, when built with the following …

Feb 9, 2024
CVE-2023-50349
5.9 MEDIUM

Sametime is impacted by a Cross Site Request Forgery (CSRF) vulnerability. Some REST APIs in the Sametime Proxy application can allow an attacker to perform …

Feb 9, 2024
CVE-2024-1402
4.3 MEDIUM

Mattermost fails to check if a custom emoji reaction exists when sending it to a post and to limit the amount of custom emojis allowed …

Feb 9, 2024
CVE-2024-25454
5.5 MEDIUM

Bento4 v1.6.0-640 was discovered to contain a NULL pointer dereference via the AP4_DescriptorFinder::Test() function.

Feb 9, 2024
CVE-2024-25453
5.5 MEDIUM

Bento4 v1.6.0-640 was discovered to contain a NULL pointer dereference via the AP4_StszAtom::GetSampleSize() function.

Feb 9, 2024
CVE-2024-25452
5.5 MEDIUM

Bento4 v1.6.0-640 was discovered to contain an out-of-memory bug via the AP4_UrlAtom::AP4_UrlAtom() function.

Feb 9, 2024
CVE-2024-25451
6.5 MEDIUM

Bento4 v1.6.0-640 was discovered to contain an out-of-memory bug via the AP4_DataBuffer::ReallocateBuffer() function.

Feb 9, 2024
CVE-2024-25679
6.5 MEDIUM

In PQUIC before 5bde5bb, retention of unused initial encryption keys allows attackers to disrupt a connection with a PSK configuration by sending a CONNECTION_CLOSE frame …

Feb 9, 2024
CVE-2024-22119
5.5 MEDIUM

The cause of vulnerability is improper validation of form input field “Name” on Graph page in Items section.

Feb 9, 2024
CVE-2023-39683
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in EasyEmail v.4.12.2 and before allows a local attacker to execute arbitrary code via the user input parameter(s). NOTE: Researcher …

Feb 9, 2024
CVE-2023-31506
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability in Grav versions 1.7.44 and before, allows remote authenticated attackers to execute arbitrary web scripts or HTML via the onmouseover …

Feb 9, 2024
CVE-2024-1122
5.3 MEDIUM

The Event Manager, Events Calendar, Events Tickets for WooCommerce – Eventin plugin for WordPress is vulnerable to unauthorized access of data due to a missing …

Feb 9, 2024
CVE-2024-0657
4.4 MEDIUM

The Internal Link Juicer: SEO Auto Linker for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings such as 'ilj_settings_field_links_per_page' in …

Feb 9, 2024
CVE-2023-49716
6.9 MEDIUM

In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an authenticated user with network access could run arbitrary commands from a remote computer.

Feb 9, 2024
CVE-2023-43609
6.9 MEDIUM

In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could obtain access to sensitive information or cause a denial-of-service condition.

Feb 9, 2024
CVE-2024-24819
5.3 MEDIUM

icingaweb2-module-incubator is a working project of bleeding edge Icinga Web 2 libraries. In affected versions the class `gipfl\Web\Form` is the base for various concrete form …

Feb 9, 2024
CVE-2024-23639
5.1 MEDIUM

Micronaut Framework is a modern, JVM-based, full stack Java framework designed for building modular, easily testable JVM applications with support for Java, Kotlin and the …

Feb 9, 2024
CVE-2024-22332
6.5 MEDIUM

The IBM Integration Bus for z/OS 10.1 through 10.1.0.2 AdminAPI is vulnerable to a denial of service due to file system exhaustion. IBM X-Force ID: …

Feb 9, 2024
CVE-2024-22318
5.1 MEDIUM

IBM i Access Client Solutions (ACS) 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.4 is vulnerable to NT LAN Manager (NTLM) hash disclosure by an attacker …

Feb 9, 2024
CVE-2024-1353
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in PHPEMS up to 1.0. Affected by this issue is the function index of the …

Feb 9, 2024
CVE-2023-45190
5.1 MEDIUM

IBM Engineering Lifecycle Optimization 7.0.2 and 7.0.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could …

Feb 9, 2024
CVE-2023-45187
6.3 MEDIUM

IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 does not invalidate session after logout which could allow an authenticated user to impersonate another user …

Feb 9, 2024
CVE-2023-42016
4.3 MEDIUM

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.3 does not set the secure attribute on authorization tokens or session cookies. …

Feb 9, 2024
CVE-2023-32341
6.5 MEDIUM

IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.3 could allow an authenticated user to cause a denial of service due to uncontrolled …

Feb 9, 2024
CVE-2024-24829
4.3 MEDIUM

Sentry is an error tracking and performance monitoring platform. Sentry’s integration platform provides a way for external services to interact with Sentry. One of such …

Feb 9, 2024
CVE-2024-25107
4.9 MEDIUM

WikiDiscover is an extension designed for use with a CreateWiki managed farm to display wikis. On Special:WikiDiscover, the `Language::date` function is used when making the …

Feb 8, 2024
CVE-2023-51630
6.1 MEDIUM

Paessler PRTG Network Monitor Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Paessler PRTG Network Monitor. …

Feb 8, 2024
CVE-2023-40264
4.3 MEDIUM

An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11. It allows authenticated path traversal in the user interface.

Feb 8, 2024
CVE-2023-40262
6.1 MEDIUM

An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11. It allows unauthenticated Stored Cross-Site Scripting (XSS) in the administration …

Feb 8, 2024
CVE-2023-49101
6.1 MEDIUM

WebAdmin in Axigen 10.3.x before 10.3.3.61, 10.4.x before 10.4.24, and 10.5.x before 10.5.10 allows XSS attacks against admins because of mishandling of viewing the usage …

Feb 8, 2024
CVE-2024-24494
6.1 MEDIUM

Cross Site Scripting vulnerability in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbitrary code via the day, exercise, pray, read_book, vitamins, laundry, …

Feb 8, 2024
CVE-2024-24115
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the Edit Page function of Cotonti CMS v0.9.24 allows authenticated attackers to execute arbitrary web scripts or HTML …

Feb 8, 2024
CVE-2024-24215
5.3 MEDIUM

An issue in the component /cgi-bin/GetJsonValue.cgi of Cellinx NVT Web Server 5.0.0.014 allows attackers to leak configuration information via a crafted POST request.

Feb 8, 2024
CVE-2024-23764
6.7 MEDIUM

Certain WithSecure products allow Local Privilege Escalation. This affects WithSecure Client Security 15 and later, WithSecure Server Security 15 and later, WithSecure Email and Server …

Feb 8, 2024
CVE-2024-24834
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realmag777 BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net …

Feb 8, 2024
CVE-2024-24871
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in creativethemeshq Blocksy blocksy.This issue affects Blocksy: from n/a through <= 2.0.19.

Feb 8, 2024
CVE-2024-24836
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Audrasjb GDPR Data Request Form allows Stored XSS.This issue affects GDPR Data Request …

Feb 8, 2024
CVE-2024-1312
5.1 MEDIUM

A use-after-free flaw was found in the Linux kernel's Memory Management subsystem when a user wins two races at the same time with a fail …

Feb 8, 2024
CVE-2023-7169
6.0 MEDIUM

Authentication Bypass by Spoofing vulnerability in Snow Software Snow Inventory Agent on Windows allows Signature Spoof.This issue affects Snow Inventory Agent: through 6.14.5. Customers advised …

Feb 8, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.