CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-47050
5.4 MEDIUM

Prior to this patch being applied, Mautic's tracking was vulnerable to Cross-Site Scripting through the Page URL variable.

Sep 18, 2024
CVE-2024-46377
9.8 CRITICAL

Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the save_settings() function of the file rental/admin_class.php.

Sep 18, 2024
CVE-2024-46376
9.8 CRITICAL

Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the update_account() function of the file rental/admin_class.php.

Sep 18, 2024
CVE-2024-46375
9.8 CRITICAL

Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the signup() function of the file rental/admin_class.php.

Sep 18, 2024
CVE-2024-46374
9.8 CRITICAL

Best House Rental Management System 1.0 contains a SQL injection vulnerability in the delete_category() function of the file rental/admin_class.php.

Sep 18, 2024
CVE-2024-46373
8.8 HIGH

Dedecms V5.7.115 contains an arbitrary code execution via file upload vulnerability in the backend.

Sep 18, 2024
CVE-2024-46372
6.1 MEDIUM

DedeCMS 5.7.115 is vulnerable to Cross Site Scripting (XSS) via the advertisement code box in the advertisement management module.

Sep 18, 2024
CVE-2024-40568
9.8 CRITICAL

Buffer Overflow vulnerability in btstack mesh commit before v.864e2f2b6b7878c8fab3cf5ee84ae566e3380c58 allows a remote attacker to execute arbitrary code via the pb_adv_handle_tranaction_cont function in the src/mesh/pb_adv.c component

Sep 18, 2024
CVE-2023-30464
7.5 HIGH

CoreDNS through 1.10.1 enables attackers to achieve DNS cache poisoning and inject fake responses via a birthday attack.

Sep 18, 2024
CVE-2022-25768
7.0 HIGH

The logic in place to facilitate the update process via the user interface lacks access control to verify if permission exists to perform the tasks. …

Sep 18, 2024
CVE-2024-44589
8.8 HIGH

Stack overflow vulnerability in the Login function in the HNAP service in D-Link DCS-960L with firmware 1.09 allows attackers to execute of arbitrary code.

Sep 18, 2024
CVE-2024-43025
6.1 MEDIUM

An HTML injection vulnerability in RWS MultiTrans v7.0.23324.2 and earlier allows attackers to alter the HTML-layout and possibly execute a phishing attack via a crafted …

Sep 18, 2024
CVE-2024-43024
6.1 MEDIUM

Multiple stored cross-site scripting (XSS) vulnerabilities in RWS MultiTrans v7.0.23324.2 and earlier allow attackers to execute arbitrary web scripts or HTML via a crafted payload.

Sep 18, 2024
CVE-2024-39339
7.5 HIGH

A vulnerability has been discovered in all versions of Smartplay headunits, which are widely used in Suzuki and Toyota cars. This misconfiguration can lead to …

Sep 18, 2024
CVE-2024-8287
7.5 HIGH

Anbox Management Service, in versions 1.17.0 through 1.23.0, does not validate the TLS certificate provided to it by the Anbox Stream Agent. An attacker must …

Sep 18, 2024
CVE-2024-34057
7.5 HIGH

Triangle Microworks TMW IEC 61850 Client source code libraries before 12.2.0 lack a buffer size check when processing received messages. The resulting buffer overflow can …

Sep 18, 2024
CVE-2024-46989
3.7 LOW

spicedb is an Open Source, Google Zanzibar-inspired permissions database to enable fine-grained authorization for customer applications. Multiple caveats over the same indirect subject type on …

Sep 18, 2024
CVE-2024-46987
7.7 HIGH

Camaleon CMS is a dynamic and advanced content management system based on Ruby on Rails. A path traversal vulnerability accessible via MediaController's download_private_file method allows …

Sep 18, 2024
CVE-2024-46986
9.9 CRITICAL

Camaleon CMS is a dynamic and advanced content management system based on Ruby on Rails. An arbitrary file write vulnerability accessible via the upload method …

Sep 18, 2024
CVE-2024-46979
5.3 MEDIUM

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to get access to notification filters …

Sep 18, 2024
CVE-2024-46978
6.5 MEDIUM

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible for any user knowing the ID …

Sep 18, 2024
CVE-2024-46959
6.5 MEDIUM

runofast Indoor Security Camera for Baby Monitor has a default password of password for the root account. This allows access to the /stream1 URI via …

Sep 18, 2024
CVE-2024-45601
7.5 HIGH

Mesop is a Python-based UI framework designed for rapid web apps development. A vulnerability has been discovered and fixed in Mesop that could potentially allow …

Sep 18, 2024
CVE-2024-45523
9.1 CRITICAL

An issue was discovered in Bravura Security Fabric versions 12.3.x before 12.3.5.32784, 12.4.x before 12.4.3.35110, 12.5.x before 12.5.2.35950, 12.6.x before 12.6.2.37183, and 12.7.x before 12.7.1.38241. …

Sep 18, 2024
CVE-2024-34399
9.8 CRITICAL

**UNSUPPORTED WHEN ASSIGNED** An issue was discovered in BMC Remedy Mid Tier 7.6.04. An unauthenticated remote attacker is able to access any user account without …

Sep 18, 2024
CVE-2023-41612
8.8 HIGH

Victure PC420 1.1.39 was discovered to use a weak encryption key for the file enabled_telnet.dat on the Micro SD card.

Sep 18, 2024
CVE-2023-41611
6.5 MEDIUM

Victure PC420 1.1.39 was discovered to use a weak and partially hardcoded key to encrypt data.

Sep 18, 2024
CVE-2023-41610
8.8 HIGH

Victure PC420 1.1.39 was discovered to contain a hardcoded root password which is stored in plaintext.

Sep 18, 2024
CVE-2024-46990
5.0 MEDIUM

Directus is a real-time API and App dashboard for managing SQL database content. When relying on blocking access to localhost using the default `0.0.0.0` filter …

Sep 18, 2024
CVE-2024-45813
5.3 MEDIUM

find-my-way is a fast, open source HTTP router, internally using a Radix Tree (aka compact Prefix Tree), supports route params, wildcards, and it's framework independent. …

Sep 18, 2024
CVE-2024-45298
4.3 MEDIUM

Wiki.js is an open source wiki app built on Node.js. A disabled user can still gain access to a wiki by abusing the password reset …

Sep 18, 2024
CVE-2023-47105
8.6 HIGH

exec.CommandContext in Chaosblade 0.3 through 1.7.3, when server mode is used, allows OS command execution via the cmd parameter without authentication.

Sep 18, 2024
CVE-2024-46086
8.8 HIGH

FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/delete/123

Sep 18, 2024
CVE-2022-25777
6.5 MEDIUM

Prior to the patched version, an authenticated user of Mautic could read system files and access the internal addresses of the application due to a …

Sep 18, 2024
CVE-2024-6878

Files or Directories Accessible to External Parties vulnerability in Eliz Software Panel allows Collect Data from Common Resource Locations.This issue affects Panel: before v2.3.24.

Sep 18, 2024
CVE-2024-6877
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Eliz Software Panel allows Reflected XSS.This issue affects Panel: before v2.3.24.

Sep 18, 2024
CVE-2024-5960
9.8 CRITICAL

Plaintext Storage of a Password vulnerability in Eliz Software Panel allows : Use of Known Domain Credentials.This issue affects Panel: before v2.3.24.

Sep 18, 2024
CVE-2024-5959
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Eliz Software Panel allows Stored XSS.This issue affects Panel: before v2.3.24.

Sep 18, 2024
CVE-2024-5958
8.8 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eliz Software Panel allows Command Line Execution through SQL Injection.This issue …

Sep 18, 2024
CVE-2024-46598
7.5 HIGH

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the iprofileidx parameter at dialin.cgi. This vulnerability allows attackers to cause a Denial …

Sep 18, 2024
CVE-2024-46597
7.5 HIGH

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sPubKey parameter at dialin.cgi. This vulnerability allows attackers to cause a Denial …

Sep 18, 2024
CVE-2024-46596
7.5 HIGH

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sAct parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial …

Sep 18, 2024
CVE-2024-46595
7.5 HIGH

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the saveitem parameter at lan2lan.cgi. This vulnerability allows attackers to cause a Denial …

Sep 18, 2024
CVE-2024-46594
7.5 HIGH

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the saveVPNProfile parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial …

Sep 18, 2024
CVE-2024-46593
7.5 HIGH

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the trapcomm parameter at cgiswm.cgi. This vulnerability allows attackers to cause a Denial …

Sep 18, 2024
CVE-2024-46592
7.5 HIGH

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the ssidencrypt_5g%d parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial …

Sep 18, 2024
CVE-2024-46591
7.5 HIGH

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sDnsPro parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial …

Sep 18, 2024
CVE-2024-46590
7.5 HIGH

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the ssidencrypt%d parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial …

Sep 18, 2024
CVE-2024-46589
7.5 HIGH

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sIpv6AiccuUser parameter at inetipv6.cgi. This vulnerability allows attackers to cause a Denial …

Sep 18, 2024
CVE-2024-46588
7.5 HIGH

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sProfileName parameter at wizfw.cgi. This vulnerability allows attackers to cause a Denial …

Sep 18, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.