CVE Database

40083+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-20004
7.5 HIGH

In Modem NL1, there is a possible system crash due to an improper input validation. This could lead to remote denial of service, if NW …

Feb 5, 2024
CVE-2024-20003
7.5 HIGH

In Modem NL1, there is a possible system crash due to an improper input validation. This could lead to remote denial of service, if NW …

Feb 5, 2024
CVE-2021-46902
7.2 HIGH

An issue was discovered in LTOS-Web-Interface in Meinberg LANTIME-Firmware before 6.24.029 MBGID-9343 and 7 before 7.04.008 MBGID-6303. Path validation is mishandled, and thus an admin …

Feb 4, 2024
CVE-2023-52425
7.5 HIGH

libexpat through 2.5.0 allows a denial of service (resource consumption) because many full reparsings are required in the case of a large token for which …

Feb 4, 2024
CVE-2021-4435
7.7 HIGH

An untrusted search path vulnerability was found in Yarn. When a victim runs certain Yarn commands in a directory with attacker-controlled content, malicious commands could …

Feb 4, 2024
CVE-2024-25062
7.5 HIGH

An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, …

Feb 4, 2024
CVE-2024-1064
7.5 HIGH

A host header injection vulnerability in the HTTP handler component of Crafty Controller allows a remote, unauthenticated attacker to trigger a Denial of Service (DoS) …

Feb 3, 2024
CVE-2023-44031
7.5 HIGH

Incorrect access control in Reprise License Management Software Reprise License Manager v15.1 allows attackers to arbitrarily save sensitive files in insecure locations via a crafted …

Feb 3, 2024
CVE-2023-43183
8.8 HIGH

Incorrect access control in Reprise License Management Software Reprise License Manager v15.1 allows read-only users to arbitrarily change the password of an admin and hijack …

Feb 3, 2024
CVE-2023-43016
7.3 HIGH

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow a …

Feb 3, 2024
CVE-2023-32327
7.1 HIGH

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) is vulnerable to …

Feb 3, 2024
CVE-2023-31004
8.3 HIGH

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow a …

Feb 3, 2024
CVE-2023-30999
7.5 HIGH

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 through 10.0.6.1) could allow an …

Feb 3, 2024
CVE-2024-1197
7.3 HIGH

A vulnerability, which was classified as critical, has been found in SourceCodester Testimonial Page Manager 1.0. This issue affects some unknown processing of the file …

Feb 2, 2024
CVE-2024-24760
8.8 HIGH

mailcow is a dockerized email package, with multiple containers linked in one bridged network. A security vulnerability has been identified in mailcow affecting versions < …

Feb 2, 2024
CVE-2024-24757
7.6 HIGH

open-irs is an issue response robot that reponds to issues in the installed repository. The `.env` file was accidentally uploaded when working with git actions. …

Feb 2, 2024
CVE-2024-24470
8.8 HIGH

Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the update_post.php component.

Feb 2, 2024
CVE-2024-24161
7.5 HIGH

MRCMS 3.0 contains an Arbitrary File Read vulnerability in /admin/file/edit.do as the incoming path parameter is not filtered.

Feb 2, 2024
CVE-2024-23831
7.5 HIGH

LedgerSMB is a free web-based double-entry accounting system. When a LedgerSMB database administrator has an active session in /setup.pl, an attacker can trick the admin …

Feb 2, 2024
CVE-2024-22107
7.2 HIGH

An issue was discovered in GTB Central Console 15.17.1-30814.NG. The method systemSettingsDnsDataAction at /opt/webapp/src/AppBundle/Controller/React/SystemSettingsController.php is vulnerable to command injection via the /old/react/v1/api/system/dns/data endpoint. An authenticated …

Feb 2, 2024
CVE-2023-6387
7.5 HIGH

A potential buffer overflow exists in the Bluetooth LE HCI CPC sample application in the Gecko SDK which may result in a denial of service …

Feb 2, 2024
CVE-2023-51838
7.5 HIGH

Ylianst MeshCentral 1.1.16 suffers from Use of a Broken or Risky Cryptographic Algorithm.

Feb 2, 2024
CVE-2023-47568
8.8 HIGH

A SQL injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to inject malicious …

Feb 2, 2024
CVE-2023-47564
8.0 HIGH

An incorrect permission assignment for critical resource vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow authenticated users to read …

Feb 2, 2024
CVE-2023-47562
7.4 HIGH

An OS command injection vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow authenticated users to execute commands via a …

Feb 2, 2024
CVE-2023-39297
8.8 HIGH

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute …

Feb 2, 2024
CVE-2020-29504
7.4 HIGH

Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain a Missing Required Cryptographic Step Vulnerability.

Feb 2, 2024
CVE-2023-38273
7.5 HIGH

IBM Cloud Pak System 2.3.1.1, 2.3.2.0, and 2.3.3.7 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. …

Feb 2, 2024
CVE-2023-47142
7.5 HIGH

IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 could allow an attacker on the organization's local network to escalate their privileges due to unauthorized …

Feb 2, 2024
CVE-2024-0269
8.3 HIGH

ManageEngine ADAudit Plus versions 7270 and below are vulnerable to the Authenticated SQL injection in File-Summary DrillDown. This issue has been fixed and released in …

Feb 2, 2024
CVE-2024-0253
8.3 HIGH

ManageEngine ADAudit Plus versions 7270 and below are vulnerable to the Authenticated SQL injection in home Graph-Data.

Feb 2, 2024
CVE-2023-6676
8.8 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in National Keep Cyber Security Services CyberMath allows Cross Site Request Forgery.This issue affects CyberMath: from v1.4 before v1.5.

Feb 2, 2024
CVE-2024-1201
7.8 HIGH

Search path or unquoted item vulnerability in HDD Health affecting versions 4.2.0.112 and earlier. This vulnerability could allow a local attacker to store a malicious …

Feb 2, 2024
CVE-2024-23895
8.2 HIGH

A vulnerability has been reported in Cups Easy (Purchase & Inventory), version 1.0, whereby user-controlled inputs are not sufficiently encoded, resulting in a Cross-Site Scripting …

Feb 2, 2024
CVE-2024-0338
7.3 HIGH

A buffer overflow vulnerability has been found in XAMPP affecting version 8.2.4 and earlier. An attacker could execute arbitrary code through a long file debug …

Feb 2, 2024
CVE-2023-39611
7.5 HIGH

An issue in Software FX Chart FX 7 version 7.0.4962.20829 allows attackers to enumerate and read files from the local filesystem by sending crafted web …

Feb 2, 2024
CVE-2024-22851
7.5 HIGH

Directory Traversal Vulnerability in LiveConfig before v.2.5.2 allows a remote attacker to obtain sensitive information via a crafted request to the /static/ endpoint.

Feb 2, 2024
CVE-2023-48645
7.8 HIGH

An issue was discovered in the Archibus app 4.0.3 for iOS. It uses a local database that is synchronized with a Web central server instance …

Feb 2, 2024
CVE-2024-24524
8.8 HIGH

Cross Site Request Forgery (CSRF) vulnerability in flusity-CMS v.2.33, allows remote attackers to execute arbitrary code via the add_menu.php component.

Feb 2, 2024
CVE-2020-24682
7.2 HIGH

Unquoted Search Path or Element vulnerability in B&R Industrial Automation Automation Studio, B&R Industrial Automation NET/PVI allows Target Programs with Elevated Privileges.This issue affects Automation …

Feb 2, 2024
CVE-2024-21860
8.2 HIGH

in OpenHarmony v4.0.0 and prior versions allow an adjacent attacker arbitrary code execution in any apps through use after free.

Feb 2, 2024
CVE-2024-21780
7.5 HIGH

Stack-based buffer overflow vulnerability exists in HOME SPOT CUBE2 V102 and earlier. Processing a specially crafted command may result in a denial of service (DoS) …

Feb 2, 2024
CVE-2021-22282
8.3 HIGH

Improper Control of Generation of Code ('Code Injection') vulnerability in B&R Industrial Automation Automation Studio allows Local Execution of Code.This issue affects Automation Studio: from …

Feb 2, 2024
CVE-2020-24681
8.2 HIGH

Incorrect Permission Assignment for Critical Resource vulnerability in B&R Industrial Automation Automation Studio allows Privilege Escalation.This issue affects Automation Studio: from 4.6.0 through 4.6.X, from …

Feb 2, 2024
CVE-2023-46045
7.8 HIGH

Graphviz 2.36.0 through 9.x before 10.0.1 has an out-of-bounds read via a crafted config6a file. NOTE: exploitability may be uncommon because this file is typically …

Feb 2, 2024
CVE-2023-38019
8.1 HIGH

IBM SOAR QRadar Plugin App 1.0 through 5.0.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially …

Feb 2, 2024
CVE-2024-22319
8.1 HIGH

IBM Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, 8.11.1 and 8.12.0.1 is susceptible to remote code execution attack via JNDI injection when passing an …

Feb 2, 2024
CVE-2024-22903
8.8 HIGH

Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the deleteUpdateAPK function.

Feb 2, 2024
CVE-2024-22900
8.8 HIGH

Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the setNetworkCardInfo function.

Feb 2, 2024
CVE-2024-22899
8.8 HIGH

Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the syncNtpTime function.

Feb 2, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.