CVE Database

59927+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-31274
5.3 MEDIUM

AVEVA PI Server versions 2023 and 2018 SP3 P05 and prior contain a vulnerability that could allow an unauthenticated user to cause the PI Message …

Jan 18, 2024
CVE-2023-28901
5.3 MEDIUM

The Skoda Automotive cloud contains a Broken Access Control vulnerability, allowing remote attackers to obtain recent trip data, vehicle mileage, fuel consumption, average and maximum …

Jan 18, 2024
CVE-2023-28900
5.3 MEDIUM

The Skoda Automotive cloud contains a Broken Access Control vulnerability, allowing to obtain nicknames and other user identifiers of Skoda Connect service users by specifying …

Jan 18, 2024
CVE-2024-0607
6.6 MEDIUM

A flaw was found in the Netfilter subsystem in the Linux kernel. The issue is in the nft_byteorder_eval() function, where the code iterates through a …

Jan 18, 2024
CVE-2024-0408
5.5 MEDIUM

A flaw was found in the X.Org server. The GLX PBuffer code does not call the XACE hook when creating the buffer, leaving it unlabeled. …

Jan 18, 2024
CVE-2024-22549
5.4 MEDIUM

FlyCms 1.0 is vulnerable to Cross Site Scripting (XSS) in the email settings of the website settings section.

Jan 18, 2024
CVE-2024-22548
5.4 MEDIUM

FlyCms 1.0 is vulnerable to Cross Site Scripting (XSS) in the system website settings website name section.

Jan 18, 2024
CVE-2023-7153
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Macroturk Software and Internet Technologies Macro-Bel allows Reflected XSS.This issue affects Macro-Bel: before …

Jan 18, 2024
CVE-2021-33631
5.5 MEDIUM

Integer Overflow or Wraparound vulnerability in openEuler kernel on Linux (filesystem modules) allows Forced Integer Overflow.This issue affects openEuler kernel: from 4.19.90 before 4.19.90-2401.3, from …

Jan 18, 2024
CVE-2021-33630
5.5 MEDIUM

NULL Pointer Dereference vulnerability in openEuler kernel on Linux (network modules) allows Pointer Manipulation. This vulnerability is associated with program files net/sched/sch_cbs.C. This issue affects …

Jan 18, 2024
CVE-2024-0669
6.3 MEDIUM

A Cross-Frame Scripting vulnerability has been found on Plone CMS affecting verssion below 6.0.5. An attacker could store a malicious URL to be opened by …

Jan 18, 2024
CVE-2023-51464
5.4 MEDIUM

Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to …

Jan 18, 2024
CVE-2023-51463
5.4 MEDIUM

Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a …

Jan 18, 2024
CVE-2024-0580
6.5 MEDIUM

Omission of user-controlled key authorization in the IDMSistemas platform, affecting the QSige product. This vulnerability allows an attacker to extract sensitive information from the API …

Jan 18, 2024
CVE-2024-0381
6.4 MEDIUM

The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the use of the 'tag' attribute in the wprm-recipe-name, wprm-recipe-date, and …

Jan 18, 2024
CVE-2023-6970
6.1 MEDIUM

The WP Recipe Maker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘Referer' header in all versions up to, and including, 9.1.0 …

Jan 18, 2024
CVE-2023-6958
6.4 MEDIUM

The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 9.1.0 …

Jan 18, 2024
CVE-2024-0655
5.5 MEDIUM

A vulnerability has been found in Novel-Plus 4.3.0-RC1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /novel/bookSetting/list. The …

Jan 18, 2024
CVE-2023-48359
4.4 MEDIUM

In autotest driver, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with …

Jan 18, 2024
CVE-2023-48358
4.4 MEDIUM

In drm driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Jan 18, 2024
CVE-2023-48357
4.4 MEDIUM

In vsp driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Jan 18, 2024
CVE-2023-48356
4.4 MEDIUM

In jpg driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Jan 18, 2024
CVE-2023-48355
4.4 MEDIUM

In jpg driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Jan 18, 2024
CVE-2023-48354
5.5 MEDIUM

In telephone service, there is a possible improper input validation. This could lead to local information disclosure with no additional execution privileges needed

Jan 18, 2024
CVE-2023-48353
4.4 MEDIUM

In vsp driver, there is a possible use after free due to a logic error. This could lead to local denial of service with System …

Jan 18, 2024
CVE-2023-48352
5.5 MEDIUM

In phasecheckserver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with …

Jan 18, 2024
CVE-2023-48351
5.5 MEDIUM

In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Jan 18, 2024
CVE-2023-48350
5.5 MEDIUM

In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Jan 18, 2024
CVE-2023-48349
5.5 MEDIUM

In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Jan 18, 2024
CVE-2023-48348
5.5 MEDIUM

In video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with …

Jan 18, 2024
CVE-2023-48347
5.5 MEDIUM

In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with …

Jan 18, 2024
CVE-2023-48346
5.5 MEDIUM

In video decoder, there is a possible improper input validation. This could lead to local denial of service with no additional execution privileges needed

Jan 18, 2024
CVE-2023-48345
5.5 MEDIUM

In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with …

Jan 18, 2024
CVE-2023-48344
5.5 MEDIUM

In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with …

Jan 18, 2024
CVE-2023-48343
5.5 MEDIUM

In video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with …

Jan 18, 2024
CVE-2023-48342
4.4 MEDIUM

In media service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Jan 18, 2024
CVE-2023-48341
5.5 MEDIUM

In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with …

Jan 18, 2024
CVE-2023-48340
5.5 MEDIUM

In video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with …

Jan 18, 2024
CVE-2023-48339
4.4 MEDIUM

In jpg driver, there is a possible missing permission check. This could lead to local information disclosure with System execution privileges needed

Jan 18, 2024
CVE-2024-0654
5.3 MEDIUM

A vulnerability, which was classified as problematic, was found in DeepFaceLab pretrained DF.wf.288res.384.92.72.22. Affected is an unknown function of the file mainscripts/Util.py. The manipulation leads …

Jan 18, 2024
CVE-2024-0651
6.3 MEDIUM

A vulnerability was found in PHPGurukul Company Visitor Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Jan 18, 2024
CVE-2023-6184
5.0 MEDIUM

Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting

Jan 18, 2024
CVE-2021-4433
5.3 MEDIUM

A vulnerability was found in Karjasoft Sami HTTP Server 2.0. It has been classified as problematic. Affected is an unknown function of the component HTTP …

Jan 18, 2024
CVE-2024-23525
6.5 MEDIUM

The Spreadsheet::ParseXLSX package before 0.30 for Perl allows XXE attacks because it neglects to use the no_xxe option of XML::Twig.

Jan 18, 2024
CVE-2024-0650
4.3 MEDIUM

A vulnerability was found in Project Worlds Visitor Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file …

Jan 18, 2024
CVE-2023-6340
5.5 MEDIUM

SonicWall Capture Client version 3.7.10, NetExtender client version 10.2.337 and earlier versions are installed with sfpmonitor.sys driver. The driver has been found to be vulnerable …

Jan 18, 2024
CVE-2024-0649
6.3 MEDIUM

A vulnerability was found in ZhiHuiYun up to 4.4.13 and classified as critical. This issue affects the function download_network_image of the file /app/Http/Controllers/ImageController.php of the …

Jan 17, 2024
CVE-2024-22414
6.5 MEDIUM

flaskBlog is a simple blog app built with Flask. Improper storage and rendering of the `/user/<user>` page allows a user's comments to execute arbitrary javascript …

Jan 17, 2024
CVE-2023-5914
5.4 MEDIUM

Cross-site scripting (XSS)

Jan 17, 2024
CVE-2023-6548
5.5 MEDIUM KEV

Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with …

Jan 17, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.