53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.
A vulnerability classified as problematic was found in EFS Easy File Sharing FTP 2.0. Affected by this vulnerability is an unknown functionality. The manipulation of …
A buffer overflow vulnerability exists in Delta Electronics Delta Industrial Automation DOPSoft version 2 when parsing the wKPFStringLen field of a DPS file. An anonymous …
Group-Office is an enterprise CRM and groupware tool. Affected versions are subject to a vulnerability which is present in the file upload mechanism of Group …
Nextcloud files Zip app is a tool to create zip archives from one or multiple files from within Nextcloud. In affected versions users can download …
Nextcloud guests app is a utility to create guest users which can only see files shared with them. In affected versions users were able to …
Nextcloud guests app is a utility to create guest users which can only see files shared with them. In affected versions users could change the …
A memory leak issue discovered in YASM v.1.3.0 allows a local attacker to cause a denial of service via the new_Token function in the modules/preprocs/nasm/nasm-pp:1512.
Zoho ManageEngine ServiceDesk Plus MSP before 14504 allows stored XSS (by a low-privileged technician) via a task's name in a time sheet.
AVEVA PI Server versions 2023 and 2018 SP3 P05 and prior contain a vulnerability that could allow an unauthenticated user to cause the PI Message …
The Skoda Automotive cloud contains a Broken Access Control vulnerability, allowing remote attackers to obtain recent trip data, vehicle mileage, fuel consumption, average and maximum …
The Skoda Automotive cloud contains a Broken Access Control vulnerability, allowing to obtain nicknames and other user identifiers of Skoda Connect service users by specifying …
A flaw was found in the Netfilter subsystem in the Linux kernel. The issue is in the nft_byteorder_eval() function, where the code iterates through a …
A flaw was found in the X.Org server. The GLX PBuffer code does not call the XACE hook when creating the buffer, leaving it unlabeled. …
FlyCms 1.0 is vulnerable to Cross Site Scripting (XSS) in the email settings of the website settings section.
FlyCms 1.0 is vulnerable to Cross Site Scripting (XSS) in the system website settings website name section.
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Macroturk Software and Internet Technologies Macro-Bel allows Reflected XSS.This issue affects Macro-Bel: before …
Integer Overflow or Wraparound vulnerability in openEuler kernel on Linux (filesystem modules) allows Forced Integer Overflow.This issue affects openEuler kernel: from 4.19.90 before 4.19.90-2401.3, from …
NULL Pointer Dereference vulnerability in openEuler kernel on Linux (network modules) allows Pointer Manipulation. This vulnerability is associated with program files net/sched/sch_cbs.C. This issue affects …
A Cross-Frame Scripting vulnerability has been found on Plone CMS affecting verssion below 6.0.5. An attacker could store a malicious URL to be opened by …
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to …
Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a …
Omission of user-controlled key authorization in the IDMSistemas platform, affecting the QSige product. This vulnerability allows an attacker to extract sensitive information from the API …
The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the use of the 'tag' attribute in the wprm-recipe-name, wprm-recipe-date, and …
The WP Recipe Maker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘Referer' header in all versions up to, and including, 9.1.0 …
The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 9.1.0 …
A vulnerability has been found in Novel-Plus 4.3.0-RC1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /novel/bookSetting/list. The …
In autotest driver, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with …
In drm driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …
In vsp driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …
In jpg driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …
In jpg driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …
In telephone service, there is a possible improper input validation. This could lead to local information disclosure with no additional execution privileges needed
In vsp driver, there is a possible use after free due to a logic error. This could lead to local denial of service with System …
In phasecheckserver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with …
In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …
In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …
In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …
In video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with …
In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with …
In video decoder, there is a possible improper input validation. This could lead to local denial of service with no additional execution privileges needed
In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with …
In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with …
In video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with …
In media service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …
In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with …
In video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with …
In jpg driver, there is a possible missing permission check. This could lead to local information disclosure with System execution privileges needed
A vulnerability, which was classified as problematic, was found in DeepFaceLab pretrained DF.wf.288res.384.92.72.22. Affected is an unknown function of the file mainscripts/Util.py. The manipulation leads …
A vulnerability was found in PHPGurukul Company Visitor Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …
Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting
Free website and port scanning — find vulnerabilities before attackers do.