CVE Database

39369+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-23861
8.2 HIGH

A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting …

Jan 26, 2024
CVE-2024-23860
8.2 HIGH

A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting …

Jan 26, 2024
CVE-2024-23859
8.2 HIGH

A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting …

Jan 26, 2024
CVE-2024-23858
8.2 HIGH

A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting …

Jan 26, 2024
CVE-2024-23857
8.2 HIGH

A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting …

Jan 26, 2024
CVE-2024-23856
8.2 HIGH

A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting …

Jan 26, 2024
CVE-2024-0920
7.2 HIGH

A vulnerability was found in TRENDnet TEW-822DRE 1.03B02. It has been declared as critical. This vulnerability affects unknown code of the file /admin_ping.htm of the …

Jan 26, 2024
CVE-2024-0919
8.8 HIGH

A vulnerability was found in TRENDnet TEW-815DAP 1.0.2.0. It has been classified as critical. This affects the function do_setNTP of the component POST Request Handler. …

Jan 26, 2024
CVE-2024-0918
7.2 HIGH

A vulnerability was found in TRENDnet TEW-800MB 1.0.1.0 and classified as critical. Affected by this issue is some unknown functionality of the component POST Request …

Jan 26, 2024
CVE-2022-48622
7.8 HIGH

In GNOME GdkPixbuf (aka gdk-pixbuf) through 2.42.10, the ANI (Windows animated cursor) decoder encounters heap memory corruption (in ani_load_chunk in io-ani.c) when parsing chunks in …

Jan 26, 2024
CVE-2024-22545
7.8 HIGH

An issue was discovered in TRENDnet TEW-824DRU version 1.04b01, allows unauthenticated attackers to execute arbitrary code via the system.ntp.server parameter in the sub_420AE0() function. The …

Jan 26, 2024
CVE-2023-6919
7.5 HIGH

Path Traversal: '/../filedir' vulnerability in Biges Safe Life Technologies Electronics Inc. VGuard allows Absolute Path Traversal.This issue affects VGuard: before V500.0003.R008.4011.C0012.B351.C.

Jan 26, 2024
CVE-2024-21385
8.3 HIGH

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

Jan 26, 2024
CVE-2024-23620
8.8 HIGH

An improper privilege management vulnerability exists in IBM Merge Healthcare eFilm Workstation. A local, authenticated attacker can exploit this vulnerability to escalate privileges to SYSTEM.

Jan 26, 2024
CVE-2024-21620
8.8 HIGH

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series …

Jan 25, 2024
CVE-2023-51833
8.1 HIGH

A command injection issue in TRENDnet TEW-411BRPplus v.2.07_eu that allows a local attacker to execute arbitrary code via the data1 parameter in the debug.cgi page.

Jan 25, 2024
CVE-2024-24399
7.2 HIGH

An arbitrary file upload vulnerability in LEPTON v7.0.0 allows authenticated attackers to execute arbitrary PHP code by uploading this code to the backend/languages/index.php languages area.

Jan 25, 2024
CVE-2024-22636
8.8 HIGH

PluXml Blog v5.8.9 was discovered to contain a remote code execution (RCE) vulnerability in the Static Pages feature. This vulnerability is exploited via injecting a …

Jan 25, 2024
CVE-2023-52251
8.8 HIGH

An issue discovered in provectus kafka-ui 0.4.0 through 0.7.1 allows remote attackers to execute arbitrary code via the q parameter of /api/clusters/local/topics/{topic}/messages.

Jan 25, 2024
CVE-2024-23817
7.1 HIGH

Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. Version 18.0.4 has a HTML Injection vulnerability in the Home page …

Jan 25, 2024
CVE-2024-23656
7.5 HIGH

Dex is an identity service that uses OpenID Connect to drive authentication for other apps. Dex 2.37.0 serves HTTPS with insecure TLS 1.0 and TLS …

Jan 25, 2024
CVE-2024-23655
7.5 HIGH

Tuta is an encrypted email service. Starting in version 3.118.12 and prior to version 3.119.10, an attacker is able to send a manipulated email so …

Jan 25, 2024
CVE-2023-52356
7.5 HIGH

A segment fault (SEGV) flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFReadRGBATileExt() API. This flaw …

Jan 25, 2024
CVE-2023-52355
7.5 HIGH

An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a …

Jan 25, 2024
CVE-2023-6267
8.6 HIGH

A flaw was found in the json payload. If annotation based security is used to secure a REST resource, the JSON body that the resource …

Jan 25, 2024
CVE-2024-22749
7.8 HIGH

GPAC v2.3 was detected to contain a buffer overflow via the function gf_isom_new_generic_sample_description function in the isomedia/isom_write.c:4577

Jan 25, 2024
CVE-2024-0822
7.5 HIGH

An authentication bypass vulnerability was found in overt-engine. This flaw allows the creation of users in the system without authentication due to a flaw in …

Jan 25, 2024
CVE-2023-52076
8.5 HIGH

Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A path traversal and arbitrary file write vulnerability exists in …

Jan 25, 2024
CVE-2023-40547
8.3 HIGH

A remote code execution vulnerability was found in Shim. The Shim boot support trusts attacker-controlled values when parsing an HTTP response. This flaw allows an …

Jan 25, 2024
CVE-2023-3181
7.8 HIGH

The C:\Program Files (x86)\Splashtop\Splashtop Software Updater\uninst.exe process creates a folder at C:\Windows\Temp~nsu.tmp and copies itself to it as Au_.exe. The C:\Windows\Temp~nsu.tmp\Au_.exe file is automatically launched …

Jan 25, 2024
CVE-2024-22432
7.8 HIGH

Networker 19.9 and all prior versions contains a Plain-text Password stored in temporary config file during backup duration in NMDA MySQL Database backups. User has …

Jan 25, 2024
CVE-2024-23855
8.2 HIGH

A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting …

Jan 25, 2024
CVE-2024-23985
7.5 HIGH

EzServer 6.4.017 allows a denial of service (daemon crash) via a long string, such as one for the RNTO command.

Jan 25, 2024
CVE-2023-24676
7.2 HIGH

An issue found in ProcessWire 3.0.210 allows attackers to execute arbitrary code and install a reverse shell via the download_zip_url parameter when installing a new …

Jan 24, 2024
CVE-2024-23646
8.8 HIGH

Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. The application allows users to create zip files from available files on the site. …

Jan 24, 2024
CVE-2021-42146
7.5 HIGH

An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97. DTLS servers allow remote attackers to reuse the same epoch number within two times …

Jan 24, 2024
CVE-2021-42145
7.5 HIGH

An assertion failure discovered in in check_certificate_request() in Contiki-NG tinyDTLS through master branch 53a0d97 allows attackers to cause a denial of service.

Jan 24, 2024
CVE-2024-23904
7.5 HIGH

Jenkins Log Command Plugin 1.0.2 and earlier does not disable a feature of its command parser that replaces an '@' character followed by a file …

Jan 24, 2024
CVE-2024-23898
8.8 HIGH

Jenkins 2.217 through 2.441 (both inclusive), LTS 2.222.1 through 2.426.2 (both inclusive) does not perform origin validation of requests made through the CLI WebSocket endpoint, …

Jan 24, 2024
CVE-2024-23649
7.5 HIGH

Lemmy is a link aggregator and forum for the fediverse. Starting in version 0.17.0 and prior to version 0.19.1, users can report private messages, even …

Jan 24, 2024
CVE-2024-23648
8.8 HIGH

Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. The password reset functionality sends to the the user requesting a password change an …

Jan 24, 2024
CVE-2023-51890
7.5 HIGH

An infinite loop issue discovered in Mathtex 1.05 and before allows a remote attackers to consume CPU resources via crafted string in the application URL.

Jan 24, 2024
CVE-2023-51888
7.5 HIGH

Buffer Overflow vulnerability in the nomath() function in Mathtex v.1.05 and before allows a remote attacker to cause a denial of service via a crafted …

Jan 24, 2024
CVE-2024-23641
7.5 HIGH

SvelteKit is a web development kit. In SvelteKit 2, sending a GET request with a body eg `{}` to a built and previewed/hosted sveltekit app …

Jan 24, 2024
CVE-2023-51886
7.5 HIGH

Buffer Overflow vulnerability in the main() function in Mathtex 1.05 and before allows a remote attacker to cause a denial of service when using \convertpath.

Jan 24, 2024
CVE-2024-22154
7.5 HIGH

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SNP Digital SalesKing.This issue affects SalesKing: from n/a through 1.6.15.

Jan 24, 2024
CVE-2023-50943
7.5 HIGH

Apache Airflow, versions before 2.8.1, have a vulnerability that allows a potential attacker to poison the XCom data by bypassing the protection of "enable_xcom_pickling=False" configuration …

Jan 24, 2024
CVE-2024-22309
8.7 HIGH

Deserialization of Untrusted Data vulnerability in QuantumCloud ChatBot with AI.This issue affects ChatBot with AI: from n/a through 5.1.0.

Jan 24, 2024
CVE-2024-22284
8.7 HIGH

Deserialization of Untrusted Data vulnerability in Thomas Belser Asgaros Forum.This issue affects Asgaros Forum: from n/a through 2.7.2.

Jan 24, 2024
CVE-2024-22152
8.0 HIGH

Unrestricted Upload of File with Dangerous Type vulnerability in WebToffee Product Import Export for WooCommerce.This issue affects Product Import Export for WooCommerce: from n/a through …

Jan 24, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.