CVE Database

40083+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-1622
7.5 HIGH

Due to a mistake in error checking, Routinator will terminate when an incoming RTR connection is reset by the peer too quickly after opening.

Feb 26, 2024
CVE-2024-0455
7.5 HIGH

The inclusion of the web scraper for AnythingLLM means that any user with the proper authorization level (manager, admin, and when in single user) could …

Feb 26, 2024
CVE-2024-0439
8.8 HIGH

As a manager, you should not be able to modify a series of settings. In the UI this is indeed hidden as a convenience for …

Feb 26, 2024
CVE-2024-0243
8.1 HIGH

With the following crawler configuration: ```python from bs4 import BeautifulSoup as Soup url = "https://example.com" loader = RecursiveUrlLoader( url=url, max_depth=2, extractor=lambda x: Soup(x, "html.parser").text ) …

Feb 26, 2024
CVE-2023-52469
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drivers/amd/pm: fix a use-after-free in kv_parse_power_table When ps allocated by kzalloc equals to NULL, kv_parse_power_table …

Feb 26, 2024
CVE-2023-52468
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: class: fix use-after-free in class_register() The lock_class_key is still registered and can be found in …

Feb 26, 2024
CVE-2023-49960
7.5 HIGH

In Indo-Sol PROFINET-INspektor NT through 2.4.0, a path traversal vulnerability in the httpuploadd service of the firmware allows remote attackers to write to arbitrary files …

Feb 26, 2024
CVE-2022-48626
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: moxart: fix potential use-after-free on remove path It was reported that the mmc host structure …

Feb 26, 2024
CVE-2024-21502
7.5 HIGH

Versions of the package fastecdsa before 2.3.2 are vulnerable to Use of Uninitialized Variable on the stack, via the curvemath_mul function in src/curveMath.c, due to …

Feb 24, 2024
CVE-2024-26192
8.2 HIGH

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

Feb 23, 2024
CVE-2024-25469
7.5 HIGH

SQL Injection vulnerability in CRMEB crmeb_java v.1.3.4 and before allows a remote attacker to obtain sensitive information via the latitude and longitude parameters in the …

Feb 23, 2024
CVE-2024-27133
7.5 HIGH

Insufficient sanitization in MLflow leads to XSS when running a recipe that uses an untrusted dataset. This issue leads to a client-side RCE when running …

Feb 23, 2024
CVE-2024-27132
7.5 HIGH

Insufficient sanitization in MLflow leads to XSS when running an untrusted recipe. This issue leads to a client-side RCE when running an untrusted recipe in …

Feb 23, 2024
CVE-2024-24310
8.8 HIGH

In the module "Generate barcode on invoice / delivery slip" (ecgeneratebarcode) from Ether Creation <= 1.2.0 for PrestaShop, a guest can perform SQL injection.

Feb 23, 2024
CVE-2024-24309
7.5 HIGH

In the module "Survey TMA" (ecomiz_survey_tma) up to version 2.0.0 from Ecomiz for PrestaShop, a guest can download personal information without restriction.

Feb 23, 2024
CVE-2021-33162
8.4 HIGH

Improper access control in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow an authenticated user to potentially enable escalation of …

Feb 23, 2024
CVE-2021-33161
7.2 HIGH

Improper input validation in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user to potentially enable escalation of …

Feb 23, 2024
CVE-2021-33158
7.2 HIGH

Improper neutralization in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user to potentially enable escalation of privilege …

Feb 23, 2024
CVE-2021-33157
7.2 HIGH

Insufficient control flow management in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user to potentially enable escalation …

Feb 23, 2024
CVE-2021-33145
7.2 HIGH

Uncaught exception in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user to potentially enable escalation of privilege …

Feb 23, 2024
CVE-2021-33141
8.6 HIGH

Improper input validation in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow an unauthenticated user to potentially enable denial of …

Feb 23, 2024
CVE-2024-1833
7.3 HIGH

A vulnerability was found in SourceCodester Employee Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Feb 23, 2024
CVE-2024-1832
7.3 HIGH

A vulnerability has been found in SourceCodester Complete File Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Feb 23, 2024
CVE-2024-1831
7.3 HIGH

A vulnerability, which was classified as critical, was found in SourceCodester Complete File Management System 1.0. Affected is an unknown function of the file users/index.php …

Feb 23, 2024
CVE-2024-1830
7.3 HIGH

A vulnerability was found in code-projects Library System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the …

Feb 23, 2024
CVE-2022-43842
8.6 HIGH

IBM Aspera Console 3.4.0 through 3.4.2 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker …

Feb 23, 2024
CVE-2024-27318
7.5 HIGH

Versions of the package onnx before and including 1.15.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a …

Feb 23, 2024
CVE-2024-1829
7.3 HIGH

A vulnerability was found in code-projects Library System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the …

Feb 23, 2024
CVE-2024-1828
7.3 HIGH

A vulnerability was found in code-projects Library System 1.0. It has been classified as critical. Affected is an unknown function of the file Source/librarian/user/teacher/registration.php. The …

Feb 23, 2024
CVE-2024-1827
7.3 HIGH

A vulnerability was found in code-projects Library System 1.0 and classified as critical. This issue affects some unknown processing of the file Source/librarian/user/teacher/login.php. The manipulation …

Feb 23, 2024
CVE-2024-23320
8.8 HIGH

Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server. This issue is a …

Feb 23, 2024
CVE-2024-1826
7.3 HIGH

A vulnerability has been found in code-projects Library System 1.0 and classified as critical. This vulnerability affects unknown code of the file Source/librarian/user/student/login.php. The manipulation …

Feb 23, 2024
CVE-2024-26150
8.7 HIGH

`@backstage/backend-common` is a common functionality library for backends for Backstage, an open platform for building developer portals. In `@backstage/backend-common` prior to versions 0.21.1, 0.20.2, and …

Feb 23, 2024
CVE-2024-1824
7.3 HIGH

A vulnerability, which was classified as critical, has been found in CodeAstro House Rental Management System 1.0. Affected by this issue is some unknown functionality …

Feb 23, 2024
CVE-2024-1820
7.3 HIGH

A vulnerability was found in code-projects Crime Reporting System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file inchargelogin.php. …

Feb 23, 2024
CVE-2024-26599
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: pwm: Fix out-of-bounds access in of_pwm_single_xlate() With args->args_count == 2 args->args[2] is not defined. Actually …

Feb 23, 2024
CVE-2024-26598
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Avoid potential UAF in LPI translation cache There is a potential UAF …

Feb 23, 2024
CVE-2024-26597
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: qualcomm: rmnet: fix global oob in rmnet_policy The variable rmnet_link_ops assign a *bigger* maxtype …

Feb 23, 2024
CVE-2023-52464
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: EDAC/thunderx: Fix possible out-of-bounds string access Enabling -Wstringop-overflow globally exposes a warning for a common …

Feb 23, 2024
CVE-2023-52457
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: serial: 8250: omap: Don't skip resource freeing if pm_runtime_resume_and_get() failed Returning an error code from …

Feb 23, 2024
CVE-2023-52455
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: iommu: Don't reserve 0-length IOVA region When the bootloader/firmware doesn't setup the framebuffers, their address …

Feb 23, 2024
CVE-2024-26594
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate mech token in session setup If client send invalid mech token in session …

Feb 23, 2024
CVE-2024-1817
7.3 HIGH

A vulnerability has been found in Demososo DM Enterprise Website Building System up to 2022.8 and classified as critical. Affected by this vulnerability is the …

Feb 23, 2024
CVE-2024-25928
7.1 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sitepact.This issue affects Sitepact: from n/a through 1.0.5.

Feb 23, 2024
CVE-2024-26593
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: i2c: i801: Fix block process call transactions According to the Intel datasheets, software must reset …

Feb 23, 2024
CVE-2024-1776
7.2 HIGH

The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to SQL Injection via the 'form-id' parameter in all versions up …

Feb 23, 2024
CVE-2024-22243
8.1 HIGH

Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed …

Feb 23, 2024
CVE-2024-1786
7.5 HIGH

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in D-Link DIR-600M C1 3.08. Affected by this issue is …

Feb 23, 2024
CVE-2024-1683
7.3 HIGH

A DLL injection vulnerability exists where an authenticated, low-privileged local attacker could modify application files on the TIE Secure Relay host, which could allow for …

Feb 23, 2024
CVE-2024-25756
8.0 HIGH

A Stack Based Buffer Overflow vulnerability in Tenda AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote attacker to execute arbitrary code via the formWifiBasicSet …

Feb 22, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.