CVE Database

122268+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-33806
7.8 HIGH

Insecure default configurations in Hikvision Interactive Tablet DS-D5B86RB/B V2.3.0 build220119, allows attackers to execute arbitrary commands.

Apr 15, 2024
CVE-2020-22540
5.4 MEDIUM

Stored Cross-Site Scripting (XSS) vulnerability in Codoforum v4.9, allows attackers to execute arbitrary code and obtain sensitive information via crafted payload to Category name component.

Apr 15, 2024
CVE-2024-3493
8.6 HIGH

A specific malformed fragmented packet type (fragmented packets may be generated automatically by devices that send large amounts of data) can cause a major nonrecoverable …

Apr 15, 2024
CVE-2024-31651
6.1 MEDIUM

A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload …

Apr 15, 2024
CVE-2024-30656
7.5 HIGH

An issue in Fireboltt Dream Wristphone BSW202_FB_AAC_v2.0_20240110-20240110-1956 allows attackers to cause a Denial of Service (DoS) via a crafted deauth frame.

Apr 15, 2024
CVE-2024-2424
7.5 HIGH

An input validation vulnerability exists in the Rockwell Automation 5015-AENFTXT that causes the secondary adapter to result in a major nonrecoverable fault (MNRF) when malicious …

Apr 15, 2024
CVE-2020-22539
7.2 HIGH

An arbitrary file upload vulnerability in the Add Category function of Codoforum v4.9 allows attackers to execute arbitrary code via uploading a crafted file.

Apr 15, 2024
CVE-2024-31652
6.1 MEDIUM

A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload …

Apr 15, 2024
CVE-2024-31650
9.6 CRITICAL

A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload …

Apr 15, 2024
CVE-2024-31649
5.4 MEDIUM

A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload …

Apr 15, 2024
CVE-2024-31648
6.1 MEDIUM

Cross Site Scripting (XSS) in Insurance Management System v1.0, allows remote attackers to execute arbitrary web scripts or HTML via a crafted payload injected into …

Apr 15, 2024
CVE-2024-23561
4.3 MEDIUM

HCL DevOps Deploy / HCL Launch is vulnerable to sensitive information disclosure vulnerability due to insufficient obfuscation of sensitive values.

Apr 15, 2024
CVE-2024-23558
6.3 MEDIUM

HCL DevOps Deploy / HCL Launch does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.

Apr 15, 2024
CVE-2024-3804
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Vesystem Cloud Desktop up to 20240408. This issue affects some unknown processing of the …

Apr 15, 2024
CVE-2024-32036
5.3 MEDIUM

ImageSharp is a 2D graphics API. A data leakage flaw was found in ImageSharp's JPEG and TGA decoders. This vulnerability is triggered when an attacker …

Apr 15, 2024
CVE-2024-32035
5.3 MEDIUM

ImageSharp is a 2D graphics API. A vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory …

Apr 15, 2024
CVE-2024-31990
4.8 MEDIUM

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The API server does not enforce project sourceNamespaces which allows attackers to use the …

Apr 15, 2024
CVE-2024-31497
5.9 MEDIUM

In PuTTY 0.68 through 0.80 before 0.81, biased ECDSA nonce generation allows an attacker to recover a user's NIST P-521 secret key via a quick …

Apr 15, 2024
CVE-2024-30840
6.5 MEDIUM

A Stack Overflow vulnerability in Tenda AC15 v15.03.05.18 allows attackers to cause a denial of service via the LISTEN parameter in the fromDhcpListClient function.

Apr 15, 2024
CVE-2024-23560
4.4 MEDIUM

HCL DevOps Deploy / HCL Launch could be vulnerable to incomplete revocation of permissions when deleting a custom security resource type.

Apr 15, 2024
CVE-2023-45503
5.3 MEDIUM

SQL Injection vulnerability in Macrob7 Macs CMS 1.1.4f, allows remote attackers to execute arbitrary code, cause a denial of service (DoS), escalate privileges, and obtain …

Apr 15, 2024
CVE-2024-3803
6.3 MEDIUM

A vulnerability classified as critical was found in Vesystem Cloud Desktop up to 20240408. This vulnerability affects unknown code of the file /Public/webuploader/0.1.5/server/fileupload.php. The manipulation …

Apr 15, 2024
CVE-2024-28558
8.8 HIGH

SQL Injection vulnerability in sourcecodester Petrol pump management software v1.0, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via crafted …

Apr 15, 2024
CVE-2024-28557
9.8 CRITICAL

SQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via crafted …

Apr 15, 2024
CVE-2024-28556
9.8 CRITICAL

SQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via crafted …

Apr 15, 2024
CVE-2024-24487
6.8 MEDIUM

An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to cause a denial of service via crafted UDP packets using the …

Apr 15, 2024
CVE-2024-24486
9.1 CRITICAL

An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to edit device settings via the SAVE EEP_DATA command.

Apr 15, 2024
CVE-2024-24485
7.5 HIGH

An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to obtain sensitive information via the GET EEP_DATA command.

Apr 15, 2024
CVE-2024-31219
4.3 MEDIUM

Discourse-reactions is a plugin that allows user to add their reactions to the post. When whispers are enabled on a site via `whispers_allowed_groups` and reactions …

Apr 15, 2024
CVE-2024-2659
7.2 HIGH

A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevated privileges to execute system commands when performing …

Apr 15, 2024
CVE-2024-28056
9.8 CRITICAL

Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify projects. When the Authentication component is removed …

Apr 15, 2024
CVE-2024-23594
6.4 MEDIUM

A buffer overflow vulnerability was reported in a system recovery bootloader that was part of the Lenovo preloaded Windows 7 and 8 operating systems from …

Apr 15, 2024
CVE-2024-23593
6.7 MEDIUM

A vulnerability was reported in a system recovery bootloader that was part of the Lenovo preloaded Windows 7 and 8 operating systems from 2012 to …

Apr 15, 2024
CVE-2024-23559
6.1 MEDIUM

HCL DevOps Deploy / Launch is generating an obsolete HTTP header.

Apr 15, 2024
CVE-2024-22014
8.8 HIGH

An issue discovered in 360 Total Security Antivirus through 11.0.0.1061 for Windows allows attackers to gain escalated privileges via Symbolic Link Follow to Arbitrary File …

Apr 15, 2024
CVE-2023-4857
7.5 HIGH

An authentication bypass vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user to execute certain IPMI calls that could lead to …

Apr 15, 2024
CVE-2023-4856
8.8 HIGH

A format string vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user to execute arbitrary commands on a specific API endpoint.

Apr 15, 2024
CVE-2023-4855
7.2 HIGH

A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevated privileges to execute unauthorized commands via IPMI.

Apr 15, 2024
CVE-2023-48710
9.8 CRITICAL

iTop is an IT service management platform. Files from the `env-production` folder can be retrieved even though they should have restricted access. Hopefully, there is …

Apr 15, 2024
CVE-2023-48709
8.0 HIGH

iTop is an IT service management platform. When exporting data from backoffice or portal in CSV or Excel files, users' inputs may include malicious formulas …

Apr 15, 2024
CVE-2023-47626
8.8 HIGH

iTop is an IT service management platform. When displaying/editing the user's personal tokens, XSS attacks are possible. This vulnerability is fixed in 3.1.1.

Apr 15, 2024
CVE-2023-47622
8.8 HIGH

iTop is an IT service management platform. When dashlet are refreshed, XSS attacks are possible. This vulnerability is fixed in 3.0.4 and 3.1.1.

Apr 15, 2024
CVE-2023-47123
8.7 HIGH

iTop is an IT service management platform. By filling malicious code in an object friendlyname / complementary name, an XSS attack can be performed when …

Apr 15, 2024
CVE-2023-45808
4.1 MEDIUM

iTop is an IT service management platform. When creating or updating an object, extkey values aren't checked to be in the current user silo. In …

Apr 15, 2024
CVE-2023-44396
6.8 MEDIUM

iTop is an IT service management platform. Dashlet edits ajax endpoints can be used to produce XSS. Fixed in iTop 2.7.10, 3.0.4, and 3.1.1.

Apr 15, 2024
CVE-2023-43790
5.7 MEDIUM

iTop is an IT service management platform. By manipulating HTTP queries, a user can inject malicious content in the fields used for the object friendlyname …

Apr 15, 2024
CVE-2023-38511
5.0 MEDIUM

iTop is an IT service management platform. Dashboard editor : can load multiple files and URL, and full path disclosure on dashboard config file. This …

Apr 15, 2024
CVE-2024-3797
6.3 MEDIUM

A vulnerability was found in SourceCodester QR Code Bookmark System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file …

Apr 15, 2024
CVE-2024-31576

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not …

Apr 15, 2024
CVE-2024-3786
6.6 MEDIUM

Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through Device Synchronizations (/admin/DeviceReplication). Exploitation of this vulnerability could allow a remote user …

Apr 15, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.