CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-0679
6.5 MEDIUM

The ColorMag theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the plugin_action_callback() function in all versions up to, …

Jan 20, 2024
CVE-2024-0623
4.3 MEDIUM

The VK Block Patterns plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.31.1.1. This is due to …

Jan 20, 2024
CVE-2023-46447
4.3 MEDIUM

The POPS! Rebel application 5.0 for Android, in POPS! Rebel Bluetooth Glucose Monitoring System, sends unencrypted glucose measurements over BLE.

Jan 20, 2024
CVE-2024-23332
4.0 MEDIUM

The Notary Project is a set of specifications and tools intended to provide a cross-industry standard for securing software supply chains by using authentic container …

Jan 19, 2024
CVE-2024-23688
5.3 MEDIUM

Consensys Discovery versions less than 0.4.5 uses the same AES/GCM nonce for the entire session. which should ideally be unique for every message. The node's …

Jan 19, 2024
CVE-2024-23686
5.3 MEDIUM

DependencyCheck for Maven 9.0.0 to 9.0.6, for CLI version 9.0.0 to 9.0.5, and for Ant versions 9.0.0 to 9.0.5, when used in debug mode, allows …

Jan 19, 2024
CVE-2024-0738
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in 个人开源 mldong 1.0. This issue affects the function ExpressionEngine of the file com/mldong/modules/wf/engine/model/DecisionModel.java. The …

Jan 19, 2024
CVE-2024-0737
5.3 MEDIUM

A vulnerability classified as problematic was found in Xlightftpd Xlight FTP Server 1.1. This vulnerability affects unknown code of the component Login. The manipulation of …

Jan 19, 2024
CVE-2024-23685
5.3 MEDIUM

Hard-coded credentials in mod-remote-storage versions under 1.7.2 and from 2.0.0 to 2.0.3 allows unauthorized users to gain read access to mod-inventory-storage records including instances, holdings, …

Jan 19, 2024
CVE-2024-23680
5.3 MEDIUM

AWS Encryption SDK for Java versions 2.0.0 to 2.2.0 and less than 1.9.0 incorrectly validates some invalid ECDSA signatures.

Jan 19, 2024
CVE-2024-22420
6.5 MEDIUM

JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture. This vulnerability depends on user interaction by opening …

Jan 19, 2024
CVE-2024-0758
6.1 MEDIUM

MolecularFaces before 0.3.0 is vulnerable to cross site scripting. A remote attacker can execute arbitrary JavaScript in the context of a victim browser via crafted …

Jan 19, 2024
CVE-2024-0736
5.3 MEDIUM

A vulnerability classified as problematic has been found in EFS Easy File Sharing FTP 3.6. This affects an unknown part of the component Login. The …

Jan 19, 2024
CVE-2024-0735
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been rated as critical. Affected by this issue is the …

Jan 19, 2024
CVE-2024-0734
6.3 MEDIUM

A vulnerability was found in Smsot up to 2.12. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the …

Jan 19, 2024
CVE-2024-0733
6.3 MEDIUM

A vulnerability was found in Smsot up to 2.12. It has been classified as critical. Affected is an unknown function of the file /api.php of …

Jan 19, 2024
CVE-2024-0732
5.3 MEDIUM

A vulnerability was found in PCMan FTP Server 2.0.7 and classified as problematic. This issue affects some unknown processing of the component STOR Command Handler. …

Jan 19, 2024
CVE-2024-0731
5.3 MEDIUM

A vulnerability has been found in PCMan FTP Server 2.0.7 and classified as problematic. This vulnerability affects unknown code of the component PUT Command Handler. …

Jan 19, 2024
CVE-2023-6450
5.5 MEDIUM

An incorrect permissions vulnerability was reported in the Lenovo App Store app that could allow an attacker to use system resources, resulting in a denial …

Jan 19, 2024
CVE-2023-6044
6.3 MEDIUM

A privilege escalation vulnerability was reported in Lenovo Vantage that could allow a local attacker with physical access to impersonate Lenovo Vantage Service and execute …

Jan 19, 2024
CVE-2023-5080
6.8 MEDIUM

A privilege escalation vulnerability was reported in some Lenovo tablet products that could allow local applications access to device identifiers and system commands.

Jan 19, 2024
CVE-2023-38541
6.7 MEDIUM

Insecure inherited permissions in some Intel HID Event Filter drivers for Windows 10 for some Intel NUC laptop software installers before version 2.2.2.1 may allow …

Jan 19, 2024
CVE-2023-33295
6.5 MEDIUM

Cohesity DataProtect prior to 6.8.1_u5 or 7.1 was discovered to have a incorrect access control vulnerability due to a lack of TLS Certificate Validation.

Jan 19, 2024
CVE-2023-29244
6.7 MEDIUM

Incorrect default permissions in some Intel Integrated Sensor Hub (ISH) driver for Windows 10 for Intel NUC P14E Laptop Element software installers before version 5.4.1.4479 …

Jan 19, 2024
CVE-2023-28722
6.7 MEDIUM

Improper buffer restrictions for some Intel NUC BIOS firmware before version IN0048 may allow a privileged user to potentially enable escalation of privilege via local …

Jan 19, 2024
CVE-2024-0730
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Project Worlds Online Time Table Generator 1.0. This affects an unknown part of the file …

Jan 19, 2024
CVE-2024-0729
5.5 MEDIUM

A vulnerability, which was classified as critical, has been found in ForU CMS up to 2020-06-23. Affected by this issue is some unknown functionality of …

Jan 19, 2024
CVE-2024-0728
4.7 MEDIUM

A vulnerability classified as problematic was found in ForU CMS up to 2020-06-23. Affected by this vulnerability is an unknown functionality of the file channel.php. …

Jan 19, 2024
CVE-2024-22957
5.5 MEDIUM

swftools 0.9.2 was discovered to contain an Out-of-bounds Read vulnerability via the function dict_do_lookup in swftools/lib/q.c:1190.

Jan 19, 2024
CVE-2024-22914
5.5 MEDIUM

A heap-use-after-free was found in SWFTools v0.9.2, in the function input at lex.swf5.c:2620. It allows an attacker to cause denial of service.

Jan 19, 2024
CVE-2024-0726
4.3 MEDIUM

A vulnerability was found in Project Worlds Student Project Allocation System 1.0. It has been rated as problematic. This issue affects some unknown processing of …

Jan 19, 2024
CVE-2024-0725
5.3 MEDIUM

A vulnerability was found in ProSSHD 1.2 on Windows. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to denial …

Jan 19, 2024
CVE-2024-0723
5.3 MEDIUM

A vulnerability was found in freeSSHd 1.0.9 on Windows. It has been classified as problematic. This affects an unknown part. The manipulation leads to denial …

Jan 19, 2024
CVE-2024-0717
5.3 MEDIUM

A vulnerability classified as critical was found in D-Link DAP-1360, DIR-300, DIR-615, DIR-615GF, DIR-615S, DIR-615T, DIR-620, DIR-620S, DIR-806A, DIR-815, DIR-815AC, DIR-815S, DIR-816, DIR-820, DIR-822, DIR-825, …

Jan 19, 2024
CVE-2024-0714
6.3 MEDIUM

A vulnerability was found in MiczFlor RPi-Jukebox-RFID up to 2.5.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Jan 19, 2024
CVE-2022-47160
6.5 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wpmet Wp Social Login and Register Social Counter.This issue affects Wp Social Login and Register …

Jan 19, 2024
CVE-2022-45845
4.3 MEDIUM

Deserialization of Untrusted Data vulnerability in Nextend Smart Slider 3.This issue affects Smart Slider 3: from n/a through 3.5.1.9.

Jan 19, 2024
CVE-2022-45083
6.6 MEDIUM

Deserialization of Untrusted Data vulnerability in ProfilePress Membership Team Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress.This …

Jan 19, 2024
CVE-2024-22877
5.4 MEDIUM

StrangeBee TheHive 5.2.0 to 5.2.8 is vulnerable to Cross Site Scripting (XSS) in the case reporting functionality. This feature allows an attacker to insert malicious …

Jan 19, 2024
CVE-2024-22876
5.4 MEDIUM

StrangeBee TheHive 5.1.0 to 5.1.9 and 5.2.0 to 5.2.8 is vulnerable to Cross Site Scripting (XSS) in the case attachment functionality which enables an attacker …

Jan 19, 2024
CVE-2023-51946
6.1 MEDIUM

Multiple reflected cross-site scripting (XSS) vulnerabilities in nasSvr.php in actidata actiNAS-SL-2U-8 3.2.03-SP1 allow remote attackers to inject arbitrary web script or HTML.

Jan 19, 2024
CVE-2024-21733
5.3 MEDIUM

Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat.This issue affects Apache Tomcat: from 8.5.7 through 8.5.63, from 9.0.0-M11 through 9.0.43. Other, EOL …

Jan 19, 2024
CVE-2024-23659
6.1 MEDIUM

SPIP before 4.1.14 and 4.2.x before 4.2.8 allows XSS via the name of an uploaded file. This is related to javascript/bigup.js and javascript/bigup.utils.js.

Jan 19, 2024
CVE-2024-23387
4.8 MEDIUM

FusionPBX prior to 5.1.0 contains a cross-site scripting vulnerability. If this vulnerability is exploited by a remote authenticated attacker with an administrative privilege, an arbitrary …

Jan 19, 2024
CVE-2023-50963
6.5 MEDIUM

IBM Storage Defender - Data Protect 1.0.0 through 1.4.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. …

Jan 19, 2024
CVE-2023-47718
4.3 MEDIUM

IBM Maximo Asset Management 7.6.1.3 and Manage Component 8.10 through 8.11 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious …

Jan 19, 2024
CVE-2023-32337
5.4 MEDIUM

IBM Maximo Spatial Asset Management 8.10 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the …

Jan 19, 2024
CVE-2023-38738
6.8 MEDIUM

IBM OpenPages with Watson 8.3 and 9.0 could provide weaker than expected security in a OpenPages environment using Native authentication. If OpenPages is using Native …

Jan 19, 2024
CVE-2023-35020
5.4 MEDIUM

IBM Sterling Control Center 6.3.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request …

Jan 19, 2024
CVE-2024-0695
4.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in EFS Easy Chat Server 3.1. Affected by this issue is some unknown functionality of …

Jan 18, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.