5.4 CVE-2023-23864
Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Michael Aronoff Very Simple Google...

2023-03-27 15:31:00

5.4 CVE-2023-23650
Auth. (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in MainWP MainWP Code Snippets Extension...

2023-03-27 15:30:00

4.8 CVE-2023-22716
Auth. (admin+) Cross-Site Scripting vulnerability in OOPSpam OOPSpam Anti-Spam plugin <= 1.1.35 versions....

2023-03-27 15:29:00

4.8 CVE-2023-22715
Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Lester 'GaMerZ' Chan WP-CommentNavi plugin...

2023-03-27 15:27:00

4.3 CVE-2023-28708
When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the...

2023-03-27 15:26:00

5.4 CVE-2023-22712
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in TemplatesNext TemplatesNext...

2023-03-27 15:26:00

9.8 CVE-2022-28492
TOTOLINK Technology CPE with firmware V6.3c.566 ,allows remote attackers to bypass Login.

2023-03-27 15:25:00

4.8 CVE-2023-28422
Auth. (admin+) Stored Cross-site Scripting (XSS) vulnerability in MagePeople Team Event Manager and...

2023-03-27 15:24:00

7.8 CVE-2022-48422
ONLYOFFICE Docs through 7.3 on certain Linux distributions allows local users to gain privileges via...

2023-03-27 15:23:00

6.1 CVE-2023-22704
Reflected Cross-Site Scripting (XSS) vulnerability in Michael Winkler teachPress plugin <= 8.1.8...

2023-03-27 15:22:00

3.8 CVE-2023-1541
Business Logic Errors in GitHub repository answerdev/answer prior to 1.0.6.

2023-03-27 15:21:00

5.3 CVE-2023-1539
Guessable CAPTCHA in GitHub repository answerdev/answer prior to 1.0.6.

2023-03-27 15:14:00

What is the Sherlock® KB project?

First of all KB for "Knowledge Base". The company ProHacktive is making its database of known vulnerabilities to date available for free. This database combines Nist's CVE database (https://nvd.nist.gov/), the CWE database (https://cwe.mitre.org/) and the CAPEC database (https://capec.mitre.org/).

For what purpose?

ProHacktive's promise is the democratization of the Cybersecurity Audit. For this, it seemed relevant to us to offer our "Knowledge Base" in different languages. Associated with this multilingual database, a clear and concise interface allows you to consult all the CVE ("Common Vulnerabilities and Exposures") present on your network. The Sherlock® service database is updated every hour from the various sources enriching our Sherlock® KB and immediately tested on the devices concerned by the new vulnerability.

Search for vulnerabilities

We also offer a simple search module in the description of each CVE. For the more curious, an advanced search allows you to point precisely to an application, an OS or a hardware. This advanced search is based on the mechanics used in our solution Sherlock®: the permanent Cybersecurity audit accessible financially and technically to all.

Developments?

We will add new languages regularly. A monitoring module will be implemented: you will be able to monitor an application, an OS or a hardware to be alerted of new vulnerabilities concerning it. Subscribe to our mailing list to be alerted when this feature is released (available on search results).