CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-37992
4.9 MEDIUM

A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6BC10-0AA0) (All versions < V4.2), SIMATIC …

Sep 10, 2024
CVE-2024-37991
5.3 MEDIUM

A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6BC10-0AA0) (All versions < V4.2), SIMATIC …

Sep 10, 2024
CVE-2024-37990
6.5 MEDIUM

A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6BC10-0AA0) (All versions < V4.2), SIMATIC …

Sep 10, 2024
CVE-2024-35783
9.1 CRITICAL

A vulnerability has been identified in SIMATIC BATCH V9.1 (All versions), SIMATIC Information Server 2020 (All versions < V2020 SP2 Update 5), SIMATIC Information Server …

Sep 10, 2024
CVE-2024-33698
9.8 CRITICAL

A vulnerability has been identified in Opcenter Quality (All versions < V2406), Opcenter RDnL (All versions < V2410), SIMATIC PCS neo V4.0 (All versions), SIMATIC …

Sep 10, 2024
CVE-2024-32006
4.3 MEDIUM

A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 SP2). The affected application does not expire the user session on …

Sep 10, 2024
CVE-2023-49069
5.3 MEDIUM

A vulnerability has been identified in Mendix Runtime V10 (All versions < V10.17.0 only if the basic authentication mechanism is used by the application), Mendix …

Sep 10, 2024
CVE-2023-30756
5.9 MEDIUM

A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 (incl. SIPLUS variants) (All versions …

Sep 10, 2024
CVE-2023-30755
4.4 MEDIUM

A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 (incl. SIPLUS variants) (All versions …

Sep 10, 2024
CVE-2023-2919
4.3 MEDIUM

The Tutor LMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.4. This is due to missing or …

Sep 10, 2024
CVE-2023-28827
5.9 MEDIUM

A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 (incl. SIPLUS variants) (All versions …

Sep 10, 2024
CVE-2024-8258
7.8 HIGH

Improper Control of Generation of Code ('Code Injection') in Electron Fuses in Logitech Options Plus version 1.60.496306 on macOS allows attackers to execute arbitrary code …

Sep 10, 2024
CVE-2024-7699
8.8 HIGH

An low privileged remote attacker can execute OS commands with root privileges due to improper neutralization of special elements in user data.

Sep 10, 2024
CVE-2024-7698
5.7 MEDIUM

A low privileged remote attacker can get access to CSRF tokens of higher privileged users which can be abused to mount CSRF attacks.

Sep 10, 2024
CVE-2024-43393
8.1 HIGH

A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the …

Sep 10, 2024
CVE-2024-43392
8.1 HIGH

A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the …

Sep 10, 2024
CVE-2024-43391
8.1 HIGH

A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the …

Sep 10, 2024
CVE-2024-43390
8.1 HIGH

A low privileged remote attacker can perform configuration changes of the firewall services, including packet forwarding or NAT through the FW_NAT.IN_IP environment variable which can …

Sep 10, 2024
CVE-2024-43389
8.1 HIGH

A low privileged remote attacker can perform configuration changes of the ospf service through OSPF_INTERFACE.SIMPLE_KEY, OSPF_INTERFACE.DIGEST_KEY environment variables which can lead to a DoS.

Sep 10, 2024
CVE-2024-43388
8.8 HIGH

A low privileged remote attacker with write permissions can reconfigure the SNMP service due to improper input validation.

Sep 10, 2024
CVE-2024-43387
8.8 HIGH

A low privileged remote attacker can read and write files as root due to improper neutralization of special elements in the variable EMAIL_RELAY_PASSWORD in mGuard …

Sep 10, 2024
CVE-2024-43386
8.8 HIGH

A low privileged remote attacker can trigger the execution of arbitrary OS commands as root due to improper neutralization of special elements in the variable …

Sep 10, 2024
CVE-2024-43385
8.8 HIGH

A low privileged remote attacker can trigger the execution of arbitrary OS commands as root due to improper neutralization of special elements in the variable …

Sep 10, 2024
CVE-2024-42425
3.8 LOW

Dell Precision Rack, 14G Intel BIOS versions prior to 2.22.2, contains an Access of Memory Location After End of Buffer vulnerability. A low privileged attacker …

Sep 10, 2024
CVE-2024-39583
8.1 HIGH

Dell PowerScale InsightIQ, versions 5.0 through 5.1, contains a Use of a Broken or Risky Cryptographic Algorithm vulnerability. An unauthenticated attacker with remote access could …

Sep 10, 2024
CVE-2024-39582
2.3 LOW

Dell PowerScale InsightIQ, version 5.0, contain a Use of hard coded Credentials vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, …

Sep 10, 2024
CVE-2024-39581
7.3 HIGH

Dell PowerScale InsightIQ, versions 5.0 through 5.1, contains a File or Directories Accessible to External Parties vulnerability. An unauthenticated attacker with remote access could potentially …

Sep 10, 2024
CVE-2024-39580
6.7 MEDIUM

Dell PowerScale InsightIQ, versions 5.0 through 5.1, contains an Improper Access Control vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, …

Sep 10, 2024
CVE-2024-39574
6.7 MEDIUM

Dell PowerScale InsightIQ, version 5.1, contain an Improper Privilege Management vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to …

Sep 10, 2024
CVE-2024-7734
5.3 MEDIUM

An unauthenticated remote attacker can exploit the behavior of the pathfinder TCP encapsulation service by establishing a high number of TCP connections to the pathfinder …

Sep 10, 2024
CVE-2024-7655
4.4 MEDIUM

The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, …

Sep 10, 2024
CVE-2024-7618
4.4 MEDIUM

The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘content’ parameter in …

Sep 10, 2024
CVE-2024-6596
9.8 CRITICAL

An unauthenticated remote attacker can run malicious c# code included in curve files and execute commands in the users context.

Sep 10, 2024
CVE-2024-42427
7.6 HIGH

Dell ThinOS versions 2402 and 2405, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with physical …

Sep 10, 2024
CVE-2024-42424
5.3 MEDIUM

Dell Precision Rack, 14G Intel BIOS versions prior to 2.22.2, contains an Improper Input Validation vulnerability. A high privileged attacker with local access could potentially …

Sep 10, 2024
CVE-2024-44072
5.7 MEDIUM

OS command injection vulnerability exists in BUFFALO wireless LAN routers and wireless LAN repeaters. If a user logs in to the management page and sends …

Sep 10, 2024
CVE-2024-7955
4.8 MEDIUM

The Starbox WordPress plugin before 3.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Sep 10, 2024
CVE-2024-7891
4.8 MEDIUM

The Floating Contact Button WordPress plugin before 2.8 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Sep 10, 2024
CVE-2024-7784
6.1 MEDIUM

During internal Axis Security Development Model (ASDM) threat-modelling, a flaw was found in the protection for device tampering (commonly known as Secure Boot) in AXIS …

Sep 10, 2024
CVE-2024-6979
6.8 MEDIUM

Amin Aliakbari, member of the AXIS OS Bug Bounty Program, has found a broken access control which would lead to less-privileged operator- and/or viewer accounts …

Sep 10, 2024
CVE-2024-6509
6.5 MEDIUM

Marinus Pfund, member of the AXIS OS Bug Bounty Program, has found the VAPIX API alwaysmulti.cgi was vulnerable for file globbing which could lead to …

Sep 10, 2024
CVE-2024-6173
6.5 MEDIUM

51l3nc3, member of the AXIS OS Bug Bounty Program, has found that a Guard Tour VAPIX API parameter allowed the use of arbitrary values allowing …

Sep 10, 2024
CVE-2024-45504
6.5 MEDIUM

Cross-site request forgery (CSRF) vulnerability in multiple Alps System Integration products and the OEM products allow a remote unauthenticated attacker to hijack the authentication of …

Sep 10, 2024
CVE-2024-45285
5.4 MEDIUM

The RFC enabled function module allows a low privileged user to perform denial of service on any user and also change or delete favourite nodes. …

Sep 10, 2024
CVE-2024-45284
2.4 LOW

An authenticated attacker with high privilege can use functions of SLCM transactions to which access should be restricted. This may result in an escalation of …

Sep 10, 2024
CVE-2024-45283
6.0 MEDIUM

SAP NetWeaver AS for Java allows an authorized attacker to obtain sensitive information. The attacker could obtain the username and password when creating an RFC …

Sep 10, 2024
CVE-2024-45281
5.8 MEDIUM

SAP BusinessObjects Business Intelligence Platform allows a high privilege user to run client desktop applications even if some of the DLLs are not digitally signed …

Sep 10, 2024
CVE-2024-45280
4.8 MEDIUM

Due to insufficient encoding of user-controlled inputs, SAP NetWeaver AS Java allows malicious scripts to be executed in the login application. This has a limited …

Sep 10, 2024
CVE-2024-45279
6.1 MEDIUM

Due to insufficient input validation, CRM Blueprint Application Builder Panel of SAP NetWeaver Application Server for ABAP allows an unauthenticated attacker to craft a URL …

Sep 10, 2024
CVE-2024-44121
4.3 MEDIUM

Under certain conditions Statutory Reports in SAP S/4 HANA allows an attacker with basic privileges to access information which would otherwise be restricted. The vulnerability …

Sep 10, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.