CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2021-4433
5.3 MEDIUM

A vulnerability was found in Karjasoft Sami HTTP Server 2.0. It has been classified as problematic. Affected is an unknown function of the component HTTP …

Jan 18, 2024
CVE-2024-23525
6.5 MEDIUM

The Spreadsheet::ParseXLSX package before 0.30 for Perl allows XXE attacks because it neglects to use the no_xxe option of XML::Twig.

Jan 18, 2024
CVE-2024-0650
4.3 MEDIUM

A vulnerability was found in Project Worlds Visitor Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file …

Jan 18, 2024
CVE-2023-6340
5.5 MEDIUM

SonicWall Capture Client version 3.7.10, NetExtender client version 10.2.337 and earlier versions are installed with sfpmonitor.sys driver. The driver has been found to be vulnerable …

Jan 18, 2024
CVE-2024-0649
6.3 MEDIUM

A vulnerability was found in ZhiHuiYun up to 4.4.13 and classified as critical. This issue affects the function download_network_image of the file /app/Http/Controllers/ImageController.php of the …

Jan 17, 2024
CVE-2024-22414
6.5 MEDIUM

flaskBlog is a simple blog app built with Flask. Improper storage and rendering of the `/user/<user>` page allows a user's comments to execute arbitrary javascript …

Jan 17, 2024
CVE-2023-5914
5.4 MEDIUM

Cross-site scripting (XSS)

Jan 17, 2024
CVE-2023-6548
5.5 MEDIUM KEV

Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with …

Jan 17, 2024
CVE-2023-48858
6.1 MEDIUM

A Cross-site scripting (XSS) vulnerability in login page php code in Armex ABO.CMS 5.9 allows remote attackers to inject arbitrary web script or HTML via …

Jan 17, 2024
CVE-2024-0647
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in Sparksuite SimpleMDE up to 1.11.2. This affects an unknown part of the component iFrame Handler. …

Jan 17, 2024
CVE-2023-7031
5.7 MEDIUM

Insecure Direct Object Reference vulnerabilities were discovered in the Avaya Aura Experience Portal Manager which may allow partial information disclosure to an authenticated non-privileged user. …

Jan 17, 2024
CVE-2022-42884
5.4 MEDIUM

Missing Authorization vulnerability in ThemeinProgress WIP Custom Login.This issue affects WIP Custom Login: from n/a through 1.2.7.

Jan 17, 2024
CVE-2024-22714
6.1 MEDIUM

Stupid Simple CMS <=1.2.4 is vulnerable to Cross Site Scripting (XSS) in the editing section of the article content.

Jan 17, 2024
CVE-2022-41790
4.3 MEDIUM

Missing Authorization vulnerability in CodePeople WP Time Slots Booking Form.This issue affects WP Time Slots Booking Form: from n/a through 1.1.76.

Jan 17, 2024
CVE-2022-41786
5.4 MEDIUM

Missing Authorization vulnerability in WP Job Portal WP Job Portal – A Complete Job Board.This issue affects WP Job Portal – A Complete Job Board: …

Jan 17, 2024
CVE-2024-20287
6.5 MEDIUM

A vulnerability in the web-based management interface of the Cisco WAP371 Wireless-AC/N Dual Radio Access Point (AP) with Single Point Setup could allow an authenticated, …

Jan 17, 2024
CVE-2024-20277
6.8 MEDIUM

A vulnerability in the web-based management interface of Cisco ThousandEyes Enterprise Agent, Virtual Appliance installation type, could allow an authenticated, remote attacker to perform a …

Jan 17, 2024
CVE-2024-20270
4.8 MEDIUM

A vulnerability in the web-based management interface of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Platform could allow an authenticated, remote attacker …

Jan 17, 2024
CVE-2024-20251
4.8 MEDIUM

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to perform a stored cross-site scripting …

Jan 17, 2024
CVE-2023-23896
5.4 MEDIUM

Missing Authorization vulnerability in MyThemeShop URL Shortener by MyThemeShop.This issue affects URL Shortener by MyThemeShop: from n/a through 1.0.17.

Jan 17, 2024
CVE-2023-23882
4.3 MEDIUM

Missing Authorization vulnerability in Brainstorm Force Ultimate Addons for Beaver Builder – Lite.This issue affects Ultimate Addons for Beaver Builder – Lite: from n/a through …

Jan 17, 2024
CVE-2023-20271
6.5 MEDIUM

A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to …

Jan 17, 2024
CVE-2023-20260
6.0 MEDIUM

A vulnerability in the application CLI of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager could allow an authenticated, local attacker to gain escalated …

Jan 17, 2024
CVE-2023-20258
6.5 MEDIUM

A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating …

Jan 17, 2024
CVE-2023-20257
4.8 MEDIUM

A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct cross-site scripting attacks. This vulnerability is …

Jan 17, 2024
CVE-2022-41695
5.4 MEDIUM

Missing Authorization vulnerability in SedLex Traffic Manager.This issue affects Traffic Manager: from n/a through 1.4.5.

Jan 17, 2024
CVE-2022-41619
5.4 MEDIUM

Missing Authorization vulnerability in SedLex Image Zoom.This issue affects Image Zoom: from n/a through 1.8.8.

Jan 17, 2024
CVE-2022-40702
5.4 MEDIUM

Missing Authorization vulnerability in Zorem Advanced Local Pickup for WooCommerce.This issue affects Advanced Local Pickup for WooCommerce: from n/a through 1.5.2.

Jan 17, 2024
CVE-2024-0641
5.5 MEDIUM

A denial of service vulnerability was found in tipc_crypto_key_revoke in net/tipc/crypto.c in the Linux kernel’s TIPC subsystem. This flaw allows guests with local user privileges …

Jan 17, 2024
CVE-2024-0639
5.5 MEDIUM

A denial of service vulnerability due to a deadlock was found in sctp_auto_asconf_init in net/sctp/socket.c in the Linux kernel’s SCTP subsystem. This flaw allows guests …

Jan 17, 2024
CVE-2023-34379
5.4 MEDIUM

Missing Authorization vulnerability in MagneticOne Cart2Cart: Magento to WooCommerce Migration.This issue affects Cart2Cart: Magento to WooCommerce Migration: from n/a through 2.0.0.

Jan 17, 2024
CVE-2022-40203
6.3 MEDIUM

Missing Authorization vulnerability in AlgolPlus Advanced Dynamic Pricing for WooCommerce.This issue affects Advanced Dynamic Pricing for WooCommerce: from n/a through 4.1.5.

Jan 17, 2024
CVE-2022-38141
4.3 MEDIUM

Missing Authorization vulnerability in Zorem Sales Report Email for WooCommerce.This issue affects Sales Report Email for WooCommerce: from n/a through 2.8.

Jan 17, 2024
CVE-2022-36418
6.5 MEDIUM

Missing Authorization vulnerability in Vagary Digital HREFLANG Tags Lite.This issue affects HREFLANG Tags Lite: from n/a through 2.0.0.

Jan 17, 2024
CVE-2023-5006
6.5 MEDIUM

The WP Discord Invite WordPress plugin before 2.5.1 does not protect some of its actions against CSRF attacks, allowing an unauthenticated attacker to perform actions …

Jan 17, 2024
CVE-2023-51743
6.5 MEDIUM

This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Set Upstream Channel ID (UCID) parameter …

Jan 17, 2024
CVE-2023-51742
6.5 MEDIUM

This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Add Downstream Frequency parameter at its …

Jan 17, 2024
CVE-2023-51739
6.9 MEDIUM

This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Device Name parameter at its web …

Jan 17, 2024
CVE-2023-51738
6.9 MEDIUM

This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Network Name (SSID) parameter at its …

Jan 17, 2024
CVE-2023-51737
6.9 MEDIUM

This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Preshared Phrase parameter at its web …

Jan 17, 2024
CVE-2023-51736
6.9 MEDIUM

This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the L2TP/PPTP Username parameter at its web …

Jan 17, 2024
CVE-2023-51735
6.9 MEDIUM

This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Pre-shared key parameter at its web …

Jan 17, 2024
CVE-2023-51734
6.9 MEDIUM

This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Identity parameter under Remote endpoint settings …

Jan 17, 2024
CVE-2023-51733
6.9 MEDIUM

This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Identity parameter under Local endpoint settings …

Jan 17, 2024
CVE-2023-51732
6.9 MEDIUM

This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the IPsec Tunnel Name parameter at its …

Jan 17, 2024
CVE-2023-51731
6.9 MEDIUM

This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Hostname parameter at its web interface. …

Jan 17, 2024
CVE-2023-51730
6.9 MEDIUM

This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the DDNS Password parameter at its web …

Jan 17, 2024
CVE-2023-51729
6.9 MEDIUM

This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the DDNS Username parameter at its web …

Jan 17, 2024
CVE-2023-51728
6.9 MEDIUM

This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the SMTP Password parameter at its web …

Jan 17, 2024
CVE-2023-51727
6.9 MEDIUM

This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the SMTP Username parameter at its web …

Jan 17, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.