CVE Database

39369+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-24932
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Djo VK Poster Group allows Reflected XSS.This issue affects VK Poster Group: from …

Feb 12, 2024
CVE-2024-24927
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UnitedThemes Brooklyn | Creative Multi-Purpose Responsive WordPress Theme allows Reflected XSS.This issue affects …

Feb 12, 2024
CVE-2024-25744
8.8 HIGH

In the Linux kernel before 6.6.7, an untrusted VMM can trigger int80 syscall handling at any given point. This is related to arch/x86/coco/tdx/tdx.c and arch/x86/mm/mem_encrypt_amd.c.

Feb 12, 2024
CVE-2024-25728
7.5 HIGH

ExpressVPN before 12.73.0 on Windows, when split tunneling is used, sends DNS requests according to the Windows configuration (e.g., sends them to DNS servers operated …

Feb 11, 2024
CVE-2024-25419
8.8 HIGH

flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/update_menu.php.

Feb 11, 2024
CVE-2024-25418
8.8 HIGH

flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/delete_menu.php.

Feb 11, 2024
CVE-2024-25417
8.8 HIGH

flusity-CMS v2.33 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /core/tools/add_translation.php.

Feb 11, 2024
CVE-2023-52428
7.5 HIGH

In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can cause a denial of service (resource consumption) via a large JWE p2c header value (aka iteration …

Feb 11, 2024
CVE-2023-52427
7.5 HIGH

In OpenDDS through 3.27, there is a segmentation fault for a DataWriter with a large value of resource_limits.max_samples. NOTE: the vendor's position is that the …

Feb 11, 2024
CVE-2023-50957
8.0 HIGH

IBM Storage Defender - Resiliency Service 2.0 could allow a privileged user to perform unauthorized actions after obtaining encrypted data from clear text key storage. …

Feb 10, 2024
CVE-2023-51488
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic, Inc. Crowdsignal Dashboard – Polls, Surveys & more allows Reflected XSS.This issue …

Feb 10, 2024
CVE-2024-0594
8.8 HIGH

The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to union-based SQL Injection via the 'q' parameter of the wpas_get_users …

Feb 10, 2024
CVE-2024-21490
7.5 HIGH

This affects versions of the package angular from 1.3.0. A regular expression used to split the value of the ng-srcset directive is vulnerable to super-linear …

Feb 10, 2024
CVE-2024-23327
7.5 HIGH

Envoy is a high-performance edge/middle/service proxy. When PPv2 is enabled both on a listener and subsequent cluster, the Envoy instance will segfault when attempting to …

Feb 9, 2024
CVE-2024-23325
7.5 HIGH

Envoy is a high-performance edge/middle/service proxy. Envoy crashes in Proxy protocol when using an address type that isn’t supported by the OS. Envoy is susceptible …

Feb 9, 2024
CVE-2024-23324
8.6 HIGH

Envoy is a high-performance edge/middle/service proxy. External authentication can be bypassed by downstream connections. Downstream clients can force invalid gRPC requests to be sent to …

Feb 9, 2024
CVE-2024-23322
7.5 HIGH

Envoy is a high-performance edge/middle/service proxy. Envoy will crash when certain timeouts happen within the same interval. The crash occurs when the following are true: …

Feb 9, 2024
CVE-2023-50386
8.8 HIGH

Improper Control of Dynamically-Managed Code Resources, Unrestricted Upload of File with Dangerous Type, Inclusion of Functionality from Untrusted Control Sphere vulnerability in Apache Solr.This issue …

Feb 9, 2024
CVE-2023-50298
7.5 HIGH

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Solr.This issue affects Apache Solr: from 6.0.0 through 8.11.2, from 9.0.0 before 9.4.1. Solr …

Feb 9, 2024
CVE-2023-50292
7.5 HIGH

Incorrect Permission Assignment for Critical Resource, Improper Control of Dynamically-Managed Code Resources vulnerability in Apache Solr. This issue affects Apache Solr: from 8.10.0 through 8.11.2, …

Feb 9, 2024
CVE-2023-50291
7.5 HIGH

Insufficiently Protected Credentials vulnerability in Apache Solr. This issue affects Apache Solr: from 6.0.0 through 8.11.2, from 9.0.0 before 9.3.0. One of the two endpoints …

Feb 9, 2024
CVE-2024-25450
8.8 HIGH

imlib2 v1.9.1 was discovered to mishandle memory allocation in the function init_imlib_fonts().

Feb 9, 2024
CVE-2024-25448
8.8 HIGH

An issue in the imlib_free_image_and_decache function of imlib2 v1.9.1 allows attackers to cause a heap buffer overflow via parsing a crafted image.

Feb 9, 2024
CVE-2024-25447
8.8 HIGH

An issue in the imlib_load_image_with_error_return function of imlib2 v1.9.1 allows attackers to cause a heap buffer overflow via parsing a crafted image.

Feb 9, 2024
CVE-2024-25446
7.8 HIGH

An issue in the HuginBase::PTools::setDestImage function of Hugin v2022.0.0 allows attackers to cause a heap buffer overflow via parsing a crafted image.

Feb 9, 2024
CVE-2024-25445
7.8 HIGH

Improper handling of values in HuginBase::PTools::Transform::transform of Hugin 2022.0.0 leads to an assertion failure.

Feb 9, 2024
CVE-2024-25443
7.8 HIGH

An issue in the HuginBase::ImageVariable<double>::linkWith function of Hugin v2022.0.0 allows attackers to cause a heap-use-after-free via parsing a crafted image.

Feb 9, 2024
CVE-2024-25442
7.8 HIGH

An issue in the HuginBase::PanoramaMemento::loadPTScript function of Hugin v2022.0.0 allows attackers to cause a heap buffer overflow via parsing a crafted image.

Feb 9, 2024
CVE-2024-25318
8.8 HIGH

Code-projects Hotel Managment System 1.0 allows SQL Injection via the 'pid' parameter in Hotel/admin/print.php?pid=2.

Feb 9, 2024
CVE-2024-25310
8.8 HIGH

Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'id' parameter at "School/delete.php?id=5."

Feb 9, 2024
CVE-2024-25313
8.8 HIGH

Code-projects Simple School Managment System 1.0 allows Authentication Bypass via the username and password parameters at School/teacher_login.php.

Feb 9, 2024
CVE-2024-25312
8.8 HIGH

Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'id' parameter at "School/sub_delete.php?id=5."

Feb 9, 2024
CVE-2024-25309
8.8 HIGH

Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'pass' parameter at School/teacher_login.php.

Feb 9, 2024
CVE-2024-25308
8.8 HIGH

Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'name' parameter at School/teacher_login.php.

Feb 9, 2024
CVE-2024-25306
8.8 HIGH

Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'aname' parameter at "School/index.php".

Feb 9, 2024
CVE-2024-25305
8.8 HIGH

Code-projects Simple School Managment System 1.0 allows Authentication Bypass via the username and password parameters at School/index.php.

Feb 9, 2024
CVE-2024-25304
8.8 HIGH

Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'apass' parameter at "School/index.php."

Feb 9, 2024
CVE-2023-6724
8.8 HIGH

Authorization Bypass Through User-Controlled Key vulnerability in Software Engineering Consultancy Machine Equipment Limited Company Hearing Tracking System allows Authentication Abuse.This issue affects Hearing Tracking System: …

Feb 9, 2024
CVE-2024-25677
8.8 HIGH

In Min before 1.31.0, local files are not correctly treated as unique security origins, which allows them to improperly request cross-origin resources. For example, a …

Feb 9, 2024
CVE-2024-23749
7.8 HIGH

KiTTY versions 0.76.1.13 and before is vulnerable to command injection via the filename variable, occurs due to insufficient input sanitization and validation, failure to escape …

Feb 9, 2024
CVE-2024-25004
7.8 HIGH

KiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the username, occurs due to insufficient bounds checking and input sanitization (at …

Feb 9, 2024
CVE-2024-25003
7.8 HIGH

KiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the hostname, occurs due to insufficient bounds checking and input sanitization. This …

Feb 9, 2024
CVE-2024-0229
7.8 HIGH

An out-of-bounds memory access flaw was found in the X.Org server. This issue can be triggered when a device frozen by a sync grab is …

Feb 9, 2024
CVE-2024-0842
7.5 HIGH

The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including, 1.2.6. …

Feb 9, 2024
CVE-2023-51761
8.3 HIGH

In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could bypass authentication and acquire admin capabilities.

Feb 9, 2024
CVE-2023-45191
7.5 HIGH

IBM Engineering Lifecycle Optimization 7.0.2 and 7.0.3 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM …

Feb 9, 2024
CVE-2024-24821
8.8 HIGH

Composer is a dependency Manager for the PHP language. In affected versions several files within the local working directory are included during the invocation of …

Feb 9, 2024
CVE-2024-24820
8.3 HIGH

Icinga Director is a tool designed to make Icinga 2 configuration handling easy. Not any of Icinga Director's configuration forms used to manipulate the monitoring …

Feb 9, 2024
CVE-2023-47131
7.5 HIGH

The N-able PassPortal extension before 3.29.2 for Chrome inserts sensitive information into a log file.

Feb 8, 2024
CVE-2023-40263
8.8 HIGH

An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11. It allows authenticated command injection via ftp.

Feb 8, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.