CVE Database

40083+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-25612
7.2 HIGH

Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as …

Mar 5, 2024
CVE-2024-25611
7.2 HIGH

Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as …

Mar 5, 2024
CVE-2024-1356
7.2 HIGH

Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as …

Mar 5, 2024
CVE-2024-23296
7.8 HIGH KEV

A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.4 and iPadOS 17.4, macOS …

Mar 5, 2024
CVE-2024-23225
7.8 HIGH KEV

A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS …

Mar 5, 2024
CVE-2024-22255
7.1 HIGH

VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malicious actor with administrative access to a virtual machine …

Mar 5, 2024
CVE-2024-22254
7.9 HIGH

VMware ESXi contains an out-of-bounds write vulnerability. A malicious actor with privileges within the VMX process may trigger an out-of-bounds write leading to an escape …

Mar 5, 2024
CVE-2024-27929
7.1 HIGH

ImageSharp is a managed, cross-platform, 2D graphics library. A heap-use-after-free flaw was found in ImageSharp's InitializeImage() function of PngDecoderCore.cs file. This vulnerability is triggered when …

Mar 5, 2024
CVE-2024-27561
8.1 HIGH

A Server-Side Request Forgery (SSRF) in the installUpdateThemePluginAction function of WonderCMS v3.1.3 allows attackers to force the application to make arbitrary requests via injection of …

Mar 5, 2024
CVE-2024-24098
7.8 HIGH

Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection via the News Feed.

Mar 5, 2024
CVE-2024-27622
7.2 HIGH

A remote code execution vulnerability has been identified in the User Defined Tags module of CMS Made Simple version 2.2.19 / 2.2.21. This vulnerability arises …

Mar 5, 2024
CVE-2023-5457
7.5 HIGH

A CWE-1269 “Product Released in Non-Release Configuration” vulnerability in the Django web framework used by the web application (due to the “debug” configuration parameter set …

Mar 5, 2024
CVE-2023-45591
7.5 HIGH

A CWE-122 “Heap-based Buffer Overflow” vulnerability in the “logger_generic” function of the “Ax_rtu” binary allows a remote authenticated attacker to trigger a memory corruption in …

Mar 5, 2024
CVE-2023-5456
8.1 HIGH

A CWE-798 “Use of Hard-coded Credentials” vulnerability in the MariaDB database of the web application allows a remote unauthenticated attacker to access the database service …

Mar 5, 2024
CVE-2024-22188
7.2 HIGH

TYPO3 before 13.0.1 allows an authenticated admin user (with system maintainer privileges) to execute arbitrary shell commands (with the privileges of the web server) via …

Mar 5, 2024
CVE-2024-1731
8.8 HIGH

The Auto Refresh Single Page plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1 via deserialization of …

Mar 5, 2024
CVE-2024-0825
8.8 HIGH

The Vimeography: Vimeo Video Gallery WordPress Plugin plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.3.2 via …

Mar 5, 2024
CVE-2024-25269
7.5 HIGH

libheif <= 1.17.6 contains a memory leak in the function JpegEncoder::Encode. This flaw allows an attacker to cause a denial of service attack.

Mar 5, 2024
CVE-2024-27718
7.8 HIGH

SQL Injection vulnerability in Baizhuo Network Smart s200 Management Platform v.S200 allows a local attacker to obtain sensitive information and escalate privileges via the /importexport.php …

Mar 5, 2024
CVE-2024-25731
7.5 HIGH

The Elink Smart eSmartCam (com.cn.dq.ipc) application 2.1.5 for Android contains hardcoded AES encryption keys that can be extracted from a binary file. Thus, encryption can …

Mar 5, 2024
CVE-2024-25164
7.5 HIGH

iA Path Traversal vulnerability exists in iDURAR v2.0.0, that allows unauthenticated attackers to expose sensitive files via the download functionality.

Mar 5, 2024
CVE-2023-49968
7.3 HIGH

Customer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at /customer_support/manage_department.php.

Mar 5, 2024
CVE-2023-49548
8.8 HIGH

Customer Support System v1 was discovered to contain a SQL injection vulnerability via the lastname parameter at /customer_support/ajax.php?action=save_user.

Mar 5, 2024
CVE-2023-49546
8.8 HIGH

Customer Support System v1 was discovered to contain a SQL injection vulnerability via the email parameter at /customer_support/ajax.php.

Mar 5, 2024
CVE-2024-1936
7.5 HIGH

The encrypted subject of an email message could be incorrectly and permanently assigned to an arbitrary other email message in Thunderbird's local cache. Consequently, when …

Mar 4, 2024
CVE-2024-2048
8.1 HIGH

Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certificate as trusted certificate. In …

Mar 4, 2024
CVE-2024-27889
8.8 HIGH

Multiple SQL Injection vulnerabilities exist in the reporting application of the Arista Edge Threat Management - Arista NG Firewall (NGFW). A user with advanced report …

Mar 4, 2024
CVE-2023-32331
7.5 HIGH

IBM Connect:Express for UNIX 1.5.0 is vulnerable to a buffer overflow that could allow a remote attacker to cause a denial of service through its …

Mar 4, 2024
CVE-2021-47107
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix READDIR buffer overflow If a client sends a READDIR count argument that is …

Mar 4, 2024
CVE-2021-47106
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix use-after-free in nft_set_catchall_destroy() We need to use list_for_each_entry_safe() iterator because we can …

Mar 4, 2024
CVE-2024-27199
7.3 HIGH KEV

In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible

Mar 4, 2024
CVE-2021-47103
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: inet: fully convert sk->sk_rx_dst to RCU rules syzbot reported various issues around early demux, one …

Mar 4, 2024
CVE-2021-47102
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: marvell: prestera: fix incorrect structure access In line: upper = info->upper_dev; We access upper_dev …

Mar 4, 2024
CVE-2021-47101
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: asix: fix uninit-value in asix_mdio_read() asix_read_cmd() may read less than sizeof(smsr) bytes and in this …

Mar 4, 2024
CVE-2021-47098
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: hwmon: (lm90) Prevent integer overflow/underflow in hysteresis calculations Commit b50aa49638c7 ("hwmon: (lm90) Prevent integer underflows …

Mar 4, 2024
CVE-2021-47097
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: Input: elantech - fix stack out of bound access in elantech_change_report_id() The array param[] in …

Mar 4, 2024
CVE-2021-47094
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Don't advance iterator after restart due to yielding After dropping mmu_lock in the …

Mar 4, 2024
CVE-2021-47088
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: mm/damon/dbgfs: protect targets destructions with kdamond_lock DAMON debugfs interface iterates current monitoring targets in 'dbgfs_target_ids_read()' …

Mar 4, 2024
CVE-2021-47087
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: tee: optee: Fix incorrect page free bug Pointer to the allocated pages (struct page *page) …

Mar 4, 2024
CVE-2021-47083
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: pinctrl: mediatek: fix global-out-of-bounds issue When eint virtual eint number is greater than gpio number, …

Mar 4, 2024
CVE-2021-47082
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: tun: avoid double free in tun_free_netdev Avoid double free in tun_free_netdev() by moving the dev->tstats …

Mar 4, 2024
CVE-2024-27694
7.4 HIGH

FlyCms v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the /system/share/ztree_category_edit.

Mar 4, 2024
CVE-2024-22463
7.4 HIGH

Dell PowerScale OneFS 8.2.x through 9.6.0.x contains a use of a broken or risky cryptographic algorithm vulnerability. A remote unprivileged attacker could potentially exploit this …

Mar 4, 2024
CVE-2024-22452
7.3 HIGH

Dell Display and Peripheral Manager for macOS prior to 1.3 contains an improper access control vulnerability. A low privilege user could potentially exploit this vulnerability …

Mar 4, 2024
CVE-2024-0156
7.0 HIGH

Dell Digital Delivery, versions prior to 5.2.0.0, contain a Buffer Overflow Vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to arbitrary …

Mar 4, 2024
CVE-2024-0155
7.0 HIGH

Dell Digital Delivery, versions prior to 5.2.0.0, contain a Use After Free Vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to …

Mar 4, 2024
CVE-2023-6241
7.0 HIGH

Use After Free vulnerability in Arm Ltd Midgard GPU Kernel Driver, Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd …

Mar 4, 2024
CVE-2023-43550
7.8 HIGH

Memory corruption while processing a QMI request for allocating memory from a DHMS supported subsystem.

Mar 4, 2024
CVE-2023-43549
8.4 HIGH

Memory corruption while processing TPC target power table in FTM TPC.

Mar 4, 2024
CVE-2023-43548
7.3 HIGH

Memory corruption while parsing qcp clip with invalid chunk data size.

Mar 4, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.