CVE Database

59714+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-22178
4.9 MEDIUM

A file write vulnerability exists in the OAS Engine Save Security Configuration functionality of Open Automation Software OAS Platform V19.00.0057. A specially crafted series of …

Apr 3, 2024
CVE-2024-21870
4.9 MEDIUM

A file write vulnerability exists in the OAS Engine Tags Configuration functionality of Open Automation Software OAS Platform V19.00.0057. A specially crafted series of network …

Apr 3, 2024
CVE-2024-3258
6.3 MEDIUM

A vulnerability was found in SourceCodester Internship Portal Management System 1.0. It has been classified as critical. This affects an unknown part of the file …

Apr 3, 2024
CVE-2024-3257
6.3 MEDIUM

A vulnerability was found in SourceCodester Internship Portal Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Apr 3, 2024
CVE-2024-3256
6.3 MEDIUM

A vulnerability has been found in SourceCodester Internship Portal Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Apr 3, 2024
CVE-2024-30570
5.3 MEDIUM

An information leak in debuginfo.htm of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information without any authentication required.

Apr 3, 2024
CVE-2024-27254
5.3 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 federated server is vulnerable to denial of service with a …

Apr 3, 2024
CVE-2024-25046
5.3 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a denial of service by an authenticated user …

Apr 3, 2024
CVE-2024-25030
6.2 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 stores potentially sensitive information in log files that could be read by a …

Apr 3, 2024
CVE-2024-22360
5.3 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to a denial of service with a specially crafted query on …

Apr 3, 2024
CVE-2023-52296
5.3 MEDIUM

IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to denial of service when querying a specific UDF built-in function …

Apr 3, 2024
CVE-2023-38729
6.8 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to sensitive information disclosure when using ADMIN_CMD with …

Apr 3, 2024
CVE-2024-3255
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in SourceCodester Internship Portal Management System 1.0. Affected is an unknown function of the file admin/edit_admin_query.php. …

Apr 3, 2024
CVE-2024-3254
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Internship Portal Management System 1.0. This issue affects some unknown processing of the …

Apr 3, 2024
CVE-2024-28782
6.3 MEDIUM

IBM QRadar Suite Software 1.10.12.0 through 1.10.18.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores user credentials in plain clear text which can …

Apr 3, 2024
CVE-2024-3253
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Internship Portal Management System 1.0. This vulnerability affects unknown code of the file admin/add_admin.php. The manipulation …

Apr 3, 2024
CVE-2024-3252
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Internship Portal Management System 1.0. This affects an unknown part of the file admin/check_admin.php. The …

Apr 3, 2024
CVE-2024-3251
6.3 MEDIUM

A vulnerability was found in SourceCodester Computer Laboratory Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

Apr 3, 2024
CVE-2024-28589
6.7 MEDIUM

An issue was discovered in Axigen Mail Server for Windows versions 10.5.18 and before, allows local low-privileged attackers to execute arbitrary code and escalate privileges …

Apr 3, 2024
CVE-2023-35764
5.3 MEDIUM

Insufficient verification of data authenticity issue in Survey Maker prior to 3.6.4 allows a remote unauthenticated attacker to spoof an IP address when posting.

Apr 3, 2024
CVE-2023-34423
6.1 MEDIUM

Survey Maker prior to 3.6.4 contains a stored cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the web …

Apr 3, 2024
CVE-2024-24506
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in Lime Survey Community Edition Version v.5.3.32+220817, allows remote attackers to execute arbitrary code via the Administrator email address parameter …

Apr 3, 2024
CVE-2024-31008
6.5 MEDIUM

An issue was discovered in WUZHICMS version 4.1.0, allows an attacker to execute arbitrary code and obtain sensitive information via the index.php file.

Apr 3, 2024
CVE-2024-2322
6.8 MEDIUM

The WooCommerce Cart Abandonment Recovery WordPress plugin before 1.2.27 does not have CSRF check in its bulk actions, which could allow attackers to make logged …

Apr 3, 2024
CVE-2024-31013
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in emlog version Pro 2.3, allow remote attackers to execute arbitrary code via a crafted payload to the bottom of …

Apr 3, 2024
CVE-2024-31009
6.5 MEDIUM

SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via lgid parameter in Banner.php.

Apr 3, 2024
CVE-2024-3227
4.7 MEDIUM

A vulnerability was found in Panwei eoffice OA up to 9.5. It has been declared as critical. This vulnerability affects unknown code of the file …

Apr 3, 2024
CVE-2024-3162
6.4 MEDIUM

The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Testimonial Widget Attributes in all versions up to, and including, …

Apr 3, 2024
CVE-2024-28836
5.4 MEDIUM

An issue was discovered in Mbed TLS 3.5.x before 3.6.0. When negotiating the TLS version on the server side, it can fall back to the …

Apr 3, 2024
CVE-2024-28755
6.5 MEDIUM

An issue was discovered in Mbed TLS 3.5.x before 3.6.0. When an SSL context was reset with the mbedtls_ssl_session_reset() API, the maximum TLS version to …

Apr 3, 2024
CVE-2024-28219
6.7 MEDIUM

In _imagingcms.c in Pillow before 10.3.0, a buffer overflow exists because strcpy is used instead of strncpy.

Apr 3, 2024
CVE-2024-26495
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in Friendica versions after v.2023.12, allows a remote attacker to execute arbitrary code and obtain sensitive information via the BBCode …

Apr 3, 2024
CVE-2024-1327
6.4 MEDIUM

The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's image box widget in all versions up to, and …

Apr 3, 2024
CVE-2024-3225
6.3 MEDIUM

A vulnerability was found in SourceCodester PHP Task Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Apr 3, 2024
CVE-2024-3224
6.3 MEDIUM

A vulnerability has been found in SourceCodester PHP Task Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Apr 3, 2024
CVE-2024-3223
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in SourceCodester PHP Task Management System 1.0. Affected is an unknown function of the file admin-manage-user.php. …

Apr 3, 2024
CVE-2024-3222
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester PHP Task Management System 1.0. This issue affects some unknown processing of the …

Apr 3, 2024
CVE-2024-3221
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester PHP Task Management System 1.0. This vulnerability affects unknown code of the file attendance-info.php. The manipulation …

Apr 3, 2024
CVE-2024-3218
5.4 MEDIUM

A vulnerability classified as critical has been found in Shibang Communications IP Network Intercom Broadcasting System 1.0. This affects an unknown part of the file …

Apr 3, 2024
CVE-2024-3209
5.5 MEDIUM

A vulnerability was found in UPX up to 4.2.2. It has been rated as critical. This issue affects the function get_ne64 of the file bele.h. …

Apr 2, 2024
CVE-2024-3207
5.5 MEDIUM

A vulnerability was found in ermig1979 Simd up to 6.0.134. It has been declared as critical. This vulnerability affects the function ReadUnsigned of the file …

Apr 2, 2024
CVE-2024-30370
4.3 MEDIUM

RARLAB WinRAR Mark-Of-The-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-Of-The-Web protection mechanism on affected installations of RARLAB WinRAR. User interaction is …

Apr 2, 2024
CVE-2024-30363
5.5 MEDIUM

Foxit PDF Reader U3D File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit …

Apr 2, 2024
CVE-2024-25075
5.1 MEDIUM

An issue was discovered in Softing uaToolkit Embedded before 1.41.1. When a subscription with a very low MaxNotificationPerPublish parameter is created, a publish response is …

Apr 2, 2024
CVE-2024-29834
6.4 MEDIUM

This vulnerability allows authenticated users with produce or consume permissions to perform unauthorized operations on partitioned topics, such as unloading topics and triggering compaction. These …

Apr 2, 2024
CVE-2024-30532
4.9 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in Builderall Team Builderall Builder for WordPress.This issue affects Builderall Builder for WordPress: from n/a through 2.0.1.

Apr 2, 2024
CVE-2024-30531
4.9 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in Nelio Software Nelio Content.This issue affects Nelio Content: from n/a through 3.2.0.

Apr 2, 2024
CVE-2024-24888
6.4 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in StellarWP Gutenberg Blocks by Kadence Blocks kadence-blocks.This issue affects Gutenberg Blocks by Kadence Blocks: from n/a through <= 3.2.25.

Apr 2, 2024
CVE-2024-30806
6.5 MEDIUM

An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap overflow in AP4_Dec3Atom::AP4_Dec3Atom at Ap4Dec3Atom.cpp, leading to a Denial of Service (DoS), as demonstrated …

Apr 2, 2024
CVE-2024-3151
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in Bdtask Multi-Store Inventory Management System up to 20240325. Affected is an unknown function of the …

Apr 2, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.