CVE Database

59927+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-39303
5.3 MEDIUM

An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to compromise the security …

Feb 2, 2024
CVE-2023-39302
6.6 MEDIUM

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute …

Feb 2, 2024
CVE-2023-32967
5.0 MEDIUM

An incorrect authorization vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to bypass intended …

Feb 2, 2024
CVE-2021-21575
5.9 MEDIUM

Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain an Observable Timing Discrepancy Vulnerability.

Feb 2, 2024
CVE-2023-6673
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in National Keep Cyber Security Services CyberMath allows Reflected XSS.This issue affects CyberMath: from …

Feb 2, 2024
CVE-2023-6672
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in National Keep Cyber Security Services CyberMath allows Stored XSS.This issue affects CyberMath: from …

Feb 2, 2024
CVE-2023-47148
5.3 MEDIUM

IBM Storage Protect Plus Server 10.1.0 through 10.1.15.2 Admin Console could allow a remote attacker to obtain sensitive information due to improper validation of unsecured …

Feb 2, 2024
CVE-2023-47144
6.1 MEDIUM

IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the …

Feb 2, 2024
CVE-2024-0963
6.4 MEDIUM

The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's CP_CALCULATED_FIELDS shortcode in all versions up to, and including, …

Feb 2, 2024
CVE-2024-0844
4.7 MEDIUM

The Popup More Popups, Lightboxes, and more popup modules plugin for WordPress is vulnerable to Local File Inclusion in version 2.1.6 via the ycfChangeElementData() function. …

Feb 2, 2024
CVE-2024-24388
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability in XunRuiCMS versions v4.6.2 and before, allows remote attackers to obtain sensitive information via crafted malicious requests to the background login.

Feb 2, 2024
CVE-2023-51820
6.8 MEDIUM

An issue in Blurams Lumi Security Camera (A31C) v.2.3.38.12558 allows a physically proximate attackers to execute arbitrary code.

Feb 2, 2024
CVE-2023-51072
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the NOC component of Nagios XI version up to and including 2024R1 allows low-privileged users to execute malicious …

Feb 2, 2024
CVE-2021-22281
6.3 MEDIUM

: Relative Path Traversal vulnerability in B&R Industrial Automation Automation Studio allows Relative Path Traversal.This issue affects Automation Studio: from 4.0 through 4.12.

Feb 2, 2024
CVE-2024-21863
4.7 MEDIUM

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through improper input.

Feb 2, 2024
CVE-2024-0285
4.7 MEDIUM

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through improper input.

Feb 2, 2024
CVE-2023-45734
4.2 MEDIUM

in OpenHarmony v3.2.4 and prior versions allow an adjacent attacker arbitrary code execution through out-of-bounds write.

Feb 2, 2024
CVE-2024-1162
4.3 MEDIUM

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.10.29. This is due …

Feb 2, 2024
CVE-2024-1047
5.3 MEDIUM

Multiple plugins and/or themes for WordPress with the ThemeIsle SDK are vulnerable to unauthorized modification of data due to a missing capability check on the …

Feb 2, 2024
CVE-2024-21485
6.5 MEDIUM

Versions of the package dash-core-components before 2.13.0; versions of the package dash-core-components before 2.0.0; versions of the package dash before 2.15.0; versions of the package …

Feb 2, 2024
CVE-2024-1073
6.4 MEDIUM

The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'filter_array' parameter in all versions up to, and including, 5.1.3 due …

Feb 2, 2024
CVE-2024-0685
5.9 MEDIUM

The Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Second Order SQL Injection via …

Feb 2, 2024
CVE-2023-38263
6.5 MEDIUM

IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow an authenticated user to perform unauthorized actions due to improper access controls. IBM X-Force ID: …

Feb 2, 2024
CVE-2023-38020
4.3 MEDIUM

IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow an authenticated user to manipulate output written to log files. IBM X-Force ID: 260576.

Feb 2, 2024
CVE-2022-40744
4.8 MEDIUM

IBM Aspera Faspex 5.0.6 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering …

Feb 2, 2024
CVE-2023-50962
5.9 MEDIUM

IBM PowerSC 1.3, 2.0, and 2.1 MFA does not implement the "HTTP Strict Transport Security" (HSTS) web security policy mechanism. IBM X-Force ID: 276004.

Feb 2, 2024
CVE-2023-50941
6.3 MEDIUM

IBM PowerSC 1.3, 2.0, and 2.1 does not provide logout functionality, which could allow an authenticated user to gain access to an unauthorized user using …

Feb 2, 2024
CVE-2023-50938
6.5 MEDIUM

IBM PowerSC 1.3, 2.0, and 2.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit …

Feb 2, 2024
CVE-2023-50935
6.5 MEDIUM

IBM PowerSC 1.3, 2.0, and 2.1 fails to properly restrict access to a URL or resource, which may allow a remote attacker to obtain unauthorized …

Feb 2, 2024
CVE-2023-50934
5.3 MEDIUM

IBM PowerSC 1.3, 2.0, and 2.1 uses single-factor authentication which can lead to unnecessary risk of compromise when compared with the benefits of a dual-factor …

Feb 2, 2024
CVE-2023-46344
5.4 MEDIUM

A vulnerability in Solar-Log Base 15 Firmware 6.0.1 Build 161, and possibly other Solar-Log Base products, allows an attacker to escalate their privileges by exploiting …

Feb 2, 2024
CVE-2023-32333
6.5 MEDIUM

IBM Maximo Asset Management 7.6.1.3 could allow a remote attacker to log into the admin panel due to improper access controls. IBM X-Force ID: 255073.

Feb 2, 2024
CVE-2023-50940
5.3 MEDIUM

IBM PowerSC 1.3, 2.0, and 2.1 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information …

Feb 2, 2024
CVE-2023-50937
5.9 MEDIUM

IBM PowerSC 1.3, 2.0, and 2.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: …

Feb 2, 2024
CVE-2023-50936
6.3 MEDIUM

IBM PowerSC 1.3, 2.0, and 2.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. …

Feb 2, 2024
CVE-2023-50933
6.1 MEDIUM

IBM PowerSC 1.3, 2.0, and 2.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed …

Feb 2, 2024
CVE-2023-50327
5.3 MEDIUM

IBM PowerSC 1.3, 2.0, and 2.1 uses insecure HTTP methods which could allow a remote attacker to perform unauthorized file request modification. IBM X-Force ID: …

Feb 2, 2024
CVE-2024-22096
6.5 MEDIUM

In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an attacker can append path traversal characters to the filename when using a specific …

Feb 2, 2024
CVE-2024-21869
6.2 MEDIUM

In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the affected product stores plaintext credentials in various places. This may allow an attacker …

Feb 2, 2024
CVE-2024-21866
5.3 MEDIUM

In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the affected product responds back with an error message containing sensitive data if it …

Feb 2, 2024
CVE-2024-21794
5.4 MEDIUM

In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an attacker can redirect users to malicious pages through the login page.

Feb 2, 2024
CVE-2023-50939
5.9 MEDIUM

IBM PowerSC 1.3, 2.0, and 2.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: …

Feb 2, 2024
CVE-2024-23034
6.1 MEDIUM

Cross Site Scripting vulnerability in the input parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.

Feb 1, 2024
CVE-2024-23033
6.1 MEDIUM

Cross Site Scripting vulnerability in the path parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.

Feb 1, 2024
CVE-2024-23032
6.1 MEDIUM

Cross Site Scripting vulnerability in num parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.

Feb 1, 2024
CVE-2024-23031
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in is_water parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.

Feb 1, 2024
CVE-2024-22927
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in the func parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.

Feb 1, 2024
CVE-2024-24755
4.3 MEDIUM

discourse-group-membership-ip-block is a discourse plugin that adds support for adding users to groups based on their IP address. discourse-group-membership-ip-block was sending all group custom fields …

Feb 1, 2024
CVE-2024-1040
4.4 MEDIUM

Gessler GmbH WEB-MASTER user account is stored using a weak hashing algorithm. The attacker can restore the passwords by breaking the hashes stored on the …

Feb 1, 2024
CVE-2023-47256
5.5 MEDIUM

ConnectWise ScreenConnect through 23.8.4 allows local users to connect to arbitrary relay servers via implicit trust of proxy settings

Feb 1, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.