CVE Database

122339+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-22592
8.8 HIGH

FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/user/group_update

Jan 18, 2024
CVE-2024-22591
8.8 HIGH

FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/user/group_save.

Jan 18, 2024
CVE-2024-22568
8.8 HIGH

FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/score/del.

Jan 18, 2024
CVE-2024-22549
5.4 MEDIUM

FlyCms 1.0 is vulnerable to Cross Site Scripting (XSS) in the email settings of the website settings section.

Jan 18, 2024
CVE-2024-22548
5.4 MEDIUM

FlyCms 1.0 is vulnerable to Cross Site Scripting (XSS) in the system website settings website name section.

Jan 18, 2024
CVE-2023-7153
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Macroturk Software and Internet Technologies Macro-Bel allows Reflected XSS.This issue affects Macro-Bel: before …

Jan 18, 2024
CVE-2023-40052
7.5 HIGH

This issue affects Progress Application Server (PAS) for OpenEdge in versions 11.7 prior to 11.7.18, 12.2 prior to 12.2.13, and innovation releases prior to 12.8.0 …

Jan 18, 2024
CVE-2023-40051
9.1 CRITICAL

This issue affects Progress Application Server (PAS) for OpenEdge in versions 11.7 prior to 11.7.18, 12.2 prior to 12.2.13, and innovation releases prior to 12.8.0. …

Jan 18, 2024
CVE-2021-33631
5.5 MEDIUM

Integer Overflow or Wraparound vulnerability in openEuler kernel on Linux (filesystem modules) allows Forced Integer Overflow.This issue affects openEuler kernel: from 4.19.90 before 4.19.90-2401.3, from …

Jan 18, 2024
CVE-2021-33630
5.5 MEDIUM

NULL Pointer Dereference vulnerability in openEuler kernel on Linux (network modules) allows Pointer Manipulation. This vulnerability is associated with program files net/sched/sch_cbs.C. This issue affects …

Jan 18, 2024
CVE-2024-22317
9.1 CRITICAL

IBM App Connect Enterprise 11.0.0.1 through 11.0.0.24 and 12.0.1.0 through 12.0.11.0 could allow a remote attacker to obtain sensitive information or cause a denial of …

Jan 18, 2024
CVE-2024-0669
6.3 MEDIUM

A Cross-Frame Scripting vulnerability has been found on Plone CMS affecting verssion below 6.0.5. An attacker could store a malicious URL to be opened by …

Jan 18, 2024
CVE-2023-5806
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mergen Software Quality Management System allows SQL Injection.This issue affects Quality …

Jan 18, 2024
CVE-2023-51464
5.4 MEDIUM

Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to …

Jan 18, 2024
CVE-2023-51463
5.4 MEDIUM

Adobe Experience Manager versions 6.5.18 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a …

Jan 18, 2024
CVE-2024-0580
6.5 MEDIUM

Omission of user-controlled key authorization in the IDMSistemas platform, affecting the QSige product. This vulnerability allows an attacker to extract sensitive information from the API …

Jan 18, 2024
CVE-2024-0381
6.4 MEDIUM

The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the use of the 'tag' attribute in the wprm-recipe-name, wprm-recipe-date, and …

Jan 18, 2024
CVE-2023-6970
6.1 MEDIUM

The WP Recipe Maker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘Referer' header in all versions up to, and including, 9.1.0 …

Jan 18, 2024
CVE-2023-6958
6.4 MEDIUM

The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 9.1.0 …

Jan 18, 2024
CVE-2023-6816
9.8 CRITICAL

A flaw was found in X.Org server. Both DeviceFocusEvent and the XIQueryPointer reply contain a bit for each logical button currently down. Buttons can be …

Jan 18, 2024
CVE-2024-0655
5.5 MEDIUM

A vulnerability has been found in Novel-Plus 4.3.0-RC1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /novel/bookSetting/list. The …

Jan 18, 2024
CVE-2023-48359
4.4 MEDIUM

In autotest driver, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with …

Jan 18, 2024
CVE-2023-48358
4.4 MEDIUM

In drm driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Jan 18, 2024
CVE-2023-48357
4.4 MEDIUM

In vsp driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Jan 18, 2024
CVE-2023-48356
4.4 MEDIUM

In jpg driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Jan 18, 2024
CVE-2023-48355
4.4 MEDIUM

In jpg driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Jan 18, 2024
CVE-2023-48354
5.5 MEDIUM

In telephone service, there is a possible improper input validation. This could lead to local information disclosure with no additional execution privileges needed

Jan 18, 2024
CVE-2023-48353
4.4 MEDIUM

In vsp driver, there is a possible use after free due to a logic error. This could lead to local denial of service with System …

Jan 18, 2024
CVE-2023-48352
5.5 MEDIUM

In phasecheckserver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with …

Jan 18, 2024
CVE-2023-48351
5.5 MEDIUM

In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Jan 18, 2024
CVE-2023-48350
5.5 MEDIUM

In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Jan 18, 2024
CVE-2023-48349
5.5 MEDIUM

In video decoder, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Jan 18, 2024
CVE-2023-48348
5.5 MEDIUM

In video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with …

Jan 18, 2024
CVE-2023-48347
5.5 MEDIUM

In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with …

Jan 18, 2024
CVE-2023-48346
5.5 MEDIUM

In video decoder, there is a possible improper input validation. This could lead to local denial of service with no additional execution privileges needed

Jan 18, 2024
CVE-2023-48345
5.5 MEDIUM

In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with …

Jan 18, 2024
CVE-2023-48344
5.5 MEDIUM

In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with …

Jan 18, 2024
CVE-2023-48343
5.5 MEDIUM

In video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with …

Jan 18, 2024
CVE-2023-48342
4.4 MEDIUM

In media service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Jan 18, 2024
CVE-2023-48341
5.5 MEDIUM

In video decoder, there is a possible out of bounds read due to improper input validation. This could lead to local denial of service with …

Jan 18, 2024
CVE-2023-48340
5.5 MEDIUM

In video decoder, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with …

Jan 18, 2024
CVE-2023-48339
4.4 MEDIUM

In jpg driver, there is a possible missing permission check. This could lead to local information disclosure with System execution privileges needed

Jan 18, 2024
CVE-2024-0654
5.3 MEDIUM

A vulnerability, which was classified as problematic, was found in DeepFaceLab pretrained DF.wf.288res.384.92.72.22. Affected is an unknown function of the file mainscripts/Util.py. The manipulation leads …

Jan 18, 2024
CVE-2024-0652
3.5 LOW

A vulnerability was found in PHPGurukul Company Visitor Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality …

Jan 18, 2024
CVE-2024-0651
6.3 MEDIUM

A vulnerability was found in PHPGurukul Company Visitor Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Jan 18, 2024
CVE-2023-6184
5.0 MEDIUM

Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting

Jan 18, 2024
CVE-2021-4433
5.3 MEDIUM

A vulnerability was found in Karjasoft Sami HTTP Server 2.0. It has been classified as problematic. Affected is an unknown function of the component HTTP …

Jan 18, 2024
CVE-2024-23525
6.5 MEDIUM

The Spreadsheet::ParseXLSX package before 0.30 for Perl allows XXE attacks because it neglects to use the no_xxe option of XML::Twig.

Jan 18, 2024
CVE-2024-22416
9.6 CRITICAL

pyLoad is a free and open-source Download Manager written in pure Python. The `pyload` API allows any API call to be made using GET requests. …

Jan 18, 2024
CVE-2024-0650
4.3 MEDIUM

A vulnerability was found in Project Worlds Visitor Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file …

Jan 18, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.