CVE Database

11843+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-24026
9.8 CRITICAL

An arbitrary File upload vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions at com.java2nb.system.controller.SysUserController: uploadImg(). An attacker can pass in specially crafted filename parameter to …

Feb 8, 2024
CVE-2024-24025
9.8 CRITICAL

An arbitrary File upload vulnerability exists in Novel-Plus v4.3.0-RC1 and prior at com.java2nb.common.controller.FileController: upload(). An attacker can pass in specially crafted filename parameter to perform …

Feb 8, 2024
CVE-2024-24024
9.8 CRITICAL

An arbitrary File download vulnerability exists in Novel-Plus v4.3.0-RC1 and prior at com.java2nb.common.controller.FileController: fileDownload(). An attacker can pass in specially crafted filePath and fieName parameters …

Feb 8, 2024
CVE-2024-24023
9.8 CRITICAL

A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior. An attacker can pass specially crafted offset, limit, and sort parameters to perform SQL injection …

Feb 8, 2024
CVE-2024-24018
9.8 CRITICAL

A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset, limit, and sort parameters to perform SQL …

Feb 8, 2024
CVE-2023-48974
9.6 CRITICAL

Cross Site Scripting vulnerability in Axigen WebMail prior to 10.3.3.61 allows a remote attacker to escalate privileges via a crafted script to the serverName_input parameter.

Feb 8, 2024
CVE-2023-38995
9.8 CRITICAL

An issue in SCHUHFRIED v.8.22.00 allows remote attacker to obtain the database password via crafted curl command.

Feb 7, 2024
CVE-2024-24563
9.8 CRITICAL

Vyper is a Pythonic Smart Contract Language for the Ethereum Virtual Machine. Arrays can be keyed by a signed integer, while they are defined for …

Feb 7, 2024
CVE-2024-20254
9.6 CRITICAL

Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to conduct cross-site request forgery (CSRF) …

Feb 7, 2024
CVE-2024-20252
9.6 CRITICAL

Multiple vulnerabilities in Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to conduct cross-site request forgery (CSRF) …

Feb 7, 2024
CVE-2024-25145
9.6 CRITICAL

Stored cross-site scripting (XSS) vulnerability in the Portal Search module's Search Result app in Liferay Portal 7.2.0 through 7.4.3.11, and older unsupported versions, and Liferay …

Feb 7, 2024
CVE-2024-24811
9.8 CRITICAL

SQLAlchemyDA is a generic database adapter for ZSQL methods. A vulnerability found in versions prior to 2.2 allows unauthenticated execution of arbitrary SQL statements on …

Feb 7, 2024
CVE-2024-24189
9.8 CRITICAL

Jsish v3.5.0 (commit 42c694c) was discovered to contain a use-after-free via the SplitChar at ./src/jsiUtils.c.

Feb 7, 2024
CVE-2024-24188
9.8 CRITICAL

Jsish v3.5.0 was discovered to contain a heap-buffer-overflow in ./src/jsiUtils.c.

Feb 7, 2024
CVE-2024-24186
9.8 CRITICAL

Jsish v3.5.0 (commit 42c694c) was discovered to contain a stack-overflow via the component IterGetKeysCallback at /jsish/src/jsiValue.c.

Feb 7, 2024
CVE-2024-24133
9.8 CRITICAL

Atmail v6.6.0 was discovered to contain a SQL injection vulnerability via the username parameter on the login page.

Feb 7, 2024
CVE-2024-24303
9.8 CRITICAL

SQL Injection vulnerability in HiPresta "Gift Wrapping Pro" (hiadvancedgiftwrapping) module for PrestaShop before version 1.4.1, allows remote attackers to escalate privileges and obtain sensitive information …

Feb 7, 2024
CVE-2023-46914
9.8 CRITICAL

SQL Injection vulnerability in RM bookingcalendar module for PrestaShop versions 2.7.9 and before, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive …

Feb 7, 2024
CVE-2024-24019
9.8 CRITICAL

A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset, limit, and sort parameters to perform SQL …

Feb 7, 2024
CVE-2024-24004
9.8 CRITICAL

jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseResponseInfo findInOutDetail() function of jshERP does not filter `column` and `order` parameters well enough, and an …

Feb 7, 2024
CVE-2024-24002
9.8 CRITICAL

jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.MaterialController: com.jsh.erp.utils.BaseResponseInfo getListWithStock() function of jshERP does not filter `column` and `order` parameters well enough, and an …

Feb 7, 2024
CVE-2024-24001
9.8 CRITICAL

jshERP v3.3 is vulnerable to SQL Injection. via the com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseResponseInfo findallocationDetail() function of jshERP which allows an attacker to construct malicious payload to bypass …

Feb 7, 2024
CVE-2024-1284
9.8 CRITICAL

Use after free in Mojo in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Feb 7, 2024
CVE-2024-1283
9.8 CRITICAL

Heap buffer overflow in Skia in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Feb 7, 2024
CVE-2024-24015
9.8 CRITICAL

A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset, limit, and sort parameters to perform SQL …

Feb 6, 2024
CVE-2024-24013
9.8 CRITICAL

A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, limit, and sort parameters to perform SQL injection …

Feb 6, 2024
CVE-2024-24000
9.8 CRITICAL

jshERP v3.3 is vulnerable to Arbitrary File Upload. The jshERP-boot/systemConfig/upload interface does not check the uploaded file type, and the biz parameter can be spliced …

Feb 6, 2024
CVE-2024-24594
9.9 CRITICAL

A cross-site scripting (XSS) vulnerability in all versions of the web server component of Allegro AI’s ClearML platform allows a remote attacker to execute a …

Feb 6, 2024
CVE-2024-24593
9.6 CRITICAL

A cross-site request forgery (CSRF) vulnerability in all versions up to 1.14.1 of the api server component of Allegro AI’s ClearML platform allows a remote …

Feb 6, 2024
CVE-2024-24592
9.8 CRITICAL

Lack of authentication in all versions of the fileserver component of Allegro AI’s ClearML platform allows a remote attacker to arbitrarily access, create, modify and …

Feb 6, 2024
CVE-2024-23917
9.8 CRITICAL

In JetBrains TeamCity before 2023.11.3 authentication bypass leading to RCE was possible

Feb 6, 2024
CVE-2024-25140
9.8 CRITICAL

A default installation of RustDesk 1.2.3 on Windows places a WDKTestCert certificate under Trusted Root Certification Authorities with Enhanced Key Usage of Code Signing (1.3.6.1.5.5.7.3.3), …

Feb 6, 2024
CVE-2023-33072
9.3 CRITICAL

Memory corruption in Core while processing control functions.

Feb 6, 2024
CVE-2024-22853
9.8 CRITICAL

D-LINK Go-RT-AC750 GORTAC750_A1_FW_v101b03 has a hardcoded password for the Alphanetworks account, which allows remote attackers to obtain root access via a telnet session.

Feb 6, 2024
CVE-2024-22852
9.8 CRITICAL

D-Link Go-RT-AC750 GORTAC750_A1_FW_v101b03 contains a stack-based buffer overflow via the function genacgi_main. This vulnerability allows attackers to enable telnet service via a specially crafted payload.

Feb 6, 2024
CVE-2024-24112
9.8 CRITICAL

xmall v1.1 was discovered to contain a SQL injection vulnerability via the orderDir parameter.

Feb 6, 2024
CVE-2024-0244
9.8 CRITICAL

Buffer overflow in CPCA PCFAX number process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger …

Feb 6, 2024
CVE-2023-6234
9.8 CRITICAL

Buffer overflow in CPCA Color LUT Resource Download process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment …

Feb 6, 2024
CVE-2023-6233
9.8 CRITICAL

Buffer overflow in SLP attribute request process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger …

Feb 6, 2024
CVE-2023-6232
9.8 CRITICAL

Buffer overflow in the Address Book username process in authentication of Mobile Device Function of Office Multifunction Printers and Laser Printers(*) which may allow an …

Feb 6, 2024
CVE-2023-6231
9.8 CRITICAL

Buffer overflow in WSD probe request process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger …

Feb 6, 2024
CVE-2023-6230
9.8 CRITICAL

Buffer overflow in the Address Book password process in authentication of Mobile Device Function of Office Multifunction Printers and Laser Printers(*) which may allow an …

Feb 6, 2024
CVE-2023-6229
9.8 CRITICAL

Buffer overflow in CPCA PDL Resource Download process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to …

Feb 6, 2024
CVE-2023-46359
9.8 CRITICAL

An OS command injection vulnerability in Hardy Barth cPH2 eCharge Ladestation v1.87.0 and earlier, may allow an unauthenticated remote attacker to execute arbitrary commands on …

Feb 6, 2024
CVE-2024-24398
9.8 CRITICAL

Directory Traversal vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the fileName …

Feb 6, 2024
CVE-2024-23049
9.8 CRITICAL

An issue in symphony v.3.6.3 and before allows a remote attacker to execute arbitrary code via the log4j component.

Feb 5, 2024
CVE-2024-0964
9.4 CRITICAL

A local file include could be remotely triggered in Gradio due to a vulnerable user-supplied JSON value in an API request.

Feb 5, 2024
CVE-2024-0709
9.8 CRITICAL

The Cryptocurrency Widgets – Price Ticker & Coins List plugin for WordPress is vulnerable to SQL Injection via the 'coinslist' parameter in versions 2.0 to …

Feb 5, 2024
CVE-2024-0221
9.1 CRITICAL

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.8.19 …

Feb 5, 2024
CVE-2023-6989
9.8 CRITICAL

The Shield Security – Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, …

Feb 5, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.