CVE Database

10843+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-43423
9.8 CRITICAL

The web application for ProGauge MAGLINK LX4 CONSOLE contains an administrative-level user account with a password that cannot be changed.

Sep 25, 2024
CVE-2024-42797
9.8 CRITICAL

An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_playlist in Kashipara Music Management System v1.0. This vulnerability allows an unauthenticated attacker to delete the valid …

Sep 25, 2024
CVE-2024-42507
9.8 CRITICAL

Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's …

Sep 25, 2024
CVE-2024-42506
9.8 CRITICAL

Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's …

Sep 25, 2024
CVE-2024-42505
9.8 CRITICAL

Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's …

Sep 25, 2024
CVE-2023-26689
9.8 CRITICAL

An issue discovered in CS-Cart MultiVendor 4.16.1 allows attackers to alter arbitrary user account profiles via crafted post request.

Sep 25, 2024
CVE-2023-26686
9.8 CRITICAL

File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via the image upload feature when customizing a shop.

Sep 25, 2024
CVE-2024-8791
9.8 CRITICAL

The Donation Forms by Charitable – Donations Plugin & Fundraising Platform for WordPress plugin for WordPress is vulnerable to privilege escalation in all versions up …

Sep 24, 2024
CVE-2024-8671
9.1 CRITICAL

The WooEvents - Calendar and Event Booking plugin for WordPress is vulnerable to arbitrary file overwrite due to insufficient file path validation in the inc/barcode.php …

Sep 24, 2024
CVE-2024-8624
9.9 CRITICAL

The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to SQL Injection via the 'meta_key' attribute of the 'mdf_select_title' shortcode in …

Sep 24, 2024
CVE-2024-7024
9.6 CRITICAL

Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. …

Sep 23, 2024
CVE-2024-47222
9.8 CRITICAL

New Cloud MyOffice SDK Collaborative Editing Server 2.2.2 through 2.8 allows SSRF via manipulation of requests from external document storage via the MS-WOPI protocol.

Sep 23, 2024
CVE-2024-0005
9.1 CRITICAL

A condition exists in FlashArray and FlashBlade Purity whereby a malicious user could execute arbitrary commands remotely through a specifically crafted SNMP configuration.

Sep 23, 2024
CVE-2024-0004
9.1 CRITICAL

A condition exists in FlashArray Purity whereby an user with array admin role can execute arbitrary commands remotely to escalate privilege on the array.

Sep 23, 2024
CVE-2024-0003
9.1 CRITICAL

A condition exists in FlashArray Purity whereby a malicious user could use a remote administrative service to create an account on the array allowing privileged …

Sep 23, 2024
CVE-2024-0002
10.0 CRITICAL

A condition exists in FlashArray Purity whereby an attacker can employ a privileged account allowing remote access to the array.

Sep 23, 2024
CVE-2024-0001
10.0 CRITICAL

A condition exists in FlashArray Purity whereby a local account intended for initial array configuration remains active potentially allowing a malicious actor to gain elevated …

Sep 23, 2024
CVE-2024-9014
9.9 CRITICAL

pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID …

Sep 23, 2024
CVE-2024-47066
9.0 CRITICAL

Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.19.13, server-side request forgery protection implemented in `src/app/api/proxy/route.ts` does not consider redirect and …

Sep 23, 2024
CVE-2024-46997
9.8 CRITICAL

DataEase is an open source data visualization analysis tool. Prior to version 2.10.1, an attacker can achieve remote command execution by adding a carefully constructed …

Sep 23, 2024
CVE-2024-34331
9.8 CRITICAL

A lack of code signature verification in Parallels Desktop for Mac v19.3.0 and below allows attackers to escalate privileges via a crafted macOS installer, because …

Sep 23, 2024
CVE-2024-47219
9.8 CRITICAL

An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows shell command injection.

Sep 22, 2024
CVE-2024-47218
9.8 CRITICAL

An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows bypassing authentication.

Sep 22, 2024
CVE-2024-46640
9.8 CRITICAL

SeaCMS 13.2 has a remote code execution vulnerability located in the file sql.class.chp. Although the system has a check function, the check function is not …

Sep 20, 2024
CVE-2024-46103
9.8 CRITICAL

SEMCMS 4.8 is vulnerable to SQL Injection via SEMCMS_Main.php.

Sep 20, 2024
CVE-2024-46101
9.8 CRITICAL

GDidees CMS <= v3.9.1 has a file upload vulnerability.

Sep 20, 2024
CVE-2024-45489
9.8 CRITICAL

Arc before 2024-08-26 allows remote code execution in JavaScript boosts. Boosts that run JavaScript cannot be shared by default; however (because of misconfigured Firebase ACLs), …

Sep 20, 2024
CVE-2024-46652
9.8 CRITICAL

Tenda AC8v4 V16.03.34.06 has a stack overflow vulnerability in the fromAdvSetMacMtuWan function.

Sep 20, 2024
CVE-2024-9043
9.8 CRITICAL

Secure Email Gateway from Cellopoint has Buffer Overflow Vulnerability in authentication process. Remote unauthenticated attackers can send crafted packets to crash the process, thereby bypassing …

Sep 20, 2024
CVE-2024-8853
9.8 CRITICAL

The Webo-facto plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.40 due to insufficient restriction on the 'doSsoAuthentification' function. …

Sep 20, 2024
CVE-2024-46983
9.8 CRITICAL

sofa-hessian is an internal improved version of Hessian3/4 powered by Ant Group CO., Ltd. The SOFA Hessian protocol uses a blacklist mechanism to restrict deserialization …

Sep 19, 2024
CVE-2024-45410
9.8 CRITICAL

Traefik is a golang, Cloud Native Application Proxy. When a HTTP request is processed by Traefik, certain HTTP headers such as X-Forwarded-Host or X-Forwarded-Port are …

Sep 19, 2024
CVE-2023-27584
9.8 CRITICAL

Dragonfly is an open source P2P-based file distribution and image acceleration system. It is hosted by the Cloud Native Computing Foundation (CNCF) as an Incubating …

Sep 19, 2024
CVE-2024-40125
9.8 CRITICAL

An arbitrary file upload vulnerability in the Media Manager function of Closed-Loop Technology CLESS Server v4.5.2 allows attackers to execute arbitrary code via uploading a …

Sep 19, 2024
CVE-2024-33109
9.9 CRITICAL

Directory Traversal in the web interface of the Tiptel IP 286 with firmware version 2.61.13.10 allows attackers to overwrite arbitrary files on the phone via …

Sep 19, 2024
CVE-2024-8963
9.4 CRITICAL KEV

Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.

Sep 19, 2024
CVE-2024-31570
9.8 CRITICAL

libfreeimage in FreeImage 3.4.0 through 3.18.0 has a stack-based buffer overflow in the PluginXPM.cpp Load function via an XPM file.

Sep 19, 2024
CVE-2024-47088
9.8 CRITICAL

This vulnerability exists in Apex Softcell LD Geo due to missing restrictions for excessive failed authentication attempts on its API based login. A remote attacker …

Sep 19, 2024
CVE-2024-46946
9.8 CRITICAL

langchain_experimental (aka LangChain Experimental) 0.1.17 through 0.3.0 for LangChain allows attackers to execute arbitrary code through sympy.sympify (which uses eval) in LLMSymbolicMathChain. LLMSymbolicMathChain was introduced …

Sep 19, 2024
CVE-2024-46377
9.8 CRITICAL

Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the save_settings() function of the file rental/admin_class.php.

Sep 18, 2024
CVE-2024-46376
9.8 CRITICAL

Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the update_account() function of the file rental/admin_class.php.

Sep 18, 2024
CVE-2024-46375
9.8 CRITICAL

Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the signup() function of the file rental/admin_class.php.

Sep 18, 2024
CVE-2024-46374
9.8 CRITICAL

Best House Rental Management System 1.0 contains a SQL injection vulnerability in the delete_category() function of the file rental/admin_class.php.

Sep 18, 2024
CVE-2024-40568
9.8 CRITICAL

Buffer Overflow vulnerability in btstack mesh commit before v.864e2f2b6b7878c8fab3cf5ee84ae566e3380c58 allows a remote attacker to execute arbitrary code via the pb_adv_handle_tranaction_cont function in the src/mesh/pb_adv.c component

Sep 18, 2024
CVE-2024-46986
9.9 CRITICAL

Camaleon CMS is a dynamic and advanced content management system based on Ruby on Rails. An arbitrary file write vulnerability accessible via the upload method …

Sep 18, 2024
CVE-2024-45523
9.1 CRITICAL

An issue was discovered in Bravura Security Fabric versions 12.3.x before 12.3.5.32784, 12.4.x before 12.4.3.35110, 12.5.x before 12.5.2.35950, 12.6.x before 12.6.2.37183, and 12.7.x before 12.7.1.38241. …

Sep 18, 2024
CVE-2024-34399
9.8 CRITICAL

**UNSUPPORTED WHEN ASSIGNED** An issue was discovered in BMC Remedy Mid Tier 7.6.04. An unauthenticated remote attacker is able to access any user account without …

Sep 18, 2024
CVE-2024-5960
9.8 CRITICAL

Plaintext Storage of a Password vulnerability in Eliz Software Panel allows : Use of Known Domain Credentials.This issue affects Panel: before v2.3.24.

Sep 18, 2024
CVE-2024-44542
9.8 CRITICAL

SQL Injection vulnerability in todesk v.1.1 allows a remote attacker to execute arbitrary code via the /todesk.com/news.html parameter.

Sep 18, 2024
CVE-2024-35515
9.8 CRITICAL

Insecure deserialization in sqlitedict up to v2.1.0 allows attackers to execute arbitrary code.

Sep 18, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.