CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-52459
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: v4l: async: Fix duplicated list deletion The list deletion call dropped here is already …

Feb 23, 2024
CVE-2023-52458
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: block: add check that partition length needs to be aligned with block size Before calling …

Feb 23, 2024
CVE-2023-52457
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: serial: 8250: omap: Don't skip resource freeing if pm_runtime_resume_and_get() failed Returning an error code from …

Feb 23, 2024
CVE-2023-52456
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: serial: imx: fix tx statemachine deadlock When using the serial port as RS485 port, the …

Feb 23, 2024
CVE-2023-52455
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: iommu: Don't reserve 0-length IOVA region When the bootloader/firmware doesn't setup the framebuffers, their address …

Feb 23, 2024
CVE-2023-52454
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: Fix a kernel panic when host sends an invalid H2C PDU length If the …

Feb 23, 2024
CVE-2023-52453
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: hisi_acc_vfio_pci: Update migration data pointer correctly on saving/resume When the optional PRE_COPY support was added …

Feb 23, 2024
CVE-2024-26594
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate mech token in session setup If client send invalid mech token in session …

Feb 23, 2024
CVE-2024-1817
7.3 HIGH

A vulnerability has been found in Demososo DM Enterprise Website Building System up to 2022.8 and classified as critical. Affected by this vulnerability is the …

Feb 23, 2024
CVE-2024-25928
7.1 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sitepact.This issue affects Sitepact: from n/a through 1.0.5.

Feb 23, 2024
CVE-2024-25915
4.9 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in Raaj Trambadia Pexels: Free Stock Photos.This issue affects Pexels: Free Stock Photos: from n/a through 1.2.2.

Feb 23, 2024
CVE-2023-24416
6.8 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Arne Franken All In One Favicon.This issue affects All In One Favicon: …

Feb 23, 2024
CVE-2024-1362
4.3 MEDIUM

The Colibri Page Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.253. This is due to …

Feb 23, 2024
CVE-2024-1361
4.3 MEDIUM

The Colibri Page Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.253. This is due to …

Feb 23, 2024
CVE-2024-1360
4.3 MEDIUM

The Colibri WP theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.94. This is due to missing …

Feb 23, 2024
CVE-2024-26593
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: i2c: i801: Fix block process call transactions According to the Intel datasheets, software must reset …

Feb 23, 2024
CVE-2024-1590
4.6 MEDIUM

The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button Widget in …

Feb 23, 2024
CVE-2023-4826
6.1 MEDIUM

The SocialDriver WordPress theme before version 2024 has a prototype pollution vulnerability that could allow an attacker to inject arbitrary properties resulting in a cross-site …

Feb 23, 2024
CVE-2024-0563
4.3 MEDIUM

Denial of service condition in M-Files Server in versions before 24.2 (excluding 23.2 SR7 and 23.8 SR5) allows anonymous user to cause denial of service …

Feb 23, 2024
CVE-2024-1779
5.3 MEDIUM

The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check …

Feb 23, 2024
CVE-2024-1778
4.3 MEDIUM

The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check …

Feb 23, 2024
CVE-2024-1777
4.3 MEDIUM

The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, …

Feb 23, 2024
CVE-2024-1776
7.2 HIGH

The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to SQL Injection via the 'form-id' parameter in all versions up …

Feb 23, 2024
CVE-2023-37540
3.9 LOW

Sametime Connect desktop chat client includes, but does not use or require, the use of an Eclipse feature called Secure Storage. Using this Eclipse feature …

Feb 23, 2024
CVE-2024-22243
8.1 HIGH

Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed …

Feb 23, 2024
CVE-2024-1786
7.5 HIGH

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in D-Link DIR-600M C1 3.08. Affected by this issue is …

Feb 23, 2024
CVE-2024-1784
3.9 LOW

A vulnerability classified as problematic was found in Limbas 5.2.14. Affected by this vulnerability is an unknown functionality of the file main_admin.php. The manipulation of …

Feb 23, 2024
CVE-2024-1783
9.8 CRITICAL

A vulnerability classified as critical has been found in Totolink LR1200GB 9.1.0u.6619_B20230130/9.3.5u.6698_B20230810. Affected is the function loginAuth of the file /cgi-bin/cstecgi.cgi of the component Web …

Feb 23, 2024
CVE-2024-1781
6.3 MEDIUM

A vulnerability was found in Totolink X6000R AX3000 9.4.0cu.852_20230719. It has been rated as critical. This issue affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi …

Feb 23, 2024
CVE-2024-1683
7.3 HIGH

A DLL injection vulnerability exists where an authenticated, low-privileged local attacker could modify application files on the TIE Secure Relay host, which could allow for …

Feb 23, 2024
CVE-2024-25756
8.0 HIGH

A Stack Based Buffer Overflow vulnerability in Tenda AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote attacker to execute arbitrary code via the formWifiBasicSet …

Feb 22, 2024
CVE-2024-25753
8.8 HIGH

Stack Based Buffer Overflow vulnerability in Tenda AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote attacker to execute arbitrary code via the formSetDeviceName function.

Feb 22, 2024
CVE-2024-25748
8.8 HIGH

A Stack Based Buffer Overflow vulnerability in tenda AC9 AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote attacker to execute arbitrary code via the …

Feb 22, 2024
CVE-2024-26152
4.7 MEDIUM

### Summary On all Label Studio versions prior to 1.11.0, data imported via file upload feature is not properly sanitized prior to being rendered within …

Feb 22, 2024
CVE-2024-25746
8.8 HIGH

Stack Based Buffer Overflow vulnerability in Tenda AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote attacker to execute arbitrary code via the add_white_node function.

Feb 22, 2024
CVE-2022-25377
7.5 HIGH

The ACME-challenge endpoint in Appwrite 0.5.0 through 0.12.x before 0.12.2 allows remote attackers to read arbitrary local files via ../ directory traversal. In order to …

Feb 22, 2024
CVE-2024-25369
5.4 MEDIUM

A reflected Cross-Site Scripting (XSS) vulnerability in FUEL CMS 1.5.2allows attackers to run arbitrary code via crafted string after the group_id parameter.

Feb 22, 2024
CVE-2024-1750
5.6 MEDIUM

A vulnerability, which was classified as critical, was found in TemmokuMVC up to 2.3. Affected is the function get_img_url/img_replace in the library lib/images_get_down.php of the …

Feb 22, 2024
CVE-2024-1749
2.4 LOW

A vulnerability, which was classified as problematic, has been found in Bdtask Bhojon Best Restaurant Management Software 2.9. This issue affects some unknown processing of …

Feb 22, 2024
CVE-2024-1748
5.0 MEDIUM

A vulnerability classified as critical was found in van_der_Schaar LAB AutoPrognosis 0.1.21. This vulnerability affects the function load_model_from_file of the component Release Note Handler. The …

Feb 22, 2024
CVE-2024-26151
8.2 HIGH

The `mjml` PyPI package, found at the `FelixSchwarz/mjml-python` GitHub repo, is an unofficial Python port of MJML, a markup language created by Mailjet. All users …

Feb 22, 2024
CVE-2024-26128
5.4 MEDIUM

baserCMS is a website development framework. Prior to version 5.0.9, there is a cross-site scripting vulnerability in the content management feature. Version 5.0.9 contains a …

Feb 22, 2024
CVE-2024-25385
6.2 MEDIUM

An issue in flvmeta v.1.2.2 allows a local attacker to cause a denial of service via the flvmeta/src/flv.c:375:21 function in flv_close.

Feb 22, 2024
CVE-2024-25130
5.4 MEDIUM

Tuleap is an open source suite to improve management of software developments and collaboration. Prior to version 15.5.99.76 of Tuleap Community Edition and prior to …

Feb 22, 2024
CVE-2024-25129
2.7 LOW

The CodeQL CLI repo holds binaries for the CodeQL command line interface (CLI). Prior to version 2.16.3, an XML parser used by the CodeQL CLI …

Feb 22, 2024
CVE-2024-22547
4.7 MEDIUM

WayOS IBR-7150 <17.06.23 is vulnerable to Cross Site Scripting (XSS).

Feb 22, 2024
CVE-2024-25802
9.8 CRITICAL

SKINsoft S-Museum 7.02.3 allows Unrestricted File Upload via the Add Media function. Unlike in CVE-2024-25801, the attack payload is the file content.

Feb 22, 2024
CVE-2024-24817
4.3 MEDIUM

Discourse Calendar adds the ability to create a dynamic calendar in the first post of a topic on the open-source discussion platform Discourse. Prior to …

Feb 22, 2024
CVE-2024-26592
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix UAF issue in ksmbd_tcp_new_connection() The race is between the handling of a new …

Feb 22, 2024
CVE-2024-26591
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix re-attachment branch in bpf_tracing_prog_attach The following case can cause a crash due to …

Feb 22, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.