CVE Database

122268+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-27309
7.4 HIGH

While an Apache Kafka cluster is being migrated from ZooKeeper mode to KRaft mode, in some cases ACLs will not be correctly enforced. Two preconditions …

Apr 12, 2024
CVE-2024-22526
5.5 MEDIUM

Buffer Overflow vulnerability in bandisoft bandiview v7.0, allows local attackers to cause a denial of service (DoS) via exr image file.

Apr 12, 2024
CVE-2024-30850

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2024-33434. Reason: This record is a duplicate of CVE-2024-33434. Notes: All CVE users should reference CVE-2024-33434 …

Apr 12, 2024
CVE-2024-30614
5.3 MEDIUM

An issue in Ametys CMS v4.5.0 and before allows attackers to obtain sensitive information via exposed resources to the error scope.

Apr 12, 2024
CVE-2024-22734
6.2 MEDIUM

An issue was discovered in AMCS Group Trux Waste Management Software before version 7.19.0018.26912, allows local attackers to obtain sensitive information via a static, hard-coded …

Apr 12, 2024
CVE-2023-49528
8.0 HIGH

Buffer Overflow vulnerability in FFmpeg version n6.1-3-g466799d4f5, allows a local attacker to execute arbitrary code and cause a denial of service (DoS) via the af_dialoguenhance.c:261:5 …

Apr 12, 2024
CVE-2023-44856
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a crafted script to the …

Apr 12, 2024
CVE-2023-44855
6.5 MEDIUM

Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019 allows a remote attacker to execute arbitrary code via a crafted script to the …

Apr 12, 2024
CVE-2023-44857
8.1 HIGH

An issue in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a crafted script to the sub_21D24 function in …

Apr 12, 2024
CVE-2023-44854
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a crafted script to the …

Apr 12, 2024
CVE-2023-44853
4.8 MEDIUM

\An issue was discovered in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a crafted script to the sub_219C4 …

Apr 12, 2024
CVE-2023-44852
8.2 HIGH

Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a crafted script to the …

Apr 12, 2024
CVE-2024-2801
6.4 MEDIUM

The Shopkeeper Extender plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'image_slide' shortcode in all versions up to, and including, 3.6 …

Apr 12, 2024
CVE-2024-2137
6.4 MEDIUM

The All-in-One Addons for Elementor – WidgetKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple pricing widgets (e.g. Pricing Single, Pricing Icon, …

Apr 12, 2024
CVE-2024-22357
5.4 MEDIUM

IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript …

Apr 12, 2024
CVE-2023-50307
5.4 MEDIUM

IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript …

Apr 12, 2024
CVE-2023-45186
4.8 MEDIUM

IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed …

Apr 12, 2024
CVE-2024-3092
8.7 HIGH

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 before 16.9.4, all versions starting from 16.10 before 16.10.2. A payload …

Apr 12, 2024
CVE-2024-2279
8.7 HIGH

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.7 to 16.8.6 all versions starting from 16.9 before 16.9.4, all versions …

Apr 12, 2024
CVE-2023-6678
4.3 MEDIUM

An issue has been discovered in GitLab EE affecting all versions before 16.8.6, all versions starting from 16.9 before 16.9.4, all versions starting from 16.10 …

Apr 12, 2024
CVE-2023-6489
4.3 MEDIUM

A denial of service vulnerability was identified in GitLab CE/EE, versions 16.7.7 prior to 16.8.6, 16.9 prior to 16.9.4 and 16.10 prior to 16.10.2 which …

Apr 12, 2024
CVE-2023-48865
6.5 MEDIUM

An issue discovered in Reportico Till 8.1.0 allows attackers to obtain sensitive information via execute_mode parameter of the URL.

Apr 11, 2024
CVE-2024-28458
7.5 HIGH

Null Pointer Dereference vulnerability in swfdump in swftools 0.9.2 allows attackers to crash the appliation via the function compileSWFActionCode in action/actioncompiler.c.

Apr 11, 2024
CVE-2024-27592
4.3 MEDIUM

Open Redirect vulnerability in Corezoid Process Engine v6.5.0 allows attackers to redirect to arbitrary websites via appending a crafted link to /login/ in the login …

Apr 11, 2024
CVE-2024-25852
8.8 HIGH

Linksys RE7000 v2.0.9, v2.0.11, and v2.0.15 have a command execution vulnerability in the "AccessControlList" parameter of the access control function point. An attacker can use …

Apr 11, 2024
CVE-2024-25376
7.8 HIGH

An issue discovered in Thesycon Software Solutions Gmbh & Co. KG TUSBAudio MSI-based installers before 5.68.0 allows a local attacker to execute arbitrary code via …

Apr 11, 2024
CVE-2024-29454

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not …

Apr 11, 2024
CVE-2024-22722
7.2 HIGH

Server Side Template Injection (SSTI) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary commands via the Group Name field under the add forms …

Apr 11, 2024
CVE-2024-22721
6.3 MEDIUM

Cross Site Request Forgery (CSRF) vulnerability in Form Tools 3.1.1 allows attackers to manipulate sensitive user data via crafted link.

Apr 11, 2024
CVE-2024-22719
8.1 HIGH

SQL Injection vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary SQL commands via the 'keyword' when searching for a client.

Apr 11, 2024
CVE-2024-22718
9.6 CRITICAL

Cross Site Scripting (XSS) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary code via the client_id parameter in the application URL.

Apr 11, 2024
CVE-2024-22717
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary code via the First Name field in the application.

Apr 11, 2024
CVE-2023-5394
7.4 HIGH

Server receiving a malformed message that where the GCL message hostname may be too large which may cause a stack overflow; resulting in possible remote …

Apr 11, 2024
CVE-2023-5393
7.4 HIGH

Server receiving a malformed message that causes a disconnect to a hostname may causing a stack overflow resulting in possible remote code execution. Honeywell recommends …

Apr 11, 2024
CVE-2023-5392
7.5 HIGH

C300 information leak due to an analysis feature which allows extracting more memory over the network than required by the function. Honeywell recommends updating to …

Apr 11, 2024
CVE-2024-30273
7.8 HIGH

Illustrator versions 28.3, 27.9.2 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of …

Apr 11, 2024
CVE-2024-30272
7.8 HIGH

Illustrator versions 28.3, 27.9.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the …

Apr 11, 2024
CVE-2024-30271
7.8 HIGH

Illustrator versions 28.3, 27.9.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the …

Apr 11, 2024
CVE-2023-50949
5.9 MEDIUM

IBM QRadar SIEM 7.5 could allow an unauthorized user to perform unauthorized actions due to improper certificate validation. IBM X-Force ID: 275706.

Apr 11, 2024
CVE-2024-31678
9.8 CRITICAL

Sourcecodester Loan Management System v1.0 is vulnerable to SQL Injection via the "password" parameter in the "login.php" file.

Apr 11, 2024
CVE-2024-0881
5.4 MEDIUM

The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel WordPress plugin before 2.2.76 does not have proper authorization, resulting in password …

Apr 11, 2024
CVE-2024-32105
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in ELEXtensions ELEX WooCommerce Dynamic Pricing and Discounts.This issue affects ELEX WooCommerce Dynamic Pricing and Discounts: from n/a through 2.1.2.

Apr 11, 2024
CVE-2023-29483
7.0 HIGH

eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from …

Apr 11, 2024
CVE-2024-32109
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Julien Berthelot / MPEmbed.Com WP Matterport Shortcode allows Cross Site Request Forgery.This issue affects WP Matterport Shortcode: from n/a …

Apr 11, 2024
CVE-2024-32108
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Stephanie Leary Convert Post Types.This issue affects Convert Post Types: from n/a through 1.4.

Apr 11, 2024
CVE-2024-32107
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in XLPlugins Finale Lite.This issue affects Finale Lite: from n/a through 2.18.0.

Apr 11, 2024
CVE-2024-32106
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in WP Compress WP Compress – Image Optimizer [All-In-One].This issue affects WP Compress – Image Optimizer [All-In-One]: from n/a through …

Apr 11, 2024
CVE-2024-32083
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Varun Kumar Easy Logo allows Stored XSS.This issue affects Easy Logo: from n/a …

Apr 11, 2024
CVE-2024-31937
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visitor Analytics TWIPLA (Visitor Analytics IO) allows Stored XSS.This issue affects TWIPLA (Visitor …

Apr 11, 2024
CVE-2024-31936
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in AyeCode Ltd UsersWP.This issue affects UsersWP: from n/a before 1.2.6.

Apr 11, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.