CVE Database

4648+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2021-4437
3.5 LOW

A vulnerability, which was classified as problematic, has been found in dbartholomae lambda-middleware frameguard up to 1.0.4. Affected by this issue is some unknown functionality …

Feb 12, 2024
CVE-2024-22226
3.3 LOW

Dell Unity, versions prior to 5.4, contain a path traversal vulnerability in its svc_supportassist utility. An authenticated attacker could potentially exploit this vulnerability, to gain …

Feb 12, 2024
CVE-2024-1433
3.1 LOW

A vulnerability, which was classified as problematic, was found in KDE Plasma Workspace up to 5.93.0. This affects the function EventPluginsManager::enabledPlugins of the file components/calendar/eventpluginsmanager.cpp …

Feb 11, 2024
CVE-2023-45718
3.9 LOW

Sametime is impacted by a failure to invalidate sessions. The application is setting sensitive cookie values in a persistent manner in Sametime Web clients. When …

Feb 9, 2024
CVE-2023-45716
1.7 LOW

Sametime is impacted by sensitive information passed in URL.

Feb 9, 2024
CVE-2024-1246
2.0 LOW

Concrete CMS in version 9 before 9.2.5 is vulnerable to reflected XSS via the Image URL Import Feature due to insufficient validation of administrator provided …

Feb 9, 2024
CVE-2024-1245
2.4 LOW

Concrete CMS version 9 before 9.2.5 is vulnerable to stored XSS in file tags and description attributes since administrator entered file attributes are not sufficiently …

Feb 9, 2024
CVE-2024-1247
2.0 LOW

Concrete CMS version 9 before 9.2.5 is vulnerable to stored XSS via the Role Name field since there is insufficient validation of administrator provided data …

Feb 9, 2024
CVE-2024-24776
3.1 LOW

Mattermost fails to check the required permissions in the POST /api/v4/channels/stats/member_count API resulting in channel member counts being leaked to a user without permissions.

Feb 9, 2024
CVE-2024-24774
3.4 LOW

Mattermost Jira Plugin handling subscriptions fails to check the security level of an incoming issue or limit it based on the user who created the …

Feb 9, 2024
CVE-2024-23319
3.5 LOW

Mattermost Jira Plugin fails to protect against logout CSRF allowing an attacker to post a specially crafted message that would disconnect a user's Jira connection …

Feb 9, 2024
CVE-2024-0628
3.8 LOW

The WP RSS Aggregator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.23.5 via the RSS feed …

Feb 7, 2024
CVE-2024-1269
2.4 LOW

A vulnerability has been found in SourceCodester Product Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /supplier.php. The …

Feb 7, 2024
CVE-2024-1267
3.5 LOW

A vulnerability, which was classified as problematic, has been found in CodeAstro Restaurant POS System 1.0. Affected by this issue is some unknown functionality of …

Feb 7, 2024
CVE-2024-1266
2.4 LOW

A vulnerability classified as problematic was found in CodeAstro University Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /st_reg.php …

Feb 7, 2024
CVE-2024-1265
2.4 LOW

A vulnerability classified as problematic has been found in CodeAstro University Management System 1.0. Affected is an unknown function of the file /att_add.php of the …

Feb 7, 2024
CVE-2024-1258
3.1 LOW

A vulnerability was found in Juanpao JPShop up to 1.5.02. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of …

Feb 6, 2024
CVE-2024-1257
3.5 LOW

A vulnerability was found in Jspxcms 10.2.0. It has been classified as problematic. Affected is an unknown function of the file /ext/collect/find_text.do. The manipulation leads …

Feb 6, 2024
CVE-2024-1256
3.5 LOW

A vulnerability was found in Jspxcms 10.2.0 and classified as problematic. This issue affects some unknown processing of the file /ext/collect/filter_text.do. The manipulation leads to …

Feb 6, 2024
CVE-2024-1048
3.3 LOW

A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CVE-2019-14865, grub2-set-bootflag will create a temporary file with the new grubenv …

Feb 6, 2024
CVE-2024-24940
2.8 LOW

In JetBrains IntelliJ IDEA before 2023.3.3 path traversal was possible when unpacking archives

Feb 6, 2024
CVE-2024-24939
3.3 LOW

In JetBrains Rider before 2023.3.3 logging of environment variables containing secret values was possible

Feb 6, 2024
CVE-2024-20828
2.4 LOW

Improper authorization verification vulnerability in Samsung Internet prior to version 24.0 allows physical attackers to access files downloaded in SecretMode without proper authentication.

Feb 6, 2024
CVE-2024-20810
3.3 LOW

Implicit intent hijacking vulnerability in Smart Suggestions prior to SMR Feb-2024 Release 1 allows local attackers to get sensitive information.

Feb 6, 2024
CVE-2024-1075
3.7 LOW

The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to maintenance mode bypass and information disclosure in all versions up to, …

Feb 5, 2024
CVE-2024-24807
2.7 LOW

Sulu is a highly extensible open-source PHP content management system based on the Symfony framework. There is an issue when inputting HTML into the Tag …

Feb 5, 2024
CVE-2024-24559
3.7 LOW

Vyper is a Pythonic Smart Contract Language for the EVM. There is an error in the stack management when compiling the `IR` for `sha3_64`. Concretely, …

Feb 5, 2024
CVE-2024-24861
3.3 LOW

A race condition was found in the Linux kernel's media/xc4000 device driver in xc4000 xc4000_get_frequency() function. This can result in return value overflow issue, possibly …

Feb 5, 2024
CVE-2015-10129
3.7 LOW

A vulnerability was found in planet-freo up to 20150116 and classified as problematic. Affected by this issue is some unknown functionality of the file admin/inc/auth.inc.php. …

Feb 4, 2024
CVE-2024-1215
3.5 LOW

A vulnerability was found in SourceCodester CRUD without Page Reload 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality …

Feb 3, 2024
CVE-2024-23553
3.0 LOW

A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform exists due to missing a specific http header attribute.

Feb 2, 2024
CVE-2024-1194
3.3 LOW

A vulnerability classified as problematic has been found in Armcode AlienIP 2.41. Affected is an unknown function of the component Locate Host Handler. The manipulation …

Feb 2, 2024
CVE-2024-1193
3.3 LOW

A vulnerability was found in Navicat 12.0.29. It has been rated as problematic. This issue affects some unknown processing of the component MySQL Conecction Handler. …

Feb 2, 2024
CVE-2024-1190
3.3 LOW

A vulnerability was found in Global Scape CuteFTP 9.3.0.3 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation of the …

Feb 2, 2024
CVE-2024-1188
3.3 LOW

A vulnerability, which was classified as problematic, was found in Rizone Soft Notepad3 1.0.2.350. Affected is an unknown function of the component Encryption Passphrase Handler. …

Feb 2, 2024
CVE-2024-1187
3.3 LOW

A vulnerability, which was classified as problematic, has been found in Munsoft Easy Outlook Express Recovery 2.0. This issue affects some unknown processing of the …

Feb 2, 2024
CVE-2024-24560
3.7 LOW

Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine. When calls to external contracts are made, we write the input buffer starting …

Feb 2, 2024
CVE-2024-1186
3.3 LOW

A vulnerability classified as problematic was found in Munsoft Easy Archive Recovery 2.0. This vulnerability affects unknown code of the component Registration Key Handler. The …

Feb 2, 2024
CVE-2024-1185
3.3 LOW

A vulnerability classified as problematic has been found in Nsasoft NBMonitor Network Bandwidth Monitor 1.6.5.0. This affects an unknown part of the component Registration Handler. …

Feb 2, 2024
CVE-2023-50359
3.4 LOW

An unchecked return value vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow local authenticated administrators to …

Feb 2, 2024
CVE-2023-45037
3.8 LOW

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow …

Feb 2, 2024
CVE-2023-45036
3.8 LOW

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow …

Feb 2, 2024
CVE-2023-45035
3.8 LOW

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow …

Feb 2, 2024
CVE-2023-41292
3.8 LOW

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow …

Feb 2, 2024
CVE-2024-1184
3.3 LOW

A vulnerability was found in Nsasoft Network Sleuth 3.0.0.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the …

Feb 2, 2024
CVE-2024-21851
2.9 LOW

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause heap overflow through integer overflow.

Feb 2, 2024
CVE-2024-21845
2.9 LOW

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause heap overflow through integer overflow.

Feb 2, 2024
CVE-2023-49118
2.9 LOW

in OpenHarmony v3.2.4 and prior versions allow a local attacker causes information leak through out-of-bounds Read.

Feb 2, 2024
CVE-2023-43756
2.9 LOW

in OpenHarmony v3.2.4 and prior versions allow a local attacker causes information leak through out-of-bounds Read.

Feb 2, 2024
CVE-2023-46159
2.6 LOW

IBM Storage Ceph 5.3z1, 5.3z5, and 6.1z1 could allow an authenticated user on the network to cause a denial of service from RGW. IBM X-Force …

Feb 2, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.