CVE Database

59927+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-24568
5.3 MEDIUM

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.3, the rules inspecting HTTP2 headers can get …

Feb 26, 2024
CVE-2024-1890
6.4 MEDIUM

Vulnerability whereby an attacker could send a malicious link to an authenticated operator, which could allow remote attackers to perform a clickjacking attack on Sunny …

Feb 26, 2024
CVE-2024-1885
6.3 MEDIUM

This vulnerability allows remote attackers to execute arbitrary code on the affected webOS of LG Signage.

Feb 26, 2024
CVE-2024-1878
6.3 MEDIUM

A vulnerability was found in SourceCodester Employee Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Feb 26, 2024
CVE-2024-1877
6.3 MEDIUM

A vulnerability was found in SourceCodester Employee Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Feb 26, 2024
CVE-2024-1875
6.3 MEDIUM

A vulnerability was found in SourceCodester Complaint Management System 1.0 and classified as critical. This issue affects some unknown processing of the file users/register-complaint.php of …

Feb 26, 2024
CVE-2024-1758
5.4 MEDIUM

The SuperFaktura WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.40.3 via the wc_sf_url_check function. This …

Feb 26, 2024
CVE-2024-1436
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wiloke WooCommerce Coupon Popup, SmartBar, Slide In | MyShopKit.This issue affects WooCommerce Coupon Popup, SmartBar, …

Feb 26, 2024
CVE-2024-1165
4.3 MEDIUM

The Brizy – Page Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.39 via the 'id'. This …

Feb 26, 2024
CVE-2024-0798
6.5 MEDIUM

A privilege escalation vulnerability exists in mintplex-labs/anything-llm, allowing users with 'default' role to delete documents uploaded by 'admin'. Despite the intended restriction that prevents 'default' …

Feb 26, 2024
CVE-2024-0440
6.5 MEDIUM

Attacker, with permission to submit a link or submits a link via POST to be collected that is using the file:// protocol can then introspect …

Feb 26, 2024
CVE-2024-0436
5.9 MEDIUM

Theoretically, it would be possible for an attacker to brute-force the password for an instance in single-user password protection mode via a timing attack given …

Feb 26, 2024
CVE-2024-0435
5.4 MEDIUM

User can send a chat that contains an XSS opportunity that will then run when the chat is sent and on subsequent page loads. Given …

Feb 26, 2024
CVE-2024-0387
6.5 MEDIUM

The EDS-4000/G4000 Series prior to version 3.2 includes IP forwarding capabilities that users cannot deactivate. An attacker may be able to send requests to the …

Feb 26, 2024
CVE-2023-52473
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: thermal: core: Fix NULL pointer dereference in zone registration error path If device_register() in thermal_zone_device_register_with_trips() …

Feb 26, 2024
CVE-2023-52472
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: crypto: rsa - add a check for allocation failure Static checkers insist that the mpi_alloc() …

Feb 26, 2024
CVE-2023-52471
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ice: Fix some null pointer dereference issues in ice_ptp.c devm_kasprintf() returns a pointer to dynamically …

Feb 26, 2024
CVE-2023-52470
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/radeon: check the alloc_workqueue return value in radeon_crtc_init() check the alloc_workqueue return value in radeon_crtc_init() …

Feb 26, 2024
CVE-2023-52467
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mfd: syscon: Fix null pointer dereference in of_syscon_register() kasprintf() returns a pointer to dynamically allocated …

Feb 26, 2024
CVE-2023-52465
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: power: supply: Fix null pointer dereference in smb2_probe devm_kasprintf and devm_kzalloc return a pointer to …

Feb 26, 2024
CVE-2023-49114
6.7 MEDIUM

A DLL hijacking vulnerability was identified in the Qognify VMS Client Viewer version 7.1 or higher, which allows local users to execute arbitrary code and …

Feb 26, 2024
CVE-2023-43051
5.4 MEDIUM

IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI …

Feb 26, 2024
CVE-2023-38359
6.1 MEDIUM

IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI …

Feb 26, 2024
CVE-2023-32344
4.3 MEDIUM

IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 is vulnerable to form action hijacking where it is possible to modify the form action to reference an …

Feb 26, 2024
CVE-2023-30996
5.3 MEDIUM

IBM Cognos Analytics 11.1.7, 11.2.4, and 12.0.0 could be vulnerable to information leakage due to unverified sources in messages sent between Windows objects of different …

Feb 26, 2024
CVE-2022-34357
6.5 MEDIUM

IBM Cognos Analytics Mobile Server 11.1.7, 11.2.4, and 12.0.0 is vulnerable to Denial of Service due to due to weak or absence of rate limiting. …

Feb 26, 2024
CVE-2021-46905
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: hso: fix NULL-deref on disconnect regression Commit 8a12f8836145 ("net: hso: fix null-ptr-deref during tty …

Feb 26, 2024
CVE-2021-46904
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: hso: fix null-ptr-deref during tty device unregistration Multiple ttys try to claim the same …

Feb 26, 2024
CVE-2024-21501
5.3 MEDIUM

Versions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attribute allowed, allowing enumeration …

Feb 24, 2024
CVE-2024-1810
6.1 MEDIUM

The Archivist – Custom Archive Templates plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘shortcode_attributes' parameter in all versions up to, and …

Feb 24, 2024
CVE-2024-22395
6.3 MEDIUM

Improper access control vulnerability has been identified in the SMA100 SSL-VPN virtual office portal, which in specific conditions could potentially enable a remote authenticated attacker …

Feb 24, 2024
CVE-2024-26188
4.3 MEDIUM

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Feb 23, 2024
CVE-2024-21423
4.8 MEDIUM

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

Feb 23, 2024
CVE-2021-33146
5.3 MEDIUM

Improper input validation in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow an unauthenticated user to potentially enable information disclosure …

Feb 23, 2024
CVE-2021-33142
6.0 MEDIUM

Improper input validation in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user to potentially enable denial of …

Feb 23, 2024
CVE-2023-51394
5.3 MEDIUM

High traffic environments may result in NULL Pointer Dereference vulnerability in Silicon Labs's Ember ZNet SDK before v7.4.0, causing a system crash.

Feb 23, 2024
CVE-2023-51393
5.3 MEDIUM

Due to an allocation of resources without limits, an uncontrolled resource consumption vulnerability exists in Silicon Labs Ember ZNet SDK prior to v7.4.0.0 (delivered as …

Feb 23, 2024
CVE-2024-27319
4.4 MEDIUM

Versions of the package onnx before and including 1.15.0 are vulnerable to Out-of-bounds Read as the ONNX_ASSERT and ONNX_ASSERTM functions have an off by one …

Feb 23, 2024
CVE-2024-1825
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in CodeAstro House Rental Management System 1.0. This affects an unknown part of the component User …

Feb 23, 2024
CVE-2023-51392
6.2 MEDIUM

Ember ZNet between v7.2.0 and v7.4.0 used software AES-CCM instead of integrated hardware cryptographic accelerators, potentially increasing risk of electromagnetic and differential power analysis sidechannel …

Feb 23, 2024
CVE-2024-1823
5.3 MEDIUM

A vulnerability classified as critical was found in CodeAstro Simple Voting System 1.0. Affected by this vulnerability is an unknown functionality of the file users.php …

Feb 23, 2024
CVE-2024-1821
5.5 MEDIUM

A vulnerability was found in code-projects Crime Reporting System 1.0. It has been rated as critical. This issue affects some unknown processing of the file …

Feb 23, 2024
CVE-2024-26596
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: dsa: fix netdev_priv() dereference before check on non-DSA netdevice events After the blamed commit, …

Feb 23, 2024
CVE-2024-26595
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_acl_tcam: Fix NULL pointer dereference in error path When calling mlxsw_sp_acl_tcam_region_destroy() from an error …

Feb 23, 2024
CVE-2024-25629
4.4 MEDIUM

c-ares is a C library for asynchronous DNS requests. `ares__read_line()` is used to parse local configuration files such as `/etc/resolv.conf`, `/etc/nsswitch.conf`, the `HOSTALIASES` file, and …

Feb 23, 2024
CVE-2024-22776
4.7 MEDIUM

Wallos 0.9 is vulnerable to Cross Site Scripting (XSS) in all text-based input fields without proper validation, excluding those requiring specific formats like date fields.

Feb 23, 2024
CVE-2024-1819
4.7 MEDIUM

A vulnerability was found in CodeAstro Membership Management System 1.0. It has been classified as critical. This affects an unknown part of the component Add …

Feb 23, 2024
CVE-2024-1818
4.7 MEDIUM

A vulnerability was found in CodeAstro Membership Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Feb 23, 2024
CVE-2023-52463
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: efivarfs: force RO when remounting if SetVariable is not supported If SetVariable at runtime is …

Feb 23, 2024
CVE-2023-52462
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: fix check for attempt to corrupt spilled pointer When register is spilled onto a …

Feb 23, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.