CVE Database

120754+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-25197
6.5 MEDIUM

Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions were discovered to contain a NULL pointer dereference via the isCurrent() function at /src/layered_costmap.cpp.

Feb 20, 2024
CVE-2024-25196
3.3 LOW

Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow via the nav2_controller process. This vulnerability is …

Feb 20, 2024
CVE-2024-1557
8.1 HIGH

Memory safety bugs present in Firefox 122. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of …

Feb 20, 2024
CVE-2024-1556
6.5 MEDIUM

The incorrect object was checked for NULL in the built-in profiler, potentially leading to invalid memory access and undefined behavior. *Note:* This issue only affects …

Feb 20, 2024
CVE-2024-1555
8.3 HIGH

When opening a website using the `firefox://` protocol handler, SameSite cookies were not properly respected. This vulnerability affects Firefox < 123.

Feb 20, 2024
CVE-2024-1554
9.8 CRITICAL

The `fetch()` API and navigation incorrectly shared the same cache, as the cache key did not include the optional headers `fetch()` may contain. Under the …

Feb 20, 2024
CVE-2024-1553
8.1 HIGH

Memory safety bugs present in Firefox 122, Firefox ESR 115.7, and Thunderbird 115.7. Some of these bugs showed evidence of memory corruption and we presume …

Feb 20, 2024
CVE-2024-1552
7.5 HIGH

Incorrect code generation could have led to unexpected numeric conversions and potential undefined behavior.*Note:* This issue only affects 32-bit ARM devices. This vulnerability affects Firefox …

Feb 20, 2024
CVE-2024-1551
6.1 MEDIUM

Set-Cookie response headers were being incorrectly honored in multipart HTTP responses. If an attacker could control the Content-Type response header, as well as control part …

Feb 20, 2024
CVE-2024-1550
6.1 MEDIUM

A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedly, which could …

Feb 20, 2024
CVE-2024-1549
6.1 MEDIUM

If a website set a large custom cursor, portions of the cursor could have overlapped with the permission dialog, potentially resulting in user confusion and …

Feb 20, 2024
CVE-2024-1548
4.3 MEDIUM

A website could have obscured the fullscreen notification by using a dropdown select input element. This could have led to user confusion and possible spoofing …

Feb 20, 2024
CVE-2024-1547
6.5 MEDIUM

Through a series of API calls and redirects, an attacker-controlled alert dialog could have been displayed on another website (with the victim website's URL shown). …

Feb 20, 2024
CVE-2024-1546
7.5 HIGH

When storing and re-accessing data on a networking channel, the length of buffers may have been confused, resulting in an out-of-bounds memory read. This vulnerability …

Feb 20, 2024
CVE-2023-50306
4.0 MEDIUM

IBM Common Licensing 9.0 could allow a local user to enumerate usernames due to an observable response discrepancy. IBM X-Force ID: 273337.

Feb 20, 2024
CVE-2023-42791
8.8 HIGH

A relative path traversal in Fortinet FortiManager version 7.4.0 and 7.2.0 through 7.2.3 and 7.0.0 through 7.0.8 and 6.4.0 through 6.4.12 and 6.2.0 through 6.2.11 …

Feb 20, 2024
CVE-2024-26581
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_rbtree: skip end interval element from gc rbtree lazy gc on insert might collect …

Feb 20, 2024
CVE-2024-26267
5.3 MEDIUM

In Liferay Portal 7.2.0 through 7.4.3.25, and older unsupported versions, and Liferay DXP 7.4 before update 26, 7.3 before update 5, 7.2 before fix pack …

Feb 20, 2024
CVE-2024-26265
5.0 MEDIUM

The Image Uploader module in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions, and Liferay DXP 7.4 before update 16, 7.3 before update 4, …

Feb 20, 2024
CVE-2024-25610
9.0 CRITICAL

In Liferay Portal 7.2.0 through 7.4.3.12, and older unsupported versions, and Liferay DXP 7.4 before update 9, 7.3 before update 4, 7.2 before fix pack …

Feb 20, 2024
CVE-2024-1661
2.5 LOW

A vulnerability classified as problematic was found in Totolink X6000R 9.4.0cu.852_B20230719. Affected by this vulnerability is an unknown functionality of the file /etc/shadow. The manipulation …

Feb 20, 2024
CVE-2023-52433
4.4 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_rbtree: skip sync GC for new elements in this transaction New elements in this …

Feb 20, 2024
CVE-2024-24794
8.1 HIGH

A use-after-free vulnerability exists in the DICOM Element Parsing as implemented in Imaging Data Commons libdicom 1.0.5. A specially crafted DICOM file can cause premature …

Feb 20, 2024
CVE-2024-24793
8.1 HIGH

A use-after-free vulnerability exists in the DICOM Element Parsing as implemented in Imaging Data Commons libdicom 1.0.5. A specially crafted DICOM file can cause premature …

Feb 20, 2024
CVE-2023-7245
7.8 HIGH

The nodejs framework in OpenVPN Connect 3.0 through 3.4.3 (Windows)/3.4.7 (macOS) was not properly configured, which allows a local user to execute arbitrary code within …

Feb 20, 2024
CVE-2024-25609
6.1 MEDIUM

HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.12, and older unsupported versions, and Liferay DXP 7.4 before update 9, 7.3 service pack 3, 7.2 fix pack …

Feb 20, 2024
CVE-2024-25608
6.1 MEDIUM

HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.18, and older unsupported versions, and Liferay DXP 7.4 before update 19, 7.3 before update 4, 7.2 before fix …

Feb 20, 2024
CVE-2024-25607
8.1 HIGH

The default password hashing algorithm (PBKDF2-HMAC-SHA1) in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions, and Liferay DXP 7.4 before update 16, 7.3 before …

Feb 20, 2024
CVE-2023-51770
7.5 HIGH

Arbitrary File Read Vulnerability in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.1. We recommend users to upgrade Apache DolphinScheduler to version 3.2.1, which …

Feb 20, 2024
CVE-2023-50270
6.5 MEDIUM

Session Fixation Apache DolphinScheduler before version 3.2.0, which session is still valid after the password change. Users are recommended to upgrade to version 3.2.1, which …

Feb 20, 2024
CVE-2023-49250
7.3 HIGH

Because the HttpUtils class did not verify certificates, an attacker that could perform a Man-in-the-Middle (MITM) attack on outgoing https connections could impersonate the server. …

Feb 20, 2024
CVE-2023-49109
9.8 CRITICAL

Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.1. We recommend users to upgrade Apache DolphinScheduler to version 3.2.1, …

Feb 20, 2024
CVE-2024-25606
8.0 HIGH

XXE vulnerability in Liferay Portal 7.2.0 through 7.4.3.7, and older unsupported versions, and Liferay DXP 7.4 before update 4, 7.3 before update 12, 7.2 before …

Feb 20, 2024
CVE-2024-25605
5.3 MEDIUM

The Journal module in Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before service pack 3, 7.2 before fix …

Feb 20, 2024
CVE-2024-25604
6.5 MEDIUM

Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before service pack 3, 7.2 before fix pack 17, and older …

Feb 20, 2024
CVE-2024-1608
9.1 CRITICAL

In OPPO Usercenter Credit SDK, there's a possible escalation of privilege due to loose permission check, This could lead to application internal information leak w/o …

Feb 20, 2024
CVE-2024-25974
5.4 MEDIUM

The Frentix GmbH OpenOlat LMS is affected by stored a Cross-Site Scripting (XSS) vulnerability. It is possible to upload files within the Media Center of …

Feb 20, 2024
CVE-2024-25973
5.4 MEDIUM

The Frentix GmbH OpenOlat LMS is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities. An attacker with rights to create or edit groups can create …

Feb 20, 2024
CVE-2024-25150
4.3 MEDIUM

Information disclosure vulnerability in the Control Panel in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before update 4, 7.2 …

Feb 20, 2024
CVE-2024-25149
5.4 MEDIUM

Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported …

Feb 20, 2024
CVE-2024-22234
7.4 HIGH

In Spring Security, versions 6.1.x prior to 6.1.7 and versions 6.2.x prior to 6.2.2, an application is vulnerable to broken access control when it directly …

Feb 20, 2024
CVE-2023-44308
6.1 MEDIUM

Open redirect vulnerability in adaptive media administration page in Liferay DXP 2023.Q3 before patch 6, and 7.4 GA through update 92 allows remote attackers to …

Feb 20, 2024
CVE-2023-5190
6.1 MEDIUM

Open redirect vulnerability in the Countries Management’s edit region page in Liferay Portal 7.4.3.45 through 7.4.3.101, and Liferay DXP 2023.Q3 before patch 6, and 7.4 …

Feb 20, 2024
CVE-2022-45320
6.3 MEDIUM

Liferay Portal before 7.4.3.16 and Liferay DXP before 7.2 fix pack 19, 7.3 before update 6, and 7.4 before update 16 allow remote authenticated users …

Feb 20, 2024
CVE-2024-1559
6.5 MEDIUM

The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'll_reciprocal' parameter in all versions up to, and including, 7.6 due …

Feb 20, 2024
CVE-2024-1510
6.4 MEDIUM

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's su_tooltip shortcode in all versions up …

Feb 20, 2024
CVE-2023-6764
8.1 HIGH

A format string vulnerability in a function of the IPSec VPN feature in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1, USG …

Feb 20, 2024
CVE-2024-22019
7.5 HIGH

A vulnerability in Node.js HTTP servers allows an attacker to send a specially crafted HTTP request with chunked encoding, leading to resource exhaustion and denial …

Feb 20, 2024
CVE-2024-21896
9.8 CRITICAL

The permission model protects itself against path traversal attacks by calling path.resolve() on any paths given by the user. If the path is to be …

Feb 20, 2024
CVE-2024-21892
7.8 HIGH

On Linux, Node.js ignores certain environment variables if those may have been set by an unprivileged user while the process is running with elevated privileges …

Feb 20, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.