CVE Database

40083+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-52626
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix operation precedence bug in port timestamping napi_poll context Indirection (*) is of lower …

Mar 26, 2024
CVE-2023-52624
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Wake DMCUB before executing GPINT commands [Why] DMCUB can be in idle when we …

Mar 26, 2024
CVE-2023-52621
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: bpf: Check rcu_read_lock_trace_held() before calling bpf map helpers These three bpf_map_{lookup,update,delete}_elem() helpers are also available …

Mar 26, 2024
CVE-2023-44989
7.5 HIGH

Insertion of Sensitive Information into Log File vulnerability in GSheetConnector CF7 Google Sheets Connector.This issue affects CF7 Google Sheets Connector: from n/a through 5.0.5.

Mar 26, 2024
CVE-2024-2894
8.8 HIGH

A vulnerability was found in Tenda AC7 15.03.06.44. It has been classified as critical. This affects the function formSetQosBand of the file /goform/SetNetControlList. The manipulation …

Mar 26, 2024
CVE-2024-2893
8.8 HIGH

A vulnerability was found in Tenda AC7 15.03.06.44 and classified as critical. Affected by this issue is the function formSetDeviceName of the file /goform/SetOnlineDevName. The …

Mar 26, 2024
CVE-2024-2929
7.8 HIGH

A memory corruption vulnerability in Rockwell Automation Arena Simulation software could potentially allow a malicious user to insert unauthorized code to the software by corrupting …

Mar 26, 2024
CVE-2024-2915
8.8 HIGH

Improper access control in PAM JIT elevation in Devolutions Server 2024.1.6 and earlier allows an attacker with access to the PAM JIT elevation feature to …

Mar 26, 2024
CVE-2024-2892
8.8 HIGH

A vulnerability has been found in Tenda AC7 15.03.06.44 and classified as critical. Affected by this vulnerability is the function formSetCfm of the file /goform/setcfm. …

Mar 26, 2024
CVE-2024-2452
7.0 HIGH

In Eclipse ThreadX NetX Duo before 6.4.0, if an attacker can control parameters of __portable_aligned_alloc() could cause an integer wrap-around and an allocation smaller than …

Mar 26, 2024
CVE-2024-2214
7.0 HIGH

In Eclipse ThreadX before version 6.4.0, the _Mtxinit() function in the Xtensa port was missing an array size check causing a memory overwrite. The affected …

Mar 26, 2024
CVE-2024-2212
7.3 HIGH

In Eclipse ThreadX before 6.4.0, xQueueCreate() and xQueueCreateSet() functions from the FreeRTOS compatibility API (utility/rtos_compatibility_layers/FreeRTOS/tx_freertos.c) were missing parameter checks. This could lead to integer wraparound, …

Mar 26, 2024
CVE-2024-21919
7.8 HIGH

An uninitialized pointer in Rockwell Automation Arena Simulation software could potentially allow a malicious user to insert unauthorized code to the software by leveraging the …

Mar 26, 2024
CVE-2024-21918
7.8 HIGH

A memory buffer vulnerability in Rockwell Automation Arena Simulation software could potentially allow a malicious user to insert unauthorized code to the software by corrupting …

Mar 26, 2024
CVE-2024-21913
7.8 HIGH

A heap-based memory buffer overflow vulnerability in Rockwell Automation Arena Simulation software could potentially allow a malicious user to insert unauthorized code into the software …

Mar 26, 2024
CVE-2024-21912
7.8 HIGH

An arbitrary code execution vulnerability in Rockwell Automation Arena Simulation could let a malicious user insert unauthorized code into the software. This is done by …

Mar 26, 2024
CVE-2024-23722
7.5 HIGH

In Fluent Bit 2.1.8 through 2.2.1, a NULL pointer dereference can be caused via an invalid HTTP payload with the content type of x-www-form-urlencoded. It …

Mar 26, 2024
CVE-2024-23482
7.0 HIGH

The ZScaler service is susceptible to a local privilege escalation vulnerability found in the ZScalerService process. Fixed Version: Mac ZApp 4.2.0.241 and later.

Mar 26, 2024
CVE-2023-50895
7.2 HIGH

In Janitza GridVis through 9.0.66, exposed dangerous methods in the de.janitza.pasw.project.server.ServerDatabaseProject project load functionality allow remote authenticated administrative users to execute arbitrary Groovy code.

Mar 26, 2024
CVE-2023-50894
8.8 HIGH

In Janitza GridVis through 9.0.66, use of hard-coded credentials in the de.janitza.pasw.feature.impl.activators.PasswordEncryption password encryption function allows remote authenticated administrative users to discover cleartext database credentials …

Mar 26, 2024
CVE-2023-41973
7.3 HIGH

ZSATray passes the previousInstallerName as a config parameter to TrayManager, and TrayManager constructs the path and appends previousInstallerName to get the full path of the …

Mar 26, 2024
CVE-2023-41972
7.3 HIGH

In some rare cases, there is a password type validation missing in Revert Password check and for some features it could be disabled. Fixed Version: …

Mar 26, 2024
CVE-2023-41969
7.3 HIGH

An arbitrary file deletion in ZSATrayManager where it protects the temporary encrypted ZApp issue reporting file from the unprivileged end user access and modification. Fixed …

Mar 26, 2024
CVE-2024-2891
8.8 HIGH

A vulnerability, which was classified as critical, was found in Tenda AC7 15.03.06.44. Affected is the function formQuickIndex of the file /goform/QuickIndex. The manipulation of …

Mar 26, 2024
CVE-2023-47150
7.5 HIGH

IBM Common Cryptographic Architecture (CCA) 7.0.0 through 7.5.36 could allow a remote user to cause a denial of service due to incorrect data handling for …

Mar 26, 2024
CVE-2024-1933
7.1 HIGH

Insecure UNIX Symbolic Link (Symlink) Following in TeamViewer Remote Client prior Version 15.52 for macOS allows an attacker with unprivileged access, to potentially elevate privileges …

Mar 26, 2024
CVE-2024-28093
8.8 HIGH

The TELNET service of AdTran NetVanta 3120 18.01.01.00.E devices is enabled by default, and has default credentials for a root-level account.

Mar 26, 2024
CVE-2024-28131
7.8 HIGH

EasyRange Ver 1.41 contains an issue with the executable file search path when displaying an extracted file on Explorer, which may lead to loading an …

Mar 26, 2024
CVE-2024-28033
7.3 HIGH

OS command injection vulnerability exists in WebProxy 1.7.8 and 1.7.9, which may allow a remote unauthenticated attacker to execute an arbitrary OS command with the …

Mar 26, 2024
CVE-2023-45771
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Contact Form With Captcha allows Reflected XSS.This issue affects Contact Form With Captcha: …

Mar 26, 2024
CVE-2023-33322
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Etoile Web Design Front End Users allows Reflected XSS.This issue affects Front End …

Mar 26, 2024
CVE-2023-23991
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPdevelop / Oplugins Booking Calendar allows SQL Injection.This issue affects Booking …

Mar 26, 2024
CVE-2023-6175
7.8 HIGH

NetScreen file parser crash in Wireshark 4.0.0 to 4.0.10 and 3.6.0 to 3.6.18 allows denial of service via crafted capture file

Mar 26, 2024
CVE-2023-49839
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KlbTheme Cosmetsy theme (core plugin), KlbTheme Partdo theme (core plugin), KlbTheme Bacola theme …

Mar 26, 2024
CVE-2024-29189
7.4 HIGH

PyAnsys Geometry is a Python client library for the Ansys Geometry service and other CAD Ansys products. On file src/ansys/geometry/core/connection/product_instance.py, upon calling this method _start_program …

Mar 26, 2024
CVE-2024-0866
8.1 HIGH

The Check & Log Email plugin for WordPress is vulnerable to Unauthenticated Hook Injection in all versions up to, and including, 1.0.9 via the check_nonce …

Mar 26, 2024
CVE-2024-29302
7.5 HIGH

SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection via update-employee.php.

Mar 26, 2024
CVE-2024-29301
7.5 HIGH

SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection via update-admin.php?admin_id=

Mar 26, 2024
CVE-2024-0901
7.5 HIGH

Remotely executed SEGV and out of bounds read allows malicious packet sender to crash or cause an out of bounds read via sending a malformed …

Mar 25, 2024
CVE-2024-1973
8.5 HIGH

By leveraging the vulnerability, lower-privileged users of Content Manager can manipulate Content Manager clients to elevate privileges and perform unauthorized operations.

Mar 25, 2024
CVE-2023-47430
7.5 HIGH

Stack-buffer-overflow vulnerability in ReadyMedia (MiniDLNA) v1.3.3 allows attackers to cause a denial of service via via the SendContainer() function at tivo_commands.c.

Mar 25, 2024
CVE-2024-2427
7.5 HIGH

A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper traffic throttling in the device. If multiple data packets are sent to …

Mar 25, 2024
CVE-2024-2426
7.5 HIGH

A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper input validation in the device. If exploited, a disruption in the CIP …

Mar 25, 2024
CVE-2024-2425
7.5 HIGH

A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper input validation in the device. If exploited, the web server will crash …

Mar 25, 2024
CVE-2024-29515
8.8 HIGH

File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP file to the save.php and …

Mar 25, 2024
CVE-2024-28850
8.1 HIGH

WP Crontrol controls the cron events on WordPress websites. WP Crontrol includes a feature that allows administrative users to create events in the WP-Cron system …

Mar 25, 2024
CVE-2024-28107
8.8 HIGH

phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. A SQL injection vulnerability has been discovered in …

Mar 25, 2024
CVE-2024-28105
7.2 HIGH

phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. The category image upload function in phpmyfaq is …

Mar 25, 2024
CVE-2024-27299
8.8 HIGH

phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. A SQL injection vulnerability has been discovered in …

Mar 25, 2024
CVE-2024-30205
7.1 HIGH

In Emacs before 29.3, Org mode considers contents of remote files to be trusted. This affects Org Mode before 9.6.23.

Mar 25, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.