CVE Database

122339+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-32337
5.4 MEDIUM

IBM Maximo Spatial Asset Management 8.10 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the …

Jan 19, 2024
CVE-2024-22424
8.3 HIGH

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The Argo CD API prior to versions 2.10-rc2, 2.9.4, 2.8.8, and 2.7.15 are vulnerable …

Jan 19, 2024
CVE-2024-22422
7.5 HIGH

AnythingLLM is an application that turns any document, resource, or piece of content into context that any LLM can use as references during chatting. In …

Jan 19, 2024
CVE-2023-40683
8.8 HIGH

IBM OpenPages with Watson 8.3 and 9.0 could allow remote attacker to bypass security restrictions, caused by insufficient authorization checks. By authenticating as an OpenPages …

Jan 19, 2024
CVE-2023-38738
6.8 MEDIUM

IBM OpenPages with Watson 8.3 and 9.0 could provide weaker than expected security in a OpenPages environment using Native authentication. If OpenPages is using Native …

Jan 19, 2024
CVE-2023-35020
5.4 MEDIUM

IBM Sterling Control Center 6.3.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request …

Jan 19, 2024
CVE-2024-0696
3.5 LOW

A vulnerability, which was classified as problematic, was found in AtroCore AtroPIM 1.8.4. This affects an unknown part of the file /#ProductSerie/view/ of the component …

Jan 18, 2024
CVE-2024-0695
4.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in EFS Easy Chat Server 3.1. Affected by this issue is some unknown functionality of …

Jan 18, 2024
CVE-2024-0693
5.3 MEDIUM

A vulnerability classified as problematic was found in EFS Easy File Sharing FTP 2.0. Affected by this vulnerability is an unknown functionality. The manipulation of …

Jan 18, 2024
CVE-2023-5131
8.2 HIGH

A heap buffer-overflow exists in Delta Electronics ISPSoft. An anonymous attacker can exploit this vulnerability by enticing a user to open a specially crafted DVP …

Jan 18, 2024
CVE-2023-5130
8.2 HIGH

A buffer overflow vulnerability exists in Delta Electronics WPLSoft. An anonymous attacker can exploit this vulnerability by enticing a user to open a specially crafted …

Jan 18, 2024
CVE-2023-50614
7.5 HIGH

An issue discovereed in EBYTE E880-IR01-V1.1 allows an attacker to obtain sensitive information via crafted POST request to /cgi-bin/luci.

Jan 18, 2024
CVE-2023-43824
8.8 HIGH

A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the wTitleTextLen field of a DPS file. A remote, unauthenticated …

Jan 18, 2024
CVE-2023-43823
8.8 HIGH

A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the wTTitleLen field of a DPS file. A remote, unauthenticated …

Jan 18, 2024
CVE-2023-43822
8.8 HIGH

A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the wLogTitlesTimeLen field of a DPS file. A remote, unauthenticated …

Jan 18, 2024
CVE-2023-43821
8.8 HIGH

A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the wLogTitlesActionLen field of a DPS file. A remote, unauthenticated …

Jan 18, 2024
CVE-2023-43820
8.8 HIGH

A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the wLogTitlesPrevValueLen field of a DPS file. A remote, unauthenticated …

Jan 18, 2024
CVE-2023-43819
8.8 HIGH

A stack based buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft when parsing the InitialMacroLen field of a DPS file. A remote, unauthenticated …

Jan 18, 2024
CVE-2023-43818
8.8 HIGH

A buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft. A remote, unauthenticated attacker can exploit this vulnerability by enticing a user to open …

Jan 18, 2024
CVE-2023-43817
7.5 HIGH

A buffer overflow exists in Delta Electronics Delta Industrial Automation DOPSoft version 2 when parsing the wMailContentLen field of a DPS file. An anonymous attacker …

Jan 18, 2024
CVE-2023-43816
6.3 MEDIUM

A buffer overflow vulnerability exists in Delta Electronics Delta Industrial Automation DOPSoft version 2 when parsing the wKPFStringLen field of a DPS file. An anonymous …

Jan 18, 2024
CVE-2023-43815
7.1 HIGH

A buffer overflow vulnerability exists in Delta Electronics Delta Industrial Automation DOPSoft version 2 when parsing the wScreenDESCTextLen field of a DPS file. An anonymous …

Jan 18, 2024
CVE-2024-22418
6.5 MEDIUM

Group-Office is an enterprise CRM and groupware tool. Affected versions are subject to a vulnerability which is present in the file upload mechanism of Group …

Jan 18, 2024
CVE-2024-22415
7.3 HIGH

jupyter-lsp is a coding assistance tool for JupyterLab (code navigation + hover suggestions + linters + autocompletion + rename) using Language Server Protocol. Installations of …

Jan 18, 2024
CVE-2024-22404
4.1 MEDIUM

Nextcloud files Zip app is a tool to create zip archives from one or multiple files from within Nextcloud. In affected versions users can download …

Jan 18, 2024
CVE-2024-22402
5.4 MEDIUM

Nextcloud guests app is a utility to create guest users which can only see files shared with them. In affected versions users were able to …

Jan 18, 2024
CVE-2024-22401
4.1 MEDIUM

Nextcloud guests app is a utility to create guest users which can only see files shared with them. In affected versions users could change the …

Jan 18, 2024
CVE-2023-51258
5.5 MEDIUM

A memory leak issue discovered in YASM v.1.3.0 allows a local attacker to cause a denial of service via the new_Token function in the modules/preprocs/nasm/nasm-pp:1512.

Jan 18, 2024
CVE-2023-51217
8.8 HIGH

An issue discovered in TenghuTOS TWS-200 firmware version:V4.0-201809201424 allows a remote attacker to execute arbitrary code via crafted command on the ping page component.

Jan 18, 2024
CVE-2023-47092

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not …

Jan 18, 2024
CVE-2024-22403
3.0 LOW

Nextcloud server is a self hosted personal cloud system. In affected versions OAuth codes did not expire. When an attacker would get access to an …

Jan 18, 2024
CVE-2024-22400
3.1 LOW

Nextcloud User Saml is an app for authenticating Nextcloud users using SAML. In affected versions users can be given a link to the Nextcloud server …

Jan 18, 2024
CVE-2024-22213
0.0 NONE

Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. In affected versions users could be …

Jan 18, 2024
CVE-2024-22419
7.3 HIGH

Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine. The `concat` built-in can write over the bounds of the memory buffer that …

Jan 18, 2024
CVE-2024-22212
9.6 CRITICAL

Nextcloud Global Site Selector is a tool which allows you to run multiple small Nextcloud instances and redirect users to the right server. A problem …

Jan 18, 2024
CVE-2023-49943
5.4 MEDIUM

Zoho ManageEngine ServiceDesk Plus MSP before 14504 allows stored XSS (by a low-privileged technician) via a task's name in a time sheet.

Jan 18, 2024
CVE-2023-34348
7.5 HIGH

AVEVA PI Server versions 2023 and 2018 SP3 P05 and prior contain a vulnerability that could allow an unauthenticated user to remotely crash the PI …

Jan 18, 2024
CVE-2023-31274
5.3 MEDIUM

AVEVA PI Server versions 2023 and 2018 SP3 P05 and prior contain a vulnerability that could allow an unauthenticated user to cause the PI Message …

Jan 18, 2024
CVE-2024-22819
8.8 HIGH

FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/email/email_templets_update.

Jan 18, 2024
CVE-2024-22818
8.8 HIGH

FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerbility via /system/site/filterKeyword_save

Jan 18, 2024
CVE-2024-22817
8.8 HIGH

FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/email/email_conf_updagte

Jan 18, 2024
CVE-2024-22603
8.8 HIGH

FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/links/add_link

Jan 18, 2024
CVE-2024-22601
8.8 HIGH

FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/score/scorerule_save

Jan 18, 2024
CVE-2023-28901
5.3 MEDIUM

The Skoda Automotive cloud contains a Broken Access Control vulnerability, allowing remote attackers to obtain recent trip data, vehicle mileage, fuel consumption, average and maximum …

Jan 18, 2024
CVE-2023-28900
5.3 MEDIUM

The Skoda Automotive cloud contains a Broken Access Control vulnerability, allowing to obtain nicknames and other user identifiers of Skoda Connect service users by specifying …

Jan 18, 2024
CVE-2024-22699
8.8 HIGH

FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/admin/update_group_save.

Jan 18, 2024
CVE-2024-0607
6.6 MEDIUM

A flaw was found in the Netfilter subsystem in the Linux kernel. The issue is in the nft_byteorder_eval() function, where the code iterates through a …

Jan 18, 2024
CVE-2024-0409
7.8 HIGH

A flaw was found in the X.Org server. The cursor code in both Xephyr and Xwayland uses the wrong type of private at creation. It …

Jan 18, 2024
CVE-2024-0408
5.5 MEDIUM

A flaw was found in the X.Org server. The GLX PBuffer code does not call the XACE hook when creating the buffer, leaving it unlabeled. …

Jan 18, 2024
CVE-2024-22593
8.8 HIGH

FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/admin/add_group_save

Jan 18, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.