CVE Database

4648+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-50328
3.7 LOW

IBM PowerSC 1.3, 2.0, and 2.1 may allow a remote attacker to view session identifiers passed via URL query strings. IBM X-Force ID: 275110.

Feb 2, 2024
CVE-2024-0325
3.6 LOW

In Helix Sync versions prior to 2024.1, a local command injection was identified. Reported by Bryan Riggins.

Feb 1, 2024
CVE-2024-24754
3.7 LOW

Bref enable serverless PHP on AWS Lambda. When Bref is used with the Event-Driven Function runtime and the handler is a `RequestHandlerInterface`, then the Lambda …

Feb 1, 2024
CVE-2024-1103
3.5 LOW

A vulnerability was found in CodeAstro Real Estate Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality …

Jan 31, 2024
CVE-2023-7043
3.3 LOW

Unquoted service path in ESET products allows to drop a prepared program to a specific location and run on boot with the NT AUTHORITY\NetworkService permissions.

Jan 31, 2024
CVE-2024-1099
3.5 LOW

A vulnerability was found in Rebuild up to 3.5.5. It has been classified as problematic. Affected is the function getFileOfData of the file /filex/read-raw. The …

Jan 31, 2024
CVE-2024-22236
3.3 LOW

In Spring Cloud Contract, versions 4.1.x prior to 4.1.1, versions 4.0.x prior to 4.0.5, and versions 3.1.x prior to 3.1.10, test execution is vulnerable to …

Jan 31, 2024
CVE-2024-23825
3.0 LOW

TablePress is a table plugin for Wordpress. For importing tables, TablePress makes external HTTP requests based on a URL that is provided by the user. …

Jan 30, 2024
CVE-2024-22200
3.3 LOW

vantage6-UI is the User Interface for vantage6. The docker image used to run the UI leaks the nginx version. To mitigate the vulnerability, users can …

Jan 30, 2024
CVE-2024-22193
3.5 LOW

The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). There are no checks on whether …

Jan 30, 2024
CVE-2024-21671
3.7 LOW

The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). It is possible to find out …

Jan 30, 2024
CVE-2024-1031
3.5 LOW

A vulnerability was found in CodeAstro Expense Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file templates/5-Add-Expenses.php …

Jan 30, 2024
CVE-2024-1030
3.5 LOW

A vulnerability was found in Cogites eReserv 7.7.58. It has been classified as problematic. This affects an unknown part of the file /front/admin/tenancyDetail.php. The manipulation …

Jan 30, 2024
CVE-2024-21803
3.5 LOW

Use After Free vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (bluetooth modules) allows Local Execution of Code. This vulnerability is associated with …

Jan 30, 2024
CVE-2024-1029
3.5 LOW

A vulnerability was found in Cogites eReserv 7.7.58 and classified as problematic. Affected by this issue is some unknown functionality of the file /front/admin/tenancyDetail.php. The …

Jan 30, 2024
CVE-2024-1028
3.5 LOW

A vulnerability has been found in SourceCodester Facebook News Feed Like 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of …

Jan 30, 2024
CVE-2024-1026
3.5 LOW

A vulnerability was found in Cogites eReserv 7.7.58 and classified as problematic. This issue affects some unknown processing of the file front/admin/config.php. The manipulation of …

Jan 30, 2024
CVE-2024-1024
3.5 LOW

A vulnerability has been found in SourceCodester Facebook News Feed Like 1.0 and classified as problematic. This vulnerability affects unknown code of the component New …

Jan 30, 2024
CVE-2024-1022
2.4 LOW

A vulnerability, which was classified as problematic, was found in CodeAstro Simple Student Result Management System 5.6. This affects an unknown part of the file …

Jan 29, 2024
CVE-2024-1020
3.5 LOW

A vulnerability classified as problematic was found in Rebuild up to 3.5.5. Affected by this vulnerability is the function getStorageFile of the file /filex/proxy-download. The …

Jan 29, 2024
CVE-2024-1018
2.4 LOW

A vulnerability classified as problematic has been found in PbootCMS 3.2.5-20230421. Affected is an unknown function of the file /admin.php?p=/Area/index#tab=t2. The manipulation of the argument …

Jan 29, 2024
CVE-2023-22836
3.5 LOW

In cases where a multi-tenant stack user is operating Foundry’s Linter service, and the user changes a group name from the default value, the renamed …

Jan 29, 2024
CVE-2024-1010
3.5 LOW

A vulnerability classified as problematic has been found in SourceCodester Employee Management System 1.0. This affects an unknown part of the file edit-profile.php. The manipulation …

Jan 29, 2024
CVE-2024-23790
3.5 LOW

Improper Input Validation vulnerability in the upload functionality for user avatars allows functionality misuse due to missing check of filetypes. This issue affects OTRS: from …

Jan 29, 2024
CVE-2024-23743
3.3 LOW

Notion through 3.1.0 on macOS might allow code execution because of RunAsNode and enableNodeClilnspectArguments. NOTE: the vendor states "the attacker must launch the Notion Desktop …

Jan 28, 2024
CVE-2024-0958
3.5 LOW

A vulnerability was found in CodeAstro Stock Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /index.php of …

Jan 27, 2024
CVE-2024-0948
2.4 LOW

** DISPUTED ** A vulnerability, which was classified as problematic, has been found in NetBox up to 3.7.0. This issue affects some unknown processing of …

Jan 26, 2024
CVE-2024-0944
3.7 LOW

A vulnerability was found in Totolink T8 4.1.5cu.833_20220905. It has been rated as problematic. Affected by this issue is some unknown functionality of the file …

Jan 26, 2024
CVE-2024-0943
3.7 LOW

A vulnerability was found in Totolink N350RT 9.3.5u.6255. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file …

Jan 26, 2024
CVE-2024-0942
3.7 LOW

A vulnerability was found in Totolink N200RE V5 9.3.5u.6255_B20211224. It has been classified as problematic. Affected is an unknown function of the file /cgi-bin/cstecgi.cgi. The …

Jan 26, 2024
CVE-2024-21336
2.5 LOW

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Jan 26, 2024
CVE-2024-21383
3.3 LOW

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Jan 26, 2024
CVE-2024-0891
3.5 LOW

A vulnerability was found in hongmaple octopus 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation of …

Jan 25, 2024
CVE-2024-0886
3.3 LOW

A vulnerability classified as problematic was found in Poikosoft EZ CD Audio Converter 8.0.7. Affected by this vulnerability is an unknown functionality of the component …

Jan 25, 2024
CVE-2023-50785
2.7 LOW

Zoho ManageEngine ADAudit Plus before 7270 allows admin users to view names of arbitrary directories via path traversal.

Jan 25, 2024
CVE-2024-22229
3.1 LOW

Dell Unity, versions prior to 5.4, contain a vulnerability whereby log messages can be spoofed by an authenticated attacker. An attacker could exploit this vulnerability …

Jan 24, 2024
CVE-2024-22308
3.4 LOW

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in smp7, wp.Insider Simple Membership.This issue affects Simple Membership: from n/a through 4.4.1.

Jan 24, 2024
CVE-2024-23217
3.3 LOW

A privacy issue was addressed with improved handling of temporary files. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, macOS …

Jan 23, 2024
CVE-2024-23211
3.3 LOW

A privacy issue was addressed with improved handling of user preferences. This issue is fixed in Safari 17.3, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 …

Jan 23, 2024
CVE-2024-23210
3.3 LOW

This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, …

Jan 23, 2024
CVE-2024-0782
3.5 LOW

A vulnerability has been found in CodeAstro Online Railway Reservation System 1.0 and classified as problematic. This vulnerability affects unknown code of the file pass-profile.php. …

Jan 22, 2024
CVE-2024-0781
3.5 LOW

A vulnerability, which was classified as problematic, was found in CodeAstro Internet Banking System 1.0. This affects an unknown part of the file pages_client_signup.php. The …

Jan 22, 2024
CVE-2024-0776
3.5 LOW

A vulnerability, which was classified as problematic, has been found in LinZhaoguan pb-cms 2.0. Affected by this issue is some unknown functionality of the component …

Jan 22, 2024
CVE-2024-0773
3.5 LOW

A vulnerability classified as problematic was found in CodeAstro Internet Banking System 1.0. Affected by this vulnerability is an unknown functionality of the file pages_client_signup.php. …

Jan 22, 2024
CVE-2016-15037
2.4 LOW

A vulnerability, which was classified as problematic, has been found in go4rayyan Scumblr up to 2.0.1a. Affected by this issue is some unknown functionality of …

Jan 21, 2024
CVE-2024-23329
3.7 LOW

changedetection.io is an open source tool designed to monitor websites for content changes. In affected versions the API endpoint `/api/v1/watch/<uuid>/history` can be accessed by any …

Jan 19, 2024
CVE-2024-22211
3.7 LOW

FreeRDP is a set of free and open source remote desktop protocol library and clients. In affected versions an integer overflow in `freerdp_bitmap_planar_context_reset` leads to …

Jan 19, 2024
CVE-2023-5081
3.3 LOW

An information disclosure vulnerability was reported in the Lenovo Tab M8 HD that could allow a local application to gather a non-resettable device identifier.

Jan 19, 2024
CVE-2024-0722
3.5 LOW

A vulnerability was found in code-projects Social Networking Site 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file …

Jan 19, 2024
CVE-2024-0721
3.5 LOW

A vulnerability has been found in Jspxcms 10.2.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Survey Label …

Jan 19, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.