CVE Database

120754+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-1247
2.0 LOW

Concrete CMS version 9 before 9.2.5 is vulnerable to stored XSS via the Role Name field since there is insufficient validation of administrator provided data …

Feb 9, 2024
CVE-2023-50386
8.8 HIGH

Improper Control of Dynamically-Managed Code Resources, Unrestricted Upload of File with Dangerous Type, Inclusion of Functionality from Untrusted Control Sphere vulnerability in Apache Solr.This issue …

Feb 9, 2024
CVE-2023-50298
7.5 HIGH

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr.This issue affects Apache Solr: from 6.0.0 through 8.11.2, from 9.0.0 before 9.4.1. Solr …

Feb 9, 2024
CVE-2023-50292
7.5 HIGH

Incorrect Permission Assignment for Critical Resource, Improper Control of Dynamically-Managed Code Resources vulnerability in Apache Solr. This issue affects Apache Solr: from 8.10.0 through 8.11.2, …

Feb 9, 2024
CVE-2023-50291
7.5 HIGH

Insufficiently Protected Credentials vulnerability in Apache Solr. This issue affects Apache Solr: from 6.0.0 through 8.11.2, from 9.0.0 before 9.3.0. One of the two endpoints …

Feb 9, 2024
CVE-2024-1402
4.3 MEDIUM

Mattermost fails to check if a custom emoji reaction exists when sending it to a post and to limit the amount of custom emojis allowed …

Feb 9, 2024
CVE-2024-25454
5.5 MEDIUM

Bento4 v1.6.0-640 was discovered to contain a NULL pointer dereference via the AP4_DescriptorFinder::Test() function.

Feb 9, 2024
CVE-2024-25453
5.5 MEDIUM

Bento4 v1.6.0-640 was discovered to contain a NULL pointer dereference via the AP4_StszAtom::GetSampleSize() function.

Feb 9, 2024
CVE-2024-25452
5.5 MEDIUM

Bento4 v1.6.0-640 was discovered to contain an out-of-memory bug via the AP4_UrlAtom::AP4_UrlAtom() function.

Feb 9, 2024
CVE-2024-25451
6.5 MEDIUM

Bento4 v1.6.0-640 was discovered to contain an out-of-memory bug via the AP4_DataBuffer::ReallocateBuffer() function.

Feb 9, 2024
CVE-2024-25450
8.8 HIGH

imlib2 v1.9.1 was discovered to mishandle memory allocation in the function init_imlib_fonts().

Feb 9, 2024
CVE-2024-25448
8.8 HIGH

An issue in the imlib_free_image_and_decache function of imlib2 v1.9.1 allows attackers to cause a heap buffer overflow via parsing a crafted image.

Feb 9, 2024
CVE-2024-25447
8.8 HIGH

An issue in the imlib_load_image_with_error_return function of imlib2 v1.9.1 allows attackers to cause a heap buffer overflow via parsing a crafted image.

Feb 9, 2024
CVE-2024-25446
7.8 HIGH

An issue in the HuginBase::PTools::setDestImage function of Hugin v2022.0.0 allows attackers to cause a heap buffer overflow via parsing a crafted image.

Feb 9, 2024
CVE-2024-25445
7.8 HIGH

Improper handling of values in HuginBase::PTools::Transform::transform of Hugin 2022.0.0 leads to an assertion failure.

Feb 9, 2024
CVE-2024-25443
7.8 HIGH

An issue in the HuginBase::ImageVariable<double>::linkWith function of Hugin v2022.0.0 allows attackers to cause a heap-use-after-free via parsing a crafted image.

Feb 9, 2024
CVE-2024-25442
7.8 HIGH

An issue in the HuginBase::PanoramaMemento::loadPTScript function of Hugin v2022.0.0 allows attackers to cause a heap buffer overflow via parsing a crafted image.

Feb 9, 2024
CVE-2024-24776
3.1 LOW

Mattermost fails to check the required permissions in the POST /api/v4/channels/stats/member_count API resulting in channel member counts being leaked to a user without permissions.

Feb 9, 2024
CVE-2024-24774
3.4 LOW

Mattermost Jira Plugin handling subscriptions fails to check the security level of an incoming issue or limit it based on the user who created the …

Feb 9, 2024
CVE-2024-23319
3.5 LOW

Mattermost Jira Plugin fails to protect against logout CSRF allowing an attacker to post a specially crafted message that would disconnect a user's Jira connection …

Feb 9, 2024
CVE-2024-25318
8.8 HIGH

Code-projects Hotel Managment System 1.0 allows SQL Injection via the 'pid' parameter in Hotel/admin/print.php?pid=2.

Feb 9, 2024
CVE-2024-25316
9.8 CRITICAL

Code-projects Hotel Managment System 1.0 allows SQL Injection via the 'eid' parameter in Hotel/admin/usersettingdel.php?eid=2.

Feb 9, 2024
CVE-2024-25315
9.8 CRITICAL

Code-projects Hotel Managment System 1.0, allows SQL Injection via the 'rid' parameter in Hotel/admin/roombook.php?rid=2.

Feb 9, 2024
CVE-2024-25314
9.8 CRITICAL

Code-projects Hotel Managment System 1.0, allows SQL Injection via the 'sid' parameter in Hotel/admin/show.php?sid=2.

Feb 9, 2024
CVE-2024-25310
8.8 HIGH

Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'id' parameter at "School/delete.php?id=5."

Feb 9, 2024
CVE-2024-25307
9.8 CRITICAL

Code-projects Cinema Seat Reservation System 1.0 allows SQL Injection via the 'id' parameter at "/Cinema-Reservation/booking.php?id=1."

Feb 9, 2024
CVE-2024-25302
9.8 CRITICAL

Sourcecodester Event Student Attendance System 1.0, allows SQL Injection via the 'student' parameter.

Feb 9, 2024
CVE-2023-6677
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Oduyo Financial Technology Online Collection allows SQL Injection.This issue affects Online …

Feb 9, 2024
CVE-2024-25313
8.8 HIGH

Code-projects Simple School Managment System 1.0 allows Authentication Bypass via the username and password parameters at School/teacher_login.php.

Feb 9, 2024
CVE-2024-25312
8.8 HIGH

Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'id' parameter at "School/sub_delete.php?id=5."

Feb 9, 2024
CVE-2024-25309
8.8 HIGH

Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'pass' parameter at School/teacher_login.php.

Feb 9, 2024
CVE-2024-25308
8.8 HIGH

Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'name' parameter at School/teacher_login.php.

Feb 9, 2024
CVE-2024-25306
8.8 HIGH

Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'aname' parameter at "School/index.php".

Feb 9, 2024
CVE-2024-25305
8.8 HIGH

Code-projects Simple School Managment System 1.0 allows Authentication Bypass via the username and password parameters at School/index.php.

Feb 9, 2024
CVE-2024-25304
8.8 HIGH

Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'apass' parameter at "School/index.php."

Feb 9, 2024
CVE-2023-6724
8.8 HIGH

Authorization Bypass Through User-Controlled Key vulnerability in Software Engineering Consultancy Machine Equipment Limited Company Hearing Tracking System allows Authentication Abuse.This issue affects Hearing Tracking System: …

Feb 9, 2024
CVE-2024-25679
6.5 MEDIUM

In PQUIC before 5bde5bb, retention of unused initial encryption keys allows attackers to disrupt a connection with a PSK configuration by sending a CONNECTION_CLOSE frame …

Feb 9, 2024
CVE-2024-25678
9.8 CRITICAL

In LiteSpeed QUIC (LSQUIC) Library before 4.0.4, DCID validation is mishandled.

Feb 9, 2024
CVE-2024-25677
8.8 HIGH

In Min before 1.31.0, local files are not correctly treated as unique security origins, which allows them to improperly request cross-origin resources. For example, a …

Feb 9, 2024
CVE-2024-25675
9.8 CRITICAL

An issue was discovered in MISP before 2.4.184. A client does not need to use POST to start an export generation process. This is related …

Feb 9, 2024
CVE-2024-25674
9.8 CRITICAL

An issue was discovered in MISP before 2.4.184. Organisation logo upload is insecure because of a lack of checks for the file extension and MIME …

Feb 9, 2024
CVE-2024-22119
5.5 MEDIUM

The cause of vulnerability is improper validation of form input field “Name” on Graph page in Items section.

Feb 9, 2024
CVE-2024-21762
9.8 CRITICAL KEV

A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, …

Feb 9, 2024
CVE-2024-24308
9.8 CRITICAL

SQL Injection vulnerability in Boostmyshop (boostmyshopagent) module for Prestashop versions 1.1.9 and before, allows remote attackers to escalate privileges and obtain sensitive information via changeOrderCarrier.php, …

Feb 9, 2024
CVE-2024-23749
7.8 HIGH

KiTTY versions 0.76.1.13 and before is vulnerable to command injection via the filename variable, occurs due to insufficient input sanitization and validation, failure to escape …

Feb 9, 2024
CVE-2023-50026
9.8 CRITICAL

SQL injection vulnerability in Presta Monster "Multi Accessories Pro" (hsmultiaccessoriespro) module for PrestaShop versions 5.1.1 and before, allows remote attackers to escalate privileges and obtain …

Feb 9, 2024
CVE-2023-46350
9.8 CRITICAL

SQL injection vulnerability in InnovaDeluxe "Manufacturer or supplier alphabetical search" (idxrmanufacturer) module for PrestaShop versions 2.0.4 and before, allows remote attackers to escalate privileges and …

Feb 9, 2024
CVE-2024-25004
7.8 HIGH

KiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the username, occurs due to insufficient bounds checking and input sanitization (at …

Feb 9, 2024
CVE-2024-25003
7.8 HIGH

KiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the hostname, occurs due to insufficient bounds checking and input sanitization. This …

Feb 9, 2024
CVE-2024-0229
7.8 HIGH

An out-of-bounds memory access flaw was found in the X.Org server. This issue can be triggered when a device frozen by a sync grab is …

Feb 9, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.