CVE Database

120754+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-25751
9.8 CRITICAL

A Stack Based Buffer Overflow vulnerability in Tenda AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote attacker to execute arbitrary code via the fromSetSysTime …

Feb 26, 2024
CVE-2024-25248
9.8 CRITICAL

SQL Injection vulnerability in the orderGoodsDelivery() function in Niushop B2B2C V5 allows attackers to run arbitrary SQL commands via the order_id parameter.

Feb 26, 2024
CVE-2023-36237
8.8 HIGH

Cross Site Request Forgery vulnerability in Bagisto before v.1.5.1 allows an attacker to execute arbitrary code via a crafted HTML script.

Feb 26, 2024
CVE-2024-27089

Rejected reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not in the allowed scope of that CNA's CVE ID …

Feb 26, 2024
CVE-2024-26149
3.7 LOW

Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. If an excessively large value is specified as the starting index for an …

Feb 26, 2024
CVE-2024-24564
3.7 LOW

Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. When using the built-in `extract32(b, start)`, if the `start` index provided has for …

Feb 26, 2024
CVE-2024-24528

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not …

Feb 26, 2024
CVE-2024-1899
5.3 MEDIUM

An issue in the anchors subparser of Showdownjs versions <= 2.1.0 could allow a remote attacker to cause denial of service conditions.

Feb 26, 2024
CVE-2024-27084

Rejected reason: This CVE is a duplicate of CVE-2024-1631.

Feb 26, 2024
CVE-2024-26455
7.5 HIGH

fluent-bit 2.2.2 contains a Use-After-Free vulnerability in /fluent-bit/plugins/custom_calyptia/calyptia.c.

Feb 26, 2024
CVE-2024-25770
4.3 MEDIUM

libming 0.4.8 contains a memory leak vulnerability in /libming/src/actioncompiler/listaction.c.

Feb 26, 2024
CVE-2024-25768
7.5 HIGH

OpenDMARC 1.4.2 contains a null pointer dereference vulnerability in /OpenDMARC/libopendmarc/opendmarc_policy.c.

Feb 26, 2024
CVE-2023-52474
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: IB/hfi1: Fix bugs with non-PAGE_SIZE-end multi-iovec user SDMA requests hfi1 user SDMA request processing has …

Feb 26, 2024
CVE-2021-46906
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: HID: usbhid: fix info leak in hid_submit_ctrl In hid_submit_ctrl(), the way of calculating the report …

Feb 26, 2024
CVE-2020-36775
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid potential deadlock Using f2fs_trylock_op() in f2fs_write_compressed_pages() to avoid potential deadlock like …

Feb 26, 2024
CVE-2019-25162
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: i2c: Fix a potential use after free Free the adap structure only after we are …

Feb 26, 2024
CVE-2019-25161

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Feb 26, 2024
CVE-2019-25160
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: netlabel: fix out-of-bounds memory accesses There are two array out-of-bounds memory accesses, one in cipso_v4_map_lvl_valid(), …

Feb 26, 2024
CVE-2024-27088
0.0 NONE

es5-ext contains ECMAScript 5 extensions. Passing functions with very long names or complex default argument names into `function#copy` or `function#toStringTokens` may cause the script to …

Feb 26, 2024
CVE-2024-27087
4.6 MEDIUM

Kirby is a content management system. The new link field introduced in Kirby 4 allows several different link types that each validate the entered link …

Feb 26, 2024
CVE-2024-27081
7.2 HIGH

ESPHome is a system to control your ESP8266/ESP32. A security misconfiguration in the edit configuration file API in the dashboard component of ESPHome version 2023.12.9 …

Feb 26, 2024
CVE-2024-25767
6.5 MEDIUM

nanomq 0.21.2 contains a Use-After-Free vulnerability in /nanomq/nng/src/core/socket.c.

Feb 26, 2024
CVE-2024-24402
9.8 CRITICAL

An issue in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted script to the /usr/local/nagios/bin/npcd component.

Feb 26, 2024
CVE-2024-24401
9.8 CRITICAL

SQL Injection vulnerability in Nagios XI 2024R1.01 allows a remote attacker to execute arbitrary code via a crafted payload to the monitoringwizard.php component.

Feb 26, 2024
CVE-2024-27456
9.1 CRITICAL

rack-cors (aka Rack CORS Middleware) 2.0.1 has 0666 permissions for the .rb files.

Feb 26, 2024
CVE-2024-27455
9.1 CRITICAL

In the Bentley ALIM Web application, certain configuration settings can cause exposure of a user's ALIM session token when the user attempts to download files. …

Feb 26, 2024
CVE-2024-27454
7.5 HIGH

orjson.loads in orjson before 3.9.15 does not limit recursion for deeply nested JSON documents.

Feb 26, 2024
CVE-2024-27447
9.8 CRITICAL

pretix before 2024.1.1 mishandles file validation.

Feb 26, 2024
CVE-2024-27444
9.8 CRITICAL

langchain_experimental (aka LangChain Experimental) in LangChain before 0.1.8 allows an attacker to bypass the CVE-2023-44467 fix and execute arbitrary code via the __import__, __subclasses__, __builtins__, …

Feb 26, 2024
CVE-2024-27359
7.5 HIGH

Certain WithSecure products allow a Denial of Service because the engine scanner can go into an infinite loop when processing an archive file. This affects …

Feb 26, 2024
CVE-2024-27350
5.9 MEDIUM

Amazon Fire OS 7 before 7.6.6.9 and 8 before 8.1.0.3 allows Fire TV applications to establish local ADB (Android Debug Bridge) connections. NOTE: some third …

Feb 26, 2024
CVE-2024-26606
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: binder: signal epoll threads of self-work In (e)poll mode, threads often depend on I/O events …

Feb 26, 2024
CVE-2024-26605
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: PCI/ASPM: Fix deadlock when enabling ASPM A last minute revert in 6.7-final introduced a potential …

Feb 26, 2024
CVE-2024-26604
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Revert "kobject: Remove redundant checks for whether ktype is NULL" This reverts commit 1b28cb81dab7c1eedc6034206f4e8d644046ad31. It …

Feb 26, 2024
CVE-2024-26603
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: x86/fpu: Stop relying on userspace for info to fault in xsave buffer Before this change, …

Feb 26, 2024
CVE-2024-26602
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sched/membarrier: reduce the ability to hammer on sys_membarrier On some systems, sys_membarrier can be very …

Feb 26, 2024
CVE-2024-26601
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ext4: regenerate buddy after block freeing failed if under fc replay This mostly reverts commit …

Feb 26, 2024
CVE-2024-26600
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: phy: ti: phy-omap-usb2: Fix NULL pointer dereference for SRP If the external phy working together …

Feb 26, 2024
CVE-2024-26468
6.1 MEDIUM

A DOM based cross-site scripting (XSS) vulnerability in the component index.html of jstrieb/urlpages before commit 035b647 allows attackers to execute arbitrary Javascript via sending a …

Feb 26, 2024
CVE-2024-26467
6.1 MEDIUM

A DOM based cross-site scripting (XSS) vulnerability in the component generator.html of tabatkins/railroad-diagrams before commit ea9a123 allows attackers to execute arbitrary Javascript via sending a …

Feb 26, 2024
CVE-2024-26466
6.1 MEDIUM

A DOM based cross-site scripting (XSS) vulnerability in the component /dom/ranges/Range-test-iframe.html of web-platform-tests/wpt before commit 938e843 allows attackers to execute arbitrary Javascript via sending a …

Feb 26, 2024
CVE-2024-26465
6.1 MEDIUM

A DOM based cross-site scripting (XSS) vulnerability in the component /beep/Beep.Instrument.js of stewdio beep.js before commit ef22ad7 allows attackers to execute arbitrary Javascript via sending …

Feb 26, 2024
CVE-2024-25925
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in SYSBASICS WooCommerce Easy Checkout Field Editor, Fees & Discounts.This issue affects WooCommerce Easy Checkout Field Editor, …

Feb 26, 2024
CVE-2024-25913
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Skymoonlabs MoveTo.This issue affects MoveTo: from n/a through 6.2.

Feb 26, 2024
CVE-2024-25909
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in JoomUnited WP Media folder.This issue affects WP Media folder: from n/a through 5.7.2.

Feb 26, 2024
CVE-2024-25763
5.5 MEDIUM

openNDS 10.2.0 is vulnerable to Use-After-Free via /openNDS/src/auth.c.

Feb 26, 2024
CVE-2024-25760

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not …

Feb 26, 2024
CVE-2024-25410
6.5 MEDIUM

flusity-CMS 2.33 is vulnerable to Unrestricted Upload of File with Dangerous Type in update_setting.php.

Feb 26, 2024
CVE-2024-25344
6.1 MEDIUM

Cross Site Scripting vulnerability in ITFlow.org before commit v.432488eca3998c5be6b6b9e8f8ba01f54bc12378 allows a remtoe attacker to execute arbitrary code and obtain sensitive information via the settings.php, settings+company.php, …

Feb 26, 2024
CVE-2024-25082
6.5 MEDIUM

Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files.

Feb 26, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.