CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-39307
8.5 HIGH

Unrestricted Upload of File with Dangerous Type vulnerability in ThemeFusion Avada.This issue affects Avada: from n/a through 7.11.1.

Mar 26, 2024
CVE-2023-38388
9.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Artbees JupiterX Core.This issue affects JupiterX Core: from n/a through 3.3.5.

Mar 26, 2024
CVE-2023-29386
9.1 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Julien Crego Manager for Icomoon.This issue affects Manager for Icomoon: from n/a through 2.0.

Mar 26, 2024
CVE-2023-28787
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: …

Mar 26, 2024
CVE-2023-28687
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in perfectwpthemes Glaze Blog Lite, themebeez Fascinate, themebeez Cream Blog, themebeez Cream Magazine allows …

Mar 26, 2024
CVE-2024-2955
7.8 HIGH

T.38 dissector crash in Wireshark 4.2.0 to 4.0.3 and 4.0.0 to 4.0.13 allows denial of service via packet injection or crafted capture file

Mar 26, 2024
CVE-2024-2902
8.8 HIGH

A vulnerability was found in Tenda AC7 15.03.06.44 and classified as critical. This issue affects the function fromSetWifiGusetBasic of the file /goform/WifiGuestSet. The manipulation of …

Mar 26, 2024
CVE-2024-2901
8.8 HIGH

A vulnerability has been found in Tenda AC7 15.03.06.44 and classified as critical. This vulnerability affects the function setSchedWifi of the file /goform/openSchedWifi. The manipulation …

Mar 26, 2024
CVE-2024-2900
8.8 HIGH

A vulnerability, which was classified as critical, was found in Tenda AC7 15.03.06.44. This affects the function saveParentControlInfo of the file /goform/saveParentControlInfo. The manipulation of …

Mar 26, 2024
CVE-2024-28442
7.5 HIGH

Directory Traversal vulnerability in Yealink VP59 v.91.15.0.118 allows a physically proximate attacker to obtain sensitive information via terms of use function in the company portal …

Mar 26, 2024
CVE-2023-6091
7.2 HIGH

Unrestricted Upload of File with Dangerous Type vulnerability in mndpsingh287 Theme Editor.This issue affects Theme Editor: from n/a through 2.7.1.

Mar 26, 2024
CVE-2023-27630
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in PeepSo Community by PeepSo.This issue affects Community by PeepSo: from n/a through 6.0.9.0.

Mar 26, 2024
CVE-2023-27459
7.4 HIGH

Deserialization of Untrusted Data vulnerability in WPEverest User Registration.This issue affects User Registration: from n/a through 2.3.2.1.

Mar 26, 2024
CVE-2023-27440
7.2 HIGH

Unrestricted Upload of File with Dangerous Type vulnerability in OnTheGoSystems Types.This issue affects Types: from n/a through 3.4.17.

Mar 26, 2024
CVE-2023-25965
5.9 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in mbbhatti Upload Resume.This issue affects Upload Resume: from n/a through 1.2.0.

Mar 26, 2024
CVE-2023-23656
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in MainWP MainWP File Uploader Extension.This issue affects MainWP File Uploader Extension: from n/a through 4.1.

Mar 26, 2024
CVE-2024-2899
8.8 HIGH

A vulnerability, which was classified as critical, has been found in Tenda AC7 15.03.06.44. Affected by this issue is the function fromSetWirelessRepeat of the file …

Mar 26, 2024
CVE-2024-2898
8.8 HIGH

A vulnerability classified as critical was found in Tenda AC7 15.03.06.44. Affected by this vulnerability is the function fromSetRouteStatic of the file /goform/SetStaticRouteCfg. The manipulation …

Mar 26, 2024
CVE-2024-2897
6.3 MEDIUM

A vulnerability classified as critical has been found in Tenda AC7 15.03.06.44. Affected is the function formWriteFacMac of the file /goform/WriteFacMac. The manipulation of the …

Mar 26, 2024
CVE-2024-22436
6.5 MEDIUM

A security vulnerability in HPE IceWall Agent products could be exploited remotely to cause a denial of service.

Mar 26, 2024
CVE-2024-2951
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Metagauss RegistrationMagic.This issue affects RegistrationMagic: from n/a through 5.3.0.0.

Mar 26, 2024
CVE-2024-2896
8.8 HIGH

A vulnerability was found in Tenda AC7 15.03.06.44. It has been rated as critical. This issue affects the function formWifiWpsStart of the file /goform/WifiWpsStart. The …

Mar 26, 2024
CVE-2024-2895
8.8 HIGH

A vulnerability was found in Tenda AC7 15.03.06.44. It has been declared as critical. This vulnerability affects the function formWifiWpsOOB of the file /goform/WifiWpsOOB. The …

Mar 26, 2024
CVE-2024-26650

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Mar 26, 2024
CVE-2024-26649
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix the null pointer when load rlc firmware If the RLC firmware is invalid …

Mar 26, 2024
CVE-2024-26648
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix variable deferencing before NULL check in edp_setup_replay() In edp_setup_replay(), 'struct dc *dc' & …

Mar 26, 2024
CVE-2024-26647
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix late derefrence 'dsc' check in 'link_set_dsc_pps_packet()' In link_set_dsc_pps_packet(), 'struct display_stream_compressor *dsc' was dereferenced …

Mar 26, 2024
CVE-2024-26646
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: thermal: intel: hfi: Add syscore callbacks for system-wide PM The kernel allocates a memory buffer …

Mar 26, 2024
CVE-2024-1313
6.5 MEDIUM

It is possible for a user in a different organization from the owner of a snapshot to bypass authorization and delete a snapshot by issuing …

Mar 26, 2024
CVE-2023-52627
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iio: adc: ad7091r: Allow users to configure device events AD7091R-5 devices are supported by the …

Mar 26, 2024
CVE-2023-52626
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix operation precedence bug in port timestamping napi_poll context Indirection (*) is of lower …

Mar 26, 2024
CVE-2023-52625
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Refactor DMCUB enter/exit idle interface [Why] We can hang in place trying to send …

Mar 26, 2024
CVE-2023-52624
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Wake DMCUB before executing GPINT commands [Why] DMCUB can be in idle when we …

Mar 26, 2024
CVE-2023-52623
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Fix a suspicious RCU usage warning I received the following warning while running cthon …

Mar 26, 2024
CVE-2023-52622
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ext4: avoid online resizing failures due to oversized flex bg When we online resize an …

Mar 26, 2024
CVE-2023-52621
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: bpf: Check rcu_read_lock_trace_held() before calling bpf map helpers These three bpf_map_{lookup,update,delete}_elem() helpers are also available …

Mar 26, 2024
CVE-2023-44989
7.5 HIGH

Insertion of Sensitive Information into Log File vulnerability in GSheetConnector CF7 Google Sheets Connector.This issue affects CF7 Google Sheets Connector: from n/a through 5.0.5.

Mar 26, 2024
CVE-2024-2894
8.8 HIGH

A vulnerability was found in Tenda AC7 15.03.06.44. It has been classified as critical. This affects the function formSetQosBand of the file /goform/SetNetControlList. The manipulation …

Mar 26, 2024
CVE-2024-2893
8.8 HIGH

A vulnerability was found in Tenda AC7 15.03.06.44 and classified as critical. Affected by this issue is the function formSetDeviceName of the file /goform/SetOnlineDevName. The …

Mar 26, 2024
CVE-2024-29735
5.3 MEDIUM

Improper Preservation of Permissions vulnerability in Apache Airflow.This issue affects Apache Airflow from 2.8.2 through 2.8.3. Airflow's local file task handler in Airflow incorrectly set …

Mar 26, 2024
CVE-2024-2929
7.8 HIGH

A memory corruption vulnerability in Rockwell Automation Arena Simulation software could potentially allow a malicious user to insert unauthorized code to the software by corrupting …

Mar 26, 2024
CVE-2024-2921
9.8 CRITICAL

Improper access control in PAM vault permissions in Devolutions Server 2024.1.10.0 and earlier allows an authenticated user with access to the PAM to access unauthorized …

Mar 26, 2024
CVE-2024-2915
8.8 HIGH

Improper access control in PAM JIT elevation in Devolutions Server 2024.1.6 and earlier allows an attacker with access to the PAM JIT elevation feature to …

Mar 26, 2024
CVE-2024-2892
8.8 HIGH

A vulnerability has been found in Tenda AC7 15.03.06.44 and classified as critical. Affected by this vulnerability is the function formSetCfm of the file /goform/setcfm. …

Mar 26, 2024
CVE-2024-2452
7.0 HIGH

In Eclipse ThreadX NetX Duo before 6.4.0, if an attacker can control parameters of __portable_aligned_alloc() could cause an integer wrap-around and an allocation smaller than …

Mar 26, 2024
CVE-2024-2214
7.0 HIGH

In Eclipse ThreadX before version 6.4.0, the _Mtxinit() function in the Xtensa port was missing an array size check causing a memory overwrite. The affected …

Mar 26, 2024
CVE-2024-2212
7.3 HIGH

In Eclipse ThreadX before 6.4.0, xQueueCreate() and xQueueCreateSet() functions from the FreeRTOS compatibility API (utility/rtos_compatibility_layers/FreeRTOS/tx_freertos.c) were missing parameter checks. This could lead to integer wraparound, …

Mar 26, 2024
CVE-2024-29833
5.4 MEDIUM

The image upload component allows SVG files and the regular expression used to remove script tags can be bypassed by using a Cross Site Scripting …

Mar 26, 2024
CVE-2024-29832
6.1 MEDIUM

The current_url parameter of the AJAX call to the GalleryBox action of admin-ajax.php is vulnerable to reflected Cross Site Scripting. The value of the current_url …

Mar 26, 2024
CVE-2024-29810
5.4 MEDIUM

The thumb_url parameter of the AJAX call to the editimage_bwg action of admin-ajax.php is vulnerable to reflected Cross Site Scripting. The value of the thumb_url …

Mar 26, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.