CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-41280
5.5 MEDIUM

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow …

Feb 2, 2024
CVE-2023-41279
5.5 MEDIUM

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow …

Feb 2, 2024
CVE-2023-41278
5.5 MEDIUM

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow …

Feb 2, 2024
CVE-2023-41277
5.5 MEDIUM

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow …

Feb 2, 2024
CVE-2023-41276
5.5 MEDIUM

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow …

Feb 2, 2024
CVE-2023-41275
5.5 MEDIUM

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow …

Feb 2, 2024
CVE-2023-41274
5.5 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to launch …

Feb 2, 2024
CVE-2023-41273
5.5 MEDIUM

A heap-based buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute …

Feb 2, 2024
CVE-2023-39303
5.3 MEDIUM

An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to compromise the security …

Feb 2, 2024
CVE-2023-39302
6.6 MEDIUM

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute …

Feb 2, 2024
CVE-2023-32967
5.0 MEDIUM

An incorrect authorization vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to bypass intended …

Feb 2, 2024
CVE-2021-21575
5.9 MEDIUM

Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain an Observable Timing Discrepancy Vulnerability.

Feb 2, 2024
CVE-2023-6673
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in National Keep Cyber Security Services CyberMath allows Reflected XSS.This issue affects CyberMath: from …

Feb 2, 2024
CVE-2023-6672
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in National Keep Cyber Security Services CyberMath allows Stored XSS.This issue affects CyberMath: from …

Feb 2, 2024
CVE-2023-47148
5.3 MEDIUM

IBM Storage Protect Plus Server 10.1.0 through 10.1.15.2 Admin Console could allow a remote attacker to obtain sensitive information due to improper validation of unsecured …

Feb 2, 2024
CVE-2023-47144
6.1 MEDIUM

IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the …

Feb 2, 2024
CVE-2024-0963
6.4 MEDIUM

The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's CP_CALCULATED_FIELDS shortcode in all versions up to, and including, …

Feb 2, 2024
CVE-2024-0844
4.7 MEDIUM

The Popup More Popups, Lightboxes, and more popup modules plugin for WordPress is vulnerable to Local File Inclusion in version 2.1.6 via the ycfChangeElementData() function. …

Feb 2, 2024
CVE-2024-24388
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability in XunRuiCMS versions v4.6.2 and before, allows remote attackers to obtain sensitive information via crafted malicious requests to the background login.

Feb 2, 2024
CVE-2023-51820
6.8 MEDIUM

An issue in Blurams Lumi Security Camera (A31C) v.2.3.38.12558 allows a physically proximate attackers to execute arbitrary code.

Feb 2, 2024
CVE-2023-51072
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the NOC component of Nagios XI version up to and including 2024R1 allows low-privileged users to execute malicious …

Feb 2, 2024
CVE-2021-22281
6.3 MEDIUM

: Relative Path Traversal vulnerability in B&R Industrial Automation Automation Studio allows Relative Path Traversal.This issue affects Automation Studio: from 4.0 through 4.12.

Feb 2, 2024
CVE-2024-21863
4.7 MEDIUM

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through improper input.

Feb 2, 2024
CVE-2024-0285
4.7 MEDIUM

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through improper input.

Feb 2, 2024
CVE-2023-45734
4.2 MEDIUM

in OpenHarmony v3.2.4 and prior versions allow an adjacent attacker arbitrary code execution through out-of-bounds write.

Feb 2, 2024
CVE-2024-1162
4.3 MEDIUM

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.10.29. This is due …

Feb 2, 2024
CVE-2024-1047
5.3 MEDIUM

Multiple plugins and/or themes for WordPress with the ThemeIsle SDK are vulnerable to unauthorized modification of data due to a missing capability check on the …

Feb 2, 2024
CVE-2024-21485
6.5 MEDIUM

Versions of the package dash-core-components before 2.13.0; versions of the package dash-core-components before 2.0.0; versions of the package dash before 2.15.0; versions of the package …

Feb 2, 2024
CVE-2024-1073
6.4 MEDIUM

The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'filter_array' parameter in all versions up to, and including, 5.1.3 due …

Feb 2, 2024
CVE-2024-0685
5.9 MEDIUM

The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Second Order SQL Injection via …

Feb 2, 2024
CVE-2023-38263
6.5 MEDIUM

IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow an authenticated user to perform unauthorized actions due to improper access controls. IBM X-Force ID: …

Feb 2, 2024
CVE-2023-38020
4.3 MEDIUM

IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow an authenticated user to manipulate output written to log files. IBM X-Force ID: 260576.

Feb 2, 2024
CVE-2022-40744
4.8 MEDIUM

IBM Aspera Faspex 5.0.6 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering …

Feb 2, 2024
CVE-2023-50962
5.9 MEDIUM

IBM PowerSC 1.3, 2.0, and 2.1 MFA does not implement the "HTTP Strict Transport Security" (HSTS) web security policy mechanism. IBM X-Force ID: 276004.

Feb 2, 2024
CVE-2023-50941
6.3 MEDIUM

IBM PowerSC 1.3, 2.0, and 2.1 does not provide logout functionality, which could allow an authenticated user to gain access to an unauthorized user using …

Feb 2, 2024
CVE-2023-50938
6.5 MEDIUM

IBM PowerSC 1.3, 2.0, and 2.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit …

Feb 2, 2024
CVE-2023-50935
6.5 MEDIUM

IBM PowerSC 1.3, 2.0, and 2.1 fails to properly restrict access to a URL or resource, which may allow a remote attacker to obtain unauthorized …

Feb 2, 2024
CVE-2023-50934
5.3 MEDIUM

IBM PowerSC 1.3, 2.0, and 2.1 uses single-factor authentication which can lead to unnecessary risk of compromise when compared with the benefits of a dual-factor …

Feb 2, 2024
CVE-2023-46344
5.4 MEDIUM

A vulnerability in Solar-Log Base 15 Firmware 6.0.1 Build 161, and possibly other Solar-Log Base products, allows an attacker to escalate their privileges by exploiting …

Feb 2, 2024
CVE-2023-32333
6.5 MEDIUM

IBM Maximo Asset Management 7.6.1.3 could allow a remote attacker to log into the admin panel due to improper access controls. IBM X-Force ID: 255073.

Feb 2, 2024
CVE-2023-50940
5.3 MEDIUM

IBM PowerSC 1.3, 2.0, and 2.1 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information …

Feb 2, 2024
CVE-2023-50937
5.9 MEDIUM

IBM PowerSC 1.3, 2.0, and 2.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: …

Feb 2, 2024
CVE-2023-50936
6.3 MEDIUM

IBM PowerSC 1.3, 2.0, and 2.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. …

Feb 2, 2024
CVE-2023-50933
6.1 MEDIUM

IBM PowerSC 1.3, 2.0, and 2.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed …

Feb 2, 2024
CVE-2023-50327
5.3 MEDIUM

IBM PowerSC 1.3, 2.0, and 2.1 uses insecure HTTP methods which could allow a remote attacker to perform unauthorized file request modification. IBM X-Force ID: …

Feb 2, 2024
CVE-2024-22096
6.5 MEDIUM

In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an attacker can append path traversal characters to the filename when using a specific …

Feb 2, 2024
CVE-2024-21869
6.2 MEDIUM

In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the affected product stores plaintext credentials in various places. This may allow an attacker …

Feb 2, 2024
CVE-2024-21866
5.3 MEDIUM

In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the affected product responds back with an error message containing sensitive data if it …

Feb 2, 2024
CVE-2024-21794
5.4 MEDIUM

In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an attacker can redirect users to malicious pages through the login page.

Feb 2, 2024
CVE-2023-50939
5.9 MEDIUM

IBM PowerSC 1.3, 2.0, and 2.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: …

Feb 2, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.