CVE Database

39369+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-4479
7.3 HIGH

Stored XSS Vulnerability in M-Files Web versions before 23.8 allows attacker to execute script on users browser via stored HTML document within limited time period.

Mar 4, 2024
CVE-2024-26622
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: tomoyo: fix UAF write bug in tomoyo_write_control() Since tomoyo_write_control() updates head->write_buf when write() of long …

Mar 4, 2024
CVE-2024-20034
7.2 HIGH

In battery, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System …

Mar 4, 2024
CVE-2024-20029
8.4 HIGH

In wlan firmware, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with …

Mar 4, 2024
CVE-2024-20027
7.9 HIGH

In da, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System …

Mar 4, 2024
CVE-2024-20005
8.2 HIGH

In da, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution …

Mar 4, 2024
CVE-2024-28088
8.1 HIGH

LangChain through 0.1.10 allows ../ directory traversal by an actor who is able to control the final part of the path parameter in a load_chain …

Mar 4, 2024
CVE-2024-28084
7.5 HIGH

p2putil.c in iNet wireless daemon (IWD) through 2.15 allows attackers to cause a denial of service (daemon crash) or possibly have unspecified other impact because …

Mar 3, 2024
CVE-2024-2147
7.3 HIGH

A vulnerability was found in SourceCodester Online Mobile Management Store 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

Mar 3, 2024
CVE-2024-26469
8.1 HIGH

Server-Side Request Forgery (SSRF) vulnerability in Tunis Soft "Product Designer" (productdesigner) module for PrestaShop before version 1.178.36, allows remote attackers to cause a denial of …

Mar 3, 2024
CVE-2024-25842
7.5 HIGH

An issue was discovered in Presta World "Account Manager - Sales Representative & Dealers - CRM" (prestasalesmanager) module for PrestaShop before version 9.0, allows remote …

Mar 3, 2024
CVE-2024-25839
7.5 HIGH

An issue was discovered in Webbax "Super Newsletter" (supernewsletter) module for PrestaShop versions 1.4.21 and before, allows local attackers to escalate privileges and obtain sensitive …

Mar 3, 2024
CVE-2024-25844
7.5 HIGH

An issue was discovered in Common-Services "So Flexibilite" (soflexibilite) module for PrestaShop before version 4.1.26, allows remote attackers to escalate privileges and obtain sensitive information …

Mar 3, 2024
CVE-2024-24307
7.5 HIGH

Path Traversal vulnerability in Tunis Soft "Product Designer" (productdesigner) module for PrestaShop before version 1.178.36, allows a remote attacker to escalate privileges and obtain sensitive …

Mar 3, 2024
CVE-2024-25016
7.5 HIGH

IBM MQ and IBM MQ Appliance 9.0, 9.1, 9.2, 9.3 LTS and 9.3 CD could allow a remote unauthenticated attacker to cause a denial of …

Mar 3, 2024
CVE-2024-0795
7.2 HIGH

If an attacked was given access to an instance with the admin or manager role there is no backend authentication that would prevent the attacked …

Mar 2, 2024
CVE-2023-52578
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: bridge: use DEV_STATS_INC() syzbot/KCSAN reported data-races in br_handle_frame_finish() [1] This function can run from …

Mar 2, 2024
CVE-2023-52572
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: cifs: Fix UAF in cifs_demultiplex_thread() There is a UAF when xfstests on cifs: BUG: KASAN: …

Mar 2, 2024
CVE-2023-52571
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: power: supply: rk817: Fix node refcount leak Dan Carpenter reports that the Smatch static checker …

Mar 2, 2024
CVE-2023-52565
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Fix OOB read If the index provided by the user is bigger than …

Mar 2, 2024
CVE-2023-52531
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: Fix a memory corruption issue A few lines above, space is kzalloc()'ed …

Mar 2, 2024
CVE-2023-52530
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix potential key use-after-free When ieee80211_key_link() is called by ieee80211_gtk_rekey_add() but returns 0 …

Mar 2, 2024
CVE-2023-52525
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: Fix oob check condition in mwifiex_process_rx_packet Only skip the code path trying to …

Mar 2, 2024
CVE-2023-52524
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: nfc: llcp: Add lock when modifying device list The device list needs its associated …

Mar 2, 2024
CVE-2023-52519
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: HID: intel-ish-hid: ipc: Disable and reenable ACPI GPE bit The EHL (Elkhart Lake) based platforms …

Mar 2, 2024
CVE-2023-52517
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: spi: sun6i: fix race between DMA RX transfer completion and RX FIFO drain Previously the …

Mar 2, 2024
CVE-2023-52515
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: RDMA/srp: Do not call scsi_done() from srp_abort() After scmd_eh_abort_handler() has called the SCSI LLD eh_abort_handler …

Mar 2, 2024
CVE-2023-52510
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ieee802154: ca8210: Fix a potential UAF in ca8210_probe If of_clk_add_provider() fails in ca8210_register_ext_clock(), it calls …

Mar 2, 2024
CVE-2023-52509
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ravb: Fix use-after-free issue in ravb_tx_timeout_work() The ravb_stop() should call cancel_work_sync(). Otherwise, ravb_tx_timeout_work() is possible …

Mar 2, 2024
CVE-2023-52507
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: nfc: nci: assert requested protocol is valid The protocol is used in a bit mask …

Mar 2, 2024
CVE-2023-52504
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: x86/alternatives: Disable KASAN in apply_alternatives() Fei has reported that KASAN triggers during apply_alternatives() on a …

Mar 2, 2024
CVE-2023-52503
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: tee: amdtee: fix use-after-free vulnerability in amdtee_close_session There is a potential race condition in amdtee_close_session …

Mar 2, 2024
CVE-2023-52501
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Do not attempt to read past "commit" When iterating over the ring buffer while …

Mar 2, 2024
CVE-2024-25063
7.5 HIGH

Due to insufficient server-side validation, a successful exploit of this vulnerability could allow an attacker to gain access to certain URLs that the attacker should …

Mar 2, 2024
CVE-2024-27355
7.5 HIGH

An issue was discovered in phpseclib 1.x before 1.0.23, 2.x before 2.0.47, and 3.x before 3.0.36. When processing the ASN.1 object identifier of a certificate, …

Mar 1, 2024
CVE-2024-27354
7.5 HIGH

An issue was discovered in phpseclib 1.x before 1.0.23, 2.x before 2.0.47, and 3.x before 3.0.36. An attacker can construct a malformed certificate containing an …

Mar 1, 2024
CVE-2024-1869
7.5 HIGH

Certain HP DesignJet print products are potentially vulnerable to information disclosure related to accessing memory out-of-bounds when using the general-purpose gateway (GGW) over port 9220.

Mar 1, 2024
CVE-2023-49545
7.5 HIGH

A directory listing vulnerability in Customer Support System v1 allows attackers to list directories and sensitive files within the application without requiring authorization.

Mar 1, 2024
CVE-2021-47081
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: habanalabs/gaudi: Fix a potential use after free in gaudi_memset_device_memory Our code analyzer reported a uaf. …

Mar 1, 2024
CVE-2021-47069
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: ipc/mqueue, msg, sem: avoid relying on a stack reference past its expiry do_mq_timedreceive calls wq_sleep …

Mar 1, 2024
CVE-2024-27101
7.3 HIGH

SpiceDB is an open source, Google Zanzibar-inspired database for creating and managing security-critical application permissions. Integer overflow in chunking helper causes dispatching to miss elements …

Mar 1, 2024
CVE-2024-22182
8.6 HIGH

A remote, unauthenticated attacker may be able to send crafted messages to the web server of the Commend WS203VICM causing the system to restart, interrupting …

Mar 1, 2024
CVE-2023-7242
8.2 HIGH

Industrial Control Systems Network Protocol Parsers (ICSNPP) - Ethercat Zeek Plugin versions d78dda6 and prior are vulnerable to out-of-bounds read during the process of analyzing …

Mar 1, 2024
CVE-2024-1174
8.2 HIGH

Previous versions of HP ThinPro (prior to HP ThinPro 8.0 SP 8) could potentially contain security vulnerabilities. HP has released HP ThinPro 8.0 SP 8, …

Mar 1, 2024
CVE-2024-1453
7.8 HIGH

In Sante DICOM Viewer Pro versions 14.0.3 and prior, a user must open a malicious DICOM file, which could allow a local attacker to disclose …

Mar 1, 2024
CVE-2024-27689
8.8 HIGH

Stupid Simple CMS v1.2.4 was discovered to contain a Cross-Site Request Forgery (CSRF) via /update-article.php.

Mar 1, 2024
CVE-2023-52558
7.5 HIGH

In OpenBSD 7.4 before errata 002 and OpenBSD 7.3 before errata 019, a network buffer that had to be split at certain length that could …

Mar 1, 2024
CVE-2023-52557
7.5 HIGH

In OpenBSD 7.3 before errata 016, npppd(8) could crash by a l2tp message which has an AVP (Attribute-Value Pair) with wrong length.

Mar 1, 2024
CVE-2024-27295
8.2 HIGH

Directus is a real-time API and App dashboard for managing SQL database content. The password reset mechanism of the Directus backend allows attackers to receive …

Mar 1, 2024
CVE-2024-27139
7.5 HIGH

** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Archiva: a vulnerability in Apache Archiva allows an unauthenticated attacker to modify account data, potentially …

Mar 1, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.