CVE Database

39369+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-24309
7.5 HIGH

In the module "Survey TMA" (ecomiz_survey_tma) up to version 2.0.0 from Ecomiz for PrestaShop, a guest can download personal information without restriction.

Feb 23, 2024
CVE-2021-33162
8.4 HIGH

Improper access control in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow an authenticated user to potentially enable escalation of …

Feb 23, 2024
CVE-2021-33161
7.2 HIGH

Improper input validation in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user to potentially enable escalation of …

Feb 23, 2024
CVE-2021-33158
7.2 HIGH

Improper neutralization in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user to potentially enable escalation of privilege …

Feb 23, 2024
CVE-2021-33157
7.2 HIGH

Insufficient control flow management in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user to potentially enable escalation …

Feb 23, 2024
CVE-2021-33145
7.2 HIGH

Uncaught exception in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user to potentially enable escalation of privilege …

Feb 23, 2024
CVE-2021-33141
8.6 HIGH

Improper input validation in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow an unauthenticated user to potentially enable denial of …

Feb 23, 2024
CVE-2024-1833
7.3 HIGH

A vulnerability was found in SourceCodester Employee Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Feb 23, 2024
CVE-2024-1832
7.3 HIGH

A vulnerability has been found in SourceCodester Complete File Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Feb 23, 2024
CVE-2024-1831
7.3 HIGH

A vulnerability, which was classified as critical, was found in SourceCodester Complete File Management System 1.0. Affected is an unknown function of the file users/index.php …

Feb 23, 2024
CVE-2024-1830
7.3 HIGH

A vulnerability was found in code-projects Library System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the …

Feb 23, 2024
CVE-2022-43842
8.6 HIGH

IBM Aspera Console 3.4.0 through 3.4.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker …

Feb 23, 2024
CVE-2024-27318
7.5 HIGH

Versions of the package onnx before and including 1.15.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a …

Feb 23, 2024
CVE-2024-1829
7.3 HIGH

A vulnerability was found in code-projects Library System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the …

Feb 23, 2024
CVE-2024-1828
7.3 HIGH

A vulnerability was found in code-projects Library System 1.0. It has been classified as critical. Affected is an unknown function of the file Source/librarian/user/teacher/registration.php. The …

Feb 23, 2024
CVE-2024-1827
7.3 HIGH

A vulnerability was found in code-projects Library System 1.0 and classified as critical. This issue affects some unknown processing of the file Source/librarian/user/teacher/login.php. The manipulation …

Feb 23, 2024
CVE-2024-23320
8.8 HIGH

Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server. This issue is a …

Feb 23, 2024
CVE-2024-1826
7.3 HIGH

A vulnerability has been found in code-projects Library System 1.0 and classified as critical. This vulnerability affects unknown code of the file Source/librarian/user/student/login.php. The manipulation …

Feb 23, 2024
CVE-2024-26150
8.7 HIGH

`@backstage/backend-common` is a common functionality library for backends for Backstage, an open platform for building developer portals. In `@backstage/backend-common` prior to versions 0.21.1, 0.20.2, and …

Feb 23, 2024
CVE-2024-1824
7.3 HIGH

A vulnerability, which was classified as critical, has been found in CodeAstro House Rental Management System 1.0. Affected by this issue is some unknown functionality …

Feb 23, 2024
CVE-2024-1820
7.3 HIGH

A vulnerability was found in code-projects Crime Reporting System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file inchargelogin.php. …

Feb 23, 2024
CVE-2024-26599
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: pwm: Fix out-of-bounds access in of_pwm_single_xlate() With args->args_count == 2 args->args[2] is not defined. Actually …

Feb 23, 2024
CVE-2024-26598
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Avoid potential UAF in LPI translation cache There is a potential UAF …

Feb 23, 2024
CVE-2024-26597
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: qualcomm: rmnet: fix global oob in rmnet_policy The variable rmnet_link_ops assign a *bigger* maxtype …

Feb 23, 2024
CVE-2023-52464
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: EDAC/thunderx: Fix possible out-of-bounds string access Enabling -Wstringop-overflow globally exposes a warning for a common …

Feb 23, 2024
CVE-2023-52457
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: serial: 8250: omap: Don't skip resource freeing if pm_runtime_resume_and_get() failed Returning an error code from …

Feb 23, 2024
CVE-2023-52455
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: iommu: Don't reserve 0-length IOVA region When the bootloader/firmware doesn't setup the framebuffers, their address …

Feb 23, 2024
CVE-2024-26594
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate mech token in session setup If client send invalid mech token in session …

Feb 23, 2024
CVE-2024-1817
7.3 HIGH

A vulnerability has been found in Demososo DM Enterprise Website Building System up to 2022.8 and classified as critical. Affected by this vulnerability is the …

Feb 23, 2024
CVE-2024-25928
7.1 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sitepact.This issue affects Sitepact: from n/a through 1.0.5.

Feb 23, 2024
CVE-2024-26593
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: i2c: i801: Fix block process call transactions According to the Intel datasheets, software must reset …

Feb 23, 2024
CVE-2024-1776
7.2 HIGH

The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to SQL Injection via the 'form-id' parameter in all versions up …

Feb 23, 2024
CVE-2024-22243
8.1 HIGH

Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed …

Feb 23, 2024
CVE-2024-1786
7.5 HIGH

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in D-Link DIR-600M C1 3.08. Affected by this issue is …

Feb 23, 2024
CVE-2024-1683
7.3 HIGH

A DLL injection vulnerability exists where an authenticated, low-privileged local attacker could modify application files on the TIE Secure Relay host, which could allow for …

Feb 23, 2024
CVE-2024-25756
8.0 HIGH

A Stack Based Buffer Overflow vulnerability in Tenda AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote attacker to execute arbitrary code via the formWifiBasicSet …

Feb 22, 2024
CVE-2024-25753
8.8 HIGH

Stack Based Buffer Overflow vulnerability in Tenda AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote attacker to execute arbitrary code via the formSetDeviceName function.

Feb 22, 2024
CVE-2024-25748
8.8 HIGH

A Stack Based Buffer Overflow vulnerability in tenda AC9 AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote attacker to execute arbitrary code via the …

Feb 22, 2024
CVE-2024-25746
8.8 HIGH

Stack Based Buffer Overflow vulnerability in Tenda AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote attacker to execute arbitrary code via the add_white_node function.

Feb 22, 2024
CVE-2022-25377
7.5 HIGH

The ACME-challenge endpoint in Appwrite 0.5.0 through 0.12.x before 0.12.2 allows remote attackers to read arbitrary local files via ../ directory traversal. In order to …

Feb 22, 2024
CVE-2024-26151
8.2 HIGH

The `mjml` PyPI package, found at the `FelixSchwarz/mjml-python` GitHub repo, is an unofficial Python port of MJML, a markup language created by Mailjet. All users …

Feb 22, 2024
CVE-2024-26592
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix UAF issue in ksmbd_tcp_new_connection() The race is between the handling of a new …

Feb 22, 2024
CVE-2024-26589
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: bpf: Reject variable offset alu on PTR_TO_FLOW_KEYS For PTR_TO_FLOW_KEYS, check_flow_keys_access() only uses fixed off for …

Feb 22, 2024
CVE-2024-26588
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Prevent out-of-bounds memory access The test_tag test triggers an unhandled page fault: # …

Feb 22, 2024
CVE-2023-52452
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix accesses to uninit stack slots Privileged programs are supposed to be able to …

Feb 22, 2024
CVE-2023-52451
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: powerpc/pseries/memhp: Fix access beyond end of drmem array dlpar_memory_remove_by_index() may access beyond the bounds of …

Feb 22, 2024
CVE-2023-52446
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix a race condition between btf_put() and map_free() When running `./test_progs -j` in my …

Feb 22, 2024
CVE-2023-52445
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: media: pvrusb2: fix use after free on context disconnection Upon module load, a kthread is …

Feb 22, 2024
CVE-2023-52444
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid dirent corruption As Al reported in link[1]: f2fs_rename() ... if (old_dir …

Feb 22, 2024
CVE-2023-52161
7.5 HIGH

The Access Point functionality in eapol_auth_key_handle in eapol.c in iNet wireless daemon (IWD) before 2.14 allows attackers to gain unauthorized access to a protected Wi-Fi …

Feb 22, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.