CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-52656
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: io_uring: drop any code related to SCM_RIGHTS This is dead code after we dropped support …

May 14, 2024
CVE-2023-52655
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: aqc111: check packet for fixup for true limit If a device sends a packet …

May 14, 2024
CVE-2023-52654
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: io_uring/af_unix: disable sending io_uring over sockets File reference cycles have caused lots of problems for …

May 14, 2024
CVE-2023-52384
4.7 MEDIUM

Double-free vulnerability in the RSMC module Impact: Successful exploitation of this vulnerability will affect availability.

May 14, 2024
CVE-2023-52383
4.7 MEDIUM

Double-free vulnerability in the RSMC module Impact: Successful exploitation of this vulnerability will affect availability.

May 14, 2024
CVE-2023-50718
6.5 MEDIUM

NocoDB is software for building databases as spreadsheets. Prior to version 0.202.10, an authenticated attacker with create access could conduct a SQL Injection attack on …

May 14, 2024
CVE-2023-50717
5.7 MEDIUM

NocoDB is software for building databases as spreadsheets. Starting in verson 0.202.6 and prior to version 0.202.10, an attacker can upload a html file with …

May 14, 2024
CVE-2023-43040
6.5 MEDIUM

IBM Spectrum Fusion HCI 2.5.2 through 2.7.2 could allow an attacker to perform unauthorized actions in RGW for Ceph due to improper bucket access. IBM …

May 14, 2024
CVE-2023-42955
4.9 MEDIUM

Claris International has successfully resolved an issue of potentially exposing password information to front-end websites when signed in to the Admin Console with an administrator …

May 14, 2024
CVE-2023-38264
5.9 MEDIUM

The IBM SDK, Java Technology Edition's Object Request Broker (ORB) 7.1.0.0 through 7.1.5.21 and 8.0.0.0 through 8.0.8.21 is vulnerable to a denial of service attack …

May 14, 2024
CVE-2023-37526
6.5 MEDIUM

HCL DRYiCE Lucy (now AEX) is affected by a Cross Origin Resource Sharing (CORS) vulnerability. The mobile app is vulnerable to a CORS misconfiguration which …

May 14, 2024
CVE-2023-29881
6.5 MEDIUM

phpok 6.4.003 is vulnerable to SQL injection in the function index_f() in phpok64/framework/api/call_control.php.

May 14, 2024
CVE-2022-32506
6.4 MEDIUM

An issue was discovered on certain Nuki Home Solutions devices. An attacker with physical access to the circuit board could use the SWD debug features …

May 14, 2024
CVE-2022-32502
6.3 MEDIUM

An issue was discovered on certain Nuki Home Solutions devices. There is a buffer overflow over the encrypted token parsing logic in the HTTP service …

May 14, 2024
CVE-2024-33382
5.3 MEDIUM

An issue in Open5GS v.2.7.0 allows an attacker to cause a denial of service via the 64 unsuccessful UE/gnb registration

May 8, 2024
CVE-2024-25528
5.9 MEDIUM

RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /PersonalAffair/worklog_template_show.aspx.

May 8, 2024
CVE-2024-24908
6.5 MEDIUM

Dell PowerProtect DM5500 version 5.15.0.0 and prior contain an Arbitrary File Delete via Path Traversal vulnerability. A remote attacker with high privileges could potentially exploit …

May 8, 2024
CVE-2024-24788
5.9 MEDIUM

A malformed DNS message in response to a query can cause the Lookup functions to get stuck in an infinite loop.

May 8, 2024
CVE-2024-24787
6.4 MEDIUM

On Darwin, building a Go module which contains CGO can trigger arbitrary code execution when using the Apple version of ld, due to usage of …

May 8, 2024
CVE-2024-4654
6.3 MEDIUM

A vulnerability was found in BlueNet Technology Clinical Browsing System 1.2.1. It has been classified as critical. This affects an unknown part of the file …

May 8, 2024
CVE-2024-4653
6.3 MEDIUM

A vulnerability was found in BlueNet Technology Clinical Browsing System 1.2.1 and classified as critical. Affected by this issue is some unknown functionality of the …

May 8, 2024
CVE-2024-33612
6.8 MEDIUM

An improper certificate validation vulnerability exists in BIG-IP Next Central Manager and may allow an attacker to impersonate an Instance Provider system. Note: Software versions …

May 8, 2024
CVE-2024-33604
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability exist in undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context …

May 8, 2024
CVE-2024-32761
6.5 MEDIUM

Under certain conditions, a data leak may occur in the Traffic Management Microkernels (TMMs) of BIG-IP tenants running on VELOS and rSeries platforms. This leak …

May 8, 2024
CVE-2024-28889
5.9 MEDIUM

When an SSL profile with alert timeout is configured with a non-default value on a virtual server, undisclosed traffic along with conditions beyond the attacker's …

May 8, 2024
CVE-2024-28132
4.4 MEDIUM

Exposure of Sensitive Information vulnerability exists in the GSLB container, which may allow an authenticated attacker with local access to view sensitive information. Note: Software …

May 8, 2024
CVE-2024-27202
4.7 MEDIUM

A DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the …

May 8, 2024
CVE-2024-4233
4.3 MEDIUM

Missing Authorization vulnerability in Tyche Softwares Print Invoice & Delivery Notes for WooCommerce, Tyche Softwares Arconix Shortcodes, Tyche Softwares Arconix FAQ.This issue affects Print Invoice …

May 8, 2024
CVE-2024-33574
4.3 MEDIUM

Missing Authorization vulnerability in appsbd Vitepos.This issue affects Vitepos: from n/a through 3.0.1.

May 8, 2024
CVE-2024-33573
4.3 MEDIUM

Missing Authorization vulnerability in EPROLO EPROLO Dropshipping.This issue affects EPROLO Dropshipping: from n/a through 1.7.1.

May 8, 2024
CVE-2024-32886
4.9 MEDIUM

Vitess is a database clustering system for horizontal scaling of MySQL. When executing the following simple query, the `vtgate` will go into an endless loop …

May 8, 2024
CVE-2024-30459
5.3 MEDIUM

Missing Authorization vulnerability in AIpost AI WP Writer.This issue affects AI WP Writer: from n/a through 3.6.5.

May 8, 2024
CVE-2024-24833
4.3 MEDIUM

Missing Authorization vulnerability in HappyMonster Happy Addons for Elementor happy-elementor-addons.This issue affects Happy Addons for Elementor: from n/a through <= 3.10.1.

May 8, 2024
CVE-2024-34255
6.1 MEDIUM

jizhicms v2.5.1 contains a Cross-Site Scripting(XSS) vulnerability in the message function.

May 8, 2024
CVE-2024-34561
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Creative interactive media 3D FlipBook, PDF Viewer, PDF Embedder – Real 3D FlipBook …

May 8, 2024
CVE-2024-34560
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GOMO gee Search Plus allows Stored XSS.This issue affects gee Search Plus: from …

May 8, 2024
CVE-2024-34558
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realmag777 WOLF allows Stored XSS.This issue affects WOLF: from n/a through 1.0.8.2.

May 8, 2024
CVE-2024-34548
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themesgrove WidgetKit allows Stored XSS.This issue affects WidgetKit: from n/a through 2.4.8.

May 8, 2024
CVE-2024-34547
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor alam Magical Addons For Elementor allows Stored XSS.This issue affects Magical Addons …

May 8, 2024
CVE-2024-34546
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Habibur Rahman Sticky Social Link sticky-social-link allows DOM-Based XSS.This issue affects Sticky Social …

May 8, 2024
CVE-2024-34414
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nobita allows Stored XSS.This issue affects raindrops: from n/a through 1.600.

May 8, 2024
CVE-2022-40218
6.5 MEDIUM

Missing Authorization vulnerability in ThemeHunk Advance WordPress Search Plugin.This issue affects Advance WordPress Search Plugin: from n/a through 1.1.4.

May 8, 2024
CVE-2024-34570
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xpro Xpro Elementor Addons allows Stored XSS.This issue affects Xpro Elementor Addons: from …

May 8, 2024
CVE-2024-34569
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Katie Zotpress zotpress.This issue affects Zotpress: from n/a through <= 7.3.9.

May 8, 2024
CVE-2024-34568
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeqx LetterPress allows Stored XSS.This issue affects LetterPress: from n/a through 1.2.1.

May 8, 2024
CVE-2024-34566
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Johan van der Wijk Content Blocks (Custom Post Widget) allows Stored XSS.This issue …

May 8, 2024
CVE-2024-34565
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Debug Info allows Stored XSS.This issue affects Debug Info: from n/a through 1.3.10.

May 8, 2024
CVE-2024-34564
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LogicHunt Inc. Counter Up allows Stored XSS.This issue affects Counter Up: from n/a …

May 8, 2024
CVE-2024-34563
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GoldAddons Gold Addons for Elementor allows Stored XSS.This issue affects Gold Addons for …

May 8, 2024
CVE-2024-34562
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Moveaddons Move Addons for Elementor allows Stored XSS.This issue affects Move Addons for …

May 8, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.