CVE Database

120754+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-47422
8.8 HIGH

An access control issue in /usr/sbin/httpd in Tenda TX9 V1 V22.03.02.54, Tenda AX3 V3 V16.03.12.11, Tenda AX9 V1 V22.03.01.46, and Tenda AX12 V1 V22.03.01.46 allows …

Feb 20, 2024
CVE-2021-29050
8.8 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in the terms of use page in Liferay Portal before 7.3.6, and Liferay DXP 7.3 before service pack 1, 7.2 …

Feb 20, 2024
CVE-2021-29038
6.3 MEDIUM

Liferay Portal 7.2.0 through 7.3.5, and older unsupported versions, and Liferay DXP 7.3 before fix pack 1, 7.2 before fix pack 17, and older unsupported …

Feb 20, 2024
CVE-2024-25141
9.1 CRITICAL

When ssl was enabled for Mongo Hook, default settings included "allow_insecure" which caused that certificates were not validated. This was unexpected and undocumented. Users are …

Feb 20, 2024
CVE-2023-52439
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: uio: Fix use-after-free in uio_open core-1 core-2 ------------------------------------------------------- uio_unregister_device uio_open idev = idr_find() device_unregister(&idev->dev) put_device(&idev->dev) …

Feb 20, 2024
CVE-2023-52438
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: binder: fix use-after-free in shinker's callback The mmap read lock is used during the shrinker's …

Feb 20, 2024
CVE-2023-52437

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Feb 20, 2024
CVE-2023-52436
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: f2fs: explicitly null-terminate the xattr list When setting an xattr, explicitly null-terminate the xattr list. …

Feb 20, 2024
CVE-2023-49034
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in ProjeQtOr 11.0.2 allows a remote attacker to execute arbitrary code via a crafted script to thecheckvalidHtmlText function in the …

Feb 20, 2024
CVE-2023-46967
6.1 MEDIUM

Cross Site Scripting vulnerability in the sanitize function in Enhancesoft osTicket 1.18.0 allows a remote attacker to escalate privileges via a crafted support ticket.

Feb 20, 2024
CVE-2024-26135
8.3 HIGH

MeshCentral is a full computer management web site. Versions prior to 1.1.21 a cross-site websocket hijacking (CSWSH) vulnerability within the control.ashx endpoint. This component is …

Feb 20, 2024
CVE-2023-52435
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: prevent mss overflow in skb_segment() Once again syzbot is able to crash the kernel …

Feb 20, 2024
CVE-2024-25631
6.1 MEDIUM

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who have enabled an external kvstore and Wireguard transparent encryption, …

Feb 20, 2024
CVE-2024-25630
6.1 MEDIUM

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who are using CRDs to store Cilium state (the default …

Feb 20, 2024
CVE-2024-25260
4.0 MEDIUM

elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.

Feb 20, 2024
CVE-2024-24763
4.3 MEDIUM

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to version 3.10.0, attackers can exploit this vulnerability to …

Feb 20, 2024
CVE-2024-24474
8.8 HIGH

QEMU before 8.2.0 has an integer underflow, and resultant buffer overflow, via a TI command when an expected non-DMA transfer length is less than the …

Feb 20, 2024
CVE-2024-22250
7.8 HIGH

Session Hijack vulnerability in Deprecated VMware Enhanced Authentication Plug-in could allow a malicious actor with unprivileged local access to a windows operating system can hijack …

Feb 20, 2024
CVE-2024-22245
9.6 CRITICAL

Arbitrary Authentication Relay and Session Hijack vulnerabilities in the deprecated VMware Enhanced Authentication Plug-in (EAP) could allow a malicious actor that could trick a target …

Feb 20, 2024
CVE-2024-22054
7.5 HIGH

A malformed discovery packet sent by a malicious actor with preexisting access to the network could interrupt the functionality of device management and discovery. Affected …

Feb 20, 2024
CVE-2024-21682
7.2 HIGH

This High severity Injection vulnerability was introduced in Assets Discovery 1.0 - 6.2.0 (all versions). Assets Discovery, which can be downloaded via Atlassian Marketplace, is …

Feb 20, 2024
CVE-2024-21678
8.5 HIGH

This High severity Stored XSS vulnerability was introduced in version 2.7.0 of Confluence Data Center. This Stored XSS vulnerability, with a CVSS Score of 8.5, …

Feb 20, 2024
CVE-2024-0794
9.8 CRITICAL

Certain HP LaserJet Pro, HP Enterprise LaserJet, and HP LaserJet Managed Printers are potentially vulnerable to Remote Code Execution due to buffer overflow when rendering …

Feb 20, 2024
CVE-2023-52434
8.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential OOBs in smb2_parse_contexts() Validate offsets and lengths before dereferencing create contexts …

Feb 20, 2024
CVE-2023-51447
6.3 MEDIUM

Decidim is a participatory democracy framework. Starting in version 0.27.0 and prior to versions 0.27.5 and 0.28.0, the dynamic file upload feature is subject to …

Feb 20, 2024
CVE-2023-48220
5.7 MEDIUM

Decidim is a participatory democracy framework. Starting in version 0.4.rc3 and prior to version 2.0.9 of the `devise_invitable` gem, the invites feature allows users to …

Feb 20, 2024
CVE-2023-47635
4.5 MEDIUM

Decidim is a participatory democracy framework. Starting in version 0.23.0 and prior to versions 0.27.5 and 0.28.0, the CSRF authenticity token check is disabled for …

Feb 20, 2024
CVE-2024-25366
6.2 MEDIUM

Buffer Overflow vulnerability in mz-automation.de libiec61859 v.1.4.0 allows a remote attacker to cause a denial of service via the mmsServer_handleGetNameListRequest function to the mms_getnamelist_service component.

Feb 20, 2024
CVE-2024-25274
9.8 CRITICAL

An arbitrary file upload vulnerability in the component /sysFile/upload of Novel-Plus v4.3.0-RC1 allows attackers to execute arbitrary code via uploading a crafted file.

Feb 20, 2024
CVE-2024-23809
9.8 CRITICAL

A double-free vulnerability exists in the BrainVision ASCII Header Parsing functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .vdhr …

Feb 20, 2024
CVE-2024-23606
9.8 CRITICAL

An out-of-bounds write vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .famos file can …

Feb 20, 2024
CVE-2024-23313
9.8 CRITICAL

An integer underflow vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .famos file can …

Feb 20, 2024
CVE-2024-23310
9.8 CRITICAL

A use-after-free vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .famos file can lead …

Feb 20, 2024
CVE-2024-23305
9.8 CRITICAL

An out-of-bounds write vulnerability exists in the BrainVisionMarker Parsing functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .vmrk file …

Feb 20, 2024
CVE-2024-22097
9.8 CRITICAL

A double-free vulnerability exists in the BrainVision Header Parsing functionality of The Biosig Project libbiosig Master Branch (ab0ee111) and 2.5.0. A specially crafted .vdhr file …

Feb 20, 2024
CVE-2024-21812
9.8 CRITICAL

An integer overflow vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .famos file can …

Feb 20, 2024
CVE-2024-21795
9.8 CRITICAL

A heap-based buffer overflow vulnerability exists in the .egi parsing functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .egi …

Feb 20, 2024
CVE-2024-23114
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in Apache Camel CassandraQL Component AggregationRepository which is vulnerable to unsafe deserialization. Under specific conditions it is possible to deserialize …

Feb 20, 2024
CVE-2024-22824
9.8 CRITICAL

An issue in Timo v.2.0.3 allows a remote attacker to execute arbitrary code via the filetype restrictions in the UploadController.java component.

Feb 20, 2024
CVE-2024-22369
7.8 HIGH

Deserialization of Untrusted Data vulnerability in Apache Camel SQL ComponentThis issue affects Apache Camel: from 3.0.0 before 3.21.4, from 3.22.0 before 3.22.1, from 4.0.0 before …

Feb 20, 2024
CVE-2024-1156
7.8 HIGH

Incorrect directory permissions for the shared NI RabbitMQ service may allow a local authenticated user to read RabbitMQ configuration information and potentially enable escalation of …

Feb 20, 2024
CVE-2024-1155
7.8 HIGH

Incorrect permissions in the installation directories for shared SystemLink Elixir based services may allow an authenticated user to potentially enable escalation of privilege via local …

Feb 20, 2024
CVE-2023-45318
10.0 CRITICAL

A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP git commit 80d4004. A specially crafted network packet can lead …

Feb 20, 2024
CVE-2023-39541
5.9 MEDIUM

A denial of service vulnerability exists in the ICMP and ICMPv6 parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted network packet can lead …

Feb 20, 2024
CVE-2023-39540
5.9 MEDIUM

A denial of service vulnerability exists in the ICMP and ICMPv6 parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted network packet can lead …

Feb 20, 2024
CVE-2023-38562
8.7 HIGH

A double-free vulnerability exists in the IP header loopback parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted set of network packets can lead …

Feb 20, 2024
CVE-2024-26270
6.5 MEDIUM

The Account Settings page in Liferay Portal 7.4.3.76 through 7.4.3.99, and Liferay DXP 2023.Q3 before patch 5, and 7.4 update 76 through 92 embeds the …

Feb 20, 2024
CVE-2024-26268
5.3 MEDIUM

User enumeration vulnerability in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Liferay DXP 7.4 before update 27, 7.3 before update 8, 7.2 …

Feb 20, 2024
CVE-2024-25199
8.1 HIGH

Inappropriate pointer order of map_sub_ and map_free(map_) (amcl_node.cpp) in Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions leads to a use-after-free.

Feb 20, 2024
CVE-2024-25198
9.1 CRITICAL

Inappropriate pointer order of laser_scan_filter_.reset() and tf_listener_.reset() (amcl_node.cpp) in Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions leads to a use-after-free.

Feb 20, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.