CVE Database

122339+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-0471
6.3 MEDIUM

A vulnerability was found in code-projects Human Resource Integrated System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file …

Jan 12, 2024
CVE-2024-0470
6.3 MEDIUM

A vulnerability was found in code-projects Human Resource Integrated System 1.0. It has been classified as critical. This affects an unknown part of the file …

Jan 12, 2024
CVE-2024-0469
6.3 MEDIUM

A vulnerability was found in code-projects Human Resource Integrated System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Jan 12, 2024
CVE-2024-0468
6.3 MEDIUM

A vulnerability has been found in code-projects Fighting Cock Information System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Jan 12, 2024
CVE-2023-51698
9.6 CRITICAL

Atril is a simple multi-page document viewer. Atril is vulnerable to a critical Command Injection Vulnerability. This vulnerability gives the attacker immediate access to the …

Jan 12, 2024
CVE-2023-49801
4.2 MEDIUM

Lif Auth Server is a server for validating logins, managing information, and account recovery for Lif Accounts. The issue relates to the `get_pfp` and `get_banner` …

Jan 12, 2024
CVE-2023-49099
3.1 LOW

Discourse is a platform for community discussion. Under very specific circumstances, secure upload URLs associated with posts can be accessed by guest users even when …

Jan 12, 2024
CVE-2023-49098
3.5 LOW

Discourse-reactions is a plugin that allows user to add their reactions to the post. Data about a user's reaction notifications could be exposed. This vulnerability …

Jan 12, 2024
CVE-2023-48297
8.6 HIGH

Discourse is a platform for community discussion. The message serializer uses the full list of expanded chat mentions (@all and @here) which can lead to …

Jan 12, 2024
CVE-2023-42463
7.4 HIGH

Wazuh is a free and open source platform used for threat prevention, detection, and response. This bug introduced a stack overflow hazard that could allow …

Jan 12, 2024
CVE-2024-22206
9.0 CRITICAL

Clerk helps developers build user management. Unauthorized access or privilege escalation due to a logic flaw in auth() in the App Router or getAuth() in …

Jan 12, 2024
CVE-2024-0467
3.5 LOW

A vulnerability, which was classified as problematic, was found in code-projects Employee Profile Management System 1.0. Affected is an unknown function of the file edit_position_query.php. …

Jan 12, 2024
CVE-2010-10011
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in Acritum Femitter Server 1.04. Affected is an unknown function. The manipulation leads to path traversal. …

Jan 12, 2024
CVE-2024-0466
5.5 MEDIUM

A vulnerability, which was classified as critical, has been found in code-projects Employee Profile Management System 1.0. This issue affects some unknown processing of the …

Jan 12, 2024
CVE-2024-0465
3.5 LOW

A vulnerability classified as problematic was found in code-projects Employee Profile Management System 1.0. This vulnerability affects unknown code of the file download.php. The manipulation …

Jan 12, 2024
CVE-2024-0464
6.3 MEDIUM

A vulnerability classified as critical has been found in code-projects Online Faculty Clearance 1.0. This affects an unknown part of the file delete_faculty.php of the …

Jan 12, 2024
CVE-2023-6683
6.5 MEDIUM

A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. The qemu_clipboard_request() function can be reached before vnc_server_cut_text_caps() was called and …

Jan 12, 2024
CVE-2023-31035
7.5 HIGH

NVIDIA DGX A100 SBIOS contains a vulnerability where an attacker may cause an SMI callout vulnerability that could be used to execute arbitrary code at …

Jan 12, 2024
CVE-2023-31034
6.6 MEDIUM

NVIDIA DGX A100 SBIOS contains a vulnerability where a local attacker can cause input validation checks to be bypassed by causing an integer overflow. A …

Jan 12, 2024
CVE-2023-31033
6.8 MEDIUM

NVIDIA DGX A100 BMC contains a vulnerability where a user may cause a missing authentication issue for a critical function by an adjacent network . …

Jan 12, 2024
CVE-2023-31032
7.5 HIGH

NVIDIA DGX A100 SBIOS contains a vulnerability where a user may cause a dynamic variable evaluation by local access. A successful exploit of this vulnerability …

Jan 12, 2024
CVE-2023-31031
4.2 MEDIUM

NVIDIA DGX Station A100 and DGX Station A800 SBIOS contains a vulnerability where a user may cause a heap-based buffer overflow by local access. A …

Jan 12, 2024
CVE-2023-31030
9.3 CRITICAL

NVIDIA DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause a stack overflow by sending a specially …

Jan 12, 2024
CVE-2023-31029
9.3 CRITICAL

NVIDIA DGX A100 baseboard management controller (BMC) contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause a stack overflow by …

Jan 12, 2024
CVE-2023-31025
6.5 MEDIUM

NVIDIA DGX A100 BMC contains a vulnerability where an attacker may cause an LDAP user injection. A successful exploit of this vulnerability may lead to …

Jan 12, 2024
CVE-2023-31024
9.0 CRITICAL

NVIDIA DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause stack memory corruption by sending a specially …

Jan 12, 2024
CVE-2024-0463
6.3 MEDIUM

A vulnerability was found in code-projects Online Faculty Clearance 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Jan 12, 2024
CVE-2024-0462
6.3 MEDIUM

A vulnerability was found in code-projects Online Faculty Clearance 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Jan 12, 2024
CVE-2024-21887
9.1 CRITICAL KEV

A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send …

Jan 12, 2024
CVE-2024-0461
6.3 MEDIUM

A vulnerability was found in code-projects Online Faculty Clearance 1.0. It has been classified as critical. Affected is an unknown function of the file deactivate.php …

Jan 12, 2024
CVE-2023-46805
8.2 HIGH KEV

An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources …

Jan 12, 2024
CVE-2023-31036
7.5 HIGH

NVIDIA Triton Inference Server for Linux and Windows contains a vulnerability where, when it is launched with the non-default command line option --model-control explicit, an …

Jan 12, 2024
CVE-2023-28899
4.7 MEDIUM

By sending a specific reset UDS request via OBDII port of Skoda vehicles, it is possible to cause vehicle engine shutdown and denial of service …

Jan 12, 2024
CVE-2024-22494
5.4 MEDIUM

A stored XSS vulnerability exists in JFinalcms 5.0.0 via the /gusetbook/save mobile parameter, which allows remote attackers to inject arbitrary web script or HTML.

Jan 12, 2024
CVE-2024-22493
5.4 MEDIUM

A stored XSS vulnerability exists in JFinalcms 5.0.0 via the /gusetbook/save content parameter, which allows remote attackers to inject arbitrary web script or HTML.

Jan 12, 2024
CVE-2024-22492
5.4 MEDIUM

A stored XSS vulnerability exists in JFinalcms 5.0.0 via the /gusetbook/save contact parameter, which allows remote attackers to inject arbitrary web script or HTML.

Jan 12, 2024
CVE-2024-0460
6.3 MEDIUM

A vulnerability was found in code-projects Faculty Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/pages/student-print.php. The …

Jan 12, 2024
CVE-2024-0459
4.7 MEDIUM

A vulnerability has been found in Blood Bank & Donor Management 5.6 and classified as critical. This vulnerability affects unknown code of the file /admin/request-received-bydonar.php. …

Jan 12, 2024
CVE-2023-51978
6.5 MEDIUM

In PHPGurukul Art Gallery Management System v1.1, "Update Artist Image" functionality of "imageid" parameter is vulnerable to SQL Injection.

Jan 12, 2024
CVE-2023-28898
5.3 MEDIUM

The Real-Time Streaming Protocol implementation in the MIB3 infotainment incorrectly handles requests to /logs URI, when the id parameter equals to zero. This issue allows …

Jan 12, 2024
CVE-2023-28897
4.0 MEDIUM

The secret value used for access to critical UDS services of the MIB3 infotainment is hardcoded in the firmware. Vulnerability discovered on Škoda Superb III …

Jan 12, 2024
CVE-2023-51949
8.8 HIGH

Verydows v2.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /protected/controller/backend/role_controller

Jan 12, 2024
CVE-2023-49262
9.8 CRITICAL

The authentication mechanism can be bypassed by overflowing the value of the Cookie "authentication" field, provided there is an active user session.

Jan 12, 2024
CVE-2023-49261
7.5 HIGH

The "tokenKey" value used in user authorization is visible in the HTML source of the login page.

Jan 12, 2024
CVE-2023-49260
6.1 MEDIUM

An XSS attack can be performed by changing the MOTD banner and pointing the victim to the "terminal_tool.cgi" path. It can be used together with …

Jan 12, 2024
CVE-2023-49259
7.5 HIGH

The authentication cookies are generated using an algorithm based on the username, hardcoded secret and the up-time, and can be guessed in a reasonable time.

Jan 12, 2024
CVE-2023-49258
6.1 MEDIUM

User browser may be forced to execute JavaScript and pass the authentication cookie to the attacker leveraging the XSS vulnerability located at "/gui/terminal_tool.cgi" in the …

Jan 12, 2024
CVE-2023-49257
8.8 HIGH

An authenticated user is able to upload an arbitrary CGI-compatible file using the certificate upload utility and execute it with the root user privileges.

Jan 12, 2024
CVE-2023-49256
7.5 HIGH

It is possible to download the configuration backup without authorization and decrypt included passwords using hardcoded static key.

Jan 12, 2024
CVE-2023-49255
9.8 CRITICAL

The router console is accessible without authentication at "data" field, and while a user needs to be logged in in order to modify the configuration, …

Jan 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.