CVE Database

59927+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-23206
6.5 MEDIUM

An access issue was addressed with improved access restrictions. This issue is fixed in Safari 17.3, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS …

Jan 23, 2024
CVE-2023-42937
5.5 MEDIUM

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.7.5 and iPadOS 16.7.5, watchOS 10.2, …

Jan 23, 2024
CVE-2023-42935
5.5 MEDIUM

An authentication issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.6.4. A local attacker may be able to view …

Jan 23, 2024
CVE-2023-42888
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in iOS 16.7.5 and iPadOS 16.7.5, watchOS 10.2, macOS Ventura 13.6.4, macOS Sonoma 14.2, …

Jan 23, 2024
CVE-2023-42887
6.3 MEDIUM

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13.6.4, macOS Sonoma 14.2. An app may be able …

Jan 23, 2024
CVE-2023-40528
5.5 MEDIUM

This issue was addressed by removing the vulnerable code. This issue is fixed in tvOS 17, watchOS 10, macOS Sonoma 14, iOS 17 and iPadOS …

Jan 23, 2024
CVE-2024-23340
5.3 MEDIUM

@hono/node-server is an adapter that allows users to run Hono applications on Node.js. Since v1.3.0, @hono/node-server has used its own Request object with `url` behavior …

Jan 22, 2024
CVE-2024-23339
6.3 MEDIUM

hoolock is a suite of lightweight utilities designed to maintain a small footprint when bundled. Starting in version 2.0.0 and prior to version 2.2.1, utility …

Jan 22, 2024
CVE-2024-23677
4.3 MEDIUM

In Splunk Enterprise versions below 9.0.8, the Splunk RapidDiag utility discloses server responses from external applications in a log file.

Jan 22, 2024
CVE-2024-23676
4.6 MEDIUM

In Splunk versions below 9.0.8 and 9.1.3, the “mrollup” SPL command lets a low-privileged user view metrics on an index that they do not have …

Jan 22, 2024
CVE-2024-23675
6.5 MEDIUM

In Splunk Enterprise versions below 9.0.8 and 9.1.3, Splunk app key value store (KV Store) improperly handles permissions for users that use the REST application …

Jan 22, 2024
CVE-2023-47141
5.3 MEDIUM

IIBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user with CONNECT privileges to cause a denial of …

Jan 22, 2024
CVE-2023-7194
6.1 MEDIUM

The Meris WordPress theme through 1.1.2 does not sanitise and escape some parameters before outputting them back in the page, leading to Reflected Cross-Site Scripting …

Jan 22, 2024
CVE-2023-7170
6.1 MEDIUM

The EventON-RSVP WordPress plugin before 2.9.5 does not sanitise and escape some parameters before outputting it back in the page, leading to a Reflected Cross-Site …

Jan 22, 2024
CVE-2023-6626
4.8 MEDIUM

The Product Enquiry for WooCommerce WordPress plugin before 3.1 does not sanitise and escape some of its settings, which could allow high privilege users such …

Jan 22, 2024
CVE-2023-6625
4.3 MEDIUM

The Product Enquiry for WooCommerce WordPress plugin before 3.1 does not have a CSRF check in place when deleting inquiries, which could allow attackers to …

Jan 22, 2024
CVE-2023-6456
4.8 MEDIUM

The WP Review Slider WordPress plugin before 13.0 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Jan 22, 2024
CVE-2023-6447
5.3 MEDIUM

The EventPrime WordPress plugin before 3.3.6 lacks authentication and authorization, allowing unauthenticated visitors to access private and password protected Events by guessing their numeric id/event …

Jan 22, 2024
CVE-2023-6384
4.3 MEDIUM

The WP User Profile Avatar WordPress plugin before 1.0.1 does not properly check for authorisation, allowing authors to delete and update arbitrary avatar

Jan 22, 2024
CVE-2023-6290
4.8 MEDIUM

The SEOPress WordPress plugin before 7.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Jan 22, 2024
CVE-2023-47747
5.3 MEDIUM

IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.1, 10.5, and 11.1 could allow an authenticated user with CONNECT privileges to cause …

Jan 22, 2024
CVE-2023-47158
5.3 MEDIUM

IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1 and 11.5 could allow an authenticated user with CONNECT privileges to cause …

Jan 22, 2024
CVE-2023-47152
5.9 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to an insecure cryptographic algorithm and to information disclosure in stack …

Jan 22, 2024
CVE-2023-27859
6.5 MEDIUM

IBM Db2 10.1, 10.5, and 11.1 could allow a remote user to execute arbitrary code caused by installing like named jar files across multiple databases. …

Jan 22, 2024
CVE-2024-0606
6.1 MEDIUM

An attacker could execute unauthorized script on a legitimate site through UXSS using window.open() by opening a javascript URI leading to unauthorized actions within the …

Jan 22, 2024
CVE-2024-0430
5.5 MEDIUM

IObit Malware Fighter v11.0.0.1274 is vulnerable to a Denial of Service vulnerability by triggering the 0x8001E00C IOCTL code of the ImfHpRegFilter.sys driver.

Jan 22, 2024
CVE-2023-50308
6.5 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5 under certain circumstances could allow an authenticated user to the database to cause …

Jan 22, 2024
CVE-2023-47746
5.3 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow an authenticated user with CONNECT privileges to cause …

Jan 22, 2024
CVE-2023-45193
5.9 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 federated server is vulnerable to a denial of service when a specially crafted …

Jan 22, 2024
CVE-2024-0784
6.3 MEDIUM

A vulnerability was found in hongmaple octopus 1.0. It has been classified as critical. Affected is an unknown function of the file /system/role/list. The manipulation …

Jan 22, 2024
CVE-2024-0783
6.3 MEDIUM

A vulnerability was found in Project Worlds Online Admission System 1.0 and classified as critical. This issue affects some unknown processing of the file documents.php. …

Jan 22, 2024
CVE-2023-44395
4.9 MEDIUM

Autolab is a course management service that enables instructors to offer autograded programming assignments to their students over the Web. Path traversal vulnerabilities were discovered …

Jan 22, 2024
CVE-2020-36772
4.4 MEDIUM

CloudLinux CageFS 7.0.8-2 or below insufficiently restricts file paths supplied to the sendmail proxy command. This allows local users to read and write arbitrary files …

Jan 22, 2024
CVE-2024-0775
6.7 MEDIUM

A use-after-free flaw was found in the __ext4_remount in fs/ext4/super.c in ext4 in the Linux kernel. This flaw allows a local user to cause an …

Jan 22, 2024
CVE-2024-22113
6.1 MEDIUM

Open redirect vulnerability in Access analysis CGI An-Analyzer released in 2023 December 31 and earlier allows a remote unauthenticated attacker to redirect users to arbitrary …

Jan 22, 2024
CVE-2024-23770
5.5 MEDIUM

darkhttpd through 1.15 allows local users to discover credentials (for --auth) by listing processes and their arguments.

Jan 22, 2024
CVE-2024-0774
5.3 MEDIUM

A vulnerability was found in Any-Capture Any Sound Recorder 2.93. It has been declared as problematic. This vulnerability affects unknown code of the component Registration …

Jan 22, 2024
CVE-2024-0772
5.3 MEDIUM

A vulnerability was found in Nsasoft ShareAlarmPro 2.1.4 and classified as problematic. Affected by this issue is some unknown functionality of the component Registration Handler. …

Jan 22, 2024
CVE-2024-0771
5.3 MEDIUM

A vulnerability has been found in Nsasoft Product Key Explorer 4.0.9 and classified as problematic. Affected by this vulnerability is an unknown functionality of the …

Jan 21, 2024
CVE-2024-0770
4.4 MEDIUM

A vulnerability, which was classified as critical, was found in European Chemicals Agency IUCLID 7.10.3 on Windows. Affected is an unknown function of the file …

Jan 21, 2024
CVE-2024-0769
5.3 MEDIUM KEV

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DIR-859 1.06B01. It has been rated as critical. Affected by this issue is some …

Jan 21, 2024
CVE-2024-23725
6.1 MEDIUM

Ghost before 5.76.0 allows XSS via a post excerpt in excerpt.js. An XSS payload can be rendered in post summaries.

Jan 21, 2024
CVE-2024-0679
6.5 MEDIUM

The ColorMag theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the plugin_action_callback() function in all versions up to, …

Jan 20, 2024
CVE-2024-0623
4.3 MEDIUM

The VK Block Patterns plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.31.1.1. This is due to …

Jan 20, 2024
CVE-2023-46447
4.3 MEDIUM

The POPS! Rebel application 5.0 for Android, in POPS! Rebel Bluetooth Glucose Monitoring System, sends unencrypted glucose measurements over BLE.

Jan 20, 2024
CVE-2024-23332
4.0 MEDIUM

The Notary Project is a set of specifications and tools intended to provide a cross-industry standard for securing software supply chains by using authentic container …

Jan 19, 2024
CVE-2024-23688
5.3 MEDIUM

Consensys Discovery versions less than 0.4.5 uses the same AES/GCM nonce for the entire session. which should ideally be unique for every message. The node's …

Jan 19, 2024
CVE-2024-23686
5.3 MEDIUM

DependencyCheck for Maven 9.0.0 to 9.0.6, for CLI version 9.0.0 to 9.0.5, and for Ant versions 9.0.0 to 9.0.5, when used in debug mode, allows …

Jan 19, 2024
CVE-2024-0738
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in 个人开源 mldong 1.0. This issue affects the function ExpressionEngine of the file com/mldong/modules/wf/engine/model/DecisionModel.java. The …

Jan 19, 2024
CVE-2024-0737
5.3 MEDIUM

A vulnerability classified as problematic was found in Xlightftpd Xlight FTP Server 1.1. This vulnerability affects unknown code of the component Login. The manipulation of …

Jan 19, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.