CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-25443
7.8 HIGH

An issue in the HuginBase::ImageVariable<double>::linkWith function of Hugin v2022.0.0 allows attackers to cause a heap-use-after-free via parsing a crafted image.

Feb 9, 2024
CVE-2024-25442
7.8 HIGH

An issue in the HuginBase::PanoramaMemento::loadPTScript function of Hugin v2022.0.0 allows attackers to cause a heap buffer overflow via parsing a crafted image.

Feb 9, 2024
CVE-2024-24776
3.1 LOW

Mattermost fails to check the required permissions in the POST /api/v4/channels/stats/member_count API resulting in channel member counts being leaked to a user without permissions.

Feb 9, 2024
CVE-2024-24774
3.4 LOW

Mattermost Jira Plugin handling subscriptions fails to check the security level of an incoming issue or limit it based on the user who created the …

Feb 9, 2024
CVE-2024-23319
3.5 LOW

Mattermost Jira Plugin fails to protect against logout CSRF allowing an attacker to post a specially crafted message that would disconnect a user's Jira connection …

Feb 9, 2024
CVE-2024-25318
8.8 HIGH

Code-projects Hotel Managment System 1.0 allows SQL Injection via the 'pid' parameter in Hotel/admin/print.php?pid=2.

Feb 9, 2024
CVE-2024-25316
9.8 CRITICAL

Code-projects Hotel Managment System 1.0 allows SQL Injection via the 'eid' parameter in Hotel/admin/usersettingdel.php?eid=2.

Feb 9, 2024
CVE-2024-25315
9.8 CRITICAL

Code-projects Hotel Managment System 1.0, allows SQL Injection via the 'rid' parameter in Hotel/admin/roombook.php?rid=2.

Feb 9, 2024
CVE-2024-25314
9.8 CRITICAL

Code-projects Hotel Managment System 1.0, allows SQL Injection via the 'sid' parameter in Hotel/admin/show.php?sid=2.

Feb 9, 2024
CVE-2024-25310
8.8 HIGH

Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'id' parameter at "School/delete.php?id=5."

Feb 9, 2024
CVE-2024-25307
9.8 CRITICAL

Code-projects Cinema Seat Reservation System 1.0 allows SQL Injection via the 'id' parameter at "/Cinema-Reservation/booking.php?id=1."

Feb 9, 2024
CVE-2024-25302
9.8 CRITICAL

Sourcecodester Event Student Attendance System 1.0, allows SQL Injection via the 'student' parameter.

Feb 9, 2024
CVE-2023-6677
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Oduyo Financial Technology Online Collection allows SQL Injection.This issue affects Online …

Feb 9, 2024
CVE-2024-25313
8.8 HIGH

Code-projects Simple School Managment System 1.0 allows Authentication Bypass via the username and password parameters at School/teacher_login.php.

Feb 9, 2024
CVE-2024-25312
8.8 HIGH

Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'id' parameter at "School/sub_delete.php?id=5."

Feb 9, 2024
CVE-2024-25309
8.8 HIGH

Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'pass' parameter at School/teacher_login.php.

Feb 9, 2024
CVE-2024-25308
8.8 HIGH

Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'name' parameter at School/teacher_login.php.

Feb 9, 2024
CVE-2024-25306
8.8 HIGH

Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'aname' parameter at "School/index.php".

Feb 9, 2024
CVE-2024-25305
8.8 HIGH

Code-projects Simple School Managment System 1.0 allows Authentication Bypass via the username and password parameters at School/index.php.

Feb 9, 2024
CVE-2024-25304
8.8 HIGH

Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'apass' parameter at "School/index.php."

Feb 9, 2024
CVE-2023-6724
8.8 HIGH

Authorization Bypass Through User-Controlled Key vulnerability in Software Engineering Consultancy Machine Equipment Limited Company Hearing Tracking System allows Authentication Abuse.This issue affects Hearing Tracking System: …

Feb 9, 2024
CVE-2024-25679
6.5 MEDIUM

In PQUIC before 5bde5bb, retention of unused initial encryption keys allows attackers to disrupt a connection with a PSK configuration by sending a CONNECTION_CLOSE frame …

Feb 9, 2024
CVE-2024-25678
9.8 CRITICAL

In LiteSpeed QUIC (LSQUIC) Library before 4.0.4, DCID validation is mishandled.

Feb 9, 2024
CVE-2024-25677
8.8 HIGH

In Min before 1.31.0, local files are not correctly treated as unique security origins, which allows them to improperly request cross-origin resources. For example, a …

Feb 9, 2024
CVE-2024-25675
9.8 CRITICAL

An issue was discovered in MISP before 2.4.184. A client does not need to use POST to start an export generation process. This is related …

Feb 9, 2024
CVE-2024-25674
9.8 CRITICAL

An issue was discovered in MISP before 2.4.184. Organisation logo upload is insecure because of a lack of checks for the file extension and MIME …

Feb 9, 2024
CVE-2024-22119
5.5 MEDIUM

The cause of vulnerability is improper validation of form input field “Name” on Graph page in Items section.

Feb 9, 2024
CVE-2024-21762
9.8 CRITICAL KEV

A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, …

Feb 9, 2024
CVE-2024-24308
9.8 CRITICAL

SQL Injection vulnerability in Boostmyshop (boostmyshopagent) module for Prestashop versions 1.1.9 and before, allows remote attackers to escalate privileges and obtain sensitive information via changeOrderCarrier.php, …

Feb 9, 2024
CVE-2024-23749
7.8 HIGH

KiTTY versions 0.76.1.13 and before is vulnerable to command injection via the filename variable, occurs due to insufficient input sanitization and validation, failure to escape …

Feb 9, 2024
CVE-2023-50026
9.8 CRITICAL

SQL injection vulnerability in Presta Monster "Multi Accessories Pro" (hsmultiaccessoriespro) module for PrestaShop versions 5.1.1 and before, allows remote attackers to escalate privileges and obtain …

Feb 9, 2024
CVE-2023-46350
9.8 CRITICAL

SQL injection vulnerability in InnovaDeluxe "Manufacturer or supplier alphabetical search" (idxrmanufacturer) module for PrestaShop versions 2.0.4 and before, allows remote attackers to escalate privileges and …

Feb 9, 2024
CVE-2024-25004
7.8 HIGH

KiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the username, occurs due to insufficient bounds checking and input sanitization (at …

Feb 9, 2024
CVE-2024-25003
7.8 HIGH

KiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the hostname, occurs due to insufficient bounds checking and input sanitization. This …

Feb 9, 2024
CVE-2024-0229
7.8 HIGH

An out-of-bounds memory access flaw was found in the X.Org server. This issue can be triggered when a device frozen by a sync grab is …

Feb 9, 2024
CVE-2023-39683
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in EasyEmail v.4.12.2 and before allows a local attacker to execute arbitrary code via the user input parameter(s). NOTE: Researcher …

Feb 9, 2024
CVE-2023-31506
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability in Grav versions 1.7.44 and before, allows remote authenticated attackers to execute arbitrary web scripts or HTML via the onmouseover …

Feb 9, 2024
CVE-2024-1122
5.3 MEDIUM

The Event Manager, Events Calendar, Events Tickets for WooCommerce – Eventin plugin for WordPress is vulnerable to unauthorized access of data due to a missing …

Feb 9, 2024
CVE-2024-0842
7.5 HIGH

The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including, 1.2.6. …

Feb 9, 2024
CVE-2024-0657
4.4 MEDIUM

The Internal Link Juicer: SEO Auto Linker for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings such as 'ilj_settings_field_links_per_page' in …

Feb 9, 2024
CVE-2023-51761
8.3 HIGH

In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could bypass authentication and acquire admin capabilities.

Feb 9, 2024
CVE-2023-49716
6.9 MEDIUM

In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an authenticated user with network access could run arbitrary commands from a remote computer.

Feb 9, 2024
CVE-2023-46687
9.8 CRITICAL

In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could execute arbitrary commands in root context from a remote computer.

Feb 9, 2024
CVE-2023-43609
6.9 MEDIUM

In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could obtain access to sensitive information or cause a denial-of-service condition.

Feb 9, 2024
CVE-2024-24819
5.3 MEDIUM

icingaweb2-module-incubator is a working project of bleeding edge Icinga Web 2 libraries. In affected versions the class `gipfl\Web\Form` is the base for various concrete form …

Feb 9, 2024
CVE-2024-23639
5.1 MEDIUM

Micronaut Framework is a modern, JVM-based, full stack Java framework designed for building modular, easily testable JVM applications with support for Java, Kotlin and the …

Feb 9, 2024
CVE-2024-22332
6.5 MEDIUM

The IBM Integration Bus for z/OS 10.1 through 10.1.0.2 AdminAPI is vulnerable to a denial of service due to file system exhaustion. IBM X-Force ID: …

Feb 9, 2024
CVE-2024-22318
5.1 MEDIUM

IBM i Access Client Solutions (ACS) 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.4 is vulnerable to NT LAN Manager (NTLM) hash disclosure by an attacker …

Feb 9, 2024
CVE-2024-1353
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in PHPEMS up to 1.0. Affected by this issue is the function index of the …

Feb 9, 2024
CVE-2023-45191
7.5 HIGH

IBM Engineering Lifecycle Optimization 7.0.2 and 7.0.3 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM …

Feb 9, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.