CVE Database

120754+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-0861
4.3 MEDIUM

An issue has been discovered in GitLab EE affecting all versions starting from 16.4 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions …

Feb 22, 2024
CVE-2024-0446
7.8 HIGH

A maliciously crafted STP, CATPART or MODEL file, when parsed in ASMKERN228A.dll and ASMdatax229A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious …

Feb 22, 2024
CVE-2024-0410
7.7 HIGH

An authorization bypass vulnerability was discovered in GitLab affecting versions 15.1 prior to 16.7.6, 16.8 prior to 16.8.3, and 16.9 prior to 16.9.1. A developer …

Feb 22, 2024
CVE-2023-6477
6.7 MEDIUM

An issue has been discovered in GitLab EE affecting all versions starting from 16.5 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions …

Feb 22, 2024
CVE-2024-26148
6.1 MEDIUM

Querybook is a user interface for querying big data. Prior to version 3.31.1, there is a vulnerability in Querybook's rich text editor that enables users …

Feb 21, 2024
CVE-2024-26147
7.5 HIGH

Helm is a package manager for Charts for Kubernetes. Versions prior to 3.14.2 contain an uninitialized variable vulnerability when Helm parses index and plugin yaml …

Feb 21, 2024
CVE-2023-3509
3.7 LOW

An issue has been discovered in GitLab affecting all versions before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before …

Feb 21, 2024
CVE-2023-52155
7.2 HIGH

A SQL Injection vulnerability in /admin/sauvegarde/run.php in PMB 7.4.7 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via the sauvegardes variable through …

Feb 21, 2024
CVE-2023-52154
7.2 HIGH

File Upload vulnerability in pmb/camera_upload.php in PMB 7.4.7 and earlier allows attackers to run arbitrary code via upload of crafted PHTML files.

Feb 21, 2024
CVE-2023-52153
9.8 CRITICAL

A SQL Injection vulnerability in /pmb/opac_css/includes/sessions.inc.php in PMB 7.4.7 and earlier allows remote unauthenticated attackers to inject arbitrary SQL commands via the PmbOpac-LOGIN cookie value.

Feb 21, 2024
CVE-2023-51828
9.8 CRITICAL

A SQL Injection vulnerability in /admin/convert/export.class.php in PMB 7.4.7 and earlier versions allows remote unauthenticated attackers to execute arbitrary SQL commands via the query parameter …

Feb 21, 2024
CVE-2024-25124
9.4 CRITICAL

Fiber is a web framework written in go. Prior to version 2.52.1, the CORS middleware allows for insecure configurations that could potentially expose the application …

Feb 21, 2024
CVE-2024-23654
4.1 MEDIUM

discourse-ai is the AI plugin for the open-source discussion platform Discourse. Prior to commit 94ba0dadc2cf38e8f81c3936974c167219878edd, interactions with different AI services are vulnerable to admin-initiated SSRF …

Feb 21, 2024
CVE-2023-38844
7.5 HIGH

SQL injection vulnerability in PMB v.7.4.7 and earlier allows a remote attacker to execute arbitrary code via the thesaurus parameter in export_skos.php.

Feb 21, 2024
CVE-2023-37177
9.8 CRITICAL

SQL Injection vulnerability in PMB Services PMB v.7.4.7 and before allows a remote unauthenticated attacker to execute arbitrary code via the query parameter in the …

Feb 21, 2024
CVE-2023-24334
8.0 HIGH

A stack overflow vulnerability in Tenda AC23 with firmware version US_AC23V1.0re_V16.03.07.45_cn_TDC01 allows attackers to run arbitrary commands via schedStartTime parameter.

Feb 21, 2024
CVE-2023-24333
8.8 HIGH

A stack overflow vulnerability in Tenda AC21 with firmware version US_AC21V1.0re_V16.03.08.15_cn_TDC01 allows attackers to run arbitrary commands via crafted POST request to /goform/openSchedWifi.

Feb 21, 2024
CVE-2023-24332
8.1 HIGH

A stack overflow vulnerability in Tenda AC6 with firmware version US_AC6V5.0re_V03.03.02.01_cn_TDC01 allows attackers to run arbitrary commands via crafted POST request to /goform/PowerSaveSet.

Feb 21, 2024
CVE-2023-24331
9.8 CRITICAL

Command Injection vulnerability in D-Link Dir 816 with firmware version DIR-816_A2_v1.10CNB04 allows attackers to run arbitrary commands via the urlAdd parameter.

Feb 21, 2024
CVE-2023-24330
8.8 HIGH

Command Injection vulnerability in D-Link Dir 882 with firmware version DIR882A1_FW130B06 allows attackers to run arbitrary commands via crafted POST request to /HNAP1/.

Feb 21, 2024
CVE-2024-26311
5.7 MEDIUM

Archer Platform 6.x before 6.14 P2 HF1 (6.14.0.2.1) contains a reflected XSS vulnerability. A remote authenticated malicious Archer user could potentially exploit this by tricking …

Feb 21, 2024
CVE-2024-26310
4.3 MEDIUM

Archer Platform 6.8 before 6.14 P2 (6.14.0.2) contains an improper access control vulnerability. A remote authenticated malicious user could potentially exploit this to gain access …

Feb 21, 2024
CVE-2024-25461
7.5 HIGH

Directory Traversal vulnerability in Terrasoft, Creatio Terrasoft CRM v.7.18.4.1532 allows a remote attacker to obtain sensitive information via a crafted request to the terrasoft.axd component.

Feb 21, 2024
CVE-2024-25249
9.8 CRITICAL

An issue in He3 App for macOS version 2.0.17, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings.

Feb 21, 2024
CVE-2023-6640
6.5 MEDIUM

Malformed S2 Nonce Get Command Class packets can be sent to crash PC Controller v5.54.0 and earlier.

Feb 21, 2024
CVE-2023-6533
6.5 MEDIUM

Malformed Device Reset Locally Command Class packets can be sent to the controller, causing the controller to assume the end device has left the network. …

Feb 21, 2024
CVE-2024-25381
6.1 MEDIUM

There is a Stored XSS Vulnerability in Emlog Pro 2.2.8 Article Publishing, due to non-filtering of quoted content.

Feb 21, 2024
CVE-2024-24479
7.5 HIGH

A Buffer Overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the wsutil/to_str.c, and format_fractional_part_nsecs components. NOTE: this …

Feb 21, 2024
CVE-2024-24476
7.5 HIGH

A buffer overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the pan/addr_resolv.c, and ws_manuf_lookup_str(), size components. NOTE: …

Feb 21, 2024
CVE-2024-22473
6.8 MEDIUM

TRNG is used before initialization by ECDSA signing driver when exiting EM2/EM3 on Virtual Secure Vault (VSE) devices. This defect may allow Signature Spoofing by …

Feb 21, 2024
CVE-2024-1707
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in GARO WALLBOX GLB+ T2EV7 0.5. This affects an unknown part of the file /index.jsp#settings of …

Feb 21, 2024
CVE-2023-50975
8.4 HIGH

The TD Bank TD Advanced Dashboard client through 3.0.3 for macOS allows arbitrary code execution because of the lack of electron::fuses::IsRunAsNodeEnabled (i.e., ELECTRON_RUN_AS_NODE can be …

Feb 21, 2024
CVE-2024-26145
6.5 MEDIUM

Discourse Calendar adds the ability to create a dynamic calendar in the first post of a topic on Discourse. Uninvited users are able to gain …

Feb 21, 2024
CVE-2024-25898
6.1 MEDIUM

A XSS vulnerability was found in the ChurchCRM v.5.5.0 functionality, edit your event, where malicious JS or HTML code can be inserted in the Event …

Feb 21, 2024
CVE-2024-25897
9.8 CRITICAL

ChurchCRM 5.5.0 FRCatalog.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET parameter.

Feb 21, 2024
CVE-2024-25896
5.3 MEDIUM

ChurchCRM 5.5.0 EventEditor.php is vulnerable to Blind SQL Injection (Time-based) via the EID POST parameter.

Feb 21, 2024
CVE-2024-25895
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in ChurchCRM 5.5.0 allows remote attackers to inject arbitrary web script or HTML via the type parameter of /EventAttendance.php

Feb 21, 2024
CVE-2024-25894
9.8 CRITICAL

ChurchCRM 5.5.0 /EventEditor.php is vulnerable to Blind SQL Injection (Time-based) via the EventCount POST parameter.

Feb 21, 2024
CVE-2024-25893
9.1 CRITICAL

ChurchCRM 5.5.0 FRCertificates.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET parameter.

Feb 21, 2024
CVE-2024-25892
8.1 HIGH

ChurchCRM 5.5.0 ConfirmReport.php is vulnerable to Blind SQL Injection (Time-based) via the familyId GET parameter.

Feb 21, 2024
CVE-2024-25891
7.5 HIGH

ChurchCRM 5.5.0 FRBidSheets.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET parameter.

Feb 21, 2024
CVE-2024-1706
3.5 LOW

A vulnerability was determined in ZKTeco ZKBio Access IVS up to 3.3.2. This impacts an unknown function of the component Department Name Search Bar. This …

Feb 21, 2024
CVE-2024-1705
5.6 MEDIUM

A vulnerability was found in Shopwind up to 4.6. It has been rated as critical. This issue affects the function actionCreate of the file /public/install/controllers/DefaultController.php …

Feb 21, 2024
CVE-2024-1704
5.5 MEDIUM

A vulnerability was found in ZhongBangKeJi CRMEB 5.2.2. It has been declared as critical. This vulnerability affects the function save/delete of the file /adminapi/system/crud. The …

Feb 21, 2024
CVE-2024-1212
10.0 CRITICAL KEV

Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.

Feb 21, 2024
CVE-2024-26138
5.3 MEDIUM

The XWiki licensor application, which manages and enforce application licenses for paid extensions, includes the document `Licenses.Code.LicenseJSON` that provides information for admins regarding active licenses. …

Feb 21, 2024
CVE-2024-26133
5.5 MEDIUM

EventStoreDB (ESDB) is an operational database built to store events. A vulnerability has been identified in the projections subsystem in versions 20 prior to 20.10.6, …

Feb 21, 2024
CVE-2024-26130
7.5 HIGH

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Starting in version 38.0.0 and prior to version 42.0.4, if `pkcs12.serialize_key_and_certificates` …

Feb 21, 2024
CVE-2024-25288
4.9 MEDIUM

SLIMS (Senayan Library Management Systems) 9 Bulian v9.6.1 is vulnerable to SQL Injection via pop-scope-vocabolary.php.

Feb 21, 2024
CVE-2024-25117
6.8 MEDIUM

php-svg-lib is a scalable vector graphics (SVG) file parsing/rendering library. Prior to version 0.5.2, php-svg-lib fails to validate that font-family doesn't contain a PHAR url, …

Feb 21, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.