CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-27303
7.3 HIGH

electron-builder is a solution to package and build a ready for distribution Electron, Proton Native app for macOS, Windows and Linux. A vulnerability that only …

Mar 6, 2024
CVE-2024-27302
9.1 CRITICAL

go-zero is a web and rpc framework. Go-zero allows user to specify a CORS Filter with a configurable allows param - which is an array …

Mar 6, 2024
CVE-2024-27289
8.1 HIGH

pgx is a PostgreSQL driver and toolkit for Go. Prior to version 4.18.2, SQL injection can occur when all of the following conditions are met: …

Mar 6, 2024
CVE-2024-27288
6.3 MEDIUM

1Panel is an open source Linux server operation and maintenance management panel. Prior to version 1.10.1-lts, users can use Burp to obtain unauthorized access to …

Mar 6, 2024
CVE-2024-27287
6.5 MEDIUM

ESPHome is a system to control your ESP8266/ESP32 for Home Automation systems. Starting in version 2023.12.9 and prior to version 2024.2.2, editing the configuration file …

Mar 6, 2024
CVE-2024-25111
8.6 HIGH

Squid is a web proxy cache. Starting in version 3.5.27 and prior to version 6.8, Squid may be vulnerable to a Denial of Service attack …

Mar 6, 2024
CVE-2024-24766
6.2 MEDIUM

CasaOS-UserService provides user management functionalities to CasaOS. Starting in version 0.4.4.3 and prior to version 0.4.7, the Casa OS Login page disclosed the username enumeration …

Mar 6, 2024
CVE-2024-24767
9.1 CRITICAL

CasaOS-UserService provides user management functionalities to CasaOS. Starting in version 0.4.4.3 and prior to version 0.4.7, CasaOS doesn't defend against password brute force attacks, which …

Mar 6, 2024
CVE-2024-24765
7.5 HIGH

CasaOS-UserService provides user management functionalities to CasaOS. Prior to version 0.4.7, path filtering of the URL for user avatar image files was not strict, making …

Mar 6, 2024
CVE-2024-24761
7.5 HIGH

Galette is a membership management web application for non profit organizations. Starting in version 1.0.0 and prior to version 1.0.2, public pages are per default …

Mar 6, 2024
CVE-2023-50716
9.6 CRITICAL

eProsima Fast DDS (formerly Fast RTPS) is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.13.0, …

Mar 6, 2024
CVE-2023-50167
5.4 MEDIUM

Pega Platform from 7.1.7 to 23.1.1 is affected by an XSS issue with editing/rendering user html content.

Mar 6, 2024
CVE-2024-2216
8.8 HIGH

A missing permission check in an HTTP endpoint in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified …

Mar 6, 2024
CVE-2024-2215
6.1 MEDIUM

A cross-site request forgery (CSRF) vulnerability in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers to connect to an attacker-specified TCP or Unix socket URL, …

Mar 6, 2024
CVE-2024-28174
5.8 MEDIUM

In JetBrains TeamCity before 2023.11.4 presigned URL generation requests in S3 Artifact Storage plugin were authorized improperly

Mar 6, 2024
CVE-2024-28173
4.3 MEDIUM

In JetBrains TeamCity between 2023.11 and 2023.11.4 custom build parameters of the "password" type could be disclosed

Mar 6, 2024
CVE-2024-28162
4.2 MEDIUM

In Jenkins Delphix Plugin 3.0.1 through 3.1.0 (both inclusive) a global option for administrators to enable or disable SSL/TLS certificate validation for Data Control Tower …

Mar 6, 2024
CVE-2024-28161
5.3 MEDIUM

In Jenkins Delphix Plugin 3.0.1, a global option for administrators to enable or disable SSL/TLS certificate validation for Data Control Tower (DCT) connections is disabled …

Mar 6, 2024
CVE-2024-28160
8.8 HIGH

Jenkins iceScrum Plugin 1.1.6 and earlier does not sanitize iceScrum project URLs on build views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by …

Mar 6, 2024
CVE-2024-28159
4.3 MEDIUM

A missing permission check in Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier allows attackers with Item/Read permission to trigger a build.

Mar 6, 2024
CVE-2024-28158
4.3 MEDIUM

A cross-site request forgery (CSRF) vulnerability in Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier allows attackers to trigger a build.

Mar 6, 2024
CVE-2024-28157
8.0 HIGH

Jenkins GitBucket Plugin 0.8 and earlier does not sanitize Gitbucket URLs on build views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers …

Mar 6, 2024
CVE-2024-28156
5.4 MEDIUM

Jenkins Build Monitor View Plugin 1.14-860.vd06ef2568b_3f and earlier does not escape Build Monitor View names, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by …

Mar 6, 2024
CVE-2024-28155
4.3 MEDIUM

Jenkins AppSpider Plugin 1.0.16 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to obtain information about available …

Mar 6, 2024
CVE-2024-28154
6.5 MEDIUM

Jenkins MQ Notifier Plugin 1.4.0 and earlier logs potentially sensitive build parameters as part of debug information in build logs by default.

Mar 6, 2024
CVE-2024-28153
5.4 MEDIUM

Jenkins OWASP Dependency-Check Plugin 5.4.5 and earlier does not escape vulnerability metadata from Dependency-Check reports, resulting in a stored cross-site scripting (XSS) vulnerability.

Mar 6, 2024
CVE-2024-28152
6.3 MEDIUM

In Jenkins Bitbucket Branch Source Plugin 866.vdea_7dcd3008e and earlier, except 848.850.v6a_a_2a_234a_c81, when discovering pull requests from forks, the trust policy "Forks in the same account" …

Mar 6, 2024
CVE-2024-28151
4.3 MEDIUM

Jenkins HTML Publisher Plugin 1.32 and earlier archives invalid symbolic links in report directories on agents and recreates them on the controller, allowing attackers with …

Mar 6, 2024
CVE-2024-28150
4.7 MEDIUM

Jenkins HTML Publisher Plugin 1.32 and earlier does not escape job names, report names, and index page titles shown as part of the report frame, …

Mar 6, 2024
CVE-2024-28149
6.5 MEDIUM

Jenkins HTML Publisher Plugin 1.16 through 1.32 (both inclusive) does not properly sanitize input, allowing attackers with Item/Configure permission to implement cross-site scripting (XSS) attacks …

Mar 6, 2024
CVE-2024-20346
5.4 MEDIUM

A vulnerability in the web-based management interface of Cisco AppDynamics Controller could allow an authenticated, remote attacker to perform a reflected cross-site scripting (XSS) attack …

Mar 6, 2024
CVE-2024-20345
6.5 MEDIUM

A vulnerability in the file upload functionality of Cisco AppDynamics Controller could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected …

Mar 6, 2024
CVE-2024-20338
7.3 HIGH

A vulnerability in the ISE Posture (System Scan) module of Cisco Secure Client for Linux could allow an authenticated, local attacker to elevate privileges on …

Mar 6, 2024
CVE-2024-20337
8.2 HIGH

A vulnerability in the SAML authentication process of Cisco Secure Client could allow an unauthenticated, remote attacker to conduct a carriage return line feed (CRLF) …

Mar 6, 2024
CVE-2024-20336
6.5 MEDIUM

A vulnerability in the web-based user interface of Cisco Small Business 100, 300, and 500 Series Wireless APs could allow an authenticated, remote attacker to …

Mar 6, 2024
CVE-2024-20335
6.5 MEDIUM

A vulnerability in the web-based management interface of Cisco Small Business 100, 300, and 500 Series Wireless APs could allow an authenticated, remote attacker to …

Mar 6, 2024
CVE-2024-20301
6.2 MEDIUM

A vulnerability in Cisco Duo Authentication for Windows Logon and RDP could allow an authenticated, physical attacker to bypass secondary authentication and access an affected …

Mar 6, 2024
CVE-2024-20292
4.4 MEDIUM

A vulnerability in the logging component of Cisco Duo Authentication for Windows Logon and RDP could allow an authenticated, local attacker to view sensitive information …

Mar 6, 2024
CVE-2023-50740
5.3 MEDIUM

In Apache Linkis <=1.4.0, The password is printed to the log when using the Oracle data source of the Linkis data source module. We recommend …

Mar 6, 2024
CVE-2024-2005
9.0 CRITICAL

In Blue Planet® products through 22.12, a misconfiguration in the SAML implementation allows for privilege escalation. Only products using SAML authentication are affected. Blue Planet® …

Mar 6, 2024
CVE-2024-26580
9.1 CRITICAL

Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.8.0 through 1.10.0, the attackers can use the specific payload to read …

Mar 6, 2024
CVE-2024-25103
6.3 MEDIUM

This vulnerability exists in AppSamvid software due to the usage of vulnerable and outdated components. An attacker with local administrative privileges could exploit this by …

Mar 6, 2024
CVE-2024-25102
7.8 HIGH

This vulnerability exists in AppSamvid software due to the usage of a weaker cryptographic algorithm (hash) SHA1 in user login component. An attacker with local …

Mar 6, 2024
CVE-2024-1224
7.1 HIGH

This vulnerability exists in USB Pratirodh due to the usage of a weaker cryptographic algorithm (hash) SHA1 in user login component. A local attacker with …

Mar 6, 2024
CVE-2024-2211
4.6 MEDIUM

Cross-Site Scripting stored vulnerability in Gophish affecting version 0.12.1. This vulnerability could allow an attacker to store a malicious JavaScript payload in the campaign menu …

Mar 6, 2024
CVE-2024-26628

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Mar 6, 2024
CVE-2024-26627
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: core: Move scsi_host_busy() out of host lock for waking up EH handler Inside scsi_eh_wakeup(), …

Mar 6, 2024
CVE-2024-26626
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ipmr: fix kernel panic when forwarding mcast packets The stacktrace was: [ 86.305548] BUG: kernel …

Mar 6, 2024
CVE-2024-26625
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: llc: call sock_orphan() at release time syzbot reported an interesting trace [1] caused by a …

Mar 6, 2024
CVE-2024-26624

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Mar 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.