CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-25469
7.5 HIGH

SQL Injection vulnerability in CRMEB crmeb_java v.1.3.4 and before allows a remote attacker to obtain sensitive information via the latitude and longitude parameters in the …

Feb 23, 2024
CVE-2024-24681
9.8 CRITICAL

An issue was discovered in Yealink Configuration Encrypt Tool (AES version) and Yealink Configuration Encrypt Tool (RSA version before 1.2). There is a single hardcoded …

Feb 23, 2024
CVE-2024-22988
9.8 CRITICAL

ZKteco ZKBio WDMS before 9.0.2 Build 20250526 allows an attacker to download a database backup via the /files/backup/ component because the filename is based on …

Feb 23, 2024
CVE-2024-27133
7.5 HIGH

Insufficient sanitization in MLflow leads to XSS when running a recipe that uses an untrusted dataset. This issue leads to a client-side RCE when running …

Feb 23, 2024
CVE-2024-27132
7.5 HIGH

Insufficient sanitization in MLflow leads to XSS when running an untrusted recipe. This issue leads to a client-side RCE when running an untrusted recipe in …

Feb 23, 2024
CVE-2024-25730
9.8 CRITICAL

Hitron CODA-4582 and CODA-4589 devices have default PSKs that are generated from 5-digit hex values concatenated with a "Hitron" substring, resulting in insufficient entropy (only …

Feb 23, 2024
CVE-2024-24310
8.8 HIGH

In the module "Generate barcode on invoice / delivery slip" (ecgeneratebarcode) from Ether Creation <= 1.2.0 for PrestaShop, a guest can perform SQL injection.

Feb 23, 2024
CVE-2024-24309
7.5 HIGH

In the module "Survey TMA" (ecomiz_survey_tma) up to version 2.0.0 from Ecomiz for PrestaShop, a guest can download personal information without restriction.

Feb 23, 2024
CVE-2024-21423
4.8 MEDIUM

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

Feb 23, 2024
CVE-2021-44457

Rejected reason: This is unused.

Feb 23, 2024
CVE-2021-43351

Rejected reason: This is unused.

Feb 23, 2024
CVE-2021-41860

Rejected reason: This is unused.

Feb 23, 2024
CVE-2021-41859

Rejected reason: This is unused.

Feb 23, 2024
CVE-2021-41858

Rejected reason: This is unused.

Feb 23, 2024
CVE-2021-41857

Rejected reason: This is unused.

Feb 23, 2024
CVE-2021-41856

Rejected reason: This is unused.

Feb 23, 2024
CVE-2021-41855

Rejected reason: This is unused.

Feb 23, 2024
CVE-2021-41854

Rejected reason: This is unused.

Feb 23, 2024
CVE-2021-41853

Rejected reason: This is unused.

Feb 23, 2024
CVE-2021-41852

Rejected reason: This is unused.

Feb 23, 2024
CVE-2021-41851

Rejected reason: This is unused.

Feb 23, 2024
CVE-2021-3885

Rejected reason: This is unused.

Feb 23, 2024
CVE-2021-37405

Rejected reason: This is unused.

Feb 23, 2024
CVE-2021-33167

Rejected reason: This is unused.

Feb 23, 2024
CVE-2021-33165

Rejected reason: This is unused.

Feb 23, 2024
CVE-2021-33163

Rejected reason: This is unused.

Feb 23, 2024
CVE-2021-33162
8.4 HIGH

Improper access control in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow an authenticated user to potentially enable escalation of …

Feb 23, 2024
CVE-2021-33161
7.2 HIGH

Improper input validation in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user to potentially enable escalation of …

Feb 23, 2024
CVE-2021-33160

Rejected reason: This is unused.

Feb 23, 2024
CVE-2021-33158
7.2 HIGH

Improper neutralization in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user to potentially enable escalation of privilege …

Feb 23, 2024
CVE-2021-33157
7.2 HIGH

Insufficient control flow management in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user to potentially enable escalation …

Feb 23, 2024
CVE-2021-33156

Rejected reason: This is unused.

Feb 23, 2024
CVE-2021-33154

Rejected reason: This is unused.

Feb 23, 2024
CVE-2021-33153

Rejected reason: This is unused.

Feb 23, 2024
CVE-2021-33152

Rejected reason: This is unused.

Feb 23, 2024
CVE-2021-33151

Rejected reason: This is unused.

Feb 23, 2024
CVE-2021-33148

Rejected reason: This is unused.

Feb 23, 2024
CVE-2021-33146
5.3 MEDIUM

Improper input validation in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow an unauthenticated user to potentially enable information disclosure …

Feb 23, 2024
CVE-2021-33145
7.2 HIGH

Uncaught exception in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user to potentially enable escalation of privilege …

Feb 23, 2024
CVE-2021-33144

Rejected reason: This is unused.

Feb 23, 2024
CVE-2021-33143

Rejected reason: This is unused.

Feb 23, 2024
CVE-2021-33142
6.0 MEDIUM

Improper input validation in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user to potentially enable denial of …

Feb 23, 2024
CVE-2021-33141
8.6 HIGH

Improper input validation in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow an unauthenticated user to potentially enable denial of …

Feb 23, 2024
CVE-2021-33140

Rejected reason: This is unused.

Feb 23, 2024
CVE-2021-33138

Rejected reason: This is unused.

Feb 23, 2024
CVE-2021-33136

Rejected reason: This is unused.

Feb 23, 2024
CVE-2021-33134

Rejected reason: This is unused.

Feb 23, 2024
CVE-2021-33133

Rejected reason: This is unused.

Feb 23, 2024
CVE-2021-33132

Rejected reason: This is unused.

Feb 23, 2024
CVE-2021-33131

Rejected reason: This is unused.

Feb 23, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.