CVE Database

122339+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-23655
7.5 HIGH

Tuta is an encrypted email service. Starting in version 3.118.12 and prior to version 3.119.10, an attacker is able to send a manipulated email so …

Jan 25, 2024
CVE-2024-21630
4.3 MEDIUM

Zulip is an open-source team collaboration tool. A vulnerability in version 8.0 is similar to CVE-2023-32677, but applies to multi-use invitations, not single-use invitation links …

Jan 25, 2024
CVE-2023-52356
7.5 HIGH

A segment fault (SEGV) flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFReadRGBATileExt() API. This flaw …

Jan 25, 2024
CVE-2023-52355
7.5 HIGH

An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a …

Jan 25, 2024
CVE-2023-41474
6.5 MEDIUM

Directory Traversal vulnerability in Ivanti Avalanche 6.3.4.153 allows a remote authenticated attacker to obtain sensitive information via the javax.faces.resource component.

Jan 25, 2024
CVE-2024-0883
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been declared as critical. This vulnerability affects the function prepare …

Jan 25, 2024
CVE-2024-0882
4.3 MEDIUM

A vulnerability was found in qwdigital LinkWechat 5.1.0. It has been classified as problematic. This affects an unknown part of the file /linkwechat-api/common/download/resource of the …

Jan 25, 2024
CVE-2023-7227
9.8 CRITICAL

SystemK NVR 504/508/516 versions 2.3.5SK.30084998 and prior are vulnerable to a command injection vulnerability in the dynamic domain name system (DDNS) settings that could allow …

Jan 25, 2024
CVE-2023-6267
8.6 HIGH

A flaw was found in the json payload. If annotation based security is used to secure a REST resource, the JSON body that the resource …

Jan 25, 2024
CVE-2024-0880
4.3 MEDIUM

A vulnerability was found in Qidianbang qdbcrm 1.1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /user/edit?id=2 of …

Jan 25, 2024
CVE-2024-22749
7.8 HIGH

GPAC v2.3 was detected to contain a buffer overflow via the function gf_isom_new_generic_sample_description function in the isomedia/isom_write.c:4577

Jan 25, 2024
CVE-2024-22529
9.8 CRITICAL

TOTOLINK X2000R_V2 V2.0.0-B20230727.10434 has a command injection vulnerability in the sub_449040 (handle function of formUploadFile) of /bin/boa.

Jan 25, 2024
CVE-2024-0822
7.5 HIGH

An authentication bypass vulnerability was found in overt-engine. This flaw allows the creation of users in the system without authentication due to a flaw in …

Jan 25, 2024
CVE-2023-52076
8.5 HIGH

Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A path traversal and arbitrary file write vulnerability exists in …

Jan 25, 2024
CVE-2023-40547
8.3 HIGH

A remote code execution vulnerability was found in Shim. The Shim boot support trusts attacker-controlled values when parsing an HTTP response. This flaw allows an …

Jan 25, 2024
CVE-2023-3181
7.8 HIGH

The C:\Program Files (x86)\Splashtop\Splashtop Software Updater\uninst.exe process creates a folder at C:\Windows\Temp~nsu.tmp and copies itself to it as Au_.exe. The C:\Windows\Temp~nsu.tmp\Au_.exe file is automatically launched …

Jan 25, 2024
CVE-2024-22729
9.8 CRITICAL

NETIS SYSTEMS MW5360 V1.0.1.3031 was discovered to contain a command injection vulnerability via the password parameter on the login page.

Jan 25, 2024
CVE-2024-22432
7.8 HIGH

Networker 19.9 and all prior versions contains a Plain-text Password stored in temporary config file during backup duration in NMDA MySQL Database backups. User has …

Jan 25, 2024
CVE-2024-0879
6.5 MEDIUM

Authentication bypass in vector-admin allows a user to register to a vector-admin server while “domain restriction” is active, even when not owning an authorized email …

Jan 25, 2024
CVE-2024-23855
8.2 HIGH

A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting …

Jan 25, 2024
CVE-2023-6282
5.4 MEDIUM

IceHrm 23.0.0.OS does not sufficiently encode user-controlled input, which creates a Cross-Site Scripting (XSS) vulnerability via /icehrm/app/fileupload_page.php, in multiple parameters. An attacker could exploit this …

Jan 25, 2024
CVE-2023-33760
5.3 MEDIUM

SpliceCom Maximiser Soft PBX v1.5 and before was discovered to utilize a default SSL certificate. This issue can allow attackers to eavesdrop on communications via …

Jan 25, 2024
CVE-2023-33759
9.8 CRITICAL

SpliceCom Maximiser Soft PBX v1.5 and before does not restrict excessive authentication attempts, allowing attackers to bypass authentication via a brute force attack.

Jan 25, 2024
CVE-2023-33758
6.1 MEDIUM

Splicecom Maximiser Soft PBX v1.5 and before was discovered to contain a cross-site scripting (XSS) vulnerability via the CLIENT_NAME and DEVICE_GUID fields in the login …

Jan 25, 2024
CVE-2023-33757
5.9 MEDIUM

A lack of SSL certificate validation in Splicecom iPCS (iOS App) v1.3.4, iPCS2 (iOS App) v2.8 and before, and iPCS (Android App) v1.8.5 and before …

Jan 25, 2024
CVE-2024-23307
4.4 MEDIUM

Integer Overflow or Wraparound vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (md, raid, raid5 modules) allows Forced Integer Overflow.

Jan 25, 2024
CVE-2024-22099
6.3 MEDIUM

NULL Pointer Dereference vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (net, bluetooth modules) allows Overflow Buffers. This vulnerability is associated with program …

Jan 25, 2024
CVE-2023-50785
2.7 LOW

Zoho ManageEngine ADAudit Plus before 7270 allows admin users to view names of arbitrary directories via path traversal.

Jan 25, 2024
CVE-2024-23985
7.5 HIGH

EzServer 6.4.017 allows a denial of service (daemon crash) via a long string, such as one for the RNTO command.

Jan 25, 2024
CVE-2024-0625
4.4 MEDIUM

The WPFront Notification Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpfront-notification-bar-options[custom_class]’ parameter in all versions up to, and including, 3.3.2 …

Jan 25, 2024
CVE-2024-0688
4.4 MEDIUM

The "WebSub (FKA. PubSubHubbub)" plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings in all versions up to, and including, 3.1.4 due …

Jan 25, 2024
CVE-2024-0624
5.3 MEDIUM

The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up …

Jan 25, 2024
CVE-2024-0617
5.3 MEDIUM

The Category Discount Woocommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpcd_save_discount() function in …

Jan 25, 2024
CVE-2024-22751
9.8 CRITICAL

D-Link DIR-882 DIR882A1_FW130B06 was discovered to contain a stack overflow via the sub_477AA0 function.

Jan 24, 2024
CVE-2023-24676
7.2 HIGH

An issue found in ProcessWire 3.0.210 allows attackers to execute arbitrary code and install a reverse shell via the download_zip_url parameter when installing a new …

Jan 24, 2024
CVE-2024-23646
8.8 HIGH

Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. The application allows users to create zip files from available files on the site. …

Jan 24, 2024
CVE-2024-23644
6.8 MEDIUM

Trillium is a composable toolkit for building internet applications with async rust. In `trillium-http` prior to 0.3.12 and `trillium-client` prior to 0.5.4, insufficient validation of …

Jan 24, 2024
CVE-2021-43584
4.8 MEDIUM

DOM-based Cross Site Scripting (XSS vulnerability in 'Tail Event Logs' functionality in Nagios Nagios Cross-Platform Agent (NCPA) before 2.4.0 allows attackers to run arbitrary code …

Jan 24, 2024
CVE-2021-42147
9.1 CRITICAL

Buffer over-read vulnerability in the dtls_sha256_update function in Contiki-NG tinyDTLS through master branch 53a0d97 allows remote attackers to cause a denial of service via crafted …

Jan 24, 2024
CVE-2021-42146
7.5 HIGH

An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97. DTLS servers allow remote attackers to reuse the same epoch number within two times …

Jan 24, 2024
CVE-2021-42145
7.5 HIGH

An assertion failure discovered in in check_certificate_request() in Contiki-NG tinyDTLS through master branch 53a0d97 allows attackers to cause a denial of service.

Jan 24, 2024
CVE-2024-23905
5.4 MEDIUM

Jenkins Red Hat Dependency Analytics Plugin 0.7.1 and earlier programmatically disables Content-Security-Policy protection for user-generated content in workspaces, archived artifacts, etc. that Jenkins offers for …

Jan 24, 2024
CVE-2024-23904
7.5 HIGH

Jenkins Log Command Plugin 1.0.2 and earlier does not disable a feature of its command parser that replaces an '@' character followed by a file …

Jan 24, 2024
CVE-2024-23903
5.3 MEDIUM

Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, …

Jan 24, 2024
CVE-2024-23902
4.3 MEDIUM

A cross-site request forgery (CSRF) vulnerability in Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier allows attackers to connect to an attacker-specified URL.

Jan 24, 2024
CVE-2024-23901
6.5 MEDIUM

Jenkins GitLab Branch Source Plugin 684.vea_fa_7c1e2fe3 and earlier unconditionally discovers projects that are shared with the configured owner group, allowing attackers to configure and share …

Jan 24, 2024
CVE-2024-23900
4.3 MEDIUM

Jenkins Matrix Project Plugin 822.v01b_8c85d16d2 and earlier does not sanitize user-defined axis names of multi-configuration projects, allowing attackers with Item/Configure permission to create or replace …

Jan 24, 2024
CVE-2024-23899
6.5 MEDIUM

Jenkins Git server Plugin 99.va_0826a_b_cdfa_d and earlier does not disable a feature of its command parser that replaces an '@' character followed by a file …

Jan 24, 2024
CVE-2024-23898
8.8 HIGH

Jenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both inclusive) does not perform origin validation of requests made through the CLI WebSocket endpoint, …

Jan 24, 2024
CVE-2024-23897
9.8 CRITICAL KEV

Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by …

Jan 24, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.