CVE Database

39369+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-27289
8.1 HIGH

pgx is a PostgreSQL driver and toolkit for Go. Prior to version 4.18.2, SQL injection can occur when all of the following conditions are met: …

Mar 6, 2024
CVE-2024-25111
8.6 HIGH

Squid is a web proxy cache. Starting in version 3.5.27 and prior to version 6.8, Squid may be vulnerable to a Denial of Service attack …

Mar 6, 2024
CVE-2024-24765
7.5 HIGH

CasaOS-UserService provides user management functionalities to CasaOS. Prior to version 0.4.7, path filtering of the URL for user avatar image files was not strict, making …

Mar 6, 2024
CVE-2024-24761
7.5 HIGH

Galette is a membership management web application for non profit organizations. Starting in version 1.0.0 and prior to version 1.0.2, public pages are per default …

Mar 6, 2024
CVE-2024-2216
8.8 HIGH

A missing permission check in an HTTP endpoint in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified …

Mar 6, 2024
CVE-2024-28160
8.8 HIGH

Jenkins iceScrum Plugin 1.1.6 and earlier does not sanitize iceScrum project URLs on build views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by …

Mar 6, 2024
CVE-2024-28157
8.0 HIGH

Jenkins GitBucket Plugin 0.8 and earlier does not sanitize Gitbucket URLs on build views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers …

Mar 6, 2024
CVE-2024-20338
7.3 HIGH

A vulnerability in the ISE Posture (System Scan) module of Cisco Secure Client for Linux could allow an authenticated, local attacker to elevate privileges on …

Mar 6, 2024
CVE-2024-20337
8.2 HIGH

A vulnerability in the SAML authentication process of Cisco Secure Client could allow an unauthenticated, remote attacker to conduct a carriage return line feed (CRLF) …

Mar 6, 2024
CVE-2024-25102
7.8 HIGH

This vulnerability exists in AppSamvid software due to the usage of a weaker cryptographic algorithm (hash) SHA1 in user login component. An attacker with local …

Mar 6, 2024
CVE-2024-1224
7.1 HIGH

This vulnerability exists in USB Pratirodh due to the usage of a weaker cryptographic algorithm (hash) SHA1 in user login component. A local attacker with …

Mar 6, 2024
CVE-2024-26625
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: llc: call sock_orphan() at release time syzbot reported an interesting trace [1] caused by a …

Mar 6, 2024
CVE-2023-52604
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: FS:JFS:UBSAN:array-index-out-of-bounds in dbAdjTree Syzkaller reported the following issue: UBSAN: array-index-out-of-bounds in fs/jfs/jfs_dmap.c:2867:6 index 196694 is …

Mar 6, 2024
CVE-2023-52603
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: UBSAN: array-index-out-of-bounds in dtSplitRoot Syzkaller reported the following issue: oop0: detected capacity change from 0 …

Mar 6, 2024
CVE-2023-52602
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: jfs: fix slab-out-of-bounds Read in dtSearch Currently while searching for current page in the sorted …

Mar 6, 2024
CVE-2023-52601
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: jfs: fix array-index-out-of-bounds in dbAdjTree Currently there is a bound check missing in the dbAdjTree …

Mar 6, 2024
CVE-2023-52600
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: jfs: fix uaf in jfs_evict_inode When the execution of diMount(ipimap) fails, the object ipimap that …

Mar 6, 2024
CVE-2023-52599
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: jfs: fix array-index-out-of-bounds in diNewExt [Syz report] UBSAN: array-index-out-of-bounds in fs/jfs/jfs_imap.c:2360:2 index -878706688 is out …

Mar 6, 2024
CVE-2023-52598
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: s390/ptrace: handle setting of fpc register correctly If the content of the floating point control …

Mar 6, 2024
CVE-2023-52594
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: Fix potential array-index-out-of-bounds read in ath9k_htc_txstatus() Fix an array-index-out-of-bounds read in ath9k_htc_txstatus(). The …

Mar 6, 2024
CVE-2023-52591
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: reiserfs: Avoid touching renamed directory if parent does not change The VFS will not be …

Mar 6, 2024
CVE-2023-52588
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to tag gcing flag on page during block migration It needs to add …

Mar 6, 2024
CVE-2023-52586
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/msm/dpu: Add mutex lock in control vblank irq Add a mutex lock to control vblank …

Mar 6, 2024
CVE-2024-1220
8.2 HIGH

A stack-based buffer overflow in the built-in web server in Moxa NPort W2150A/W2250A Series firmware version 2.3 and prior allows a remote attacker to exploit …

Mar 6, 2024
CVE-2023-33677
7.5 HIGH

Sourcecodester Lost and Found Information System's Version 1.0 is vulnerable to unauthenticated SQL Injection at "?page=items/view&id=*".

Mar 6, 2024
CVE-2024-25817
7.8 HIGH

Buffer Overflow vulnerability in eza before version 0.18.2, allows local attackers to execute arbitrary code via the .git/HEAD, .git/refs, and .git/objects components.

Mar 6, 2024
CVE-2024-22889
7.5 HIGH

Due to incorrect access control in Plone version v6.0.9, remote attackers can view and list all files hosted on the website via sending a crafted …

Mar 6, 2024
CVE-2023-43318
8.8 HIGH

TP-Link JetStream Smart Switch TL-SG2210P 5.0 Build 20211201 allows attackers to escalate privileges via modification of the 'tid' and 'usrlvl' values in GET requests.

Mar 6, 2024
CVE-2023-38946
8.8 HIGH

An issue in Multilaser RE160 firmware v5.07.51_pt_MTL01 and v5.07.52_pt_MTL01 allows attackers to bypass the access control and gain complete access to the application via supplying …

Mar 6, 2024
CVE-2024-27765
7.5 HIGH

Directory Traversal vulnerability in Jeewms v.3.7 and before allows a remote attacker to obtain sensitive information via the cgformTemplateController component.

Mar 5, 2024
CVE-2024-24786
7.5 HIGH

The protojson.Unmarshal function can enter an infinite loop when unmarshaling certain forms of invalid JSON. This condition can occur when unmarshaling into a message which …

Mar 5, 2024
CVE-2024-24784
7.5 HIGH

The ParseAddressList function incorrectly handles comments (text within parentheses) within display names. Since this is a misalignment with conforming address parsers, it can result in …

Mar 5, 2024
CVE-2024-24278
7.5 HIGH

An issue in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive information via a crafted payload to the message …

Mar 5, 2024
CVE-2024-1764
7.6 HIGH

Improper privilege management in Just-in-time (JIT) elevation module in Devolutions Server 2023.3.14.0 and earlier allows a user to continue using the elevated privilege even after …

Mar 5, 2024
CVE-2024-25858
8.4 HIGH

In Foxit PDF Reader before 2024.1 and PDF Editor before 2024.1, code execution via JavaScript could occur because of an unoptimized prompt message for users …

Mar 5, 2024
CVE-2024-25613
7.2 HIGH

Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as …

Mar 5, 2024
CVE-2024-25612
7.2 HIGH

Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as …

Mar 5, 2024
CVE-2024-25611
7.2 HIGH

Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as …

Mar 5, 2024
CVE-2024-1356
7.2 HIGH

Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as …

Mar 5, 2024
CVE-2024-23296
7.8 HIGH KEV

A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.4 and iPadOS 17.4, macOS …

Mar 5, 2024
CVE-2024-23225
7.8 HIGH KEV

A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS …

Mar 5, 2024
CVE-2024-22255
7.1 HIGH

VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malicious actor with administrative access to a virtual machine …

Mar 5, 2024
CVE-2024-22254
7.9 HIGH

VMware ESXi contains an out-of-bounds write vulnerability. A malicious actor with privileges within the VMX process may trigger an out-of-bounds write leading to an escape …

Mar 5, 2024
CVE-2024-27929
7.1 HIGH

ImageSharp is a managed, cross-platform, 2D graphics library. A heap-use-after-free flaw was found in ImageSharp's InitializeImage() function of PngDecoderCore.cs file. This vulnerability is triggered when …

Mar 5, 2024
CVE-2024-27561
8.1 HIGH

A Server-Side Request Forgery (SSRF) in the installUpdateThemePluginAction function of WonderCMS v3.1.3 allows attackers to force the application to make arbitrary requests via injection of …

Mar 5, 2024
CVE-2024-24098
7.8 HIGH

Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection via the News Feed.

Mar 5, 2024
CVE-2024-27622
7.2 HIGH

A remote code execution vulnerability has been identified in the User Defined Tags module of CMS Made Simple version 2.2.19 / 2.2.21. This vulnerability arises …

Mar 5, 2024
CVE-2023-5457
7.5 HIGH

A CWE-1269 “Product Released in Non-Release Configuration” vulnerability in the Django web framework used by the web application (due to the “debug” configuration parameter set …

Mar 5, 2024
CVE-2023-45591
7.5 HIGH

A CWE-122 “Heap-based Buffer Overflow” vulnerability in the “logger_generic” function of the “Ax_rtu” binary allows a remote authenticated attacker to trigger a memory corruption in …

Mar 5, 2024
CVE-2023-5456
8.1 HIGH

A CWE-798 “Use of Hard-coded Credentials” vulnerability in the MariaDB database of the web application allows a remote unauthenticated attacker to access the database service …

Mar 5, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.