CVE Database

120754+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-21891
8.8 HIGH

Node.js depends on multiple built-in utility functions to normalize paths provided to node:fs functions, which can be overwitten with user-defined implementations leading to filesystem permission …

Feb 20, 2024
CVE-2024-21890
6.5 MEDIUM

The Node.js Permission Model does not clarify in the documentation that wildcards should be only used as the last character of a file path. For …

Feb 20, 2024
CVE-2024-0715
7.6 HIGH

Expression Language Injection vulnerability in Hitachi Global Link Manager on Windows allows Code Injection.This issue affects Hitachi Global Link Manager: before 8.8.7-03.

Feb 20, 2024
CVE-2023-6399
5.7 MEDIUM

A format string vulnerability in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1, USG FLEX series firmware versions from 4.50 through 5.37 …

Feb 20, 2024
CVE-2023-6398
7.2 HIGH

A post-authentication command injection vulnerability in the file upload binary in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1, USG FLEX series …

Feb 20, 2024
CVE-2023-6397
6.5 MEDIUM

A null pointer dereference vulnerability in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1 and USG FLEX series firmware versions from 4.50 …

Feb 20, 2024
CVE-2024-1648
7.5 HIGH

electron-pdf version 20.0.0 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the HTML content …

Feb 20, 2024
CVE-2024-1647
7.5 HIGH

Pyhtml2pdf version 0.0.6 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the HTML content …

Feb 20, 2024
CVE-2024-1651
10.0 CRITICAL

Torrentpier version 2.4.1 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to insecure deserialization.

Feb 20, 2024
CVE-2024-1644
9.9 CRITICAL

Suite CRM version 7.14.2 allows including local php files. This is possible because the application is vulnerable to LFI.

Feb 20, 2024
CVE-2024-1297
7.2 HIGH

Loomio version 2.22.0 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to OS Command Injection.

Feb 20, 2024
CVE-2022-48625
7.5 HIGH

Yealink Config Encrypt Tool add RSA before 1.2 has a built-in RSA key pair, and thus there is a risk of decryption by an adversary.

Feb 20, 2024
CVE-2024-26134
7.5 HIGH

cbor2 provides encoding and decoding for the Concise Binary Object Representation (CBOR) (RFC 8949) serialization format. Starting in version 5.5.1 and prior to version 5.6.2, …

Feb 19, 2024
CVE-2024-26129
5.8 MEDIUM

PrestaShop is an open-source e-commerce platform. Starting in version 8.1.0 and prior to version 8.1.4, PrestaShop is vulnerable to path disclosure in a JavaScript variable. …

Feb 19, 2024
CVE-2024-1638
8.2 HIGH

The documentation specifies that the BT_GATT_PERM_READ_LESC and BT_GATT_PERM_WRITE_LESC defines for a Bluetooth characteristic: Attribute read/write permission with LE Secure Connection encryption. If set, requires that …

Feb 19, 2024
CVE-2024-1635
7.5 HIGH

A vulnerability was found in Undertow. This vulnerability impacts a server that supports the wildfly-http-client protocol. Whenever a malicious user opens and closes a connection …

Feb 19, 2024
CVE-2023-6260
9.0 CRITICAL

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Brivo ACS100, ACS300 allows OS Command Injection, Bypassing Physical Security.This …

Feb 19, 2024
CVE-2023-6259
7.1 HIGH

Insufficiently Protected Credentials, : Improper Access Control vulnerability in Brivo ACS100, ACS300 allows Password Recovery Exploitation, Bypassing Physical Security.This issue affects ACS100, ACS300: from 5.2.4 …

Feb 19, 2024
CVE-2024-25640
4.6 MEDIUM

Iris is a web collaborative platform that helps incident responders share technical details during investigations. A stored Cross-Site Scripting (XSS) vulnerability has been identified in …

Feb 19, 2024
CVE-2024-25636
7.1 HIGH

Misskey is an open source, decentralized social media platform with ActivityPub support. Prior to version 2024.2.0, when fetching remote Activity Streams objects, Misskey doesn't check …

Feb 19, 2024
CVE-2024-25635
8.8 HIGH

alf.io is an open source ticket reservation system. Prior to version 2.0-Mr-2402, organization owners can view the generated API KEY and USERS of other organization …

Feb 19, 2024
CVE-2024-25634
7.2 HIGH

alf.io is an open source ticket reservation system. Prior to version 2.0-Mr-2402, an attacker can access data from other organizers. The attacker can use a …

Feb 19, 2024
CVE-2024-25626
8.8 HIGH

Yocto Project is an open source collaboration project that helps developers create custom Linux-based systems regardless of the hardware architecture. In Yocto Projects Bitbake before …

Feb 19, 2024
CVE-2023-50257
9.6 CRITICAL

eProsima Fast DDS (formerly Fast RTPS) is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Even with the application …

Feb 19, 2024
CVE-2024-25983
3.5 LOW

Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise …

Feb 19, 2024
CVE-2024-25982
4.3 MEDIUM

The link to update all installed language packs did not include the necessary token to prevent a CSRF risk.

Feb 19, 2024
CVE-2024-25981
4.3 MEDIUM

Separate Groups mode restrictions were not honored when performing a forum export, which would export forum data for all groups. By default this only provided …

Feb 19, 2024
CVE-2024-25980
4.3 MEDIUM

Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups. By default this only provided additional …

Feb 19, 2024
CVE-2024-25979
5.3 MEDIUM

The URL parameters accepted by forum search were not limited to the allowed parameters.

Feb 19, 2024
CVE-2024-25978
7.5 HIGH

Insufficient file size checks resulted in a denial of service risk in the file picker's unzip functionality.

Feb 19, 2024
CVE-2024-1633
2.0 LOW

During the secure boot, bl2 (the second stage of the bootloader) loops over images defined in the table “bl2_mem_params_descs”. For each image, the bl2 reads …

Feb 19, 2024
CVE-2024-25625
8.1 HIGH

Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. A potential security vulnerability has been discovered in `pimcore/admin-ui-classic-bundle` prior to version 1.3.4. The vulnerability …

Feb 19, 2024
CVE-2024-25623
8.5 HIGH

Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.2.7, 4.1.15, 4.0.15, and 3.5.19, when fetching remote statuses, Mastodon doesn't …

Feb 19, 2024
CVE-2024-1597
10.0 CRITICAL

pgjdbc, the PostgreSQL JDBC Driver, allows attacker to inject SQL if using PreferQueryMode=SIMPLE. Note this is not the default. In the default mode there is …

Feb 19, 2024
CVE-2024-1346
6.8 MEDIUM

Weak MySQL database root password in LaborOfficeFree affects version 19.10. This vulnerability allows an attacker to calculate the root password of the MySQL database used …

Feb 19, 2024
CVE-2024-1345
6.8 MEDIUM

Weak MySQL database root password in LaborOfficeFree affects version 19.10. This vulnerability allows an attacker to perform a brute force attack and easily discover the …

Feb 19, 2024
CVE-2024-1344
6.8 MEDIUM

Encrypted database credentials in LaborOfficeFree affecting version 19.10. This vulnerability allows an attacker to read and extract the username and password from the database of …

Feb 19, 2024
CVE-2024-1343
4.7 MEDIUM

A weak permission was found in the backup directory in LaborOfficeFree affecting version 19.10. This vulnerability allows any authenticated user to read backup files in …

Feb 19, 2024
CVE-2024-1580
5.9 MEDIUM

An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the …

Feb 19, 2024
CVE-2024-26308
5.5 MEDIUM

Allocation of Resources Without Limits or Throttling vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.21 before 1.26. Users are recommended to …

Feb 19, 2024
CVE-2024-25710
8.1 HIGH

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.3 through 1.25.0. Users are recommended to …

Feb 19, 2024
CVE-2024-24722
9.1 CRITICAL

An unquoted service path vulnerability in the 12d Synergy Server and File Replication Server components may allow an attacker to gain elevated privileges via the …

Feb 19, 2024
CVE-2024-26328
6.0 MEDIUM

An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c does not set NumVFs to PCI_SRIOV_TOTAL_VF, and thus interaction with hw/nvme/ctrl.c is mishandled.

Feb 19, 2024
CVE-2024-26327
5.3 MEDIUM

An issue was discovered in QEMU 7.1.0 through 8.2.1. register_vfs in hw/pci/pcie_sriov.c mishandles the situation where a guest writes NumVFs greater than TotalVFs, leading to …

Feb 19, 2024
CVE-2024-26318
6.1 MEDIUM

Serenity before 6.8.0 allows XSS via an email link because LoginPage.tsx permits return URLs that do not begin with a / character.

Feb 19, 2024
CVE-2020-36774
5.5 MEDIUM

plugins/gtk+/glade-gtk-box.c in GNOME Glade before 3.38.1 and 3.39.x before 3.40.0 mishandles widget rebuilding for GladeGtkBox, leading to a denial of service (application crash).

Feb 19, 2024
CVE-2022-48624
7.8 HIGH

close_altfile in filename.c in less before 606 omits shell_quote calls for LESSCLOSE.

Feb 19, 2024
CVE-2023-6249
8.0 HIGH

Signed to unsigned conversion esp32_ipm_send

Feb 18, 2024
CVE-2023-5779
4.4 MEDIUM

can: out of bounds in remove_rx_filter function

Feb 18, 2024
CVE-2023-6749
8.0 HIGH

Unchecked length coming from user input in settings shell

Feb 18, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.