CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-26590
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: erofs: fix inconsistent per-file compression format EROFS can select compression algorithms on a per-file basis, …

Feb 22, 2024
CVE-2024-26589
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: bpf: Reject variable offset alu on PTR_TO_FLOW_KEYS For PTR_TO_FLOW_KEYS, check_flow_keys_access() only uses fixed off for …

Feb 22, 2024
CVE-2024-26588
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Prevent out-of-bounds memory access The test_tag test triggers an unhandled page fault: # …

Feb 22, 2024
CVE-2024-26587
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: netdevsim: don't try to destroy PHC on VFs PHC gets initialized in nsim_init_netdevsim(), which …

Feb 22, 2024
CVE-2024-26586
6.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_acl_tcam: Fix stack corruption When tc filters are first added to a net device, …

Feb 22, 2024
CVE-2023-52452
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix accesses to uninit stack slots Privileged programs are supposed to be able to …

Feb 22, 2024
CVE-2023-52451
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: powerpc/pseries/memhp: Fix access beyond end of drmem array dlpar_memory_remove_by_index() may access beyond the bounds of …

Feb 22, 2024
CVE-2023-52450
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: perf/x86/intel/uncore: Fix NULL pointer dereference issue in upi_fill_topology() Get logical socket id instead of physical …

Feb 22, 2024
CVE-2023-52449
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mtd: Fix gluebi NULL pointer dereference caused by ftl notifier If both ftl.ko and gluebi.ko …

Feb 22, 2024
CVE-2023-52448
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: gfs2: Fix kernel NULL pointer dereference in gfs2_rgrp_dump Syzkaller has reported a NULL pointer dereference …

Feb 22, 2024
CVE-2023-52447
6.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: Defer the free of inner map when necessary When updating or deleting an inner …

Feb 22, 2024
CVE-2023-52446
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix a race condition between btf_put() and map_free() When running `./test_progs -j` in my …

Feb 22, 2024
CVE-2023-52445
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: media: pvrusb2: fix use after free on context disconnection Upon module load, a kthread is …

Feb 22, 2024
CVE-2023-52444
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid dirent corruption As Al reported in link[1]: f2fs_rename() ... if (old_dir …

Feb 22, 2024
CVE-2023-52443
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: apparmor: avoid crash when parsed profile name is empty When processing a packed profile in …

Feb 22, 2024
CVE-2023-52161
7.5 HIGH

The Access Point functionality in eapol_auth_key_handle in eapol.c in iNet wireless daemon (IWD) before 2.14 allows attackers to gain unauthorized access to a protected Wi-Fi …

Feb 22, 2024
CVE-2023-52160
6.5 MEDIUM

The implementation of PEAP in wpa_supplicant through 2.10 allows authentication bypass. For a successful attack, wpa_supplicant must be configured to not verify the network's TLS …

Feb 22, 2024
CVE-2024-25828
4.9 MEDIUM

cmseasy V7.7.7.9 has an arbitrary file deletion vulnerability in lib/admin/template_admin.php.

Feb 22, 2024
CVE-2023-51653
9.8 CRITICAL

Hertzbeat is a real-time monitoring system. In the implementation of `JmxCollectImpl.java`, `JMXConnectorFactory.connect` is vulnerable to JNDI injection. The corresponding interface is `/api/monitor/detect`. If there is …

Feb 22, 2024
CVE-2023-51389
9.8 CRITICAL

Hertzbeat is a real-time monitoring system. At the interface of `/define/yml`, SnakeYAML is used as a parser to parse yml content, but no security configuration …

Feb 22, 2024
CVE-2023-51388
9.8 CRITICAL

Hertzbeat is a real-time monitoring system. In `CalculateAlarm.java`, `AviatorEvaluator` is used to directly execute the expression function, and no security policy is configured, resulting in …

Feb 22, 2024
CVE-2024-26284
6.1 MEDIUM

Utilizing a 302 redirect, an attacker could have conducted a Universal Cross-Site Scripting (UXSS) on a victim website, if the victim had a link to …

Feb 22, 2024
CVE-2024-26283
7.8 HIGH

An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external URL with a custom Firefox scheme. …

Feb 22, 2024
CVE-2024-26282
7.1 HIGH

Using an AMP url with a canonical element, an attacker could have executed JavaScript from an opened bookmarked page. This vulnerability affects Firefox for iOS …

Feb 22, 2024
CVE-2024-26281
4.7 MEDIUM

Upon scanning a JavaScript URI with the QR code scanner, an attacker could have executed unauthorized scripts on the current top origin sites in the …

Feb 22, 2024
CVE-2024-25851
8.0 HIGH

Netis WF2780 v2.1.40144 was discovered to contain a command injection vulnerability via the config_sequence parameter in other_para of cgitest.cgi.

Feb 22, 2024
CVE-2024-25850
9.8 CRITICAL

Netis WF2780 v2.1.40144 was discovered to contain a command injection vulnerability via the wps_ap_ssid5g parameter

Feb 22, 2024
CVE-2024-1563
8.1 HIGH

An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external URL with a custom Firefox scheme …

Feb 22, 2024
CVE-2023-51450
5.6 MEDIUM

baserCMS is a website development framework. Prior to version 5.0.9, there is an OS Command Injection vulnerability in the site search feature of baserCMS. Version …

Feb 22, 2024
CVE-2023-44379
6.1 MEDIUM

baserCMS is a website development framework. Prior to version 5.0.9, there is a cross-site scripting vulnerability in the site search feature. Version 5.0.9 contains a …

Feb 22, 2024
CVE-2024-26445
6.1 MEDIUM

flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/delete_place.php

Feb 22, 2024
CVE-2024-26352
8.8 HIGH

flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/add_places.php

Feb 22, 2024
CVE-2024-26351
6.1 MEDIUM

flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/update_place.php

Feb 22, 2024
CVE-2024-26350
8.8 HIGH

flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/update_contact_form_settings.php

Feb 22, 2024
CVE-2024-26349
4.3 MEDIUM

flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/delete_translation.php

Feb 22, 2024
CVE-2024-25876
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in the Header module of Enhavo CMS v0.13.1 allows attackers to execute arbitrary web scripts or HTML via a crafted …

Feb 22, 2024
CVE-2024-25875
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in the Header module of Enhavo CMS v0.13.1 allows attackers to execute arbitrary web scripts or HTML via a crafted …

Feb 22, 2024
CVE-2024-25874
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability in the New/Edit Article module of Enhavo CMS v0.13.1 allows attackers to execute arbitrary web scripts or HTML via a …

Feb 22, 2024
CVE-2024-25873
5.4 MEDIUM

Enhavo v0.13.1 was discovered to contain an HTML injection vulnerability in the Author text field under the Blockquote module. This vulnerability allows attackers to execute …

Feb 22, 2024
CVE-2024-23094
8.8 HIGH

Flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /cover/addons/info_media_gallery/action/edit_addon_post.php

Feb 22, 2024
CVE-2023-3966
7.5 HIGH

A flaw was found in Open vSwitch where multiple versions are vulnerable to crafted Geneve packets, which may result in a denial of service and …

Feb 22, 2024
CVE-2024-26287

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Feb 22, 2024
CVE-2024-25021
8.4 HIGH

IBM AIX 7.3, VIOS 4.1's Perl implementation could allow a non-privileged local user to exploit a vulnerability to execute arbitrary commands. IBM X-Force ID: 281320.

Feb 22, 2024
CVE-2024-1104
7.5 HIGH

An unauthenticated remote attacker can bypass the brute force prevention mechanism and disturb the webservice for all users.

Feb 22, 2024
CVE-2024-0220
8.3 HIGH

B&R Automation Studio Upgrade Service and B&R Technology Guarding use insufficient cryptography for communication to the upgrade and the licensing servers. A network-based attacker could …

Feb 22, 2024
CVE-2024-26578
5.9 MEDIUM

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1. Repeated submission during registration resulted …

Feb 22, 2024
CVE-2024-23349
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1. XSS attack when user enters …

Feb 22, 2024
CVE-2024-22393
9.1 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1. Pixel Flood Attack by uploading large pixel files …

Feb 22, 2024
CVE-2023-29181
8.8 HIGH

A use of externally-controlled format string in Fortinet FortiOS 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.14, 6.0.0 through 6.0.16, FortiProxy …

Feb 22, 2024
CVE-2023-29180
7.5 HIGH

A null pointer dereference in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.14, 6.0.0 through 6.0.16, FortiProxy 7.2.0 …

Feb 22, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.