CVE Database

39369+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-25262
8.1 HIGH

texlive-bin commit c515e was discovered to contain heap buffer overflow via the function ttfLoadHDMX:ttfdump. This vulnerability allows attackers to cause a Denial of Service (DoS) …

Feb 29, 2024
CVE-2024-25006
8.1 HIGH

XenForo before 2.2.14 allows Directory Traversal (with write access) by an authenticated user who has permissions to administer styles, and uses a ZIP archive for …

Feb 29, 2024
CVE-2024-23302
7.5 HIGH

Couchbase Server before 7.2.4 has a private key leak in goxdcr.log.

Feb 29, 2024
CVE-2024-22939
8.8 HIGH

Cross Site Request Forgery vulnerability in FlyCms v.1.0 allows a remote attacker to execute arbitrary code via the system/article/category_edit component.

Feb 29, 2024
CVE-2024-20321
8.6 HIGH

A vulnerability in the External Border Gateway Protocol (eBGP) implementation of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of …

Feb 29, 2024
CVE-2024-20267
8.6 HIGH

A vulnerability with the handling of MPLS traffic for Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause the netstack process to unexpectedly …

Feb 29, 2024
CVE-2024-1971
7.3 HIGH

A vulnerability has been found in Surya2Developer Online Shopping System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Feb 29, 2024
CVE-2024-1939
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Feb 29, 2024
CVE-2024-1938
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium …

Feb 29, 2024
CVE-2024-1470
7.1 HIGH

Authorization Bypass Through User-Controlled Key vulnerability in NetIQ (OpenText) Client Login Extension on Windows allows Privilege Escalation, Code Injection.This issue only affects NetIQ Client Login …

Feb 29, 2024
CVE-2024-1317
8.8 HIGH

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to SQL Injection via …

Feb 29, 2024
CVE-2024-1217
7.6 HIGH

The Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to unauthorized plugin deactivation due to a …

Feb 29, 2024
CVE-2024-1206
8.8 HIGH

The WP Recipe Maker plugin for WordPress is vulnerable to SQL Injection via the 'recipes' parameter in all versions up to, and including, 9.1.2 due …

Feb 29, 2024
CVE-2024-0702
7.3 HIGH

The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on several …

Feb 29, 2024
CVE-2023-7110
7.3 HIGH

A vulnerability, which was classified as critical, has been found in code-projects Library Management System 2.0. This issue affects some unknown processing of the file …

Feb 29, 2024
CVE-2023-7109
7.3 HIGH

A vulnerability classified as critical was found in code-projects Library Management System 2.0. This vulnerability affects unknown code of the file /admin/login.php. The manipulation of …

Feb 29, 2024
CVE-2023-7107
7.3 HIGH

A vulnerability was found in code-projects E-Commerce Website 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the …

Feb 29, 2024
CVE-2023-6881
7.3 HIGH

Possible buffer overflow in is_mount_point

Feb 29, 2024
CVE-2023-51779
7.0 HIGH

bt_sock_recvmsg in net/bluetooth/af_bluetooth.c in the Linux kernel through 6.6.8 has a use-after-free because of a bt_sock_ioctl race condition.

Feb 29, 2024
CVE-2023-51774
8.4 HIGH

The json-jwt (aka JSON::JWT) gem 1.16.3 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be …

Feb 29, 2024
CVE-2023-50658
7.5 HIGH

The jose2go component before 1.6.0 for Go allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.

Feb 29, 2024
CVE-2023-50437
8.6 HIGH

An issue was discovered in Couchbase Server before 7.2.x before 7.2.4. otpCookie is shown with full admin on pools/default/serverGroups and engageCluster2.

Feb 29, 2024
CVE-2023-34198
7.3 HIGH

In Stormshield Network Security (SNS) 1.0.0 through 3.7.36 before 3.7.37, 3.8.0 through 3.11.24 before 3.11.25, 4.0.0 through 4.3.18 before 4.3.19, 4.4.0 through 4.6.5 before 4.6.6, …

Feb 29, 2024
CVE-2023-25921
8.5 HIGH

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 allows the attacker to upload or transfer files of dangerous types that can …

Feb 29, 2024
CVE-2022-34269
8.8 HIGH

An issue was discovered in RWS WorldServer before 11.7.3. An authenticated, remote attacker can perform a ws-legacy/load_dtd?system_id= blind SSRF attack to deploy JSP code to …

Feb 29, 2024
CVE-2024-23910
8.8 HIGH

Cross-site request forgery (CSRF) vulnerability in ELECOM wireless LAN routers and wireless LAN repeater allows a remote unauthenticated attacker to hijack the authentication of administrators …

Feb 28, 2024
CVE-2024-25869
8.8 HIGH

An Unrestricted File Upload vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary code via upload of a …

Feb 28, 2024
CVE-2024-25866
8.8 HIGH

A SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary SQL commands via the email parameter …

Feb 28, 2024
CVE-2024-22983
8.1 HIGH

SQL injection vulnerability in Projectworlds Visitor Management System in PHP v.1.0 allows a remote attacker to escalate privileges via the name parameter in the myform.php …

Feb 28, 2024
CVE-2023-49338
7.5 HIGH

Couchbase Server 7.1.x and 7.2.x before 7.2.4 does not require authentication for the /admin/stats and /admin/vitals endpoints on TCP port 8093 of localhost.

Feb 28, 2024
CVE-2023-45859
7.6 HIGH

In Hazelcast through 4.1.10, 4.2 through 4.2.8, 5.0 through 5.0.5, 5.1 through 5.1.7, 5.2 through 5.2.4, and 5.3 through 5.3.2, some client operations don't check …

Feb 28, 2024
CVE-2023-25925
8.5 HIGH

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow a remote authenticated attacker to execute arbitrary commands on the system …

Feb 28, 2024
CVE-2024-25859
7.1 HIGH

A path traversal vulnerability in the /path/to/uploads/ directory of Blesta before v5.9.2 allows attackers to takeover user accounts and execute arbitrary code.

Feb 28, 2024
CVE-2024-24148
7.5 HIGH

A memory leak issue discovered in parseSWF_FREECHARACTER in libming v0.4.8 allows attackers to cause a denial of service via a crafted SWF file.

Feb 28, 2024
CVE-2023-52047
8.8 HIGH

Dedecms v5.7.112 was discovered to contain a Cross-Site Request Forgery (CSRF) in the file manager.

Feb 28, 2024
CVE-2024-26342
7.5 HIGH

A Null pointer dereference in usr/sbin/httpd in ASUS AC68U 3.0.0.4.384.82230 allows remote attackers to trigger DoS via network packet.

Feb 28, 2024
CVE-2024-1847
7.8 HIGH

Heap-based Buffer Overflow, Memory Corruption, Out-Of-Bounds Read, Out-Of-Bounds Write, Stack-based Buffer Overflow, Type Confusion, Uninitialized Variable, Use-After-Free vulnerabilities exist in the file reading procedure in …

Feb 28, 2024
CVE-2024-27515
7.2 HIGH

Osclass 5.1.2 is vulnerable to SQL Injection.

Feb 28, 2024
CVE-2024-25902
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in miniorange Malware Scanner.This issue affects Malware Scanner: from n/a through 4.7.2.

Feb 28, 2024
CVE-2024-24868
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Project & Document Manager.This issue affects SP Project & …

Feb 28, 2024
CVE-2024-21886
7.8 HIGH

A heap buffer overflow flaw was found in the DisableDevice function in the X.Org server. This issue may lead to an application crash or, in …

Feb 28, 2024
CVE-2024-21885
7.8 HIGH

A flaw was found in X.Org server. In the XISendDeviceHierarchyEvent function, it is possible to exceed the allocated array length when certain new device IDs …

Feb 28, 2024
CVE-2024-1636
8.0 HIGH

Potential Cross-Site Scripting (XSS) in the page editing area.

Feb 28, 2024
CVE-2024-1632
8.8 HIGH

Low-privileged users with access to the Sitefinity backend may obtain sensitive information from the site's administrative area.

Feb 28, 2024
CVE-2024-0786
8.8 HIGH

The Conversios – Google Analytics 4 (GA4), Meta Pixel & more Via Google Tag Manager For WooCommerce plugin for WordPress is vulnerable to time-based SQL …

Feb 28, 2024
CVE-2021-47049
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: Drivers: hv: vmbus: Use after free in __vmbus_open() The "open_info" variable is added to the …

Feb 28, 2024
CVE-2021-47048
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: spi: spi-zynqmp-gqspi: fix use-after-free in zynqmp_qspi_exec_op When handling op->addr, it is using the buffer "tmpbuf" …

Feb 28, 2024
CVE-2021-47046
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix off by one in hdmi_14_process_transaction() The hdcp_i2c_offsets[] array did not have an entry …

Feb 28, 2024
CVE-2021-47044
7.7 HIGH

In the Linux kernel, the following vulnerability has been resolved: sched/fair: Fix shift-out-of-bounds in load_balance() Syzbot reported a handful of occurrences where an sd->nr_balance_failed can …

Feb 28, 2024
CVE-2021-47040
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: io_uring: fix overflows checks in provide buffers Colin reported before possible overflow and sign extension …

Feb 28, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.