CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-45276
7.5 HIGH

An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication.

Oct 15, 2024
CVE-2024-45275
9.8 CRITICAL

The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full control of the affected devices.

Oct 15, 2024
CVE-2024-45274
9.8 CRITICAL

An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication.

Oct 15, 2024
CVE-2024-45273
8.4 HIGH

An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used.

Oct 15, 2024
CVE-2024-45272
7.5 HIGH

An unauthenticated remote attacker can perform a brute-force attack on the credentials of the remote service portal with a high chance of success, resulting in …

Oct 15, 2024
CVE-2024-45271
8.4 HIGH

An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation.

Oct 15, 2024
CVE-2024-9974
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Oct 15, 2024
CVE-2024-9973
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/?page=reports …

Oct 15, 2024
CVE-2024-47945
9.8 CRITICAL

The devices are vulnerable to session hijacking due to insufficient entropy in its session ID generation algorithm. The session IDs are predictable, with only 32,768 …

Oct 15, 2024
CVE-2024-9985
10.0 CRITICAL

Enterprise Cloud Database from Ragic does not properly validate the file type for uploads. Attackers with regular privileges can upload a webshell and use it …

Oct 15, 2024
CVE-2024-9984
9.8 CRITICAL

Enterprise Cloud Database from Ragic does not authenticate access to specific functionality, allowing unauthenticated remote attackers to use this functionality to obtain any user's session …

Oct 15, 2024
CVE-2024-9983
7.5 HIGH

Enterprise Cloud Database from Ragic does not properly validate a specific page parameter, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system …

Oct 15, 2024
CVE-2024-9925
9.8 CRITICAL

SQL injection vulnerability in TAI Smart Factory's QPLANT SF version 1.0. Exploitation of this vulnerability could allow a remote attacker to retrieve all database information …

Oct 15, 2024
CVE-2024-9895
6.4 MEDIUM

The Smart Online Order for Clover plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's moo_receipt_link shortcode in all versions up to, …

Oct 15, 2024
CVE-2024-47944
6.8 MEDIUM

The device directly executes .patch firmware upgrade files on a USB stick without any prior authentication in the admin interface. This leads to an unauthenticated …

Oct 15, 2024
CVE-2024-47943
9.8 CRITICAL

The firmware upgrade function in the admin web interface of the Rittal IoT Interface & CMC III Processing Unit devices checks if the patch files …

Oct 15, 2024
CVE-2024-9982
9.8 CRITICAL

AIM LINE Marketing Platform from Esi Technology does not properly validate a specific query parameter. When the LINE Campaign Module is enabled, unauthenticated remote attackers …

Oct 15, 2024
CVE-2024-9981
8.8 HIGH

The ee-class from FormosaSoft does not properly validate a specific page parameter, allowing remote attackers with regular privileges to upload a malicious PHP file first …

Oct 15, 2024
CVE-2024-9980
8.8 HIGH

The ee-class from FormosaSoft does not properly validate a specific page parameter, allowing remote attackers with regular privileges to inject arbitrary SQL commands to read, …

Oct 15, 2024
CVE-2024-9837
7.3 HIGH

The The AADMY – Add Auto Date Month Year Into Posts plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, …

Oct 15, 2024
CVE-2024-9972
9.8 CRITICAL

Property Management System from ChanGate has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database …

Oct 15, 2024
CVE-2024-46898
7.5 HIGH

SHIRASAGI prior to v1.19.1 processes URLs in HTTP requests improperly, resulting in a path traversal vulnerability. If this vulnerability is exploited, arbitrary files on the …

Oct 15, 2024
CVE-2024-9944
5.3 MEDIUM

The WooCommerce plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 9.0.2. This is due to the plugin not …

Oct 15, 2024
CVE-2024-0129
6.3 MEDIUM

NVIDIA NeMo contains a vulnerability in SaveRestoreConnector where a user may cause a path traversal issue via an unsafe .tar file extraction. A successful exploit …

Oct 15, 2024
CVE-2024-21535
6.1 MEDIUM

Versions of the package markdown-to-jsx before 7.4.0 are vulnerable to Cross-site Scripting (XSS) via the src property due to improper input sanitization. An attacker can …

Oct 15, 2024
CVE-2024-9971
8.8 HIGH

The specific query functionality in the FlowMaster BPM Plus from NewType does not properly restrict user input, allowing remote attackers with regular privileges to inject …

Oct 15, 2024
CVE-2024-9970
8.8 HIGH

The FlowMaster BPM Plus system from NewType has a privilege escalation vulnerability. Remote attackers with regular privileges can elevate their privileges to administrator by tampering …

Oct 15, 2024
CVE-2024-9969
5.4 MEDIUM

NewType WebEIP v3.0 does not properly validate user input, allowing a remote attacker with regular privileges to insert JavaScript into specific parameters, resulting in a …

Oct 15, 2024
CVE-2024-9968
8.8 HIGH

WebEIP v3.0 from NewType does not properly validate user input, allowing remote attackers with regular privilege to inject SQL commands to read, modify, and delete …

Oct 15, 2024
CVE-2024-9952
2.4 LOW

A vulnerability was found in SourceCodester Online Eyewear Shop 1.0 and classified as problematic. This issue affects some unknown processing of the file /admin/?page=system_info/contact_info of …

Oct 15, 2024
CVE-2024-9820
6.5 MEDIUM

The WP 2FA with Telegram plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in versions up to, and including, 3.0. This is due to …

Oct 15, 2024
CVE-2024-9687
8.8 HIGH

The WP 2FA with Telegram plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 3.0. This is due to insufficient …

Oct 15, 2024
CVE-2024-6757
4.3 MEDIUM

The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, …

Oct 15, 2024
CVE-2024-9548
7.2 HIGH

The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the resource parameter in all versions up to, and including, 5.2.6 due …

Oct 15, 2024
CVE-2024-9546
5.3 MEDIUM

The WPIDE – File Manager & Code Editor plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.4.9. …

Oct 15, 2024
CVE-2024-30117
2.5 LOW

A dynamic search for a prerequisite library could allow the possibility for an attacker to replace the correct file under some circumstances.

Oct 14, 2024
CVE-2024-9953
4.9 MEDIUM

A potential denial-of-service (DoS) vulnerability exists in CERT VINCE software versions prior to 3.0.8. An authenticated administrative user can inject an arbitrary pickle object into …

Oct 14, 2024
CVE-2024-35520
8.4 HIGH

Netgear R7000 1.0.11.136 is vulnerable to Command Injection in RMT_invite.cgi via device_name2 parameter.

Oct 14, 2024
CVE-2024-35519
8.4 HIGH

Netgear EX6120 v1.0.0.68, Netgear EX6100 v1.0.2.28, and Netgear EX3700 v1.0.0.96 are vulnerable to command injection in operating_mode.cgi via the ap_mode parameter.

Oct 14, 2024
CVE-2024-35518
8.4 HIGH

Netgear EX6120 v1.0.0.68 is vulnerable to Command Injection in genie_fix2.cgi via the wan_dns1_pri parameter.

Oct 14, 2024
CVE-2024-6207
7.5 HIGH

CVE 2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html and send a specially crafted CIP message to the device. If exploited, a threat actor could help prevent access to the legitimate …

Oct 14, 2024
CVE-2024-48911
7.8 HIGH

OpenCanary, a multi-protocol network honeypot, directly executed commands taken from its config file. Prior to version 0.9.4, where the config file is stored in an …

Oct 14, 2024
CVE-2024-48909
2.0 LOW

SpiceDB is an open source database for scalably storing and querying fine-grained authorization data. Starting in version 1.35.0 and prior to version 1.37.1, clients that …

Oct 14, 2024
CVE-2024-48824
7.5 HIGH

An issue in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a remote attacker to obtain sensitive information via the Racine & FileName parameters in the download-file.php …

Oct 14, 2024
CVE-2024-48823
9.8 CRITICAL

Local file inclusion in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a remote attacker to escalate privileges via the PassageAutoServer.php page.

Oct 14, 2024
CVE-2024-48822
8.8 HIGH

Privilege escalation in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a remote attacker to escalate privileges via the FtpConfig.php page.

Oct 14, 2024
CVE-2024-48821
6.1 MEDIUM

Cross Site Scripting vulnerability in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a remote attacker to escalate privileges via the FtpConfig.php component.

Oct 14, 2024
CVE-2024-47885
5.9 MEDIUM

The Astro web framework has a DOM Clobbering gadget in the client-side router starting in version 3.0.0 and prior to version 4.16.1. It can lead …

Oct 14, 2024
CVE-2023-48082
9.1 CRITICAL

Nagios XI before 2024R1 was discovered to improperly handle API keys generation (randomly-generated), allowing attackers to possibly generate the same set of API keys for …

Oct 14, 2024
CVE-2024-48795
5.3 MEDIUM

An issue in Creative Labs Pte Ltd com.creative.apps.xficonnect 2.00.02 allows a remote attacker to obtain sensitive information via the firmware update process.

Oct 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.