CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-20026
4.2 MEDIUM

In da, there is a possible information disclosure due to improper input validation. This could lead to local information disclosure with System execution privileges needed. …

Mar 4, 2024
CVE-2024-20025
6.7 MEDIUM

In da, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System …

Mar 4, 2024
CVE-2024-20024
6.0 MEDIUM

In flashc, there is a possible out of bounds write due to lack of valudation. This could lead to local escalation of privilege with System …

Mar 4, 2024
CVE-2024-20023
6.7 MEDIUM

In flashc, there is a possible out of bounds write due to lack of valudation. This could lead to local escalation of privilege with System …

Mar 4, 2024
CVE-2024-20022
6.7 MEDIUM

In lk, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System …

Mar 4, 2024
CVE-2024-20020
4.4 MEDIUM

In OPTEE, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local information disclosure with System …

Mar 4, 2024
CVE-2024-20019
5.9 MEDIUM

In wlan driver, there is a possible memory leak due to improper input handling. This could lead to remote denial of service with no additional …

Mar 4, 2024
CVE-2024-20018
9.8 CRITICAL

In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with …

Mar 4, 2024
CVE-2024-20017
9.8 CRITICAL

In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no …

Mar 4, 2024
CVE-2024-20005
8.2 HIGH

In da, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution …

Mar 4, 2024
CVE-2024-2156
6.3 MEDIUM

A vulnerability was found in SourceCodester Best POS Management System 1.0. It has been classified as critical. Affected is an unknown function of the file …

Mar 4, 2024
CVE-2024-2155
4.3 MEDIUM

A vulnerability was found in SourceCodester Best POS Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file index.php. …

Mar 4, 2024
CVE-2024-2154
6.3 MEDIUM

A vulnerability has been found in SourceCodester Online Mobile Management Store 1.0 and classified as critical. This vulnerability affects unknown code of the file view_product.php. …

Mar 4, 2024
CVE-2024-2153
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in SourceCodester Online Mobile Management Store 1.0. This affects an unknown part of the file /admin/orders/view_order.php. …

Mar 4, 2024
CVE-2024-2152
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Online Mobile Management Store 1.0. Affected by this issue is some unknown functionality …

Mar 4, 2024
CVE-2024-2151
4.3 MEDIUM

A vulnerability classified as problematic was found in SourceCodester Online Mobile Management Store 1.0. Affected by this vulnerability is an unknown functionality of the component …

Mar 4, 2024
CVE-2024-28088
8.1 HIGH

LangChain through 0.1.10 allows ../ directory traversal by an actor who is able to control the final part of the path parameter in a load_chain …

Mar 4, 2024
CVE-2024-28084
7.5 HIGH

p2putil.c in iNet wireless daemon (IWD) through 2.15 allows attackers to cause a denial of service (daemon crash) or possibly have unspecified other impact because …

Mar 3, 2024
CVE-2019-25210
6.5 MEDIUM

An issue was discovered in Cloud Native Computing Foundation (CNCF) Helm through 3.13.3. It displays values of secrets when the --dry-run flag is used. This …

Mar 3, 2024
CVE-2024-2150
5.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Insurance Management System 1.0. This issue affects some unknown processing. The manipulation of …

Mar 3, 2024
CVE-2024-2149
4.7 MEDIUM

A vulnerability classified as critical was found in CodeAstro Membership Management System 1.0. This vulnerability affects unknown code of the file settings.php. The manipulation of …

Mar 3, 2024
CVE-2024-2148
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Online Mobile Management Store 1.0. This affects an unknown part of the file /classes/Users.php. The …

Mar 3, 2024
CVE-2024-2147
7.3 HIGH

A vulnerability was found in SourceCodester Online Mobile Management Store 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

Mar 3, 2024
CVE-2023-28512
5.9 MEDIUM

IBM Watson CP4D Data Stores 4.6.0, 4.6.1, and 4.6.2 could allow an attacker with specific knowledge about the system to manipulate data due to improper …

Mar 3, 2024
CVE-2023-27291
4.5 MEDIUM

IBM Watson CP4D Data Stores 4.6.0, 4.6.1, 4.6.2, and 4.6.3 does not encrypt sensitive or critical information before storage or transmission which could allow an …

Mar 3, 2024
CVE-2022-43880
4.4 MEDIUM

IBM QRadar WinCollect Agent 10.0 through 10.1.2 could allow a privileged user to cause a denial of service. IBM X-Force ID: 240151.

Mar 3, 2024
CVE-2024-2146
3.5 LOW

A vulnerability was found in SourceCodester Online Mobile Management Store 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality …

Mar 3, 2024
CVE-2024-0765
6.5 MEDIUM

As a default user on a multi-user instance of AnythingLLM, you could execute a call to the `/export-data` endpoint of the system and then unzip …

Mar 3, 2024
CVE-2024-2145
3.5 LOW

A vulnerability was found in SourceCodester Online Mobile Management Store 1.0. It has been classified as problematic. Affected is an unknown function of the file …

Mar 3, 2024
CVE-2024-22355
5.9 MEDIUM

IBM QRadar Suite Products 1.10.12.0 through 1.10.18.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 does not require that users should have strong passwords …

Mar 3, 2024
CVE-2023-47742
5.9 MEDIUM

IBM QRadar Suite Products 1.10.12.0 through 1.10.18.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could disclose sensitive information using man in the middle …

Mar 3, 2024
CVE-2023-43054
6.4 MEDIUM

IBM Engineering Test Management 7.0.2 and 7.0.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web …

Mar 3, 2024
CVE-2024-27255
5.9 MEDIUM

IBM MQ Operator 2.0.0 LTS, 2.0.18 LTS, 3.0.0 CD, 3.0.1 CD, 2.4.0 through 2.4.7, 2.3.0 through 2.3.3, 2.2.0 through 2.2.2, and 2.3.0 through 2.3.3 uses …

Mar 3, 2024
CVE-2023-47745
6.2 MEDIUM

IBM MQ Operator 2.0.0 LTS, 2.0.18 LTS, 3.0.0 CD, 3.0.1 CD, 2.4.0 through 2.4.7, 2.3.0 through 2.3.3, 2.2.0 through 2.2.2, and 2.3.0 through 2.3.3 stores …

Mar 3, 2024
CVE-2024-26469
8.1 HIGH

Server-Side Request Forgery (SSRF) vulnerability in Tunis Soft "Product Designer" (productdesigner) module for PrestaShop before version 1.178.36, allows remote attackers to cause a denial of …

Mar 3, 2024
CVE-2024-25847
9.8 CRITICAL

SQL Injection vulnerability in MyPrestaModules "Product Catalog (CSV, Excel) Import" (simpleimportproduct) modules for PrestaShop versions 6.5.0 and before, allows attackers to escalate privileges and obtain …

Mar 3, 2024
CVE-2024-25842
7.5 HIGH

An issue was discovered in Presta World "Account Manager - Sales Representative & Dealers - CRM" (prestasalesmanager) module for PrestaShop before version 9.0, allows remote …

Mar 3, 2024
CVE-2024-25839
7.5 HIGH

An issue was discovered in Webbax "Super Newsletter" (supernewsletter) module for PrestaShop versions 1.4.21 and before, allows local attackers to escalate privileges and obtain sensitive …

Mar 3, 2024
CVE-2024-24302
9.8 CRITICAL

An issue was discovered in Tunis Soft "Product Designer" (productdesigner) module for PrestaShop before version 1.178.36, allows remote attackers to execute arbitrary code, escalate privileges, …

Mar 3, 2024
CVE-2024-25844
7.5 HIGH

An issue was discovered in Common-Services "So Flexibilite" (soflexibilite) module for PrestaShop before version 4.1.26, allows remote attackers to escalate privileges and obtain sensitive information …

Mar 3, 2024
CVE-2024-25551
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in sourcecodester Simple Student Attendance System v1.0 allows attackers to execute arbitrary code via crafted GET request to web application …

Mar 3, 2024
CVE-2024-24307
7.5 HIGH

Path Traversal vulnerability in Tunis Soft "Product Designer" (productdesigner) module for PrestaShop before version 1.178.36, allows a remote attacker to escalate privileges and obtain sensitive …

Mar 3, 2024
CVE-2024-25016
7.5 HIGH

IBM MQ and IBM MQ Appliance 9.0, 9.1, 9.2, 9.3 LTS and 9.3 CD could allow a remote unauthenticated attacker to cause a denial of …

Mar 3, 2024
CVE-2024-2135
2.4 LOW

A vulnerability was found in Bdtask Hospita AutoManager up to 20240223 and classified as problematic. This issue affects some unknown processing of the file /hospital_activities/birth/form …

Mar 3, 2024
CVE-2024-2134
4.3 MEDIUM

A vulnerability has been found in Bdtask Hospita AutoManager up to 20240223 and classified as problematic. This vulnerability affects unknown code of the file /investigation/delete/ …

Mar 3, 2024
CVE-2024-2133
2.4 LOW

A vulnerability, which was classified as problematic, was found in Bdtask Isshue Multi Store eCommerce Shopping Cart Solution 4.0. This affects an unknown part of …

Mar 3, 2024
CVE-2024-26621
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm: huge_memory: don't force huge page alignment on 32 bit commit efa7df3e3bb5 ("mm: align larger …

Mar 2, 2024
CVE-2024-25865
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in hexo-theme-anzhiyu v1.6.12, allows remote attackers to execute arbitrary code via the algolia search function.

Mar 2, 2024
CVE-2024-0968

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as the vulnerability is not in distributable software.

Mar 2, 2024
CVE-2024-0795
7.2 HIGH

If an attacked was given access to an instance with the admin or manager role there is no backend authentication that would prevent the attacked …

Mar 2, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.