CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-52435
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: prevent mss overflow in skb_segment() Once again syzbot is able to crash the kernel …

Feb 20, 2024
CVE-2024-25631
6.1 MEDIUM

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who have enabled an external kvstore and Wireguard transparent encryption, …

Feb 20, 2024
CVE-2024-25630
6.1 MEDIUM

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For Cilium users who are using CRDs to store Cilium state (the default …

Feb 20, 2024
CVE-2024-25260
4.0 MEDIUM

elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.

Feb 20, 2024
CVE-2024-24763
4.3 MEDIUM

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to version 3.10.0, attackers can exploit this vulnerability to …

Feb 20, 2024
CVE-2023-51447
6.3 MEDIUM

Decidim is a participatory democracy framework. Starting in version 0.27.0 and prior to versions 0.27.5 and 0.28.0, the dynamic file upload feature is subject to …

Feb 20, 2024
CVE-2023-48220
5.7 MEDIUM

Decidim is a participatory democracy framework. Starting in version 0.4.rc3 and prior to version 2.0.9 of the `devise_invitable` gem, the invites feature allows users to …

Feb 20, 2024
CVE-2023-47635
4.5 MEDIUM

Decidim is a participatory democracy framework. Starting in version 0.23.0 and prior to versions 0.27.5 and 0.28.0, the CSRF authenticity token check is disabled for …

Feb 20, 2024
CVE-2024-25366
6.2 MEDIUM

Buffer Overflow vulnerability in mz-automation.de libiec61859 v.1.4.0 allows a remote attacker to cause a denial of service via the mmsServer_handleGetNameListRequest function to the mms_getnamelist_service component.

Feb 20, 2024
CVE-2023-39541
5.9 MEDIUM

A denial of service vulnerability exists in the ICMP and ICMPv6 parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted network packet can lead …

Feb 20, 2024
CVE-2023-39540
5.9 MEDIUM

A denial of service vulnerability exists in the ICMP and ICMPv6 parsing functionality of Weston Embedded uC-TCP-IP v3.06.01. A specially crafted network packet can lead …

Feb 20, 2024
CVE-2024-26270
6.5 MEDIUM

The Account Settings page in Liferay Portal 7.4.3.76 through 7.4.3.99, and Liferay DXP 2023.Q3 before patch 5, and 7.4 update 76 through 92 embeds the …

Feb 20, 2024
CVE-2024-26268
5.3 MEDIUM

User enumeration vulnerability in Liferay Portal 7.2.0 through 7.4.3.26, and older unsupported versions, and Liferay DXP 7.4 before update 27, 7.3 before update 8, 7.2 …

Feb 20, 2024
CVE-2024-25197
6.5 MEDIUM

Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions were discovered to contain a NULL pointer dereference via the isCurrent() function at /src/layered_costmap.cpp.

Feb 20, 2024
CVE-2024-1556
6.5 MEDIUM

The incorrect object was checked for NULL in the built-in profiler, potentially leading to invalid memory access and undefined behavior. *Note:* This issue only affects …

Feb 20, 2024
CVE-2024-1551
6.1 MEDIUM

Set-Cookie response headers were being incorrectly honored in multipart HTTP responses. If an attacker could control the Content-Type response header, as well as control part …

Feb 20, 2024
CVE-2024-1550
6.1 MEDIUM

A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedly, which could …

Feb 20, 2024
CVE-2024-1549
6.1 MEDIUM

If a website set a large custom cursor, portions of the cursor could have overlapped with the permission dialog, potentially resulting in user confusion and …

Feb 20, 2024
CVE-2024-1548
4.3 MEDIUM

A website could have obscured the fullscreen notification by using a dropdown select input element. This could have led to user confusion and possible spoofing …

Feb 20, 2024
CVE-2024-1547
6.5 MEDIUM

Through a series of API calls and redirects, an attacker-controlled alert dialog could have been displayed on another website (with the victim website's URL shown). …

Feb 20, 2024
CVE-2023-50306
4.0 MEDIUM

IBM Common Licensing 9.0 could allow a local user to enumerate usernames due to an observable response discrepancy. IBM X-Force ID: 273337.

Feb 20, 2024
CVE-2024-26267
5.3 MEDIUM

In Liferay Portal 7.2.0 through 7.4.3.25, and older unsupported versions, and Liferay DXP 7.4 before update 26, 7.3 before update 5, 7.2 before fix pack …

Feb 20, 2024
CVE-2024-26265
5.0 MEDIUM

The Image Uploader module in Liferay Portal 7.2.0 through 7.4.3.15, and older unsupported versions, and Liferay DXP 7.4 before update 16, 7.3 before update 4, …

Feb 20, 2024
CVE-2023-52433
4.4 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_rbtree: skip sync GC for new elements in this transaction New elements in this …

Feb 20, 2024
CVE-2024-25609
6.1 MEDIUM

HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.12, and older unsupported versions, and Liferay DXP 7.4 before update 9, 7.3 service pack 3, 7.2 fix pack …

Feb 20, 2024
CVE-2024-25608
6.1 MEDIUM

HtmlUtil.escapeRedirect in Liferay Portal 7.2.0 through 7.4.3.18, and older unsupported versions, and Liferay DXP 7.4 before update 19, 7.3 before update 4, 7.2 before fix …

Feb 20, 2024
CVE-2023-50270
6.5 MEDIUM

Session Fixation Apache DolphinScheduler before version 3.2.0, which session is still valid after the password change. Users are recommended to upgrade to version 3.2.1, which …

Feb 20, 2024
CVE-2024-25605
5.3 MEDIUM

The Journal module in Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before service pack 3, 7.2 before fix …

Feb 20, 2024
CVE-2024-25604
6.5 MEDIUM

Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before service pack 3, 7.2 before fix pack 17, and older …

Feb 20, 2024
CVE-2024-25974
5.4 MEDIUM

The Frentix GmbH OpenOlat LMS is affected by stored a Cross-Site Scripting (XSS) vulnerability. It is possible to upload files within the Media Center of …

Feb 20, 2024
CVE-2024-25973
5.4 MEDIUM

The Frentix GmbH OpenOlat LMS is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities. An attacker with rights to create or edit groups can create …

Feb 20, 2024
CVE-2024-25150
4.3 MEDIUM

Information disclosure vulnerability in the Control Panel in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before update 4, 7.2 …

Feb 20, 2024
CVE-2024-25149
5.4 MEDIUM

Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 15, and older unsupported …

Feb 20, 2024
CVE-2023-44308
6.1 MEDIUM

Open redirect vulnerability in adaptive media administration page in Liferay DXP 2023.Q3 before patch 6, and 7.4 GA through update 92 allows remote attackers to …

Feb 20, 2024
CVE-2023-5190
6.1 MEDIUM

Open redirect vulnerability in the Countries Management’s edit region page in Liferay Portal 7.4.3.45 through 7.4.3.101, and Liferay DXP 2023.Q3 before patch 6, and 7.4 …

Feb 20, 2024
CVE-2022-45320
6.3 MEDIUM

Liferay Portal before 7.4.3.16 and Liferay DXP before 7.2 fix pack 19, 7.3 before update 6, and 7.4 before update 16 allow remote authenticated users …

Feb 20, 2024
CVE-2024-1559
6.5 MEDIUM

The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'll_reciprocal' parameter in all versions up to, and including, 7.6 due …

Feb 20, 2024
CVE-2024-1510
6.4 MEDIUM

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's su_tooltip shortcode in all versions up …

Feb 20, 2024
CVE-2024-21890
6.5 MEDIUM

The Node.js Permission Model does not clarify in the documentation that wildcards should be only used as the last character of a file path. For …

Feb 20, 2024
CVE-2023-6399
5.7 MEDIUM

A format string vulnerability in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1, USG FLEX series firmware versions from 4.50 through 5.37 …

Feb 20, 2024
CVE-2023-6397
6.5 MEDIUM

A null pointer dereference vulnerability in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1 and USG FLEX series firmware versions from 4.50 …

Feb 20, 2024
CVE-2024-26129
5.8 MEDIUM

PrestaShop is an open-source e-commerce platform. Starting in version 8.1.0 and prior to version 8.1.4, PrestaShop is vulnerable to path disclosure in a JavaScript variable. …

Feb 19, 2024
CVE-2024-25640
4.6 MEDIUM

Iris is a web collaborative platform that helps incident responders share technical details during investigations. A stored Cross-Site Scripting (XSS) vulnerability has been identified in …

Feb 19, 2024
CVE-2024-25982
4.3 MEDIUM

The link to update all installed language packs did not include the necessary token to prevent a CSRF risk.

Feb 19, 2024
CVE-2024-25981
4.3 MEDIUM

Separate Groups mode restrictions were not honored when performing a forum export, which would export forum data for all groups. By default this only provided …

Feb 19, 2024
CVE-2024-25980
4.3 MEDIUM

Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups. By default this only provided additional …

Feb 19, 2024
CVE-2024-25979
5.3 MEDIUM

The URL parameters accepted by forum search were not limited to the allowed parameters.

Feb 19, 2024
CVE-2024-1346
6.8 MEDIUM

Weak MySQL database root password in LaborOfficeFree affects version 19.10. This vulnerability allows an attacker to calculate the root password of the MySQL database used …

Feb 19, 2024
CVE-2024-1345
6.8 MEDIUM

Weak MySQL database root password in LaborOfficeFree affects version 19.10. This vulnerability allows an attacker to perform a brute force attack and easily discover the …

Feb 19, 2024
CVE-2024-1344
6.8 MEDIUM

Encrypted database credentials in LaborOfficeFree affecting version 19.10. This vulnerability allows an attacker to read and extract the username and password from the database of …

Feb 19, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.