CVE Database

10843+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-36582
9.8 CRITICAL

alexbinary object-deep-assign 1.0.11 is vulnerable to Prototype Pollution via the extend() method of Module.deepAssign (/src/index.js)

Jun 17, 2024
CVE-2024-36580
9.8 CRITICAL

A Prototype Pollution issue in cdr0 sg 1.0.10 allows an attacker to execute arbitrary code.

Jun 17, 2024
CVE-2024-6057
9.8 CRITICAL

Improper authentication in the vault password feature in Devolutions Remote Desktop Manager 2024.1.31.0 and earlier allows an attacker that has compromised an access to an …

Jun 17, 2024
CVE-2024-6048
9.8 CRITICAL

Openfind's MailGates and MailAudit fail to properly filter user input when analyzing email attachments. An unauthenticated remote attacker can exploit this vulnerability to inject system …

Jun 17, 2024
CVE-2024-6047
9.8 CRITICAL KEV

Certain EOL GeoVision devices fail to properly filter user input for the specific functionality. Unauthenticated remote attackers can exploit this vulnerability to inject and execute …

Jun 17, 2024
CVE-2024-5163
9.8 CRITICAL

Improper permission settings for mobile applications (com.transsion.carlcare) may lead to user password and account security risks.

Jun 17, 2024
CVE-2024-34451
9.1 CRITICAL

Ghost through 5.85.1 allows remote attackers to bypass an authentication rate-limit protection mechanism by using many X-Forwarded-For headers with different values. NOTE: the vendor's position …

Jun 16, 2024
CVE-2024-38396
9.8 CRITICAL

An issue was discovered in iTerm2 3.5.x before 3.5.2. Unfiltered use of an escape sequence to report a window title, in combination with the built-in …

Jun 16, 2024
CVE-2024-38468
9.8 CRITICAL

Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized password resets via the resetPassword API.

Jun 16, 2024
CVE-2024-38466
9.8 CRITICAL

Shenzhen Guoxin Synthesis image system before 8.3.0 has a 123456Qw default password.

Jun 16, 2024
CVE-2024-38462
9.8 CRITICAL

iRODS before 4.3.2 provides an msiSendMail function with a problematic dependency on the mail binary, such as in the mailMS.cpp#L94-L106 reference.

Jun 16, 2024
CVE-2024-38448
9.1 CRITICAL

htags in GNU Global through 6.6.12 allows code execution in situations where dbpath (aka -d) is untrusted, because shell metacharacters may be used.

Jun 16, 2024
CVE-2024-38441
9.8 CRITICAL

Netatalk before 3.2.1 has an off-by-one error and resultant heap-based buffer overflow because of setting ibuf[len] to '\0' in FPMapName in afp_mapname in etc/afpd/directory.c. 2.4.1 …

Jun 16, 2024
CVE-2024-38439
9.8 CRITICAL

Netatalk before 3.2.1 has an off-by-one error and resultant heap-based buffer overflow because of setting ibuf[PASSWDLEN] to '\0' in FPLoginExt in login in etc/uams/uams_pam.c. 2.4.1 …

Jun 16, 2024
CVE-2024-38428
9.1 CRITICAL

url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data …

Jun 16, 2024
CVE-2024-38395
9.8 CRITICAL

In iTerm2 before 3.5.2, the "Terminal may report window title" setting is not honored, and thus remote code execution might occur but "is not trivially …

Jun 16, 2024
CVE-2024-4258
9.8 CRITICAL

The Video Gallery – YouTube Playlist, Channel Gallery by YotuWP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and …

Jun 15, 2024
CVE-2024-3105
9.9 CRITICAL

The Woody code snippets – Insert Header Footer Code, AdSense Ads plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, …

Jun 15, 2024
CVE-2024-5871
9.8 CRITICAL

The WooCommerce - Social Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.2 via deserialization of …

Jun 15, 2024
CVE-2024-37831
9.8 CRITICAL

Itsourcecode Payroll Management System 1.0 is vulnerable to SQL Injection in payroll_items.php via the ID parameter.

Jun 14, 2024
CVE-2024-37642
9.1 CRITICAL

TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a command injection vulnerability via the ipv4_ping, ipv6_ping parameter at /formSystemCheck .

Jun 14, 2024
CVE-2024-34539
9.4 CRITICAL

Hardcoded credentials in TerraMaster TOS firmware through 5.1 allow a remote attacker to successfully login to the mail or webmail server. These credentials can also …

Jun 14, 2024
CVE-2024-33375
9.8 CRITICAL

LB-LINK BL-W1210M v2.0 was discovered to store user credentials in plaintext within the router's firmware.

Jun 14, 2024
CVE-2024-33374
9.8 CRITICAL

Incorrect access control in the UART/Serial interface on the LB-LINK BL-W1210M v2.0 router allows attackers to access the root terminal without authentication.

Jun 14, 2024
CVE-2024-5671
9.8 CRITICAL

Insecure Deserialization in some workflows of the IPS Manager allows unauthenticated remote attackers to perform arbitrary code execution and access to the vulnerable Trellix IPS …

Jun 14, 2024
CVE-2024-37637
9.8 CRITICAL

TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid5g in the function setWizardCfg.

Jun 14, 2024
CVE-2024-3912
9.8 CRITICAL

Certain models of ASUS routers have an arbitrary firmware upload vulnerability. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands on …

Jun 14, 2024
CVE-2024-2472
9.1 CRITICAL

The LatePoint Plugin plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the …

Jun 14, 2024
CVE-2024-5577
9.8 CRITICAL

The Where I Was, Where I Will Be plugin for WordPress is vulnerable to Remote File Inclusion in version <= 1.1.1 via the WIW_HEADER parameter …

Jun 14, 2024
CVE-2024-4936
9.8 CRITICAL

The Canto plugin for WordPress is vulnerable to Remote File Inclusion in all versions up to, and including, 3.0.8 via the abspath parameter. This makes …

Jun 14, 2024
CVE-2024-27174
9.8 CRITICAL

Remote Command program allows an attacker to get Remote Code Execution. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute …

Jun 14, 2024
CVE-2024-27173
9.8 CRITICAL

Remote Command program allows an attacker to get Remote Code Execution by overwriting existing Python files containing executable code. This vulnerability can be executed in …

Jun 14, 2024
CVE-2024-27172
9.8 CRITICAL

Remote Command program allows an attacker to get Remote Code Execution. As for the affected products/models/versions, see the reference URL.

Jun 14, 2024
CVE-2024-3080
9.8 CRITICAL

Certain ASUS router models have authentication bypass vulnerability, allowing unauthenticated remote attackers to log in the device.

Jun 14, 2024
CVE-2024-27145
9.8 CRITICAL

The Toshiba printers provide several ways to upload files using the admin web interface. An attacker can remotely compromise any Toshiba printer. An attacker can …

Jun 14, 2024
CVE-2024-27144
9.8 CRITICAL

The Toshiba printers provide several ways to upload files using the web interface without authentication. An attacker can overwrite any insecure files. And the Toshiba …

Jun 14, 2024
CVE-2024-27143
9.8 CRITICAL

Toshiba printers use SNMP for configuration. Using the private community, it is possible to remotely execute commands as root on the remote printer. Using this …

Jun 14, 2024
CVE-2024-31777
9.8 CRITICAL

File Upload vulnerability in openeclass v.3.15 and before allows an attacker to execute arbitrary code via a crafted file to the certbadge.php endpoint.

Jun 13, 2024
CVE-2024-0095
9.0 CRITICAL

NVIDIA Triton Inference Server for Linux and Windows contains a vulnerability where a user can inject forged logs and executable commands by injecting arbitrary data …

Jun 13, 2024
CVE-2024-32913
9.8 CRITICAL

In wl_notify_rx_mgmt_frame of wl_cfg80211.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with …

Jun 13, 2024
CVE-2024-32911
9.8 CRITICAL

There is a possible escalation of privilege due to improperly used crypto. This could lead to remote escalation of privilege with no additional execution privileges …

Jun 13, 2024
CVE-2024-32905
9.8 CRITICAL

In circ_read of link_device_memory_legacy.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution …

Jun 13, 2024
CVE-2024-29786
9.8 CRITICAL

In pktproc_fill_data_addr_without_bm of link_rx_pktproc.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution …

Jun 13, 2024
CVE-2024-37635
9.8 CRITICAL

TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiBasicCfg

Jun 13, 2024
CVE-2024-37634
9.8 CRITICAL

TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiEasyCfg.

Jun 13, 2024
CVE-2024-37632
9.8 CRITICAL

TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via the password parameter in function loginAuth .

Jun 13, 2024
CVE-2024-38281
9.8 CRITICAL

An attacker can access the maintenance console using hard coded credentials for a hidden wireless network on the device.

Jun 13, 2024
CVE-2024-22441
9.8 CRITICAL

HPE Cray Parallel Application Launch Service (PALS) is subject to an authentication bypass.

Jun 13, 2024
CVE-2024-37849
9.8 CRITICAL

A SQL Injection vulnerability in itsourcecode Billing System 1.0 allows a local attacker to execute arbitrary code in process.php via the username parameter.

Jun 13, 2024
CVE-2024-30300
9.8 CRITICAL

Adobe Framemaker Publishing Server versions 2020.3, 2022.2 and earlier are affected by an Information Exposure vulnerability (CWE-200) that could lead to privilege escalation. An attacker …

Jun 13, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.