CVE Database

120754+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-0323
9.8 CRITICAL

The FTP server used on the B&R Automation Runtime supports unsecure encryption mechanisms, such as SSLv3, TLSv1.0 and TLS1.1. An network-based attacker can exploit the …

Feb 5, 2024
CVE-2023-47355
7.5 HIGH

The com.eypcnnapps.quickreboot (aka Eyuep Can Yilmaz {ROOT] Quick Reboot) application 1.0.8 for Android has exposed broadcast receivers for PowerOff, Reboot, and Recovery (e.g., com.eypcnnapps.quickreboot.widget.PowerOff) that …

Feb 5, 2024
CVE-2024-24768
6.5 MEDIUM

1Panel is an open source Linux server operation and maintenance management panel. The HTTPS cookie that comes with the panel does not have the Secure …

Feb 5, 2024
CVE-2024-24762
7.5 HIGH

`python-multipart` is a streaming multipart parser for Python. When using form data, `python-multipart` uses a Regular Expression to parse the HTTP `Content-Type` header, including options. …

Feb 5, 2024
CVE-2023-7216
5.3 MEDIUM

A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a user into opening a …

Feb 5, 2024
CVE-2023-52138
8.2 HIGH

Engrampa is an archive manager for the MATE environment. Engrampa is found to be vulnerable to a Path Traversal vulnerability that can be leveraged to …

Feb 5, 2024
CVE-2024-23109
10.0 CRITICAL

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands …

Feb 5, 2024
CVE-2024-23108
10.0 CRITICAL

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands …

Feb 5, 2024
CVE-2024-1225
7.3 HIGH

A vulnerability classified as critical was found in QiboSoft QiboCMS X1 up to 1.0.6. Affected by this vulnerability is the function rmb_pay of the file …

Feb 5, 2024
CVE-2023-5643
7.8 HIGH

Out-of-bounds Write vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver …

Feb 5, 2024
CVE-2023-5249
7.0 HIGH

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver allows a local non-privileged user to make improper …

Feb 5, 2024
CVE-2021-4436
9.8 CRITICAL

The 3DPrint Lite WordPress plugin before 1.9.1.5 does not have any authorisation and does not check the uploaded file in its p3dlite_handle_upload AJAX action , …

Feb 5, 2024
CVE-2024-24864
5.3 MEDIUM

A race condition was found in the Linux kernel's media/dvb-core in dvbdmx_write() function. This can result in a null pointer dereference issue, possibly leading to …

Feb 5, 2024
CVE-2024-24861
3.3 LOW

A race condition was found in the Linux kernel's media/xc4000 device driver in xc4000 xc4000_get_frequency() function. This can result in return value overflow issue, possibly …

Feb 5, 2024
CVE-2024-24860
4.6 MEDIUM

A race condition was found in the Linux kernel's bluetooth device driver in {min,max}_key_size_set() function. This can result in a null pointer dereference issue, possibly …

Feb 5, 2024
CVE-2024-24859
4.6 MEDIUM

A race condition was found in the Linux kernel's net/bluetooth in sniff_{min,max}_interval_set() function. This can result in a bluetooth sniffing exception issue, possibly leading denial …

Feb 5, 2024
CVE-2024-24858
4.6 MEDIUM

A race condition was found in the Linux kernel's net/bluetooth in {conn,adv}_{min,max}_interval_set() function. This can result in I2cap connection or broadcast abnormality issue, possibly leading …

Feb 5, 2024
CVE-2024-24857
4.6 MEDIUM

A race condition was found in the Linux kernel's net/bluetooth device driver in conn_info_{min,max}_age_set() function. This can result in integrity overflow issue, possibly leading to …

Feb 5, 2024
CVE-2024-24855
5.0 MEDIUM

A race condition was found in the Linux kernel's scsi device driver in lpfc_unregister_fcf_rescan() function. This can result in a null pointer dereference issue, possibly …

Feb 5, 2024
CVE-2024-23196
5.3 MEDIUM

A race condition was found in the Linux kernel's sound/hda device driver in snd_hdac_regmap_sync() function. This can result in a null pointer dereference issue, possibly …

Feb 5, 2024
CVE-2024-22667
7.8 HIGH

Vim before 9.0.2142 has a stack-based buffer overflow because did_set_langmap in map.c calls sprintf to write to the error buffer that is passed down to …

Feb 5, 2024
CVE-2024-22386
5.3 MEDIUM

A race condition was found in the Linux kernel's drm/exynos device driver in exynos_drm_crtc_atomic_disable() function. This can result in a null pointer dereference issue, possibly …

Feb 5, 2024
CVE-2024-24865
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noah Kagan Scroll Triggered Box allows Stored XSS.This issue affects Scroll Triggered Box: …

Feb 5, 2024
CVE-2024-24848
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MJS Software PT Sign Ups – Beautiful volunteer sign ups and management made …

Feb 5, 2024
CVE-2024-24847
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jgadbois CalculatorPro Calculators allows Reflected XSS.This issue affects CalculatorPro Calculators: from n/a through …

Feb 5, 2024
CVE-2024-24846
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MightyThemes Mighty Addons for Elementor allows Reflected XSS.This issue affects Mighty Addons for …

Feb 5, 2024
CVE-2024-24841
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan's Art Add Customer for WooCommerce allows Stored XSS.This issue affects Add Customer …

Feb 5, 2024
CVE-2024-24839
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gordon Böhme, Antonio Leutsch Structured Content (JSON-LD) #wpsc allows Stored XSS.This issue affects …

Feb 5, 2024
CVE-2024-24838
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Five Star Plugins Five Star Restaurant Reviews allows Stored XSS.This issue affects Five …

Feb 5, 2024
CVE-2023-7077
9.8 CRITICAL

Sharp NEC Displays (P403, P463, P553, P703, P801, X554UN, X464UN, X554UNS, X464UNV, X474HB, X464UNS, X554UNV, X555UNS, X555UNV, X754HB, X554HB, E705, E805, E905, UN551S, UN551VS, X551UHD, …

Feb 5, 2024
CVE-2024-24870
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Dempfle Advanced iFrame allows Stored XSS.This issue affects Advanced iFrame: from n/a …

Feb 5, 2024
CVE-2024-24866
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Biteship Biteship: Plugin Ongkos Kirim Kurir Instant, Reguler, Kargo allows Reflected XSS.This issue …

Feb 5, 2024
CVE-2024-20016
4.4 MEDIUM

In ged, there is a possible out of bounds write due to an integer overflow. This could lead to local denial of service with System …

Feb 5, 2024
CVE-2024-20015
7.8 HIGH

In telephony, there is a possible escalation of privilege due to a permissions bypass. This could lead to local escalation of privilege with no additional …

Feb 5, 2024
CVE-2024-20013
6.7 MEDIUM

In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Feb 5, 2024
CVE-2024-20012
6.7 MEDIUM

In keyInstall, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege with System execution privileges …

Feb 5, 2024
CVE-2024-20011
9.8 CRITICAL

In alac decoder, there is a possible information disclosure due to an incorrect bounds check. This could lead to remote code execution with no additional …

Feb 5, 2024
CVE-2024-20010
6.7 MEDIUM

In keyInstall, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege with System execution privileges …

Feb 5, 2024
CVE-2024-20009
8.8 HIGH

In alac decoder, there is a possible out of bounds write due to an incorrect error handling. This could lead to remote escalation of privilege …

Feb 5, 2024
CVE-2024-20007
7.5 HIGH

In mp3 decoder, there is a possible out of bounds write due to a race condition. This could lead to remote escalation of privilege with …

Feb 5, 2024
CVE-2024-20006
6.7 MEDIUM

In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Feb 5, 2024
CVE-2024-20004
7.5 HIGH

In Modem NL1, there is a possible system crash due to an improper input validation. This could lead to remote denial of service, if NW …

Feb 5, 2024
CVE-2024-20003
7.5 HIGH

In Modem NL1, there is a possible system crash due to an improper input validation. This could lead to remote denial of service, if NW …

Feb 5, 2024
CVE-2024-20002
6.7 MEDIUM

In TVAPI, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Feb 5, 2024
CVE-2024-20001
6.7 MEDIUM

In TVAPI, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Feb 5, 2024
CVE-2023-5800
5.4 MEDIUM

Vintage, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API create_overlay.cgi did not have a sufficient input validation allowing for …

Feb 5, 2024
CVE-2023-5677
6.3 MEDIUM

Brandon Rothel from QED Secure Solutions and Sam Hanson of Dragos have found that the VAPIX API tcptest.cgi did not have a sufficient input validation …

Feb 5, 2024
CVE-2023-51504
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dan Dulaney Dan's Embedder for Google Calendar allows Stored XSS.This issue affects Dan's …

Feb 5, 2024
CVE-2023-47170

Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2023.

Feb 5, 2024
CVE-2024-25089
9.8 CRITICAL

Malwarebytes Binisoft Windows Firewall Control before 6.9.9.2 allows remote attackers to execute arbitrary code via gRPC named pipes.

Feb 4, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.