CVE Database

120754+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-25081
4.2 MEDIUM

Splinefont in FontForge through 20230101 allows command injection via crafted filenames.

Feb 26, 2024
CVE-2024-24714
7.2 HIGH

Unrestricted Upload of File with Dangerous Type vulnerability in bPlugins LLC Icons Font Loader.This issue affects Icons Font Loader: from n/a through 1.1.4.

Feb 26, 2024
CVE-2024-24568
5.3 MEDIUM

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.3, the rules inspecting HTTP2 headers can get …

Feb 26, 2024
CVE-2024-23839
7.1 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.3, specially crafted traffic can cause a heap …

Feb 26, 2024
CVE-2024-23837
7.5 HIGH

LibHTP is a security-aware parser for the HTTP protocol. Crafted traffic can cause excessive processing time of HTTP headers, leading to denial of service. This …

Feb 26, 2024
CVE-2024-23836
7.5 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 6.0.16 and 7.0.3, an attacker can craft …

Feb 26, 2024
CVE-2024-23835
7.5 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.3, excessive memory use during pgsql parsing …

Feb 26, 2024
CVE-2024-23605
8.8 HIGH

A heap-based buffer overflow vulnerability exists in the GGUF library header.n_kv functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to code …

Feb 26, 2024
CVE-2024-23496
8.8 HIGH

A heap-based buffer overflow vulnerability exists in the GGUF library gguf_fread_str functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to code …

Feb 26, 2024
CVE-2024-22873
8.1 HIGH

Tencent Blueking CMDB v3.2.x to v3.9.x was discovered to contain a Server-Side Request Forgery (SSRF) via the event subscription function (/service/subscription.go). This vulnerability allows attackers …

Feb 26, 2024
CVE-2024-22371
2.9 LOW

Exposure of sensitive data by by crafting a malicious EventFactory and providing a custom ExchangeCreatedEvent that exposes sensitive data. Vulnerability in Apache Camel.This issue affects …

Feb 26, 2024
CVE-2024-22201
7.5 HIGH

Jetty is a Java based web server and servlet engine. An HTTP/2 SSL connection that is established and TCP congested will be leaked when it …

Feb 26, 2024
CVE-2024-21836
8.8 HIGH

A heap-based buffer overflow vulnerability exists in the GGUF library header.n_tensors functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to code …

Feb 26, 2024
CVE-2024-21825
8.8 HIGH

A heap-based buffer overflow vulnerability exists in the GGUF library GGUF_TYPE_ARRAY/GGUF_TYPE_STRING parsing functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to …

Feb 26, 2024
CVE-2024-21802
8.8 HIGH

A heap-based buffer overflow vulnerability exists in the GGUF library info->ne functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to code …

Feb 26, 2024
CVE-2024-1890
6.4 MEDIUM

Vulnerability whereby an attacker could send a malicious link to an authenticated operator, which could allow remote attackers to perform a clickjacking attack on Sunny …

Feb 26, 2024
CVE-2024-1889
8.8 HIGH

Cross-Site Request Forgery vulnerability in SMA Cluster Controller, affecting version 01.05.01.R. This vulnerability could allow an attacker to send a malicious link to an authenticated …

Feb 26, 2024
CVE-2024-1886
3.0 LOW

This vulnerability allows remote attackers to traverse the directory on the affected webOS of LG Signage.

Feb 26, 2024
CVE-2024-1885
6.3 MEDIUM

This vulnerability allows remote attackers to execute arbitrary code on the affected webOS of LG Signage.

Feb 26, 2024
CVE-2024-1878
6.3 MEDIUM

A vulnerability was found in SourceCodester Employee Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Feb 26, 2024
CVE-2024-1877
6.3 MEDIUM

A vulnerability was found in SourceCodester Employee Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Feb 26, 2024
CVE-2024-1876
7.3 HIGH

A vulnerability was found in SourceCodester Employee Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /psubmit.php. …

Feb 26, 2024
CVE-2024-1875
6.3 MEDIUM

A vulnerability was found in SourceCodester Complaint Management System 1.0 and classified as critical. This issue affects some unknown processing of the file users/register-complaint.php of …

Feb 26, 2024
CVE-2024-1871
3.5 LOW

A vulnerability, which was classified as problematic, was found in SourceCodester Employee Management System 1.0. Affected is an unknown function of the file /process/assignp.php of …

Feb 26, 2024
CVE-2024-1758
5.4 MEDIUM

The SuperFaktura WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.40.3 via the wc_sf_url_check function. This …

Feb 26, 2024
CVE-2024-1735
9.1 CRITICAL

A vulnerability has been identified in armeria-saml versions less than 1.27.2, allowing the use of malicious SAML messages to bypass authentication. All users who rely …

Feb 26, 2024
CVE-2024-1710
8.8 HIGH

The Addon Library plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the onAjaxAction function action in …

Feb 26, 2024
CVE-2024-1622
7.5 HIGH

Due to a mistake in error checking, Routinator will terminate when an incoming RTR connection is reset by the peer too quickly after opening.

Feb 26, 2024
CVE-2024-1436
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wiloke WooCommerce Coupon Popup, SmartBar, Slide In | MyShopKit.This issue affects WooCommerce Coupon Popup, SmartBar, …

Feb 26, 2024
CVE-2024-1165
4.3 MEDIUM

The Brizy – Page Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.39 via the 'id'. This …

Feb 26, 2024
CVE-2024-0798
6.5 MEDIUM

A privilege escalation vulnerability exists in mintplex-labs/anything-llm, allowing users with 'default' role to delete documents uploaded by 'admin'. Despite the intended restriction that prevents 'default' …

Feb 26, 2024
CVE-2024-0455
7.5 HIGH

The inclusion of the web scraper for AnythingLLM means that any user with the proper authorization level (manager, admin, and when in single user) could …

Feb 26, 2024
CVE-2024-0440
6.5 MEDIUM

Attacker, with permission to submit a link or submits a link via POST to be collected that is using the file:// protocol can then introspect …

Feb 26, 2024
CVE-2024-0439
8.8 HIGH

As a manager, you should not be able to modify a series of settings. In the UI this is indeed hidden as a convenience for …

Feb 26, 2024
CVE-2024-0436
5.9 MEDIUM

Theoretically, it would be possible for an attacker to brute-force the password for an instance in single-user password protection mode via a timing attack given …

Feb 26, 2024
CVE-2024-0435
5.4 MEDIUM

User can send a chat that contains an XSS opportunity that will then run when the chat is sent and on subsequent page loads. Given …

Feb 26, 2024
CVE-2024-0387
6.5 MEDIUM

The EDS-4000/G4000 Series prior to version 3.2 includes IP forwarding capabilities that users cannot deactivate. An attacker may be able to send requests to the …

Feb 26, 2024
CVE-2024-0243
8.1 HIGH

With the following crawler configuration: ```python from bs4 import BeautifulSoup as Soup url = "https://example.com" loader = RecursiveUrlLoader( url=url, max_depth=2, extractor=lambda x: Soup(x, "html.parser").text ) …

Feb 26, 2024
CVE-2023-5775
2.2 LOW

The BackWPup plugin for WordPress is vulnerable to Plaintext Storage of Backup Destination Password in all versions up to, and including, 4.0.2. This is due …

Feb 26, 2024
CVE-2023-52473
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: thermal: core: Fix NULL pointer dereference in zone registration error path If device_register() in thermal_zone_device_register_with_trips() …

Feb 26, 2024
CVE-2023-52472
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: crypto: rsa - add a check for allocation failure Static checkers insist that the mpi_alloc() …

Feb 26, 2024
CVE-2023-52471
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ice: Fix some null pointer dereference issues in ice_ptp.c devm_kasprintf() returns a pointer to dynamically …

Feb 26, 2024
CVE-2023-52470
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/radeon: check the alloc_workqueue return value in radeon_crtc_init() check the alloc_workqueue return value in radeon_crtc_init() …

Feb 26, 2024
CVE-2023-52469
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drivers/amd/pm: fix a use-after-free in kv_parse_power_table When ps allocated by kzalloc equals to NULL, kv_parse_power_table …

Feb 26, 2024
CVE-2023-52468
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: class: fix use-after-free in class_register() The lock_class_key is still registered and can be found in …

Feb 26, 2024
CVE-2023-52467
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mfd: syscon: Fix null pointer dereference in of_syscon_register() kasprintf() returns a pointer to dynamically allocated …

Feb 26, 2024
CVE-2023-52466

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Feb 26, 2024
CVE-2023-52465
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: power: supply: Fix null pointer dereference in smb2_probe devm_kasprintf and devm_kzalloc return a pointer to …

Feb 26, 2024
CVE-2023-49960
7.5 HIGH

In Indo-Sol PROFINET-INspektor NT through 2.4.0, a path traversal vulnerability in the httpuploadd service of the firmware allows remote attackers to write to arbitrary files …

Feb 26, 2024
CVE-2023-49959
9.8 CRITICAL

In Indo-Sol PROFINET-INspektor NT through 2.4.0, a command injection vulnerability in the gedtupdater service of the firmware allows remote attackers to execute arbitrary system commands …

Feb 26, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.