CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-48874
9.8 CRITICAL

Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could give attackers the ability to force Ruijie's proxy servers to perform any request …

Dec 6, 2024
CVE-2024-47791
7.5 HIGH

Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could allow an attacker to subscribe to partial possible topics in Ruijie MQTT broker, …

Dec 6, 2024
CVE-2024-47146
6.5 MEDIUM

Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could allow an attacker to obtain the devices serial number if physically adjacent and …

Dec 6, 2024
CVE-2024-46874
8.1 HIGH

Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could allow MQTT clients connecting with device credentials to send messages to some topics. …

Dec 6, 2024
CVE-2024-45722
7.5 HIGH

Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x uses weak credential mechanism that could allow an attacker to easily calculate MQTT credentials.

Dec 6, 2024
CVE-2024-52558
5.3 MEDIUM

The affected product is vulnerable to an integer underflow. An unauthenticated attacker could send a malformed HTTP request, which could allow the attacker to crash …

Dec 6, 2024
CVE-2024-52320
9.8 CRITICAL

The affected product is vulnerable to a command injection. An unauthenticated attacker could send commands through a malicious HTTP request which could result in remote …

Dec 6, 2024
CVE-2024-51727
6.5 MEDIUM

Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x contains a feature that could enable attackers to invalidate a legitimate user's session and …

Dec 6, 2024
CVE-2024-48871
9.8 CRITICAL

The affected product is vulnerable to a stack-based buffer overflow. An unauthenticated attacker could send a malicious HTTP request that the webserver fails to properly …

Dec 6, 2024
CVE-2024-48703
4.8 MEDIUM

PhpGurukul Medical Card Generation System v1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/search-medicalcard.php via the searchdata parameter.

Dec 6, 2024
CVE-2024-47547
9.4 CRITICAL

Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x contains a weak mechanism for its users to change their passwords which leaves authentication …

Dec 6, 2024
CVE-2024-47043
7.5 HIGH

Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could enable an attacker to correlate a device serial number and the user's phone …

Dec 6, 2024
CVE-2024-42494
6.5 MEDIUM

Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x contains a a feature that could enable sub accounts or attackers to view and …

Dec 6, 2024
CVE-2024-11220
7.8 HIGH

A local low-level user on the server machine with credentials to the running OAS services can create and execute a report with an rdlx file …

Dec 6, 2024
CVE-2024-55268
6.1 MEDIUM

A Reflected Cross Site Scripting (XSS) vulnerability was found in /covidtms/registered-user-testing.php in PHPGurukul COVID 19 Testing Management System 1.0 which allows remote attackers to execute …

Dec 6, 2024
CVE-2024-54749
7.5 HIGH

Ubiquiti U7-Pro 7.0.35 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root. NOTE: this is disputed …

Dec 6, 2024
CVE-2024-54143

openwrt/asu is an image on demand server for OpenWrt based distributions. The request hashing mechanism truncates SHA-256 hashes to only 12 characters. This significantly reduces …

Dec 6, 2024
CVE-2024-53691
8.8 HIGH

A link following vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained …

Dec 6, 2024
CVE-2024-50404
8.8 HIGH

A link following vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow remote attackers who have gained user access to …

Dec 6, 2024
CVE-2024-50403
7.2 HIGH

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers …

Dec 6, 2024
CVE-2024-50402
7.2 HIGH

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers …

Dec 6, 2024
CVE-2024-50393
9.8 CRITICAL

A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to execute arbitrary …

Dec 6, 2024
CVE-2024-50389
9.8 CRITICAL

A SQL injection vulnerability has been reported to affect QuRouter. If exploited, the vulnerability could allow remote attackers to inject malicious code. We have already …

Dec 6, 2024
CVE-2024-50388
9.8 CRITICAL

An OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability could allow remote attackers to execute …

Dec 6, 2024
CVE-2024-50387
9.8 CRITICAL

A SQL injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to inject malicious …

Dec 6, 2024
CVE-2024-48868
7.5 HIGH

An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow …

Dec 6, 2024
CVE-2024-48867
7.5 HIGH

An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow …

Dec 6, 2024
CVE-2024-48866
5.3 MEDIUM

An improper handling of URL encoding (Hex Encoding) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow …

Dec 6, 2024
CVE-2024-48865
7.5 HIGH

An improper certificate validation vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow attackers with local network …

Dec 6, 2024
CVE-2024-48863
9.8 CRITICAL

A command injection vulnerability has been reported to affect License Center. If exploited, the vulnerability could allow remote attackers to execute arbitrary commands. We have …

Dec 6, 2024
CVE-2024-48859
9.1 CRITICAL

An improper authentication vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to compromise the …

Dec 6, 2024
CVE-2024-54750
9.8 CRITICAL

Ubiquiti U6-LR 6.6.65 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root. NOTE: In Ubiquiti's view …

Dec 6, 2024
CVE-2024-54747
9.8 CRITICAL

WAVLINK WN531P3 202383 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.

Dec 6, 2024
CVE-2024-54745
9.8 CRITICAL

WAVLINK WN701AE M01AE_V240305 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.

Dec 6, 2024
CVE-2024-54137
7.4 HIGH

liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. A correctness error has been identified in the reference implementation of the …

Dec 6, 2024
CVE-2024-54136
9.8 CRITICAL

ClipBucket V5 provides open source video hosting with PHP. ClipBucket-v5 Version 5.5.1 Revision 199 and below is vulnerable to PHP Deserialization vulnerability. The vulnerability exists …

Dec 6, 2024
CVE-2024-54135
9.8 CRITICAL

ClipBucket V5 provides open source video hosting with PHP. ClipBucket-v5 Version 2.0 to Version 5.5.1 Revision 199 are vulnerable to PHP Deserialization vulnerability. The vulnerability …

Dec 6, 2024
CVE-2024-50677
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in OroPlatform CMS v5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the …

Dec 6, 2024
CVE-2024-30129
5.3 MEDIUM

The HTTP host header can be manipulated and cause the application to behave in unexpected ways. Any changes made to the header would cause the …

Dec 6, 2024
CVE-2024-12254
7.5 HIGH

Starting in Python 3.12.0, the asyncio._SelectorSocketTransport.writelines() method would not "pause" writing and signal to the Protocol to drain the buffer to the wire once the …

Dec 6, 2024
CVE-2024-54141
8.6 HIGH

phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. Prior to 4.0.0, phpMyFAQ exposes the database (ie …

Dec 6, 2024
CVE-2024-42196
6.2 MEDIUM

HCL Launch stores potentially sensitive information in log files that could be read by a local user with access to HTTP request logs.

Dec 6, 2024
CVE-2024-11738
5.3 MEDIUM

A flaw was found in Rustls 0.23.13 and related APIs. This vulnerability allows denial of service (panic) via a fragmented TLS ClientHello message.

Dec 6, 2024
CVE-2024-54216
7.7 HIGH

Path Traversal: '.../...//' vulnerability in reputeinfosystems ARForms arforms allows Path Traversal.This issue affects ARForms: from n/a through <= 6.4.1.

Dec 6, 2024
CVE-2024-54214
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in roninwp Revy revy allows Upload a Web Shell to a Web Server.This issue affects Revy: from …

Dec 6, 2024
CVE-2024-54213
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zionbuilder ZionBuilder zionbuilder allows Stored XSS.This issue affects ZionBuilder: from n/a through <= …

Dec 6, 2024
CVE-2024-54212
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor Alam Magical Addons For Elementor magical-addons-for-elementor allows Stored XSS.This issue affects Magical …

Dec 6, 2024
CVE-2024-54211
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visualmodo Borderless borderless allows Cross-Site Scripting (XSS).This issue affects Borderless: from n/a through …

Dec 6, 2024
CVE-2024-54210
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codexshaper Advanced Element Bucket Addons for Elementor cs-element-bucket allows Stored XSS.This issue affects …

Dec 6, 2024
CVE-2024-54209
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Awesome Shortcodes awesome-shortcodes allows Reflected XSS.This issue affects Awesome Shortcodes: from n/a …

Dec 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.