CVE Database

59927+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-25126
5.3 MEDIUM

Rack is a modular Ruby web server interface. Carefully crafted content type headers can cause Rack’s media type parser to take much longer than expected, …

Feb 29, 2024
CVE-2024-26559
5.3 MEDIUM

An issue in uverif v.2.0 allows a remote attacker to obtain sensitive information.

Feb 28, 2024
CVE-2024-25579
6.8 MEDIUM

OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent attacker with an administrative privilege to execute arbitrary OS commands by sending a …

Feb 28, 2024
CVE-2024-22532
6.5 MEDIUM

Buffer Overflow vulnerability in XNSoft NConvert 7.163 (for Windows x86) allows attackers to cause a denial of service via crafted xwd file.

Feb 28, 2024
CVE-2024-21798
4.8 MEDIUM

ELECOM wireless LAN routers contain a cross-site scripting vulnerability. Assume that a malicious administrative user configures the affected product with specially crafted content. When another …

Feb 28, 2024
CVE-2023-5617
5.3 MEDIUM

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.6, including 9.5.x and 8.3.x, display the version of Tomcat when a server error …

Feb 28, 2024
CVE-2024-26450
5.4 MEDIUM

An issue exists within Piwigo before v.14.2.0 allowing a malicious user to take over the application. This exploit involves chaining a Cross Site Request Forgery …

Feb 28, 2024
CVE-2024-25868
6.1 MEDIUM

A Cross Site Scripting (XSS) vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary code via the membershipType …

Feb 28, 2024
CVE-2023-45873
6.5 MEDIUM

An issue was discovered in Couchbase Server through 7.2.2. A data reader may cause a denial of service (application exist) because of the OOM killer.

Feb 28, 2024
CVE-2023-25922
4.3 MEDIUM

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 allows the attacker to upload or transfer files of dangerous types that can …

Feb 28, 2024
CVE-2024-27285
5.4 MEDIUM

YARD is a Ruby Documentation tool. The "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate …

Feb 28, 2024
CVE-2024-25435
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in Md1health Md1patient v2.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the …

Feb 28, 2024
CVE-2024-25202
6.1 MEDIUM

Cross Site Scripting vulnerability in Phpgurukul User Registration & Login and User Management System 1.0 allows attackers to run arbitrary code via the search bar.

Feb 28, 2024
CVE-2023-52048
4.7 MEDIUM

RuoYi v4.7.8 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /system/notice/.

Feb 28, 2024
CVE-2024-27948
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in bytesforall Atahualpa.This issue affects Atahualpa: from n/a through 3.7.24.

Feb 28, 2024
CVE-2023-51692
4.3 MEDIUM

Missing Authorization vulnerability in CusRev Customer Reviews for WooCommerce.This issue affects Customer Reviews for WooCommerce: from n/a through 5.38.1.

Feb 28, 2024
CVE-2023-51533
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Ecwid Ecommerce Ecwid Ecommerce Shopping Cart.This issue affects Ecwid Ecommerce Shopping Cart: from n/a through 6.12.4.

Feb 28, 2024
CVE-2024-27103
6.1 MEDIUM

Querybook is a Big Data Querying UI. When a user searches for their queries, datadocs, tables and lists, the search result is marked and highlighted, …

Feb 28, 2024
CVE-2024-21749
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Atakan Au 1 click disable all.This issue affects 1 click disable all: from n/a through 1.0.1.

Feb 28, 2024
CVE-2024-0560
6.3 MEDIUM

A vulnerability was found in 3Scale, when used with Keycloak 15 (or RHSSO 7.5.0) and superiors. When the auth_type is use_3scale_oidc_issuer_endpoint, the Token Introspection policy …

Feb 28, 2024
CVE-2023-52226
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Advanced Flamingo.This issue affects Advanced Flamingo: from n/a through 1.0.

Feb 28, 2024
CVE-2023-52223
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in MailerLite MailerLite – WooCommerce integration.This issue affects MailerLite – WooCommerce integration: from n/a through 2.0.8.

Feb 28, 2024
CVE-2023-51683
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Easy PayPal & Stripe Buy Now Button.This issue affects Easy PayPal & Stripe Buy Now Button: from …

Feb 28, 2024
CVE-2023-51681
6.5 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Duplicator Duplicator – WordPress Migration & Backup Plugin.This issue affects Duplicator – WordPress Migration & Backup Plugin: from n/a …

Feb 28, 2024
CVE-2024-24705
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Octa Code Accessibility.This issue affects Accessibility: from n/a through 1.0.6.

Feb 28, 2024
CVE-2024-24702
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Matt Martz & Andy Stratton Page Restrict.This issue affects Page Restrict: from n/a through 2.5.5.

Feb 28, 2024
CVE-2023-6917
6.0 MEDIUM

A vulnerability has been identified in the Performance Co-Pilot (PCP) package, stemming from the mixed privilege levels utilized by systemd services associated with PCP. While …

Feb 28, 2024
CVE-2024-1965
6.5 MEDIUM

Server-Side Request Forgery vulnerability in Haivision's Aviwest Manager and Aviwest Steamhub. This vulnerability could allow an attacker to enumerate internal network configuration without the need …

Feb 28, 2024
CVE-2024-1808
6.4 MEDIUM

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'su_qrcode' shortcode in all versions up …

Feb 28, 2024
CVE-2024-26016
4.3 MEDIUM

A low privilege authenticated user could import an existing dashboard or chart that they do not have access to and then modify its metadata, thereby …

Feb 28, 2024
CVE-2024-24779
5.0 MEDIUM

Apache Superset with custom roles that include `can write on dataset` and without all data access permissions, allows for users to create virtual datasets to …

Feb 28, 2024
CVE-2024-24773
4.9 MEDIUM

Improper parsing of nested SQL statements on SQLLab would allow authenticated users to surpass their data authorization scope. This issue affects Apache Superset: before 3.0.4, …

Feb 28, 2024
CVE-2024-24772
4.3 MEDIUM

A guest user could exploit a chart data REST API and send arbitrary SQL statements that on error could leak information from the underlying analytics …

Feb 28, 2024
CVE-2024-27315
4.3 MEDIUM

An authenticated user with privileges to create Alerts on Alerts & Reports has the capability to generate a specially crafted SQL statement that triggers an …

Feb 28, 2024
CVE-2024-1861
4.3 MEDIUM

The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan plugin for WordPress is vulnerable to unauthorized modification of data due …

Feb 28, 2024
CVE-2024-1860
6.5 MEDIUM

The Disable Json API, Login Lockdown, XMLRPC, Pingback, Stop User Enumeration Anti Hacker Scan plugin for WordPress is vulnerable to unauthorized modification of data due …

Feb 28, 2024
CVE-2024-1719
4.3 MEDIUM

The Easy PayPal & Stripe Buy Now Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.3 …

Feb 28, 2024
CVE-2024-22459
6.8 MEDIUM

Dell ECS, versions 3.6 through 3.6.2.5, and 3.7 through 3.7.0.6, and 3.8 through 3.8.0.4 versions, contain an improper access control vulnerability. A remote high privileged …

Feb 28, 2024
CVE-2024-1954
6.3 MEDIUM

The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and …

Feb 28, 2024
CVE-2024-1791
6.4 MEDIUM

The CodeMirror Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Code Mirror block in all versions up to, and including, 1.2.4 …

Feb 28, 2024
CVE-2024-1566
6.5 MEDIUM

The Redirects plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save function in all versions …

Feb 28, 2024
CVE-2024-1516
5.3 MEDIUM

The WP eCommerce plugin for WordPress is vulnerable to unauthorized arbitrary post creation due to a missing capability check on the check_for_saas_push() function in all …

Feb 28, 2024
CVE-2024-1476
5.3 MEDIUM

The Under Construction / Maintenance Mode from Acurax plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6 …

Feb 28, 2024
CVE-2024-1368
5.3 MEDIUM

The Page Duplicator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the duplicate_dat_page() function in all …

Feb 28, 2024
CVE-2024-1136
5.3 MEDIUM

The Coming Soon Page & Maintenance Mode plugin for WordPress is vulnerable to unauthorized access of data due to an improperly implemented URL check in …

Feb 28, 2024
CVE-2024-0975
5.3 MEDIUM

The WordPress Access Control plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.13 via the REST API. …

Feb 28, 2024
CVE-2024-0768
4.3 MEDIUM

The Envo's Elementor Templates & Widgets for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.4.4. This …

Feb 28, 2024
CVE-2024-0767
4.3 MEDIUM

The Envo's Elementor Templates & Widgets for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.4. This …

Feb 28, 2024
CVE-2024-0766
4.3 MEDIUM

The Envo's Elementor Templates & Widgets for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

Feb 28, 2024
CVE-2024-0682
5.3 MEDIUM

The Page Restrict plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 2.5.5. This is due to the plugin …

Feb 28, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.