CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-20725
5.5 MEDIUM

Substance3D - Painter versions 9.1.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Feb 15, 2024
CVE-2024-20724
5.5 MEDIUM

Substance3D - Painter versions 9.1.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Feb 15, 2024
CVE-2024-20723
7.8 HIGH

Substance3D - Painter versions 9.1.1 and earlier are affected by a Buffer Overflow vulnerability that could result in arbitrary code execution in the context of …

Feb 15, 2024
CVE-2024-20722
5.5 MEDIUM

Substance3D - Painter versions 9.1.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Feb 15, 2024
CVE-2024-0390
9.8 CRITICAL

INPRAX "iZZi connect" application on Android contains hard-coded MQTT queue credentials. The same MQTT queue is used by corresponding physical recuperation devices. Exploiting this vulnerability …

Feb 15, 2024
CVE-2023-4539
7.5 HIGH

Use of a hard-coded password for a special database account created during Comarch ERP XL installation allows an attacker to retrieve embedded sensitive data stored …

Feb 15, 2024
CVE-2023-4538
6.2 MEDIUM

The database access credentials configured during installation are stored in a special table, and are encrypted with a shared key, same among all Comarch ERP …

Feb 15, 2024
CVE-2023-4537
7.4 HIGH

Comarch ERP XL client is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypted communication vulnerable to …

Feb 15, 2024
CVE-2024-24386
7.2 HIGH

An issue in VitalPBX v.3.2.4-5 allows an attacker to execute arbitrary code via a crafted payload to the /var/lib/vitalpbx/scripts folder.

Feb 15, 2024
CVE-2024-24256
5.9 MEDIUM

SQL Injection vulnerability in Yonyou space-time enterprise information integration platform v.9.0 and before allows an attacker to obtain sensitive information via the gwbhAIM parameter in …

Feb 15, 2024
CVE-2024-0353
7.8 HIGH

Local privilege escalation vulnerability potentially allowed an attacker to misuse ESET’s file operations to delete files without having proper permission.

Feb 15, 2024
CVE-2024-21727
6.1 MEDIUM

XSS vulnerability in DP Calendar component for Joomla.

Feb 15, 2024
CVE-2024-0708
5.3 MEDIUM

The Landing Page Cat – Coming Soon Page, Maintenance Page & Squeeze Pages plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions …

Feb 15, 2024
CVE-2023-51787
7.5 HIGH

An issue was discovered in Wind River VxWorks 7 22.09 and 23.03. If a VxWorks task or POSIX thread that uses OpenSSL exits, limited per-task …

Feb 15, 2024
CVE-2023-46596
5.1 MEDIUM

Improper input validation in Algosec FireFlow VisualFlow workflow editor via Name, Description and Configuration File field in version A32.20, A32.50, A32.60 permits an attacker to …

Feb 15, 2024
CVE-2022-23093
6.5 MEDIUM

ping reads raw IP packets from the network to process responses in the pr_pack() function. As part of processing a response ping has to reconstruct …

Feb 15, 2024
CVE-2022-23092
8.8 HIGH

The implementation of lib9p's handling of RWALK messages was missing a bounds check needed when unpacking the message contents. The missing check means that the …

Feb 15, 2024
CVE-2022-23091
4.0 MEDIUM

A particular case of memory sharing is mishandled in the virtual memory system. This is very similar to SA-21:08.vm, but with a different root cause. …

Feb 15, 2024
CVE-2022-23090
7.7 HIGH

The aio_aqueue function, used by the lio_listio system call, fails to release a reference to a credential in an error case. An attacker may cause …

Feb 15, 2024
CVE-2021-29640

Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2021.

Feb 15, 2024
CVE-2021-29639

Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2021.

Feb 15, 2024
CVE-2021-29638

Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2021.

Feb 15, 2024
CVE-2021-29637

Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2021.

Feb 15, 2024
CVE-2021-29636

Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2021.

Feb 15, 2024
CVE-2021-29635

Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2021.

Feb 15, 2024
CVE-2021-29634

Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2021.

Feb 15, 2024
CVE-2021-29633

Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2021.

Feb 15, 2024
CVE-2024-25941
3.3 LOW

The jail(2) system call has not limited a visiblity of allocated TTYs (the kern.ttys sysctl). This gives rise to an information leak about processes outside …

Feb 15, 2024
CVE-2024-25940
6.3 MEDIUM

`bhyveload -h <host-path>` may be used to grant loader access to the <host-path> directory tree on the host. Affected versions of bhyveload(8) do not make …

Feb 15, 2024
CVE-2024-25559
4.7 MEDIUM

URL spoofing vulnerability exists in a-blog cms Ver.3.1.0 to Ver.3.1.8. If an attacker sends a specially crafted request, the administrator of the product may be …

Feb 15, 2024
CVE-2024-1488
8.0 HIGH

A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If …

Feb 15, 2024
CVE-2022-23089
4.7 MEDIUM

When dumping core and saving process information, proc_getargv() might return an sbuf which have a sbuf_len() of 0 or -1, which is not properly handled. …

Feb 15, 2024
CVE-2022-23088
9.8 CRITICAL

The 802.11 beacon handling routine failed to validate the length of an IEEE 802.11s Mesh ID before copying it to a heap-allocated buffer. While a …

Feb 15, 2024
CVE-2022-23087
8.8 HIGH

The e1000 network adapters permit a variety of modifications to an Ethernet packet when it is being transmitted. These include the insertion of IP and …

Feb 15, 2024
CVE-2022-23086
7.8 HIGH

Handlers for *_CFG_PAGE read / write ioctls in the mpr, mps, and mpt drivers allocated a buffer of a caller-specified size, but copied to it …

Feb 15, 2024
CVE-2022-23085
8.2 HIGH

A user-provided integer option was passed to nmreq_copyin() without checking if it would overflow. This insufficient bounds checking could lead to kernel memory corruption. On …

Feb 15, 2024
CVE-2022-23084
7.5 HIGH

The total size of the user-provided nmreq to nmreq_copyin() was first computed and then trusted during the copyin. This time-of-check to time-of-use bug could lead …

Feb 15, 2024
CVE-2024-26264
9.8 CRITICAL

EBM Technologies RISWEB's specific query function parameter does not properly restrict user input, and this feature page is accessible without login. This allows remote attackers …

Feb 15, 2024
CVE-2024-26263
5.3 MEDIUM

EBM Technologies RISWEB's specific URL path is not properly controlled by permission, allowing attackers to browse specific pages and query sensitive data without login.

Feb 15, 2024
CVE-2024-26262
8.8 HIGH

EBM Technologies Uniweb/SoliPACS WebServer's query functionality lacks proper restrictions of user input, allowing remote attackers authenticated as regular user to inject SQL commands for reading, …

Feb 15, 2024
CVE-2024-26261
9.8 CRITICAL

The functionality for file download in HGiga OAKlouds' certain modules contains an Arbitrary File Read and Delete vulnerability. Attackers can put file path in specific …

Feb 15, 2024
CVE-2024-26260
9.8 CRITICAL

The functionality for synchronization in HGiga OAKlouds' certain moudules has an OS Command Injection vulnerability, allowing remote attackers to inject system commands within specific request …

Feb 15, 2024
CVE-2024-1523
8.8 HIGH

EC-WEB FS-EZViewer(Web)'s query functionality lacks proper restrictions of user input, allowing remote attackers authenticated as regular user to inject SQL commands for reading, modifying, and …

Feb 15, 2024
CVE-2024-25620
6.4 MEDIUM

Helm is a tool for managing Charts. Charts are packages of pre-configured Kubernetes resources. When either the Helm client or SDK is used to save …

Feb 15, 2024
CVE-2024-24301
8.8 HIGH

Command Injection vulnerability discovered in 4ipnet EAP-767 device v3.42.00 within the web interface of the device allows attackers with valid credentials to inject arbitrary shell …

Feb 14, 2024
CVE-2024-24300
9.8 CRITICAL

4ipnet EAP-767 v3.42.00 is vulnerable to Incorrect Access Control. The device uses the same set of credentials, regardless of how many times a user logs …

Feb 14, 2024
CVE-2023-6138
7.9 HIGH

A potential security vulnerability has been identified in the system BIOS for certain HP Workstation PCs, which might allow escalation of privilege, arbitrary code execution, …

Feb 14, 2024
CVE-2022-48220
6.4 MEDIUM

Potential vulnerabilities have been identified in certain HP Desktop PC products using the HP TamperLock feature, which might allow intrusion detection bypass via a physical …

Feb 14, 2024
CVE-2022-48219
6.4 MEDIUM

Potential vulnerabilities have been identified in certain HP Desktop PC products using the HP TamperLock feature, which might allow intrusion detection bypass via a physical …

Feb 14, 2024
CVE-2024-1471
5.9 MEDIUM

An HTML injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application could modify Repository parameters, which could lead …

Feb 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.