CVE Database

40083+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-23507
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through …

Jan 31, 2024
CVE-2024-22305
7.5 HIGH

Authorization Bypass Through User-Controlled Key vulnerability in ali Forms Contact Form builder with drag & drop for WordPress – Kali Forms.This issue affects Contact Form …

Jan 31, 2024
CVE-2024-22290
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in AboZain,O7abeeb,UnitOne Custom Dashboard Widgets allows Cross-Site Scripting (XSS).This issue affects Custom Dashboard Widgets: from n/a through 1.3.1.

Jan 31, 2024
CVE-2024-22287
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Luděk Melichar Better Anchor Links allows Cross-Site Scripting (XSS).This issue affects Better Anchor Links: from n/a through 1.7.5.

Jan 31, 2024
CVE-2023-44313
7.6 HIGH

Server-Side Request Forgery (SSRF) vulnerability in Apache ServiceComb Service-Center. Attackers can obtain sensitive server information through specially crafted requests.This issue affects Apache ServiceComb before 2.1.0(include). …

Jan 31, 2024
CVE-2024-23775
7.5 HIGH

Integer Overflow vulnerability in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2, allows attackers to cause a denial of service (DoS) via mbedtls_x509_set_extension().

Jan 31, 2024
CVE-2024-1069
7.2 HIGH

The Contact Form Entries plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation on the 'view_page' function in versions up …

Jan 31, 2024
CVE-2023-31505
7.2 HIGH

An arbitrary file upload vulnerability in Schlix CMS v2.2.8-1, allows remote authenticated attackers to execute arbitrary code and obtain sensitive information via a crafted .phtml …

Jan 31, 2024
CVE-2024-1077
8.8 HIGH

Use after free in Network in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit heap corruption via a malicious file. (Chromium …

Jan 30, 2024
CVE-2024-1060
8.8 HIGH

Use after free in Canvas in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Jan 30, 2024
CVE-2024-1059
8.8 HIGH

Use after free in Peer Connection in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML …

Jan 30, 2024
CVE-2024-24558
8.2 HIGH

TanStack Query supplies asynchronous state management, server-state utilities and data fetching for the web. The `@tanstack/react-query-next-experimental` NPM package is vulnerable to a cross-site scripting vulnerability. …

Jan 30, 2024
CVE-2024-24556
7.2 HIGH

urql is a GraphQL client that exposes a set of helpers for several frameworks. The `@urql/next` package is vulnerable to XSS. To exploit this an …

Jan 30, 2024
CVE-2024-23841
8.2 HIGH

apollo-client-nextjs is the Apollo Client support for the Next.js App Router. The @apollo/experimental-apollo-client-nextjs NPM package is vulnerable to a cross-site scripting vulnerability. To exploit this …

Jan 30, 2024
CVE-2024-1036
7.3 HIGH

A vulnerability was found in openBI up to 1.0.8 and classified as critical. This issue affects the function uploadIcon of the file /application/index/controller/Screen.php of the …

Jan 30, 2024
CVE-2024-23838
7.5 HIGH

TrueLayer.NET is the .Net client for TrueLayer. The vulnerability could potentially allow a malicious actor to gain control over the destination URL of the HttpClient …

Jan 30, 2024
CVE-2023-6258
8.1 HIGH

A security vulnerability has been identified in the pkcs11-provider, which is associated with Public-Key Cryptography Standards (PKCS#11). If exploited successfully, this vulnerability could result in …

Jan 30, 2024
CVE-2023-46230
8.2 HIGH

In Splunk Add-on Builder versions below 4.1.4, the app writes sensitive information to internal log files.

Jan 30, 2024
CVE-2024-21649
8.8 HIGH

The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). Prior to 4.2.0, authenticated users could …

Jan 30, 2024
CVE-2024-1035
7.3 HIGH

A vulnerability has been found in openBI up to 1.0.8 and classified as critical. This vulnerability affects the function uploadIcon of the file /application/index/controller/Icon.php. The …

Jan 30, 2024
CVE-2024-1019
8.6 HIGH

ModSecurity / libModSecurity 3.0.0 to 3.0.11 is affected by a WAF bypass for path-based payloads submitted via specially crafted request URLs. ModSecurity v3 decodes percent-encoded …

Jan 30, 2024
CVE-2024-1034
7.3 HIGH

A vulnerability, which was classified as critical, was found in openBI up to 1.0.8. This affects the function uploadFile of the file /application/index/controller/File.php. The manipulation …

Jan 30, 2024
CVE-2024-1032
7.3 HIGH

A vulnerability classified as critical was found in openBI up to 1.0.8. Affected by this vulnerability is the function testConnection of the file /application/index/controller/Databasesource.php of …

Jan 30, 2024
CVE-2024-22523
7.5 HIGH

Directory Traversal vulnerability in Qiyu iFair version 23.8_ad0 and before, allows remote attackers to obtain sensitive information via uploadimage component.

Jan 30, 2024
CVE-2024-1061
8.6 HIGH

The 'HTML5 Video Player' WordPress Plugin, version < 2.5.25 is affected by an unauthenticated SQL injection vulnerability in the 'id' parameter in the 'get_view' function.

Jan 30, 2024
CVE-2023-6942
7.5 HIGH

Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation EZSocket versions 3.0 to 5.92, GT Designer3 Version1(GOT1000) versions 1.325P and prior, GT Designer3 Version1(GOT2000) …

Jan 30, 2024
CVE-2023-36260
7.5 HIGH

An issue was discovered in the Feed Me plugin 4.6.1 for Craft CMS. It allows remote attackers to cause a denial of service (DoS) via …

Jan 30, 2024
CVE-2024-21488
7.3 HIGH

Versions of the package network before 0.7.0 are vulnerable to Arbitrary Command Injection due to use of the child_process exec function without input sanitization. If …

Jan 30, 2024
CVE-2024-21840
7.9 HIGH

Incorrect Default Permissions vulnerability in Hitachi Storage Plug-in for VMware vCenter allows local users to read and write specific files. This issue affects Hitachi Storage …

Jan 30, 2024
CVE-2024-22938
7.8 HIGH

Insecure Permissions vulnerability in BossCMS v.1.3.0 allows a local attacker to execute arbitrary code and escalate privileges via the init function in admin.class.php component.

Jan 30, 2024
CVE-2023-5372
7.2 HIGH

The post-authentication command injection vulnerability in Zyxel NAS326 firmware versions through V5.21(AAZF.15)C0 and NAS542 firmware versions through V5.21(ABAG.12)C0 could allow an authenticated attacker with administrator …

Jan 30, 2024
CVE-2023-51843
8.2 HIGH

react-dashboard 1.4.0 is vulnerable to Cross Site Scripting (XSS) as httpOnly is not set.

Jan 30, 2024
CVE-2023-4551
7.2 HIGH

Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows OS Command Injection. The AppBuilder's Scheduler functionality that facilitates creation of scheduled tasks is …

Jan 29, 2024
CVE-2023-4550
7.5 HIGH

Improper Input Validation, Files or Directories Accessible to External Parties vulnerability in OpenText AppBuilder on Windows, Linux allows Probe System Files. An unauthenticated or authenticated …

Jan 29, 2024
CVE-2023-49038
7.2 HIGH

Command injection in the ping utility on Buffalo LS210D 1.78-0.03 allows a remote authenticated attacker to inject arbitrary commands onto the NAS as root.

Jan 29, 2024
CVE-2024-24140
7.2 HIGH

Sourcecodester Daily Habit Tracker App 1.0 allows SQL Injection via the parameter 'tracker.'

Jan 29, 2024
CVE-2024-24139
7.2 HIGH

Sourcecodester Login System with Email Verification 1.0 allows SQL Injection via the 'user' parameter.

Jan 29, 2024
CVE-2023-51842
7.5 HIGH

An algorithm-downgrade issue was discovered in Ylianst MeshCentral 1.1.16.

Jan 29, 2024
CVE-2024-23940
7.8 HIGH

Trend Micro uiAirSupport, included in the Trend Micro Security 2023 family of consumer products, version 6.0.2092 and below is vulnerable to a DLL hijacking/proxying vulnerability, …

Jan 29, 2024
CVE-2024-23828
8.8 HIGH

Nginx-UI is a web interface to manage Nginx configurations. It is vulnerable to an authenticated arbitrary command execution via CRLF attack when changing the value …

Jan 29, 2024
CVE-2024-1009
7.3 HIGH

A vulnerability was found in SourceCodester Employee Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Jan 29, 2024
CVE-2023-1705
8.4 HIGH

Missing Authorization vulnerability in Forcepoint F|One SmartEdge Agent on Windows (bgAutoinstaller service modules) allows Privilege Escalation, Functionality Bypass.This issue affects F|One SmartEdge Agent: before 1.7.0.230330-554.

Jan 29, 2024
CVE-2024-1006
7.3 HIGH

A vulnerability was found in Shanxi Diankeyun Technology NODERP up to 6.0.2 and classified as critical. This issue affects some unknown processing of the file …

Jan 29, 2024
CVE-2024-1004
7.2 HIGH

A vulnerability, which was classified as critical, was found in Totolink N200RE 9.3.5u.6139_B20201216. This affects the function loginAuth of the file /cgi-bin/cstecgi.cgi. The manipulation of …

Jan 29, 2024
CVE-2024-1003
7.2 HIGH

A vulnerability, which was classified as critical, has been found in Totolink N200RE 9.3.5u.6139_B20201216. Affected by this issue is the function setLanguageCfg of the file …

Jan 29, 2024
CVE-2023-7204
7.5 HIGH

The WP STAGING WordPress Backup plugin before 3.2.0 allows access to cache files during the cloning process which provides

Jan 29, 2024
CVE-2023-7074
8.8 HIGH

The WP SOCIAL BOOKMARK MENU WordPress plugin through 1.2 does not have CSRF check in place when updating its settings, which could allow attackers to …

Jan 29, 2024
CVE-2023-6946
8.8 HIGH

The Autotitle for WordPress plugin through 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

Jan 29, 2024
CVE-2023-6391
8.8 HIGH

The Custom User CSS WordPress plugin through 0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make …

Jan 29, 2024
CVE-2023-6390
8.8 HIGH

The WordPress Users WordPress plugin through 1.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

Jan 29, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.