CVE Database

122268+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-45929
9.1 CRITICAL

S-Lang 2.3.2 was discovered to contain a segmentation fault via the function fixup_tgetstr().

Mar 27, 2024
CVE-2023-45927
9.1 CRITICAL

S-Lang 2.3.2 was discovered to contain an arithmetic exception via the function tt_sprintf().

Mar 27, 2024
CVE-2023-45913
6.2 MEDIUM

Mesa v23.0.4 was discovered to contain a NULL pointer dereference via the function dri2GetGlxDrawableFromXDrawableId(). This vulnerability is triggered when the X11 server sends an DRI2_BufferSwapComplete …

Mar 27, 2024
CVE-2023-40290
8.3 HIGH

An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue that affects Internet Explorer 11 on …

Mar 27, 2024
CVE-2023-40289
7.2 HIGH

A command injection issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker can exploit this to elevate privileges from a user …

Mar 27, 2024
CVE-2023-40288
8.3 HIGH

An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue.

Mar 27, 2024
CVE-2023-40287
8.3 HIGH

An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue.

Mar 27, 2024
CVE-2023-40286
8.3 HIGH

An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue.

Mar 27, 2024
CVE-2023-40285
6.5 MEDIUM

An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue.

Mar 27, 2024
CVE-2023-40284
8.3 HIGH

An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue.

Mar 27, 2024
CVE-2023-39804
6.2 MEDIUM

In GNU tar before 1.35, mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c.

Mar 27, 2024
CVE-2024-2945
6.3 MEDIUM

A vulnerability was found in Campcodes Online Examination System 1.0. It has been classified as critical. Affected is an unknown function of the file /adminpanel/admin/facebox_modal/updateExaminee.php. …

Mar 27, 2024
CVE-2024-2944
6.3 MEDIUM

A vulnerability was found in Campcodes Online Examination System 1.0 and classified as critical. This issue affects some unknown processing of the file /adminpanel/admin/query/deleteCourseExe.php. The …

Mar 27, 2024
CVE-2024-2943
6.3 MEDIUM

A vulnerability has been found in Campcodes Online Examination System 1.0 and classified as critical. This vulnerability affects unknown code of the file /adminpanel/admin/query/deleteExamExe.php. The …

Mar 27, 2024
CVE-2024-2942
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Campcodes Online Examination System 1.0. This affects an unknown part of the file /adminpanel/admin/query/deleteQuestionExe.php. The …

Mar 27, 2024
CVE-2024-2941
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Campcodes Online Examination System 1.0. Affected by this issue is some unknown functionality of …

Mar 27, 2024
CVE-2024-2210
6.4 MEDIUM

The The Plus Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.4.1 via the …

Mar 27, 2024
CVE-2024-2203
6.4 MEDIUM

The The Plus Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.4.1 via the …

Mar 27, 2024
CVE-2024-2139
6.4 MEDIUM

The Master Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Pricing Table widget in all versions up to, and …

Mar 27, 2024
CVE-2024-2097
7.5 HIGH

An authenticated malicious client can send a special LINQ query to execute arbitrary code remotely (RCE) on the SCM server from List control, and execute …

Mar 27, 2024
CVE-2024-25736
7.5 HIGH

An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can restart the device via a /device/reboot GET request.

Mar 27, 2024
CVE-2024-25735
9.1 CRITICAL

An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. Remote attackers can discover cleartext passwords via a SoftAP /device/config GET request.

Mar 27, 2024
CVE-2024-25734
7.5 HIGH

An issue was discovered on WyreStorm Apollo VX20 devices before 1.3.58. The TELNET service prompts for a password only after a valid username is entered, …

Mar 27, 2024
CVE-2024-25580
6.2 MEDIUM

An issue was discovered in gui/util/qktxhandler.cpp in Qt before 5.15.17, 6.x before 6.2.12, 6.3.x through 6.5.x before 6.5.5, and 6.6.x before 6.6.2. A buffer overflow …

Mar 27, 2024
CVE-2024-25395
8.8 HIGH

A buffer overflow occurs in utilities/rt-link/src/rtlink.c in RT-Thread through 5.0.2.

Mar 27, 2024
CVE-2024-25394
4.3 MEDIUM

A buffer overflow occurs in utilities/ymodem/ry_sy.c in RT-Thread through 5.0.2 because of an incorrect sprintf call or a missing '\0' character.

Mar 27, 2024
CVE-2024-25393
9.8 CRITICAL

A stack buffer overflow occurs in net/at/src/at_server.c in RT-Thread through 5.0.2.

Mar 27, 2024
CVE-2024-25392
5.9 MEDIUM

An out-of-bounds access occurs in utilities/var_export/var_export.c in RT-Thread through 5.0.2.

Mar 27, 2024
CVE-2024-25391
8.4 HIGH

A stack buffer overflow occurs in libc/posix/ipc/mqueue.c in RT-Thread through 5.0.2.

Mar 27, 2024
CVE-2024-25390
8.4 HIGH

A heap buffer overflow occurs in finsh/msh_file.c and finsh/msh.c in RT-Thread through 5.0.2.

Mar 27, 2024
CVE-2024-25389
7.5 HIGH

RT-Thread through 5.0.2 generates random numbers with a weak algorithm of "seed = 214013L * seed + 2531011L; return (seed >> 16) & 0x7FFF;" in …

Mar 27, 2024
CVE-2024-25388
8.4 HIGH

drivers/wlan/wlan_mgmt,c in RT-Thread through 5.0.2 has an integer signedness error and resultant buffer overflow.

Mar 27, 2024
CVE-2024-24335
8.4 HIGH

A heap buffer overflow occurs in the dfs_v2 romfs filesystem RT-Thread through 5.0.2.

Mar 27, 2024
CVE-2024-24334
8.4 HIGH

A heap buffer overflow occurs in dfs_v2 dfs_file in RT-Thread through 5.0.2.

Mar 27, 2024
CVE-2024-1532
6.8 MEDIUM

A vulnerability exists in the stb-language file handling that affects the RTU500 series product versions listed below. A malicious actor could enforce diagnostic texts being …

Mar 27, 2024
CVE-2024-0400
7.5 HIGH

SCM Software is a client and server application. An Authenticated System manager client can execute LINQ query in the SCM server, for customized filtering. An …

Mar 27, 2024
CVE-2024-2940
3.5 LOW

A vulnerability classified as problematic was found in Campcodes Online Examination System 1.0. Affected by this vulnerability is an unknown functionality of the file /adminpanel/admin/facebox_modal/updateCourse.php. …

Mar 27, 2024
CVE-2024-2244
5.3 MEDIUM

REST service authentication anomaly with “valid username/no password” credential combination for batch job processing resulting in successful service invocation. The anomaly doesn’t exist with other …

Mar 27, 2024
CVE-2024-1531
8.2 HIGH

A vulnerability exists in the stb-language file handling that affects the RTU500 series product versions listed below. A malicious actor could print random memory content …

Mar 27, 2024
CVE-2024-2939
3.5 LOW

A vulnerability classified as problematic has been found in Campcodes Online Examination System 1.0. Affected is an unknown function of the file /adminpanel/admin/facebox_modal/updateExaminee.php. The manipulation …

Mar 27, 2024
CVE-2024-2938
6.3 MEDIUM

A vulnerability was found in Campcodes Online Examination System 1.0. It has been rated as critical. This issue affects some unknown processing of the file …

Mar 27, 2024
CVE-2024-2935
3.5 LOW

A vulnerability, which was classified as problematic, has been found in SourceCodester Todo List in Kanban Board 1.0. Affected by this issue is some unknown …

Mar 27, 2024
CVE-2024-2934
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Todo List in Kanban Board 1.0. Affected by this vulnerability is an unknown functionality of the …

Mar 27, 2024
CVE-2024-2932
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Online Chatting System 1.0. Affected is an unknown function of the file admin/update_room.php. The manipulation …

Mar 27, 2024
CVE-2024-2206
6.5 MEDIUM

An SSRF vulnerability exists in the gradio-app/gradio due to insufficient validation of user-supplied URLs in the `/proxy` route. Attackers can exploit this vulnerability by manipulating …

Mar 27, 2024
CVE-2024-2930
7.3 HIGH

A vulnerability was found in SourceCodester Music Gallery Site 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Mar 27, 2024
CVE-2024-2209
6.3 MEDIUM

A user with administrative privileges can create a compromised dll file of the same name as the original dll within the HP printer’s Firmware Update …

Mar 27, 2024
CVE-2017-20190

Some Microsoft technologies as used in Windows 8 through 11 allow a temporary client-side performance degradation during processing of multiple Unicode combining characters, aka a …

Mar 27, 2024
CVE-2024-2927
7.3 HIGH

A vulnerability was found in code-projects Mobile Shop 1.0. It has been classified as critical. Affected is an unknown function of the file Details.php of …

Mar 26, 2024
CVE-2024-2917
5.4 MEDIUM

A vulnerability was found in Campcodes House Rental Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Mar 26, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.