CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-1264
6.3 MEDIUM

A vulnerability has been found in Juanpao JPShop up to 1.5.02 and classified as critical. Affected by this vulnerability is the function actionUpdate of the …

Feb 7, 2024
CVE-2024-0971
6.5 MEDIUM

A SQL injection vulnerability exists where an authenticated, low-privileged remote attacker could potentially alter scan DB content.

Feb 7, 2024
CVE-2024-0955
4.8 MEDIUM

A stored XSS vulnerability exists where an authenticated, remote attacker with administrator privileges on the Nessus application could alter Nessus proxy settings, which could lead …

Feb 7, 2024
CVE-2024-24255
4.2 MEDIUM

A Race Condition discovered in geofence.cpp and mission_feasibility_checker.cpp in PX4 Autopilot 1.14 and earlier allows attackers to send drones on unintended missions.

Feb 6, 2024
CVE-2024-22388
5.9 MEDIUM

Certain configuration available in the communication channel for encoders could expose sensitive data when reader configuration cards are programmed. This data could include credential and …

Feb 6, 2024
CVE-2024-1263
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Juanpao JPShop up to 1.5.02. Affected is the function actionUpdate of the file /api/controllers/merchant/shop/PosterController.php of …

Feb 6, 2024
CVE-2024-1262
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Juanpao JPShop up to 1.5.02. This issue affects the function actionUpdate of the file …

Feb 6, 2024
CVE-2024-24254
4.2 MEDIUM

PX4 Autopilot 1.14 and earlier, due to the lack of synchronization mechanism for loading geofence data, has a Race Condition vulnerability in the geofence.cpp and …

Feb 6, 2024
CVE-2024-1261
6.3 MEDIUM

A vulnerability classified as critical was found in Juanpao JPShop up to 1.5.02. This vulnerability affects the function actionIndex of the file /api/controllers/merchant/app/ComboController.php of the …

Feb 6, 2024
CVE-2024-1260
6.3 MEDIUM

A vulnerability classified as critical has been found in Juanpao JPShop up to 1.5.02. This affects the function actionIndex of the file /api/controllers/admin/app/ComboController.php of the …

Feb 6, 2024
CVE-2023-45227
5.4 MEDIUM

An attacker with access to the web application with vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scripting payload into the "dns.0.server" parameter.

Feb 6, 2024
CVE-2023-45222
5.4 MEDIUM

An attacker with access to the web application that has the vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scripting payload into the …

Feb 6, 2024
CVE-2023-45213
6.6 MEDIUM

A potential attacker with access to the Westermo Lynx device would be able to execute malicious code that could affect the correct functioning of the …

Feb 6, 2024
CVE-2023-42765
5.4 MEDIUM

An attacker with access to the vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scripting payload into the "username" parameter in the SNMP …

Feb 6, 2024
CVE-2023-40544
5.7 MEDIUM

An attacker with access to the network where the affected devices are located could maliciously actions to obtain, via a sniffer, sensitive information exchanged via …

Feb 6, 2024
CVE-2023-40143
5.4 MEDIUM

An attacker with access to the Westermo Lynx web application that has the vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scripting payload …

Feb 6, 2024
CVE-2024-1259
6.3 MEDIUM

A vulnerability was found in Juanpao JPShop up to 1.5.02. It has been rated as critical. Affected by this issue is some unknown functionality of …

Feb 6, 2024
CVE-2024-22241
4.3 MEDIUM

Aria Operations for Networks contains a cross site scripting vulnerability. A malicious actor with admin privileges can inject a malicious payload into the login banner …

Feb 6, 2024
CVE-2024-22240
4.9 MEDIUM

Aria Operations for Networks contains a local file read vulnerability. A malicious actor with admin privileges may exploit this vulnerability leading to unauthorized access to …

Feb 6, 2024
CVE-2024-22239
5.3 MEDIUM

Aria Operations for Networks contains a local privilege escalation vulnerability. A console user with access to Aria Operations for Networks may exploit this vulnerability to …

Feb 6, 2024
CVE-2024-22238
6.4 MEDIUM

Aria Operations for Networks contains a cross site scripting vulnerability. A malicious actor with admin privileges may be able to inject malicious code into user …

Feb 6, 2024
CVE-2024-1255
5.3 MEDIUM

A vulnerability has been found in sepidz SepidzDigitalMenu up to 7.1.0728.1 and classified as problematic. This vulnerability affects unknown code of the file /Waiters. The …

Feb 6, 2024
CVE-2024-1254
4.7 MEDIUM

A vulnerability, which was classified as critical, was found in Byzoro Smart S20 Management Platform up to 20231120. This affects an unknown part of the …

Feb 6, 2024
CVE-2024-22331
6.2 MEDIUM

IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.19, 7.1 through 7.1.2.15, 7.2 through 7.2.3.8, 7.3 through 7.3.2.3, and IBM UrbanCode Deploy (UCD) - IBM DevOps Deploy …

Feb 6, 2024
CVE-2024-1253
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in Byzoro Smart S40 Management Platform up to 20240126. Affected by this issue is some …

Feb 6, 2024
CVE-2024-1252
5.5 MEDIUM

A vulnerability classified as critical was found in Tongda OA 2017 up to 11.9. Affected by this vulnerability is an unknown functionality of the file …

Feb 6, 2024
CVE-2024-24291
6.1 MEDIUM

An issue in the component /member/index/login of yzmcms v7.0 allows attackers to direct users to malicious sites via a crafted URL.

Feb 6, 2024
CVE-2024-23344
5.3 MEDIUM

Tuleap is an Open Source Suite to improve management of software developments and collaboration. Some users might get access to restricted information when a process …

Feb 6, 2024
CVE-2024-1251
5.5 MEDIUM

A vulnerability classified as critical has been found in Tongda OA 2017 up to 11.10. Affected is an unknown function of the file /general/email/outbox/delete.php. The …

Feb 6, 2024
CVE-2023-46183
5.3 MEDIUM

IBM PowerVM Hypervisor FW950.00 through FW950.90, FW1020.00 through FW1020.40, and FW1030.00 through FW1030.30 could allow a system administrator to obtain sensitive partition information. IBM X-Force …

Feb 6, 2024
CVE-2024-0911
5.5 MEDIUM

A flaw was found in indent, a program for formatting C code. This issue may allow an attacker to trick a user into processing a …

Feb 6, 2024
CVE-2024-0690
5.0 MEDIUM

An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in …

Feb 6, 2024
CVE-2024-24943
5.3 MEDIUM

In JetBrains Toolbox App before 2.2 a DoS attack was possible via a malicious SVG image

Feb 6, 2024
CVE-2024-24942
5.3 MEDIUM

In JetBrains TeamCity before 2023.11.3 path traversal allowed reading data within JAR archives

Feb 6, 2024
CVE-2024-24941
6.1 MEDIUM

In JetBrains IntelliJ IDEA before 2023.3.3 a plugin for JetBrains Space was able to send an authentication token to an inappropriate URL

Feb 6, 2024
CVE-2024-24938
5.3 MEDIUM

In JetBrains TeamCity before 2023.11.2 limited directory traversal was possible in the Kotlin DSL documentation

Feb 6, 2024
CVE-2024-24937
4.6 MEDIUM

In JetBrains TeamCity before 2023.11.2 stored XSS via agent distribution was possible

Feb 6, 2024
CVE-2024-24936
4.3 MEDIUM

In JetBrains TeamCity before 2023.11.2 access control at the S3 Artifact Storage plugin endpoint was missed

Feb 6, 2024
CVE-2024-0684
5.5 MEDIUM

A flaw was found in the GNU coreutils "split" program. A heap overflow with user-controlled data of multiple hundred bytes in length could occur in …

Feb 6, 2024
CVE-2023-4503
6.8 MEDIUM

An improper initialization vulnerability was found in Galleon. When using Galleon to provision custom EAP or EAP-XP servers, the servers are created unsecured. This issue …

Feb 6, 2024
CVE-2024-22365
5.5 MEDIUM

linux-pam (aka Linux PAM) before 1.6.0 allows attackers to cause a denial of service (blocked login process) via mkfifo because the openat call (for protect_dir) …

Feb 6, 2024
CVE-2023-32479
6.7 MEDIUM

Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server versions prior to 11.9.0 contain privilege escalation vulnerability due to improper ACL of …

Feb 6, 2024
CVE-2023-32474
6.6 MEDIUM

Dell Display Manager application, version 2.1.1.17 and prior, contain an insecure operation on windows junction/mount point. A local malicious user could potentially exploit this vulnerability …

Feb 6, 2024
CVE-2023-32454
6.3 MEDIUM

DUP framework version 4.9.4.36 and prior contains insecure operation on Windows junction/Mount point vulnerability. A local malicious standard user could exploit the vulnerability to create …

Feb 6, 2024
CVE-2023-28063
6.7 MEDIUM

Dell BIOS contains a Signed to Unsigned Conversion Error vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to …

Feb 6, 2024
CVE-2023-52239
6.5 MEDIUM

The XML parser in Magic xpi Integration Platform 4.13.4 allows XXE attacks, e.g., via onItemImport.

Feb 6, 2024
CVE-2023-28049
4.7 MEDIUM

Dell Command | Monitor, versions prior to 10.9, contain an arbitrary folder deletion vulnerability. A locally authenticated malicious user may exploit this vulnerability in order …

Feb 6, 2024
CVE-2023-33077
6.7 MEDIUM

Memory corruption in HLOS while converting from authorization token to HIDL vector.

Feb 6, 2024
CVE-2023-33076
5.9 MEDIUM

Memory corruption in Core when updating rollback version for TA and OTA feature is enabled.

Feb 6, 2024
CVE-2023-33069
6.7 MEDIUM

Memory corruption in Audio while processing the calibration data returned from ACDB loader.

Feb 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.