CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-46586
7.5 HIGH

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sCloudPass parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial …

Sep 18, 2024
CVE-2024-46585
7.5 HIGH

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sProfileName parameter at usergrp.cgi. This vulnerability allows attackers to cause a Denial …

Sep 18, 2024
CVE-2024-46584
7.5 HIGH

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the AControlIp1 parameter at acontrol.cgi. This vulnerability allows attackers to cause a Denial …

Sep 18, 2024
CVE-2024-46583
7.5 HIGH

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the extRadSrv2 parameter at cgiapp.cgi. This vulnerability allows attackers to cause a Denial …

Sep 18, 2024
CVE-2024-46582
7.5 HIGH

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sSrvAddr parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial …

Sep 18, 2024
CVE-2024-46581
7.5 HIGH

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sProfName parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial …

Sep 18, 2024
CVE-2024-46580
7.5 HIGH

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the fid parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial …

Sep 18, 2024
CVE-2024-46571
7.5 HIGH

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sPPPSrvNm parameter at fwuser.cgi. This vulnerability allows attackers to cause a Denial …

Sep 18, 2024
CVE-2024-46568
7.5 HIGH

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sPeerId parameter at vpn.cgi. This vulnerability allows attackers to cause a Denial …

Sep 18, 2024
CVE-2024-46567
7.5 HIGH

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the iProfileIdx parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial …

Sep 18, 2024
CVE-2024-46566
7.5 HIGH

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sAppName parameter at sslapp.cgi. This vulnerability allows attackers to cause a Denial …

Sep 18, 2024
CVE-2024-46565
7.5 HIGH

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sSrvName parameter at service.cgi. This vulnerability allows attackers to cause a Denial …

Sep 18, 2024
CVE-2024-46564
7.5 HIGH

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sProfileName parameter at fextobj.cgi. This vulnerability allows attackers to cause a Denial …

Sep 18, 2024
CVE-2024-46561
7.5 HIGH

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the queryret parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial …

Sep 18, 2024
CVE-2024-46560
7.5 HIGH

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the pub_key parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial …

Sep 18, 2024
CVE-2024-46559
7.5 HIGH

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sBPA_UsrNme parameter at inet15.cgi. This vulnerability allows attackers to cause a Denial …

Sep 18, 2024
CVE-2024-46558
7.5 HIGH

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the newProname parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial …

Sep 18, 2024
CVE-2024-46557
7.5 HIGH

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sProfileName parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial …

Sep 18, 2024
CVE-2024-46556
7.5 HIGH

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sInRCSecret0 parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial …

Sep 18, 2024
CVE-2024-46555
7.5 HIGH

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the pb parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial …

Sep 18, 2024
CVE-2024-46554
7.5 HIGH

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the profname parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial …

Sep 18, 2024
CVE-2024-46553
7.5 HIGH

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the ipaddrmsk%d parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial …

Sep 18, 2024
CVE-2024-46552
7.5 HIGH

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sStRtMskShow parameter at ipstrt.cgi. This vulnerability allows attackers to cause a Denial …

Sep 18, 2024
CVE-2024-46551
7.5 HIGH

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sBPA_Pwd parameter at inet15.cgi. This vulnerability allows attackers to cause a Denial …

Sep 18, 2024
CVE-2024-46550
7.5 HIGH

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the CGIbyFieldName parameter at chglog.cgi. This vulnerability allows attackers to cause a Denial …

Sep 18, 2024
CVE-2024-45858
7.8 HIGH

An arbitrary code execution vulnerability exists in versions 0.2.9 up to 0.5.10 of the Guardrails AI Guardrails framework because of the way it validates XML …

Sep 18, 2024
CVE-2024-44542
9.8 CRITICAL

SQL Injection vulnerability in todesk v.1.1 allows a remote attacker to execute arbitrary code via the /todesk.com/news.html parameter.

Sep 18, 2024
CVE-2024-39590
7.5 HIGH

Multiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC_v3 16bf8bac1a36d95b73e7b8722d0edb8b9c5bb56a. A specially crafted EtherNet/IP request can lead to denial …

Sep 18, 2024
CVE-2024-39589
7.5 HIGH

Multiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC_v3 16bf8bac1a36d95b73e7b8722d0edb8b9c5bb56a. A specially crafted EtherNet/IP request can lead to denial …

Sep 18, 2024
CVE-2024-36981
7.5 HIGH

An out-of-bounds read vulnerability exists in the OpenPLC Runtime EtherNet/IP PCCC parser functionality of OpenPLC_v3 b4702061dc14d1024856f71b4543298d77007b88. A specially crafted network request can lead to denial …

Sep 18, 2024
CVE-2024-36980
7.5 HIGH

An out-of-bounds read vulnerability exists in the OpenPLC Runtime EtherNet/IP PCCC parser functionality of OpenPLC_v3 b4702061dc14d1024856f71b4543298d77007b88. A specially crafted network request can lead to denial …

Sep 18, 2024
CVE-2024-35515
9.8 CRITICAL

Insecure deserialization in sqlitedict up to v2.1.0 allows attackers to execute arbitrary code.

Sep 18, 2024
CVE-2024-34026
9.0 CRITICAL

A stack-based buffer overflow vulnerability exists in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC _v3 b4702061dc14d1024856f71b4543298d77007b88. A specially crafted EtherNet/IP request can lead to …

Sep 18, 2024
CVE-2023-49203
7.5 HIGH

Technitium 11.5.3 allows remote attackers to cause a denial of service (bandwidth amplification) because the DNSBomb manipulation causes accumulation of low-rate DNS queries such that …

Sep 18, 2024
CVE-2023-28457
7.5 HIGH

An issue was discovered in Technitium through 11.0.3. It enables attackers to conduct a DNS cache poisoning attack and inject fake responses within 1 second, …

Sep 18, 2024
CVE-2023-28456
7.5 HIGH

An issue was discovered in Technitium through 11.0.2. It enables attackers to launch amplification attacks (3 times more than other "golden model" software like BIND) …

Sep 18, 2024
CVE-2023-28455
7.5 HIGH

An issue was discovered in Technitium through 11.0.2. The forwarding mode enables attackers to create a query loop using Technitium resolvers, launching amplification attacks and …

Sep 18, 2024
CVE-2023-28452
7.5 HIGH

An issue was discovered in CoreDNS through 1.10.1. There is a vulnerability in DNS resolving software, which triggers a resolver to ignore valid responses, thus …

Sep 18, 2024
CVE-2023-28451
7.5 HIGH

An issue was discovered in Technitium 11.0.2. There is a vulnerability (called BadDNS) in DNS resolving software, which triggers a resolver to ignore valid responses, …

Sep 18, 2024
CVE-2022-25776
8.3 HIGH

Prior to the patched version, logged in users of Mautic are able to access areas of the application that they should be prevented from accessing. …

Sep 18, 2024
CVE-2022-25775
6.6 MEDIUM

Prior to the patched version, logged in users of Mautic are vulnerable to an SQL injection vulnerability in the Reports bundle. The user could retrieve …

Sep 18, 2024
CVE-2022-25774
4.8 MEDIUM

Prior to the patched version, logged in users of Mautic are vulnerable to a self XSS vulnerability in the notifications within Mautic. Users could inject …

Sep 18, 2024
CVE-2022-25769
7.2 HIGH

ImpactThe default .htaccess file has some restrictions in the access to PHP files to only allow specific PHP files to be executed in the root …

Sep 18, 2024
CVE-2024-8891
5.3 MEDIUM

An attacker with no knowledge of the current users in the web application, could build a dictionary of potential users and check the server responses …

Sep 18, 2024
CVE-2024-39081
4.2 MEDIUM

An issue in SMART TYRE CAR & BIKE v4.2.0 allows attackers to perform a man-in-the-middle attack via Bluetooth communications.

Sep 18, 2024
CVE-2024-31198
5.3 MEDIUM

Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of10::Port:unpack. This issue affects libfluid: 0.1.0.

Sep 18, 2024
CVE-2024-31197
5.3 MEDIUM

Improper Null Termination vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of10::Port:unpack. This issue affects libfluid: 0.1.0.

Sep 18, 2024
CVE-2024-31196
5.3 MEDIUM

Unchecked Return Value to NULL Pointer Dereference vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::ActionList::unpack10. This …

Sep 18, 2024
CVE-2024-31195
6.5 MEDIUM

Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of13::MultipartReplyTable::unpack. This issue affects libfluid: 0.1.0.

Sep 18, 2024
CVE-2024-31194
6.5 MEDIUM

Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of13::MultipartReplyPortStats::unpack. This issue affects libfluid: 0.1.0.

Sep 18, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.