CVE Database

122268+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-27719
6.1 MEDIUM

A cross site scripting (XSS) vulnerability in rems FAQ Management System v.1.0 allows a remote attacker to obtain sensitive information via a crafted payload to …

Mar 28, 2024
CVE-2024-25971
5.5 MEDIUM

Dell PowerProtect Data Manager, version 19.15, contains an XML External Entity Injection vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to …

Mar 28, 2024
CVE-2024-25963
5.9 MEDIUM

Dell PowerScale OneFS, versions 8.2.2.x through 9.5.0.x contains a use of a broken cryptographic algorithm vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, …

Mar 28, 2024
CVE-2024-25960
7.3 HIGH

Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains a cleartext transmission of sensitive information vulnerability. A local low privileged attacker could potentially exploit this vulnerability, …

Mar 28, 2024
CVE-2024-25955
7.2 HIGH

Dell vApp Manager, versions prior to 9.2.4.9 contain a Command Injection Vulnerability. An authorized attacker could potentially exploit this vulnerability leading to an execution of …

Mar 28, 2024
CVE-2024-25954
5.3 MEDIUM

Dell PowerScale OneFS, versions 9.5.0.x through 9.7.0.x, contain an insufficient session expiration vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial …

Mar 28, 2024
CVE-2024-25953
6.0 MEDIUM

Dell PowerScale OneFS versions 9.4.0.x through 9.7.0.x contains an UNIX symbolic link (symlink) following vulnerability. A local high privileged attacker could potentially exploit this vulnerability, …

Mar 28, 2024
CVE-2024-25952
6.0 MEDIUM

Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains an UNIX symbolic link (symlink) following vulnerability. A local high privileged attacker could potentially exploit this vulnerability, …

Mar 28, 2024
CVE-2024-25946
7.2 HIGH

Dell vApp Manager, versions prior to 9.2.4.9 contain a Command Injection Vulnerability. An authorized attacker could potentially exploit this vulnerability leading to an execution of …

Mar 28, 2024
CVE-2024-25961
6.0 MEDIUM

Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.x contains an improper privilege management vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to …

Mar 28, 2024
CVE-2024-25959
7.9 HIGH

Dell PowerScale OneFS versions 9.4.0.x through 9.7.0.x contains an insertion of sensitive information into log file vulnerability. A low privileged local attacker could potentially exploit …

Mar 28, 2024
CVE-2023-42974
7.0 HIGH

A race condition was addressed with improved state handling. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS 17.2, …

Mar 28, 2024
CVE-2023-42962
7.5 HIGH

This issue was addressed with improved checks This issue is fixed in iOS 17.2 and iPadOS 17.2, iOS 16.7.3 and iPadOS 16.7.3. A remote attacker …

Mar 28, 2024
CVE-2023-42956
6.5 MEDIUM

The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, iOS 17.2 and iPadOS 17.2, macOS Sonoma 14.2. Processing web …

Mar 28, 2024
CVE-2023-42950
8.8 HIGH

A use after free issue was addressed with improved memory management. This issue is fixed in Safari 17.2, iOS 17.2 and iPadOS 17.2, tvOS 17.2, …

Mar 28, 2024
CVE-2023-42947
8.6 HIGH

A path handling issue was addressed with improved validation. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS 17.2, …

Mar 28, 2024
CVE-2023-42936
5.5 MEDIUM

This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS …

Mar 28, 2024
CVE-2023-42931
7.8 HIGH

The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.6.3, macOS Sonoma 14.2, macOS Monterey 12.7.2. A process may gain …

Mar 28, 2024
CVE-2023-42930
5.5 MEDIUM

This issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.6.3, macOS Sonoma 14.2, macOS Monterey 12.7.2. An app may be …

Mar 28, 2024
CVE-2023-42913
8.8 HIGH

This issue was addressed through improved state management. This issue is fixed in macOS Sonoma 14.2. Remote Login sessions may be able to obtain full …

Mar 28, 2024
CVE-2023-42896
5.5 MEDIUM

An issue was addressed with improved handling of temporary files. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS …

Mar 28, 2024
CVE-2023-42893
5.5 MEDIUM

A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS …

Mar 28, 2024
CVE-2023-42892
7.8 HIGH

A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.6.3, macOS Sonoma 14.2, macOS Monterey 12.7.2. A local …

Mar 28, 2024
CVE-2023-40390
5.5 MEDIUM

A privacy issue was addressed by moving sensitive data to a protected location. This issue is fixed in macOS Sonoma 14.2. An app may be …

Mar 28, 2024
CVE-2024-3042
6.3 MEDIUM

A vulnerability was found in SourceCodester Simple Subscription Website 1.0 and classified as critical. This issue affects some unknown processing of the file manage_user.php. The …

Mar 28, 2024
CVE-2024-3041
6.3 MEDIUM

A vulnerability has been found in Netentsec NS-ASG Application Security Gateway 6.3 and classified as critical. This vulnerability affects unknown code of the file /protocol/log/listloginfo.php. …

Mar 28, 2024
CVE-2024-3040
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Netentsec NS-ASG Application Security Gateway 6.3. This affects an unknown part of the file /admin/list_crl_conf. …

Mar 28, 2024
CVE-2024-3039
6.3 MEDIUM

A vulnerability classified as critical has been found in Shanghai Brad Technology BladeX 3.4.0. Affected is an unknown function of the file /api/blade-user/export-user of the …

Mar 28, 2024
CVE-2024-31140
4.1 MEDIUM

In JetBrains TeamCity before 2024.03 server administrators could remove arbitrary files from the server by installing tools

Mar 28, 2024
CVE-2024-31139
5.9 MEDIUM

In JetBrains TeamCity before 2024.03 xXE was possible in the Maven build steps detector

Mar 28, 2024
CVE-2024-31138
4.6 MEDIUM

In JetBrains TeamCity before 2024.03 xSS was possible via Agent Distribution settings

Mar 28, 2024
CVE-2024-31137
6.8 MEDIUM

In JetBrains TeamCity before 2024.03 reflected XSS was possible via Space connection configuration

Mar 28, 2024
CVE-2024-31136
7.4 HIGH

In JetBrains TeamCity before 2024.03 2FA could be bypassed by providing a special URL parameter

Mar 28, 2024
CVE-2024-31135
6.1 MEDIUM

In JetBrains TeamCity before 2024.03 open redirect was possible on the login page

Mar 28, 2024
CVE-2024-31134
6.5 MEDIUM

In JetBrains TeamCity before 2024.03 authenticated users without administrative permissions could register other users when self-registration was disabled

Mar 28, 2024
CVE-2024-30612
8.1 HIGH

Tenda AC10U v15.03.06.48 has a stack overflow vulnerability in the deviceId, limitSpeed, limitSpeedUp parameter from formSetClientState function.

Mar 28, 2024
CVE-2024-30604
7.5 HIGH

Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the list1 parameter of the fromDhcpListClient function.

Mar 28, 2024
CVE-2024-30603
6.5 MEDIUM

Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the urls parameter of the saveParentControlInfo function.

Mar 28, 2024
CVE-2024-30602
9.8 CRITICAL

Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the schedStartTime parameter of the setSchedWifi function.

Mar 28, 2024
CVE-2024-30601
8.0 HIGH

Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the time parameter of the saveParentControlInfo function.

Mar 28, 2024
CVE-2024-30600
8.0 HIGH

Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the schedEndTime parameter of the setSchedWifi function.

Mar 28, 2024
CVE-2024-30599
8.8 HIGH

Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the deviceMac parameter of the addWifiMacFilter function.

Mar 28, 2024
CVE-2024-30598
6.5 MEDIUM

Tenda FH1203 v2.0.1.6 firmware has a stack overflow vulnerability in the security_5g parameter of the formWifiBasicSet function.

Mar 28, 2024
CVE-2024-30597
6.5 MEDIUM

Tenda FH1203 v2.0.1.6 firmware has a stack overflow vulnerability in the security parameter of the formWifiBasicSet function.

Mar 28, 2024
CVE-2024-0259
7.3 HIGH

Fortra's Robot Schedule Enterprise Agent for Windows prior to version 3.04 is susceptible to privilege escalation. A low-privileged user can overwrite the service executable. When …

Mar 28, 2024
CVE-2023-45715
3.5 LOW

The console may experience a service interruption when processing file names with invalid characters.

Mar 28, 2024
CVE-2023-45706
2.0 LOW

An administrative user of WebReports may perform a Cross Site Scripting (XSS) and/or Man in the Middle (MITM) exploit through SAML configuration.

Mar 28, 2024
CVE-2023-45705
3.5 LOW

An administrative user of WebReports may perform a Server Side Request Forgery (SSRF) exploit through SMTP configuration options.

Mar 28, 2024
CVE-2024-30607
8.0 HIGH

Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the deviceId parameter of the saveParentControlInfo function.

Mar 28, 2024
CVE-2024-30606
8.0 HIGH

Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the page parameter of the fromDhcpListClient function.

Mar 28, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.