CVE Database

122339+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-28722
6.7 MEDIUM

Improper buffer restrictions for some Intel NUC BIOS firmware before version IN0048 may allow a privileged user to potentially enable escalation of privilege via local …

Jan 19, 2024
CVE-2024-0730
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Project Worlds Online Time Table Generator 1.0. This affects an unknown part of the file …

Jan 19, 2024
CVE-2024-0729
5.5 MEDIUM

A vulnerability, which was classified as critical, has been found in ForU CMS up to 2020-06-23. Affected by this issue is some unknown functionality of …

Jan 19, 2024
CVE-2024-0728
4.7 MEDIUM

A vulnerability classified as problematic was found in ForU CMS up to 2020-06-23. Affected by this vulnerability is an unknown functionality of the file channel.php. …

Jan 19, 2024
CVE-2024-22957
5.5 MEDIUM

swftools 0.9.2 was discovered to contain an Out-of-bounds Read vulnerability via the function dict_do_lookup in swftools/lib/q.c:1190.

Jan 19, 2024
CVE-2024-22956
7.8 HIGH

swftools 0.9.2 was discovered to contain a heap-use-after-free vulnerability via the function removeFromTo at swftools/src/swfc.c:838

Jan 19, 2024
CVE-2024-22955
7.8 HIGH

swftools 0.9.2 was discovered to contain a stack-buffer-underflow vulnerability via the function parseExpression at swftools/src/swfc.c:2576.

Jan 19, 2024
CVE-2024-22919
7.8 HIGH

swftools0.9.2 was discovered to contain a global-buffer-overflow vulnerability via the function parseExpression at swftools/src/swfc.c:2587.

Jan 19, 2024
CVE-2024-22915
7.8 HIGH

A heap-use-after-free was found in SWFTools v0.9.2, in the function swf_DeleteTag at rfxswf.c:1193. It allows an attacker to cause code execution.

Jan 19, 2024
CVE-2024-22914
5.5 MEDIUM

A heap-use-after-free was found in SWFTools v0.9.2, in the function input at lex.swf5.c:2620. It allows an attacker to cause denial of service.

Jan 19, 2024
CVE-2024-22913
7.8 HIGH

A heap-buffer-overflow was found in SWFTools v0.9.2, in the function swf5lex at lex.swf5.c:1321. It allows an attacker to cause code execution.

Jan 19, 2024
CVE-2024-22912
7.8 HIGH

A global-buffer-overflow was found in SWFTools v0.9.2, in the function countline at swf5compiler.flex:327. It allows an attacker to cause code execution.

Jan 19, 2024
CVE-2024-22911
7.8 HIGH

A stack-buffer-underflow vulnerability was found in SWFTools v0.9.2, in the function parseExpression at src/swfc.c:2602.

Jan 19, 2024
CVE-2024-0726
4.3 MEDIUM

A vulnerability was found in Project Worlds Student Project Allocation System 1.0. It has been rated as problematic. This issue affects some unknown processing of …

Jan 19, 2024
CVE-2024-0725
5.3 MEDIUM

A vulnerability was found in ProSSHD 1.2 on Windows. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to denial …

Jan 19, 2024
CVE-2024-0723
5.3 MEDIUM

A vulnerability was found in freeSSHd 1.0.9 on Windows. It has been classified as problematic. This affects an unknown part. The manipulation leads to denial …

Jan 19, 2024
CVE-2024-0722
3.5 LOW

A vulnerability was found in code-projects Social Networking Site 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file …

Jan 19, 2024
CVE-2023-47034
7.5 HIGH

A vulnerability in UniswapFrontRunBot 0xdB94c allows attackers to cause financial losses via unspecified vectors.

Jan 19, 2024
CVE-2023-47033
7.5 HIGH

MultiSigWallet 0xF0C99 was discovered to contain a reentrancy vulnerability via the function executeTransaction.

Jan 19, 2024
CVE-2024-0721
3.5 LOW

A vulnerability has been found in Jspxcms 10.2.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Survey Label …

Jan 19, 2024
CVE-2024-0720
3.5 LOW

A vulnerability, which was classified as problematic, was found in FactoMineR FactoInvestigate up to 1.9. Affected is an unknown function of the component HTML Report …

Jan 19, 2024
CVE-2024-0718
2.4 LOW

A vulnerability, which was classified as problematic, has been found in liuwy-dlsdys zhglxt 4.7.7. This issue affects some unknown processing of the file /oa/notify/edit of …

Jan 19, 2024
CVE-2024-0717
5.3 MEDIUM

A vulnerability classified as critical was found in D-Link DAP-1360, DIR-300, DIR-615, DIR-615GF, DIR-615S, DIR-615T, DIR-620, DIR-620S, DIR-806A, DIR-815, DIR-815AC, DIR-815S, DIR-816, DIR-820, DIR-822, DIR-825, …

Jan 19, 2024
CVE-2024-22920
7.8 HIGH

swftools 0.9.2 was discovered to contain a heap-use-after-free via the function bufferWriteData in swftools/lib/action/compile.c.

Jan 19, 2024
CVE-2024-22563
7.5 HIGH

openvswitch 2.17.8 was discovered to contain a memory leak via the function xmalloc__ in openvswitch-2.17.8/lib/util.c.

Jan 19, 2024
CVE-2024-22562
7.8 HIGH

swftools 0.9.2 was discovered to contain a Stack Buffer Underflow via the function dict_foreach_keyvalue at swftools/lib/q.c.

Jan 19, 2024
CVE-2024-0716
3.1 LOW

A vulnerability classified as problematic has been found in Byzoro Smart S150 Management Platform V31R02B15. This affects an unknown part of the file /log/download.php of …

Jan 19, 2024
CVE-2024-0714
6.3 MEDIUM

A vulnerability was found in MiczFlor RPi-Jukebox-RFID up to 2.5.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Jan 19, 2024
CVE-2022-47160
6.5 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wpmet Wp Social Login and Register Social Counter.This issue affects Wp Social Login and Register …

Jan 19, 2024
CVE-2022-45845
4.3 MEDIUM

Deserialization of Untrusted Data vulnerability in Nextend Smart Slider 3.This issue affects Smart Slider 3: from n/a through 3.5.1.9.

Jan 19, 2024
CVE-2022-45083
6.6 MEDIUM

Deserialization of Untrusted Data vulnerability in ProfilePress Membership Team Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress.This …

Jan 19, 2024
CVE-2022-40700
8.2 HIGH

Server-Side Request Forgery (SSRF) vulnerability in Montonio Montonio for WooCommerce, Wpopal Wpopal Core Features, AMO for WP – Membership Management ArcStone wp-amo, Long Watch Studio …

Jan 19, 2024
CVE-2024-22877
5.4 MEDIUM

StrangeBee TheHive 5.2.0 to 5.2.8 is vulnerable to Cross Site Scripting (XSS) in the case reporting functionality. This feature allows an attacker to insert malicious …

Jan 19, 2024
CVE-2024-22876
5.4 MEDIUM

StrangeBee TheHive 5.1.0 to 5.1.9 and 5.2.0 to 5.2.8 is vulnerable to Cross Site Scripting (XSS) in the case attachment functionality which enables an attacker …

Jan 19, 2024
CVE-2024-0712
7.3 HIGH

A vulnerability was found in Byzoro Smart S150 Management Platform V31R02B15. It has been classified as critical. Affected is an unknown function of the file …

Jan 19, 2024
CVE-2023-51948
7.5 HIGH

A Site-wide directory listing vulnerability in /fm in actidata actiNAS SL 2U-8 RDX 3.2.03-SP1 allows remote attackers to list the files hosted by the web …

Jan 19, 2024
CVE-2023-51947
9.1 CRITICAL

Improper access control on nasSvr.php in actidata actiNAS SL 2U-8 RDX 3.2.03-SP1 allows remote attackers to read and modify different types of data without authentication.

Jan 19, 2024
CVE-2023-51946
6.1 MEDIUM

Multiple reflected cross-site scripting (XSS) vulnerabilities in nasSvr.php in actidata actiNAS-SL-2U-8 3.2.03-SP1 allow remote attackers to inject arbitrary web script or HTML.

Jan 19, 2024
CVE-2023-50030
9.8 CRITICAL

In the module "Jms Setting" (jmssetting) from Joommasters for PrestaShop, a guest can perform SQL injection in versions <= 1.1.0. The method `JmsSetting::getSecondImgs()` has a …

Jan 19, 2024
CVE-2023-50028
9.8 CRITICAL

In the module "Sliding cart block" (blockslidingcart) up to version 2.3.8 from PrestashopModules.eu for PrestaShop, a guest can perform SQL injection.

Jan 19, 2024
CVE-2023-46351
9.8 CRITICAL

In the module mib < 1.6.1 from MyPresta.eu for PrestaShop, a guest can perform SQL injection. The methods `mib::getManufacturersByCategory()` has sensitive SQL calls that can …

Jan 19, 2024
CVE-2023-43985
9.8 CRITICAL

SunnyToo stblogsearch up to v1.0.0 was discovered to contain a SQL injection vulnerability via the StBlogSearchClass::prepareSearch component.

Jan 19, 2024
CVE-2023-27168
9.8 CRITICAL

An arbitrary file upload vulnerability in Xpand IT Write-back Manager v2.3.1 allows attackers to execute arbitrary code via a crafted jsp file.

Jan 19, 2024
CVE-2024-21733
5.3 MEDIUM

Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat.This issue affects Apache Tomcat: from 8.5.7 through 8.5.63, from 9.0.0-M11 through 9.0.43. Other, EOL …

Jan 19, 2024
CVE-2024-0705
9.8 CRITICAL

The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, …

Jan 19, 2024
CVE-2024-23659
6.1 MEDIUM

SPIP before 4.1.14 and 4.2.x before 4.2.8 allows XSS via the name of an uploaded file. This is related to javascript/bigup.js and javascript/bigup.utils.js.

Jan 19, 2024
CVE-2024-23387
4.8 MEDIUM

FusionPBX prior to 5.1.0 contains a cross-site scripting vulnerability. If this vulnerability is exploited by a remote authenticated attacker with an administrative privilege, an arbitrary …

Jan 19, 2024
CVE-2023-5716
9.8 CRITICAL

ASUS Armoury Crate has a vulnerability in arbitrary file write and allows remote attackers to access or modify arbitrary files by sending specific HTTP requests …

Jan 19, 2024
CVE-2023-50963
6.5 MEDIUM

IBM Storage Defender - Data Protect 1.0.0 through 1.4.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. …

Jan 19, 2024
CVE-2023-47718
4.3 MEDIUM

IBM Maximo Asset Management 7.6.1.3 and Manage Component 8.10 through 8.11 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious …

Jan 19, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.