CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2019-25162
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: i2c: Fix a potential use after free Free the adap structure only after we are …

Feb 26, 2024
CVE-2019-25161

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Feb 26, 2024
CVE-2019-25160
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: netlabel: fix out-of-bounds memory accesses There are two array out-of-bounds memory accesses, one in cipso_v4_map_lvl_valid(), …

Feb 26, 2024
CVE-2024-27088
0.0 NONE

es5-ext contains ECMAScript 5 extensions. Passing functions with very long names or complex default argument names into `function#copy` or `function#toStringTokens` may cause the script to …

Feb 26, 2024
CVE-2024-27087
4.6 MEDIUM

Kirby is a content management system. The new link field introduced in Kirby 4 allows several different link types that each validate the entered link …

Feb 26, 2024
CVE-2024-27081
7.2 HIGH

ESPHome is a system to control your ESP8266/ESP32. A security misconfiguration in the edit configuration file API in the dashboard component of ESPHome version 2023.12.9 …

Feb 26, 2024
CVE-2024-25767
6.5 MEDIUM

nanomq 0.21.2 contains a Use-After-Free vulnerability in /nanomq/nng/src/core/socket.c.

Feb 26, 2024
CVE-2024-24402
9.8 CRITICAL

An issue in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted script to the /usr/local/nagios/bin/npcd component.

Feb 26, 2024
CVE-2024-24401
9.8 CRITICAL

SQL Injection vulnerability in Nagios XI 2024R1.01 allows a remote attacker to execute arbitrary code via a crafted payload to the monitoringwizard.php component.

Feb 26, 2024
CVE-2024-27456
9.1 CRITICAL

rack-cors (aka Rack CORS Middleware) 2.0.1 has 0666 permissions for the .rb files.

Feb 26, 2024
CVE-2024-27455
9.1 CRITICAL

In the Bentley ALIM Web application, certain configuration settings can cause exposure of a user's ALIM session token when the user attempts to download files. …

Feb 26, 2024
CVE-2024-27454
7.5 HIGH

orjson.loads in orjson before 3.9.15 does not limit recursion for deeply nested JSON documents.

Feb 26, 2024
CVE-2024-27447
9.8 CRITICAL

pretix before 2024.1.1 mishandles file validation.

Feb 26, 2024
CVE-2024-27444
9.8 CRITICAL

langchain_experimental (aka LangChain Experimental) in LangChain before 0.1.8 allows an attacker to bypass the CVE-2023-44467 fix and execute arbitrary code via the __import__, __subclasses__, __builtins__, …

Feb 26, 2024
CVE-2024-27359
7.5 HIGH

Certain WithSecure products allow a Denial of Service because the engine scanner can go into an infinite loop when processing an archive file. This affects …

Feb 26, 2024
CVE-2024-27350
5.9 MEDIUM

Amazon Fire OS 7 before 7.6.6.9 and 8 before 8.1.0.3 allows Fire TV applications to establish local ADB (Android Debug Bridge) connections. NOTE: some third …

Feb 26, 2024
CVE-2024-26606
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: binder: signal epoll threads of self-work In (e)poll mode, threads often depend on I/O events …

Feb 26, 2024
CVE-2024-26605
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: PCI/ASPM: Fix deadlock when enabling ASPM A last minute revert in 6.7-final introduced a potential …

Feb 26, 2024
CVE-2024-26604
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Revert "kobject: Remove redundant checks for whether ktype is NULL" This reverts commit 1b28cb81dab7c1eedc6034206f4e8d644046ad31. It …

Feb 26, 2024
CVE-2024-26603
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: x86/fpu: Stop relying on userspace for info to fault in xsave buffer Before this change, …

Feb 26, 2024
CVE-2024-26602
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sched/membarrier: reduce the ability to hammer on sys_membarrier On some systems, sys_membarrier can be very …

Feb 26, 2024
CVE-2024-26601
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ext4: regenerate buddy after block freeing failed if under fc replay This mostly reverts commit …

Feb 26, 2024
CVE-2024-26600
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: phy: ti: phy-omap-usb2: Fix NULL pointer dereference for SRP If the external phy working together …

Feb 26, 2024
CVE-2024-26468
6.1 MEDIUM

A DOM based cross-site scripting (XSS) vulnerability in the component index.html of jstrieb/urlpages before commit 035b647 allows attackers to execute arbitrary Javascript via sending a …

Feb 26, 2024
CVE-2024-26467
6.1 MEDIUM

A DOM based cross-site scripting (XSS) vulnerability in the component generator.html of tabatkins/railroad-diagrams before commit ea9a123 allows attackers to execute arbitrary Javascript via sending a …

Feb 26, 2024
CVE-2024-26466
6.1 MEDIUM

A DOM based cross-site scripting (XSS) vulnerability in the component /dom/ranges/Range-test-iframe.html of web-platform-tests/wpt before commit 938e843 allows attackers to execute arbitrary Javascript via sending a …

Feb 26, 2024
CVE-2024-26465
6.1 MEDIUM

A DOM based cross-site scripting (XSS) vulnerability in the component /beep/Beep.Instrument.js of stewdio beep.js before commit ef22ad7 allows attackers to execute arbitrary Javascript via sending …

Feb 26, 2024
CVE-2024-25925
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in SYSBASICS WooCommerce Easy Checkout Field Editor, Fees & Discounts.This issue affects WooCommerce Easy Checkout Field Editor, …

Feb 26, 2024
CVE-2024-25913
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Skymoonlabs MoveTo.This issue affects MoveTo: from n/a through 6.2.

Feb 26, 2024
CVE-2024-25909
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in JoomUnited WP Media folder.This issue affects WP Media folder: from n/a through 5.7.2.

Feb 26, 2024
CVE-2024-25763
5.5 MEDIUM

openNDS 10.2.0 is vulnerable to Use-After-Free via /openNDS/src/auth.c.

Feb 26, 2024
CVE-2024-25760

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not …

Feb 26, 2024
CVE-2024-25410
6.5 MEDIUM

flusity-CMS 2.33 is vulnerable to Unrestricted Upload of File with Dangerous Type in update_setting.php.

Feb 26, 2024
CVE-2024-25344
6.1 MEDIUM

Cross Site Scripting vulnerability in ITFlow.org before commit v.432488eca3998c5be6b6b9e8f8ba01f54bc12378 allows a remtoe attacker to execute arbitrary code and obtain sensitive information via the settings.php, settings+company.php, …

Feb 26, 2024
CVE-2024-25082
6.5 MEDIUM

Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files.

Feb 26, 2024
CVE-2024-25081
4.2 MEDIUM

Splinefont in FontForge through 20230101 allows command injection via crafted filenames.

Feb 26, 2024
CVE-2024-24714
7.2 HIGH

Unrestricted Upload of File with Dangerous Type vulnerability in bPlugins LLC Icons Font Loader.This issue affects Icons Font Loader: from n/a through 1.1.4.

Feb 26, 2024
CVE-2024-24568
5.3 MEDIUM

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.3, the rules inspecting HTTP2 headers can get …

Feb 26, 2024
CVE-2024-23839
7.1 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.3, specially crafted traffic can cause a heap …

Feb 26, 2024
CVE-2024-23837
7.5 HIGH

LibHTP is a security-aware parser for the HTTP protocol. Crafted traffic can cause excessive processing time of HTTP headers, leading to denial of service. This …

Feb 26, 2024
CVE-2024-23836
7.5 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 6.0.16 and 7.0.3, an attacker can craft …

Feb 26, 2024
CVE-2024-23835
7.5 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.3, excessive memory use during pgsql parsing …

Feb 26, 2024
CVE-2024-23605
8.8 HIGH

A heap-based buffer overflow vulnerability exists in the GGUF library header.n_kv functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to code …

Feb 26, 2024
CVE-2024-23496
8.8 HIGH

A heap-based buffer overflow vulnerability exists in the GGUF library gguf_fread_str functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to code …

Feb 26, 2024
CVE-2024-22873
8.1 HIGH

Tencent Blueking CMDB v3.2.x to v3.9.x was discovered to contain a Server-Side Request Forgery (SSRF) via the event subscription function (/service/subscription.go). This vulnerability allows attackers …

Feb 26, 2024
CVE-2024-22371
2.9 LOW

Exposure of sensitive data by by crafting a malicious EventFactory and providing a custom ExchangeCreatedEvent that exposes sensitive data. Vulnerability in Apache Camel.This issue affects …

Feb 26, 2024
CVE-2024-22201
7.5 HIGH

Jetty is a Java based web server and servlet engine. An HTTP/2 SSL connection that is established and TCP congested will be leaked when it …

Feb 26, 2024
CVE-2024-21836
8.8 HIGH

A heap-based buffer overflow vulnerability exists in the GGUF library header.n_tensors functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to code …

Feb 26, 2024
CVE-2024-21825
8.8 HIGH

A heap-based buffer overflow vulnerability exists in the GGUF library GGUF_TYPE_ARRAY/GGUF_TYPE_STRING parsing functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to …

Feb 26, 2024
CVE-2024-21802
8.8 HIGH

A heap-based buffer overflow vulnerability exists in the GGUF library info->ne functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to code …

Feb 26, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.