CVE Database

10843+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-51051
9.8 CRITICAL

AVSCMS v8.2.0 was discovered to contain weak default credentials for the Administrator account.

Nov 18, 2024
CVE-2024-51053
9.8 CRITICAL

An arbitrary file upload vulnerability in the component /main/fileupload.php of AVSCMS v8.2.0 allows attackers to execute arbitrary code via uploading a crafted file.

Nov 18, 2024
CVE-2024-50919
9.8 CRITICAL

Jpress until v5.1.1 has arbitrary file uploads on the windows platform, and the construction of non-standard file formats such as .jsp. can lead to arbitrary …

Nov 18, 2024
CVE-2024-47533
9.8 CRITICAL

Cobbler, a Linux installation server that allows for rapid setup of network installation environments, has an improper authentication vulnerability starting in version 3.0.0 and prior …

Nov 18, 2024
CVE-2024-44756
9.8 CRITICAL

NUS-M9 ERP Management Software v3.0.0 was discovered to contain a SQL injection vulnerability via the usercode parameter at /UserWH/checkLogin.

Nov 18, 2024
CVE-2024-0012
9.8 CRITICAL KEV

An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator …

Nov 18, 2024
CVE-2024-52434
9.1 CRITICAL

Deserialization of Untrusted Data vulnerability in supsystic Popup by Supsystic popup-by-supsystic allows Command Injection.This issue affects Popup by Supsystic: from n/a through <= 1.10.29.

Nov 18, 2024
CVE-2024-52433
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in Mindstien Technologies My Geo Posts Free my-geo-posts-free allows Object Injection.This issue affects My Geo Posts Free: from n/a through …

Nov 18, 2024
CVE-2024-52432
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in NIX Solutions Ltd NIX Anti-Spam Light nix-anti-spam-light allows Object Injection.This issue affects NIX Anti-Spam Light: from n/a through <= …

Nov 18, 2024
CVE-2024-52431
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pressaholic WordPress Video Robot - The Ultimate Video Importer allows SQL …

Nov 18, 2024
CVE-2024-52430
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in bublick Lis Video Gallery lis-video-gallery allows Object Injection.This issue affects Lis Video Gallery: from n/a through <= 0.2.1.

Nov 18, 2024
CVE-2024-52429
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in AntonHoelstad WP Quick Setup wp-quick-setup allows Upload a Web Shell to a Web Server.This issue affects …

Nov 18, 2024
CVE-2024-52427
9.9 CRITICAL

Deserialization of Untrusted Data vulnerability in Vollstart Event Tickets with Ticket Scanner event-tickets-with-ticket-scanner allows Server Side Include (SSI) Injection.This issue affects Event Tickets with Ticket …

Nov 18, 2024
CVE-2024-52316
9.8 CRITICAL

Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuthContext component which may throw an …

Nov 18, 2024
CVE-2024-47208
9.8 CRITICAL

Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.17. Users are …

Nov 18, 2024
CVE-2024-11315
9.8 CRITICAL

The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload …

Nov 18, 2024
CVE-2024-11314
9.8 CRITICAL

The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload …

Nov 18, 2024
CVE-2024-11313
9.8 CRITICAL

The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload …

Nov 18, 2024
CVE-2024-11312
9.8 CRITICAL

The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload …

Nov 18, 2024
CVE-2024-11311
9.8 CRITICAL

The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload …

Nov 18, 2024
CVE-2015-20111
9.8 CRITICAL

miniupnp before 4c90b87, as used in Bitcoin Core before 0.12 and other products, lacks checks for snprintf return values, leading to a buffer overflow and …

Nov 18, 2024
CVE-2023-43091
9.8 CRITICAL

A flaw was found in GNOME Maps, which is vulnerable to a code injection attack via its service.json configuration file. If the configuration file is …

Nov 17, 2024
CVE-2024-52397
9.1 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Davor Zeljkovic Convert Docx2post convert-docx2post allows Upload a Web Shell to a Web Server.This issue affects …

Nov 16, 2024
CVE-2024-52416
10.0 CRITICAL

Missing Authorization vulnerability in Eugen Bobrowski Debug Tool debug-tool allows Upload a Web Shell to a Web Server.This issue affects Debug Tool: from n/a through …

Nov 16, 2024
CVE-2024-52414
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in Anthony Carbon WDES Responsive Mobile Menu wdes-responsive-mobile-menu allows Object Injection.This issue affects WDES Responsive Mobile Menu: from n/a through …

Nov 16, 2024
CVE-2024-52413
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in dmcwebzone Airin Blog airin-blog allows Object Injection.This issue affects Airin Blog: from n/a through <= 1.6.1.

Nov 16, 2024
CVE-2024-52412
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in Stephen Cui Xin allows Object Injection.This issue affects Xin: from n/a through 1.0.8.1.

Nov 16, 2024
CVE-2024-52411
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in flowcraft Advanced Personalization personalization-by-flowcraft allows Object Injection.This issue affects Advanced Personalization: from n/a through <= 1.1.2.

Nov 16, 2024
CVE-2024-52410
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in Phoenixheart Referrer Detector referrer-detector allows Object Injection.This issue affects Referrer Detector: from n/a through <= 4.2.1.0.

Nov 16, 2024
CVE-2024-52409
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in Phoenixheart AJAX Random Posts ajax-random-posts allows Object Injection.This issue affects AJAX Random Posts: from n/a through <= 0.3.3.

Nov 16, 2024
CVE-2024-52408
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in pushassist Push Notifications for WordPress by PushAssist push-notification-for-wp-by-pushassist allows Upload a Web Shell to a Web …

Nov 16, 2024
CVE-2024-52407
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in BasePress BasePress Migration Tools basepress-migration-tools allows Upload a Web Shell to a Web Server.This issue affects …

Nov 16, 2024
CVE-2024-52406
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in wibergsweb CSV to html csv-to-html allows Upload a Web Shell to a Web Server.This issue affects …

Nov 16, 2024
CVE-2024-52405
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in bikramjoshii B-Banner Slider b-banner-slider allows Upload a Web Shell to a Web Server.This issue affects B-Banner …

Nov 16, 2024
CVE-2024-52404
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in bigfiveagency CF7 Reply Manager cf7-reply-manager.This issue affects CF7 Reply Manager: from n/a through <= 1.2.3.

Nov 16, 2024
CVE-2024-52403
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Saad Iqbal User Management user-management allows Upload a Web Shell to a Web Server.This issue affects …

Nov 16, 2024
CVE-2024-52400
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Subhasis Laha Gallerio gallerio allows Upload a Web Shell to a Web Server.This issue affects Gallerio: …

Nov 16, 2024
CVE-2024-52399
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Clarisse K. Writer Helper writer-helper allows Upload a Web Shell to a Web Server.This issue affects …

Nov 16, 2024
CVE-2024-52398
9.1 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Halyra CDI collect-and-deliver-interface-for-woocommerce.This issue affects CDI: from n/a through <= 5.5.3.

Nov 16, 2024
CVE-2024-8856
9.8 CRITICAL

The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the …

Nov 16, 2024
CVE-2024-11263
9.3 CRITICAL

When the Global Pointer (GP) relative addressing is enabled (CONFIG_RISCV_GP=y), the gp reg points at 0x800 bytes past the start of the .sdata section which …

Nov 15, 2024
CVE-2024-44758
9.8 CRITICAL

An arbitrary file upload vulnerability in the component /Production/UploadFile of NUS-M9 ERP Management Software v3.0.0 allows attackers to execute arbitrary code via uploading crafted files.

Nov 15, 2024
CVE-2024-10934
9.8 CRITICAL

In OpenBSD 7.5 before errata 008 and OpenBSD 7.4 before errata 021, avoid possible mbuf double free in NFS client and server implementation, do not …

Nov 15, 2024
CVE-2024-45971
9.8 CRITICAL

Multiple Buffer overflows in the MMS Client in MZ Automation LibIEC61850 before commit 1f52be9ddeae00e69cd43e4cac3cb4f0c880c4f0 allow a malicious server to cause a stack-based buffer overflow via …

Nov 15, 2024
CVE-2024-45970
9.8 CRITICAL

Multiple Buffer overflows in the MMS Client in MZ Automation LibIEC61850 before commit ac925fae8e281ac6defcd630e9dd756264e9c5bc allow a malicious server to cause a stack-based buffer overflow via …

Nov 15, 2024
CVE-2024-51164
9.1 CRITICAL

Multiple parameters have SQL injection vulnerability in JEPaaS 7.2.8 via /je/login/btnLog/insertBtnLog, which could allow a remote user to submit a specially crafted query, allowing an …

Nov 15, 2024
CVE-2024-50724
9.8 CRITICAL

KASO v9.0 was discovered to contain a SQL injection vulnerability via the person_id parameter at /cardcase/editcard.jsp.

Nov 15, 2024
CVE-2024-50649
9.8 CRITICAL

The user avatar upload function in python_book V1.0 has an arbitrary file upload vulnerability.

Nov 15, 2024
CVE-2024-50648
9.8 CRITICAL

yshopmall V1.0 has an arbitrary file upload vulnerability, which can enable RCE or even take over the server when improperly configured to parse JSP files.

Nov 15, 2024
CVE-2023-20036
9.9 CRITICAL

A vulnerability in the web UI of Cisco IND could allow an authenticated, remote attacker to execute arbitrary commands with administrative privileges on the underlying …

Nov 15, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.