CVE Database

11843+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-22127
9.1 CRITICAL

SAP NetWeaver Administrator AS Java (Administrator Log Viewer plug-in) - version 7.50, allows an attacker with high privileges to upload potentially dangerous files which leads …

Mar 12, 2024
CVE-2023-49785
9.1 CRITICAL

NextChat, also known as ChatGPT-Next-Web, is a cross-platform chat user interface for use with ChatGPT. Versions 2.11.2 and prior are vulnerable to server-side request forgery …

Mar 12, 2024
CVE-2024-27228
9.8 CRITICAL

there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution …

Mar 11, 2024
CVE-2024-27227
9.8 CRITICAL

A malicious DNS response can trigger a number of OOB reads, writes, and other memory issues

Mar 11, 2024
CVE-2024-27207
9.1 CRITICAL

Exported broadcast receivers allowing malicious apps to bypass broadcast protection.

Mar 11, 2024
CVE-2024-0039
9.8 CRITICAL

In attp_build_value_cmd of att_protocol.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution …

Mar 11, 2024
CVE-2024-2184
9.8 CRITICAL

Buffer overflow in identifier field of WSD probe request process of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the …

Mar 11, 2024
CVE-2023-46427
9.8 CRITICAL

An issue was discovered in gpac version 2.3-DEV-rev588-g7edc40fee-master, allows remote attackers to execute arbitrary code, cause a denial of service (DoS), and obtain sensitive information …

Mar 9, 2024
CVE-2023-49340
9.8 CRITICAL

An issue was discovered in Newland Nquire 1000 Interactive Kiosk version NQ1000-II_G_V1.00.011, allows remote attackers to escalate privileges and bypass authentication via incorrect access control …

Mar 9, 2024
CVE-2024-21899
9.8 CRITICAL

An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to compromise the security …

Mar 8, 2024
CVE-2024-25849
9.8 CRITICAL

In the module "Make an offer" (makeanoffer) <= 1.7.1 from PrestaToolKit for PrestaShop, a guest can perform SQL injection via MakeOffers::checkUserExistingOffer()` and `MakeOffers::addUserOffer()` .

Mar 8, 2024
CVE-2024-25845
9.8 CRITICAL

In the module "CD Custom Fields 4 Orders" (cdcustomfields4orders) <= 1.0.0 from Cleanpresta.com for PrestaShop, a guest can perform SQL injection in affected versions.

Mar 8, 2024
CVE-2024-2044
9.9 CRITICAL

pgAdmin <= 8.3 is affected by a path-traversal vulnerability while deserializing users’ sessions in the session handling code. If the server is running on Windows, …

Mar 7, 2024
CVE-2024-0818
9.1 CRITICAL

Arbitrary File Overwrite Via Path Traversal in paddlepaddle/paddle before 2.6

Mar 7, 2024
CVE-2024-0917
9.8 CRITICAL

remote code execution in paddlepaddle/paddle 2.6.0

Mar 7, 2024
CVE-2023-42662
9.3 CRITICAL

JFrog Artifactory versions 7.59 and above, but below 7.59.18, 7.63.18, 7.68.19, 7.71.8 are vulnerable to an issue whereby user interaction with specially crafted URLs could …

Mar 7, 2024
CVE-2023-41503
9.8 CRITICAL

Student Enrollment In PHP v1.0 was discovered to contain a SQL injection vulnerability via the Login function.

Mar 7, 2024
CVE-2023-41014
9.8 CRITICAL

code-projects.org Online Job Portal 1.0 is vulnerable to SQL Injection via the Username parameter for "Employer."

Mar 7, 2024
CVE-2024-28222
9.8 CRITICAL

In Veritas NetBackup before 8.1.2 and NetBackup Appliance before 3.1.2, the BPCD process inadequately validates the file path, allowing an unauthenticated attacker to upload and …

Mar 7, 2024
CVE-2024-28213
9.8 CRITICAL

nGrinder before 3.5.9 allows to accept serialized Java objects from unauthenticated users, which could allow remote attacker to execute arbitrary code via unsafe Java objects …

Mar 7, 2024
CVE-2024-28212
9.8 CRITICAL

nGrinder before 3.5.9 uses old version of SnakeYAML, which could allow remote attacker to execute arbitrary code via unsafe deserialization.

Mar 7, 2024
CVE-2024-28211
9.8 CRITICAL

nGrinder before 3.5.9 allows connection to malicious JMX/RMI server by default, which could be the cause of executing arbitrary code via RMI registry by remote …

Mar 7, 2024
CVE-2024-22857
9.8 CRITICAL

Heap based buffer flow in zlog v1.1.0 to v1.2.17 in zlog_rule_new().The size of record_name is MAXLEN_PATH(1024) + 1 but file_path may have data upto MAXLEN_CFG_LINE(MAXLEN_PATH*4) …

Mar 7, 2024
CVE-2023-51786
9.1 CRITICAL

An issue was discovered in Lustre versions 2.13.x, 2.14.x, and 2.15.x before 2.15.4, allows attackers to escalate privileges and obtain sensitive information via Incorrect Access …

Mar 7, 2024
CVE-2023-49989
9.8 CRITICAL

Hotel Booking Management v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at update.php.

Mar 7, 2024
CVE-2024-27307
9.8 CRITICAL

JSONata is a JSON query and transformation language. Starting in version 1.4.0 and prior to version 1.8.7 and 2.0.4, a malicious expression can use the …

Mar 6, 2024
CVE-2024-27304
9.8 CRITICAL

pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to …

Mar 6, 2024
CVE-2024-27302
9.1 CRITICAL

go-zero is a web and rpc framework. Go-zero allows user to specify a CORS Filter with a configurable allows param - which is an array …

Mar 6, 2024
CVE-2024-24767
9.1 CRITICAL

CasaOS-UserService provides user management functionalities to CasaOS. Starting in version 0.4.4.3 and prior to version 0.4.7, CasaOS doesn't defend against password brute force attacks, which …

Mar 6, 2024
CVE-2023-50716
9.6 CRITICAL

eProsima Fast DDS (formerly Fast RTPS) is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.13.0, …

Mar 6, 2024
CVE-2024-2005
9.0 CRITICAL

In Blue Planet® products through 22.12, a misconfiguration in the SAML implementation allows for privilege escalation. Only products using SAML authentication are affected. Blue Planet® …

Mar 6, 2024
CVE-2024-26580
9.1 CRITICAL

Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.8.0 through 1.10.0, the attackers can use the specific payload to read …

Mar 6, 2024
CVE-2023-38945
9.8 CRITICAL

Multilaser RE160 v5.07.51_pt_MTL01 and v5.07.52_pt_MTL01, Multilaser RE160V v12.03.01.08_pt and V12.03.01.09_pt, and Multilaser RE163V v12.03.01.08_pt allows attackers to bypass the access control and gain complete access …

Mar 6, 2024
CVE-2023-38944
9.8 CRITICAL

An issue in Multilaser RE160V firmware v12.03.01.09_pt and Multilaser RE163V firmware v12.03.01.10_pt allows attackers to bypass the access control and gain complete access to the …

Mar 6, 2024
CVE-2024-27764
9.8 CRITICAL

An issue in Jeewms v.3.7 and before allows a remote attacker to escalate privileges via the AuthInterceptor component.

Mar 5, 2024
CVE-2024-24276
9.6 CRITICAL

Cross Site Scripting (XSS) vulnerability in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive information via a crafted payload …

Mar 5, 2024
CVE-2024-24275
9.6 CRITICAL

Cross Site Scripting vulnerability in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive information via a crafted payload to …

Mar 5, 2024
CVE-2024-2056
9.8 CRITICAL

Services that are running and bound to the loopback interface on the Artica Proxy are accessible through the proxy service. In particular, the "tailon" service …

Mar 5, 2024
CVE-2024-2055
9.8 CRITICAL

The "Rich Filemanager" feature of Artica Proxy provides a web-based interface for file management capabilities. When the feature is enabled, it does not require authentication …

Mar 5, 2024
CVE-2024-22253
9.3 CRITICAL

VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine …

Mar 5, 2024
CVE-2024-22252
9.3 CRITICAL

VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine …

Mar 5, 2024
CVE-2024-27565
9.8 CRITICAL

A Server-Side Request Forgery (SSRF) in weixin.php of ChatGPT-wechat-personal commit a0857f6 allows attackers to force the application to make arbitrary requests.

Mar 5, 2024
CVE-2023-7103
9.8 CRITICAL

Authentication Bypass by Primary Weakness vulnerability in ZKSoftware Biometric Security Solutions UFace 5 allows Authentication Bypass.This issue affects UFace 5: through 12022024.

Mar 5, 2024
CVE-2024-26339
9.1 CRITICAL

swftools v0.9.2 was discovered to contain a strcpy parameter overlap via /home/swftools/src/swfc+0x48318a.

Mar 5, 2024
CVE-2024-21815
9.1 CRITICAL

Insufficiently protected credentials (CWE-522) for third party DVR integrations to the Command Centre Server are accessible to authenticated but unprivileged users. This issue affects: Gallagher …

Mar 5, 2024
CVE-2023-49970
9.8 CRITICAL

Customer Support System v1 was discovered to contain a SQL injection vulnerability via the subject parameter at /customer_support/ajax.php?action=save_ticket.

Mar 5, 2024
CVE-2023-49547
9.8 CRITICAL

Customer Support System v1 was discovered to contain a SQL injection vulnerability via the username parameter at /customer_support/ajax.php?action=login.

Mar 5, 2024
CVE-2024-27198
9.8 CRITICAL KEV

In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible

Mar 4, 2024
CVE-2023-43553
9.8 CRITICAL

Memory corruption while parsing beacon/probe response frame when AP sends more supported links in MLIE.

Mar 4, 2024
CVE-2023-43552
9.8 CRITICAL

Memory corruption while processing MBSSID beacon containing several subelement IE.

Mar 4, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.