CVE Database

40083+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-27936
8.8 HIGH

Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. Starting in version 1.32.1 and prior to version 1.41.0 of the deno library, maliciously …

Mar 21, 2024
CVE-2024-27935
7.2 HIGH

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 1.35.1 and prior to version 1.36.3, a vulnerability in Deno's Node.js compatibility runtime allows …

Mar 21, 2024
CVE-2024-27934
8.4 HIGH

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 1.36.2 and prior to version 1.40.3, use of inherently unsafe `*const c_void` and `ExternalPointer` …

Mar 21, 2024
CVE-2024-27933
8.2 HIGH

Deno is a JavaScript, TypeScript, and WebAssembly runtime. In version 1.39.0, use of raw file descriptors in `op_node_ipc_pipe()` leads to premature close of arbitrary file …

Mar 21, 2024
CVE-2024-27923
8.8 HIGH

Grav is a content management system (CMS). Prior to version 1.7.43, users who may write a page may use the `frontmatter` feature due to insufficient …

Mar 21, 2024
CVE-2024-27918
8.2 HIGH

Coder allows oragnizations to provision remote development environments via Terraform. Prior to versions 2.6.1, 2.7.3, and 2.8.4, a vulnerability in Coder's OIDC authentication could allow …

Mar 21, 2024
CVE-2024-27916
7.1 HIGH

Minder is a software supply chain security platform. Prior to version 0.0.33, a Minder user can use the endpoints `GetRepositoryByName`, `DeleteRepositoryByName`, and `GetArtifactByName` to access …

Mar 21, 2024
CVE-2024-27292
7.5 HIGH

Docassemble is an expert system for guided interviews and document assembly. The vulnerability allows attackers to gain unauthorized access to information on the system through …

Mar 21, 2024
CVE-2024-27105
8.1 HIGH

Frappe is a full-stack web application framework. Prior to versions 14.66.3 and 15.16.0, file permission can be bypassed using certain endpoints, granting less privileged users …

Mar 21, 2024
CVE-2024-24813
7.5 HIGH

Frappe is a full-stack web application framework. Prior to versions 14.64.0 and 15.0.0, SQL injection from a particular whitelisted method can result in access to …

Mar 21, 2024
CVE-2024-24520
7.8 HIGH

An issue in Lepton CMS v.7.0.0 allows a local attacker to execute arbitrary code via the upgrade.php file in the languages place.

Mar 21, 2024
CVE-2023-49982
8.8 HIGH

Broken access control in the component /admin/management/users of School Fees Management System v1.0 allows attackers to escalate privileges and perform Administrative actions, including adding and …

Mar 21, 2024
CVE-2023-49981
7.5 HIGH

A directory listing vulnerability in School Fees Management System v1.0 allows attackers to list directories and sensitive files within the application without requiring authorization.

Mar 21, 2024
CVE-2023-49980
7.5 HIGH

A directory listing vulnerability in Best Student Result Management System v1.0 allows attackers to list directories and sensitive files within the application without requiring authorization.

Mar 21, 2024
CVE-2023-49979
7.5 HIGH

A directory listing vulnerability in Customer Support System v1 allows attackers to list directories and sensitive files within the application without requiring authorization.

Mar 21, 2024
CVE-2023-49978
8.8 HIGH

Incorrect access control in Customer Support System v1 allows non-administrator users to access administrative pages and execute actions reserved for administrators.

Mar 21, 2024
CVE-2023-35899
7.0 HIGH

IBM Cloud Pak for Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 is potentially vulnerable to CSV …

Mar 21, 2024
CVE-2024-28916
8.8 HIGH

Xbox Gaming Services Elevation of Privilege Vulnerability

Mar 21, 2024
CVE-2024-2469
8.0 HIGH

An attacker with an Administrator role in GitHub Enterprise Server could gain SSH root access via remote code execution. This vulnerability affected GitHub Enterprise Server …

Mar 20, 2024
CVE-2024-29026
8.2 HIGH

Owncast is an open source, self-hosted, decentralized, single user live video streaming and chat server. In versions 0.1.2 and prior, a lenient CORS policy allows …

Mar 20, 2024
CVE-2024-29033
7.5 HIGH

OAuthenticator provides plugins for JupyterHub to use common OAuth providers, as well as base classes for writing one's own Authenticators with any OAuth 2.0 provider. …

Mar 20, 2024
CVE-2024-23721
7.5 HIGH

A Directory Traversal issue was discovered in process_post on Draytek Vigor3910 4.3.2.5 devices. When sending a certain POST request, it calls the function and exports …

Mar 20, 2024
CVE-2024-2711
8.8 HIGH

A vulnerability was found in Tenda AC10U 15.03.06.48. It has been rated as critical. Affected by this issue is the function addWifiMacFilter of the file …

Mar 20, 2024
CVE-2024-2710
8.8 HIGH

A vulnerability was found in Tenda AC10U 15.03.06.49. It has been declared as critical. Affected by this vulnerability is the function setSchedWifi of the file …

Mar 20, 2024
CVE-2024-2709
8.8 HIGH

A vulnerability was found in Tenda AC10U 15.03.06.49. It has been classified as critical. Affected is the function fromSetRouteStatic of the file /goform/SetStaticRouteCfg. The manipulation …

Mar 20, 2024
CVE-2024-2708
8.8 HIGH

A vulnerability was found in Tenda AC10U 15.03.06.49 and classified as critical. This issue affects the function formexeCommand of the file /goform/execCommand. The manipulation of …

Mar 20, 2024
CVE-2024-2706
8.8 HIGH

A vulnerability, which was classified as critical, was found in Tenda AC10U 15.03.06.49. This affects the function formWifiWpsStart of the file /goform/WifiWpsStart. The manipulation of …

Mar 20, 2024
CVE-2024-2705
8.8 HIGH

A vulnerability, which was classified as critical, has been found in Tenda AC10U 1.0/15.03.06.49. Affected by this issue is the function formSetQosBand of the file …

Mar 20, 2024
CVE-2024-2627
8.8 HIGH

Use after free in Canvas in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Mar 20, 2024
CVE-2024-2625
8.8 HIGH

Object lifecycle issue in V8 in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. …

Mar 20, 2024
CVE-2024-2704
8.8 HIGH

A vulnerability classified as critical was found in Tenda AC10U 15.03.06.49. Affected by this vulnerability is the function formSetFirewallCfg of the file /goform/SetFirewallCfg. The manipulation …

Mar 20, 2024
CVE-2024-2703
8.8 HIGH

A vulnerability classified as critical has been found in Tenda AC10U 15.03.06.49. Affected is the function formSetDeviceName of the file /goform/SetOnlineDevName. The manipulation of the …

Mar 20, 2024
CVE-2023-50967
7.5 HIGH

latchset jose through version 11 allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.

Mar 20, 2024
CVE-2024-28735
8.1 HIGH

Unit4 Financials by Coda versions prior to 2023Q4 suffer from an incorrect access control authorization bypass vulnerability which allows an authenticated user to modify the …

Mar 20, 2024
CVE-2023-51444
7.2 HIGH

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. An arbitrary file upload vulnerability exists …

Mar 20, 2024
CVE-2023-41877
7.2 HIGH

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. A path traversal vulnerability in versions …

Mar 20, 2024
CVE-2023-41038
7.5 HIGH

Firebird is a relational database. Versions 4.0.0 through 4.0.3 and version 5.0 beta1 are vulnerable to a server crash when a user uses a specific …

Mar 20, 2024
CVE-2024-28396
7.5 HIGH

An issue in MyPrestaModules ordersexport v.6.0.2 and before allows a remote attacker to execute arbitrary code via the download.php component.

Mar 20, 2024
CVE-2024-1856
8.5 HIGH

In Progress® Telerik® Reporting versions prior to 2024 Q1 (18.0.24.130), a code execution attack is possible by a remote threat actor through an insecure deserialization …

Mar 20, 2024
CVE-2024-1801
7.7 HIGH

In Progress® Telerik® Reporting versions prior to 2024 Q1 (18.0.24.130), a code execution attack is possible by a local threat actor through an insecure deserialization …

Mar 20, 2024
CVE-2024-2721
8.2 HIGH

Deserialization of Untrusted Data vulnerability in Social Media Share Buttons By Sygnoos Social Media Share Buttons.This issue affects Social Media Share Buttons: from n/a through …

Mar 20, 2024
CVE-2024-2702
8.2 HIGH

Missing Authorization vulnerability in Olive Themes Olive One Click Demo Import allows importing settings and data, ultimately leading to XSS.This issue affects Olive One Click …

Mar 20, 2024
CVE-2024-2459
7.4 HIGH

The UX Flat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'button' shortcode in all versions up to, and including, 4.4 …

Mar 20, 2024
CVE-2024-1205
8.8 HIGH

The Management App for WooCommerce – Order notifications, Order management, Lead management, Uptime Monitoring plugin for WordPress is vulnerable to arbitrary file uploads due to …

Mar 20, 2024
CVE-2024-28583
7.8 HIGH

Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the readLine() function when reading images in …

Mar 20, 2024
CVE-2024-28582
8.4 HIGH

Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the rgbe_RGBEToFloat() function when reading images in …

Mar 20, 2024
CVE-2024-28581
8.4 HIGH

Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the _assignPixel<>() function when reading images in …

Mar 20, 2024
CVE-2024-28580
8.4 HIGH

Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the ReadData() function when reading images in …

Mar 20, 2024
CVE-2024-28578
8.4 HIGH

Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the Load() function when reading images in …

Mar 20, 2024
CVE-2024-28569
7.8 HIGH

Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the Imf_2_2::Xdr::read() function when reading images in …

Mar 20, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.