CVE Database

10843+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-44097
9.8 CRITICAL

According to the researcher: "The TLS connections are encrypted against tampering or eavesdropping. However, the application does not validate the server certificate properly while initializing …

Oct 2, 2024
CVE-2024-35293
9.1 CRITICAL

An unauthenticated remote attacker may use a missing authentication for critical function vulnerability to reboot or erase the affected devices resulting in data loss and/or …

Oct 2, 2024
CVE-2024-45186
9.8 CRITICAL

FileSender before 2.49 allows server-side template injection (SSTI) for retrieving credentials.

Oct 2, 2024
CVE-2024-45999
9.8 CRITICAL

A SQL Injection vulnerability was discovered in Cloudlog 2.6.15, specifically within the get_station_info()function located in the file /application/models/Oqrs_model.php. The vulnerability is exploitable via the station_id …

Oct 1, 2024
CVE-2024-47608
9.8 CRITICAL

Logicytics is designed to harvest and collect data for forensic analysis. Logicytics has a basic vuln affecting compromised devices from shell injections. This vulnerability is …

Oct 1, 2024
CVE-2024-9402
9.8 CRITICAL

Memory safety bugs present in Firefox 130, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence of memory corruption and we presume …

Oct 1, 2024
CVE-2024-9401
9.8 CRITICAL

Memory safety bugs present in Firefox 130, Firefox ESR 115.15, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence of memory corruption …

Oct 1, 2024
CVE-2024-9392
9.8 CRITICAL

A compromised content process could have allowed for the arbitrary loading of cross-origin pages. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox …

Oct 1, 2024
CVE-2024-25660
9.0 CRITICAL

The WebDAV service in Infinera TNMS (Transcend Network Management System) 19.10.3 allows a low-privileged remote attacker to conduct unauthorized file operations, because of execution with …

Oct 1, 2024
CVE-2024-41276
9.8 CRITICAL

A vulnerability in Kaiten version 57.131.12 and earlier allows attackers to bypass the PIN code authentication mechanism. The application requires users to input a 6-digit …

Oct 1, 2024
CVE-2024-9289
9.8 CRITICAL

The WordPress & WooCommerce Affiliate Program plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 8.4.1. This is due …

Oct 1, 2024
CVE-2024-9265
9.8 CRITICAL

The Echo RSS Feed Post Generator plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.4.6. This is due …

Oct 1, 2024
CVE-2024-9108
9.8 CRITICAL

The Wechat Social login plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'convert_remoteimage_to_local' function in versions …

Oct 1, 2024
CVE-2024-9106
9.8 CRITICAL

The Wechat Social login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.3.0. This is due to insufficient verification …

Oct 1, 2024
CVE-2024-9194
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Linux and Microsoft Windows Octopus Server on Windows, Linux allows SQL …

Sep 30, 2024
CVE-2024-42017
10.0 CRITICAL

An issue was discovered in Atos Eviden iCare 2.7.1 through 2.7.11. The application exposes a web interface locally. In the worst-case scenario, if the application …

Sep 30, 2024
CVE-2024-46293
9.8 CRITICAL

Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Incorrect Access Control. There is a lack of authorization checks for admin operations. Specifically, an attacker …

Sep 30, 2024
CVE-2024-8456
9.8 CRITICAL

Certain switch models from PLANET Technology lack proper access control in firmware upload and download functionality, allowing unauthenticated remote attackers to download and upload firmware …

Sep 30, 2024
CVE-2024-8353
9.8 CRITICAL

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.16.1 …

Sep 28, 2024
CVE-2024-46256
9.8 CRITICAL

A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add Let's Encrypt Certificate.

Sep 27, 2024
CVE-2024-8630
9.4 CRITICAL

Alisonic Sibylla devices are vulnerable to SQL injection attacks, which could allow complete access to the database.

Sep 27, 2024
CVE-2024-8310
9.8 CRITICAL

OPW Fuel Management Systems SiteSentinel could allow an attacker to bypass authentication to the server and obtain full admin privileges.

Sep 27, 2024
CVE-2024-6981
9.8 CRITICAL

OMNTEC Proteus Tank Monitoring OEL8000III Series could allow an attacker to perform administrative actions without proper authentication.

Sep 27, 2024
CVE-2024-46367
9.6 CRITICAL

A Stored Cross-Site Scripting (XSS) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to inject arbitrary JavaScript code by submitting a malicious payload within …

Sep 27, 2024
CVE-2024-47070
9.0 CRITICAL

authentik is an open-source identity provider. A vulnerability that exists in versions prior to 2024.8.3 and 2024.6.5 allows bypassing password login by adding X-Forwarded-For header …

Sep 27, 2024
CVE-2024-8643
9.8 CRITICAL

Session Fixation vulnerability in Oceanic Software ValeApp allows Brute Force, Session Hijacking.This issue affects ValeApp: before v2.0.0.

Sep 27, 2024
CVE-2024-8607
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Oceanic Software ValeApp allows SQL Injection.This issue affects ValeApp: before v2.0.0.

Sep 27, 2024
CVE-2024-46628
9.8 CRITICAL

Tenda G3 Router firmware v15.03.05.05 was discovered to contain a remote code execution (RCE) vulnerability via the usbPartitionName parameter in the formSetUSBPartitionUmount function.

Sep 26, 2024
CVE-2024-46627
9.1 CRITICAL

Incorrect access control in BECN DATAGERRY v2.2 allows attackers to execute arbitrary commands via crafted web requests.

Sep 26, 2024
CVE-2024-7108
9.8 CRITICAL

Incorrect Authorization vulnerability in National Keep Cyber Security Services CyberMath allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects CyberMath: before CYBM.240816253.

Sep 26, 2024
CVE-2024-0132
9.0 CRITICAL

NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a specifically crafted container image may gain …

Sep 26, 2024
CVE-2024-7772
9.8 CRITICAL

The Jupiter X Core plugin for WordPress is vulnerable to arbitrary file uploads due to a mishandled file type validation in the 'validate' function in …

Sep 26, 2024
CVE-2024-6593
9.1 CRITICAL

Incorrect Authorization vulnerability in WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows allows an attacker with network access to execute restricted management commands. This …

Sep 25, 2024
CVE-2024-6592
9.1 CRITICAL

Incorrect Authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on …

Sep 25, 2024
CVE-2024-8275
9.8 CRITICAL

The The Events Calendar plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tribe_has_next_event' function in all versions up to, …

Sep 25, 2024
CVE-2024-8514
9.1 CRITICAL

The Prisna GWT – Google Website Translator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.11 via …

Sep 25, 2024
CVE-2024-7385
9.1 CRITICAL

The WordPress Simple HTML Sitemap plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 3.1 …

Sep 25, 2024
CVE-2024-8621
9.9 CRITICAL

The Daily Prayer Time plugin for WordPress is vulnerable to SQL Injection via the 'max_word' attribute of the 'quran_verse' shortcode in all versions up to, …

Sep 25, 2024
CVE-2024-8485
9.8 CRITICAL

The REST API TO MiniProgram plugin for WordPress is vulnerable to privilege escalation via account takeovr in all versions up to, and including, 4.7.1 via …

Sep 25, 2024
CVE-2024-9148
9.6 CRITICAL

Flowise < 2.1.1 suffers from a Stored Cross-Site vulnerability due to a lack of input sanitization in Flowise Chat Embed < 2.0.0.

Sep 25, 2024
CVE-2024-9142
9.8 CRITICAL

External Control of File Name or Path, : Incorrect Permission Assignment for Critical Resource vulnerability in Olgu Computer Systems e-Belediye allows Manipulating Web Input to …

Sep 25, 2024
CVE-2024-8940
10.0 CRITICAL

Vulnerability in the Scriptcase application version 9.4.019, which involves the arbitrary upload of a file via /scriptcase/devel/lib/third/jquery_plugin/jQuery-File-Upload/server/php/ via a POST request. An attacker could upload …

Sep 25, 2024
CVE-2024-8878
9.8 CRITICAL

The password recovery mechanism for the forgotten password in Riello Netman 204 allows an attacker to reset the admin password and take over control of …

Sep 25, 2024
CVE-2024-8877
9.8 CRITICAL

Improper neutralization of special elements results in a SQL Injection vulnerability in Riello Netman 204. It is only limited to the SQLite database of measurement …

Sep 25, 2024
CVE-2024-8436
9.9 CRITICAL

The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to SQL Injection via the 'edit_imageId' and 'edit_imageDelete' parameters in all versions …

Sep 25, 2024
CVE-2024-46957
9.8 CRITICAL

Mellium mellium.im/xmpp 0.0.1 through 0.21.4 allows response spoofing if the implementation uses predictable IDs because the stanza type is not checked. This is fixed in …

Sep 25, 2024
CVE-2024-46612
9.8 CRITICAL

IceCMS v3.4.7 and before was discovered to contain a hardcoded JWT key, allowing an attacker to forge JWT authentication information.

Sep 25, 2024
CVE-2024-45066
10.0 CRITICAL

A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE IP sub-menu can allow a remote attacker to inject arbitrary commands.

Sep 25, 2024
CVE-2024-43693
10.0 CRITICAL

A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE UTILITY sub-menu can allow a remote attacker to inject arbitrary commands.

Sep 25, 2024
CVE-2024-43692
9.8 CRITICAL

An attacker can directly request the ProGauge MAGLINK LX CONSOLE resource sub page with full privileges by requesting the URL directly.

Sep 25, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.