CVE Database

122339+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-6340
5.5 MEDIUM

SonicWall Capture Client version 3.7.10, NetExtender client version 10.2.337 and earlier versions are installed with sfpmonitor.sys driver. The driver has been found to be vulnerable …

Jan 18, 2024
CVE-2024-0649
6.3 MEDIUM

A vulnerability was found in ZhiHuiYun up to 4.4.13 and classified as critical. This issue affects the function download_network_image of the file /app/Http/Controllers/ImageController.php of the …

Jan 17, 2024
CVE-2024-0648
7.3 HIGH

A vulnerability has been found in Yunyou CMS up to 2.2.6 and classified as critical. This vulnerability affects unknown code of the file /app/index/controller/Common.php. The …

Jan 17, 2024
CVE-2024-22414
6.5 MEDIUM

flaskBlog is a simple blog app built with Flask. Improper storage and rendering of the `/user/<user>` page allows a user's comments to execute arbitrary javascript …

Jan 17, 2024
CVE-2024-22410
3.3 LOW

Creditcoin is a network that enables cross-blockchain credit transactions. The Windows binary of the Creditcoin node loads a suite of DLLs provided by Microsoft at …

Jan 17, 2024
CVE-2023-6549
8.2 HIGH KEV

Improper Restriction of Operations within the Bounds of a Memory Buffer in NetScaler ADC and NetScaler Gateway allows Unauthenticated Denial of Service and Out-Of-Bounds Memory …

Jan 17, 2024
CVE-2023-5914
5.4 MEDIUM

Cross-site scripting (XSS)

Jan 17, 2024
CVE-2023-6548
5.5 MEDIUM KEV

Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with …

Jan 17, 2024
CVE-2023-48858
6.1 MEDIUM

A Cross-site scripting (XSS) vulnerability in login page php code in Armex ABO.CMS 5.9 allows remote attackers to inject arbitrary web script or HTML via …

Jan 17, 2024
CVE-2023-44077
9.8 CRITICAL

Studio Network Solutions ShareBrowser before 7.0 on macOS mishandles signature verification, aka PMP-2636.

Jan 17, 2024
CVE-2024-0647
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in Sparksuite SimpleMDE up to 1.11.2. This affects an unknown part of the component iFrame Handler. …

Jan 17, 2024
CVE-2023-7031
5.7 MEDIUM

Insecure Direct Object Reference vulnerabilities were discovered in the Avaya Aura Experience Portal Manager which may allow partial information disclosure to an authenticated non-privileged user. …

Jan 17, 2024
CVE-2022-42884
5.4 MEDIUM

Missing Authorization vulnerability in ThemeinProgress WIP Custom Login.This issue affects WIP Custom Login: from n/a through 1.2.7.

Jan 17, 2024
CVE-2024-22715
8.8 HIGH

Stupid Simple CMS <=1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin-edit.php.

Jan 17, 2024
CVE-2024-22714
6.1 MEDIUM

Stupid Simple CMS <=1.2.4 is vulnerable to Cross Site Scripting (XSS) in the editing section of the article content.

Jan 17, 2024
CVE-2022-41790
4.3 MEDIUM

Missing Authorization vulnerability in CodePeople WP Time Slots Booking Form.This issue affects WP Time Slots Booking Form: from n/a through 1.1.76.

Jan 17, 2024
CVE-2022-41786
5.4 MEDIUM

Missing Authorization vulnerability in WP Job Portal WP Job Portal – A Complete Job Board.This issue affects WP Job Portal – A Complete Job Board: …

Jan 17, 2024
CVE-2024-20287
6.5 MEDIUM

A vulnerability in the web-based management interface of the Cisco WAP371 Wireless-AC/N Dual Radio Access Point (AP) with Single Point Setup could allow an authenticated, …

Jan 17, 2024
CVE-2024-20277
6.8 MEDIUM

A vulnerability in the web-based management interface of Cisco ThousandEyes Enterprise Agent, Virtual Appliance installation type, could allow an authenticated, remote attacker to perform a …

Jan 17, 2024
CVE-2024-20272
7.3 HIGH

A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to upload arbitrary files to an affected system …

Jan 17, 2024
CVE-2024-20270
4.8 MEDIUM

A vulnerability in the web-based management interface of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Platform could allow an authenticated, remote attacker …

Jan 17, 2024
CVE-2024-20251
4.8 MEDIUM

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to perform a stored cross-site scripting …

Jan 17, 2024
CVE-2023-50950
3.7 LOW

IBM QRadar SIEM 7.5 could disclose sensitive email information in responses from offense rules. IBM X-Force ID: 275709.

Jan 17, 2024
CVE-2023-23896
5.4 MEDIUM

Missing Authorization vulnerability in MyThemeShop URL Shortener by MyThemeShop.This issue affects URL Shortener by MyThemeShop: from n/a through 1.0.17.

Jan 17, 2024
CVE-2023-23882
4.3 MEDIUM

Missing Authorization vulnerability in Brainstorm Force Ultimate Addons for Beaver Builder – Lite.This issue affects Ultimate Addons for Beaver Builder – Lite: from n/a through …

Jan 17, 2024
CVE-2023-20271
6.5 MEDIUM

A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to …

Jan 17, 2024
CVE-2023-20260
6.0 MEDIUM

A vulnerability in the application CLI of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager could allow an authenticated, local attacker to gain escalated …

Jan 17, 2024
CVE-2023-20258
6.5 MEDIUM

A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating …

Jan 17, 2024
CVE-2023-20257
4.8 MEDIUM

A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct cross-site scripting attacks. This vulnerability is …

Jan 17, 2024
CVE-2022-41990
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Vinoj Cardoza 3D Tag Cloud allows Stored XSS.This issue affects 3D Tag Cloud: from n/a through 3.8.

Jan 17, 2024
CVE-2022-41695
5.4 MEDIUM

Missing Authorization vulnerability in SedLex Traffic Manager.This issue affects Traffic Manager: from n/a through 1.4.5.

Jan 17, 2024
CVE-2022-41619
5.4 MEDIUM

Missing Authorization vulnerability in SedLex Image Zoom.This issue affects Image Zoom: from n/a through 1.8.8.

Jan 17, 2024
CVE-2022-40702
5.4 MEDIUM

Missing Authorization vulnerability in Zorem Advanced Local Pickup for WooCommerce.This issue affects Advanced Local Pickup for WooCommerce: from n/a through 1.5.2.

Jan 17, 2024
CVE-2024-0646
7.0 HIGH

An out-of-bounds memory write flaw was found in the Linux kernel’s Transport Layer Security functionality in how a user calls a function splice with a …

Jan 17, 2024
CVE-2024-0641
5.5 MEDIUM

A denial of service vulnerability was found in tipc_crypto_key_revoke in net/tipc/crypto.c in the Linux kernel’s TIPC subsystem. This flaw allows guests with local user privileges …

Jan 17, 2024
CVE-2024-0639
5.5 MEDIUM

A denial of service vulnerability due to a deadlock was found in sctp_auto_asconf_init in net/sctp/socket.c in the Linux kernel’s SCTP subsystem. This flaw allows guests …

Jan 17, 2024
CVE-2024-0396
7.1 HIGH

In Progress MOVEit Transfer versions released before 2022.0.10 (14.0.10), 2022.1.11 (14.1.11), 2023.0.8 (15.0.8), 2023.1.3 (15.1.3), an input validation issue was discovered. An authenticated user can …

Jan 17, 2024
CVE-2023-34379
5.4 MEDIUM

Missing Authorization vulnerability in MagneticOne Cart2Cart: Magento to WooCommerce Migration.This issue affects Cart2Cart: Magento to WooCommerce Migration: from n/a through 2.0.0.

Jan 17, 2024
CVE-2022-40203
6.3 MEDIUM

Missing Authorization vulnerability in AlgolPlus Advanced Dynamic Pricing for WooCommerce.This issue affects Advanced Dynamic Pricing for WooCommerce: from n/a through 4.1.5.

Jan 17, 2024
CVE-2022-38141
4.3 MEDIUM

Missing Authorization vulnerability in Zorem Sales Report Email for WooCommerce.This issue affects Sales Report Email for WooCommerce: from n/a through 2.8.

Jan 17, 2024
CVE-2022-36418
6.5 MEDIUM

Missing Authorization vulnerability in Vagary Digital HREFLANG Tags Lite.This issue affects HREFLANG Tags Lite: from n/a through 2.0.0.

Jan 17, 2024
CVE-2023-5041
8.8 HIGH

The Track The Click WordPress plugin before 0.3.12 does not properly sanitize query parameters to the stats REST endpoint before using them in a database …

Jan 17, 2024
CVE-2023-5006
6.5 MEDIUM

The WP Discord Invite WordPress plugin before 2.5.1 does not protect some of its actions against CSRF attacks, allowing an unauthenticated attacker to perform actions …

Jan 17, 2024
CVE-2024-0645
7.3 HIGH

Buffer overflow vulnerability in Explorer++ affecting version 1.3.5.531. A local attacker could execute arbitrary code via a long filename argument by monitoring Structured Exception Handler …

Jan 17, 2024
CVE-2024-0643
10.0 CRITICAL

Unrestricted upload of dangerous file types in the C21 Live Encoder and Live Mosaic product, version 5.3. This vulnerability allows a remote attacker to upload …

Jan 17, 2024
CVE-2024-0642
9.8 CRITICAL

Inadequate access control in the C21 Live Encoder and Live Mosaic product, version 5.3. This vulnerability allows a remote attacker to access the application as …

Jan 17, 2024
CVE-2021-4434
10.0 CRITICAL

The Social Warfare plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.5.2 via the 'swp_url' parameter. This allows …

Jan 17, 2024
CVE-2023-52285
7.5 HIGH

ExamSys 9150244 allows SQL Injection via the /Support/action/Pages.php s_score2 parameter.

Jan 17, 2024
CVE-2023-51743
6.5 MEDIUM

This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Set Upstream Channel ID (UCID) parameter …

Jan 17, 2024
CVE-2023-51742
6.5 MEDIUM

This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Add Downstream Frequency parameter at its …

Jan 17, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.