CVE Database

40083+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-0817
7.8 HIGH

Command injection in IrGraph.draw in paddlepaddle/paddle 2.6.0

Mar 7, 2024
CVE-2024-26566
8.2 HIGH

An issue in Cute Http File Server v.3.1 allows a remote attacker to escalate privileges via the password verification component.

Mar 7, 2024
CVE-2024-24375
7.5 HIGH

SQL injection vulnerability in Jfinalcms v.5.0.0 allows a remote attacker to obtain sensitive information via /admin/admin name parameter.

Mar 7, 2024
CVE-2024-0199
7.7 HIGH

An authorization bypass vulnerability was discovered in GitLab affecting versions 11.3 prior to 16.7.7, 16.7.6 prior to 16.8.4, and 16.8.3 prior to 16.9.2. An attacker …

Mar 7, 2024
CVE-2023-49988
7.5 HIGH

Hotel Booking Management v1.0 was discovered to contain a SQL injection vulnerability via the npss parameter at rooms.php.

Mar 7, 2024
CVE-2023-47415
7.5 HIGH

Cypress Solutions CTM-200 v2.7.1.5600 and below was discovered to contain an OS command injection vulnerability via the cli_text parameter.

Mar 7, 2024
CVE-2024-28110
7.5 HIGH

Go SDK for CloudEvents is the official CloudEvents SDK to integrate applications with CloudEvents. Prior to version 2.15.2, using cloudevents.WithRoundTripper to create a cloudevents.Client with …

Mar 6, 2024
CVE-2024-27917
7.5 HIGH

Shopware is an open commerce platform based on Symfony Framework and Vue. The Symfony Session Handler pops the Session Cookie and assigns it to the …

Mar 6, 2024
CVE-2024-27308
7.5 HIGH

Mio is a Metal I/O library for Rust. When using named pipes on Windows, mio will under some circumstances return invalid tokens that correspond to …

Mar 6, 2024
CVE-2023-48703
7.5 HIGH

RobotsAndPencils go-saml, a SAML client library written in Go, contains an authentication bypass vulnerability in all known versions. This is due to how the `xmlsec1` …

Mar 6, 2024
CVE-2024-2176
8.8 HIGH

Use after free in FedCM in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Mar 6, 2024
CVE-2024-2174
8.8 HIGH

Inappropriate implementation in V8 in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Mar 6, 2024
CVE-2024-2173
8.8 HIGH

Out of bounds memory access in V8 in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to perform out of bounds memory access via …

Mar 6, 2024
CVE-2024-27303
7.3 HIGH

electron-builder is a solution to package and build a ready for distribution Electron, Proton Native app for macOS, Windows and Linux. A vulnerability that only …

Mar 6, 2024
CVE-2024-27289
8.1 HIGH

pgx is a PostgreSQL driver and toolkit for Go. Prior to version 4.18.2, SQL injection can occur when all of the following conditions are met: …

Mar 6, 2024
CVE-2024-25111
8.6 HIGH

Squid is a web proxy cache. Starting in version 3.5.27 and prior to version 6.8, Squid may be vulnerable to a Denial of Service attack …

Mar 6, 2024
CVE-2024-24765
7.5 HIGH

CasaOS-UserService provides user management functionalities to CasaOS. Prior to version 0.4.7, path filtering of the URL for user avatar image files was not strict, making …

Mar 6, 2024
CVE-2024-24761
7.5 HIGH

Galette is a membership management web application for non profit organizations. Starting in version 1.0.0 and prior to version 1.0.2, public pages are per default …

Mar 6, 2024
CVE-2024-2216
8.8 HIGH

A missing permission check in an HTTP endpoint in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified …

Mar 6, 2024
CVE-2024-28160
8.8 HIGH

Jenkins iceScrum Plugin 1.1.6 and earlier does not sanitize iceScrum project URLs on build views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by …

Mar 6, 2024
CVE-2024-28157
8.0 HIGH

Jenkins GitBucket Plugin 0.8 and earlier does not sanitize Gitbucket URLs on build views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers …

Mar 6, 2024
CVE-2024-20338
7.3 HIGH

A vulnerability in the ISE Posture (System Scan) module of Cisco Secure Client for Linux could allow an authenticated, local attacker to elevate privileges on …

Mar 6, 2024
CVE-2024-20337
8.2 HIGH

A vulnerability in the SAML authentication process of Cisco Secure Client could allow an unauthenticated, remote attacker to conduct a carriage return line feed (CRLF) …

Mar 6, 2024
CVE-2024-25102
7.8 HIGH

This vulnerability exists in AppSamvid software due to the usage of a weaker cryptographic algorithm (hash) SHA1 in user login component. An attacker with local …

Mar 6, 2024
CVE-2024-1224
7.1 HIGH

This vulnerability exists in USB Pratirodh due to the usage of a weaker cryptographic algorithm (hash) SHA1 in user login component. A local attacker with …

Mar 6, 2024
CVE-2024-26625
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: llc: call sock_orphan() at release time syzbot reported an interesting trace [1] caused by a …

Mar 6, 2024
CVE-2023-52604
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: FS:JFS:UBSAN:array-index-out-of-bounds in dbAdjTree Syzkaller reported the following issue: UBSAN: array-index-out-of-bounds in fs/jfs/jfs_dmap.c:2867:6 index 196694 is …

Mar 6, 2024
CVE-2023-52603
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: UBSAN: array-index-out-of-bounds in dtSplitRoot Syzkaller reported the following issue: oop0: detected capacity change from 0 …

Mar 6, 2024
CVE-2023-52602
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: jfs: fix slab-out-of-bounds Read in dtSearch Currently while searching for current page in the sorted …

Mar 6, 2024
CVE-2023-52601
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: jfs: fix array-index-out-of-bounds in dbAdjTree Currently there is a bound check missing in the dbAdjTree …

Mar 6, 2024
CVE-2023-52600
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: jfs: fix uaf in jfs_evict_inode When the execution of diMount(ipimap) fails, the object ipimap that …

Mar 6, 2024
CVE-2023-52599
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: jfs: fix array-index-out-of-bounds in diNewExt [Syz report] UBSAN: array-index-out-of-bounds in fs/jfs/jfs_imap.c:2360:2 index -878706688 is out …

Mar 6, 2024
CVE-2023-52598
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: s390/ptrace: handle setting of fpc register correctly If the content of the floating point control …

Mar 6, 2024
CVE-2023-52594
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: Fix potential array-index-out-of-bounds read in ath9k_htc_txstatus() Fix an array-index-out-of-bounds read in ath9k_htc_txstatus(). The …

Mar 6, 2024
CVE-2023-52591
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: reiserfs: Avoid touching renamed directory if parent does not change The VFS will not be …

Mar 6, 2024
CVE-2023-52588
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to tag gcing flag on page during block migration It needs to add …

Mar 6, 2024
CVE-2023-52586
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/msm/dpu: Add mutex lock in control vblank irq Add a mutex lock to control vblank …

Mar 6, 2024
CVE-2024-1220
8.2 HIGH

A stack-based buffer overflow in the built-in web server in Moxa NPort W2150A/W2250A Series firmware version 2.3 and prior allows a remote attacker to exploit …

Mar 6, 2024
CVE-2023-33677
7.5 HIGH

Sourcecodester Lost and Found Information System's Version 1.0 is vulnerable to unauthenticated SQL Injection at "?page=items/view&id=*".

Mar 6, 2024
CVE-2024-25817
7.8 HIGH

Buffer Overflow vulnerability in eza before version 0.18.2, allows local attackers to execute arbitrary code via the .git/HEAD, .git/refs, and .git/objects components.

Mar 6, 2024
CVE-2024-22889
7.5 HIGH

Due to incorrect access control in Plone version v6.0.9, remote attackers can view and list all files hosted on the website via sending a crafted …

Mar 6, 2024
CVE-2023-43318
8.8 HIGH

TP-Link JetStream Smart Switch TL-SG2210P 5.0 Build 20211201 allows attackers to escalate privileges via modification of the 'tid' and 'usrlvl' values in GET requests.

Mar 6, 2024
CVE-2023-38946
8.8 HIGH

An issue in Multilaser RE160 firmware v5.07.51_pt_MTL01 and v5.07.52_pt_MTL01 allows attackers to bypass the access control and gain complete access to the application via supplying …

Mar 6, 2024
CVE-2024-27765
7.5 HIGH

Directory Traversal vulnerability in Jeewms v.3.7 and before allows a remote attacker to obtain sensitive information via the cgformTemplateController component.

Mar 5, 2024
CVE-2024-24786
7.5 HIGH

The protojson.Unmarshal function can enter an infinite loop when unmarshaling certain forms of invalid JSON. This condition can occur when unmarshaling into a message which …

Mar 5, 2024
CVE-2024-24784
7.5 HIGH

The ParseAddressList function incorrectly handles comments (text within parentheses) within display names. Since this is a misalignment with conforming address parsers, it can result in …

Mar 5, 2024
CVE-2024-24278
7.5 HIGH

An issue in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive information via a crafted payload to the message …

Mar 5, 2024
CVE-2024-1764
7.6 HIGH

Improper privilege management in Just-in-time (JIT) elevation module in Devolutions Server 2023.3.14.0 and earlier allows a user to continue using the elevated privilege even after …

Mar 5, 2024
CVE-2024-25858
8.4 HIGH

In Foxit PDF Reader before 2024.1 and PDF Editor before 2024.1, code execution via JavaScript could occur because of an unoptimized prompt message for users …

Mar 5, 2024
CVE-2024-25613
7.2 HIGH

Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as …

Mar 5, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.