CVE Database

120754+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2022-23085
8.2 HIGH

A user-provided integer option was passed to nmreq_copyin() without checking if it would overflow. This insufficient bounds checking could lead to kernel memory corruption. On …

Feb 15, 2024
CVE-2022-23084
7.5 HIGH

The total size of the user-provided nmreq to nmreq_copyin() was first computed and then trusted during the copyin. This time-of-check to time-of-use bug could lead …

Feb 15, 2024
CVE-2024-26264
9.8 CRITICAL

EBM Technologies RISWEB's specific query function parameter does not properly restrict user input, and this feature page is accessible without login. This allows remote attackers …

Feb 15, 2024
CVE-2024-26263
5.3 MEDIUM

EBM Technologies RISWEB's specific URL path is not properly controlled by permission, allowing attackers to browse specific pages and query sensitive data without login.

Feb 15, 2024
CVE-2024-26262
8.8 HIGH

EBM Technologies Uniweb/SoliPACS WebServer's query functionality lacks proper restrictions of user input, allowing remote attackers authenticated as regular user to inject SQL commands for reading, …

Feb 15, 2024
CVE-2024-26261
9.8 CRITICAL

The functionality for file download in HGiga OAKlouds' certain modules contains an Arbitrary File Read and Delete vulnerability. Attackers can put file path in specific …

Feb 15, 2024
CVE-2024-26260
9.8 CRITICAL

The functionality for synchronization in HGiga OAKlouds' certain moudules has an OS Command Injection vulnerability, allowing remote attackers to inject system commands within specific request …

Feb 15, 2024
CVE-2024-1523
8.8 HIGH

EC-WEB FS-EZViewer(Web)'s query functionality lacks proper restrictions of user input, allowing remote attackers authenticated as regular user to inject SQL commands for reading, modifying, and …

Feb 15, 2024
CVE-2024-25620
6.4 MEDIUM

Helm is a tool for managing Charts. Charts are packages of pre-configured Kubernetes resources. When either the Helm client or SDK is used to save …

Feb 15, 2024
CVE-2024-24301
8.8 HIGH

Command Injection vulnerability discovered in 4ipnet EAP-767 device v3.42.00 within the web interface of the device allows attackers with valid credentials to inject arbitrary shell …

Feb 14, 2024
CVE-2024-24300
9.8 CRITICAL

4ipnet EAP-767 v3.42.00 is vulnerable to Incorrect Access Control. The device uses the same set of credentials, regardless of how many times a user logs …

Feb 14, 2024
CVE-2023-6138
7.9 HIGH

A potential security vulnerability has been identified in the system BIOS for certain HP Workstation PCs, which might allow escalation of privilege, arbitrary code execution, …

Feb 14, 2024
CVE-2022-48220
6.4 MEDIUM

Potential vulnerabilities have been identified in certain HP Desktop PC products using the HP TamperLock feature, which might allow intrusion detection bypass via a physical …

Feb 14, 2024
CVE-2022-48219
6.4 MEDIUM

Potential vulnerabilities have been identified in certain HP Desktop PC products using the HP TamperLock feature, which might allow intrusion detection bypass via a physical …

Feb 14, 2024
CVE-2024-1471
5.9 MEDIUM

An HTML injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application could modify Repository parameters, which could lead …

Feb 14, 2024
CVE-2024-1367
7.2 HIGH

A command injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application could modify Logging parameters, which could lead …

Feb 14, 2024
CVE-2023-49721
6.7 MEDIUM

An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident attacker to bypass Secure Boot.

Feb 14, 2024
CVE-2023-48733
6.7 MEDIUM

An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure Boot.

Feb 14, 2024
CVE-2024-25619
3.1 LOW

Mastodon is a free, open-source social network server based on ActivityPub. When an OAuth Application is destroyed, the streaming server wasn't being informed that the …

Feb 14, 2024
CVE-2024-25618
4.2 MEDIUM

Mastodon is a free, open-source social network server based on ActivityPub. Mastodon allows new identities from configured authentication providers (CAS, SAML, OIDC) to attach to …

Feb 14, 2024
CVE-2024-25617
5.3 MEDIUM

Squid is an open source caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Collapse of Data into Unsafe Value …

Feb 14, 2024
CVE-2024-25165
7.8 HIGH

A global-buffer-overflow vulnerability was found in SWFTools v0.9.2, in the function LineText at lib/swf5compiler.flex.

Feb 14, 2024
CVE-2024-1482
7.1 HIGH

An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed an attacker to create new branches in public repositories and run arbitrary GitHub …

Feb 14, 2024
CVE-2023-50927
8.6 HIGH

Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. An attacker can trigger out-of-bounds reads in the RPL-Lite implementation of the RPL protocol …

Feb 14, 2024
CVE-2023-50926
7.5 HIGH

Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. An out-of-bounds read can be caused by an incoming DIO message when using the …

Feb 14, 2024
CVE-2024-25301
7.2 HIGH

Redaxo v5.15.1 was discovered to contain a remote code execution (RCE) vulnerability via the component /pages/templates.php.

Feb 14, 2024
CVE-2024-25300
4.8 MEDIUM

A cross-site scripting (XSS) vulnerability in Redaxo v5.15.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name …

Feb 14, 2024
CVE-2023-48229
7.0 HIGH

Contiki-NG is an open-source, cross-platform operating system for Next-Generation IoT devices. An out-of-bounds write exists in the driver for IEEE 802.15.4 radios on nRF platforms …

Feb 14, 2024
CVE-2024-0011
4.3 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the Captive Portal feature of Palo Alto Networks PAN-OS software enables execution of malicious JavaScript (in the context …

Feb 14, 2024
CVE-2024-0010
4.3 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the GlobalProtect portal feature of Palo Alto Networks PAN-OS software enables execution of malicious JavaScript (in the context …

Feb 14, 2024
CVE-2024-0009
6.3 MEDIUM

An improper verification vulnerability in the GlobalProtect gateway feature of Palo Alto Networks PAN-OS software enables a malicious user with stolen credentials to establish a …

Feb 14, 2024
CVE-2024-0008
6.6 MEDIUM

Web sessions in the management interface in Palo Alto Networks PAN-OS software do not expire in certain situations, making it susceptible to unauthorized access.

Feb 14, 2024
CVE-2024-0007
6.8 MEDIUM

A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a malicious authenticated read-write administrator to store a JavaScript payload using the web …

Feb 14, 2024
CVE-2024-24990
7.5 HIGH

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note: The …

Feb 14, 2024
CVE-2024-24989
7.5 HIGH

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note: The …

Feb 14, 2024
CVE-2024-24966
6.2 MEDIUM

When LDAP remote authentication is configured on F5OS, a remote user without an assigned role will be incorrectly authorized. Note: Software versions which have reached …

Feb 14, 2024
CVE-2024-24775
7.5 HIGH

When a virtual server is enabled with VLAN group and SNAT listener is configured, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. …

Feb 14, 2024
CVE-2024-23982
7.5 HIGH

When a BIG-IP PEM classification profile is configured on a UDP virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. This …

Feb 14, 2024
CVE-2024-23979
7.5 HIGH

When SSL Client Certificate LDAP or Certificate Revocation List Distribution Point (CRLDP) authentication profile is configured on a virtual server, undisclosed requests can cause an …

Feb 14, 2024
CVE-2024-23976
6.0 MEDIUM

When running in Appliance mode, an authenticated attacker assigned the Administrator role may be able to bypass Appliance mode restrictions utilizing iAppsLX templates on a …

Feb 14, 2024
CVE-2024-23805
7.5 HIGH

Undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. For the Application Visibility and Reporting module, this may occur when the HTTP Analytics …

Feb 14, 2024
CVE-2024-23607
5.5 MEDIUM

A directory traversal vulnerability exists in the F5OS QKView utility that allows an authenticated attacker to read files outside the QKView directory. Note: Software versions …

Feb 14, 2024
CVE-2024-23603
3.8 LOW

An SQL injection vulnerability exists in an undisclosed page of the BIG-IP Configuration utility. Note: Software versions which have reached End of Technical Support (EoTS) …

Feb 14, 2024
CVE-2024-23314
7.5 HIGH

When HTTP/2 is configured on BIG-IP or BIG-IP Next SPK systems, undisclosed responses can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions …

Feb 14, 2024
CVE-2024-23308
7.5 HIGH

When a BIG-IP Advanced WAF or BIG-IP ASM policy with a Request Body Handling option is attached to a virtual server, undisclosed requests can cause …

Feb 14, 2024
CVE-2024-23306
7.1 HIGH

A vulnerability exists in BIG-IP Next CNF and SPK systems that may allow access to undisclosed sensitive files. Note: Software versions which have reached End …

Feb 14, 2024
CVE-2024-22389
7.2 HIGH

When BIG-IP is deployed in high availability (HA) and an iControl REST API token is updated, the change does not sync to the peer device. …

Feb 14, 2024
CVE-2024-22093
8.7 HIGH

When running in appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint on multi-bladed systems. A successful exploit can …

Feb 14, 2024
CVE-2024-21849
7.5 HIGH

When an Advanced WAF/ASM security policy and a Websockets profile are configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) …

Feb 14, 2024
CVE-2024-21789
7.5 HIGH

When a BIG-IP ASM/Advanced WAF security policy is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software …

Feb 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.