CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2022-33862
6.7 MEDIUM

IPP software prior to v1.71 is vulnerable to default credential vulnerability. This could lead attackers to identify and access vulnerable systems.

Nov 25, 2024
CVE-2022-33861
5.1 MEDIUM

IPP software versions prior to v1.71 do not sufficiently verify the authenticity of data, in a way that causes it to accept invalid data.

Nov 25, 2024
CVE-2021-23282
5.2 MEDIUM

Eaton Intelligent Power Manager (IPM) prior to 1.70 is vulnerable to stored Cross site scripting. The vulnerability exists due to insufficient validation of input from …

Nov 25, 2024
CVE-2024-9666
4.7 MEDIUM

A vulnerability was found in the Keycloak Server. The Keycloak Server is vulnerable to a denial of service (DoS) attack due to improper handling of …

Nov 25, 2024
CVE-2024-11662
6.3 MEDIUM

A vulnerability was found in welliamcao OpsManage 3.0.1/3.0.2/3.0.3/3.0.4/3.0.5. It has been rated as critical. This issue affects the function deploy_host_vars of the file /apps/api/views/deploy_api.py of …

Nov 25, 2024
CVE-2024-11661
4.3 MEDIUM

A vulnerability was found in Codezips Free Exam Hall Seating Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of …

Nov 25, 2024
CVE-2024-10492
2.7 LOW

A vulnerability was found in Keycloak. A user with high privileges could read sensitive information from a Vault file that is not within the expected …

Nov 25, 2024
CVE-2024-10451
5.9 MEDIUM

A flaw was found in Keycloak. This issue occurs because sensitive runtime values, such as passwords, may be captured during the Keycloak build process and …

Nov 25, 2024
CVE-2024-10270
6.5 MEDIUM

A vulnerability was found in the Keycloak-services package. If untrusted data is passed to the SearchQueryUtils method, it could lead to a denial of service …

Nov 25, 2024
CVE-2024-6538
5.3 MEDIUM

A flaw was found in OpenShift Console. A Server Side Request Forgery (SSRF) attack can happen if an attacker supplies all or part of a …

Nov 25, 2024
CVE-2024-11660
3.5 LOW

A vulnerability was found in code-projects Farmacia 1.0. It has been classified as problematic. This affects an unknown part of the file usuario.php. The manipulation …

Nov 25, 2024
CVE-2024-11659
4.7 MEDIUM

A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118 and classified as critical. Affected by this issue is some unknown functionality …

Nov 25, 2024
CVE-2024-7056
3.5 LOW

The WPForms WordPress plugin before 1.9.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as Admin to …

Nov 25, 2024
CVE-2024-6393
4.8 MEDIUM

The Photo Gallery, Sliders, Proofing and WordPress plugin before 3.59.5 does not sanitise and escape some of its Images settings, which could allow high privilege …

Nov 25, 2024
CVE-2024-11658
4.7 MEDIUM

A vulnerability has been found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118 and classified as critical. Affected by this vulnerability is an unknown …

Nov 25, 2024
CVE-2024-11657
4.7 MEDIUM

A vulnerability, which was classified as critical, was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. Affected is an unknown function of the …

Nov 25, 2024
CVE-2024-10710
3.5 LOW

The YaDisk Files WordPress plugin through 1.2.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Nov 25, 2024
CVE-2024-10709
6.8 MEDIUM

The YaDisk Files WordPress plugin through 1.2.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where …

Nov 25, 2024
CVE-2024-11656
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. This issue affects some unknown processing …

Nov 25, 2024
CVE-2024-11655
4.7 MEDIUM

A vulnerability classified as critical was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. This vulnerability affects unknown code of the file /admin/network/diag_pinginterface. …

Nov 25, 2024
CVE-2020-11311

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as duplicate. All references should point to CVE-2021-1904.

Nov 25, 2024
CVE-2024-11654
4.7 MEDIUM

A vulnerability classified as critical has been found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. This affects an unknown part of the file …

Nov 25, 2024
CVE-2024-11653
4.7 MEDIUM

A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. It has been rated as critical. Affected by this issue is some …

Nov 25, 2024
CVE-2024-11483
5.0 MEDIUM

A vulnerability was found in the Ansible Automation Platform (AAP). This flaw allows attackers to escalate privileges by improperly leveraging read-scoped OAuth2 tokens to gain …

Nov 25, 2024
CVE-2024-53930
5.4 MEDIUM

WikiDocs before 1.0.65 allows stored XSS by authenticated users via data that comes after $$\\, which is mishandled by a KaTeX parser.

Nov 25, 2024
CVE-2024-11652
4.7 MEDIUM

A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. It has been declared as critical. Affected by this vulnerability is an …

Nov 25, 2024
CVE-2024-11651
4.7 MEDIUM

A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. It has been classified as critical. Affected is an unknown function of …

Nov 25, 2024
CVE-2024-11650
6.5 MEDIUM

A vulnerability was found in Tenda i9 1.0.0.8(3828) and classified as critical. This issue affects the function websReadEvent of the file /goform/GetIPTV. The manipulation leads …

Nov 25, 2024
CVE-2024-11649
7.3 HIGH

A vulnerability has been found in 1000 Projects Beauty Parlour Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file …

Nov 25, 2024
CVE-2024-11648
7.3 HIGH

A vulnerability, which was classified as critical, was found in 1000 Projects Beauty Parlour Management System 1.0. This affects an unknown part of the file …

Nov 25, 2024
CVE-2024-11647
7.3 HIGH

A vulnerability, which was classified as critical, has been found in 1000 Projects Beauty Parlour Management System 1.0. Affected by this issue is some unknown …

Nov 25, 2024
CVE-2024-53916
7.5 HIGH

In OpenStack Neutron before 25.0.1, neutron/extensions/tagging.py can use an incorrect ID during policy enforcement. It does not apply the proper policy check for changing network …

Nov 25, 2024
CVE-2024-11646
7.3 HIGH

A vulnerability classified as critical was found in 1000 Projects Beauty Parlour Management System 1.0. Affected by this vulnerability is an unknown functionality of the …

Nov 25, 2024
CVE-2024-11666
9.0 CRITICAL

Affected devices beacon to eCharge cloud infrastructure asking if there are any command they should run. This communication is established over an insecure channel since …

Nov 24, 2024
CVE-2024-11665
8.8 HIGH

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in hardy-barth cph2_echarge_firmware allows OS Command Injection.This issue affects cph2_echarge_firmware: through 2.0.4.

Nov 24, 2024
CVE-2024-53915
9.8 CRITICAL

An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24405. It allows remote attackers to execute arbitrary code because untrusted data, …

Nov 24, 2024
CVE-2024-53914
9.8 CRITICAL

An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24344. It allows remote attackers to execute arbitrary code because untrusted data, …

Nov 24, 2024
CVE-2024-53913
9.8 CRITICAL

An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24343. It allows remote attackers to execute arbitrary code because untrusted data, …

Nov 24, 2024
CVE-2024-53912
9.8 CRITICAL

An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24341. It allows remote attackers to execute arbitrary code because untrusted data, …

Nov 24, 2024
CVE-2024-53911
9.8 CRITICAL

An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24339. It allows remote attackers to execute arbitrary code because untrusted data, …

Nov 24, 2024
CVE-2024-53910
9.8 CRITICAL

An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24336. It allows remote attackers to execute arbitrary code because untrusted data, …

Nov 24, 2024
CVE-2024-53909
9.8 CRITICAL

An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24334. It allows remote attackers to execute arbitrary code because untrusted data, …

Nov 24, 2024
CVE-2024-53901
5.5 MEDIUM

The Imager package before 1.025 for Perl has a heap-based buffer overflow leading to denial of service, or possibly unspecified other impact, when the trim() …

Nov 24, 2024
CVE-2024-53899
7.8 HIGH

virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this …

Nov 24, 2024
CVE-2024-11233
4.8 MEDIUM

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, due to an error in convert.quoted-printable-decode filter certain data can lead to buffer …

Nov 24, 2024
CVE-2024-11236
9.8 CRITICAL

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an …

Nov 24, 2024
CVE-2024-11234
4.8 MEDIUM

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, when using streams with configured proxy and "request_fulluri" option, the URI is not …

Nov 24, 2024
CVE-2024-35160
4.3 MEDIUM

IBM Watson Query on Cloud Pak for Data 1.8, 2.0, 2.1, 2.2 and IBM Db2 Big SQL on Cloud Pak for Data 7.3, 7.4, 7.5, …

Nov 23, 2024
CVE-2024-11632
7.3 HIGH

A vulnerability was found in code-projects Simple Car Rental System 1.0. It has been classified as critical. Affected is an unknown function of the file …

Nov 23, 2024
CVE-2023-7299
6.3 MEDIUM

A vulnerability was found in DataGear up to 4.60. It has been declared as critical. This vulnerability affects unknown code of the file /dataSet/resolveSql. The …

Nov 23, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.