CVE Database

54652+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-42823
5.5 MEDIUM

The issue was resolved by sanitizing logging This issue is fixed in watchOS 10.1, macOS Sonoma 14.1, tvOS 17.1, macOS Monterey 12.7.1, iOS 16.7.2 and …

Feb 21, 2024
CVE-2024-22235
6.7 MEDIUM

VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'.

Feb 21, 2024
CVE-2024-25151
5.4 MEDIUM

The Calendar module in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack …

Feb 21, 2024
CVE-2024-1676
5.4 MEDIUM

Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security …

Feb 21, 2024
CVE-2024-1672
5.4 MEDIUM

Inappropriate implementation in Content Security Policy in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass content security policy via a crafted HTML …

Feb 21, 2024
CVE-2024-1671
6.5 MEDIUM

Inappropriate implementation in Site Isolation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass content security policy via a crafted HTML page. …

Feb 21, 2024
CVE-2024-1562
5.3 MEDIUM

The WooCommerce Google Sheet Connector plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the execute_post_data function …

Feb 21, 2024
CVE-2024-1501
4.7 MEDIUM

The Database Reset plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.22. This is due to missing …

Feb 21, 2024
CVE-2024-1108
6.5 MEDIUM

The Plugin Groups plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the admin_init() function in all …

Feb 21, 2024
CVE-2024-0407
6.5 MEDIUM

Certain HP Enterprise LaserJet, and HP LaserJet Managed Printers are potentially vulnerable to information disclosure, when connections made by the device back to services enabled …

Feb 21, 2024
CVE-2023-50923
4.3 MEDIUM

In QUIC in RFC 9000, the Latency Spin Bit specification (section 17.4) does not strictly constrain the bit value when the feature is disabled, which …

Feb 21, 2024
CVE-2024-26140
4.6 MEDIUM

com.yetanalytics/lrs is the Yet Analytics Core LRS Library. Prior to version 1.2.17 of the LRS library and version 0.7.5 of SQL LRS, a maliciously crafted …

Feb 20, 2024
CVE-2024-25428
6.5 MEDIUM

SQL Injection vulnerability in MRCMS v3.1.2 allows attackers to run arbitrary system commands via the status parameter.

Feb 20, 2024
CVE-2023-6936
5.3 MEDIUM

In wolfSSL prior to 5.6.6, if callback functions are enabled (via the WOLFSSL_CALLBACKS flag), then a malicious TLS client or network attacker can trigger a …

Feb 20, 2024
CVE-2021-29038
6.3 MEDIUM

Liferay Portal 7.2.0 through 7.3.5, and older unsupported versions, and Liferay DXP 7.3 before fix pack 1, 7.2 before fix pack 17, and older unsupported …

Feb 20, 2024
CVE-2023-49034
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in ProjeQtOr 11.0.2 allows a remote attacker to execute arbitrary code via a crafted script to thecheckvalidHtmlText function in the …

Feb 20, 2024
CVE-2023-46967
6.1 MEDIUM

Cross Site Scripting vulnerability in the sanitize function in Enhancesoft osTicket 1.18.0 allows a remote attacker to escalate privileges via a crafted support ticket.

Feb 20, 2024
CVE-2023-52435
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: prevent mss overflow in skb_segment() Once again syzbot is able to crash the kernel …

Feb 20, 2024
CVE-2024-25631
6.1 MEDIUM

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who have enabled an external kvstore and Wireguard transparent encryption, …

Feb 20, 2024
CVE-2024-25630
6.1 MEDIUM

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who are using CRDs to store Cilium state (the default …

Feb 20, 2024
CVE-2024-25260
4.0 MEDIUM

elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.

Feb 20, 2024
CVE-2024-24763
4.3 MEDIUM

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to version 3.10.0, attackers can exploit this vulnerability to …

Feb 20, 2024
CVE-2023-51447
6.3 MEDIUM

Decidim is a participatory democracy framework. Starting in version 0.27.0 and prior to versions 0.27.5 and 0.28.0, the dynamic file upload feature is subject to …

Feb 20, 2024
CVE-2023-48220
5.7 MEDIUM

Decidim is a participatory democracy framework. Starting in version 0.4.rc3 and prior to version 2.0.9 of the `devise_invitable` gem, the invites feature allows users to …

Feb 20, 2024
CVE-2023-47635
4.5 MEDIUM

Decidim is a participatory democracy framework. Starting in version 0.23.0 and prior to versions 0.27.5 and 0.28.0, the CSRF authenticity token check is disabled for …

Feb 20, 2024
CVE-2024-25366
6.2 MEDIUM

Buffer Overflow vulnerability in mz-automation.de libiec61859 v.1.4.0 allows a remote attacker to cause a denial of service via the mmsServer_handleGetNameListRequest function to the mms_getnamelist_service component.

Feb 20, 2024
CVE-2023-39541
5.9 MEDIUM

A denial of service vulnerability exists in the ICMP and ICMPv6 parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted network packet can lead …

Feb 20, 2024
CVE-2023-39540
5.9 MEDIUM

A denial of service vulnerability exists in the ICMP and ICMPv6 parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted network packet can lead …

Feb 20, 2024
CVE-2024-26270
6.5 MEDIUM

The Account Settings page in Liferay Portal 7.4.3.76 through 7.4.3.99, and Liferay DXP 2023.Q3 before patch 5, and 7.4 update 76 through 92 embeds the …

Feb 20, 2024
CVE-2024-26268
5.3 MEDIUM

User enumeration vulnerability in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Liferay DXP 7.4 before update 27, 7.3 before update 8, 7.2 …

Feb 20, 2024
CVE-2024-25197
6.5 MEDIUM

Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions were discovered to contain a NULL pointer dereference via the isCurrent() function at /src/layered_costmap.cpp.

Feb 20, 2024
CVE-2024-1556
6.5 MEDIUM

The incorrect object was checked for NULL in the built-in profiler, potentially leading to invalid memory access and undefined behavior. *Note:* This issue only affects …

Feb 20, 2024
CVE-2024-1551
6.1 MEDIUM

Set-Cookie response headers were being incorrectly honored in multipart HTTP responses. If an attacker could control the Content-Type response header, as well as control part …

Feb 20, 2024
CVE-2024-1550
6.1 MEDIUM

A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedly, which could …

Feb 20, 2024
CVE-2024-1549
6.1 MEDIUM

If a website set a large custom cursor, portions of the cursor could have overlapped with the permission dialog, potentially resulting in user confusion and …

Feb 20, 2024
CVE-2024-1548
4.3 MEDIUM

A website could have obscured the fullscreen notification by using a dropdown select input element. This could have led to user confusion and possible spoofing …

Feb 20, 2024
CVE-2024-1547
6.5 MEDIUM

Through a series of API calls and redirects, an attacker-controlled alert dialog could have been displayed on another website (with the victim website's URL shown). …

Feb 20, 2024
CVE-2023-50306
4.0 MEDIUM

IBM Common Licensing 9.0 could allow a local user to enumerate usernames due to an observable response discrepancy. IBM X-Force ID: 273337.

Feb 20, 2024
CVE-2024-26267
5.3 MEDIUM

In Liferay Portal 7.2.0 through 7.4.3.25, and older unsupported versions, and Liferay DXP 7.4 before update 26, 7.3 before update 5, 7.2 before fix pack …

Feb 20, 2024
CVE-2024-26265
5.0 MEDIUM

The Image Uploader module in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions, and Liferay DXP 7.4 before update 16, 7.3 before update 4, …

Feb 20, 2024
CVE-2023-52433
4.4 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_rbtree: skip sync GC for new elements in this transaction New elements in this …

Feb 20, 2024
CVE-2024-25609
6.1 MEDIUM

HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.12, and older unsupported versions, and Liferay DXP 7.4 before update 9, 7.3 service pack 3, 7.2 fix pack …

Feb 20, 2024
CVE-2024-25608
6.1 MEDIUM

HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.18, and older unsupported versions, and Liferay DXP 7.4 before update 19, 7.3 before update 4, 7.2 before fix …

Feb 20, 2024
CVE-2023-50270
6.5 MEDIUM

Session Fixation Apache DolphinScheduler before version 3.2.0, which session is still valid after the password change. Users are recommended to upgrade to version 3.2.1, which …

Feb 20, 2024
CVE-2024-25605
5.3 MEDIUM

The Journal module in Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before service pack 3, 7.2 before fix …

Feb 20, 2024
CVE-2024-25604
6.5 MEDIUM

Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before service pack 3, 7.2 before fix pack 17, and older …

Feb 20, 2024
CVE-2024-25974
5.4 MEDIUM

The Frentix GmbH OpenOlat LMS is affected by stored a Cross-Site Scripting (XSS) vulnerability. It is possible to upload files within the Media Center of …

Feb 20, 2024
CVE-2024-25973
5.4 MEDIUM

The Frentix GmbH OpenOlat LMS is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities. An attacker with rights to create or edit groups can create …

Feb 20, 2024
CVE-2024-25150
4.3 MEDIUM

Information disclosure vulnerability in the Control Panel in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before update 4, 7.2 …

Feb 20, 2024
CVE-2024-25149
5.4 MEDIUM

Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported …

Feb 20, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.