CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-42791
8.8 HIGH

A relative path traversal in Fortinet FortiManager version 7.4.0 and 7.2.0 through 7.2.3 and 7.0.0 through 7.0.8 and 6.4.0 through 6.4.12 and 6.2.0 through 6.2.11 …

Feb 20, 2024
CVE-2024-26581
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_rbtree: skip end interval element from gc rbtree lazy gc on insert might collect …

Feb 20, 2024
CVE-2024-26267
5.3 MEDIUM

In Liferay Portal 7.2.0 through 7.4.3.25, and older unsupported versions, and Liferay DXP 7.4 before update 26, 7.3 before update 5, 7.2 before fix pack …

Feb 20, 2024
CVE-2024-26265
5.0 MEDIUM

The Image Uploader module in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions, and Liferay DXP 7.4 before update 16, 7.3 before update 4, …

Feb 20, 2024
CVE-2024-25610
9.0 CRITICAL

In Liferay Portal 7.2.0 through 7.4.3.12, and older unsupported versions, and Liferay DXP 7.4 before update 9, 7.3 before update 4, 7.2 before fix pack …

Feb 20, 2024
CVE-2024-1661
2.5 LOW

A vulnerability classified as problematic was found in Totolink X6000R 9.4.0cu.852_B20230719. Affected by this vulnerability is an unknown functionality of the file /etc/shadow. The manipulation …

Feb 20, 2024
CVE-2023-52433
4.4 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_rbtree: skip sync GC for new elements in this transaction New elements in this …

Feb 20, 2024
CVE-2024-24794
8.1 HIGH

A use-after-free vulnerability exists in the DICOM Element Parsing as implemented in Imaging Data Commons libdicom 1.0.5. A specially crafted DICOM file can cause premature …

Feb 20, 2024
CVE-2024-24793
8.1 HIGH

A use-after-free vulnerability exists in the DICOM Element Parsing as implemented in Imaging Data Commons libdicom 1.0.5. A specially crafted DICOM file can cause premature …

Feb 20, 2024
CVE-2023-7245
7.8 HIGH

The nodejs framework in OpenVPN Connect 3.0 through 3.4.3 (Windows)/3.4.7 (macOS) was not properly configured, which allows a local user to execute arbitrary code within …

Feb 20, 2024
CVE-2024-25609
6.1 MEDIUM

HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.12, and older unsupported versions, and Liferay DXP 7.4 before update 9, 7.3 service pack 3, 7.2 fix pack …

Feb 20, 2024
CVE-2024-25608
6.1 MEDIUM

HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.18, and older unsupported versions, and Liferay DXP 7.4 before update 19, 7.3 before update 4, 7.2 before fix …

Feb 20, 2024
CVE-2024-25607
8.1 HIGH

The default password hashing algorithm (PBKDF2-HMAC-SHA1) in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions, and Liferay DXP 7.4 before update 16, 7.3 before …

Feb 20, 2024
CVE-2023-51770
7.5 HIGH

Arbitrary File Read Vulnerability in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.1. We recommend users to upgrade Apache DolphinScheduler to version 3.2.1, which …

Feb 20, 2024
CVE-2023-50270
6.5 MEDIUM

Session Fixation Apache DolphinScheduler before version 3.2.0, which session is still valid after the password change. Users are recommended to upgrade to version 3.2.1, which …

Feb 20, 2024
CVE-2023-49250
7.3 HIGH

Because the HttpUtils class did not verify certificates, an attacker that could perform a Man-in-the-Middle (MITM) attack on outgoing https connections could impersonate the server. …

Feb 20, 2024
CVE-2023-49109
9.8 CRITICAL

Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.1. We recommend users to upgrade Apache DolphinScheduler to version 3.2.1, …

Feb 20, 2024
CVE-2024-25606
8.0 HIGH

XXE vulnerability in Liferay Portal 7.2.0 through 7.4.3.7, and older unsupported versions, and Liferay DXP 7.4 before update 4, 7.3 before update 12, 7.2 before …

Feb 20, 2024
CVE-2024-25605
5.3 MEDIUM

The Journal module in Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before service pack 3, 7.2 before fix …

Feb 20, 2024
CVE-2024-25604
6.5 MEDIUM

Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before service pack 3, 7.2 before fix pack 17, and older …

Feb 20, 2024
CVE-2024-1608
9.1 CRITICAL

In OPPO Usercenter Credit SDK, there's a possible escalation of privilege due to loose permission check, This could lead to application internal information leak w/o …

Feb 20, 2024
CVE-2024-25974
5.4 MEDIUM

The Frentix GmbH OpenOlat LMS is affected by stored a Cross-Site Scripting (XSS) vulnerability. It is possible to upload files within the Media Center of …

Feb 20, 2024
CVE-2024-25973
5.4 MEDIUM

The Frentix GmbH OpenOlat LMS is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities. An attacker with rights to create or edit groups can create …

Feb 20, 2024
CVE-2024-25150
4.3 MEDIUM

Information disclosure vulnerability in the Control Panel in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before update 4, 7.2 …

Feb 20, 2024
CVE-2024-25149
5.4 MEDIUM

Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported …

Feb 20, 2024
CVE-2024-22234
7.4 HIGH

In Spring Security, versions 6.1.x prior to 6.1.7 and versions 6.2.x prior to 6.2.2, an application is vulnerable to broken access control when it directly …

Feb 20, 2024
CVE-2023-44308
6.1 MEDIUM

Open redirect vulnerability in adaptive media administration page in Liferay DXP 2023.Q3 before patch 6, and 7.4 GA through update 92 allows remote attackers to …

Feb 20, 2024
CVE-2023-5190
6.1 MEDIUM

Open redirect vulnerability in the Countries Management’s edit region page in Liferay Portal 7.4.3.45 through 7.4.3.101, and Liferay DXP 2023.Q3 before patch 6, and 7.4 …

Feb 20, 2024
CVE-2022-45320
6.3 MEDIUM

Liferay Portal before 7.4.3.16 and Liferay DXP before 7.2 fix pack 19, 7.3 before update 6, and 7.4 before update 16 allow remote authenticated users …

Feb 20, 2024
CVE-2024-1559
6.5 MEDIUM

The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'll_reciprocal' parameter in all versions up to, and including, 7.6 due …

Feb 20, 2024
CVE-2024-1510
6.4 MEDIUM

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's su_tooltip shortcode in all versions up …

Feb 20, 2024
CVE-2023-6764
8.1 HIGH

A format string vulnerability in a function of the IPSec VPN feature in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1, USG …

Feb 20, 2024
CVE-2024-22019
7.5 HIGH

A vulnerability in Node.js HTTP servers allows an attacker to send a specially crafted HTTP request with chunked encoding, leading to resource exhaustion and denial …

Feb 20, 2024
CVE-2024-21896
9.8 CRITICAL

The permission model protects itself against path traversal attacks by calling path.resolve() on any paths given by the user. If the path is to be …

Feb 20, 2024
CVE-2024-21892
7.8 HIGH

On Linux, Node.js ignores certain environment variables if those may have been set by an unprivileged user while the process is running with elevated privileges …

Feb 20, 2024
CVE-2024-21891
8.8 HIGH

Node.js depends on multiple built-in utility functions to normalize paths provided to node:fs functions, which can be overwitten with user-defined implementations leading to filesystem permission …

Feb 20, 2024
CVE-2024-21890
6.5 MEDIUM

The Node.js Permission Model does not clarify in the documentation that wildcards should be only used as the last character of a file path. For …

Feb 20, 2024
CVE-2024-0715
7.6 HIGH

Expression Language Injection vulnerability in Hitachi Global Link Manager on Windows allows Code Injection.This issue affects Hitachi Global Link Manager: before 8.8.7-03.

Feb 20, 2024
CVE-2023-6399
5.7 MEDIUM

A format string vulnerability in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1, USG FLEX series firmware versions from 4.50 through 5.37 …

Feb 20, 2024
CVE-2023-6398
7.2 HIGH

A post-authentication command injection vulnerability in the file upload binary in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1, USG FLEX series …

Feb 20, 2024
CVE-2023-6397
6.5 MEDIUM

A null pointer dereference vulnerability in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1 and USG FLEX series firmware versions from 4.50 …

Feb 20, 2024
CVE-2024-1648
7.5 HIGH

electron-pdf version 20.0.0 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the HTML content …

Feb 20, 2024
CVE-2024-1647
7.5 HIGH

Pyhtml2pdf version 0.0.6 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the HTML content …

Feb 20, 2024
CVE-2024-1651
10.0 CRITICAL

Torrentpier version 2.4.1 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to insecure deserialization.

Feb 20, 2024
CVE-2024-1644
9.9 CRITICAL

Suite CRM version 7.14.2 allows including local php files. This is possible because the application is vulnerable to LFI.

Feb 20, 2024
CVE-2024-1297
7.2 HIGH

Loomio version 2.22.0 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to OS Command Injection.

Feb 20, 2024
CVE-2022-48625
7.5 HIGH

Yealink Config Encrypt Tool add RSA before 1.2 has a built-in RSA key pair, and thus there is a risk of decryption by an adversary.

Feb 20, 2024
CVE-2024-26134
7.5 HIGH

cbor2 provides encoding and decoding for the Concise Binary Object Representation (CBOR) (RFC 8949) serialization format. Starting in version 5.5.1 and prior to version 5.6.2, …

Feb 19, 2024
CVE-2024-26129
5.8 MEDIUM

PrestaShop is an open-source e-commerce platform. Starting in version 8.1.0 and prior to version 8.1.4, PrestaShop is vulnerable to path disclosure in a JavaScript variable. …

Feb 19, 2024
CVE-2024-1638
8.2 HIGH

The documentation specifies that the BT_GATT_PERM_READ_LESC and BT_GATT_PERM_WRITE_LESC defines for a Bluetooth characteristic: Attribute read/write permission with LE Secure Connection encryption. If set, requires that …

Feb 19, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.