CVE Database

120754+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-24003
9.8 CRITICAL

jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseResponseInfo findInOutMaterialCount() function of jshERP does not filter `column` and `order` parameters well enough, and an …

Feb 8, 2024
CVE-2024-22394
9.8 CRITICAL

An improper authentication vulnerability has been identified in SonicWall SonicOS SSL-VPN feature, which in specific conditions could allow a remote attacker to bypass authentication. This …

Feb 8, 2024
CVE-2024-24350
8.8 HIGH

File Upload vulnerability in Software Publico e-Sic Livre v.2.0 and before allows a remote attacker to execute arbitrary code via the extension filtering component.

Feb 8, 2024
CVE-2024-24026
9.8 CRITICAL

An arbitrary File upload vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions at com.java2nb.system.controller.SysUserController: uploadImg(). An attacker can pass in specially crafted filename parameter to …

Feb 8, 2024
CVE-2024-24025
9.8 CRITICAL

An arbitrary File upload vulnerability exists in Novel-Plus v4.3.0-RC1 and prior at com.java2nb.common.controller.FileController: upload(). An attacker can pass in specially crafted filename parameter to perform …

Feb 8, 2024
CVE-2024-24024
9.8 CRITICAL

An arbitrary File download vulnerability exists in Novel-Plus v4.3.0-RC1 and prior at com.java2nb.common.controller.FileController: fileDownload(). An attacker can pass in specially crafted filePath and fieName parameters …

Feb 8, 2024
CVE-2024-24023
9.8 CRITICAL

A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior. An attacker can pass specially crafted offset, limit, and sort parameters to perform SQL injection …

Feb 8, 2024
CVE-2024-24018
9.8 CRITICAL

A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset, limit, and sort parameters to perform SQL …

Feb 8, 2024
CVE-2023-48974
9.6 CRITICAL

Cross Site Scripting vulnerability in Axigen WebMail prior to 10.3.3.61 allows a remote attacker to escalate privileges via a crafted script to the serverName_input parameter.

Feb 8, 2024
CVE-2024-24806
7.3 HIGH

libuv is a multi-platform support library with a focus on asynchronous I/O. The `uv_getaddrinfo` function in `src/unix/getaddrinfo.c` (and its windows counterpart `src/win/getaddrinfo.c`), truncates hostnames to …

Feb 7, 2024
CVE-2024-23448
5.7 MEDIUM

An issue was discovered whereby APM Server could log at ERROR level, a response from Elasticsearch indicating that indexing the document failed and that response …

Feb 7, 2024
CVE-2024-1066
6.5 MEDIUM

An issue has been discovered in GitLab EE affecting all versions from 13.3.0 prior to 16.6.7, 16.7 prior to 16.7.5, and 16.8 prior to 16.8.2 …

Feb 7, 2024
CVE-2023-6840
6.7 MEDIUM

An issue has been discovered in GitLab EE affecting all versions from 16.4 prior to 16.6.7, 16.7 prior to 16.7.5, and 16.8 prior to 16.8.2 …

Feb 7, 2024
CVE-2023-6736
6.5 MEDIUM

An issue has been discovered in GitLab EE affecting all versions starting from 11.3 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions …

Feb 7, 2024
CVE-2023-6536
6.5 MEDIUM

A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP …

Feb 7, 2024
CVE-2023-6535
6.5 MEDIUM

A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP …

Feb 7, 2024
CVE-2023-6356
6.5 MEDIUM

A flaw was found in the Linux kernel's NVMe driver. This issue may allow an unauthenticated malicious actor to send a set of crafted TCP …

Feb 7, 2024
CVE-2024-24488
5.5 MEDIUM

An issue in Shenzen Tenda Technology CP3V2.0 V11.10.00.2311090948 allows a local attacker to obtain sensitive information via the password component.

Feb 7, 2024
CVE-2024-22984

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not …

Feb 7, 2024
CVE-2023-38995
9.8 CRITICAL

An issue in SCHUHFRIED v.8.22.00 allows remote attacker to obtain the database password via crafted curl command.

Feb 7, 2024
CVE-2024-23769
7.3 HIGH

Improper privilege control for the named pipe in Samsung Magician PC Software 8.0.0 (for Windows) allows a local attacker to read privileged data.

Feb 7, 2024
CVE-2024-24824
8.8 HIGH

Graylog is a free and open log management platform. Starting in version 2.0.0 and prior to versions 5.1.11 and 5.2.4, arbitrary classes can be loaded …

Feb 7, 2024
CVE-2024-24823
5.7 MEDIUM

Graylog is a free and open log management platform. Starting in version 4.3.0 and prior to versions 5.1.11 and 5.2.4, reauthenticating with an existing session …

Feb 7, 2024
CVE-2024-24822
6.5 MEDIUM

Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. Prior to version 1.3.3, an attacker can create, delete etc. tags without having the …

Feb 7, 2024
CVE-2024-24816
6.1 MEDIUM

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability vulnerability has been discovered in versions prior to 4.24.0-lts in samples that use …

Feb 7, 2024
CVE-2024-24706
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Forum One WP-CFM wp-cfm.This issue affects WP-CFM: from n/a through 1.7.8.

Feb 7, 2024
CVE-2024-24563
9.8 CRITICAL

Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine. Arrays can be keyed by a signed integer, while they are defined for …

Feb 7, 2024
CVE-2024-23806
5.3 MEDIUM

Sensitive data can be extracted from HID iCLASS SE reader configuration cards. This could include credential and device administrator keys.

Feb 7, 2024
CVE-2024-20290
7.5 HIGH

A vulnerability in the OLE2 file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on …

Feb 7, 2024
CVE-2024-20255
8.2 HIGH

A vulnerability in the SOAP API of Cisco Expressway Series and Cisco TelePresence Video Communication Server could allow an unauthenticated, remote attacker to conduct a …

Feb 7, 2024
CVE-2024-20254
9.6 CRITICAL

Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to conduct cross-site request forgery (CSRF) …

Feb 7, 2024
CVE-2024-20252
9.6 CRITICAL

Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to conduct cross-site request forgery (CSRF) …

Feb 7, 2024
CVE-2023-47700
5.9 MEDIUM

IBM SAN Volume Controller, IBM Storwize, IBM FlashSystem and IBM Storage Virtualize 8.6 products could allow a remote attacker to spoof a trusted system that …

Feb 7, 2024
CVE-2023-43017
8.2 HIGH

IBM Security Verify Access 10.0.0.0 through 10.0.6.1 could allow a privileged user to install a configuration file that could allow remote access. IBM X-Force ID: …

Feb 7, 2024
CVE-2023-38369
6.2 MEDIUM

IBM Security Access Manager Container 10.0.0.0 through 10.0.6.1 does not require that docker images should have strong passwords by default, which makes it easier for …

Feb 7, 2024
CVE-2023-32330
7.5 HIGH

IBM Security Verify Access 10.0.0.0 through 10.0.6.1 uses insecure calls that could allow an attacker on the network to take control of the server. IBM …

Feb 7, 2024
CVE-2023-32328
7.5 HIGH

IBM Security Verify Access 10.0.0.0 through 10.0.6.1 uses insecure protocols in some instances that could allow an attacker on the network to take control of …

Feb 7, 2024
CVE-2023-31002
5.1 MEDIUM

IBM Security Access Manager Container 10.0.0.0 through 10.0.6.1 temporarily stores sensitive information in files that could be accessed by a local user. IBM X-Force ID: …

Feb 7, 2024
CVE-2024-24815
6.1 MEDIUM

CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A cross-site scripting vulnerability has been discovered in the core HTML parsing module in versions of CKEditor4 …

Feb 7, 2024
CVE-2024-22012
7.8 HIGH

there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional …

Feb 7, 2024
CVE-2024-25145
9.6 CRITICAL

Stored cross-site scripting (XSS) vulnerability in the Portal Search module's Search Result app in Liferay Portal 7.2.0 through 7.4.3.11, and older unsupported versions, and Liferay …

Feb 7, 2024
CVE-2024-25143
6.5 MEDIUM

The Document and Media widget In Liferay Portal 7.2.0 through 7.3.6, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before …

Feb 7, 2024
CVE-2024-24812
5.4 MEDIUM

Frappe is a full-stack web application framework that uses Python and MariaDB on the server side and a tightly integrated client side library. Prior to …

Feb 7, 2024
CVE-2024-24811
9.8 CRITICAL

SQLAlchemyDA is a generic database adapter for ZSQL methods. A vulnerability found in versions prior to 2.2 allows unauthenticated execution of arbitrary SQL statements on …

Feb 7, 2024
CVE-2024-24771
7.7 HIGH

Open Forms allows users create and publish smart forms. Versions prior to 2.2.9, 2.3.7, 2.4.5, and 2.5.2 contain a non-exploitable multi-factor authentication weakness. Superusers who …

Feb 7, 2024
CVE-2024-25201
7.5 HIGH

Espruino 2v20 (commit fcc9ba4) was discovered to contain an Out-of-bounds Read via jsvStringIteratorPrintfCallback at src/jsvar.c.

Feb 7, 2024
CVE-2024-25200
7.5 HIGH

Espruino 2v20 (commit fcc9ba4) was discovered to contain a Stack Overflow via the jspeFactorFunctionCall at src/jsparse.c.

Feb 7, 2024
CVE-2024-24189
9.8 CRITICAL

Jsish v3.5.0 (commit 42c694c) was discovered to contain a use-after-free via the SplitChar at ./src/jsiUtils.c.

Feb 7, 2024
CVE-2024-24188
9.8 CRITICAL

Jsish v3.5.0 was discovered to contain a heap-buffer-overflow in ./src/jsiUtils.c.

Feb 7, 2024
CVE-2024-24186
9.8 CRITICAL

Jsish v3.5.0 (commit 42c694c) was discovered to contain a stack-overflow via the component IterGetKeysCallback at /jsish/src/jsiValue.c.

Feb 7, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.