CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-23307
4.4 MEDIUM

Integer Overflow or Wraparound vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (md, raid, raid5 modules) allows Forced Integer Overflow.

Jan 25, 2024
CVE-2024-22099
6.3 MEDIUM

NULL Pointer Dereference vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (net, bluetooth modules) allows Overflow Buffers. This vulnerability is associated with program …

Jan 25, 2024
CVE-2024-0625
4.4 MEDIUM

The WPFront Notification Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpfront-notification-bar-options[custom_class]’ parameter in all versions up to, and including, 3.3.2 …

Jan 25, 2024
CVE-2024-0688
4.4 MEDIUM

The "WebSub (FKA. PubSubHubbub)" plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings in all versions up to, and including, 3.1.4 due …

Jan 25, 2024
CVE-2024-0624
5.3 MEDIUM

The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up …

Jan 25, 2024
CVE-2024-0617
5.3 MEDIUM

The Category Discount Woocommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpcd_save_discount() function in …

Jan 25, 2024
CVE-2024-23644
6.8 MEDIUM

Trillium is a composable toolkit for building internet applications with async rust. In `trillium-http` prior to 0.3.12 and `trillium-client` prior to 0.5.4, insufficient validation of …

Jan 24, 2024
CVE-2021-43584
4.8 MEDIUM

DOM-based Cross Site Scripting (XSS vulnerability in 'Tail Event Logs' functionality in Nagios Nagios Cross-Platform Agent (NCPA) before 2.4.0 allows attackers to run arbitrary code …

Jan 24, 2024
CVE-2024-23905
5.4 MEDIUM

Jenkins Red Hat Dependency Analytics Plugin 0.7.1 and earlier programmatically disables Content-Security-Policy protection for user-generated content in workspaces, archived artifacts, etc. that Jenkins offers for …

Jan 24, 2024
CVE-2024-23903
5.3 MEDIUM

Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, …

Jan 24, 2024
CVE-2024-23902
4.3 MEDIUM

A cross-site request forgery (CSRF) vulnerability in Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier allows attackers to connect to an attacker-specified URL.

Jan 24, 2024
CVE-2024-23901
6.5 MEDIUM

Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier unconditionally discovers projects that are shared with the configured owner group, allowing attackers to configure and share …

Jan 24, 2024
CVE-2024-23900
4.3 MEDIUM

Jenkins Matrix Project Plugin 822.v01b_8c85d16d2 and earlier does not sanitize user-defined axis names of multi-configuration projects, allowing attackers with Item/Configure permission to create or replace …

Jan 24, 2024
CVE-2024-23899
6.5 MEDIUM

Jenkins Git server Plugin 99.va_0826a_b_cdfa_d and earlier does not disable a feature of its command parser that replaces an '@' character followed by a file …

Jan 24, 2024
CVE-2024-22720
4.8 MEDIUM

Kanboard 1.2.34 is vulnerable to Html Injection in the group management feature.

Jan 24, 2024
CVE-2024-22725
6.1 MEDIUM

Orthanc versions before 1.12.2 are affected by a reflected cross-site scripting (XSS) vulnerability. The vulnerability was present in the server's error reporting.

Jan 24, 2024
CVE-2023-44281
6.6 MEDIUM

Dell Pair Installer version prior to 1.2.1 contains an elevation of privilege vulnerability. A low privilege user with local access to the system could potentially …

Jan 24, 2024
CVE-2024-22141
6.5 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Cozmoslabs Profile Builder Pro.This issue affects Profile Builder Pro: from n/a through 3.10.0.

Jan 24, 2024
CVE-2023-6697
6.1 MEDIUM

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the map id parameter in all versions …

Jan 24, 2024
CVE-2023-51702
6.5 MEDIUM

Since version 5.2.0, when using deferrable mode with the path of a Kubernetes configuration file for authentication, the Airflow worker serializes this configuration file as …

Jan 24, 2024
CVE-2023-50944
6.5 MEDIUM

Apache Airflow, versions before 2.8.1, have a vulnerability that allows an authenticated user to access the source code of a DAG to which they don't …

Jan 24, 2024
CVE-2024-22301
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ignazio Scimone Albo Pretorio On line.This issue affects Albo Pretorio On line: from n/a through …

Jan 24, 2024
CVE-2024-22294
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in IP2Location IP2Location Country Blocker.This issue affects IP2Location Country Blocker: from n/a through 2.33.3.

Jan 24, 2024
CVE-2024-22134
4.9 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in Renzo Johnson Contact Form 7 Extension For Mailchimp.This issue affects Contact Form 7 Extension For Mailchimp: from n/a through …

Jan 24, 2024
CVE-2024-0854
5.4 MEDIUM

URL redirection to untrusted site ('Open Redirect') vulnerability in file access component in Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.0.1-42218-7, 7.1.1-42962-7 and 7.2.1-69057-2 allows remote …

Jan 24, 2024
CVE-2023-44001
5.4 MEDIUM

An issue in Ailand clinic mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 24, 2024
CVE-2023-44000
5.4 MEDIUM

An issue in Otakara lapis totuka mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 24, 2024
CVE-2023-43999
5.4 MEDIUM

An issue in COLORFUL_laundry mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 24, 2024
CVE-2023-43998
5.4 MEDIUM

An issue in Books-futaba mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 24, 2024
CVE-2023-43997
5.4 MEDIUM

An issue in Yoruichi hobby base mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 24, 2024
CVE-2023-43996
5.4 MEDIUM

An issue in Q co ltd mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 24, 2024
CVE-2023-43995
5.4 MEDIUM

An issue in picot.golf mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 24, 2024
CVE-2023-43994
5.4 MEDIUM

An issue in Cleaning_makotoya mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 24, 2024
CVE-2023-43993
5.4 MEDIUM

An issue in smaregi_app_market mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 24, 2024
CVE-2023-43992
5.4 MEDIUM

An issue in STOCKMAN GROUP mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 24, 2024
CVE-2023-43991
5.4 MEDIUM

An issue in PRIMA CLINIC mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 24, 2024
CVE-2023-43990
5.4 MEDIUM

An issue in cherub-hair mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 24, 2024
CVE-2023-43989
5.4 MEDIUM

An issue in mokumoku chohu mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 24, 2024
CVE-2023-43988
5.4 MEDIUM

An issue in nature fitness saijo mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

Jan 24, 2024
CVE-2024-0665
6.1 MEDIUM

The WP Customer Area plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 8.2.1 …

Jan 24, 2024
CVE-2024-22372
6.8 MEDIUM

OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent attacker with an administrative privilege to execute arbitrary OS commands by sending a …

Jan 24, 2024
CVE-2024-22366
6.8 MEDIUM

Active debug code exists in Yamaha wireless LAN access point devices. If a logged-in user who knows how to use the debug function accesses the …

Jan 24, 2024
CVE-2024-22380
5.5 MEDIUM

Electronic Delivery Check System (Ministry of Agriculture, Forestry and Fisheries The Agriculture and Rural Development Project Version) March, Heisei 31 era edition Ver.14.0.001.002 and earlier …

Jan 24, 2024
CVE-2024-21796
5.5 MEDIUM

Electronic Deliverables Creation Support Tool (Construction Edition) prior to Ver1.0.4 and Electronic Deliverables Creation Support Tool (Design & Survey Edition) prior to Ver1.0.4 improperly restrict …

Jan 24, 2024
CVE-2024-21765
5.5 MEDIUM

Electronic Delivery Check System (Doboku) Ver.18.1.0 and earlier, Electronic Delivery Check System (Dentsu) Ver.12.1.0 and earlier, Electronic Delivery Check System (Kikai) Ver.10.1.0 and earlier, and …

Jan 24, 2024
CVE-2022-4964
5.5 MEDIUM

Ubuntu's pipewire-pulse in snap grants microphone access even when the snap interface for audio-record is not set.

Jan 24, 2024
CVE-2024-23638
6.5 MEDIUM

Squid is a caching proxy for the Web. Due to an expired pointer reference bug, Squid prior to version 6.6 is vulnerable to a Denial …

Jan 24, 2024
CVE-2024-23633
4.7 MEDIUM

Label Studio, an open source data labeling tool had a remote import feature allowed users to import data from a remote web source, that was …

Jan 24, 2024
CVE-2024-23453
5.5 MEDIUM

Android Spoon application version 7.11.1 to 8.6.0 uses hard-coded credentials, which may allow a local attacker to retrieve the hard-coded API key when the application …

Jan 24, 2024
CVE-2024-0814
6.5 MEDIUM

Incorrect security UI in Payments in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially spoof security UI via a crafted HTML page. …

Jan 24, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.