CVE Database

10843+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-9465
9.1 CRITICAL KEV

An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, …

Oct 9, 2024
CVE-2024-45746
9.8 CRITICAL

An issue was discovered in Trusted Firmware-M through 2.1.0. User provided (and controlled) mailbox messages contain a pointer to a list of input arguments (in_vec) …

Oct 9, 2024
CVE-2024-25825
9.8 CRITICAL

FydeOS for PC 17.1 R114, FydeOS for VMware 17.0 R114, FydeOS for You 17.1 R114, and OpenFyde R114 were discovered to be configured with the …

Oct 9, 2024
CVE-2024-8015
9.1 CRITICAL

In Progress Telerik Report Server versions prior to 2024 Q3 (10.2.24.924), a remote code execution attack is possible through object injection via an insecure type …

Oct 9, 2024
CVE-2024-9680
9.8 CRITICAL KEV

An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this …

Oct 9, 2024
CVE-2023-46586
9.1 CRITICAL

cgi.c in weborf .0.17, 0.18, 0.19, and 0.20 (before 1.0) lacks '\0' termination of the path for CGI scripts because strncpy is misused.

Oct 9, 2024
CVE-2024-45160
9.1 CRITICAL

Incorrect credential validation in LemonLDAP::NG 2.18.x and 2.19.x before 2.19.2 allows attackers to bypass OAuth2 client authentication via an empty client_password parameter (client secret).

Oct 9, 2024
CVE-2024-32608
9.8 CRITICAL

HDF5 library through 1.14.3 has memory corruption in H5A__close resulting in the corruption of the instruction pointer and causing denial of service or potential code …

Oct 9, 2024
CVE-2024-47823
9.8 CRITICAL

Livewire is a full-stack framework for Laravel that allows for dynamic UI components without leaving PHP. In livewire/livewire prior to `2.12.7` and `v3.5.2`, the file …

Oct 8, 2024
CVE-2024-43468
9.8 CRITICAL KEV

Microsoft Configuration Manager Remote Code Execution Vulnerability

Oct 8, 2024
CVE-2024-38124
9.0 CRITICAL

Windows Netlogon Elevation of Privilege Vulnerability

Oct 8, 2024
CVE-2024-45918
9.8 CRITICAL

Fujian Kelixin Communication Command and Dispatch Platform <=7.6.6.4391 is vulnerable to SQL Injection via /client/get_gis_fence.php.

Oct 8, 2024
CVE-2024-44349
9.8 CRITICAL

A SQL injection vulnerability in login portal in AnteeoWMS before v4.7.34 allows unauthenticated attackers to execute arbitrary SQL commands via the username parameter and disclosure …

Oct 8, 2024
CVE-2024-3057
9.8 CRITICAL

A flaw exists whereby a user can make a specific call to a FlashArray endpoint allowing privilege escalation.

Oct 8, 2024
CVE-2024-8884
9.8 CRITICAL

CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause exposure of credentials when attacker has access to application on network …

Oct 8, 2024
CVE-2024-8943
9.8 CRITICAL

The LatePoint plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.0.12. This is due to insufficient verification on the …

Oct 8, 2024
CVE-2024-8911
9.8 CRITICAL

The LatePoint plugin for WordPress is vulnerable to Arbitrary User Password Change via SQL Injection in versions up to, and including, 5.0.11. This is due …

Oct 8, 2024
CVE-2024-47553
9.9 CRITICAL

A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate user input to the ```ssmctl-client``` …

Oct 8, 2024
CVE-2024-41798
9.8 CRITICAL

A vulnerability has been identified in SENTRON 7KM PAC3200 (All versions). Affected devices only provide a 4-digit PIN to protect from administrative access via Modbus …

Oct 8, 2024
CVE-2024-45874
9.8 CRITICAL

A DLL hijacking vulnerability in VegaBird Vooki 5.2.9 allows attackers to execute arbitrary code / maintain persistence via placing a crafted DLL file in the …

Oct 7, 2024
CVE-2024-45873
9.8 CRITICAL

A DLL hijacking vulnerability in VegaBird Yaazhini 2.0.2 allows attackers to execute arbitrary code / maintain persistence via placing a crafted DLL file in the …

Oct 7, 2024
CVE-2024-46076
9.8 CRITICAL

RuoYi v4.7.9 and before has a security flaw that allows escaping from comments within the code generation feature, enabling the injection of malicious code.

Oct 7, 2024
CVE-2024-46446
9.8 CRITICAL

Mecha CMS 3.0.0 is vulnerable to Directory Traversal. An attacker can construct cookies and URIs that bypass user identity checks. Parameters can then be passed …

Oct 7, 2024
CVE-2024-9574
9.8 CRITICAL

SQL injection vulnerability in SOPlanning <1.45, via /soplanning/www/user_groupes.php in the by parameter, which could allow a remote user to submit a specially crafted query, allowing …

Oct 7, 2024
CVE-2024-33066
9.8 CRITICAL

Memory corruption while redirecting log file to any file location with any file name.

Oct 7, 2024
CVE-2024-20103
9.8 CRITICAL

In wlan firmware, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no …

Oct 7, 2024
CVE-2024-20101
9.8 CRITICAL

In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no …

Oct 7, 2024
CVE-2024-20100
9.8 CRITICAL

In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no …

Oct 7, 2024
CVE-2024-47350
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YITHEMES YITH WooCommerce Ajax Search yith-woocommerce-ajax-search.This issue affects YITH WooCommerce Ajax …

Oct 6, 2024
CVE-2024-45252
9.8 CRITICAL

Elsight – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Oct 6, 2024
CVE-2024-45251
9.8 CRITICAL

Elsight – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Oct 6, 2024
CVE-2024-45249
9.8 CRITICAL

Cavok – CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Oct 6, 2024
CVE-2024-44014
9.6 CRITICAL

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Vmax Studio Vmax Project Manager vmax-project-manager allows PHP Local File Inclusion.This issue …

Oct 5, 2024
CVE-2024-47849
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in The Wikimedia Foundation Mediawiki - Cargo allows SQL Injection.This issue affects …

Oct 5, 2024
CVE-2024-43685
9.8 CRITICAL

Improper Authentication vulnerability in Microchip TimeProvider 4100 (login modules) allows Session Hijacking.This issue affects TimeProvider 4100: from 1.0 before 2.4.7.

Oct 4, 2024
CVE-2023-26770
9.8 CRITICAL

TaskCafe 0.3.2 lacks validation in the Cookie value. Any unauthenticated attacker who knows a registered UserID can change the password of that user.

Oct 4, 2024
CVE-2024-47656
9.8 CRITICAL

This vulnerability exists in Shilpi Client Dashboard due to missing restrictions for incorrect login attempts on its API based login. A remote attacker could exploit …

Oct 4, 2024
CVE-2024-45367
9.1 CRITICAL

The web server for ONS-S8 - Spectra Aggregation Switch includes an incomplete authentication process, which can lead to an attacker authenticating without a password.

Oct 3, 2024
CVE-2024-43699
9.8 CRITICAL

Delta Electronics DIAEnergie is vulnerable to an SQL injection in the script AM_RegReport.aspx. An unauthenticated attacker may be able to exploit this issue to obtain …

Oct 3, 2024
CVE-2024-41925
9.8 CRITICAL

The web service for ONS-S8 - Spectra Aggregation Switch includes functions which do not properly validate user input, allowing an attacker to traverse directories, bypass …

Oct 3, 2024
CVE-2024-41593
9.8 CRITICAL

DrayTek Vigor310 devices through 4.3.2.6 allow a remote attacker to execute arbitrary code via the function ft_payload_dns(), because a byte sign-extension operation occurs for the …

Oct 3, 2024
CVE-2024-7826
9.8 CRITICAL

Improper Check for Unusual or Exceptional Conditions vulnerability in Webroot SecureAnywhere - Web Shield on Windows, ARM, 64 bit, 32 bit (wrURL.Dll modules) allows Functionality …

Oct 3, 2024
CVE-2024-7825
9.8 CRITICAL

Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Webroot SecureAnywhere - Web Shield on Windows, ARM, 64 bit, 32 bit (wrUrl.Dll modules) allows …

Oct 3, 2024
CVE-2024-7824
9.8 CRITICAL

Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Webroot SecureAnywhere - Web Shield on Windows, ARM, 64 bit, 32 bit (wrUrl.Dll modules) allows …

Oct 3, 2024
CVE-2024-45519
10.0 CRITICAL KEV

The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1 sometimes allows …

Oct 2, 2024
CVE-2024-24117
9.8 CRITICAL

Insecure Permissions vulnerability in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release (9736) allows a remote attacker to gain privileges via the login check state component.

Oct 2, 2024
CVE-2024-9441
9.8 CRITICAL

The Linear eMerge e3-Series through version 1.00-07 is vulnerable to an OS command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary OS commands …

Oct 2, 2024
CVE-2024-24116
9.8 CRITICAL

An issue in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release(9736) allows a remote attacker to gain privileges via the system/config_menu.htm.

Oct 2, 2024
CVE-2024-20432
9.9 CRITICAL

A vulnerability in the REST API and web UI of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, low-privileged, remote attacker to perform …

Oct 2, 2024
CVE-2024-6360
9.8 CRITICAL

Incorrect Permission Assignment for Critical Resource vulnerability in OpenText™ Vertica could allow Privilege Abuse and result in unauthorized access or privileges to Vertica agent apikey. …

Oct 2, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.