CVE Database

10843+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-50523
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in RainbowLink Inc. All Post Contact Form allpost-contactform allows Upload a Web Shell to a Web Server.This …

Nov 4, 2024
CVE-2024-51558
9.8 CRITICAL

This vulnerability exists in the Wave 2.0 due to missing restrictions for excessive failed authentication attempts on its API based login. A remote attacker could …

Nov 4, 2024
CVE-2024-10035
9.8 CRITICAL

Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Special Elements used in a Command ('Command Injection'), Improper Neutralization of Special Elements used …

Nov 4, 2024
CVE-2024-51661
9.1 CRITICAL

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Command Injection.This issue …

Nov 4, 2024
CVE-2024-23590
9.1 CRITICAL

Session Fixation vulnerability in Apache Kylin. This issue affects Apache Kylin: from 2.0.0 through 4.x. Users are recommended to upgrade to version 5.0.0 or above, …

Nov 4, 2024
CVE-2024-51252
9.8 CRITICAL

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the restore function.

Nov 1, 2024
CVE-2024-51431
9.8 CRITICAL

LB-LINK BL-WR 1300H v.1.0.4 contains hardcoded credentials stored in /etc/shadow which are easily guessable.

Nov 1, 2024
CVE-2024-28265
9.1 CRITICAL

IBOS v4.5.5 has an arbitrary file deletion vulnerability via \system\modules\dashboard\controllers\LoginController.php.

Nov 1, 2024
CVE-2024-7456
9.8 CRITICAL

A SQL injection vulnerability exists in the `/api/v1/external-users` route of lunary-ai/lunary version v1.4.2. The `order by` clause of the SQL query uses `sql.unsafe` without prior …

Nov 1, 2024
CVE-2024-48359
9.8 CRITICAL

Qualitor v8.24 was discovered to contain a remote code execution (RCE) vulnerability via the gridValoresPopHidden parameter.

Oct 31, 2024
CVE-2024-51065
9.8 CRITICAL

Phpgurukul Beauty Parlour Management System v1.1 is vulnerable to SQL Injection in admin/index.php via the the username parameter.

Oct 31, 2024
CVE-2024-51064
9.8 CRITICAL

Phpgurukul Teachers Record Management System v2.1 is vulnerable to SQL Injection via the tid parameter to admin/queries.php.

Oct 31, 2024
CVE-2024-51063
9.1 CRITICAL

Phpgurukul Teachers Record Management System v2.1 is vulnerable to SQL Injection in add-teacher.php via the mobile number or email parameter.

Oct 31, 2024
CVE-2024-51060
9.1 CRITICAL

Projectworlds Online Admission System v1 is vulnerable to SQL Injection in index.php via the 'a_id' parameter.

Oct 31, 2024
CVE-2024-42515
9.9 CRITICAL

Glossarizer through 1.5.2 improperly tries to convert text into HTML. Even though the application itself escapes special characters (e.g., <>), the underlying library converts these …

Oct 31, 2024
CVE-2024-39332
9.8 CRITICAL

Webswing 23.2.2 allows remote attackers to modify client-side JavaScript code to achieve path traversal, likely leading to remote code execution via modification of shell scripts …

Oct 31, 2024
CVE-2023-52044
9.8 CRITICAL

Studio-42 eLfinder 2.1.62 is vulnerable to Remote Code Execution (RCE) as there is no restriction for uploading files with the .php8 extension.

Oct 31, 2024
CVE-2024-51482
9.9 CRITICAL

ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder v1.37.* <= 1.37.64 is vulnerable to boolean-based SQL Injection in function of web/ajax/event.php. This …

Oct 31, 2024
CVE-2024-51478
9.9 CRITICAL

YesWiki is a wiki system written in PHP. Prior to 4.4.5, the use of a weak cryptographic algorithm and a hard-coded salt to hash the …

Oct 31, 2024
CVE-2024-51260
9.8 CRITICAL

DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the acme_process function.

Oct 31, 2024
CVE-2024-51255
9.8 CRITICAL

DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the ruequest_certificate function.

Oct 31, 2024
CVE-2024-48910
9.1 CRITICAL

DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify was vulnerable to prototype pollution. This vulnerability is fixed in 2.4.2.

Oct 31, 2024
CVE-2024-51259
9.8 CRITICAL

DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the setup_cacertificate function.

Oct 31, 2024
CVE-2024-42835
9.8 CRITICAL

langflow v1.0.12 was discovered to contain a remote code execution (RCE) vulnerability via the PythonCodeTool component.

Oct 31, 2024
CVE-2024-49674
9.6 CRITICAL

Cross-Site Request Forgery (CSRF) vulnerability in lukashuser EKC Tournament Manager ekc-tournament-manager allows Upload a Web Shell to a Web Server.This issue affects EKC Tournament Manager: …

Oct 31, 2024
CVE-2024-43984
9.6 CRITICAL

Cross-Site Request Forgery (CSRF) vulnerability in Podlove Podlove Podcast Publisher allows Code Injection.This issue affects Podlove Podcast Publisher: from n/a through 4.1.13.

Oct 31, 2024
CVE-2024-10392
9.8 CRITICAL

The AI Power: Complete AI Pack plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'handle_image_upload' function …

Oct 31, 2024
CVE-2024-48307
9.8 CRITICAL

JeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalData.

Oct 31, 2024
CVE-2024-51427
9.8 CRITICAL

An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an unspecified impact via the …

Oct 30, 2024
CVE-2024-51424
9.8 CRITICAL

An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an unspecified impact via the …

Oct 30, 2024
CVE-2024-48112
9.8 CRITICAL

A deserialization vulnerability in the component \controller\Index.php of Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.

Oct 30, 2024
CVE-2024-48202
9.8 CRITICAL

icecms <=3.4.7 has a File Upload vulnerability in FileUtils.java,uploadFile.

Oct 30, 2024
CVE-2024-10456
9.8 CRITICAL

Delta Electronics InfraSuite Device Master versions prior to 1.0.12 are affected by a deserialization vulnerability that targets the Device-Gateway, which could allow deserialization of arbitrary …

Oct 30, 2024
CVE-2024-51298
9.8 CRITICAL

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doGRETunnel function.

Oct 30, 2024
CVE-2024-33699
9.9 CRITICAL

The LevelOne WBR-6012 router's web application has a vulnerability in its firmware version R0.40e6, allowing attackers to change the administrator password and gain higher privileges …

Oct 30, 2024
CVE-2024-23309
9.0 CRITICAL

The LevelOne WBR-6012 router with firmware R0.40e6 has an authentication bypass vulnerability in its web application due to reliance on client IP addresses for authentication. …

Oct 30, 2024
CVE-2024-10525
9.8 CRITICAL

In Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if a malicious broker sends a crafted SUBACK packet with no reason codes, a client using libmosquitto …

Oct 30, 2024
CVE-2024-8512
9.1 CRITICAL

The W3SPEEDSTER plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 7.26 via the 'script' parameter of the …

Oct 30, 2024
CVE-2024-50511
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in donimedia WP donimedia carousel wp-donimedia-carousel allows Upload a Web Shell to a Web Server.This issue affects …

Oct 30, 2024
CVE-2024-50510
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in webandprint AR For Woocommerce ar-for-woocommerce allows Upload a Web Shell to a Web Server.This issue affects …

Oct 30, 2024
CVE-2024-50507
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in Daschmi DS.DownloadList dsdownloadlist allows Object Injection.This issue affects DS.DownloadList: from n/a through <= 1.3.

Oct 30, 2024
CVE-2024-50503
9.8 CRITICAL

Authentication Bypass Using an Alternate Path or Channel vulnerability in Deryck User Toolkit user-toolkit allows Authentication Bypass.This issue affects User Toolkit: from n/a through <= …

Oct 30, 2024
CVE-2024-51568
10.0 CRITICAL

CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecutioner() sink. There is /filemanager/upload (aka File Manager upload) unauthenticated remote code …

Oct 29, 2024
CVE-2024-51567
10.0 CRITICAL KEV

upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatus by bypassing secMiddleware …

Oct 29, 2024
CVE-2024-51378
10.0 CRITICAL KEV

getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or …

Oct 29, 2024
CVE-2024-48573
9.8 CRITICAL

A NoSQL injection vulnerability in AquilaCMS 1.409.20 and prior allows unauthenticated attackers to reset user and administrator account passwords via the "Reset password" feature.

Oct 29, 2024
CVE-2024-48138
9.8 CRITICAL

A remote code execution (RCE) vulnerability in the component /PluXml/core/admin/parametres_edittpl.php of PluXml v5.8.16 and lower allows attackers to execute arbitrary code via injecting a crafted …

Oct 29, 2024
CVE-2024-44081
9.8 CRITICAL

In Jitsi Meet before 2.0.9779, the functionality to share a video file was implemented in an insecure way, resulting in clients loading videos from an …

Oct 29, 2024
CVE-2024-48206
9.8 CRITICAL

A Deserialization of Untrusted Data vulnerability in chainer v7.8.1.post1 leads to execution of arbitrary code.

Oct 29, 2024
CVE-2024-48063
9.8 CRITICAL

In PyTorch <=2.4.1, the RemoteModule has Deserialization RCE. NOTE: this is disputed by multiple parties because this is intended behavior in PyTorch distributed computing.

Oct 29, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.