CVE Database

9973+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-21795
9.8 CRITICAL

A heap-based buffer overflow vulnerability exists in the .egi parsing functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .egi …

Feb 20, 2024
CVE-2024-23114
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in Apache Camel CassandraQL Component AggregationRepository which is vulnerable to unsafe deserialization. Under specific conditions it is possible to deserialize …

Feb 20, 2024
CVE-2024-22824
9.8 CRITICAL

An issue in Timo v.2.0.3 allows a remote attacker to execute arbitrary code via the filetype restrictions in the UploadController.java component.

Feb 20, 2024
CVE-2023-45318
10.0 CRITICAL

A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP git commit 80d4004. A specially crafted network packet can lead …

Feb 20, 2024
CVE-2024-25198
9.1 CRITICAL

Inappropriate pointer order of laser_scan_filter_.reset() and tf_listener_.reset() (amcl_node.cpp) in Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions leads to a use-after-free.

Feb 20, 2024
CVE-2024-1554
9.8 CRITICAL

The `fetch()` API and navigation incorrectly shared the same cache, as the cache key did not include the optional headers `fetch()` may contain. Under the …

Feb 20, 2024
CVE-2024-25610
9.0 CRITICAL

In Liferay Portal 7.2.0 through 7.4.3.12, and older unsupported versions, and Liferay DXP 7.4 before update 9, 7.3 before update 4, 7.2 before fix pack …

Feb 20, 2024
CVE-2023-49109
9.8 CRITICAL

Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.1. We recommend users to upgrade Apache DolphinScheduler to version 3.2.1, …

Feb 20, 2024
CVE-2024-1608
9.1 CRITICAL

In OPPO Usercenter Credit SDK, there's a possible escalation of privilege due to loose permission check, This could lead to application internal information leak w/o …

Feb 20, 2024
CVE-2024-21896
9.8 CRITICAL

The permission model protects itself against path traversal attacks by calling path.resolve() on any paths given by the user. If the path is to be …

Feb 20, 2024
CVE-2024-1651
10.0 CRITICAL

Torrentpier version 2.4.1 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to insecure deserialization.

Feb 20, 2024
CVE-2024-1644
9.9 CRITICAL

Suite CRM version 7.14.2 allows including local php files. This is possible because the application is vulnerable to LFI.

Feb 20, 2024
CVE-2023-6260
9.0 CRITICAL

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Brivo ACS100, ACS300 allows OS Command Injection, Bypassing Physical Security.This …

Feb 19, 2024
CVE-2023-50257
9.6 CRITICAL

eProsima Fast DDS (formerly Fast RTPS) is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Even with the application …

Feb 19, 2024
CVE-2024-1597
10.0 CRITICAL

pgjdbc, the PostgreSQL JDBC Driver, allows attacker to inject SQL if using PreferQueryMode=SIMPLE. Note this is not the default. In the default mode there is …

Feb 19, 2024
CVE-2024-24722
9.1 CRITICAL

An unquoted service path vulnerability in the 12d Synergy Server and File Replication Server components may allow an attacker to gain elevated privileges via the …

Feb 19, 2024
CVE-2023-52381
9.8 CRITICAL

Script injection vulnerability in the email module.Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.

Feb 18, 2024
CVE-2023-52378
9.8 CRITICAL

Vulnerability of incorrect service logic in the WindowManagerServices module.Successful exploitation of this vulnerability may cause features to perform abnormally.

Feb 18, 2024
CVE-2023-52370
9.8 CRITICAL

Stack overflow vulnerability in the network acceleration module.Successful exploitation of this vulnerability may cause unauthorized file access.

Feb 18, 2024
CVE-2023-52369
9.1 CRITICAL

Stack overflow vulnerability in the NFC module.Successful exploitation of this vulnerability may affect service availability and integrity.

Feb 18, 2024
CVE-2024-1512
9.8 CRITICAL

The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to union based SQL Injection via the 'user' parameter …

Feb 17, 2024
CVE-2024-0610
9.8 CRITICAL

The Piraeus Bank WooCommerce Payment Gateway plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'MerchantReference' parameter in all versions up to, …

Feb 17, 2024
CVE-2024-21915
9.0 CRITICAL

A privilege escalation vulnerability exists in Rockwell Automation FactoryTalk® Service Platform (FTSP). If exploited, a malicious user with basic user group privileges could potentially sign …

Feb 16, 2024
CVE-2024-25320
9.8 CRITICAL

Tongda OA v2017 and up to v11.9 was discovered to contain a SQL injection vulnerability via the $AFF_ID parameter at /affair/delete.php.

Feb 16, 2024
CVE-2024-24377
9.8 CRITICAL

An issue in idocv v.14.1.3_20231228 allows a remote attacker to execute arbitrary code and obtain sensitive information via a crafted script.

Feb 16, 2024
CVE-2024-25414
9.8 CRITICAL

An arbitrary file upload vulnerability in /admin/upgrade of CSZ CMS v1.3.0 allows attackers to execute arbitrary code via uploading a crafted Zip file.

Feb 16, 2024
CVE-2024-0031
9.8 CRITICAL

In attp_build_read_by_type_value_cmd of att_protocol.cc , there is a possible out of bounds write due to improper input validation. This could lead to remote code execution …

Feb 16, 2024
CVE-2024-23674
9.6 CRITICAL

The Online-Ausweis-Funktion eID scheme in the German National Identity card through 2024-02-15 allows authentication bypass by spoofing. A man-in-the-middle attacker can assume a victim's identify …

Feb 15, 2024
CVE-2024-23479
9.6 CRITICAL

SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulnerability. If exploited, this vulnerability allows an unauthenticated …

Feb 15, 2024
CVE-2024-23476
9.6 CRITICAL

The SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulnerability. If exploited, this vulnerability allows an …

Feb 15, 2024
CVE-2023-40057
9.0 CRITICAL

The SolarWinds Access Rights Manager was found to be susceptible to a Remote Code Execution Vulnerability. If exploited, this vulnerability allows an authenticated user to …

Feb 15, 2024
CVE-2024-25502
9.8 CRITICAL

Directory Traversal vulnerability in flusity CMS v.2.4 allows a remote attacker to execute arbitrary code and obtain sensitive information via the download_backup.php component.

Feb 15, 2024
CVE-2023-7081
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in POSTAHSİL Online Payment System allows SQL Injection.This issue affects Online Payment …

Feb 15, 2024
CVE-2023-5155
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Utarit Information Technologies SoliPay Mobile App allows SQL Injection.This issue affects …

Feb 15, 2024
CVE-2024-23113
9.8 CRITICAL KEV

A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 …

Feb 15, 2024
CVE-2024-20720
9.1 CRITICAL

Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') …

Feb 15, 2024
CVE-2024-20719
9.1 CRITICAL

Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin attacker …

Feb 15, 2024
CVE-2024-20738
9.8 CRITICAL

Adobe FrameMaker Publishing Server versions 2022.1 and earlier are affected by an Improper Authentication vulnerability that could result in a Security feature bypass. An attacker …

Feb 15, 2024
CVE-2023-39245
9.8 CRITICAL

DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an information disclosure vulnerability in EHAC component. An remote unauthenticated attacker could potentially exploit …

Feb 15, 2024
CVE-2023-32484
9.8 CRITICAL

Dell Networking Switches running Enterprise SONiC versions 4.1.0, 4.0.5, 3.5.4 and below contains an improper input validation vulnerability. A remote unauthenticated malicious user may exploit …

Feb 15, 2024
CVE-2023-32462
9.8 CRITICAL

Dell OS10 Networking Switches running 10.5.2.x and above contain an OS command injection vulnerability when using remote user authentication. A remote unauthenticated attacker could potentially …

Feb 15, 2024
CVE-2023-28078
9.1 CRITICAL

Dell OS10 Networking Switches running 10.5.2.x and above contain a vulnerability with zeroMQ when VLT is configured. A remote unauthenticated attacker could potentially exploit this …

Feb 15, 2024
CVE-2024-0390
9.8 CRITICAL

INPRAX "iZZi connect" application on Android contains hard-coded MQTT queue credentials. The same MQTT queue is used by corresponding physical recuperation devices. Exploiting this vulnerability …

Feb 15, 2024
CVE-2022-23088
9.8 CRITICAL

The 802.11 beacon handling routine failed to validate the length of an IEEE 802.11s Mesh ID before copying it to a heap-allocated buffer. While a …

Feb 15, 2024
CVE-2024-26264
9.8 CRITICAL

EBM Technologies RISWEB's specific query function parameter does not properly restrict user input, and this feature page is accessible without login. This allows remote attackers …

Feb 15, 2024
CVE-2024-26261
9.8 CRITICAL

The functionality for file download in HGiga OAKlouds' certain modules contains an Arbitrary File Read and Delete vulnerability. Attackers can put file path in specific …

Feb 15, 2024
CVE-2024-26260
9.8 CRITICAL

The functionality for synchronization in HGiga OAKlouds' certain moudules has an OS Command Injection vulnerability, allowing remote attackers to inject system commands within specific request …

Feb 15, 2024
CVE-2024-24300
9.8 CRITICAL

4ipnet EAP-767 v3.42.00 is vulnerable to Incorrect Access Control. The device uses the same set of credentials, regardless of how many times a user logs …

Feb 14, 2024
CVE-2024-25223
9.8 CRITICAL

Simple Admin Panel App v1.0 was discovered to contain a SQL injection vulnerability via the orderID parameter at /adminView/viewEachOrder.php.

Feb 14, 2024
CVE-2024-25222
9.8 CRITICAL

Task Manager App v1.0 was discovered to contain a SQL injection vulnerability via the projectID parameter at /TaskManager/EditProject.php.

Feb 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.