CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-3445
6.3 MEDIUM

A vulnerability was found in SourceCodester Laundry Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /karyawan/laporan_filter. …

Apr 8, 2024
CVE-2024-31447
5.3 MEDIUM

Shopware 6 is an open commerce platform based on Symfony Framework and Vue. Starting in version 6.3.5.0 and prior to versions 6.6.1.0 and 6.5.8.8, when …

Apr 8, 2024
CVE-2024-3444
4.7 MEDIUM

A vulnerability was found in Wangshen SecGate 3600 up to 20240408. It has been classified as critical. This affects an unknown part of the file …

Apr 8, 2024
CVE-2024-3442
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Prison Management System 1.0. This affects an unknown part of the file /Employee/delete_leave.php. The manipulation …

Apr 8, 2024
CVE-2024-31221
5.9 MEDIUM

Sunshine is a self-hosted game stream host for Moonlight. Starting in version 0.10.0 and prior to version 0.23.0, after unpairing all devices in the web …

Apr 8, 2024
CVE-2024-31205
4.2 MEDIUM

Saleor is an e-commerce platform. Starting in version 3.10.0 and prior to versions 3.14.64, 3.15.39, 3.16.39, 3.17.35, 3.18.31, and 3.19.19, an attacker may bypass cross-set …

Apr 8, 2024
CVE-2024-30269
5.3 MEDIUM

DataEase, an open source data visualization and analysis tool, has a database configuration information exposure vulnerability prior to version 2.5.0. Visiting the `/de2api/engine/getEngine;.js` path via …

Apr 8, 2024
CVE-2024-3441
6.3 MEDIUM

A vulnerability was found in SourceCodester Prison Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Apr 8, 2024
CVE-2024-3440
4.7 MEDIUM

A vulnerability was found in SourceCodester Prison Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Apr 8, 2024
CVE-2024-2511
5.9 MEDIUM

Issue summary: Some non-default TLS server configurations can cause unbounded memory growth when processing TLSv1.3 sessions Impact summary: An attacker may exploit certain server configurations …

Apr 8, 2024
CVE-2024-31812
6.5 MEDIUM

In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getWiFiExtenderConfig.

Apr 8, 2024
CVE-2024-31806
6.5 MEDIUM

TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a Denial-of-Service (DoS) vulnerability in the RebootSystem function which can reboot the system without authorization.

Apr 8, 2024
CVE-2024-31805
6.5 MEDIUM

TOTOLINK EX200 V4.0.3c.7646_B20201211 allows attackers to start the Telnet service without authorization via the telnet_enabled parameter in the setTelnetCfg function.

Apr 8, 2024
CVE-2024-26811
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate payload size in ipc response If installing malicious ksmbd-tools, ksmbd.mountd can return invalid …

Apr 8, 2024
CVE-2023-52385
6.2 MEDIUM

Out-of-bounds write vulnerability in the RSMC module. Impact: Successful exploitation of this vulnerability will affect availability.

Apr 8, 2024
CVE-2023-52364
6.3 MEDIUM

Vulnerability of input parameters being not strictly verified in the RSMC module. Impact: Successful exploitation of this vulnerability may cause out-of-bounds write.

Apr 8, 2024
CVE-2024-31375
5.4 MEDIUM

Missing Authorization vulnerability in Saleswonder Team: Tobias WP2LEADS wp2leads.This issue affects WP2LEADS: from n/a through <= 3.2.7.

Apr 8, 2024
CVE-2024-31357
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BdThemes Ultimate Store Kit Elementor Addons allows Stored XSS.This issue affects Ultimate Store …

Apr 8, 2024
CVE-2024-23192
6.1 MEDIUM

RSS feeds that contain malicious data- attributes could be abused to inject script code to a users browser session when reading compromised RSS feeds or …

Apr 8, 2024
CVE-2024-23191
5.4 MEDIUM

Upsell advertisement information of an account can be manipulated to execute script code in the context of the users browser session. To exploit this an …

Apr 8, 2024
CVE-2024-23190
5.4 MEDIUM

Upsell shop information of an account can be manipulated to execute script code in the context of the users browser session. To exploit this an …

Apr 8, 2024
CVE-2024-23189
5.4 MEDIUM

Embedded content references at tasks could be used to temporarily execute script code in the context of the users browser session. To exploit this an …

Apr 8, 2024
CVE-2023-52554
6.5 MEDIUM

Permission control vulnerability in the Bluetooth module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Apr 8, 2024
CVE-2023-52551
5.3 MEDIUM

Vulnerability of data verification errors in the kernel module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Apr 8, 2024
CVE-2023-52544
4.3 MEDIUM

Vulnerability of file path verification being bypassed in the email module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Apr 8, 2024
CVE-2023-52543
6.2 MEDIUM

Permission verification vulnerability in the system module. Impact: Successful exploitation of this vulnerability will affect availability.

Apr 8, 2024
CVE-2023-52542
6.5 MEDIUM

Permission verification vulnerability in the system module. Impact: Successful exploitation of this vulnerability will affect availability.

Apr 8, 2024
CVE-2024-1958
4.8 MEDIUM

The WPB Show Core WordPress plugin before 2.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Apr 8, 2024
CVE-2024-1956
6.1 MEDIUM

The wpb-show-core WordPress plugin before 2.7 does not sanitise and escape the parameters before outputting it back in the response of an unauthenticated request, leading …

Apr 8, 2024
CVE-2024-1752
6.1 MEDIUM

The Font Farsi WordPress plugin through 1.6.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Apr 8, 2024
CVE-2024-1589
6.1 MEDIUM

The SendPress Newsletters WordPress plugin through 1.23.11.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Apr 8, 2024
CVE-2024-1588
6.8 MEDIUM

The SendPress Newsletters WordPress plugin through 1.23.11.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Apr 8, 2024
CVE-2024-1292
4.7 MEDIUM

The WPB Show Core WordPress plugin before 2.7 does not sanitise and escape some parameters before outputting them back in the page, leading to a …

Apr 8, 2024
CVE-2024-23658
4.4 MEDIUM

In camera driver, there is a possible use after free due to a logic error. This could lead to local denial of service with System …

Apr 8, 2024
CVE-2023-52536
4.4 MEDIUM

In faceid service, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service …

Apr 8, 2024
CVE-2023-52535
4.4 MEDIUM

In vsp driver, there is a possible missing verification incorrect input. This could lead to local denial of service with no additional execution privileges needed

Apr 8, 2024
CVE-2023-52534
5.9 MEDIUM

In ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote denial of service with no additional execution …

Apr 8, 2024
CVE-2023-52533
5.3 MEDIUM

In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote information disclosure no additional execution privileges needed

Apr 8, 2024
CVE-2023-52352
5.5 MEDIUM

In Network Adapter Service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges needed

Apr 8, 2024
CVE-2023-52350
4.4 MEDIUM

In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Apr 8, 2024
CVE-2023-52349
4.4 MEDIUM

In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Apr 8, 2024
CVE-2023-52348
4.4 MEDIUM

In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Apr 8, 2024
CVE-2023-52347
5.5 MEDIUM

In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Apr 8, 2024
CVE-2023-52346
4.4 MEDIUM

In modem driver, there is a possible system crash due to improper input validation. This could lead to local information disclosure with System execution privileges …

Apr 8, 2024
CVE-2023-52345
6.0 MEDIUM

In modem driver, there is a possible system crash due to improper input validation. This could lead to local information disclosure with System execution privileges …

Apr 8, 2024
CVE-2023-52344
5.3 MEDIUM

In modem-ps-nas-ngmm, there is a possible undefined behavior due to incorrect error handling. This could lead to remote information disclosure no additional execution privileges needed

Apr 8, 2024
CVE-2023-52343
5.5 MEDIUM

In SecurityCommand message after as security has been actived., there is a possible improper input validation. This could lead to remote information disclosure no additional …

Apr 8, 2024
CVE-2024-3436
6.3 MEDIUM

A vulnerability was found in SourceCodester Prison Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /Admin/edit-photo.php …

Apr 8, 2024
CVE-2024-3434
5.4 MEDIUM

A vulnerability classified as critical was found in CP Plus Wi-Fi Camera up to 20240401. Affected by this vulnerability is an unknown functionality of the …

Apr 8, 2024
CVE-2021-47208
4.3 MEDIUM

The Mojolicious module before 9.11 for Perl has a bug in format detection that can potentially be exploited for denial of service.

Apr 8, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.