CVE Database

120754+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-48679
5.4 MEDIUM

Stored cross-site scripting (XSS) vulnerability due to missing origin validation in postMessage. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build …

Feb 27, 2024
CVE-2023-48678
5.5 MEDIUM

Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 37391.

Feb 27, 2024
CVE-2024-27508
7.5 HIGH

Atheme 7.2.12 contains a memory leak vulnerability in /atheme/src/crypto-benchmark/main.c.

Feb 27, 2024
CVE-2024-26464

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not …

Feb 27, 2024
CVE-2024-26144
5.3 MEDIUM

Rails is a web-application framework. Starting with version 5.2.0, there is a possible sensitive session information leak in Active Storage. By default, Active Storage sends …

Feb 27, 2024
CVE-2024-26143
6.1 MEDIUM

Rails is a web-application framework. There is a possible XSS vulnerability when using the translation helpers in Action Controller. Applications using translation methods like translate, …

Feb 27, 2024
CVE-2024-26142
7.5 HIGH

Rails is a web-application framework. Starting in version 7.1.0, there is a possible ReDoS vulnerability in the Accept header parsing routines of Action Dispatch. This …

Feb 27, 2024
CVE-2024-25400
9.8 CRITICAL

Subrion CMS 4.2.1 is vulnerable to SQL Injection via ia.core.mysqli.php. NOTE: this is disputed by multiple third parties because it refers to an HTTP request …

Feb 27, 2024
CVE-2024-25399
6.1 MEDIUM

Subrion CMS 4.2.1 is vulnerable to Cross Site Scripting (XSS) via adminer.php.

Feb 27, 2024
CVE-2024-25398
7.5 HIGH

In Srelay (the SOCKS proxy and Relay) v.0.4.8p3, a specially crafted network payload can trigger a denial of service condition and disrupt the service.

Feb 27, 2024
CVE-2024-1923
6.3 MEDIUM

A vulnerability was found in SourceCodester Simple Student Attendance System 1.0 and classified as critical. Affected by this issue is the function delete_class/delete_student of the …

Feb 27, 2024
CVE-2024-1922
3.5 LOW

A vulnerability has been found in SourceCodester Online Job Portal 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the …

Feb 27, 2024
CVE-2024-1403
10.0 CRITICAL

In OpenEdge Authentication Gateway and AdminServer prior to 11.7.19, 12.2.14, 12.8.1 on all platforms supported by the OpenEdge product, an authentication bypass vulnerability has been …

Feb 27, 2024
CVE-2024-27905
9.1 CRITICAL

** UNSUPPORTED WHEN ASSIGNED ** Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Aurora. An endpoint exposing internals to unauthenticated users can …

Feb 27, 2024
CVE-2024-27507
7.5 HIGH

libLAS 1.8.1 contains a memory leak vulnerability in /libLAS/apps/ts2las.cpp.

Feb 27, 2024
CVE-2024-25723
8.8 HIGH

ZenML Server in the ZenML machine learning package before 0.46.7 for Python allows remote privilege escalation because the /api/v1/users/{user_name_or_id}/activate REST API endpoint allows access on …

Feb 27, 2024
CVE-2024-1921
4.7 MEDIUM

A vulnerability, which was classified as critical, was found in osuuu LightPicture up to 1.2.2. Affected is an unknown function of the file /app/controller/Setup.php. The …

Feb 27, 2024
CVE-2024-1423

Rejected reason: Accidental Request

Feb 27, 2024
CVE-2024-1920
5.6 MEDIUM

A vulnerability, which was classified as critical, has been found in osuuu LightPicture up to 1.2.2. This issue affects the function handle of the file …

Feb 27, 2024
CVE-2024-1919
3.5 LOW

A vulnerability classified as problematic was found in SourceCodester Online Job Portal 1.0. This vulnerability affects unknown code of the file /Employer/ManageWalkin.php of the component …

Feb 27, 2024
CVE-2024-0819
7.3 HIGH

Improper initialization of default settings in TeamViewer Remote Client prior version 15.51.5 for Windows, Linux and macOS, allow a low privileged user to elevate privileges …

Feb 27, 2024
CVE-2024-0551
7.1 HIGH

Enable exports of the database and associated exported information of the system via the default user role. The attacked would have to have been granted …

Feb 27, 2024
CVE-2023-51747
7.1 HIGH

Apache James prior to versions 3.8.1 and 3.7.5 is vulnerable to SMTP smuggling. A lenient behaviour in line delimiter handling might create a difference of …

Feb 27, 2024
CVE-2024-1918
4.7 MEDIUM

A vulnerability has been found in Byzoro Smart S42 Management Platform up to 20240219 and classified as critical. Affected by this vulnerability is an unknown …

Feb 27, 2024
CVE-2024-0197
7.8 HIGH

A flaw in the installer for Thales SafeNet Sentinel HASP LDK prior to 9.16 on Windows allows an attacker to escalate their privilege level via …

Feb 27, 2024
CVE-2024-1912
4.3 MEDIUM

The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.7.4. This is due to missing or …

Feb 27, 2024
CVE-2024-1910
4.3 MEDIUM

The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.7.4. This is due to missing or …

Feb 27, 2024
CVE-2024-1909
4.3 MEDIUM

The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.7.4. This is due to missing or …

Feb 27, 2024
CVE-2024-1907
4.3 MEDIUM

The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.7.4. This is due to missing or …

Feb 27, 2024
CVE-2024-1906
4.3 MEDIUM

The Categorify plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.7.4. This is due to missing or …

Feb 27, 2024
CVE-2024-1653
4.3 MEDIUM

The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the categorifyAjaxUpdateFolderPosition in all versions up …

Feb 27, 2024
CVE-2024-1652
4.3 MEDIUM

The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the categorifyAjaxClearCategory function in all versions …

Feb 27, 2024
CVE-2024-1650
4.3 MEDIUM

The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the categorifyAjaxRenameCategory function in all versions …

Feb 27, 2024
CVE-2024-1649
4.3 MEDIUM

The Categorify plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the categorifyAjaxDeleteCategory function in all versions …

Feb 27, 2024
CVE-2023-7016
7.8 HIGH

A flaw in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker to execute code at a SYSTEM level via local …

Feb 27, 2024
CVE-2023-5993
7.8 HIGH

A flaw in the Windows Installer in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker to escalate their privilege level …

Feb 27, 2024
CVE-2021-46937
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/damon/dbgfs: fix 'struct pid' leaks in 'dbgfs_target_ids_write()' DAMON debugfs interface increases the reference counts of …

Feb 27, 2024
CVE-2021-46936
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: fix use-after-free in tw_timer_handler A real world panic issue was found as follow in …

Feb 27, 2024
CVE-2021-46935
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: binder: fix async_free_space accounting for empty parcels In 4.13, commit 74310e06be4d ("android: binder: Move buffer …

Feb 27, 2024
CVE-2021-46934
3.3 LOW

In the Linux kernel, the following vulnerability has been resolved: i2c: validate user data in compat ioctl Wrong user data may cause warning in i2c_transfer(), …

Feb 27, 2024
CVE-2021-46933
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: Clear ffs_eventfd in ffs_data_clear. ffs_data_clear is indirectly called from both ffs_fs_kill_sb and …

Feb 27, 2024
CVE-2021-46932
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Input: appletouch - initialize work before device registration Syzbot has reported warning in __flush_work(). This …

Feb 27, 2024
CVE-2021-46931
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Wrap the tx reporter dump callback to extract the sq Function mlx5e_tx_reporter_dump_sq() casts its …

Feb 27, 2024
CVE-2021-46930
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: mtu3: fix list_head check warning This is caused by uninitialization of list_head. BUG: KASAN: …

Feb 27, 2024
CVE-2021-46929
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sctp: use call_rcu to free endpoint This patch is to delay the endpoint free by …

Feb 27, 2024
CVE-2021-46928
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: parisc: Clear stale IIR value on instruction access rights trap When a trap 7 (Instruction …

Feb 27, 2024
CVE-2021-46927
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nitro_enclaves: Use get_user_pages_unlocked() call to handle mmap assert After commit 5b78ed24e8ec ("mm/pagemap: add mmap_assert_locked() annotations …

Feb 27, 2024
CVE-2021-46926
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: intel-sdw-acpi: harden detection of controller The existing code currently sets a pointer to …

Feb 27, 2024
CVE-2021-46925
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/smc: fix kernel panic caused by race of smc_sock A crash occurs when smc_cdc_tx_handler() tries …

Feb 27, 2024
CVE-2021-46924
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: NFC: st21nfca: Fix memory leak in device probe and remove 'phy->pending_skb' is alloced when device …

Feb 27, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.