CVE Database

120754+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-20729
7.8 HIGH

Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

Feb 15, 2024
CVE-2024-20728
7.8 HIGH

Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Feb 15, 2024
CVE-2024-20727
7.8 HIGH

Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Feb 15, 2024
CVE-2024-20726
7.8 HIGH

Acrobat Reader versions 20.005.30539, 23.008.20470 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Feb 15, 2024
CVE-2024-1530
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in ECshop 4.1.8. Affected by this issue is some unknown functionality of the file /admin/view_sendlist.php. …

Feb 15, 2024
CVE-2023-39245
9.8 CRITICAL

DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an information disclosure vulnerability in EHAC component. An remote unauthenticated attacker could potentially exploit …

Feb 15, 2024
CVE-2023-39244
7.3 HIGH

DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an information disclosure vulnerability in EHAC component. An remote unauthenticated attacker could potentially exploit …

Feb 15, 2024
CVE-2023-32484
9.8 CRITICAL

Dell Networking Switches running Enterprise SONiC versions 4.1.0, 4.0.5, 3.5.4 and below contains an improper input validation vulnerability. A remote unauthenticated malicious user may exploit …

Feb 15, 2024
CVE-2023-32462
9.8 CRITICAL

Dell OS10 Networking Switches running 10.5.2.x and above contain an OS command injection vulnerability when using remote user authentication. A remote unauthenticated attacker could potentially …

Feb 15, 2024
CVE-2023-28078
9.1 CRITICAL

Dell OS10 Networking Switches running 10.5.2.x and above contain a vulnerability with zeroMQ when VLT is configured. A remote unauthenticated attacker could potentially exploit this …

Feb 15, 2024
CVE-2024-20744
7.8 HIGH

Substance3D - Painter versions 9.1.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Feb 15, 2024
CVE-2024-20743
7.8 HIGH

Substance3D - Painter versions 9.1.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Feb 15, 2024
CVE-2024-20742
7.8 HIGH

Substance3D - Painter versions 9.1.1 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read …

Feb 15, 2024
CVE-2024-20741
7.8 HIGH

Substance3D - Painter versions 9.1.1 and earlier are affected by a Write-what-where Condition vulnerability that could result in arbitrary code execution in the context of …

Feb 15, 2024
CVE-2024-20740
7.8 HIGH

Substance3D - Painter versions 9.1.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Feb 15, 2024
CVE-2024-20725
5.5 MEDIUM

Substance3D - Painter versions 9.1.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Feb 15, 2024
CVE-2024-20724
5.5 MEDIUM

Substance3D - Painter versions 9.1.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Feb 15, 2024
CVE-2024-20723
7.8 HIGH

Substance3D - Painter versions 9.1.1 and earlier are affected by a Buffer Overflow vulnerability that could result in arbitrary code execution in the context of …

Feb 15, 2024
CVE-2024-20722
5.5 MEDIUM

Substance3D - Painter versions 9.1.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Feb 15, 2024
CVE-2024-0390
9.8 CRITICAL

INPRAX "iZZi connect" application on Android contains hard-coded MQTT queue credentials. The same MQTT queue is used by corresponding physical recuperation devices. Exploiting this vulnerability …

Feb 15, 2024
CVE-2023-4539
7.5 HIGH

Use of a hard-coded password for a special database account created during Comarch ERP XL installation allows an attacker to retrieve embedded sensitive data stored …

Feb 15, 2024
CVE-2023-4538
6.2 MEDIUM

The database access credentials configured during installation are stored in a special table, and are encrypted with a shared key, same among all Comarch ERP …

Feb 15, 2024
CVE-2023-4537
7.4 HIGH

Comarch ERP XL client is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypted communication vulnerable to …

Feb 15, 2024
CVE-2024-24386
7.2 HIGH

An issue in VitalPBX v.3.2.4-5 allows an attacker to execute arbitrary code via a crafted payload to the /var/lib/vitalpbx/scripts folder.

Feb 15, 2024
CVE-2024-24256
5.9 MEDIUM

SQL Injection vulnerability in Yonyou space-time enterprise information integration platform v.9.0 and before allows an attacker to obtain sensitive information via the gwbhAIM parameter in …

Feb 15, 2024
CVE-2024-0353
7.8 HIGH

Local privilege escalation vulnerability potentially allowed an attacker to misuse ESET’s file operations to delete files without having proper permission.

Feb 15, 2024
CVE-2024-21727
6.1 MEDIUM

XSS vulnerability in DP Calendar component for Joomla.

Feb 15, 2024
CVE-2024-0708
5.3 MEDIUM

The Landing Page Cat – Coming Soon Page, Maintenance Page & Squeeze Pages plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions …

Feb 15, 2024
CVE-2023-51787
7.5 HIGH

An issue was discovered in Wind River VxWorks 7 22.09 and 23.03. If a VxWorks task or POSIX thread that uses OpenSSL exits, limited per-task …

Feb 15, 2024
CVE-2023-46596
5.1 MEDIUM

Improper input validation in Algosec FireFlow VisualFlow workflow editor via Name, Description and Configuration File field in version A32.20, A32.50, A32.60 permits an attacker to …

Feb 15, 2024
CVE-2022-23093
6.5 MEDIUM

ping reads raw IP packets from the network to process responses in the pr_pack() function. As part of processing a response ping has to reconstruct …

Feb 15, 2024
CVE-2022-23092
8.8 HIGH

The implementation of lib9p's handling of RWALK messages was missing a bounds check needed when unpacking the message contents. The missing check means that the …

Feb 15, 2024
CVE-2022-23091
4.0 MEDIUM

A particular case of memory sharing is mishandled in the virtual memory system. This is very similar to SA-21:08.vm, but with a different root cause. …

Feb 15, 2024
CVE-2022-23090
7.7 HIGH

The aio_aqueue function, used by the lio_listio system call, fails to release a reference to a credential in an error case. An attacker may cause …

Feb 15, 2024
CVE-2021-29640

Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2021.

Feb 15, 2024
CVE-2021-29639

Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2021.

Feb 15, 2024
CVE-2021-29638

Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2021.

Feb 15, 2024
CVE-2021-29637

Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2021.

Feb 15, 2024
CVE-2021-29636

Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2021.

Feb 15, 2024
CVE-2021-29635

Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2021.

Feb 15, 2024
CVE-2021-29634

Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2021.

Feb 15, 2024
CVE-2021-29633

Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2021.

Feb 15, 2024
CVE-2024-25941
3.3 LOW

The jail(2) system call has not limited a visiblity of allocated TTYs (the kern.ttys sysctl). This gives rise to an information leak about processes outside …

Feb 15, 2024
CVE-2024-25940
6.3 MEDIUM

`bhyveload -h <host-path>` may be used to grant loader access to the <host-path> directory tree on the host. Affected versions of bhyveload(8) do not make …

Feb 15, 2024
CVE-2024-25559
4.7 MEDIUM

URL spoofing vulnerability exists in a-blog cms Ver.3.1.0 to Ver.3.1.8. If an attacker sends a specially crafted request, the administrator of the product may be …

Feb 15, 2024
CVE-2024-1488
8.0 HIGH

A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If …

Feb 15, 2024
CVE-2022-23089
4.7 MEDIUM

When dumping core and saving process information, proc_getargv() might return an sbuf which have a sbuf_len() of 0 or -1, which is not properly handled. …

Feb 15, 2024
CVE-2022-23088
9.8 CRITICAL

The 802.11 beacon handling routine failed to validate the length of an IEEE 802.11s Mesh ID before copying it to a heap-allocated buffer. While a …

Feb 15, 2024
CVE-2022-23087
8.8 HIGH

The e1000 network adapters permit a variety of modifications to an Ethernet packet when it is being transmitted. These include the insertion of IP and …

Feb 15, 2024
CVE-2022-23086
7.8 HIGH

Handlers for *_CFG_PAGE read / write ioctls in the mpr, mps, and mpt drivers allocated a buffer of a caller-specified size, but copied to it …

Feb 15, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.