CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-42834
5.5 MEDIUM

A privacy issue was addressed with improved handling of files. This issue is fixed in watchOS 10.1, macOS Sonoma 14.1, macOS Monterey 12.7.2, macOS Ventura …

Feb 21, 2024
CVE-2023-42823
5.5 MEDIUM

The issue was resolved by sanitizing logging This issue is fixed in watchOS 10.1, macOS Sonoma 14.1, tvOS 17.1, macOS Monterey 12.7.1, iOS 16.7.2 and …

Feb 21, 2024
CVE-2024-22235
6.7 MEDIUM

VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'.

Feb 21, 2024
CVE-2024-25151
5.4 MEDIUM

The Calendar module in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack …

Feb 21, 2024
CVE-2024-1676
5.4 MEDIUM

Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security …

Feb 21, 2024
CVE-2024-1675
8.8 HIGH

Insufficient policy enforcement in Download in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. (Chromium …

Feb 21, 2024
CVE-2024-1674
8.8 HIGH

Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security …

Feb 21, 2024
CVE-2024-1673
8.8 HIGH

Use after free in Accessibility in Google Chrome prior to 122.0.6261.57 allowed a remote attacker who had compromised the renderer process to potentially exploit heap …

Feb 21, 2024
CVE-2024-1672
5.4 MEDIUM

Inappropriate implementation in Content Security Policy in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass content security policy via a crafted HTML …

Feb 21, 2024
CVE-2024-1671
6.5 MEDIUM

Inappropriate implementation in Site Isolation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass content security policy via a crafted HTML page. …

Feb 21, 2024
CVE-2024-1670
8.8 HIGH

Use after free in Mojo in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Feb 21, 2024
CVE-2024-1669
8.8 HIGH

Out of bounds memory access in Blink in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to perform out of bounds memory access via …

Feb 21, 2024
CVE-2024-1562
5.3 MEDIUM

The WooCommerce Google Sheet Connector plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the execute_post_data function …

Feb 21, 2024
CVE-2024-1501
4.7 MEDIUM

The Database Reset plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.22. This is due to missing …

Feb 21, 2024
CVE-2024-26269
9.6 CRITICAL

Cross-site scripting (XSS) vulnerability in the Frontend JS module's portlet.js in Liferay Portal 7.2.0 through 7.4.3.37, and Liferay DXP 7.4 before update 38, 7.3 before …

Feb 21, 2024
CVE-2024-26266
9.0 CRITICAL

Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.2.0 through 7.4.3.13, and older unsupported versions, and Liferay DXP 7.4 before update 10, 7.3 before …

Feb 21, 2024
CVE-2024-25603
9.0 CRITICAL

Stored cross-site scripting (XSS) vulnerability in the Dynamic Data Mapping module's DDMForm in Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP …

Feb 21, 2024
CVE-2024-1631
9.1 CRITICAL

Impact: The library offers a function to generate an ed25519 key pair via Ed25519KeyIdentity.generate with an optional param to provide a 32 byte seed value, …

Feb 21, 2024
CVE-2024-1108
6.5 MEDIUM

The Plugin Groups plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the admin_init() function in all …

Feb 21, 2024
CVE-2023-42498
9.6 CRITICAL

Reflected cross-site scripting (XSS) vulnerability in the Language Override edit screen in Liferay Portal 7.4.3.8 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 5, and …

Feb 21, 2024
CVE-2023-42496
9.6 CRITICAL

Reflected cross-site scripting (XSS) vulnerability on the add assignees to a role page in Liferay Portal 7.3.3 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch …

Feb 21, 2024
CVE-2023-40191
9.0 CRITICAL

Reflected cross-site scripting (XSS) vulnerability in the instance settings for Accounts in Liferay Portal 7.4.3.44 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 6, and …

Feb 21, 2024
CVE-2024-25602
9.0 CRITICAL

Stored cross-site scripting (XSS) vulnerability in Users Admin module's edit user page in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP …

Feb 21, 2024
CVE-2024-25601
9.0 CRITICAL

Stored cross-site scripting (XSS) vulnerability in Expando module's geolocation custom fields in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 …

Feb 21, 2024
CVE-2024-25152
9.0 CRITICAL

Stored cross-site scripting (XSS) vulnerability in Message Board widget in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service …

Feb 21, 2024
CVE-2024-25147
9.6 CRITICAL

Cross-site scripting (XSS) vulnerability in HtmlUtil.escapeJsLink in Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 …

Feb 21, 2024
CVE-2024-24475

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not …

Feb 21, 2024
CVE-2024-0407
6.5 MEDIUM

Certain HP Enterprise LaserJet, and HP LaserJet Managed Printers are potentially vulnerable to information disclosure, when connections made by the device back to services enabled …

Feb 21, 2024
CVE-2023-50923
4.3 MEDIUM

In QUIC in RFC 9000, the Latency Spin Bit specification (section 17.4) does not strictly constrain the bit value when the feature is disabled, which …

Feb 21, 2024
CVE-2024-23758
7.5 HIGH

An issue discovered in Unisys Stealth 5.3.062.0 allows attackers to view sensitive information via the Enterprise ManagementInstaller_msi.log file.

Feb 20, 2024
CVE-2024-26140
4.6 MEDIUM

com.yetanalytics/lrs is the Yet Analytics Core LRS Library. Prior to version 1.2.17 of the LRS library and version 0.7.5 of SQL LRS, a maliciously crafted …

Feb 20, 2024
CVE-2024-26136
7.5 HIGH

kedi ElectronCord is a bot management tool for Discord. Commit aaaeaf4e6c99893827b2eea4dd02f755e1e24041 exposes an account access token in the `config.json` file. Malicious actors could potentially exploit …

Feb 20, 2024
CVE-2024-25428
6.5 MEDIUM

SQL Injection vulnerability in MRCMS v3.1.2 allows attackers to run arbitrary system commands via the status parameter.

Feb 20, 2024
CVE-2024-23830
8.3 HIGH

MantisBT is an open source issue tracker. Prior to version 2.26.1, an unauthenticated attacker who knows a user's email address and username can hijack the …

Feb 20, 2024
CVE-2023-6936
5.3 MEDIUM

In wolfSSL prior to 5.6.6, if callback functions are enabled (via the WOLFSSL_CALLBACKS flag), then a malicious TLS client or network attacker can trigger a …

Feb 20, 2024
CVE-2023-47422
8.8 HIGH

An access control issue in /usr/sbin/httpd in Tenda TX9 V1 V22.03.02.54, Tenda AX3 V3 V16.03.12.11, Tenda AX9 V1 V22.03.01.46, and Tenda AX12 V1 V22.03.01.46 allows …

Feb 20, 2024
CVE-2021-29050
8.8 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in the terms of use page in Liferay Portal before 7.3.6, and Liferay DXP 7.3 before service pack 1, 7.2 …

Feb 20, 2024
CVE-2021-29038
6.3 MEDIUM

Liferay Portal 7.2.0 through 7.3.5, and older unsupported versions, and Liferay DXP 7.3 before fix pack 1, 7.2 before fix pack 17, and older unsupported …

Feb 20, 2024
CVE-2024-25141
9.1 CRITICAL

When ssl was enabled for Mongo Hook, default settings included "allow_insecure" which caused that certificates were not validated. This was unexpected and undocumented. Users are …

Feb 20, 2024
CVE-2023-52439
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: uio: Fix use-after-free in uio_open core-1 core-2 ------------------------------------------------------- uio_unregister_device uio_open idev = idr_find() device_unregister(&idev->dev) put_device(&idev->dev) …

Feb 20, 2024
CVE-2023-52438
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: binder: fix use-after-free in shinker's callback The mmap read lock is used during the shrinker's …

Feb 20, 2024
CVE-2023-52437

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Feb 20, 2024
CVE-2023-52436
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: f2fs: explicitly null-terminate the xattr list When setting an xattr, explicitly null-terminate the xattr list. …

Feb 20, 2024
CVE-2023-49034
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in ProjeQtOr 11.0.2 allows a remote attacker to execute arbitrary code via a crafted script to thecheckvalidHtmlText function in the …

Feb 20, 2024
CVE-2023-46967
6.1 MEDIUM

Cross Site Scripting vulnerability in the sanitize function in Enhancesoft osTicket 1.18.0 allows a remote attacker to escalate privileges via a crafted support ticket.

Feb 20, 2024
CVE-2024-26135
8.3 HIGH

MeshCentral is a full computer management web site. Versions prior to 1.1.21 a cross-site websocket hijacking (CSWSH) vulnerability within the control.ashx endpoint. This component is …

Feb 20, 2024
CVE-2023-52435
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: prevent mss overflow in skb_segment() Once again syzbot is able to crash the kernel …

Feb 20, 2024
CVE-2024-25631
6.1 MEDIUM

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who have enabled an external kvstore and Wireguard transparent encryption, …

Feb 20, 2024
CVE-2024-25630
6.1 MEDIUM

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who are using CRDs to store Cilium state (the default …

Feb 20, 2024
CVE-2024-25260
4.0 MEDIUM

elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.

Feb 20, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.