CVE Database

122339+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-0491
5.3 MEDIUM

A vulnerability classified as problematic has been found in Huaxia ERP up to 3.1. Affected is an unknown function of the file src/main/java/com/jsh/erp/controller/UserController.java. The manipulation …

Jan 13, 2024
CVE-2024-0490
5.3 MEDIUM

A vulnerability was found in Huaxia ERP up to 3.1. It has been rated as problematic. This issue affects some unknown processing of the file …

Jan 13, 2024
CVE-2024-0489
6.3 MEDIUM

A vulnerability was found in code-projects Fighting Cock Information System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file …

Jan 13, 2024
CVE-2024-0488
6.3 MEDIUM

A vulnerability was found in code-projects Fighting Cock Information System 1.0. It has been classified as critical. This affects an unknown part of the file …

Jan 13, 2024
CVE-2024-0487
6.3 MEDIUM

A vulnerability was found in code-projects Fighting Cock Information System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Jan 13, 2024
CVE-2024-0486
6.3 MEDIUM

A vulnerability has been found in code-projects Fighting Cock Information System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Jan 13, 2024
CVE-2024-0485
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in code-projects Fighting Cock Information System 1.0. Affected is an unknown function of the file admin/pages/tables/add_con.php. …

Jan 13, 2024
CVE-2024-0484
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in code-projects Fighting Cock Information System 1.0. This issue affects some unknown processing of the …

Jan 13, 2024
CVE-2024-0483
6.3 MEDIUM

A vulnerability classified as critical was found in Taokeyun up to 1.0.5. This vulnerability affects the function index of the file application/index/controller/app/Task.php of the component …

Jan 13, 2024
CVE-2024-0482
6.3 MEDIUM

A vulnerability classified as critical has been found in Taokeyun up to 1.0.5. This affects the function index of the file application/index/controller/app/Video.php of the component …

Jan 13, 2024
CVE-2024-0481
6.3 MEDIUM

A vulnerability was found in Taokeyun up to 1.0.5. It has been rated as critical. Affected by this issue is the function shopGoods of the …

Jan 13, 2024
CVE-2024-22209
6.4 MEDIUM

Open edX Platform is a service-oriented platform for authoring and delivering online learning. A user with a JWT and more limited scopes could call endpoints …

Jan 13, 2024
CVE-2024-21640
5.4 MEDIUM

Chromium Embedded Framework (CEF) is a simple framework for embedding Chromium-based browsers in other applications.`CefVideoConsumerOSR::OnFrameCaptured` does not check `pixel_format` properly, which leads to out-of-bounds read …

Jan 13, 2024
CVE-2024-0480
7.3 HIGH

A vulnerability was found in Taokeyun up to 1.0.5. It has been declared as critical. Affected by this vulnerability is the function index of the …

Jan 13, 2024
CVE-2024-0251
6.1 MEDIUM

The Advanced Woo Search plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the search parameter in all versions up to, and including, 2.96 …

Jan 13, 2024
CVE-2024-0479
7.3 HIGH

A vulnerability was found in Taokeyun up to 1.0.5. It has been classified as critical. Affected is the function login of the file application/index/controller/m/User.php of …

Jan 13, 2024
CVE-2024-0478
6.3 MEDIUM

A vulnerability was found in code-projects Fighting Cock Information System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/pages/edit_chicken.php. …

Jan 13, 2024
CVE-2024-0477
6.3 MEDIUM

A vulnerability has been found in code-projects Fighting Cock Information System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/action/update-deworm.php. …

Jan 13, 2024
CVE-2024-0476
2.4 LOW

A vulnerability, which was classified as problematic, was found in Blood Bank & Donor Management 1.0. This affects an unknown part of the file request-received-bydonar.php. …

Jan 13, 2024
CVE-2023-52289
7.5 HIGH

An issue was discovered in the flaskcode package through 0.0.8 for Python. An unauthenticated directory traversal, exploitable with a POST request to a /update-resource-data/<file_path> URI …

Jan 13, 2024
CVE-2023-52288
7.5 HIGH

An issue was discovered in the flaskcode package through 0.0.8 for Python. An unauthenticated directory traversal, exploitable with a GET request to a /resource-data/<file_path>.txt URI …

Jan 13, 2024
CVE-2023-51071
6.5 MEDIUM

An access control issue in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to arbitrarily disable the SMB service on a …

Jan 13, 2024
CVE-2023-51070
7.5 HIGH

An access control issue in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to arbitrarily adjust sensitive SMB settings on the …

Jan 13, 2024
CVE-2023-51068
5.4 MEDIUM

An authenticated reflected cross-site scripting (XSS) vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 allows attackers to execute arbitrary javascript on a victim's browser …

Jan 13, 2024
CVE-2023-51067
6.1 MEDIUM

An unauthenticated reflected cross-site scripting (XSS) vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 allows attackers to execute arbitrary javascript on a victim's browser …

Jan 13, 2024
CVE-2023-51066
8.8 HIGH

An authenticated remote code execution vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows attackers to arbitrarily execute commands.

Jan 13, 2024
CVE-2023-51065
7.5 HIGH

Incorrect access control in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows unauthenticated attackers to obtain system backups and other sensitive information from …

Jan 13, 2024
CVE-2023-51064
6.1 MEDIUM

QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 was discovered to contain a DOM Based reflected XSS vulnerability within the component qnme-ajax?method=tree_table.

Jan 13, 2024
CVE-2023-51063
8.8 HIGH

QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 was discovered to contain a DOM Based Reflected Cross Site Scripting (XSS) vulnerability within the component …

Jan 13, 2024
CVE-2023-51062
5.3 MEDIUM

An unauthenticated log file read in the component log-smblog-save of QStar Archive Solutions RELEASE_3-0 Build 7 Patch 0 allows attackers to disclose the SMB Log …

Jan 13, 2024
CVE-2023-51805
6.5 MEDIUM

SQL Injection vulnerability in TDuckCLoud tduck-platform v.4.0 allows a remote attacker to obtain sensitive information via the getFormKey parameter in the search function of FormDataMysqlService.java …

Jan 13, 2024
CVE-2023-51804
7.5 HIGH

An issue in rymcu forest v.0.02 allows a remote attacker to obtain sensitive information via manipulation of the HTTP body URL in the com.rymcu.forest.web.api.common.UploadController file.

Jan 13, 2024
CVE-2023-46943
9.1 CRITICAL

An issue was discovered in NPM's package @evershop/evershop before version 1.0.0-rc.8. The HMAC secret used for generating tokens is hardcoded as "secret". A weak HMAC …

Jan 13, 2024
CVE-2023-46942
7.5 HIGH

Lack of authentication in NPM's package @evershop/evershop before version 1.0.0-rc.8, allows remote attackers to obtain sensitive information via improper authorization in GraphQL endpoints.

Jan 13, 2024
CVE-2023-33472
8.8 HIGH

An issue was discovered in Scada-LTS v2.7.5.2 build 4551883606 and before, allows remote attackers with low-level authentication to escalate privileges, execute arbitrary code, and obtain …

Jan 13, 2024
CVE-2023-50072
5.4 MEDIUM

A Stored Cross-Site Scripting (XSS) vulnerability exists in OpenKM version 7.1.40 (dbb6e88) With Professional Extension that allows an authenticated user to upload a note on …

Jan 13, 2024
CVE-2024-22142
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Cozmoslabs Profile Builder Pro allows Reflected XSS.This issue affects Profile Builder Pro: from …

Jan 13, 2024
CVE-2024-22137
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MailMunch Constant Contact Forms by MailMunch allows Stored XSS.This issue affects Constant Contact …

Jan 13, 2024
CVE-2024-0475
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in code-projects Dormitory Management System 1.0. Affected by this issue is some unknown functionality of …

Jan 13, 2024
CVE-2024-23301
5.5 MEDIUM

Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers to gain access to system secrets otherwise only readable …

Jan 12, 2024
CVE-2024-0474
7.3 HIGH

A vulnerability classified as critical was found in code-projects Dormitory Management System 1.0. Affected by this vulnerability is an unknown functionality of the file login.php. …

Jan 12, 2024
CVE-2024-0230
2.4 LOW

A session management issue was addressed with improved checks. This issue is fixed in Magic Keyboard Firmware Update 2.0.6. An attacker with physical access to …

Jan 12, 2024
CVE-2023-48166
7.5 HIGH

A directory traversal vulnerability in the SOAP Server integrated in Atos Unify OpenScape Voice V10 before V10R3.26.1 allows a remote attacker to view the contents …

Jan 12, 2024
CVE-2024-21639
5.3 MEDIUM

CEF (Chromium Embedded Framework ) is a simple framework for embedding Chromium-based browsers in other applications. `CefLayeredWindowUpdaterOSR::OnAllocatedSharedMemory` does not check the size of the shared …

Jan 12, 2024
CVE-2024-0473
6.3 MEDIUM

A vulnerability classified as critical has been found in code-projects Dormitory Management System 1.0. Affected is an unknown function of the file comment.php. The manipulation …

Jan 12, 2024
CVE-2024-0472
3.5 LOW

A vulnerability was found in code-projects Dormitory Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file …

Jan 12, 2024
CVE-2023-49647
8.8 HIGH

Improper access control in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows before version 5.16.10 may allow an …

Jan 12, 2024
CVE-2022-4962
4.3 MEDIUM

A vulnerability was found in Apollo 2.0.0/2.0.1 and classified as problematic. Affected by this issue is some unknown functionality of the file /users of the …

Jan 12, 2024
CVE-2024-21655
4.3 MEDIUM

Discourse is a platform for community discussion. For fields that are client editable, limits on sizes are not imposed. This allows a malicious actor to …

Jan 12, 2024
CVE-2024-21654
4.8 MEDIUM

Rubygems.org is the Ruby community's gem hosting service. Rubygems.org users with MFA enabled would normally be protected from account takeover in the case of email …

Jan 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.