CVE Database

39369+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-1546
7.5 HIGH

When storing and re-accessing data on a networking channel, the length of buffers may have been confused, resulting in an out-of-bounds memory read. This vulnerability …

Feb 20, 2024
CVE-2023-42791
8.8 HIGH

A relative path traversal in Fortinet FortiManager version 7.4.0 and 7.2.0 through 7.2.3 and 7.0.0 through 7.0.8 and 6.4.0 through 6.4.12 and 6.2.0 through 6.2.11 …

Feb 20, 2024
CVE-2024-26581
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_rbtree: skip end interval element from gc rbtree lazy gc on insert might collect …

Feb 20, 2024
CVE-2024-24794
8.1 HIGH

A use-after-free vulnerability exists in the DICOM Element Parsing as implemented in Imaging Data Commons libdicom 1.0.5. A specially crafted DICOM file can cause premature …

Feb 20, 2024
CVE-2024-24793
8.1 HIGH

A use-after-free vulnerability exists in the DICOM Element Parsing as implemented in Imaging Data Commons libdicom 1.0.5. A specially crafted DICOM file can cause premature …

Feb 20, 2024
CVE-2023-7245
7.8 HIGH

The nodejs framework in OpenVPN Connect 3.0 through 3.4.3 (Windows)/3.4.7 (macOS) was not properly configured, which allows a local user to execute arbitrary code within …

Feb 20, 2024
CVE-2024-25607
8.1 HIGH

The default password hashing algorithm (PBKDF2-HMAC-SHA1) in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions, and Liferay DXP 7.4 before update 16, 7.3 before …

Feb 20, 2024
CVE-2023-51770
7.5 HIGH

Arbitrary File Read Vulnerability in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.1. We recommend users to upgrade Apache DolphinScheduler to version 3.2.1, which …

Feb 20, 2024
CVE-2023-49250
7.3 HIGH

Because the HttpUtils class did not verify certificates, an attacker that could perform a Man-in-the-Middle (MITM) attack on outgoing https connections could impersonate the server. …

Feb 20, 2024
CVE-2024-25606
8.0 HIGH

XXE vulnerability in Liferay Portal 7.2.0 through 7.4.3.7, and older unsupported versions, and Liferay DXP 7.4 before update 4, 7.3 before update 12, 7.2 before …

Feb 20, 2024
CVE-2024-22234
7.4 HIGH

In Spring Security, versions 6.1.x prior to 6.1.7 and versions 6.2.x prior to 6.2.2, an application is vulnerable to broken access control when it directly …

Feb 20, 2024
CVE-2023-6764
8.1 HIGH

A format string vulnerability in a function of the IPSec VPN feature in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1, USG …

Feb 20, 2024
CVE-2024-22019
7.5 HIGH

A vulnerability in Node.js HTTP servers allows an attacker to send a specially crafted HTTP request with chunked encoding, leading to resource exhaustion and denial …

Feb 20, 2024
CVE-2024-21892
7.8 HIGH

On Linux, Node.js ignores certain environment variables if those may have been set by an unprivileged user while the process is running with elevated privileges …

Feb 20, 2024
CVE-2024-21891
8.8 HIGH

Node.js depends on multiple built-in utility functions to normalize paths provided to node:fs functions, which can be overwitten with user-defined implementations leading to filesystem permission …

Feb 20, 2024
CVE-2024-0715
7.6 HIGH

Expression Language Injection vulnerability in Hitachi Global Link Manager on Windows allows Code Injection.This issue affects Hitachi Global Link Manager: before 8.8.7-03.

Feb 20, 2024
CVE-2023-6398
7.2 HIGH

A post-authentication command injection vulnerability in the file upload binary in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1, USG FLEX series …

Feb 20, 2024
CVE-2024-1648
7.5 HIGH

electron-pdf version 20.0.0 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the HTML content …

Feb 20, 2024
CVE-2024-1647
7.5 HIGH

Pyhtml2pdf version 0.0.6 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the HTML content …

Feb 20, 2024
CVE-2024-1297
7.2 HIGH

Loomio version 2.22.0 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to OS Command Injection.

Feb 20, 2024
CVE-2022-48625
7.5 HIGH

Yealink Config Encrypt Tool add RSA before 1.2 has a built-in RSA key pair, and thus there is a risk of decryption by an adversary.

Feb 20, 2024
CVE-2024-26134
7.5 HIGH

cbor2 provides encoding and decoding for the Concise Binary Object Representation (CBOR) (RFC 8949) serialization format. Starting in version 5.5.1 and prior to version 5.6.2, …

Feb 19, 2024
CVE-2024-1638
8.2 HIGH

The documentation specifies that the BT_GATT_PERM_READ_LESC and BT_GATT_PERM_WRITE_LESC defines for a Bluetooth characteristic: Attribute read/write permission with LE Secure Connection encryption. If set, requires that …

Feb 19, 2024
CVE-2024-1635
7.5 HIGH

A vulnerability was found in Undertow. This vulnerability impacts a server that supports the wildfly-http-client protocol. Whenever a malicious user opens and closes a connection …

Feb 19, 2024
CVE-2023-6259
7.1 HIGH

Insufficiently Protected Credentials, : Improper Access Control vulnerability in Brivo ACS100, ACS300 allows Password Recovery Exploitation, Bypassing Physical Security.This issue affects ACS100, ACS300: from 5.2.4 …

Feb 19, 2024
CVE-2024-25636
7.1 HIGH

Misskey is an open source, decentralized social media platform with ActivityPub support. Prior to version 2024.2.0, when fetching remote Activity Streams objects, Misskey doesn't check …

Feb 19, 2024
CVE-2024-25635
8.8 HIGH

alf.io is an open source ticket reservation system. Prior to version 2.0-Mr-2402, organization owners can view the generated API KEY and USERS of other organization …

Feb 19, 2024
CVE-2024-25634
7.2 HIGH

alf.io is an open source ticket reservation system. Prior to version 2.0-Mr-2402, an attacker can access data from other organizers. The attacker can use a …

Feb 19, 2024
CVE-2024-25626
8.8 HIGH

Yocto Project is an open source collaboration project that helps developers create custom Linux-based systems regardless of the hardware architecture. In Yocto Projects Bitbake before …

Feb 19, 2024
CVE-2024-25978
7.5 HIGH

Insufficient file size checks resulted in a denial of service risk in the file picker's unzip functionality.

Feb 19, 2024
CVE-2024-25625
8.1 HIGH

Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. A potential security vulnerability has been discovered in `pimcore/admin-ui-classic-bundle` prior to version 1.3.4. The vulnerability …

Feb 19, 2024
CVE-2024-25623
8.5 HIGH

Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.2.7, 4.1.15, 4.0.15, and 3.5.19, when fetching remote statuses, Mastodon doesn't …

Feb 19, 2024
CVE-2024-25710
8.1 HIGH

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Commons Compress.This issue affects Apache Commons Compress: from 1.3 through 1.25.0. Users are recommended to …

Feb 19, 2024
CVE-2022-48624
7.8 HIGH

close_altfile in filename.c in less before 606 omits shell_quote calls for LESSCLOSE.

Feb 19, 2024
CVE-2023-6249
8.0 HIGH

Signed to unsigned conversion esp32_ipm_send

Feb 18, 2024
CVE-2023-6749
8.0 HIGH

Unchecked length coming from user input in settings shell

Feb 18, 2024
CVE-2023-52379
7.5 HIGH

Permission control vulnerability in the calendarProvider module.Successful exploitation of this vulnerability may affect service confidentiality.

Feb 18, 2024
CVE-2022-48621
7.5 HIGH

Vulnerability of missing authentication for critical functions in the Wi-Fi module.Successful exploitation of this vulnerability may affect service confidentiality.

Feb 18, 2024
CVE-2023-52377
7.4 HIGH

Vulnerability of input data not being verified in the cellular data module.Successful exploitation of this vulnerability may cause out-of-bounds access.

Feb 18, 2024
CVE-2023-52376
7.5 HIGH

Information management vulnerability in the Gallery module.Successful exploitation of this vulnerability may affect service confidentiality.

Feb 18, 2024
CVE-2023-52375
7.5 HIGH

Permission control vulnerability in the WindowManagerServices module.Successful exploitation of this vulnerability may affect availability.

Feb 18, 2024
CVE-2023-52374
7.5 HIGH

Permission control vulnerability in the package management module.Successful exploitation of this vulnerability may affect service confidentiality.

Feb 18, 2024
CVE-2023-52373
7.5 HIGH

Vulnerability of permission verification in the content sharing pop-up module.Successful exploitation of this vulnerability may cause unauthorized file sharing.

Feb 18, 2024
CVE-2023-52372
7.5 HIGH

Vulnerability of input parameter verification in the motor module.Successful exploitation of this vulnerability may affect availability.

Feb 18, 2024
CVE-2023-52367
7.7 HIGH

Vulnerability of improper access control in the media library module.Successful exploitation of this vulnerability may affect service availability and integrity.

Feb 18, 2024
CVE-2023-52366
7.5 HIGH

Out-of-bounds read vulnerability in the smart activity recognition module.Successful exploitation of this vulnerability may cause features to perform abnormally.

Feb 18, 2024
CVE-2023-52387
7.5 HIGH

Resource reuse vulnerability in the GPU module. Successful exploitation of this vulnerability may affect service confidentiality.

Feb 18, 2024
CVE-2023-52362
7.5 HIGH

Permission management vulnerability in the lock screen module.Successful exploitation of this vulnerability may affect availability.

Feb 18, 2024
CVE-2023-52361
7.5 HIGH

The VerifiedBoot module has a vulnerability that may cause authentication errors.Successful exploitation of this vulnerability may affect integrity.

Feb 18, 2024
CVE-2023-52360
7.5 HIGH

Logic vulnerabilities in the baseband.Successful exploitation of this vulnerability may affect service integrity.

Feb 18, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.