CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-24865
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noah Kagan Scroll Triggered Box allows Stored XSS.This issue affects Scroll Triggered Box: …

Feb 5, 2024
CVE-2024-24841
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan's Art Add Customer for WooCommerce allows Stored XSS.This issue affects Add Customer …

Feb 5, 2024
CVE-2024-24839
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gordon Böhme, Antonio Leutsch Structured Content (JSON-LD) #wpsc allows Stored XSS.This issue affects …

Feb 5, 2024
CVE-2024-24838
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Five Star Plugins Five Star Restaurant Reviews allows Stored XSS.This issue affects Five …

Feb 5, 2024
CVE-2024-24870
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Dempfle Advanced iFrame allows Stored XSS.This issue affects Advanced iFrame: from n/a …

Feb 5, 2024
CVE-2024-20016
4.4 MEDIUM

In ged, there is a possible out of bounds write due to an integer overflow. This could lead to local denial of service with System …

Feb 5, 2024
CVE-2024-20013
6.7 MEDIUM

In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Feb 5, 2024
CVE-2024-20012
6.7 MEDIUM

In keyInstall, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege with System execution privileges …

Feb 5, 2024
CVE-2024-20010
6.7 MEDIUM

In keyInstall, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege with System execution privileges …

Feb 5, 2024
CVE-2024-20006
6.7 MEDIUM

In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Feb 5, 2024
CVE-2024-20002
6.7 MEDIUM

In TVAPI, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Feb 5, 2024
CVE-2024-20001
6.7 MEDIUM

In TVAPI, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Feb 5, 2024
CVE-2023-5800
5.4 MEDIUM

Vintage, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API create_overlay.cgi did not have a sufficient input validation allowing for …

Feb 5, 2024
CVE-2023-5677
6.3 MEDIUM

Brandon Rothel from QED Secure Solutions and Sam Hanson of Dragos have found that the VAPIX API tcptest.cgi did not have a sufficient input validation …

Feb 5, 2024
CVE-2023-51504
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan Dulaney Dan's Embedder for Google Calendar allows Stored XSS.This issue affects Dan's …

Feb 5, 2024
CVE-2021-46903
6.5 MEDIUM

An issue was discovered in LTOS-Web-Interface in Meinberg LANTIME-Firmware before 6.24.029 MBGID-9343 and 7 before 7.04.008 MBGID-6303. An admin can delete required user accounts (in …

Feb 4, 2024
CVE-2023-52426
5.5 MEDIUM

libexpat through 2.5.0 allows recursive XML Entity Expansion if XML_DTD is undefined at compile time.

Feb 4, 2024
CVE-2018-25098
4.3 MEDIUM

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in blockmason credit-protocol. It has been declared as problematic. Affected by this vulnerability is the function …

Feb 4, 2024
CVE-2023-6240
6.5 MEDIUM

A Marvin vulnerability side-channel leakage was found in the RSA decryption operation in the Linux Kernel. This issue may allow a network attacker to decrypt …

Feb 4, 2024
CVE-2019-25159
5.5 MEDIUM

A vulnerability was found in mpedraza2020 Intranet del Monterroso up to 4.50.0. It has been classified as critical. This affects an unknown part of the …

Feb 4, 2024
CVE-2023-50947
5.4 MEDIUM

IBM Business Automation Workflow 22.0.2, 23.0.1, and 23.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web …

Feb 4, 2024
CVE-2023-33851
5.3 MEDIUM

IBM PowerVM Hypervisor FW950.00 through FW950.90, FW1020.00 through FW1020.40, and FW1030.00 through FW1030.30 could reveal sensitive partition data to a system administrator. IBM X-Force ID: …

Feb 4, 2024
CVE-2024-0853
5.3 MEDIUM

curl inadvertently kept the SSL session ID for connections in its cache even when the verify status (*OCSP stapling*) test failed. A subsequent transfer to …

Feb 3, 2024
CVE-2023-49950
5.4 MEDIUM

The Jinja templating in Logpoint SIEM 6.10.0 through 7.x before 7.3.0 does not correctly sanitize log data being displayed when using a custom Jinja template …

Feb 3, 2024
CVE-2024-23550
6.2 MEDIUM

HCL DevOps Deploy / HCL Launch (UCD) could disclose sensitive user information when installing the Windows agent.

Feb 3, 2024
CVE-2024-0909
5.3 MEDIUM

The Anonymous Restricted Content plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 1.6.2. This is due to insufficient …

Feb 3, 2024
CVE-2024-0895
5.4 MEDIUM

The PDF Flipbook, 3D Flipbook – DearFlip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via outline settings in all versions up to, and …

Feb 3, 2024
CVE-2023-37528
6.5 MEDIUM

A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attack to exploit an application parameter during …

Feb 3, 2024
CVE-2024-1200
5.3 MEDIUM

A vulnerability was found in Jspxcms 10.2.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /template/1/default/. The manipulation …

Feb 3, 2024
CVE-2023-32329
6.2 MEDIUM

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow a …

Feb 3, 2024
CVE-2023-31006
6.5 MEDIUM

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) is vulnerable to …

Feb 3, 2024
CVE-2023-31005
6.2 MEDIUM

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow a …

Feb 3, 2024
CVE-2024-1199
5.4 MEDIUM

A vulnerability has been found in CodeAstro Employee Task Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of …

Feb 3, 2024
CVE-2024-1198
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in openBI up to 6.0.3. Affected is the function addxinzhi of the file application/controllers/User.php of the …

Feb 3, 2024
CVE-2024-1196
4.3 MEDIUM

A vulnerability classified as problematic was found in SourceCodester Testimonial Page Manager 1.0. This vulnerability affects unknown code of the file add-testimonial.php of the component …

Feb 2, 2024
CVE-2024-1195
5.5 MEDIUM

A vulnerability classified as critical was found in iTop VPN up to 4.0.0.1. Affected by this vulnerability is an unknown functionality in the library ITopVpnCallbackProcess.sys …

Feb 2, 2024
CVE-2024-1189
5.3 MEDIUM

A vulnerability has been found in AMPPS 2.7 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Encryption Passphrase …

Feb 2, 2024
CVE-2023-37527
5.4 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code …

Feb 2, 2024
CVE-2024-23635
6.1 MEDIUM

AntiSamy is a library for performing fast, configurable cleansing of HTML coming from untrusted sources. Prior to 1.7.5, there is a potential for a mutation …

Feb 2, 2024
CVE-2024-24160
5.4 MEDIUM

MRCMS 3.0 contains a Cross-Site Scripting (XSS) vulnerability via /admin/system/saveinfo.do.

Feb 2, 2024
CVE-2024-23824
4.7 MEDIUM

mailcow is a dockerized email package, with multiple containers linked in one bridged network. The application is vulnerable to pixel flood attack, once the payload …

Feb 2, 2024
CVE-2023-47567
4.7 MEDIUM

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute …

Feb 2, 2024
CVE-2023-47566
6.7 MEDIUM

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute …

Feb 2, 2024
CVE-2023-47561
5.5 MEDIUM

A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via …

Feb 2, 2024
CVE-2023-45028
5.5 MEDIUM

An uncontrolled resource consumption vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to launch …

Feb 2, 2024
CVE-2023-45027
5.5 MEDIUM

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to read the …

Feb 2, 2024
CVE-2023-45026
5.5 MEDIUM

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to read the …

Feb 2, 2024
CVE-2023-41283
5.5 MEDIUM

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute …

Feb 2, 2024
CVE-2023-41282
5.5 MEDIUM

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute …

Feb 2, 2024
CVE-2023-41281
5.5 MEDIUM

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute …

Feb 2, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.