CVE Database

40083+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-52482
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: x86/srso: Add SRSO mitigation for Hygon processors Add mitigation for the speculative return stack overflow …

Feb 29, 2024
CVE-2023-52480
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix race condition between session lookup and expire Thread A + Thread B ksmbd_session_lookup …

Feb 29, 2024
CVE-2023-52479
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix uaf in smb20_oplock_break_ack drop reference after use opinfo.

Feb 29, 2024
CVE-2023-52475
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: Input: powermate - fix use-after-free in powermate_config_complete syzbot has found a use-after-free bug [1] in …

Feb 29, 2024
CVE-2023-50905
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Melapress WP Activity Log allows Stored XSS.This issue affects WP Activity Log: from …

Feb 29, 2024
CVE-2023-1841
8.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Honeywell MPA2 Access Panel (Web server modules) allows XSS Using Invalid Characters.This issue …

Feb 29, 2024
CVE-2024-1468
8.8 HIGH

The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in …

Feb 29, 2024
CVE-2024-22871
7.5 HIGH

An issue in Clojure versions 1.20 to 1.12.0-alpha5 allows an attacker to cause a denial of service (DoS) via the clojure.core$partial$fn__5920 function.

Feb 29, 2024
CVE-2024-27284
7.5 HIGH

cassandra-rs is a Cassandra (CQL) driver for Rust. Code that attempts to use an item (e.g., a row) returned by an iterator after the iterator …

Feb 29, 2024
CVE-2024-26470
8.1 HIGH

A host header injection vulnerability in the forgot password function of FullStackHero's WebAPI Boilerplate v1.0.0 and v1.0.1 allows attackers to leak the password reset token …

Feb 29, 2024
CVE-2024-26461
7.5 HIGH

Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.

Feb 29, 2024
CVE-2024-26131
8.4 HIGH

Element Android is an Android Matrix Client. Element Android version 1.4.3 through 1.6.10 is vulnerable to intent redirection, allowing a third-party malicious application to start …

Feb 29, 2024
CVE-2024-25832
8.8 HIGH

F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to upload a file of dangerous type by manipulating …

Feb 29, 2024
CVE-2024-25713
8.6 HIGH

yyjson through 0.8.0 has a double free, leading to remote code execution in some cases, because the pool_free function lacks loop checks. (pool_free is part …

Feb 29, 2024
CVE-2024-25262
8.1 HIGH

texlive-bin commit c515e was discovered to contain heap buffer overflow via the function ttfLoadHDMX:ttfdump. This vulnerability allows attackers to cause a Denial of Service (DoS) …

Feb 29, 2024
CVE-2024-25006
8.1 HIGH

XenForo before 2.2.14 allows Directory Traversal (with write access) by an authenticated user who has permissions to administer styles, and uses a ZIP archive for …

Feb 29, 2024
CVE-2024-23302
7.5 HIGH

Couchbase Server before 7.2.4 has a private key leak in goxdcr.log.

Feb 29, 2024
CVE-2024-22939
8.8 HIGH

Cross Site Request Forgery vulnerability in FlyCms v.1.0 allows a remote attacker to execute arbitrary code via the system/article/category_edit component.

Feb 29, 2024
CVE-2024-20321
8.6 HIGH

A vulnerability in the External Border Gateway Protocol (eBGP) implementation of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of …

Feb 29, 2024
CVE-2024-20267
8.6 HIGH

A vulnerability with the handling of MPLS traffic for Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause the netstack process to unexpectedly …

Feb 29, 2024
CVE-2024-1971
7.3 HIGH

A vulnerability has been found in Surya2Developer Online Shopping System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Feb 29, 2024
CVE-2024-1939
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Feb 29, 2024
CVE-2024-1938
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium …

Feb 29, 2024
CVE-2024-1470
7.1 HIGH

Authorization Bypass Through User-Controlled Key vulnerability in NetIQ (OpenText) Client Login Extension on Windows allows Privilege Escalation, Code Injection.This issue only affects NetIQ Client Login …

Feb 29, 2024
CVE-2024-1317
8.8 HIGH

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to SQL Injection via …

Feb 29, 2024
CVE-2024-1217
7.6 HIGH

The Contact Form builder with drag & drop for WordPress – Kali Forms plugin for WordPress is vulnerable to unauthorized plugin deactivation due to a …

Feb 29, 2024
CVE-2024-1206
8.8 HIGH

The WP Recipe Maker plugin for WordPress is vulnerable to SQL Injection via the 'recipes' parameter in all versions up to, and including, 9.1.2 due …

Feb 29, 2024
CVE-2024-0702
7.3 HIGH

The Oliver POS – A WooCommerce Point of Sale (POS) plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on several …

Feb 29, 2024
CVE-2023-7110
7.3 HIGH

A vulnerability, which was classified as critical, has been found in code-projects Library Management System 2.0. This issue affects some unknown processing of the file …

Feb 29, 2024
CVE-2023-7109
7.3 HIGH

A vulnerability classified as critical was found in code-projects Library Management System 2.0. This vulnerability affects unknown code of the file /admin/login.php. The manipulation of …

Feb 29, 2024
CVE-2023-7107
7.3 HIGH

A vulnerability was found in code-projects E-Commerce Website 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the …

Feb 29, 2024
CVE-2023-6881
7.3 HIGH

Possible buffer overflow in is_mount_point

Feb 29, 2024
CVE-2023-51779
7.0 HIGH

bt_sock_recvmsg in net/bluetooth/af_bluetooth.c in the Linux kernel through 6.6.8 has a use-after-free because of a bt_sock_ioctl race condition.

Feb 29, 2024
CVE-2023-51774
8.4 HIGH

The json-jwt (aka JSON::JWT) gem 1.16.3 for Ruby sometimes allows bypass of identity checks via a sign/encryption confusion attack. For example, JWE can sometimes be …

Feb 29, 2024
CVE-2023-50658
7.5 HIGH

The jose2go component before 1.6.0 for Go allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.

Feb 29, 2024
CVE-2023-50437
8.6 HIGH

An issue was discovered in Couchbase Server before 7.2.x before 7.2.4. otpCookie is shown with full admin on pools/default/serverGroups and engageCluster2.

Feb 29, 2024
CVE-2023-34198
7.3 HIGH

In Stormshield Network Security (SNS) 1.0.0 through 3.7.36 before 3.7.37, 3.8.0 through 3.11.24 before 3.11.25, 4.0.0 through 4.3.18 before 4.3.19, 4.4.0 through 4.6.5 before 4.6.6, …

Feb 29, 2024
CVE-2023-25921
8.5 HIGH

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 allows the attacker to upload or transfer files of dangerous types that can …

Feb 29, 2024
CVE-2022-34269
8.8 HIGH

An issue was discovered in RWS WorldServer before 11.7.3. An authenticated, remote attacker can perform a ws-legacy/load_dtd?system_id= blind SSRF attack to deploy JSP code to …

Feb 29, 2024
CVE-2024-23910
8.8 HIGH

Cross-site request forgery (CSRF) vulnerability in ELECOM wireless LAN routers and wireless LAN repeater allows a remote unauthenticated attacker to hijack the authentication of administrators …

Feb 28, 2024
CVE-2024-25869
8.8 HIGH

An Unrestricted File Upload vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary code via upload of a …

Feb 28, 2024
CVE-2024-25866
8.8 HIGH

A SQL Injection vulnerability in CodeAstro Membership Management System in PHP v.1.0 allows a remote attacker to execute arbitrary SQL commands via the email parameter …

Feb 28, 2024
CVE-2024-22983
8.1 HIGH

SQL injection vulnerability in Projectworlds Visitor Management System in PHP v.1.0 allows a remote attacker to escalate privileges via the name parameter in the myform.php …

Feb 28, 2024
CVE-2023-49338
7.5 HIGH

Couchbase Server 7.1.x and 7.2.x before 7.2.4 does not require authentication for the /admin/stats and /admin/vitals endpoints on TCP port 8093 of localhost.

Feb 28, 2024
CVE-2023-45859
7.6 HIGH

In Hazelcast through 4.1.10, 4.2 through 4.2.8, 5.0 through 5.0.5, 5.1 through 5.1.7, 5.2 through 5.2.4, and 5.3 through 5.3.2, some client operations don't check …

Feb 28, 2024
CVE-2023-25925
8.5 HIGH

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow a remote authenticated attacker to execute arbitrary commands on the system …

Feb 28, 2024
CVE-2024-25859
7.1 HIGH

A path traversal vulnerability in the /path/to/uploads/ directory of Blesta before v5.9.2 allows attackers to takeover user accounts and execute arbitrary code.

Feb 28, 2024
CVE-2024-24148
7.5 HIGH

A memory leak issue discovered in parseSWF_FREECHARACTER in libming v0.4.8 allows attackers to cause a denial of service via a crafted SWF file.

Feb 28, 2024
CVE-2023-52047
8.8 HIGH

Dedecms v5.7.112 was discovered to contain a Cross-Site Request Forgery (CSRF) in the file manager.

Feb 28, 2024
CVE-2024-26342
7.5 HIGH

A Null pointer dereference in usr/sbin/httpd in ASUS AC68U 3.0.0.4.384.82230 allows remote attackers to trigger DoS via network packet.

Feb 28, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.