CVE Database

11843+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-25603
9.0 CRITICAL

Stored cross-site scripting (XSS) vulnerability in the Dynamic Data Mapping module's DDMForm in Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP …

Feb 21, 2024
CVE-2024-1631
9.1 CRITICAL

Impact: The library offers a function to generate an ed25519 key pair via Ed25519KeyIdentity.generate with an optional param to provide a 32 byte seed value, …

Feb 21, 2024
CVE-2023-42498
9.6 CRITICAL

Reflected cross-site scripting (XSS) vulnerability in the Language Override edit screen in Liferay Portal 7.4.3.8 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 5, and …

Feb 21, 2024
CVE-2023-42496
9.6 CRITICAL

Reflected cross-site scripting (XSS) vulnerability on the add assignees to a role page in Liferay Portal 7.3.3 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch …

Feb 21, 2024
CVE-2023-40191
9.0 CRITICAL

Reflected cross-site scripting (XSS) vulnerability in the instance settings for Accounts in Liferay Portal 7.4.3.44 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 6, and …

Feb 21, 2024
CVE-2024-25602
9.0 CRITICAL

Stored cross-site scripting (XSS) vulnerability in Users Admin module's edit user page in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP …

Feb 21, 2024
CVE-2024-25601
9.0 CRITICAL

Stored cross-site scripting (XSS) vulnerability in Expando module's geolocation custom fields in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 …

Feb 21, 2024
CVE-2024-25152
9.0 CRITICAL

Stored cross-site scripting (XSS) vulnerability in Message Board widget in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service …

Feb 21, 2024
CVE-2024-25147
9.6 CRITICAL

Cross-site scripting (XSS) vulnerability in HtmlUtil.escapeJsLink in Liferay Portal 7.2.0 through 7.4.1, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 …

Feb 21, 2024
CVE-2024-25141
9.1 CRITICAL

When ssl was enabled for Mongo Hook, default settings included "allow_insecure" which caused that certificates were not validated. This was unexpected and undocumented. Users are …

Feb 20, 2024
CVE-2024-22245
9.6 CRITICAL

Arbitrary Authentication Relay and Session Hijack vulnerabilities in the deprecated VMware Enhanced Authentication Plug-in (EAP) could allow a malicious actor that could trick a target …

Feb 20, 2024
CVE-2024-0794
9.8 CRITICAL

Certain HP LaserJet Pro, HP Enterprise LaserJet, and HP LaserJet Managed Printers are potentially vulnerable to Remote Code Execution due to buffer overflow when rendering …

Feb 20, 2024
CVE-2024-25274
9.8 CRITICAL

An arbitrary file upload vulnerability in the component /sysFile/upload of Novel-Plus v4.3.0-RC1 allows attackers to execute arbitrary code via uploading a crafted file.

Feb 20, 2024
CVE-2024-23809
9.8 CRITICAL

A double-free vulnerability exists in the BrainVision ASCII Header Parsing functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .vdhr …

Feb 20, 2024
CVE-2024-23606
9.8 CRITICAL

An out-of-bounds write vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .famos file can …

Feb 20, 2024
CVE-2024-23313
9.8 CRITICAL

An integer underflow vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .famos file can …

Feb 20, 2024
CVE-2024-23310
9.8 CRITICAL

A use-after-free vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .famos file can lead …

Feb 20, 2024
CVE-2024-23305
9.8 CRITICAL

An out-of-bounds write vulnerability exists in the BrainVisionMarker Parsing functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .vmrk file …

Feb 20, 2024
CVE-2024-22097
9.8 CRITICAL

A double-free vulnerability exists in the BrainVision Header Parsing functionality of The Biosig Project libbiosig Master Branch (ab0ee111) and 2.5.0. A specially crafted .vdhr file …

Feb 20, 2024
CVE-2024-21812
9.8 CRITICAL

An integer overflow vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .famos file can …

Feb 20, 2024
CVE-2024-21795
9.8 CRITICAL

A heap-based buffer overflow vulnerability exists in the .egi parsing functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .egi …

Feb 20, 2024
CVE-2024-23114
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in Apache Camel CassandraQL Component AggregationRepository which is vulnerable to unsafe deserialization. Under specific conditions it is possible to deserialize …

Feb 20, 2024
CVE-2024-22824
9.8 CRITICAL

An issue in Timo v.2.0.3 allows a remote attacker to execute arbitrary code via the filetype restrictions in the UploadController.java component.

Feb 20, 2024
CVE-2023-45318
10.0 CRITICAL

A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP git commit 80d4004. A specially crafted network packet can lead …

Feb 20, 2024
CVE-2024-25198
9.1 CRITICAL

Inappropriate pointer order of laser_scan_filter_.reset() and tf_listener_.reset() (amcl_node.cpp) in Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions leads to a use-after-free.

Feb 20, 2024
CVE-2024-1554
9.8 CRITICAL

The `fetch()` API and navigation incorrectly shared the same cache, as the cache key did not include the optional headers `fetch()` may contain. Under the …

Feb 20, 2024
CVE-2024-25610
9.0 CRITICAL

In Liferay Portal 7.2.0 through 7.4.3.12, and older unsupported versions, and Liferay DXP 7.4 before update 9, 7.3 before update 4, 7.2 before fix pack …

Feb 20, 2024
CVE-2023-49109
9.8 CRITICAL

Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.1. We recommend users to upgrade Apache DolphinScheduler to version 3.2.1, …

Feb 20, 2024
CVE-2024-1608
9.1 CRITICAL

In OPPO Usercenter Credit SDK, there's a possible escalation of privilege due to loose permission check, This could lead to application internal information leak w/o …

Feb 20, 2024
CVE-2024-21896
9.8 CRITICAL

The permission model protects itself against path traversal attacks by calling path.resolve() on any paths given by the user. If the path is to be …

Feb 20, 2024
CVE-2024-1651
10.0 CRITICAL

Torrentpier version 2.4.1 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to insecure deserialization.

Feb 20, 2024
CVE-2024-1644
9.9 CRITICAL

Suite CRM version 7.14.2 allows including local php files. This is possible because the application is vulnerable to LFI.

Feb 20, 2024
CVE-2023-6260
9.0 CRITICAL

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Brivo ACS100, ACS300 allows OS Command Injection, Bypassing Physical Security.This …

Feb 19, 2024
CVE-2023-50257
9.6 CRITICAL

eProsima Fast DDS (formerly Fast RTPS) is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Even with the application …

Feb 19, 2024
CVE-2024-1597
10.0 CRITICAL

pgjdbc, the PostgreSQL JDBC Driver, allows attacker to inject SQL if using PreferQueryMode=SIMPLE. Note this is not the default. In the default mode there is …

Feb 19, 2024
CVE-2024-24722
9.1 CRITICAL

An unquoted service path vulnerability in the 12d Synergy Server and File Replication Server components may allow an attacker to gain elevated privileges via the …

Feb 19, 2024
CVE-2023-52381
9.8 CRITICAL

Script injection vulnerability in the email module.Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.

Feb 18, 2024
CVE-2023-52378
9.8 CRITICAL

Vulnerability of incorrect service logic in the WindowManagerServices module.Successful exploitation of this vulnerability may cause features to perform abnormally.

Feb 18, 2024
CVE-2023-52370
9.8 CRITICAL

Stack overflow vulnerability in the network acceleration module.Successful exploitation of this vulnerability may cause unauthorized file access.

Feb 18, 2024
CVE-2023-52369
9.1 CRITICAL

Stack overflow vulnerability in the NFC module.Successful exploitation of this vulnerability may affect service availability and integrity.

Feb 18, 2024
CVE-2024-1512
9.8 CRITICAL

The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to union based SQL Injection via the 'user' parameter …

Feb 17, 2024
CVE-2024-0610
9.8 CRITICAL

The Piraeus Bank WooCommerce Payment Gateway plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'MerchantReference' parameter in all versions up to, …

Feb 17, 2024
CVE-2024-21915
9.0 CRITICAL

A privilege escalation vulnerability exists in Rockwell Automation FactoryTalk® Service Platform (FTSP). If exploited, a malicious user with basic user group privileges could potentially sign …

Feb 16, 2024
CVE-2024-25320
9.8 CRITICAL

Tongda OA v2017 and up to v11.9 was discovered to contain a SQL injection vulnerability via the $AFF_ID parameter at /affair/delete.php.

Feb 16, 2024
CVE-2024-24377
9.8 CRITICAL

An issue in idocv v.14.1.3_20231228 allows a remote attacker to execute arbitrary code and obtain sensitive information via a crafted script.

Feb 16, 2024
CVE-2024-25414
9.8 CRITICAL

An arbitrary file upload vulnerability in /admin/upgrade of CSZ CMS v1.3.0 allows attackers to execute arbitrary code via uploading a crafted Zip file.

Feb 16, 2024
CVE-2024-0031
9.8 CRITICAL

In attp_build_read_by_type_value_cmd of att_protocol.cc , there is a possible out of bounds write due to improper input validation. This could lead to remote code execution …

Feb 16, 2024
CVE-2024-23674
9.6 CRITICAL

The Online-Ausweis-Funktion eID scheme in the German National Identity card through 2024-02-15 allows authentication bypass by spoofing. A man-in-the-middle attacker can assume a victim's identify …

Feb 15, 2024
CVE-2024-23479
9.6 CRITICAL

SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulnerability. If exploited, this vulnerability allows an unauthenticated …

Feb 15, 2024
CVE-2024-23476
9.6 CRITICAL

The SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulnerability. If exploited, this vulnerability allows an …

Feb 15, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.