CVE Database

59927+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-49987
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability in the component /management/term of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via …

Mar 7, 2024
CVE-2023-49986
4.7 MEDIUM

A cross-site scripting (XSS) vulnerability in the component /admin/parent of School Fees Management System 1.0 allow attackers to execute arbitrary web scripts or HTML via …

Mar 7, 2024
CVE-2024-2236
5.9 MEDIUM

A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead …

Mar 6, 2024
CVE-2024-28111
6.5 MEDIUM

Canarytokens helps track activity and actions on a network. Canarytokens.org supports exporting the history of a Canarytoken's incidents in CSV format. The generation of these …

Mar 6, 2024
CVE-2024-27915
6.8 MEDIUM

Sulu is a PHP content management system. Starting in verson 2.2.0 and prior to version 2.4.17 and 2.5.13, access to pages is granted regardless of …

Mar 6, 2024
CVE-2024-27288
6.3 MEDIUM

1Panel is an open source Linux server operation and maintenance management panel. Prior to version 1.10.1-lts, users can use Burp to obtain unauthorized access to …

Mar 6, 2024
CVE-2024-27287
6.5 MEDIUM

ESPHome is a system to control your ESP8266/ESP32 for Home Automation systems. Starting in version 2023.12.9 and prior to version 2024.2.2, editing the configuration file …

Mar 6, 2024
CVE-2024-24766
6.2 MEDIUM

CasaOS-UserService provides user management functionalities to CasaOS. Starting in version 0.4.4.3 and prior to version 0.4.7, the Casa OS Login page disclosed the username enumeration …

Mar 6, 2024
CVE-2023-50167
5.4 MEDIUM

Pega Platform from 7.1.7 to 23.1.1 is affected by an XSS issue with editing/rendering user html content.

Mar 6, 2024
CVE-2024-2215
6.1 MEDIUM

A cross-site request forgery (CSRF) vulnerability in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers to connect to an attacker-specified TCP or Unix socket URL, …

Mar 6, 2024
CVE-2024-28174
5.8 MEDIUM

In JetBrains TeamCity before 2023.11.4 presigned URL generation requests in S3 Artifact Storage plugin were authorized improperly

Mar 6, 2024
CVE-2024-28173
4.3 MEDIUM

In JetBrains TeamCity between 2023.11 and 2023.11.4 custom build parameters of the "password" type could be disclosed

Mar 6, 2024
CVE-2024-28162
4.2 MEDIUM

In Jenkins Delphix Plugin 3.0.1 through 3.1.0 (both inclusive) a global option for administrators to enable or disable SSL/TLS certificate validation for Data Control Tower …

Mar 6, 2024
CVE-2024-28161
5.3 MEDIUM

In Jenkins Delphix Plugin 3.0.1, a global option for administrators to enable or disable SSL/TLS certificate validation for Data Control Tower (DCT) connections is disabled …

Mar 6, 2024
CVE-2024-28159
4.3 MEDIUM

A missing permission check in Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier allows attackers with Item/Read permission to trigger a build.

Mar 6, 2024
CVE-2024-28158
4.3 MEDIUM

A cross-site request forgery (CSRF) vulnerability in Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier allows attackers to trigger a build.

Mar 6, 2024
CVE-2024-28156
5.4 MEDIUM

Jenkins Build Monitor View Plugin 1.14-860.vd06ef2568b_3f and earlier does not escape Build Monitor View names, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by …

Mar 6, 2024
CVE-2024-28155
4.3 MEDIUM

Jenkins AppSpider Plugin 1.0.16 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to obtain information about available …

Mar 6, 2024
CVE-2024-28154
6.5 MEDIUM

Jenkins MQ Notifier Plugin 1.4.0 and earlier logs potentially sensitive build parameters as part of debug information in build logs by default.

Mar 6, 2024
CVE-2024-28153
5.4 MEDIUM

Jenkins OWASP Dependency-Check Plugin 5.4.5 and earlier does not escape vulnerability metadata from Dependency-Check reports, resulting in a stored cross-site scripting (XSS) vulnerability.

Mar 6, 2024
CVE-2024-28152
6.3 MEDIUM

In Jenkins Bitbucket Branch Source Plugin 866.vdea_7dcd3008e and earlier, except 848.850.v6a_a_2a_234a_c81, when discovering pull requests from forks, the trust policy "Forks in the same account" …

Mar 6, 2024
CVE-2024-28151
4.3 MEDIUM

Jenkins HTML Publisher Plugin 1.32 and earlier archives invalid symbolic links in report directories on agents and recreates them on the controller, allowing attackers with …

Mar 6, 2024
CVE-2024-28150
4.7 MEDIUM

Jenkins HTML Publisher Plugin 1.32 and earlier does not escape job names, report names, and index page titles shown as part of the report frame, …

Mar 6, 2024
CVE-2024-28149
6.5 MEDIUM

Jenkins HTML Publisher Plugin 1.16 through 1.32 (both inclusive) does not properly sanitize input, allowing attackers with Item/Configure permission to implement cross-site scripting (XSS) attacks …

Mar 6, 2024
CVE-2024-20346
5.4 MEDIUM

A vulnerability in the web-based management interface of Cisco AppDynamics Controller could allow an authenticated, remote attacker to perform a reflected cross-site scripting (XSS) attack …

Mar 6, 2024
CVE-2024-20345
6.5 MEDIUM

A vulnerability in the file upload functionality of Cisco AppDynamics Controller could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected …

Mar 6, 2024
CVE-2024-20336
6.5 MEDIUM

A vulnerability in the web-based user interface of Cisco Small Business 100, 300, and 500 Series Wireless APs could allow an authenticated, remote attacker to …

Mar 6, 2024
CVE-2024-20335
6.5 MEDIUM

A vulnerability in the web-based management interface of Cisco Small Business 100, 300, and 500 Series Wireless APs could allow an authenticated, remote attacker to …

Mar 6, 2024
CVE-2024-20301
6.2 MEDIUM

A vulnerability in Cisco Duo Authentication for Windows Logon and RDP could allow an authenticated, physical attacker to bypass secondary authentication and access an affected …

Mar 6, 2024
CVE-2024-20292
4.4 MEDIUM

A vulnerability in the logging component of Cisco Duo Authentication for Windows Logon and RDP could allow an authenticated, local attacker to view sensitive information …

Mar 6, 2024
CVE-2023-50740
5.3 MEDIUM

In Apache Linkis <=1.4.0, The password is printed to the log when using the Oracle data source of the Linkis data source module. We recommend …

Mar 6, 2024
CVE-2024-25103
6.3 MEDIUM

This vulnerability exists in AppSamvid software due to the usage of vulnerable and outdated components. An attacker with local administrative privileges could exploit this by …

Mar 6, 2024
CVE-2024-2211
4.6 MEDIUM

Cross-Site Scripting stored vulnerability in Gophish affecting version 0.12.1. This vulnerability could allow an attacker to store a malicious JavaScript payload in the campaign menu …

Mar 6, 2024
CVE-2024-26627
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: core: Move scsi_host_busy() out of host lock for waking up EH handler Inside scsi_eh_wakeup(), …

Mar 6, 2024
CVE-2024-26626
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ipmr: fix kernel panic when forwarding mcast packets The stacktrace was: [ 86.305548] BUG: kernel …

Mar 6, 2024
CVE-2024-26623
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: pds_core: Prevent race issues involving the adminq There are multiple paths that can result in …

Mar 6, 2024
CVE-2023-52607
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: powerpc/mm: Fix null-pointer dereference in pgtable_cache_add kasprintf() returns a pointer to dynamically allocated memory which …

Mar 6, 2024
CVE-2023-52606
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: powerpc/lib: Validate size for vector operations Some of the fp/vmx code in sstep.c assume a …

Mar 6, 2024
CVE-2023-52597
4.0 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KVM: s390: fix setting of fpc register kvm_arch_vcpu_ioctl_set_fpu() allows to set the floating point control …

Mar 6, 2024
CVE-2023-52596
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sysctl: Fix out of bounds access for empty sysctl registers When registering tables to the …

Mar 6, 2024
CVE-2023-52595
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: rt2x00: restart beacon queue when hardware reset When a hardware reset is triggered, all …

Mar 6, 2024
CVE-2023-52593
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: wfx: fix possible NULL pointer dereference in wfx_set_mfp_ap() Since 'ieee80211_beacon_get()' can return NULL, 'wfx_set_mfp_ap()' …

Mar 6, 2024
CVE-2023-52590
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ocfs2: Avoid touching renamed directory if parent does not change The VFS will not be …

Mar 6, 2024
CVE-2023-52589
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: rkisp1: Fix IRQ disable race issue In rkisp1_isp_stop() and rkisp1_csi_disable() the driver masks the …

Mar 6, 2024
CVE-2023-52587
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: IB/ipoib: Fix mcast list locking Releasing the `priv->lock` while iterating the `priv->multicast_list` in `ipoib_mcast_join_task()` opens …

Mar 6, 2024
CVE-2023-52585
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix possible NULL dereference in amdgpu_ras_query_error_status_helper() Return invalid error code -EINVAL for invalid block …

Mar 6, 2024
CVE-2023-52583
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ceph: fix deadlock or deadcode of misusing dget() The lock order is incorrect between denty …

Mar 6, 2024
CVE-2024-1989
6.4 MEDIUM

The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Sassy_Social_Share' shortcode in all versions …

Mar 6, 2024
CVE-2024-1771
4.3 MEDIUM

The Total theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the total_order_sections() function in all versions …

Mar 6, 2024
CVE-2024-1760
4.3 MEDIUM

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and …

Mar 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.