CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-25723
8.8 HIGH

ZenML Server in the ZenML machine learning package before 0.46.7 for Python allows remote privilege escalation because the /api/v1/users/{user_name_or_id}/activate REST API endpoint allows access on …

Feb 27, 2024
CVE-2024-1921
4.7 MEDIUM

A vulnerability, which was classified as critical, was found in osuuu LightPicture up to 1.2.2. Affected is an unknown function of the file /app/controller/Setup.php. The …

Feb 27, 2024
CVE-2024-1423

Rejected reason: Accidental Request

Feb 27, 2024
CVE-2024-1920
5.6 MEDIUM

A vulnerability, which was classified as critical, has been found in osuuu LightPicture up to 1.2.2. This issue affects the function handle of the file …

Feb 27, 2024
CVE-2024-1919
3.5 LOW

A vulnerability classified as problematic was found in SourceCodester Online Job Portal 1.0. This vulnerability affects unknown code of the file /Employer/ManageWalkin.php of the component …

Feb 27, 2024
CVE-2024-0819
7.3 HIGH

Improper initialization of default settings in TeamViewer Remote Client prior version 15.51.5 for Windows, Linux and macOS, allow a low privileged user to elevate privileges …

Feb 27, 2024
CVE-2024-0551
7.1 HIGH

Enable exports of the database and associated exported information of the system via the default user role. The attacked would have to have been granted …

Feb 27, 2024
CVE-2023-51747
7.1 HIGH

Apache James prior to versions 3.8.1 and 3.7.5 is vulnerable to SMTP smuggling. A lenient behaviour in line delimiter handling might create a difference of …

Feb 27, 2024
CVE-2024-1918
4.7 MEDIUM

A vulnerability has been found in Byzoro Smart S42 Management Platform up to 20240219 and classified as critical. Affected by this vulnerability is an unknown …

Feb 27, 2024
CVE-2024-0197
7.8 HIGH

A flaw in the installer for Thales SafeNet Sentinel HASP LDK prior to 9.16 on Windows allows an attacker to escalate their privilege level via …

Feb 27, 2024
CVE-2024-1912
4.3 MEDIUM

The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.7.4. This is due to missing or …

Feb 27, 2024
CVE-2024-1910
4.3 MEDIUM

The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.7.4. This is due to missing or …

Feb 27, 2024
CVE-2024-1909
4.3 MEDIUM

The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.7.4. This is due to missing or …

Feb 27, 2024
CVE-2024-1907
4.3 MEDIUM

The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.7.4. This is due to missing or …

Feb 27, 2024
CVE-2024-1906
4.3 MEDIUM

The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.7.4. This is due to missing or …

Feb 27, 2024
CVE-2024-1653
4.3 MEDIUM

The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the categorifyAjaxUpdateFolderPosition in all versions up …

Feb 27, 2024
CVE-2024-1652
4.3 MEDIUM

The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the categorifyAjaxClearCategory function in all versions …

Feb 27, 2024
CVE-2024-1650
4.3 MEDIUM

The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the categorifyAjaxRenameCategory function in all versions …

Feb 27, 2024
CVE-2024-1649
4.3 MEDIUM

The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the categorifyAjaxDeleteCategory function in all versions …

Feb 27, 2024
CVE-2023-7016
7.8 HIGH

A flaw in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker to execute code at a SYSTEM level via local …

Feb 27, 2024
CVE-2023-5993
7.8 HIGH

A flaw in the Windows Installer in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker to escalate their privilege level …

Feb 27, 2024
CVE-2021-46937
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/damon/dbgfs: fix 'struct pid' leaks in 'dbgfs_target_ids_write()' DAMON debugfs interface increases the reference counts of …

Feb 27, 2024
CVE-2021-46936
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: fix use-after-free in tw_timer_handler A real world panic issue was found as follow in …

Feb 27, 2024
CVE-2021-46935
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: binder: fix async_free_space accounting for empty parcels In 4.13, commit 74310e06be4d ("android: binder: Move buffer …

Feb 27, 2024
CVE-2021-46934
3.3 LOW

In the Linux kernel, the following vulnerability has been resolved: i2c: validate user data in compat ioctl Wrong user data may cause warning in i2c_transfer(), …

Feb 27, 2024
CVE-2021-46933
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: Clear ffs_eventfd in ffs_data_clear. ffs_data_clear is indirectly called from both ffs_fs_kill_sb and …

Feb 27, 2024
CVE-2021-46932
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Input: appletouch - initialize work before device registration Syzbot has reported warning in __flush_work(). This …

Feb 27, 2024
CVE-2021-46931
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Wrap the tx reporter dump callback to extract the sq Function mlx5e_tx_reporter_dump_sq() casts its …

Feb 27, 2024
CVE-2021-46930
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: mtu3: fix list_head check warning This is caused by uninitialization of list_head. BUG: KASAN: …

Feb 27, 2024
CVE-2021-46929
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sctp: use call_rcu to free endpoint This patch is to delay the endpoint free by …

Feb 27, 2024
CVE-2021-46928
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: parisc: Clear stale IIR value on instruction access rights trap When a trap 7 (Instruction …

Feb 27, 2024
CVE-2021-46927
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nitro_enclaves: Use get_user_pages_unlocked() call to handle mmap assert After commit 5b78ed24e8ec ("mm/pagemap: add mmap_assert_locked() annotations …

Feb 27, 2024
CVE-2021-46926
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: intel-sdw-acpi: harden detection of controller The existing code currently sets a pointer to …

Feb 27, 2024
CVE-2021-46925
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/smc: fix kernel panic caused by race of smc_sock A crash occurs when smc_cdc_tx_handler() tries …

Feb 27, 2024
CVE-2021-46924
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: NFC: st21nfca: Fix memory leak in device probe and remove 'phy->pending_skb' is alloced when device …

Feb 27, 2024
CVE-2021-46923
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fs/mount_setattr: always cleanup mount_kattr Make sure that finish_mount_kattr() is called after mount_kattr was succesfully built …

Feb 27, 2024
CVE-2021-46922
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KEYS: trusted: Fix TPM reservation for seal/unseal The original patch 8c657a0590de ("KEYS: trusted: Reserve TPM …

Feb 27, 2024
CVE-2021-46921
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: locking/qrwlock: Fix ordering in queued_write_lock_slowpath() While this code is executed with the wait_lock held, a …

Feb 27, 2024
CVE-2024-1106
6.1 MEDIUM

The Shariff Wrapper WordPress plugin before 4.6.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Feb 27, 2024
CVE-2024-0855
5.3 MEDIUM

The Spiffy Calendar WordPress plugin before 4.9.9 doesn't check the event_author parameter, and allows any user to alter it when creating an event, leading to …

Feb 27, 2024
CVE-2023-7203
6.1 MEDIUM

The Smart Forms WordPress plugin before 2.6.87 does not have authorisation in various AJAX actions, which could allow users with a role as low as …

Feb 27, 2024
CVE-2023-7202
6.1 MEDIUM

The Fatal Error Notify WordPress plugin before 1.5.3 does not have authorisation and CSRF checks in its test_error AJAX action, allowing any authenticated users, such …

Feb 27, 2024
CVE-2023-7198
4.3 MEDIUM

The WP Dashboard Notes WordPress plugin before 1.0.11 is vulnerable to Insecure Direct Object References (IDOR) in post_id= parameter. Authenticated users are able to delete …

Feb 27, 2024
CVE-2023-7167
6.1 MEDIUM

The Persian Fonts WordPress plugin through 1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Feb 27, 2024
CVE-2023-7165
7.5 HIGH

The JetBackup WordPress plugin before 2.0.9.9 doesn't use index files to prevent public directory listing of sensitive directories in certain configurations, which allows malicious actors …

Feb 27, 2024
CVE-2023-7115
4.8 MEDIUM

The Page Builder: Pagelayer WordPress plugin before 1.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Feb 27, 2024
CVE-2023-6585
7.5 HIGH

The WP JobSearch WordPress plugin before 2.3.4 does not validate files to be uploaded, which could allow unauthenticated attackers to upload arbitrary files such as …

Feb 27, 2024
CVE-2023-6584
7.5 HIGH

The WP JobSearch WordPress plugin before 2.3.4 does not prevent attackers from logging-in as any users with the only knowledge of that user's email address.

Feb 27, 2024
CVE-2023-51518
9.8 CRITICAL

Apache James prior to version 3.7.5 and 3.8.0 exposes a JMX endpoint on localhost subject to pre-authentication deserialisation of untrusted data. Given a deserialisation gadjet, …

Feb 27, 2024
CVE-2023-50379
8.8 HIGH

Malicious code injection in Apache Ambari in prior to 2.7.8. Users are recommended to upgrade to version 2.7.8, which fixes this issue. Impact: A Cluster …

Feb 27, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.