CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-22288
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels allows Reflected …

Mar 27, 2024
CVE-2024-22149
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Oliver Seidel, Bastian Germann CformsII allows Stored XSS.This issue affects CformsII: from n/a …

Mar 27, 2024
CVE-2023-52228
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mark Kinchin Beds24 Online Booking allows Stored XSS.This issue affects Beds24 Online Booking: …

Mar 27, 2024
CVE-2023-49815
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in WappPress Team WappPress.This issue affects WappPress: from n/a through 5.0.3.

Mar 27, 2024
CVE-2023-46052
7.1 HIGH

Sane 1.2.1 heap bounds overwrite in init_options() from backend/test.c via a long init_mode string in a configuration file. NOTE: this is disputed because there is …

Mar 27, 2024
CVE-2023-46051
3.3 LOW

TeX Live 944e257 allows a NULL pointer dereference in texk/web2c/pdftexdir/tounicode.c. NOTE: this is disputed because it should be categorized as a usability problem.

Mar 27, 2024
CVE-2023-46049
5.3 MEDIUM

LLVM 15.0.0 has a NULL pointer dereference in the parseOneMetadata() function via a crafted pdflatex.fmt file (or perhaps a crafted .o file) to llvm-lto. NOTE: …

Mar 27, 2024
CVE-2023-39306
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeFusion Fusion Builder allows Reflected XSS.This issue affects Fusion Builder: from n/a through …

Mar 27, 2024
CVE-2023-31854

std::bad_alloc is mishandled in Precomp 0.4.8. NOTE: this is disputed because it should be categorized as a usability problem.

Mar 27, 2024
CVE-2023-31634
9.8 CRITICAL

In TeslaMate before 1.27.2, there is unauthorized access to port 4000 for remote viewing and operation of user data. After accessing the IP address for …

Mar 27, 2024
CVE-2023-29134
8.6 HIGH

An issue was discovered in the Cargo extension for MediaWiki through 1.39.3. There is mishandling of backticks to smartSplit.

Mar 27, 2024
CVE-2023-46048
6.2 MEDIUM

Tex Live 944e257 has a NULL pointer dereference in texk/web2c/pdftexdir/writet1.c. NOTE: this is disputed because it should be categorized as a usability problem.

Mar 27, 2024
CVE-2023-46047
7.3 HIGH

An issue in Sane 1.2.1 allows a local attacker to execute arbitrary code via a crafted file to the sanei_configure_attach() function. NOTE: this is disputed …

Mar 27, 2024
CVE-2023-46046
5.5 MEDIUM

An issue in MiniZinc before 2.8.0 allows a NULL pointer dereference via ti_expr in a crafted .mzn file. NOTE: this is disputed because there is …

Mar 27, 2024
CVE-2023-45935
4.2 MEDIUM

Qt 6 through 6.6 was discovered to contain a NULL pointer dereference via the function QXcbConnection::initializeAllAtoms(). NOTE: this is disputed because it is not expected …

Mar 27, 2024
CVE-2023-45925

GNU Midnight Commander 4.8.29-146-g299d9a2fb was discovered to contain a NULL pointer dereference via the function x_error_handler() at tty/x11conn.c. NOTE: this is disputed because it should …

Mar 27, 2024
CVE-2023-45924
9.8 CRITICAL

libglxproto.c in OpenGL libglvnd bb06db5a was discovered to contain a segmentation violation via the function glXGetDrawableScreen(). NOTE: this is disputed because there are no common …

Mar 27, 2024
CVE-2023-45922
4.3 MEDIUM

glx_pbuffer.c in Mesa 23.0.4 was discovered to contain a segmentation violation when calling __glXGetDrawableAttribute(). NOTE: this is disputed because there are no common situations in …

Mar 27, 2024
CVE-2023-45920
4.2 MEDIUM

Xfig v3.2.8 was discovered to contain a NULL pointer dereference when calling XGetWMHints(). NOTE: this is disputed because it is not expected that an X …

Mar 27, 2024
CVE-2023-45919
5.3 MEDIUM

Mesa 23.0.4 was discovered to contain a buffer over-read in glXQueryServerString(). NOTE: this is disputed because there are no common situations in which users require …

Mar 27, 2024
CVE-2023-45931
7.5 HIGH

Mesa 23.0.4 was discovered to contain a NULL pointer dereference in check_xshm() for the has_error state. NOTE: this is disputed because there is no scenario …

Mar 27, 2024
CVE-2023-45929
9.1 CRITICAL

S-Lang 2.3.2 was discovered to contain a segmentation fault via the function fixup_tgetstr().

Mar 27, 2024
CVE-2023-45927
9.1 CRITICAL

S-Lang 2.3.2 was discovered to contain an arithmetic exception via the function tt_sprintf().

Mar 27, 2024
CVE-2023-45913
6.2 MEDIUM

Mesa v23.0.4 was discovered to contain a NULL pointer dereference via the function dri2GetGlxDrawableFromXDrawableId(). This vulnerability is triggered when the X11 server sends an DRI2_BufferSwapComplete …

Mar 27, 2024
CVE-2023-40290
8.3 HIGH

An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue that affects Internet Explorer 11 on …

Mar 27, 2024
CVE-2023-40289
7.2 HIGH

A command injection issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker can exploit this to elevate privileges from a user …

Mar 27, 2024
CVE-2023-40288
8.3 HIGH

An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue.

Mar 27, 2024
CVE-2023-40287
8.3 HIGH

An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue.

Mar 27, 2024
CVE-2023-40286
8.3 HIGH

An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue.

Mar 27, 2024
CVE-2023-40285
6.5 MEDIUM

An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue.

Mar 27, 2024
CVE-2023-40284
8.3 HIGH

An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue.

Mar 27, 2024
CVE-2023-39804
6.2 MEDIUM

In GNU tar before 1.35, mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c.

Mar 27, 2024
CVE-2024-2945
6.3 MEDIUM

A vulnerability was found in Campcodes Online Examination System 1.0. It has been classified as critical. Affected is an unknown function of the file /adminpanel/admin/facebox_modal/updateExaminee.php. …

Mar 27, 2024
CVE-2024-2944
6.3 MEDIUM

A vulnerability was found in Campcodes Online Examination System 1.0 and classified as critical. This issue affects some unknown processing of the file /adminpanel/admin/query/deleteCourseExe.php. The …

Mar 27, 2024
CVE-2024-2943
6.3 MEDIUM

A vulnerability has been found in Campcodes Online Examination System 1.0 and classified as critical. This vulnerability affects unknown code of the file /adminpanel/admin/query/deleteExamExe.php. The …

Mar 27, 2024
CVE-2024-2942
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Campcodes Online Examination System 1.0. This affects an unknown part of the file /adminpanel/admin/query/deleteQuestionExe.php. The …

Mar 27, 2024
CVE-2024-2941
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Campcodes Online Examination System 1.0. Affected by this issue is some unknown functionality of …

Mar 27, 2024
CVE-2024-2210
6.4 MEDIUM

The The Plus Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.4.1 via the …

Mar 27, 2024
CVE-2024-2203
6.4 MEDIUM

The The Plus Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.4.1 via the …

Mar 27, 2024
CVE-2024-2139
6.4 MEDIUM

The Master Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Pricing Table widget in all versions up to, and …

Mar 27, 2024
CVE-2024-2097
7.5 HIGH

An authenticated malicious client can send a special LINQ query to execute arbitrary code remotely (RCE) on the SCM server from List control, and execute …

Mar 27, 2024
CVE-2024-25736
7.5 HIGH

An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can restart the device via a /device/reboot GET request.

Mar 27, 2024
CVE-2024-25735
9.1 CRITICAL

An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can discover cleartext passwords via a SoftAP /device/config GET request.

Mar 27, 2024
CVE-2024-25734
7.5 HIGH

An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. The TELNET service prompts for a password only after a valid username is entered, …

Mar 27, 2024
CVE-2024-25580
6.2 MEDIUM

An issue was discovered in gui/util/qktxhandler.cpp in Qt before 5.15.17, 6.x before 6.2.12, 6.3.x through 6.5.x before 6.5.5, and 6.6.x before 6.6.2. A buffer overflow …

Mar 27, 2024
CVE-2024-25395
8.8 HIGH

A buffer overflow occurs in utilities/rt-link/src/rtlink.c in RT-Thread through 5.0.2.

Mar 27, 2024
CVE-2024-25394
4.3 MEDIUM

A buffer overflow occurs in utilities/ymodem/ry_sy.c in RT-Thread through 5.0.2 because of an incorrect sprintf call or a missing '\0' character.

Mar 27, 2024
CVE-2024-25393
9.8 CRITICAL

A stack buffer overflow occurs in net/at/src/at_server.c in RT-Thread through 5.0.2.

Mar 27, 2024
CVE-2024-25392
5.9 MEDIUM

An out-of-bounds access occurs in utilities/var_export/var_export.c in RT-Thread through 5.0.2.

Mar 27, 2024
CVE-2024-25391
8.4 HIGH

A stack buffer overflow occurs in libc/posix/ipc/mqueue.c in RT-Thread through 5.0.2.

Mar 27, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.