CVE Database

39369+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2021-46936
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: fix use-after-free in tw_timer_handler A real world panic issue was found as follow in …

Feb 27, 2024
CVE-2023-7165
7.5 HIGH

The JetBackup WordPress plugin before 2.0.9.9 doesn't use index files to prevent public directory listing of sensitive directories in certain configurations, which allows malicious actors …

Feb 27, 2024
CVE-2023-6585
7.5 HIGH

The WP JobSearch WordPress plugin before 2.3.4 does not validate files to be uploaded, which could allow unauthenticated attackers to upload arbitrary files such as …

Feb 27, 2024
CVE-2023-6584
7.5 HIGH

The WP JobSearch WordPress plugin before 2.3.4 does not prevent attackers from logging-in as any users with the only knowledge of that user's email address.

Feb 27, 2024
CVE-2023-50379
8.8 HIGH

Malicious code injection in Apache Ambari in prior to 2.7.8. Users are recommended to upgrade to version 2.7.8, which fixes this issue. Impact: A Cluster …

Feb 27, 2024
CVE-2024-0759
7.5 HIGH

Should an instance of AnythingLLM be hosted on an internal network and the attacked be explicitly granted a permission level of manager or admin, they …

Feb 27, 2024
CVE-2024-25711
7.5 HIGH

diffoscope before 256 allows directory traversal via an embedded filename in a GPG file. Contents of any file, such as ../.ssh/id_rsa, may be disclosed to …

Feb 27, 2024
CVE-2024-24100
8.3 HIGH

Code-projects Computer Book Store 1.0 is vulnerable to SQL Injection via PublisherID.

Feb 27, 2024
CVE-2024-24096
7.8 HIGH

Code-projects Computer Book Store 1.0 is vulnerable to SQL Injection via BookSBIN.

Feb 27, 2024
CVE-2024-22917
8.6 HIGH

SQL injection vulnerability in Dynamic Lab Management System Project in PHP v.1.0 allows a remote attacker to execute arbitrary code via a crafted script.

Feb 27, 2024
CVE-2024-27356
7.5 HIGH

An issue was discovered on certain GL-iNet devices. Attackers can download files such as logs via commands, potentially obtaining critical user information. This affects MT6000 …

Feb 27, 2024
CVE-2024-22544
8.0 HIGH

An issue was discovered in Linksys Router E1700 version 1.0.04 (build 3), allows authenticated attackers to execute arbitrary code via the setDateTime function.

Feb 27, 2024
CVE-2023-36237
8.8 HIGH

Cross Site Request Forgery vulnerability in Bagisto before v.1.5.1 allows an attacker to execute arbitrary code via a crafted HTML script.

Feb 26, 2024
CVE-2024-26455
7.5 HIGH

fluent-bit 2.2.2 contains a Use-After-Free vulnerability in /fluent-bit/plugins/custom_calyptia/calyptia.c.

Feb 26, 2024
CVE-2024-25768
7.5 HIGH

OpenDMARC 1.4.2 contains a null pointer dereference vulnerability in /OpenDMARC/libopendmarc/opendmarc_policy.c.

Feb 26, 2024
CVE-2023-52474
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: IB/hfi1: Fix bugs with non-PAGE_SIZE-end multi-iovec user SDMA requests hfi1 user SDMA request processing has …

Feb 26, 2024
CVE-2019-25162
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: i2c: Fix a potential use after free Free the adap structure only after we are …

Feb 26, 2024
CVE-2019-25160
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: netlabel: fix out-of-bounds memory accesses There are two array out-of-bounds memory accesses, one in cipso_v4_map_lvl_valid(), …

Feb 26, 2024
CVE-2024-27081
7.2 HIGH

ESPHome is a system to control your ESP8266/ESP32. A security misconfiguration in the edit configuration file API in the dashboard component of ESPHome version 2023.12.9 …

Feb 26, 2024
CVE-2024-27454
7.5 HIGH

orjson.loads in orjson before 3.9.15 does not limit recursion for deeply nested JSON documents.

Feb 26, 2024
CVE-2024-27359
7.5 HIGH

Certain WithSecure products allow a Denial of Service because the engine scanner can go into an infinite loop when processing an archive file. This affects …

Feb 26, 2024
CVE-2024-24714
7.2 HIGH

Unrestricted Upload of File with Dangerous Type vulnerability in bPlugins LLC Icons Font Loader.This issue affects Icons Font Loader: from n/a through 1.1.4.

Feb 26, 2024
CVE-2024-23839
7.1 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.3, specially crafted traffic can cause a heap …

Feb 26, 2024
CVE-2024-23837
7.5 HIGH

LibHTP is a security-aware parser for the HTTP protocol. Crafted traffic can cause excessive processing time of HTTP headers, leading to denial of service. This …

Feb 26, 2024
CVE-2024-23836
7.5 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 6.0.16 and 7.0.3, an attacker can craft …

Feb 26, 2024
CVE-2024-23835
7.5 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.3, excessive memory use during pgsql parsing …

Feb 26, 2024
CVE-2024-23605
8.8 HIGH

A heap-based buffer overflow vulnerability exists in the GGUF library header.n_kv functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to code …

Feb 26, 2024
CVE-2024-23496
8.8 HIGH

A heap-based buffer overflow vulnerability exists in the GGUF library gguf_fread_str functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to code …

Feb 26, 2024
CVE-2024-22873
8.1 HIGH

Tencent Blueking CMDB v3.2.x to v3.9.x was discovered to contain a Server-Side Request Forgery (SSRF) via the event subscription function (/service/subscription.go). This vulnerability allows attackers …

Feb 26, 2024
CVE-2024-22201
7.5 HIGH

Jetty is a Java based web server and servlet engine. An HTTP/2 SSL connection that is established and TCP congested will be leaked when it …

Feb 26, 2024
CVE-2024-21836
8.8 HIGH

A heap-based buffer overflow vulnerability exists in the GGUF library header.n_tensors functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to code …

Feb 26, 2024
CVE-2024-21825
8.8 HIGH

A heap-based buffer overflow vulnerability exists in the GGUF library GGUF_TYPE_ARRAY/GGUF_TYPE_STRING parsing functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to …

Feb 26, 2024
CVE-2024-21802
8.8 HIGH

A heap-based buffer overflow vulnerability exists in the GGUF library info->ne functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to code …

Feb 26, 2024
CVE-2024-1889
8.8 HIGH

Cross-Site Request Forgery vulnerability in SMA Cluster Controller, affecting version 01.05.01.R. This vulnerability could allow an attacker to send a malicious link to an authenticated …

Feb 26, 2024
CVE-2024-1876
7.3 HIGH

A vulnerability was found in SourceCodester Employee Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /psubmit.php. …

Feb 26, 2024
CVE-2024-1710
8.8 HIGH

The Addon Library plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the onAjaxAction function action in …

Feb 26, 2024
CVE-2024-1622
7.5 HIGH

Due to a mistake in error checking, Routinator will terminate when an incoming RTR connection is reset by the peer too quickly after opening.

Feb 26, 2024
CVE-2024-0455
7.5 HIGH

The inclusion of the web scraper for AnythingLLM means that any user with the proper authorization level (manager, admin, and when in single user) could …

Feb 26, 2024
CVE-2024-0439
8.8 HIGH

As a manager, you should not be able to modify a series of settings. In the UI this is indeed hidden as a convenience for …

Feb 26, 2024
CVE-2024-0243
8.1 HIGH

With the following crawler configuration: ```python from bs4 import BeautifulSoup as Soup url = "https://example.com" loader = RecursiveUrlLoader( url=url, max_depth=2, extractor=lambda x: Soup(x, "html.parser").text ) …

Feb 26, 2024
CVE-2023-52469
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drivers/amd/pm: fix a use-after-free in kv_parse_power_table When ps allocated by kzalloc equals to NULL, kv_parse_power_table …

Feb 26, 2024
CVE-2023-52468
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: class: fix use-after-free in class_register() The lock_class_key is still registered and can be found in …

Feb 26, 2024
CVE-2023-49960
7.5 HIGH

In Indo-Sol PROFINET-INspektor NT through 2.4.0, a path traversal vulnerability in the httpuploadd service of the firmware allows remote attackers to write to arbitrary files …

Feb 26, 2024
CVE-2022-48626
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: moxart: fix potential use-after-free on remove path It was reported that the mmc host structure …

Feb 26, 2024
CVE-2024-21502
7.5 HIGH

Versions of the package fastecdsa before 2.3.2 are vulnerable to Use of Uninitialized Variable on the stack, via the curvemath_mul function in src/curveMath.c, due to …

Feb 24, 2024
CVE-2024-26192
8.2 HIGH

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

Feb 23, 2024
CVE-2024-25469
7.5 HIGH

SQL Injection vulnerability in CRMEB crmeb_java v.1.3.4 and before allows a remote attacker to obtain sensitive information via the latitude and longitude parameters in the …

Feb 23, 2024
CVE-2024-27133
7.5 HIGH

Insufficient sanitization in MLflow leads to XSS when running a recipe that uses an untrusted dataset. This issue leads to a client-side RCE when running …

Feb 23, 2024
CVE-2024-27132
7.5 HIGH

Insufficient sanitization in MLflow leads to XSS when running an untrusted recipe. This issue leads to a client-side RCE when running an untrusted recipe in …

Feb 23, 2024
CVE-2024-24310
8.8 HIGH

In the module "Generate barcode on invoice / delivery slip" (ecgeneratebarcode) from Ether Creation <= 1.2.0 for PrestaShop, a guest can perform SQL injection.

Feb 23, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.