CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-23178
5.4 MEDIUM

An issue was discovered in the Phonos extension in MediaWiki before 1.40.2. PhonosButton.js allows i18n-based XSS via the phonos-purge-needed-error message.

Jan 12, 2024
CVE-2024-23177
6.1 MEDIUM

An issue was discovered in the WatchAnalytics extension in MediaWiki before 1.40.2. XSS can occur via the Special:PageStatistics page parameter.

Jan 12, 2024
CVE-2024-23174
5.4 MEDIUM

An issue was discovered in the PageTriage extension in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. XSS can occur via …

Jan 12, 2024
CVE-2024-23173
6.1 MEDIUM

An issue was discovered in the Cargo extension in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. The Special:Drilldown page allows …

Jan 12, 2024
CVE-2024-23172
5.4 MEDIUM

An issue was discovered in the CheckUser extension in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. XSS can occur via …

Jan 12, 2024
CVE-2024-23171
5.4 MEDIUM

An issue was discovered in the CampaignEvents extension in MediaWiki before 1.35.14, 1.36.x through 1.39.x before 1.39.6, and 1.40.x before 1.40.2. The Special:EventDetails page allows …

Jan 12, 2024
CVE-2022-4961
5.5 MEDIUM

A vulnerability was found in Weitong Mall 1.0.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file …

Jan 12, 2024
CVE-2022-48619
5.5 MEDIUM

An issue was discovered in drivers/input/input.c in the Linux kernel before 5.17.10. An attacker can cause a denial of service (panic) because input_set_capability mishandles the …

Jan 12, 2024
CVE-2024-0454
6.0 MEDIUM

ELAN Match-on-Chip FPR solution has design fault about potential risk of valid SID leakage and enumeration with spoof sensor. This fault leads to that Windows …

Jan 12, 2024
CVE-2023-52339
6.5 MEDIUM

In libebml before 1.4.5, an integer overflow in MemIOCallback.cpp can occur when reading or writing. It may result in buffer overflows.

Jan 12, 2024
CVE-2024-21617
6.5 MEDIUM

An Incomplete Cleanup vulnerability in Nonstop active routing (NSR) component of Juniper Networks Junos OS allows an adjacent, unauthenticated attacker to cause memory leak leading …

Jan 12, 2024
CVE-2024-21613
6.5 MEDIUM

A Missing Release of Memory after Effective Lifetime vulnerability in Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an …

Jan 12, 2024
CVE-2024-21607
5.3 MEDIUM

An Unsupported Feature in the UI vulnerability in Juniper Networks Junos OS on MX Series and EX9200 Series allows an unauthenticated, network-based attacker to cause …

Jan 12, 2024
CVE-2024-21603
6.5 MEDIUM

An Improper Check for Unusual or Exceptional Conditions vulnerability in the kernel of Juniper Network Junos OS on MX Series allows a network based attacker …

Jan 12, 2024
CVE-2024-21601
5.9 MEDIUM

A Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the Flow-processing Daemon (flowd) of Juniper Networks Junos OS on SRX Series …

Jan 12, 2024
CVE-2024-21600
6.5 MEDIUM

An Improper Neutralization of Equivalent Special Elements vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on PTX Series allows a unauthenticated, …

Jan 12, 2024
CVE-2024-21599
6.5 MEDIUM

A Missing Release of Memory after Effective Lifetime vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series allows an …

Jan 12, 2024
CVE-2024-21597
5.3 MEDIUM

An Exposure of Resource to Wrong Sphere vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series allows an unauthenticated, …

Jan 12, 2024
CVE-2024-21596
5.3 MEDIUM

A Heap-based Buffer Overflow vulnerability in the Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network based …

Jan 12, 2024
CVE-2024-21594
5.5 MEDIUM

A Heap-based Buffer Overflow vulnerability in the Network Services Daemon (NSD) of Juniper Networks Junos OS allows authenticated, low privileged, local attacker to cause a …

Jan 12, 2024
CVE-2024-21587
6.5 MEDIUM

An Improper Handling of Exceptional Conditions vulnerability in the broadband edge subscriber management daemon (bbe-smgd) of Juniper Networks Junos OS on MX Series allows an …

Jan 12, 2024
CVE-2024-21585
5.9 MEDIUM

An Improper Handling of Exceptional Conditions vulnerability in BGP session processing of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker, …

Jan 12, 2024
CVE-2023-36842
6.5 MEDIUM

An Improper Check for Unusual or Exceptional Conditions vulnerability in Juniper DHCP Daemon (jdhcpd) of Juniper Networks Junos OS allows an adjacent, unauthenticated attacker to …

Jan 12, 2024
CVE-2024-21982
4.8 MEDIUM

ONTAP versions 9.4 and higher are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information to unprivileged attackers when …

Jan 12, 2024
CVE-2024-0443
5.5 MEDIUM

A flaw was found in the blkgs destruction path in block/blk-cgroup.c in the Linux kernel, leading to a cgroup blkio memory leakage problem. When a …

Jan 12, 2024
CVE-2024-21337
5.2 MEDIUM

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

Jan 11, 2024
CVE-2024-20675
6.3 MEDIUM

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

Jan 11, 2024
CVE-2024-0426
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in ForU CMS up to 2020-06-23. This issue affects some unknown processing of the file …

Jan 11, 2024
CVE-2023-7226
6.3 MEDIUM

A vulnerability was found in meetyoucrop big-whale 1.1 and classified as critical. Affected by this issue is some unknown functionality of the file /auth/user/all.api of …

Jan 11, 2024
CVE-2023-50129
6.5 MEDIUM

Missing encryption in the NFC tags of the Flient Smart Door Lock v1.0 allows attackers to create a cloned tag via brief physical proximity to …

Jan 11, 2024
CVE-2023-50128
5.3 MEDIUM

The remote keyless system of the Hozard alarm system (alarmsystemen) v1.0 sends an identical radio frequency signal for each request, which results in an attacker …

Jan 11, 2024
CVE-2023-50127
5.9 MEDIUM

Hozard alarm system (Alarmsysteem) v1.0 is vulnerable to Improper Authentication. Commands sent via the SMS functionality are accepted from random phone numbers, which allows an …

Jan 11, 2024
CVE-2023-50126
6.5 MEDIUM

Missing encryption in the RFID tags of the Hozard alarm system (Alarmsysteem) v1.0 allow attackers to create a cloned tag via brief physical proximity to …

Jan 11, 2024
CVE-2023-50125
5.9 MEDIUM

A default engineer password set on the Hozard alarm system (Alarmsysteem) v1.0 allows an attacker to bring the alarm system to a disarmed state.

Jan 11, 2024
CVE-2023-50124
6.8 MEDIUM

Flient Smart Door Lock v1.0 is vulnerable to Use of Default Credentials. Due to default credentials on a debug interface, in combination with certain design …

Jan 11, 2024
CVE-2024-0425
5.3 MEDIUM

A vulnerability classified as critical was found in ForU CMS up to 2020-06-23. This vulnerability affects unknown code of the file /admin/index.php?act=reset_admin_psw. The manipulation leads …

Jan 11, 2024
CVE-2024-0419
5.3 MEDIUM

A vulnerability was found in Jasper httpdx up to 1.5.4 and classified as problematic. This issue affects some unknown processing of the component HTTP POST …

Jan 11, 2024
CVE-2024-0418
5.3 MEDIUM

A vulnerability has been found in iSharer and upRedSun File Sharing Wizard up to 1.5.0 and classified as problematic. This vulnerability affects unknown code of …

Jan 11, 2024
CVE-2024-0417
5.4 MEDIUM

A vulnerability, which was classified as critical, was found in DeShang DSShop up to 2.1.5. This affects an unknown part of the file application/home/controller/MemberAuth.php. The …

Jan 11, 2024
CVE-2024-0416
5.4 MEDIUM

A vulnerability, which was classified as critical, has been found in DeShang DSMall up to 5.0.3. Affected by this issue is some unknown functionality of …

Jan 11, 2024
CVE-2024-0415
6.3 MEDIUM

A vulnerability classified as critical was found in DeShang DSMall up to 6.1.0. Affected by this vulnerability is an unknown functionality of the file application/home/controller/TaobaoExport.php …

Jan 11, 2024
CVE-2024-0414
5.3 MEDIUM

A vulnerability classified as problematic has been found in DeShang DSCMS up to 3.1.2/7.1. Affected is an unknown function of the file public/install.php. The manipulation …

Jan 11, 2024
CVE-2024-0413
5.3 MEDIUM

A vulnerability was found in DeShang DSKMS up to 3.1.2. It has been rated as problematic. This issue affects some unknown processing of the file …

Jan 11, 2024
CVE-2024-0412
5.3 MEDIUM

A vulnerability was found in DeShang DSShop up to 3.1.0. It has been declared as problematic. This vulnerability affects unknown code of the file public/install.php …

Jan 11, 2024
CVE-2024-0411
5.3 MEDIUM

A vulnerability was found in DeShang DSMall up to 6.1.0. It has been classified as problematic. This affects an unknown part of the file public/install.php …

Jan 11, 2024
CVE-2023-6554
6.5 MEDIUM

When access to the "admin" folder is not protected by some external authorization mechanisms e.g. Apache Basic Auth, it is possible for any user to …

Jan 11, 2024
CVE-2023-5118
5.4 MEDIUM

The application is vulnerable to Stored Cross-Site Scripting (XSS) in the endpoint /sofer/DocumentService.asc/SaveAnnotation, where input data transmitted via the POST method in the parameters author …

Jan 11, 2024
CVE-2023-6938
6.4 MEDIUM

The Oxygen Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a custom field in all versions up to, and including, 4.8 due …

Jan 11, 2024
CVE-2023-6244
6.5 MEDIUM

The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5.4 …

Jan 11, 2024
CVE-2023-6242
6.5 MEDIUM

The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.5.4 …

Jan 11, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.