CVE Database

10843+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-12286
9.8 CRITICAL

MOBATIME Network Master Clock - DTS 4801 allows attackers to use SSH to gain initial access using default credentials.

Dec 10, 2024
CVE-2024-55547
9.8 CRITICAL

SNMP objects in NET-SNMP used in ORing IAP-420 allows Command Injection. This issue affects IAP-420: through 2.01e.

Dec 10, 2024
CVE-2024-45494
9.8 CRITICAL

An issue was discovered in MSA FieldServer Gateway 5.0.0 through 6.5.2 (Fixed in 7.0.0). The FieldServer Gateway has an internally used shared administrative user account …

Dec 10, 2024
CVE-2024-45493
9.8 CRITICAL

An issue was discovered in MSA FieldServer Gateway 5.0.0 through 6.5.2 (Fixed in 7.0.0). The FieldServer Gateway has internal users, whose access is supposed to …

Dec 10, 2024
CVE-2024-54751
9.8 CRITICAL

COMFAST CF-WR630AX v2.7.0.2 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.

Dec 10, 2024
CVE-2024-5660
9.8 CRITICAL

Use of Hardware Page Aggregation (HPA) and Stage-1 and/or Stage-2 translation on Cortex-A77, Cortex-A78, Cortex-A78C, Cortex-A78AE, Cortex-A710, Cortex-X1, Cortex-X1C, Cortex-X2, Cortex-X3, Cortex-X4, Cortex-X925, Neoverse V1, …

Dec 10, 2024
CVE-2024-55586
9.8 CRITICAL

Nette Database through 3.2.4 allows SQL injection in certain situations involving an untrusted filter that is directly passed to the where method. NOTE: the vendor's …

Dec 10, 2024
CVE-2024-37143
10.0 CRITICAL

Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack versions prior to RCM 3.8.1.0 (for RCM 3.8.x train) and prior …

Dec 10, 2024
CVE-2024-53552
9.8 CRITICAL

CrushFTP 10 before 10.8.3 and 11 before 11.2.3 mishandles password reset, leading to account takeover.

Dec 10, 2024
CVE-2024-47578
9.1 CRITICAL

Adobe Document Service allows an attacker with administrator privileges to send a crafted request from a vulnerable web application. It is usually used to target …

Dec 10, 2024
CVE-2024-55638
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 7.0 before 7.102, from 8.0.0 before 10.2.11, from 10.3.0 …

Dec 10, 2024
CVE-2024-55637
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 …

Dec 10, 2024
CVE-2024-55636
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 …

Dec 10, 2024
CVE-2024-46455
9.8 CRITICAL

unstructured v.0.14.2 and before is vulnerable to XML External Entity (XXE) via the XMLParser.

Dec 9, 2024
CVE-2024-53441
9.1 CRITICAL

An issue in the index.js decryptCookie function of cookie-encrypter v1.0.1 allows attackers to execute a bit flipping attack.

Dec 9, 2024
CVE-2024-54934
9.8 CRITICAL

Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_class.php.

Dec 9, 2024
CVE-2024-54932
9.8 CRITICAL

Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_department.php.

Dec 9, 2024
CVE-2024-54931
9.8 CRITICAL

A SQL Injection was found in /admin/delete_event.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized …

Dec 9, 2024
CVE-2024-54925
9.8 CRITICAL

A SQL Injection was found in /remove_sent_message.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized …

Dec 9, 2024
CVE-2024-54924
9.8 CRITICAL

A SQL Injection was found in /admin/edit_content.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized …

Dec 9, 2024
CVE-2024-54923
9.8 CRITICAL

A SQL Injection vulnerability was found in /admin/edit_teacher.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get …

Dec 9, 2024
CVE-2024-54921
9.8 CRITICAL

A SQL Injection was found in /student_signup.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized …

Dec 9, 2024
CVE-2024-54918
9.8 CRITICAL

Kashipara E-learning Management System v1.0 is vulnerable to Remote Code Execution via File Upload in /teacher_avatar.php.

Dec 9, 2024
CVE-2024-48956
9.8 CRITICAL

Serviceware Processes 6.0 through 7.3 before 7.4 allows attackers without valid authentication to send a specially crafted HTTP request to a service endpoint resulting in …

Dec 9, 2024
CVE-2022-38946
9.8 CRITICAL

Arbitrary File Upload vulnerability in Doctor-Appointment version 1.0 in /Frontend/signup_com.php, allows attackers to execute arbitrary code.

Dec 9, 2024
CVE-2024-40583
9.1 CRITICAL

Pentaminds CuroVMS v2.0.1 was discovered to contain exposed credentials.

Dec 9, 2024
CVE-2022-38947
9.8 CRITICAL

SQL Injection vulnerability in Flipkart-Clone-PHP version 1.0 in entry.php in product_title parameter, allows attackers to execute arbitrary code.

Dec 9, 2024
CVE-2024-54920
9.8 CRITICAL

A SQL Injection vulnerability was found in /teacher_signup.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL command to get …

Dec 9, 2024
CVE-2024-8259
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eryaz Information Technologies NatraCar B2B Dealer Management Program allows SQL Injection.This …

Dec 9, 2024
CVE-2024-53947
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Superset. Specifically, certain engine-specific functions are not checked, which allows …

Dec 9, 2024
CVE-2024-54215
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in roninwp Revy revy.This issue affects Revy: from n/a through <= 1.18.

Dec 9, 2024
CVE-2024-53822
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Genetech Pie Register Premium.This issue affects Pie Register Premium: from n/a before 3.8.3.3.

Dec 9, 2024
CVE-2024-43222
9.8 CRITICAL

Missing Authorization vulnerability in SeventhQueen Sweet Date sweetdate allows Privilege Escalation.This issue affects Sweet Date: from n/a through <= 3.7.3.

Dec 9, 2024
CVE-2023-32117
9.8 CRITICAL

Missing Authorization vulnerability in SoftLab Integrate Google Drive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Integrate Google Drive: from n/a through 1.1.99.

Dec 9, 2024
CVE-2024-55564
9.8 CRITICAL

The POSIX::2008 package before 0.24 for Perl has a potential _execve50c env buffer overflow.

Dec 9, 2024
CVE-2024-55560
9.8 CRITICAL

MailCleaner before 28d913e has default values of ssh_host_dsa_key, ssh_host_rsa_key, and ssh_host_ed25519_key that persist after installation.

Dec 8, 2024
CVE-2024-12209
9.8 CRITICAL

The WP Umbrella: Update Backup Restore & Monitoring plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.17.0 …

Dec 8, 2024
CVE-2024-44852
9.8 CRITICAL

Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a segmentation violation via the component theta_star::ThetaStar::isUnsafeToPlan().

Dec 6, 2024
CVE-2024-41650
9.8 CRITICAL

Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to …

Dec 6, 2024
CVE-2024-41649
9.8 CRITICAL

Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to …

Dec 6, 2024
CVE-2024-41648
9.8 CRITICAL

Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to …

Dec 6, 2024
CVE-2024-41647
9.8 CRITICAL

Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to …

Dec 6, 2024
CVE-2024-41646
9.8 CRITICAL

Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to …

Dec 6, 2024
CVE-2024-41645
9.8 CRITICAL

Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to …

Dec 6, 2024
CVE-2024-41644
9.8 CRITICAL

Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via the dyn_param_handler_ component.

Dec 6, 2024
CVE-2024-38927
9.8 CRITICAL

Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered …

Dec 6, 2024
CVE-2024-38926
9.8 CRITICAL

Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered …

Dec 6, 2024
CVE-2024-38925
9.8 CRITICAL

Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered …

Dec 6, 2024
CVE-2024-38924
9.8 CRITICAL

Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered …

Dec 6, 2024
CVE-2024-38923
9.8 CRITICAL

Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered …

Dec 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.