CVE Database

122268+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-22343
4.0 MEDIUM

IBM TXSeries for Multiplatforms 8.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: …

May 14, 2024
CVE-2024-22064
8.3 HIGH

ZTE ZXUN-ePDG product, which serves as the network node of the VoWifi system, under by default configuration, uses a set of non-unique cryptographic keys during …

May 14, 2024
CVE-2024-1693
4.3 MEDIUM

The SP Project & Document Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the cdm_save_category …

May 14, 2024
CVE-2024-1467
4.3 MEDIUM

The Starter Templates — Elementor, WordPress & Beaver Builder Templates plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and …

May 14, 2024
CVE-2024-1230
4.3 MEDIUM

The SimpleShop plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.10.0. This is due to missing or …

May 14, 2024
CVE-2024-1229
5.3 MEDIUM

The SimpleShop plugin for WordPress is vulnerable to unauthorized disconnection from SimpleShop due to a missing capability check on the maybe_disconnect_simpleshop function in all versions …

May 14, 2024
CVE-2024-1166
6.4 MEDIUM

The Image Hover Effects – Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Hover Effects Widget in all …

May 14, 2024
CVE-2024-0445
6.4 MEDIUM

The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's element attributes in all versions up to, …

May 14, 2024
CVE-2024-0100
6.5 MEDIUM

NVIDIA Triton Inference Server for Linux contains a vulnerability in the tracing API, where a user can corrupt system files. A successful exploit of this …

May 14, 2024
CVE-2024-0098
5.5 MEDIUM

NVIDIA ChatRTX for Windows contains a vulnerability in the ChatRTX UI and backend, where a user can cause a clear-text transmission of sensitive information issue …

May 14, 2024
CVE-2024-0097
7.5 HIGH

NVIDIA ChatRTX for Windows contains a vulnerability in ChatRTX UI, where a user can cause an improper privilege management issue by exploiting interprocess communication between …

May 14, 2024
CVE-2024-0096
7.5 HIGH

NVIDIA ChatRTX for Windows contains a vulnerability in Chat RTX UI, where a user can cause an improper privilege management issue by sending user inputs …

May 14, 2024
CVE-2024-0088
5.5 MEDIUM

NVIDIA Triton Inference Server for Linux contains a vulnerability in shared memory APIs, where a user can cause an improper memory access issue by a …

May 14, 2024
CVE-2024-0087
9.0 CRITICAL

NVIDIA Triton Inference Server for Linux contains a vulnerability where a user can set the logging location to an arbitrary file. If this file exists, …

May 14, 2024
CVE-2023-6688
6.5 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.11 prior to 16.11.2. A problem with the processing logic for Google …

May 14, 2024
CVE-2023-6682
6.5 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting …

May 14, 2024
CVE-2023-6327
5.3 MEDIUM

The ShopLentor (formerly WooLentor) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the purchased_new_products function in …

May 14, 2024
CVE-2023-5971
4.8 MEDIUM

The Save as PDF Plugin by Pdfcrowd WordPress plugin before 3.2.0 does not sanitise and escape some of its settings, which could allow high privilege …

May 14, 2024
CVE-2023-5447
5.5 MEDIUM

Missing lock check in SynHsaService may create a use-after-free condition which causes abnormal termination of the service, resulting in denial of service for the Synaptics …

May 14, 2024
CVE-2023-5052
6.3 MEDIUM

vulnerability in Uniform Server Zero, version 10.2.5, consisting of an XSS through the /us_extra/phpinfo.php page. This vulnerability could allow a remote user to send a …

May 14, 2024
CVE-2023-52721
6.2 MEDIUM

The WindowManager module has a vulnerability in permission control. Impact: Successful exploitation of this vulnerability may affect confidentiality.

May 14, 2024
CVE-2023-52720
4.1 MEDIUM

Race condition vulnerability in the soundtrigger module Impact: Successful exploitation of this vulnerability will affect availability.

May 14, 2024
CVE-2023-52719
7.1 HIGH

Privilege escalation vulnerability in the PMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

May 14, 2024
CVE-2023-52656
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: io_uring: drop any code related to SCM_RIGHTS This is dead code after we dropped support …

May 14, 2024
CVE-2023-52655
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: aqc111: check packet for fixup for true limit If a device sends a packet …

May 14, 2024
CVE-2023-52654
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: io_uring/af_unix: disable sending io_uring over sockets File reference cycles have caused lots of problems for …

May 14, 2024
CVE-2023-52384
4.7 MEDIUM

Double-free vulnerability in the RSMC module Impact: Successful exploitation of this vulnerability will affect availability.

May 14, 2024
CVE-2023-52383
4.7 MEDIUM

Double-free vulnerability in the RSMC module Impact: Successful exploitation of this vulnerability will affect availability.

May 14, 2024
CVE-2023-50718
6.5 MEDIUM

NocoDB is software for building databases as spreadsheets. Prior to version 0.202.10, an authenticated attacker with create access could conduct a SQL Injection attack on …

May 14, 2024
CVE-2023-50717
5.7 MEDIUM

NocoDB is software for building databases as spreadsheets. Starting in verson 0.202.6 and prior to version 0.202.10, an attacker can upload a html file with …

May 14, 2024
CVE-2023-49781
7.3 HIGH

NocoDB is software for building databases as spreadsheets. Prior to 0.202.9, a stored cross-site scripting vulnerability exists within the Formula virtual cell comments functionality. The …

May 14, 2024
CVE-2023-47712
7.8 HIGH

IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a local user to gain elevated privileges on the system due to improper permissions control. …

May 14, 2024
CVE-2023-47711
2.7 LOW

IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow an authenticated user to upload files that would cause a denial of service. IBM X-Force …

May 14, 2024
CVE-2023-47709
9.1 CRITICAL

IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially …

May 14, 2024
CVE-2023-46870
7.3 HIGH

extcap/nrf_sniffer_ble.py, extcap/nrf_sniffer_ble.sh, extcap/SnifferAPI/*.py in Nordic Semiconductor nRF Sniffer for Bluetooth LE 3.0.0, 3.1.0, 4.0.0, 4.1.0, and 4.1.1 have set incorrect file permission, which allows attackers …

May 14, 2024
CVE-2023-43040
6.5 MEDIUM

IBM Spectrum Fusion HCI 2.5.2 through 2.7.2 could allow an attacker to perform unauthorized actions in RGW for Ceph due to improper bucket access. IBM …

May 14, 2024
CVE-2023-42955
4.9 MEDIUM

Claris International has successfully resolved an issue of potentially exposing password information to front-end websites when signed in to the Admin Console with an administrator …

May 14, 2024
CVE-2023-38264
5.9 MEDIUM

The IBM SDK, Java Technology Edition's Object Request Broker (ORB) 7.1.0.0 through 7.1.5.21 and 8.0.0.0 through 8.0.8.21 is vulnerable to a denial of service attack …

May 14, 2024
CVE-2023-37526
6.5 MEDIUM

HCL DRYiCE Lucy (now AEX) is affected by a Cross Origin Resource Sharing (CORS) vulnerability. The mobile app is vulnerable to a CORS misconfiguration which …

May 14, 2024
CVE-2023-29881
6.5 MEDIUM

phpok 6.4.003 is vulnerable to SQL injection in the function index_f() in phpok64/framework/api/call_control.php.

May 14, 2024
CVE-2023-26863

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not …

May 14, 2024
CVE-2023-26566
8.6 HIGH

Sangoma FreePBX 1805 through 2203 on Linux contains hardcoded credentials for the Asterisk REST Interface (ARI), which allows remote attackers to reconfigure Asterisk and make …

May 14, 2024
CVE-2022-4967
7.7 HIGH

strongSwan versions 5.9.2 through 5.9.5 are affected by authorization bypass through improper validation of certificate with host mismatch (CWE-297). When certificates are used to authenticate …

May 14, 2024
CVE-2022-32510
7.1 HIGH

An issue was discovered on certain Nuki Home Solutions devices. The HTTP API exposed by a Bridge used an unencrypted channel to provide an administrative …

May 14, 2024
CVE-2022-32509
8.8 HIGH

An issue was discovered on certain Nuki Home Solutions devices. Lack of certificate validation on HTTP communications allows attackers to intercept and tamper data. This …

May 14, 2024
CVE-2022-32508
7.5 HIGH

An issue was discovered on certain Nuki Home Solutions devices. By sending a malformed HTTP verb, it is possible to force a reboot of the …

May 14, 2024
CVE-2022-32507
8.8 HIGH

An issue was discovered on certain Nuki Home Solutions devices. Some BLE commands, which should have been designed to be only called from privileged accounts, …

May 14, 2024
CVE-2022-32506
6.4 MEDIUM

An issue was discovered on certain Nuki Home Solutions devices. An attacker with physical access to the circuit board could use the SWD debug features …

May 14, 2024
CVE-2022-32505
7.1 HIGH

An issue was discovered on certain Nuki Home Solutions devices. It is possible to send multiple BLE malformed packets to block some of the functionality …

May 14, 2024
CVE-2022-32504
9.8 CRITICAL

An issue was discovered on certain Nuki Home Solutions devices. The code used to parse the JSON objects received from the WebSocket service provided by …

May 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.