CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-0290
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Kashipara Food Management System 1.0. This issue affects some unknown processing of the file …

Jan 8, 2024
CVE-2024-0289
6.3 MEDIUM

A vulnerability classified as critical was found in Kashipara Food Management System 1.0. This vulnerability affects unknown code of the file stock_entry_submit.php. The manipulation of …

Jan 8, 2024
CVE-2024-0288
6.3 MEDIUM

A vulnerability classified as critical has been found in Kashipara Food Management System 1.0. This affects an unknown part of the file rawstock_used_damaged_submit.php. The manipulation …

Jan 8, 2024
CVE-2024-0287
6.3 MEDIUM

A vulnerability was found in Kashipara Food Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Jan 7, 2024
CVE-2023-7214
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Totolink N350RT 9.3.5u.6139_B20201216. Affected by this issue is the function main of the file …

Jan 7, 2024
CVE-2023-7213
6.3 MEDIUM

A vulnerability classified as critical was found in Totolink N350RT 9.3.5u.6139_B20201216. Affected by this vulnerability is the function main of the file /cgi-bin/cstecgi.cgi?action=login&flag=1 of the …

Jan 7, 2024
CVE-2024-0286
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in PHPGurukul Hospital Management System 1.0. This affects an unknown part of the file index.php#contact_us of …

Jan 7, 2024
CVE-2023-7212
4.7 MEDIUM

A vulnerability classified as critical has been found in DeDeCMS up to 5.7.112. Affected is an unknown function of the file file_class.php of the component …

Jan 7, 2024
CVE-2024-0281
6.3 MEDIUM

A vulnerability was found in Kashipara Food Management System up to 1.0 and classified as critical. Affected by this issue is some unknown functionality of …

Jan 7, 2024
CVE-2024-0280
6.3 MEDIUM

A vulnerability has been found in Kashipara Food Management System up to 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality …

Jan 7, 2024
CVE-2024-0279
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Kashipara Food Management System up to 1.0. Affected is an unknown function of the file …

Jan 7, 2024
CVE-2024-0278
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Kashipara Food Management System up to 1.0. This issue affects some unknown processing of …

Jan 7, 2024
CVE-2024-0277
6.3 MEDIUM

A vulnerability classified as critical was found in Kashipara Food Management System up to 1.0. This vulnerability affects unknown code of the file party_submit.php. The …

Jan 7, 2024
CVE-2024-0276
6.3 MEDIUM

A vulnerability classified as critical has been found in Kashipara Food Management System up to 1.0. This affects an unknown part of the file rawstock_used_damaged_smt.php. …

Jan 7, 2024
CVE-2024-0275
6.3 MEDIUM

A vulnerability was found in Kashipara Food Management System up to 1.0. It has been rated as critical. Affected by this issue is some unknown …

Jan 7, 2024
CVE-2024-0274
6.3 MEDIUM

A vulnerability was found in Kashipara Food Management System up to 1.0. It has been declared as critical. Affected by this vulnerability is an unknown …

Jan 7, 2024
CVE-2024-0273
6.3 MEDIUM

A vulnerability was found in Kashipara Food Management System up to 1.0. It has been classified as critical. Affected is an unknown function of the …

Jan 7, 2024
CVE-2024-0272
6.3 MEDIUM

A vulnerability was found in Kashipara Food Management System up to 1.0 and classified as critical. This issue affects some unknown processing of the file …

Jan 7, 2024
CVE-2023-7211
5.6 MEDIUM

A vulnerability was found in Uniway Router 2.0. It has been declared as critical. This vulnerability affects unknown code of the component Administrative Web Interface. …

Jan 7, 2024
CVE-2024-0271
6.3 MEDIUM

A vulnerability has been found in Kashipara Food Management System up to 1.0 and classified as critical. This vulnerability affects unknown code of the file …

Jan 7, 2024
CVE-2024-0270
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Kashipara Food Management System up to 1.0. This affects an unknown part of the file …

Jan 7, 2024
CVE-2024-0266
4.3 MEDIUM

A vulnerability classified as problematic has been found in Project Worlds Online Lawyer Management System 1.0. Affected is an unknown function of the component User …

Jan 7, 2024
CVE-2024-0265
6.3 MEDIUM

A vulnerability was found in SourceCodester Clinic Queuing System 1.0. It has been rated as critical. This issue affects some unknown processing of the file …

Jan 7, 2024
CVE-2024-0263
5.3 MEDIUM

A vulnerability was found in ACME Ultra Mini HTTPd 1.21. It has been classified as problematic. This affects an unknown part of the component HTTP …

Jan 7, 2024
CVE-2024-0261
5.3 MEDIUM

A vulnerability has been found in Sentex FTPDMIN 0.96 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component RNFR …

Jan 7, 2024
CVE-2024-0260
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in SourceCodester Engineers Online Portal 1.0. Affected is an unknown function of the file change_password_teacher.php of …

Jan 7, 2024
CVE-2023-6801
6.4 MEDIUM

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

Jan 6, 2024
CVE-2023-6798
5.4 MEDIUM

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to unauthorized settings update …

Jan 6, 2024
CVE-2023-50121
5.7 MEDIUM

Autel EVO NANO drone flight control firmware version 1.6.5 is vulnerable to denial of service (DoS).

Jan 6, 2024
CVE-2023-50609
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in AVA teaching video application service platform version 3.1, allows remote attackers to execute arbitrary code via a crafted script …

Jan 6, 2024
CVE-2023-39853
6.5 MEDIUM

SQL Injection vulnerability in Dzzoffice version 2.01, allows remote attackers to obtain sensitive information via the doobj and doevent parameters in the Network Disk backend …

Jan 6, 2024
CVE-2024-21641
6.5 MEDIUM

Flarum is open source discussion platform software. Prior to version 1.8.5, the Flarum `/logout` route includes a redirect parameter that allows any third party to …

Jan 5, 2024
CVE-2023-47559
5.5 MEDIUM

A cross-site scripting (XSS) vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow authenticated users to inject malicious code via a …

Jan 5, 2024
CVE-2023-46836
4.7 MEDIUM

The fixes for XSA-422 (Branch Type Confusion) and XSA-434 (Speculative Return Stack Overflow) are not IRQ-safe. It was believed that the mitigations always operated in …

Jan 5, 2024
CVE-2023-46835
5.5 MEDIUM

The current setup of the quarantine page tables assumes that the quarantine domain (dom_io) has been initialized with an address width of DEFAULT_DOMAIN_ADDRESS_WIDTH (48) and …

Jan 5, 2024
CVE-2023-41289
6.3 MEDIUM

An OS command injection vulnerability has been reported to affect QcalAgent. If exploited, the vulnerability could allow authenticated users to execute commands via a network. …

Jan 5, 2024
CVE-2023-41287
4.3 MEDIUM

A SQL injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow users to inject malicious code via a network. …

Jan 5, 2024
CVE-2023-39294
6.6 MEDIUM

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute …

Jan 5, 2024
CVE-2023-34328
5.5 MEDIUM

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] AMD CPUs since ~2014 have extensions to normal …

Jan 5, 2024
CVE-2023-34327
5.5 MEDIUM

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] AMD CPUs since ~2014 have extensions to normal …

Jan 5, 2024
CVE-2023-34324
4.9 MEDIUM

Closing of an event channel in the Linux kernel can result in a deadlock. This happens when the close is being performed in parallel to …

Jan 5, 2024
CVE-2023-34323
5.5 MEDIUM

When a transaction is committed, C Xenstored will first check the quota is correct before attempting to commit any nodes. It would be possible that …

Jan 5, 2024
CVE-2024-0246
4.3 MEDIUM

A vulnerability classified as problematic has been found in IceWarp 12.0.2.1/12.0.3.1. This affects an unknown part of the file /install/ of the component Utility Download …

Jan 5, 2024
CVE-2023-52126
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Suman Bhattarai Send Users Email.This issue affects Send Users Email: from n/a through 1.4.3.

Jan 5, 2024
CVE-2023-52125
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webvitaly iframe allows Stored XSS.This issue affects iframe: from n/a through 4.8.

Jan 5, 2024
CVE-2023-52124
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShapedPlugin LLC WP Tabs – Responsive Tabs Plugin for WordPress allows Stored XSS.This …

Jan 5, 2024
CVE-2023-52151
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Uncanny Automator, Uncanny Owl Uncanny Automator – Automate everything with the #1 no-code automation and …

Jan 5, 2024
CVE-2023-52148
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in wp.Insider, wpaffiliatemgr Affiliates Manager.This issue affects Affiliates Manager: from n/a through 2.9.30.

Jan 5, 2024
CVE-2023-52146
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Aaron J 404 Solution.This issue affects 404 Solution: from n/a through 2.33.0.

Jan 5, 2024
CVE-2023-52122
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in PressTigers Simple Job Board.This issue affects Simple Job Board: from n/a through 2.10.6.

Jan 5, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.