CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-0344
5.5 MEDIUM

A vulnerability, which was classified as critical, has been found in soxft TimeMail up to 1.1. Affected by this issue is some unknown functionality of …

Jan 9, 2024
CVE-2024-21664
4.3 MEDIUM

jwx is a Go module implementing various JWx (JWA/JWE/JWK/JWS/JWT, otherwise known as JOSE) technologies. Calling `jws.Parse` with a JSON serialized payload where the `signature` field …

Jan 9, 2024
CVE-2024-0343
4.3 MEDIUM

A vulnerability classified as problematic was found in CodeAstro Simple House Rental System 5.6. Affected by this vulnerability is an unknown functionality of the component …

Jan 9, 2024
CVE-2024-0342
6.3 MEDIUM

A vulnerability classified as critical has been found in Inis up to 2.0.1. Affected is an unknown function of the file /app/api/controller/default/Sqlite.php. The manipulation of …

Jan 9, 2024
CVE-2024-21668
4.4 MEDIUM

react-native-mmkv is a library that allows easy use of MMKV inside React Native applications. Before version 2.11.0, the react-native-mmkv logged the optional encryption key for …

Jan 9, 2024
CVE-2024-21319
6.8 MEDIUM

Microsoft Identity Denial of service vulnerability

Jan 9, 2024
CVE-2024-21320
6.5 MEDIUM

Windows Themes Spoofing Vulnerability

Jan 9, 2024
CVE-2024-21316
6.1 MEDIUM

Windows Server Key Distribution Service Security Feature Bypass

Jan 9, 2024
CVE-2024-21314
6.5 MEDIUM

Microsoft Message Queuing Information Disclosure Vulnerability

Jan 9, 2024
CVE-2024-21313
5.3 MEDIUM

Windows TCP/IP Information Disclosure Vulnerability

Jan 9, 2024
CVE-2024-21311
5.5 MEDIUM

Windows Cryptographic Services Information Disclosure Vulnerability

Jan 9, 2024
CVE-2024-21306
5.7 MEDIUM

Microsoft Bluetooth Driver Spoofing Vulnerability

Jan 9, 2024
CVE-2024-21305
4.4 MEDIUM

Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability

Jan 9, 2024
CVE-2024-20699
5.5 MEDIUM

Windows Hyper-V Denial of Service Vulnerability

Jan 9, 2024
CVE-2024-20694
5.5 MEDIUM

Windows CoreMessaging Information Disclosure Vulnerability

Jan 9, 2024
CVE-2024-20692
5.7 MEDIUM

Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability

Jan 9, 2024
CVE-2024-20691
4.7 MEDIUM

Windows Themes Information Disclosure Vulnerability

Jan 9, 2024
CVE-2024-20690
6.5 MEDIUM

Windows Nearby Sharing Spoofing Vulnerability

Jan 9, 2024
CVE-2024-20680
6.5 MEDIUM

Windows Message Queuing Client (MSMQC) Information Disclosure

Jan 9, 2024
CVE-2024-20666
6.6 MEDIUM

BitLocker Security Feature Bypass Vulnerability

Jan 9, 2024
CVE-2024-20664
6.5 MEDIUM

Microsoft Message Queuing Information Disclosure Vulnerability

Jan 9, 2024
CVE-2024-20663
6.5 MEDIUM

Windows Message Queuing Client (MSMQC) Information Disclosure

Jan 9, 2024
CVE-2024-20662
4.9 MEDIUM

Windows Online Certificate Status Protocol (OCSP) Information Disclosure Vulnerability

Jan 9, 2024
CVE-2024-20660
6.5 MEDIUM

Microsoft Message Queuing Information Disclosure Vulnerability

Jan 9, 2024
CVE-2024-20655
6.6 MEDIUM

Microsoft Online Certificate Status Protocol (OCSP) Remote Code Execution Vulnerability

Jan 9, 2024
CVE-2024-0340
4.4 MEDIUM

A vulnerability was found in vhost_new_msg in drivers/vhost/vhost.c in the Linux kernel, which does not properly initialize memory in messages passed between virtual guests and …

Jan 9, 2024
CVE-2024-0226
4.8 MEDIUM

Synopsys Seeker versions prior to 2023.12.0 are vulnerable to a stored cross-site scripting vulnerability through a specially crafted payload.

Jan 9, 2024
CVE-2024-22165
6.5 MEDIUM

In Splunk Enterprise Security (ES) versions lower than 7.1.2, an attacker can create a malformed Investigation to perform a denial of service (DoS). The malformed …

Jan 9, 2024
CVE-2024-22164
4.3 MEDIUM

In Splunk Enterprise Security (ES) versions below 7.1.2, an attacker can use investigation attachments to perform a denial of service (DoS) to the Investigation. The …

Jan 9, 2024
CVE-2023-6129
6.5 MEDIUM

Issue summary: The POLY1305 MAC (message authentication code) implementation contains a bug that might corrupt the internal state of applications running on PowerPC CPU based …

Jan 9, 2024
CVE-2023-7223
5.3 MEDIUM

A vulnerability classified as problematic has been found in Totolink T6 4.1.9cu.5241_B20210923. This affects an unknown part of the file /cgi-bin/cstecgi.cgi. The manipulation of the …

Jan 9, 2024
CVE-2022-28975
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in Infoblox NIOS v8.5.2-409296 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into …

Jan 9, 2024
CVE-2024-22370
4.6 MEDIUM

In JetBrains YouTrack before 2023.3.22666 stored XSS via markdown was possible

Jan 9, 2024
CVE-2023-42797
6.6 MEDIUM

A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05.20), CP-8050 MASTER MODULE (All versions < CPCI85 V05.20). The network configuration …

Jan 9, 2024
CVE-2024-22368
5.5 MEDIUM

The Spreadsheet::ParseXLSX package before 0.28 for Perl can encounter an out-of-memory condition during parsing of a crafted XLSX document. This occurs because the memoize implementation …

Jan 9, 2024
CVE-2023-6149
5.7 MEDIUM

Qualys Jenkins Plugin for WAS prior to version and including 2.0.11 was identified to be affected by a security flaw, which was missing a permission …

Jan 9, 2024
CVE-2023-6148
5.7 MEDIUM

Qualys Jenkins Plugin for Policy Compliance prior to version and including 1.0.5 was identified to be affected by a security flaw, which was missing a …

Jan 9, 2024
CVE-2023-50974
5.5 MEDIUM

In Appwrite CLI before 3.0.0, when using the login command, the credentials of the Appwrite user are stored in a ~/.appwrite/prefs.json file with 0644 as …

Jan 9, 2024
CVE-2023-6147
5.7 MEDIUM

Qualys Jenkins Plugin for Policy Compliance prior to version and including 1.0.5 was identified to be affected by a security flaw, which was missing a …

Jan 9, 2024
CVE-2023-6842
4.4 MEDIUM

The Formidable Forms – Contact Form, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Jan 9, 2024
CVE-2023-6830
6.5 MEDIUM

The Formidable Forms plugin for WordPress is vulnerable to HTML injection in versions up to, and including, 6.7. This vulnerability allows unauthenticated users to inject …

Jan 9, 2024
CVE-2023-6788
5.4 MEDIUM

The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.8.1. This is …

Jan 9, 2024
CVE-2023-6594
4.4 MEDIUM

The WordPress Button Plugin MaxButtons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 9.7.4 …

Jan 9, 2024
CVE-2024-22124
4.1 MEDIUM

Under certain conditions, Internet Communication Manager (ICM) or SAP Web Dispatcher - versions KERNEL 7.22, KERNEL 7.53, KERNEL 7.54, KRNL64UC 7.22, KRNL64UC 7.22EXT, KRNL64UC 7.53, …

Jan 9, 2024
CVE-2024-21738
4.1 MEDIUM

SAP NetWeaver ABAP Application Server and ABAP Platform do not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. An attacker with low privileges …

Jan 9, 2024
CVE-2024-21736
6.4 MEDIUM

SAP S/4HANA Finance for (Advanced Payment Management) - versions SAPSCORE 128, S4CORE 107, does not perform necessary authorization checks. A function import could be triggered …

Jan 9, 2024
CVE-2023-36629
5.5 MEDIUM

The ST ST54-android-packages-apps-Nfc package before 130-20230215-23W07p0 for Android has an out-of-bounds read.

Jan 9, 2024
CVE-2023-27000
6.1 MEDIUM

Cross Site Scripting vulnerability found in NetScoutnGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code via the name parameter of the Profile and Exclusion …

Jan 9, 2024
CVE-2023-26998
5.4 MEDIUM

Cross Site Scripting vulnerability found in NetScoutnGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code via the creator parameter of the Alert Configuration page.

Jan 9, 2024
CVE-2023-46906
4.9 MEDIUM

juzaweb <= 3.4 is vulnerable to Incorrect Access Control, resulting in an application outage after a 500 HTTP status code. The payload in the timezone …

Jan 9, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.