CVE Database

38976+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-23947
8.8 HIGH

Multiple improper array index validation vulnerabilities exist in the readMSH functionality of libigl v2.5.0. A specially crafted .msh file can lead to an out-of-bounds write. …

May 28, 2024
CVE-2024-22181
7.8 HIGH

An out-of-bounds write vulnerability exists in the readNODE functionality of libigl v2.5.0. A specially crafted .node file can lead to an out-of-bounds write. An attacker …

May 28, 2024
CVE-2023-49600
8.1 HIGH

An out-of-bounds write vulnerability exists in the PlyFile ply_cast_ascii functionality of libigl v2.5.0. A specially crafted .ply file can lead to a heap buffer overflow. …

May 28, 2024
CVE-2023-35953
7.8 HIGH

Multiple stack-based buffer overflow vulnerabilities exist in the readOFF.cpp functionality of libigl v2.4.0. A specially-crafted .off file can lead to a buffer overflow. An attacker …

May 28, 2024
CVE-2023-35952
7.8 HIGH

Multiple stack-based buffer overflow vulnerabilities exist in the readOFF.cpp functionality of libigl v2.4.0. A specially-crafted .off file can lead to a buffer overflow. An attacker …

May 28, 2024
CVE-2023-35951
7.8 HIGH

Multiple stack-based buffer overflow vulnerabilities exist in the readOFF.cpp functionality of libigl v2.4.0. A specially-crafted .off file can lead to a buffer overflow. An attacker …

May 28, 2024
CVE-2023-35950
7.8 HIGH

Multiple stack-based buffer overflow vulnerabilities exist in the readOFF.cpp functionality of libigl v2.4.0. A specially-crafted .off file can lead to a buffer overflow. An attacker …

May 28, 2024
CVE-2023-35949
7.8 HIGH

Multiple stack-based buffer overflow vulnerabilities exist in the readOFF.cpp functionality of libigl v2.4.0. A specially-crafted .off file can lead to a buffer overflow. An attacker …

May 28, 2024
CVE-2024-5415
7.1 HIGH

A vulnerability have been discovered in PhpMyBackupPro affecting version 2.3 that could allow an attacker to execute XSS through /phpmybackuppro/backup.php, 'comments' and 'db' parameters. This …

May 28, 2024
CVE-2024-5414
7.1 HIGH

A vulnerability have been discovered in PhpMyBackupPro affecting version 2.3 that could allow an attacker to execute XSS through /phpmybackuppro/get_file.php, 'view' parameter. This vulnerabilities could …

May 28, 2024
CVE-2024-5413
7.1 HIGH

A vulnerability have been discovered in PhpMyBackupPro affecting version 2.3 that could allow an attacker to execute XSS through /phpmybackuppro/scheduled.php, all parameters. This vulnerabilities could …

May 28, 2024
CVE-2024-3657
7.5 HIGH

A flaw was found in 389-ds-base. A specially-crafted LDAP query can potentially cause a failure on the directory server, leading to a denial of service

May 28, 2024
CVE-2024-5411
8.8 HIGH

Missing input validation and OS command integration of the input in the ORing IAP-420 web-interface allows authenticated command injection.This issue affects IAP-420 version 2.01e and …

May 28, 2024
CVE-2023-52712
7.8 HIGH

Various Issues Due To Exposed SMI Handler in AmdPspP2CmboxV2. The first issue can be leveraged to bypass the protections that have been put in place …

May 28, 2024
CVE-2023-52711
7.8 HIGH

Various Issues Due To Exposed SMI Handler in AmdPspP2CmboxV2. The first issue can be leveraged to bypass the protections that have been put in place …

May 28, 2024
CVE-2023-52710
7.8 HIGH

Huawei Matebook D16(Model: CREM-WXX9, BIOS: v2.26), As the communication buffer size hasn’t been properly validated to be of the expected size, it can partially overlap …

May 28, 2024
CVE-2023-52548
7.8 HIGH

Huawei Matebook D16(Model: CREM-WXX9, BIOS: v2.26) Arbitrary Memory Corruption in SMI Handler of ThisiServicesSmm SMM module. This can be leveraged by a malicious OS attacker …

May 28, 2024
CVE-2023-52547
7.8 HIGH

Huawei Matebook D16(Model: CREM-WXX9, BIOS: v2.26. Memory Corruption in SMI Handler of HddPassword SMM Module. This can be leveraged by a malicious OS attacker to …

May 28, 2024
CVE-2022-48681
7.2 HIGH

Some Huawei smart speakers have a memory overflow vulnerability. Successful exploitation of this vulnerability may cause certain functions to fail.

May 28, 2024
CVE-2024-28886
8.4 HIGH

OS command injection vulnerability exists in UTAU versions prior to v0.4.19. If a user of the product opens a crafted UTAU project file (.ust file), …

May 28, 2024
CVE-2024-29078
7.5 HIGH

Incorrect permission assignment for critical resource issue exists in MosP kintai kanri V4.6.6 and earlier, which may allow a remote unauthenticated attacker with access to …

May 28, 2024
CVE-2024-36428
8.1 HIGH

OrangeHRM 3.3.3 allows admin/viewProjects sortOrder SQL injection.

May 27, 2024
CVE-2024-36426
7.5 HIGH

In TARGIT Decision Suite 23.2.15007.0 before Autumn 2023, the session token is part of the URL and may be sent in a cleartext HTTP session.

May 27, 2024
CVE-2024-29415
8.1 HIGH

The ip package through 2.0.1 for Node.js might allow SSRF because some IP addresses (such as 127.1, 01200034567, 012.1.2.3, 000:0:0000::01, and ::fFFf:127.0.0.1) are improperly categorized …

May 27, 2024
CVE-2024-35237
7.5 HIGH

MIT IdentiBot is an open-source Discord bot written in Node.js that verifies individuals' affiliations with MIT, grants them roles in a Discord server, and stores …

May 27, 2024
CVE-2024-35231
8.6 HIGH

rack-contrib provides contributed rack middleware and utilities for Rack, a Ruby web server interface. Versions of rack-contrib prior to 2.5.0 are vulnerable to denial of …

May 27, 2024
CVE-2024-35219
8.3 HIGH

OpenAPI Generator allows generation of API client libraries (SDK generation), server stubs, documentation and configuration automatically given an OpenAPI Spec. Prior to version 7.6.0, attackers …

May 27, 2024
CVE-2024-34477
7.8 HIGH

configureNFS in lib/common/functions.sh in FOG through 1.5.10 allows local users to gain privileges by mounting a crafted NFS share (because of no_root_squash and insecure). In …

May 27, 2024
CVE-2024-5409
7.1 HIGH

RhinOS 3.0-1190 is vulnerable to an XSS via the "tamper" parameter in /admin/lib/phpthumb/phpthumb.php. An attacker could create a malicious URL and send it to a …

May 27, 2024
CVE-2024-5408
7.1 HIGH

Vulnerability in RhinOS 3.0-1190 consisting of an XSS through the "search" parameter of /portal/search.htm. This vulnerability could allow a remote attacker to steal details of …

May 27, 2024
CVE-2023-6349
7.5 HIGH

A heap overflow vulnerability exists in libvpx - Encoding a frame that has larger dimensions than the originally configured size with VP9 may result in …

May 27, 2024
CVE-2024-5403
7.2 HIGH

ASKEY 5G NR Small Cell fails to properly filter user input for certain functionality, allowing remote attackers with administrator privilege to execute arbitrary system commands …

May 27, 2024
CVE-2024-5400
8.8 HIGH

Openfind Mail2000 does not properly filter parameters of specific CGI. Remote attackers with regular privileges can exploit this vulnerability to execute arbitrary system commands on …

May 27, 2024
CVE-2024-4535
8.8 HIGH

The KKProgressbar2 Free WordPress plugin through 1.1.4.2 does not have CSRF checks in some places, which could allow attackers to make logged in users perform …

May 27, 2024
CVE-2024-4531
7.1 HIGH

The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform …

May 27, 2024
CVE-2024-5399
7.2 HIGH

Openfind Mail2000 does not properly filter parameters of specific API. Remote attackers with administrative privileges can exploit this vulnerability to execute arbitrary system commands on …

May 27, 2024
CVE-2024-5384
7.3 HIGH

A vulnerability classified as critical was found in SourceCodester Facebook News Feed Like 1.0. This vulnerability affects unknown code of the file index.php. The manipulation …

May 27, 2024
CVE-2024-36054
7.4 HIGH

Hw64.sys in Marvin Test HW.exe before 5.0.5.0 allows unprivileged user-mode processes to arbitrarily read kernel memory (and consequently gain all privileges) via IOCTL 0x9c4064b8 (via …

May 26, 2024
CVE-2024-34454
7.4 HIGH

Nintendo Wii U OS 5.5.5 allows man-in-the-middle attackers to forge SSL certificates as though they came from a Root CA, because there is a secondary …

May 26, 2024
CVE-2024-5377
7.3 HIGH

A vulnerability was found in SourceCodester Vehicle Management System 1.0. It has been classified as critical. This affects an unknown part of the file /newvehicle.php. …

May 26, 2024
CVE-2024-5362
7.3 HIGH

A vulnerability classified as critical has been found in SourceCodester Online Hospital Management System 1.0. Affected is an unknown function of the file departmentDoctor.php. The …

May 26, 2024
CVE-2024-5357
7.3 HIGH

A vulnerability has been found in PHPGurukul Zoo Management System 2.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

May 26, 2024
CVE-2024-30056
7.1 HIGH

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

May 25, 2024
CVE-2024-35388
8.8 HIGH

TOTOLINK NR1800X v9.1.0u.6681_B20230703 was discovered to contain a stack overflow via the password parameter in the function urldecode

May 24, 2024
CVE-2024-33471
7.2 HIGH

An issue in the Sensor Settings of AVTECH Room Alert 4E v4.4.0 allows attackers to gain access to SMTP credentials in plaintext via a crafted …

May 24, 2024
CVE-2024-35395
8.8 HIGH

TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in as root.

May 24, 2024
CVE-2024-35618
7.5 HIGH

PingCAP TiDB v7.5.1 was discovered to contain a NULL pointer dereference via the component SortedRowContainer.

May 24, 2024
CVE-2024-35340
8.6 HIGH

Tenda FH1206 V1.2.0.8(8155) was discovered to contain a command injection vulnerability via the cmdinput parameter at ip/goform/formexeCommand.

May 24, 2024
CVE-2021-47571
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: staging: rtl8192e: Fix use after free in _rtl92e_pci_disconnect() The free_rtllib() function frees the "dev" pointer …

May 24, 2024
CVE-2021-47566
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: proc/vmcore: fix clearing user buffer by properly using clear_user() To clear a user buffer we …

May 24, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.