CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-42930
5.5 MEDIUM

This issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.6.3, macOS Sonoma 14.2, macOS Monterey 12.7.2. An app may be …

Mar 28, 2024
CVE-2023-42896
5.5 MEDIUM

An issue was addressed with improved handling of temporary files. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 and iPadOS …

Mar 28, 2024
CVE-2023-42893
5.5 MEDIUM

A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS …

Mar 28, 2024
CVE-2023-40390
5.5 MEDIUM

A privacy issue was addressed by moving sensitive data to a protected location. This issue is fixed in macOS Sonoma 14.2. An app may be …

Mar 28, 2024
CVE-2024-3042
6.3 MEDIUM

A vulnerability was found in SourceCodester Simple Subscription Website 1.0 and classified as critical. This issue affects some unknown processing of the file manage_user.php. The …

Mar 28, 2024
CVE-2024-3041
6.3 MEDIUM

A vulnerability has been found in Netentsec NS-ASG Application Security Gateway 6.3 and classified as critical. This vulnerability affects unknown code of the file /protocol/log/listloginfo.php. …

Mar 28, 2024
CVE-2024-3040
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Netentsec NS-ASG Application Security Gateway 6.3. This affects an unknown part of the file /admin/list_crl_conf. …

Mar 28, 2024
CVE-2024-3039
6.3 MEDIUM

A vulnerability classified as critical has been found in Shanghai Brad Technology BladeX 3.4.0. Affected is an unknown function of the file /api/blade-user/export-user of the …

Mar 28, 2024
CVE-2024-31140
4.1 MEDIUM

In JetBrains TeamCity before 2024.03 server administrators could remove arbitrary files from the server by installing tools

Mar 28, 2024
CVE-2024-31139
5.9 MEDIUM

In JetBrains TeamCity before 2024.03 xXE was possible in the Maven build steps detector

Mar 28, 2024
CVE-2024-31138
4.6 MEDIUM

In JetBrains TeamCity before 2024.03 xSS was possible via Agent Distribution settings

Mar 28, 2024
CVE-2024-31137
6.8 MEDIUM

In JetBrains TeamCity before 2024.03 reflected XSS was possible via Space connection configuration

Mar 28, 2024
CVE-2024-31135
6.1 MEDIUM

In JetBrains TeamCity before 2024.03 open redirect was possible on the login page

Mar 28, 2024
CVE-2024-31134
6.5 MEDIUM

In JetBrains TeamCity before 2024.03 authenticated users without administrative permissions could register other users when self-registration was disabled

Mar 28, 2024
CVE-2024-30603
6.5 MEDIUM

Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the urls parameter of the saveParentControlInfo function.

Mar 28, 2024
CVE-2024-30598
6.5 MEDIUM

Tenda FH1203 v2.0.1.6 firmware has a stack overflow vulnerability in the security_5g parameter of the formWifiBasicSet function.

Mar 28, 2024
CVE-2024-30597
6.5 MEDIUM

Tenda FH1203 v2.0.1.6 firmware has a stack overflow vulnerability in the security parameter of the formWifiBasicSet function.

Mar 28, 2024
CVE-2024-30590
6.5 MEDIUM

Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the schedEndTime parameter of the setSchedWifi function.

Mar 28, 2024
CVE-2024-30588
4.3 MEDIUM

Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the schedStartTime parameter of the setSchedWifi function.

Mar 28, 2024
CVE-2024-30586
6.5 MEDIUM

Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the security_5g parameter of the formWifiBasicSet function.

Mar 28, 2024
CVE-2024-30585
6.5 MEDIUM

Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceId parameter of the saveParentControlInfo function.

Mar 28, 2024
CVE-2024-29898
4.9 MEDIUM

CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. An oversight during the writing of the patch for CVE-2024-29897 may have exposed suppressed wiki …

Mar 28, 2024
CVE-2024-29897
4.9 MEDIUM

CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. It is possible for users with (delete) or (suppressrevision) on any wiki in the farm …

Mar 28, 2024
CVE-2024-29200
6.8 MEDIUM

Kimai is a web-based multi-user time-tracking application. The permission `view_other_timesheet` performs differently for the Kimai UI and the API, thus returning unexpected data through the …

Mar 28, 2024
CVE-2024-30594
6.5 MEDIUM

Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceMac parameter of the addWifiMacFilter function.

Mar 28, 2024
CVE-2024-30422
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPVibes Elementor Addon Elements addon-elements-for-elementor-page-builder.This issue affects Elementor Addon Elements: from n/a through …

Mar 28, 2024
CVE-2024-30421
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Pixelite Events Manager.This issue affects Events Manager: from n/a through 6.4.7.1.

Mar 28, 2024
CVE-2024-2818
4.3 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions before 16.8.5, all versions starting from 16.9 before 16.9.3, all versions starting from 16.10 …

Mar 28, 2024
CVE-2024-29240
4.3 MEDIUM

Missing authorization vulnerability in LayoutSave webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to conduct limited denial-of-service attacks via …

Mar 28, 2024
CVE-2024-29239
5.4 MEDIUM

Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Recording.CountByCategory webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 …

Mar 28, 2024
CVE-2024-29238
5.4 MEDIUM

Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Log.CountByCategory webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 …

Mar 28, 2024
CVE-2024-29237
5.4 MEDIUM

Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in ActionRule.Delete webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 …

Mar 28, 2024
CVE-2024-29236
5.4 MEDIUM

Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in AudioPattern.Delete webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 …

Mar 28, 2024
CVE-2024-29235
5.4 MEDIUM

Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in IOModule.EnumLog webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 …

Mar 28, 2024
CVE-2024-29234
5.4 MEDIUM

Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Group.Save webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 …

Mar 28, 2024
CVE-2024-29233
5.4 MEDIUM

Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Emap.Delete webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 …

Mar 28, 2024
CVE-2024-29232
5.4 MEDIUM

Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Alert.Enum webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 …

Mar 28, 2024
CVE-2024-29231
5.4 MEDIUM

Improper validation of array index vulnerability in UserPrivilege.Enum webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to obtain non-sensitive …

Mar 28, 2024
CVE-2024-29230
5.4 MEDIUM

Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in SnapShot.CountByCategory webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 …

Mar 28, 2024
CVE-2024-29227
5.4 MEDIUM

Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in Layout.LayoutSave webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 …

Mar 28, 2024
CVE-2024-25923
5.3 MEDIUM

Insertion of Sensitive Information into Log File vulnerability in PeepSo Community by PeepSo.This issue affects Community by PeepSo: from n/a through 6.2.7.0.

Mar 28, 2024
CVE-2024-22138
5.3 MEDIUM

Insertion of Sensitive Information into Log File vulnerability in Seraphinite Solutions Seraphinite Accelerator.This issue affects Seraphinite Accelerator: from n/a through 2.20.47.

Mar 28, 2024
CVE-2023-52234
6.5 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Booster Booster Elite for WooCommerce.This issue affects Booster Elite for WooCommerce: from n/a before 7.1.2.

Mar 28, 2024
CVE-2023-52231
6.5 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Booster Booster Plus for WooCommerce.This issue affects Booster Plus for WooCommerce: from n/a before 7.1.2.

Mar 28, 2024
CVE-2023-50374
5.5 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in NiteoThemes CMP – Coming Soon & Maintenance.This issue affects CMP – Coming Soon & Maintenance: from n/a through 4.1.10.

Mar 28, 2024
CVE-2022-45850
6.1 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Nickys Image Map Pro allows Stored XSS.This issue affects Image Map Pro: from n/a before 5.6.9.

Mar 28, 2024
CVE-2024-30221
5.4 MEDIUM

Deserialization of Untrusted Data vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart.This issue affects Sunshine Photo Cart: from n/a through <= 3.1.1.

Mar 28, 2024
CVE-2024-29090
6.8 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 2.1.4.

Mar 28, 2024
CVE-2024-28004
5.4 MEDIUM

Missing Authorization vulnerability in ExtendThemes Colibri Page Builder.This issue affects Colibri Page Builder: from n/a through 1.0.248.

Mar 28, 2024
CVE-2024-28003
5.4 MEDIUM

Missing Authorization vulnerability in Megamenu Max Mega Menu.This issue affects Max Mega Menu: from n/a through 3.3.

Mar 28, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.