CVE Database

59927+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-1261
6.3 MEDIUM

A vulnerability classified as critical was found in Juanpao JPShop up to 1.5.02. This vulnerability affects the function actionIndex of the file /api/controllers/merchant/app/ComboController.php of the …

Feb 6, 2024
CVE-2024-1260
6.3 MEDIUM

A vulnerability classified as critical has been found in Juanpao JPShop up to 1.5.02. This affects the function actionIndex of the file /api/controllers/admin/app/ComboController.php of the …

Feb 6, 2024
CVE-2023-45227
5.4 MEDIUM

An attacker with access to the web application with vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scripting payload into the "dns.0.server" parameter.

Feb 6, 2024
CVE-2023-45222
5.4 MEDIUM

An attacker with access to the web application that has the vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scripting payload into the …

Feb 6, 2024
CVE-2023-45213
6.6 MEDIUM

A potential attacker with access to the Westermo Lynx device would be able to execute malicious code that could affect the correct functioning of the …

Feb 6, 2024
CVE-2023-42765
5.4 MEDIUM

An attacker with access to the vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scripting payload into the "username" parameter in the SNMP …

Feb 6, 2024
CVE-2023-40544
5.7 MEDIUM

An attacker with access to the network where the affected devices are located could maliciously actions to obtain, via a sniffer, sensitive information exchanged via …

Feb 6, 2024
CVE-2023-40143
5.4 MEDIUM

An attacker with access to the Westermo Lynx web application that has the vulnerable software could introduce arbitrary JavaScript by injecting a cross-site scripting payload …

Feb 6, 2024
CVE-2024-1259
6.3 MEDIUM

A vulnerability was found in Juanpao JPShop up to 1.5.02. It has been rated as critical. Affected by this issue is some unknown functionality of …

Feb 6, 2024
CVE-2024-22241
4.3 MEDIUM

Aria Operations for Networks contains a cross site scripting vulnerability. A malicious actor with admin privileges can inject a malicious payload into the login banner …

Feb 6, 2024
CVE-2024-22240
4.9 MEDIUM

Aria Operations for Networks contains a local file read vulnerability. A malicious actor with admin privileges may exploit this vulnerability leading to unauthorized access to …

Feb 6, 2024
CVE-2024-22239
5.3 MEDIUM

Aria Operations for Networks contains a local privilege escalation vulnerability. A console user with access to Aria Operations for Networks may exploit this vulnerability to …

Feb 6, 2024
CVE-2024-22238
6.4 MEDIUM

Aria Operations for Networks contains a cross site scripting vulnerability. A malicious actor with admin privileges may be able to inject malicious code into user …

Feb 6, 2024
CVE-2024-1255
5.3 MEDIUM

A vulnerability has been found in sepidz SepidzDigitalMenu up to 7.1.0728.1 and classified as problematic. This vulnerability affects unknown code of the file /Waiters. The …

Feb 6, 2024
CVE-2024-1254
4.7 MEDIUM

A vulnerability, which was classified as critical, was found in Byzoro Smart S20 Management Platform up to 20231120. This affects an unknown part of the …

Feb 6, 2024
CVE-2024-22331
6.2 MEDIUM

IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.19, 7.1 through 7.1.2.15, 7.2 through 7.2.3.8, 7.3 through 7.3.2.3, and IBM UrbanCode Deploy (UCD) - IBM DevOps Deploy …

Feb 6, 2024
CVE-2024-1253
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in Byzoro Smart S40 Management Platform up to 20240126. Affected by this issue is some …

Feb 6, 2024
CVE-2024-1252
5.5 MEDIUM

A vulnerability classified as critical was found in Tongda OA 2017 up to 11.9. Affected by this vulnerability is an unknown functionality of the file …

Feb 6, 2024
CVE-2024-24291
6.1 MEDIUM

An issue in the component /member/index/login of yzmcms v7.0 allows attackers to direct users to malicious sites via a crafted URL.

Feb 6, 2024
CVE-2024-23344
5.3 MEDIUM

Tuleap is an Open Source Suite to improve management of software developments and collaboration. Some users might get access to restricted information when a process …

Feb 6, 2024
CVE-2024-1251
5.5 MEDIUM

A vulnerability classified as critical has been found in Tongda OA 2017 up to 11.10. Affected is an unknown function of the file /general/email/outbox/delete.php. The …

Feb 6, 2024
CVE-2023-46183
5.3 MEDIUM

IBM PowerVM Hypervisor FW950.00 through FW950.90, FW1020.00 through FW1020.40, and FW1030.00 through FW1030.30 could allow a system administrator to obtain sensitive partition information. IBM X-Force …

Feb 6, 2024
CVE-2024-0911
5.5 MEDIUM

A flaw was found in indent, a program for formatting C code. This issue may allow an attacker to trick a user into processing a …

Feb 6, 2024
CVE-2024-0690
5.0 MEDIUM

An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in …

Feb 6, 2024
CVE-2024-24943
5.3 MEDIUM

In JetBrains Toolbox App before 2.2 a DoS attack was possible via a malicious SVG image

Feb 6, 2024
CVE-2024-24942
5.3 MEDIUM

In JetBrains TeamCity before 2023.11.3 path traversal allowed reading data within JAR archives

Feb 6, 2024
CVE-2024-24941
6.1 MEDIUM

In JetBrains IntelliJ IDEA before 2023.3.3 a plugin for JetBrains Space was able to send an authentication token to an inappropriate URL

Feb 6, 2024
CVE-2024-24938
5.3 MEDIUM

In JetBrains TeamCity before 2023.11.2 limited directory traversal was possible in the Kotlin DSL documentation

Feb 6, 2024
CVE-2024-24937
4.6 MEDIUM

In JetBrains TeamCity before 2023.11.2 stored XSS via agent distribution was possible

Feb 6, 2024
CVE-2024-24936
4.3 MEDIUM

In JetBrains TeamCity before 2023.11.2 access control at the S3 Artifact Storage plugin endpoint was missed

Feb 6, 2024
CVE-2024-0684
5.5 MEDIUM

A flaw was found in the GNU coreutils "split" program. A heap overflow with user-controlled data of multiple hundred bytes in length could occur in …

Feb 6, 2024
CVE-2023-4503
6.8 MEDIUM

An improper initialization vulnerability was found in Galleon. When using Galleon to provision custom EAP or EAP-XP servers, the servers are created unsecured. This issue …

Feb 6, 2024
CVE-2024-22365
5.5 MEDIUM

linux-pam (aka Linux PAM) before 1.6.0 allows attackers to cause a denial of service (blocked login process) via mkfifo because the openat call (for protect_dir) …

Feb 6, 2024
CVE-2023-32479
6.7 MEDIUM

Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server versions prior to 11.9.0 contain privilege escalation vulnerability due to improper ACL of …

Feb 6, 2024
CVE-2023-32474
6.6 MEDIUM

Dell Display Manager application, version 2.1.1.17 and prior, contain an insecure operation on windows junction/mount point. A local malicious user could potentially exploit this vulnerability …

Feb 6, 2024
CVE-2023-32454
6.3 MEDIUM

DUP framework version 4.9.4.36 and prior contains insecure operation on Windows junction/Mount point vulnerability. A local malicious standard user could exploit the vulnerability to create …

Feb 6, 2024
CVE-2023-28063
6.7 MEDIUM

Dell BIOS contains a Signed to Unsigned Conversion Error vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to …

Feb 6, 2024
CVE-2023-52239
6.5 MEDIUM

The XML parser in Magic xpi Integration Platform 4.13.4 allows XXE attacks, e.g., via onItemImport.

Feb 6, 2024
CVE-2023-28049
4.7 MEDIUM

Dell Command | Monitor, versions prior to 10.9, contain an arbitrary folder deletion vulnerability. A locally authenticated malicious user may exploit this vulnerability in order …

Feb 6, 2024
CVE-2023-33077
6.7 MEDIUM

Memory corruption in HLOS while converting from authorization token to HIDL vector.

Feb 6, 2024
CVE-2023-33076
5.9 MEDIUM

Memory corruption in Core when updating rollback version for TA and OTA feature is enabled.

Feb 6, 2024
CVE-2023-33069
6.7 MEDIUM

Memory corruption in Audio while processing the calibration data returned from ACDB loader.

Feb 6, 2024
CVE-2023-33068
6.7 MEDIUM

Memory corruption in Audio while processing IIR config data from AFE calibration block.

Feb 6, 2024
CVE-2023-33067
6.7 MEDIUM

Memory corruption in Audio while calling START command on host voice PCM multiple times for the same RX or TX tap points.

Feb 6, 2024
CVE-2023-33065
6.1 MEDIUM

Information disclosure in Audio while accessing AVCS services from ADSP payload.

Feb 6, 2024
CVE-2023-33064
5.5 MEDIUM

Transient DOS in Audio when invoking callback function of ASM driver.

Feb 6, 2024
CVE-2024-24808
4.7 MEDIUM

pyLoad is an open-source Download Manager written in pure Python. There is an open redirect vulnerability due to incorrect validation of input values when redirecting …

Feb 6, 2024
CVE-2024-20827
4.6 MEDIUM

Improper access control vulnerability in Samsung Gallery prior to version 14.5.04.4 allows physical attackers to access the picture using physical keyboard on the lockscreen.

Feb 6, 2024
CVE-2024-20826
5.5 MEDIUM

Implicit intent hijacking vulnerability in UPHelper library prior to version 4.0.0 allows local attackers to access sensitive information via implicit intent.

Feb 6, 2024
CVE-2024-20825
5.5 MEDIUM

Implicit intent hijacking vulnerability in IAP of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent.

Feb 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.