CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-26472
6.1 MEDIUM

KLiK SocialMediaWebsite version 1.0.1 from msaad1999 has a reflected cross-site scripting (XSS) vulnerability which may allow remote attackers to execute arbitrary JavaScript in the web …

Feb 29, 2024
CVE-2024-26471
5.4 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in zhimengzhe iBarn v1.5 allows attackers to inject malicious JavaScript into the web browser of a victim via the …

Feb 29, 2024
CVE-2024-26470
8.1 HIGH

A host header injection vulnerability in the forgot password function of FullStackHero's WebAPI Boilerplate v1.0.0 and v1.0.1 allows attackers to leak the password reset token …

Feb 29, 2024
CVE-2024-26462
5.5 MEDIUM

Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/kdc/ndr.c.

Feb 29, 2024
CVE-2024-26461
7.5 HIGH

Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.

Feb 29, 2024
CVE-2024-26458
5.3 MEDIUM

Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.

Feb 29, 2024
CVE-2024-26132
4.0 MEDIUM

Element Android is an Android Matrix Client. A third-party malicious application installed on the same phone can force Element Android, version 0.91.0 through 1.6.12, to …

Feb 29, 2024
CVE-2024-26131
8.4 HIGH

Element Android is an Android Matrix Client. Element Android version 1.4.3 through 1.6.10 is vulnerable to intent redirection, allowing a third-party malicious application to start …

Feb 29, 2024
CVE-2024-25932
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Manish Kumar Agarwal Change Table Prefix change-table-prefix allows Cross Site Request Forgery.This issue affects Change Table Prefix: from n/a …

Feb 29, 2024
CVE-2024-25931
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Heureka Group Heureka.This issue affects Heureka: from n/a through 1.0.8.

Feb 29, 2024
CVE-2024-25930
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Nuggethon Custom Order Statuses for WooCommerce.This issue affects Custom Order Statuses for WooCommerce: from n/a through 1.5.2.

Feb 29, 2024
CVE-2024-25833
9.8 CRITICAL

F-logic DataCube3 v1.0 is vulnerable to unauthenticated SQL injection, which could allow an unauthenticated malicious actor to execute arbitrary SQL queries in database.

Feb 29, 2024
CVE-2024-25832
8.8 HIGH

F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to upload a file of dangerous type by manipulating …

Feb 29, 2024
CVE-2024-25831
5.4 MEDIUM

F-logic DataCube3 Version 1.0 is affected by a reflected cross-site scripting (XSS) vulnerability due to improper input sanitization. An authenticated, remote attacker can execute arbitrary …

Feb 29, 2024
CVE-2024-25830
9.8 CRITICAL

F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction. An unauthenticated, remote attacker can exploit this, by sending …

Feb 29, 2024
CVE-2024-25713
8.6 HIGH

yyjson through 0.8.0 has a double free, leading to remote code execution in some cases, because the pool_free function lacks loop checks. (pool_free is part …

Feb 29, 2024
CVE-2024-25712
6.1 MEDIUM

http-swagger before 1.2.6 allows XSS via PUT requests, because a file that has been uploaded (via httpSwagger.WrapHandler and *webdav.memFile) can subsequently be accessed via a …

Feb 29, 2024
CVE-2024-25262
8.1 HIGH

texlive-bin commit c515e was discovered to contain heap buffer overflow via the function ttfLoadHDMX:ttfdump. This vulnerability allows attackers to cause a Denial of Service (DoS) …

Feb 29, 2024
CVE-2024-25128
9.1 CRITICAL

Flask-AppBuilder is an application development framework, built on top of Flask. When Flask-AppBuilder is set to AUTH_TYPE AUTH_OID, it allows an attacker to forge an …

Feb 29, 2024
CVE-2024-25065
9.1 CRITICAL

Possible path traversal in Apache OFBiz allowing authentication bypass. Users are recommended to upgrade to version 18.12.12, that fixes the issue.

Feb 29, 2024
CVE-2024-25006
8.1 HIGH

XenForo before 2.2.14 allows Directory Traversal (with write access) by an authenticated user who has permissions to administer styles, and uses a ZIP archive for …

Feb 29, 2024
CVE-2024-24708
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in W3speedster W3SPEEDSTER.This issue affects W3SPEEDSTER: from n/a through 7.19.

Feb 29, 2024
CVE-2024-24701
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Native Grid LLC A no-code page builder for beautiful performance-based content.This issue affects A no-code page builder for beautiful …

Feb 29, 2024
CVE-2024-24155
6.5 MEDIUM

Bento4 v1.5.1-628 contains a Memory leak on AP4_Movie::AP4_Movie, parsing tracks and added into m_Tracks list, but mp42aac cannot correctly delete when we got an no …

Feb 29, 2024
CVE-2024-24150
6.5 MEDIUM

A memory leak issue discovered in parseSWF_TEXTRECORD in libming v0.4.8 allows attackers to cause a denial of service via a crafted SWF file.

Feb 29, 2024
CVE-2024-24149
6.5 MEDIUM

A memory leak issue discovered in parseSWF_GLYPHENTRY in libming v0.4.8 allows attackers to cause a denial of service via a crafted SWF file.

Feb 29, 2024
CVE-2024-24147
6.5 MEDIUM

A memory leak issue discovered in parseSWF_FILLSTYLEARRAY in libming v0.4.8 allows attackers to cause s denial of service via a crafted SWF file.

Feb 29, 2024
CVE-2024-24146
6.5 MEDIUM

A memory leak issue discovered in parseSWF_DEFINEBUTTON in libming v0.4.8 allows attackers to cause s denial of service via a crafted SWF file.

Feb 29, 2024
CVE-2024-23946
5.3 MEDIUM

Possible path traversal in Apache OFBiz allowing file inclusion. Users are recommended to upgrade to version 18.12.12, that fixes the issue.

Feb 29, 2024
CVE-2024-23807
9.8 CRITICAL

The Apache Xerces C++ XML parser on versions 3.0.0 before 3.2.5 contains a use-after-free error triggered during the scanning of external DTDs. Users are recommended …

Feb 29, 2024
CVE-2024-23519
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in M&S Consulting Email Before Download.This issue affects Email Before Download: from n/a through 6.9.7.

Feb 29, 2024
CVE-2024-23328
9.1 CRITICAL

Dataease is an open source data visualization analysis tool. A deserialization vulnerability exists in the DataEase datasource, which can be exploited to execute arbitrary code. …

Feb 29, 2024
CVE-2024-23302
7.5 HIGH

Couchbase Server before 7.2.4 has a private key leak in goxdcr.log.

Feb 29, 2024
CVE-2024-23052
9.8 CRITICAL

An issue in WuKongOpenSource WukongCRM v.72crm_9.0.1_20191202 allows a remote attacker to execute arbitrary code via the parseObject() function in the fastjson component.

Feb 29, 2024
CVE-2024-22939
8.8 HIGH

Cross Site Request Forgery vulnerability in FlyCms v.1.0 allows a remote attacker to execute arbitrary code via the system/article/category_edit component.

Feb 29, 2024
CVE-2024-22936
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability in Parents & Student Portal in Genesis School Management Systems in Genesis AIMS Student Information Systems v.3053 allows remote attackers to …

Feb 29, 2024
CVE-2024-22251
5.9 MEDIUM

VMware Workstation and Fusion contain an out-of-bounds read vulnerability in the USB CCID (chip card interface device). A malicious actor with local administrative privileges on …

Feb 29, 2024
CVE-2024-21726
6.5 MEDIUM

Inadequate content filtering leads to XSS vulnerabilities in various components.

Feb 29, 2024
CVE-2024-21725
6.1 MEDIUM

Inadequate escaping of mail addresses lead to XSS vulnerabilities in various components.

Feb 29, 2024
CVE-2024-21724
6.1 MEDIUM

Inadequate input validation for media selection fields lead to XSS vulnerabilities in various extensions.

Feb 29, 2024
CVE-2024-21723
4.3 MEDIUM

Inadequate parsing of URLs could result into an open redirect.

Feb 29, 2024
CVE-2024-21722
6.3 MEDIUM

The MFA management features did not properly terminate existing user sessions when a user's MFA methods have been modified.

Feb 29, 2024
CVE-2024-20344
5.3 MEDIUM

A vulnerability in system resource management in Cisco UCS 6400 and 6500 Series Fabric Interconnects that are in Intersight Managed Mode (IMM) could allow an …

Feb 29, 2024
CVE-2024-20321
8.6 HIGH

A vulnerability in the External Border Gateway Protocol (eBGP) implementation of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of …

Feb 29, 2024
CVE-2024-20294
6.6 MEDIUM

A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to …

Feb 29, 2024
CVE-2024-20291
5.8 MEDIUM

A vulnerability in the access control list (ACL) programming for port channel subinterfaces of Cisco Nexus 3000 and 9000 Series Switches in standalone NX-OS mode …

Feb 29, 2024
CVE-2024-20267
8.6 HIGH

A vulnerability with the handling of MPLS traffic for Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause the netstack process to unexpectedly …

Feb 29, 2024
CVE-2024-1971
7.3 HIGH

A vulnerability has been found in Surya2Developer Online Shopping System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Feb 29, 2024
CVE-2024-1970
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in SourceCodester Online Learning System V2 1.0. Affected is an unknown function of the file /index.php. …

Feb 29, 2024
CVE-2024-1939
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Feb 29, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.