CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-53335
7.8 HIGH

TOTOLINK A810R V4.1.2cu.5182_B20201026 is vulnerable to Buffer Overflow in downloadFlile.cgi.

Nov 21, 2024
CVE-2024-53334
8.8 HIGH

TOTOLINK A810R V4.1.2cu.5182_B20201026 is vulnerable to Buffer Overflow in infostat.cgi.

Nov 21, 2024
CVE-2024-53333
6.3 MEDIUM

TOTOLINK EX200 v4.0.3c.7646_B20201211 was found to contain a command insertion vulnerability in the setUssd function. This vulnerability allows an attacker to execute arbitrary commands via …

Nov 21, 2024
CVE-2024-52309

SFTPGo is a full-featured and highly configurable SFTP, HTTP/S, FTP/S and WebDAV server - S3, Google Cloud Storage, Azure Blob. One powerful feature of SFTPGo …

Nov 21, 2024
CVE-2024-52307
5.6 MEDIUM

authentik is an open-source identity provider. Due to the usage of a non-constant time comparison for the /-/metrics/ endpoint it was possible to brute-force the …

Nov 21, 2024
CVE-2024-52289
9.8 CRITICAL

authentik is an open-source identity provider. Redirect URIs in the OAuth2 provider in authentik are checked by RegEx comparison. When no Redirect URIs are configured …

Nov 21, 2024
CVE-2024-52287
7.2 HIGH

authentik is an open-source identity provider. When using the client_credentials or device_code OAuth grants, it was possible for an attacker to get a token from …

Nov 21, 2024
CVE-2024-48288
8.0 HIGH

TP-Link TL-IPC42C V4.0_20211227_1.0.16 is vulnerable to command injection due to the lack of malicious code verification on both the frontend and backend.

Nov 21, 2024
CVE-2024-48286
8.0 HIGH

Linksys E3000 1.0.06.002_US is vulnerable to command injection via the diag_ping_start function.

Nov 21, 2024
CVE-2024-52803
7.5 HIGH

LLama Factory enables fine-tuning of large language models. A critical remote OS command injection vulnerability has been identified in the LLama Factory training process. This …

Nov 21, 2024
CVE-2024-52799
8.2 HIGH

Argo Workflows Chart is used to set up argo and its needed dependencies through one command. Prior to 0.44.0, the workflow-role has excessive privileges, the …

Nov 21, 2024
CVE-2024-49529
5.5 MEDIUM

InDesign Desktop versions 19.0, 20.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Nov 21, 2024
CVE-2024-45517
5.4 MEDIUM

An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A Cross-Site Scripting (XSS) vulnerability in the /h/rest endpoint of the Zimbra webmail and admin …

Nov 21, 2024
CVE-2024-45513
4.8 MEDIUM

An issue was discovered in Zimbra Collaboration (ZCS) through 10.1. A stored Cross-Site Scripting (XSS) vulnerability exists in the /modern/contacts/print endpoint of Zimbra webmail. This …

Nov 21, 2024
CVE-2024-45194
4.8 MEDIUM

In Zimbra Collaboration (ZCS) 9.0 and 10.0, a vulnerability in the Webmail Modern UI allows execution of stored Cross-Site Scripting (XSS) payloads. An attacker with …

Nov 21, 2024
CVE-2024-8526

A vulnerability in Automated Logic WebCTRL 7.0 could allow an attacker to send a maliciously crafted URL, which when visited by an authenticated WebCTRL user, …

Nov 21, 2024
CVE-2024-8525

An unrestricted upload of file with dangerous type in Automated Logic WebCTRL 7.0 could allow an unauthenticated user to perform remote command execution via a …

Nov 21, 2024
CVE-2024-45514
5.4 MEDIUM

An issue was discovered in Zimbra Collaboration (ZCS) through v10.1. A Cross-Site Scripting (XSS) vulnerability exists in one of the endpoints of Zimbra Webmail due …

Nov 21, 2024
CVE-2024-45512
5.4 MEDIUM

An issue was discovered in webmail in Zimbra Collaboration (ZCS) through 10.1. An attacker can exploit this vulnerability by creating a folder in the Briefcase …

Nov 21, 2024
CVE-2024-53429
7.5 HIGH

Open62541 v1.4.6 is has an assertion failure in fuzz_binary_decode, which leads to a crash.

Nov 21, 2024
CVE-2024-48747
6.8 MEDIUM

An issue in alist-tvbox v1.7.1 allows a remote attacker to execute arbitrary code via the /atv-cli file.

Nov 21, 2024
CVE-2024-29224
9.8 CRITICAL

An OS command injection vulnerability exists in the NAT parameter of GoCast 1.1.3. A specially crafted HTTP request can lead to arbitrary command execution. An …

Nov 21, 2024
CVE-2024-28892
9.8 CRITICAL

An OS command injection vulnerability exists in the name parameter of GoCast 1.1.3. A specially crafted HTTP request can lead to arbitrary command execution. An …

Nov 21, 2024
CVE-2024-28027
7.2 HIGH

Three OS command injection vulnerabilities exist in the web interface I/O configuration functionality of MC Technologies MC LR Router 2.10.5. A specially crafted HTTP request …

Nov 21, 2024
CVE-2024-28026
7.2 HIGH

Three OS command injection vulnerabilities exist in the web interface I/O configuration functionality of MC Technologies MC LR Router 2.10.5. A specially crafted HTTP request …

Nov 21, 2024
CVE-2024-28025
7.2 HIGH

Three OS command injection vulnerabilities exist in the web interface I/O configuration functionality of MC Technologies MC LR Router 2.10.5. A specially crafted HTTP request …

Nov 21, 2024
CVE-2024-21855
9.8 CRITICAL

A lack of authentication vulnerability exists in the HTTP API functionality of GoCast 1.1.3. A specially crafted HTTP request can lead to arbitrary command execution. …

Nov 21, 2024
CVE-2024-21786
7.2 HIGH

An OS command injection vulnerability exists in the web interface configuration upload functionality of MC Technologies MC LR Router 2.10.5. A specially crafted HTTP request …

Nov 21, 2024
CVE-2024-11592
7.3 HIGH

A vulnerability has been found in 1000 Projects Beauty Parlour Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file …

Nov 21, 2024
CVE-2024-7130
5.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kion Computer KION Exchange Programs Software allows Reflected XSS.This issue affects …

Nov 21, 2024
CVE-2024-7026
7.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Teknogis Informatics Closed Circuit Vehicle Tracking Software allows SQL Injection, Blind …

Nov 21, 2024
CVE-2024-53426
6.2 MEDIUM

A heap-buffer-overflow vulnerability has been identified in ntopng 6.2 in the Flow::dissectMDNS function.

Nov 21, 2024
CVE-2024-53425
6.2 MEDIUM

A heap-buffer-overflow vulnerability was discovered in the SkipSpacesAndLineEnd function in Assimp v5.4.3. This issue occurs when processing certain malformed MD5 model files, leading to an …

Nov 21, 2024
CVE-2024-11591
7.3 HIGH

A vulnerability, which was classified as critical, was found in 1000 Projects Beauty Parlour Management System 1.0. This affects an unknown part of the file …

Nov 21, 2024
CVE-2024-11089
5.3 MEDIUM

The Anonymous Restricted Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.5 via the WordPress core …

Nov 21, 2024
CVE-2024-11088
5.3 MEDIUM

The Simple Membership plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.5.5 via the WordPress core search …

Nov 21, 2024
CVE-2024-7016
4.8 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Smarttek Informatics Smart Doctor's allows Stored XSS required admin privileges.This issue …

Nov 21, 2024
CVE-2024-11590
7.3 HIGH

A vulnerability, which was classified as critical, has been found in 1000 Projects Bookstore Management System 1.0. Affected by this issue is some unknown functionality …

Nov 21, 2024
CVE-2024-11589
6.3 MEDIUM

A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /expcatedit.php. …

Nov 21, 2024
CVE-2024-11588
3.5 LOW

A vulnerability was found in AVL-DiTEST-DiagDev libdoip 1.0.0. It has been rated as problematic. This issue affects the function DoIPConnection::reactOnReceivedTcpMessage of the file DoIPConnection.cpp. The …

Nov 21, 2024
CVE-2024-11587
3.5 LOW

A vulnerability was found in idcCMS 1.60. It has been classified as problematic. This affects the function GetCityOptionJs of the file /inc/classProvCity.php. The manipulation of …

Nov 21, 2024
CVE-2024-9851
6.4 MEDIUM

The LSX Tour Operator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.4.9 …

Nov 21, 2024
CVE-2024-9828
4.1 MEDIUM

The Taskbuilder WordPress plugin before 3.0.5 does not sanitize user input into the 'load_orders' parameter and uses it in a SQL statement, allowing high privilege …

Nov 21, 2024
CVE-2024-9768
4.8 MEDIUM

The Formidable Forms WordPress plugin before 6.14.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Nov 21, 2024
CVE-2024-9600
4.8 MEDIUM

The Ditty WordPress plugin before 3.1.47 does not sanitise and escape some of its settings, which could allow high privilege users such as author to …

Nov 21, 2024
CVE-2024-9542
4.3 MEDIUM

The Sky Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.1 via the render …

Nov 21, 2024
CVE-2024-9442
6.4 MEDIUM

The F4 Improvements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.9.0 due …

Nov 21, 2024
CVE-2024-9371
6.1 MEDIUM

The Branda – White Label & Branding, Custom Login Page Customizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of …

Nov 21, 2024
CVE-2024-9111
6.4 MEDIUM

The Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.36 due …

Nov 21, 2024
CVE-2024-8157
4.3 MEDIUM

The Alphabetical List WordPress plugin through 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

Nov 21, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.