CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-0587
6.1 MEDIUM

The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'disqus_name' parameter in all versions up …

Jan 23, 2024
CVE-2023-39197
4.0 MEDIUM

An out-of-bounds read vulnerability was found in Netfilter Connection Tracking (conntrack) in the Linux kernel. This flaw allows a remote user to disclose sensitive information …

Jan 23, 2024
CVE-2024-23224
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.3, macOS Ventura 13.6.4. An app may be able to access …

Jan 23, 2024
CVE-2024-23223
6.2 MEDIUM

A privacy issue was addressed with improved handling of files. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, …

Jan 23, 2024
CVE-2024-23219
6.2 MEDIUM

The issue was addressed with improved authentication. This issue is fixed in iOS 17.3 and iPadOS 17.3. Stolen Device Protection may be unexpectedly disabled.

Jan 23, 2024
CVE-2024-23218
5.9 MEDIUM

A timing side-channel issue was addressed with improvements to constant-time computation in cryptographic functions. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS …

Jan 23, 2024
CVE-2024-23215
5.5 MEDIUM

An issue was addressed with improved handling of temporary files. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, …

Jan 23, 2024
CVE-2024-23207
5.5 MEDIUM

This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.3, macOS Sonoma …

Jan 23, 2024
CVE-2024-23206
6.5 MEDIUM

An access issue was addressed with improved access restrictions. This issue is fixed in Safari 17.3, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS …

Jan 23, 2024
CVE-2023-42937
5.5 MEDIUM

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.7.5 and iPadOS 16.7.5, watchOS 10.2, …

Jan 23, 2024
CVE-2023-42935
5.5 MEDIUM

An authentication issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.6.4. A local attacker may be able to view …

Jan 23, 2024
CVE-2023-42888
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in iOS 16.7.5 and iPadOS 16.7.5, watchOS 10.2, macOS Ventura 13.6.4, macOS Sonoma 14.2, …

Jan 23, 2024
CVE-2023-42887
6.3 MEDIUM

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13.6.4, macOS Sonoma 14.2. An app may be able …

Jan 23, 2024
CVE-2023-40528
5.5 MEDIUM

This issue was addressed by removing the vulnerable code. This issue is fixed in tvOS 17, watchOS 10, macOS Sonoma 14, iOS 17 and iPadOS …

Jan 23, 2024
CVE-2024-23340
5.3 MEDIUM

@hono/node-server is an adapter that allows users to run Hono applications on Node.js. Since v1.3.0, @hono/node-server has used its own Request object with `url` behavior …

Jan 22, 2024
CVE-2024-23339
6.3 MEDIUM

hoolock is a suite of lightweight utilities designed to maintain a small footprint when bundled. Starting in version 2.0.0 and prior to version 2.2.1, utility …

Jan 22, 2024
CVE-2024-23677
4.3 MEDIUM

In Splunk Enterprise versions below 9.0.8, the Splunk RapidDiag utility discloses server responses from external applications in a log file.

Jan 22, 2024
CVE-2024-23676
4.6 MEDIUM

In Splunk versions below 9.0.8 and 9.1.3, the “mrollup” SPL command lets a low-privileged user view metrics on an index that they do not have …

Jan 22, 2024
CVE-2024-23675
6.5 MEDIUM

In Splunk Enterprise versions below 9.0.8 and 9.1.3, Splunk app key value store (KV Store) improperly handles permissions for users that use the REST application …

Jan 22, 2024
CVE-2023-47141
5.3 MEDIUM

IIBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user with CONNECT privileges to cause a denial of …

Jan 22, 2024
CVE-2023-7194
6.1 MEDIUM

The Meris WordPress theme through 1.1.2 does not sanitise and escape some parameters before outputting them back in the page, leading to Reflected Cross-Site Scripting …

Jan 22, 2024
CVE-2023-7170
6.1 MEDIUM

The EventON-RSVP WordPress plugin before 2.9.5 does not sanitise and escape some parameters before outputting it back in the page, leading to a Reflected Cross-Site …

Jan 22, 2024
CVE-2023-6626
4.8 MEDIUM

The Product Enquiry for WooCommerce WordPress plugin before 3.1 does not sanitise and escape some of its settings, which could allow high privilege users such …

Jan 22, 2024
CVE-2023-6625
4.3 MEDIUM

The Product Enquiry for WooCommerce WordPress plugin before 3.1 does not have a CSRF check in place when deleting inquiries, which could allow attackers to …

Jan 22, 2024
CVE-2023-6456
4.8 MEDIUM

The WP Review Slider WordPress plugin before 13.0 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Jan 22, 2024
CVE-2023-6447
5.3 MEDIUM

The EventPrime WordPress plugin before 3.3.6 lacks authentication and authorization, allowing unauthenticated visitors to access private and password protected Events by guessing their numeric id/event …

Jan 22, 2024
CVE-2023-6384
4.3 MEDIUM

The WP User Profile Avatar WordPress plugin before 1.0.1 does not properly check for authorisation, allowing authors to delete and update arbitrary avatar

Jan 22, 2024
CVE-2023-6290
4.8 MEDIUM

The SEOPress WordPress plugin before 7.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Jan 22, 2024
CVE-2023-47747
5.3 MEDIUM

IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.1, 10.5, and 11.1 could allow an authenticated user with CONNECT privileges to cause …

Jan 22, 2024
CVE-2023-47158
5.3 MEDIUM

IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1 and 11.5 could allow an authenticated user with CONNECT privileges to cause …

Jan 22, 2024
CVE-2023-47152
5.9 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to an insecure cryptographic algorithm and to information disclosure in stack …

Jan 22, 2024
CVE-2023-27859
6.5 MEDIUM

IBM Db2 10.1, 10.5, and 11.1 could allow a remote user to execute arbitrary code caused by installing like named jar files across multiple databases. …

Jan 22, 2024
CVE-2024-0606
6.1 MEDIUM

An attacker could execute unauthorized script on a legitimate site through UXSS using window.open() by opening a javascript URI leading to unauthorized actions within the …

Jan 22, 2024
CVE-2024-0430
5.5 MEDIUM

IObit Malware Fighter v11.0.0.1274 is vulnerable to a Denial of Service vulnerability by triggering the 0x8001E00C IOCTL code of the ImfHpRegFilter.sys driver.

Jan 22, 2024
CVE-2023-50308
6.5 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5 under certain circumstances could allow an authenticated user to the database to cause …

Jan 22, 2024
CVE-2023-47746
5.3 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow an authenticated user with CONNECT privileges to cause …

Jan 22, 2024
CVE-2023-45193
5.9 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 federated server is vulnerable to a denial of service when a specially crafted …

Jan 22, 2024
CVE-2024-0784
6.3 MEDIUM

A vulnerability was found in hongmaple octopus 1.0. It has been classified as critical. Affected is an unknown function of the file /system/role/list. The manipulation …

Jan 22, 2024
CVE-2024-0783
6.3 MEDIUM

A vulnerability was found in Project Worlds Online Admission System 1.0 and classified as critical. This issue affects some unknown processing of the file documents.php. …

Jan 22, 2024
CVE-2023-44395
4.9 MEDIUM

Autolab is a course management service that enables instructors to offer autograded programming assignments to their students over the Web. Path traversal vulnerabilities were discovered …

Jan 22, 2024
CVE-2020-36772
4.4 MEDIUM

CloudLinux CageFS 7.0.8-2 or below insufficiently restricts file paths supplied to the sendmail proxy command. This allows local users to read and write arbitrary files …

Jan 22, 2024
CVE-2024-0775
6.7 MEDIUM

A use-after-free flaw was found in the __ext4_remount in fs/ext4/super.c in ext4 in the Linux kernel. This flaw allows a local user to cause an …

Jan 22, 2024
CVE-2024-22113
6.1 MEDIUM

Open redirect vulnerability in Access analysis CGI An-Analyzer released in 2023 December 31 and earlier allows a remote unauthenticated attacker to redirect users to arbitrary …

Jan 22, 2024
CVE-2024-23770
5.5 MEDIUM

darkhttpd through 1.15 allows local users to discover credentials (for --auth) by listing processes and their arguments.

Jan 22, 2024
CVE-2024-0774
5.3 MEDIUM

A vulnerability was found in Any-Capture Any Sound Recorder 2.93. It has been declared as problematic. This vulnerability affects unknown code of the component Registration …

Jan 22, 2024
CVE-2024-0772
5.3 MEDIUM

A vulnerability was found in Nsasoft ShareAlarmPro 2.1.4 and classified as problematic. Affected by this issue is some unknown functionality of the component Registration Handler. …

Jan 22, 2024
CVE-2024-0771
5.3 MEDIUM

A vulnerability has been found in Nsasoft Product Key Explorer 4.0.9 and classified as problematic. Affected by this vulnerability is an unknown functionality of the …

Jan 21, 2024
CVE-2024-0770
4.4 MEDIUM

A vulnerability, which was classified as critical, was found in European Chemicals Agency IUCLID 7.10.3 on Windows. Affected is an unknown function of the file …

Jan 21, 2024
CVE-2024-0769
5.3 MEDIUM KEV

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DIR-859 1.06B01. It has been rated as critical. Affected by this issue is some …

Jan 21, 2024
CVE-2024-23725
6.1 MEDIUM

Ghost before 5.76.0 allows XSS via a post excerpt in excerpt.js. An XSS payload can be rendered in post summaries.

Jan 21, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.