CVE Database

39369+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-23258
7.8 HIGH

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Sonoma 14.4, visionOS 1.1. Processing an image may lead to …

Mar 8, 2024
CVE-2024-23249
7.1 HIGH

The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.4. Processing a file may lead to a denial-of-service or …

Mar 8, 2024
CVE-2024-23248
7.1 HIGH

The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.4. Processing a file may lead to a denial-of-service or …

Mar 8, 2024
CVE-2024-23247
7.8 HIGH

The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. Processing a file …

Mar 8, 2024
CVE-2024-23246
8.6 HIGH

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS …

Mar 8, 2024
CVE-2024-23244
7.8 HIGH

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4. An app from a standard user …

Mar 8, 2024
CVE-2024-23233
7.8 HIGH

This issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.4. Entitlements and privacy permissions granted to this app may be …

Mar 8, 2024
CVE-2024-23226
8.8 HIGH

The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, …

Mar 8, 2024
CVE-2024-23216
7.1 HIGH

A path handling issue was addressed with improved validation. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app …

Mar 8, 2024
CVE-2024-0258
8.6 HIGH

The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. …

Mar 8, 2024
CVE-2019-6268
7.5 HIGH

RAD SecFlow-2 devices with Hardware 0202, Firmware 4.1.01.63, and U-Boot 2010.12 allow URIs beginning with /.. for Directory Traversal, as demonstrated by reading /etc/shadow.

Mar 8, 2024
CVE-2024-25729
8.8 HIGH

Arris SBG6580 devices have predictable default WPA2 security passwords that could lead to unauthorized remote access. (They use the first 6 characters of the SSID …

Mar 8, 2024
CVE-2024-2264
7.3 HIGH

A vulnerability, which was classified as critical, has been found in keerti1924 PHP-MYSQL-User-Login-System 1.0. Affected by this issue is some unknown functionality of the file …

Mar 7, 2024
CVE-2024-28115
8.8 HIGH

FreeRTOS is a real-time operating system for microcontrollers. FreeRTOS Kernel versions through 10.6.1 do not sufficiently protect against local privilege escalation via Return Oriented Programming …

Mar 7, 2024
CVE-2024-1986
8.8 HIGH

The Booster Elite for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the wc_add_new_product() function in …

Mar 7, 2024
CVE-2024-0203
8.8 HIGH

The Digits plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.4.1. This is due to missing nonce validation …

Mar 7, 2024
CVE-2024-1773
8.8 HIGH

The PDF Invoices and Packing Slips For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.7 …

Mar 7, 2024
CVE-2024-22752
8.1 HIGH

Insecure permissions issue in EaseUS MobiMover 6.0.5 Build 21620 allows attackers to gain escalated privileges via use of crafted executable launched from the application installation …

Mar 7, 2024
CVE-2024-27733
7.7 HIGH

File Upload vulnerability in Byzro Network Smart s42 Management Platform v.S42 allows a local attacker to execute arbitrary code via the useratte/userattestation.php component.

Mar 7, 2024
CVE-2024-1351
8.8 HIGH

Under certain configurations of --tlsCAFile and tls.CAFile, MongoDB Server may skip peer certificate validation which may result in untrusted connections to succeed. This may effectively …

Mar 7, 2024
CVE-2023-48725
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the JSON Parsing getblockschedule() functionality of Netgear RAX30 1.0.11.96 and 1.0.7.78. A specially crafted HTTP request can lead …

Mar 7, 2024
CVE-2023-42661
7.2 HIGH

JFrog Artifactory prior to version 7.76.2 is vulnerable to Arbitrary File Write of untrusted data, which may lead to DoS or Remote Code Execution when …

Mar 7, 2024
CVE-2024-1170
8.2 HIGH

The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulnerable …

Mar 7, 2024
CVE-2024-1169
7.5 HIGH

The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulnerable …

Mar 7, 2024
CVE-2024-1931
7.5 HIGH

NLnet Labs Unbound version 1.18.0 up to and including version 1.19.1 contain a vulnerability that can cause denial of service by a certain code path …

Mar 7, 2024
CVE-2024-1382
8.8 HIGH

The Restaurant Reservations plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.9 via the nd_rst_layout attribute of …

Mar 7, 2024
CVE-2023-33676
8.4 HIGH

Sourcecodester Lost and Found Information System's Version 1.0 is vulnerable to unauthenticated SQL Injection at "?page=items/view&id=*" which can be escalated to the remote command execution.

Mar 7, 2024
CVE-2022-46499
8.8 HIGH

Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the pat_number parameter at his_admin_view_single_patient.php.

Mar 7, 2024
CVE-2022-46497
8.1 HIGH

Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the pat_number parameter at his_doc_view_single_patien.php.

Mar 7, 2024
CVE-2024-28215
7.5 HIGH

nGrinder before 3.5.9 allows an attacker to create or update webhook configuration due to lack of access control, which could be the cause of information …

Mar 7, 2024
CVE-2023-51395
8.8 HIGH

The vulnerability described by CVE-2023-0972 has been additionally discovered in Silicon Labs Z-Wave end devices. This vulnerability may allow an unauthenticated attacker within Z-Wave range …

Mar 7, 2024
CVE-2024-28097
7.3 HIGH

Calendar functionality in Schoolbox application before version 23.1.3 is vulnerable to stored cross-site scripting allowing authenticated attacker to perform security actions in the context of …

Mar 7, 2024
CVE-2024-28096
7.3 HIGH

Class functionality in Schoolbox application before version 23.1.3 is vulnerable to stored cross-site scripting allowing authenticated attacker to perform security actions in the context of …

Mar 7, 2024
CVE-2024-28095
7.3 HIGH

News functionality in Schoolbox application before version 23.1.3 is vulnerable to stored cross-site scripting allowing authenticated attacker to perform security actions in the context of …

Mar 7, 2024
CVE-2024-28094
8.8 HIGH

Chat functionality in Schoolbox application before version 23.1.3 is vulnerable to blind SQL Injection enabling the authenticated attackers to read, modify, and delete database records.

Mar 7, 2024
CVE-2024-0815
8.8 HIGH

Command injection in paddle.utils.download._wget_download (bypass filter) in paddlepaddle/paddle 2.6.0

Mar 7, 2024
CVE-2024-0817
7.8 HIGH

Command injection in IrGraph.draw in paddlepaddle/paddle 2.6.0

Mar 7, 2024
CVE-2024-26566
8.2 HIGH

An issue in Cute Http File Server v.3.1 allows a remote attacker to escalate privileges via the password verification component.

Mar 7, 2024
CVE-2024-24375
7.5 HIGH

SQL injection vulnerability in Jfinalcms v.5.0.0 allows a remote attacker to obtain sensitive information via /admin/admin name parameter.

Mar 7, 2024
CVE-2024-0199
7.7 HIGH

An authorization bypass vulnerability was discovered in GitLab affecting versions 11.3 prior to 16.7.7, 16.7.6 prior to 16.8.4, and 16.8.3 prior to 16.9.2. An attacker …

Mar 7, 2024
CVE-2023-49988
7.5 HIGH

Hotel Booking Management v1.0 was discovered to contain a SQL injection vulnerability via the npss parameter at rooms.php.

Mar 7, 2024
CVE-2023-47415
7.5 HIGH

Cypress Solutions CTM-200 v2.7.1.5600 and below was discovered to contain an OS command injection vulnerability via the cli_text parameter.

Mar 7, 2024
CVE-2024-28110
7.5 HIGH

Go SDK for CloudEvents is the official CloudEvents SDK to integrate applications with CloudEvents. Prior to version 2.15.2, using cloudevents.WithRoundTripper to create a cloudevents.Client with …

Mar 6, 2024
CVE-2024-27917
7.5 HIGH

Shopware is an open commerce platform based on Symfony Framework and Vue. The Symfony Session Handler pops the Session Cookie and assigns it to the …

Mar 6, 2024
CVE-2024-27308
7.5 HIGH

Mio is a Metal I/O library for Rust. When using named pipes on Windows, mio will under some circumstances return invalid tokens that correspond to …

Mar 6, 2024
CVE-2023-48703
7.5 HIGH

RobotsAndPencils go-saml, a SAML client library written in Go, contains an authentication bypass vulnerability in all known versions. This is due to how the `xmlsec1` …

Mar 6, 2024
CVE-2024-2176
8.8 HIGH

Use after free in FedCM in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Mar 6, 2024
CVE-2024-2174
8.8 HIGH

Inappropriate implementation in V8 in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Mar 6, 2024
CVE-2024-2173
8.8 HIGH

Out of bounds memory access in V8 in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to perform out of bounds memory access via …

Mar 6, 2024
CVE-2024-27303
7.3 HIGH

electron-builder is a solution to package and build a ready for distribution Electron, Proton Native app for macOS, Windows and Linux. A vulnerability that only …

Mar 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.