CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-43794
6.1 MEDIUM

OpenSearch Dashboards Security Plugin adds a configuration management UI for the OpenSearch Security features to OpenSearch Dashboards. Improper validation of the nextUrl parameter can lead …

Aug 23, 2024
CVE-2024-42918
5.4 MEDIUM

itsourcecode Online Accreditation Management System contains a Cross Site Scripting vulnerability, which allows an attacker to execute arbitrary code via a crafted payload to the …

Aug 23, 2024
CVE-2024-42531
9.8 CRITICAL

Ezviz Internet PT Camera CS-CV246 D15655150 allows an unauthenticated host to access its live video stream by crafting a set of RTSP packets with a …

Aug 23, 2024
CVE-2024-41878
5.4 MEDIUM

Adobe Experience Manager versions 6.5.19 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. This vulnerability could allow an attacker to inject and …

Aug 23, 2024
CVE-2024-41877
5.4 MEDIUM

Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject …

Aug 23, 2024
CVE-2024-41876
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim …

Aug 23, 2024
CVE-2024-41875
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject …

Aug 23, 2024
CVE-2024-41849
4.1 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Input Validation vulnerability that could lead to a security feature bypass. An low-privileged …

Aug 23, 2024
CVE-2024-41848
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim …

Aug 23, 2024
CVE-2024-41847
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim …

Aug 23, 2024
CVE-2024-41846
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject …

Aug 23, 2024
CVE-2024-41845
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject …

Aug 23, 2024
CVE-2024-41844
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject …

Aug 23, 2024
CVE-2024-41843
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject …

Aug 23, 2024
CVE-2024-41842
4.8 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject …

Aug 23, 2024
CVE-2024-41841
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim …

Aug 23, 2024
CVE-2024-39841
8.8 HIGH

A SQL Injection vulnerability exists in the service configuration functionality in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before …

Aug 23, 2024
CVE-2024-33854
9.1 CRITICAL

A SQL Injection vulnerability exists in the Graph Template component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before …

Aug 23, 2024
CVE-2024-33853
9.1 CRITICAL

A SQL Injection vulnerability exists in the Timeperiod component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.

Aug 23, 2024
CVE-2024-33852
9.1 CRITICAL

A SQL Injection vulnerability exists in the Downtime component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.

Aug 23, 2024
CVE-2024-32501
9.8 CRITICAL

A SQL Injection vulnerability exists in the updateServiceHost functionality in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.

Aug 23, 2024
CVE-2024-44386
7.3 HIGH

Tenda FH1206 V1.2.0.8(8155)_EN contains a Buffer Overflow vulnerability via the function fromSetIpBind.

Aug 23, 2024
CVE-2024-44382
9.8 CRITICAL

D-Link DI_8004W 16.07.26A1 contains a command execution vulnerability in the jhttpd upgrade_filter_asp function.

Aug 23, 2024
CVE-2024-44381
9.8 CRITICAL

D-Link DI_8004W 16.07.26A1 contains a command execution vulnerability in jhttpd msp_info_htm function.

Aug 23, 2024
CVE-2024-43032
4.3 MEDIUM

autMan v2.9.6 allows attackers to bypass authentication via a crafted web request.

Aug 23, 2024
CVE-2024-43031
4.3 MEDIUM

autMan v2.9.6 was discovered to contain an access control issue.

Aug 23, 2024
CVE-2024-42756
8.8 HIGH

An issue in Netgear DGN1000WW v.1.1.00.45 allows a remote attacker to execute arbitrary code via the Diagnostics page

Aug 23, 2024
CVE-2024-42636
7.2 HIGH

DedeCMS V5.7.115 has a command execution vulnerability via file_manage_view.php?fmdo=newfile&activepath.

Aug 23, 2024
CVE-2024-42523
7.2 HIGH

publiccms V4.0.202302.e and before is vulnerable to Any File Upload via publiccms/admin/cmsTemplate/saveMetaData

Aug 23, 2024
CVE-2024-42364
6.5 MEDIUM

Homepage is a highly customizable homepage with Docker and service API integrations. The default setup of homepage 0.9.1 is vulnerable to DNS rebinding. Homepage is …

Aug 23, 2024
CVE-2024-8113
5.4 MEDIUM

Stored XSS in organizer and event settings of pretix up to 2024.7.0 allows malicious event organizers to inject HTML tags into e-mail previews on settings …

Aug 23, 2024
CVE-2024-8112
4.3 MEDIUM

A vulnerability was found in thinkgem JeeSite 5.3. It has been rated as problematic. This issue affects some unknown processing of the file /js/a/login of …

Aug 23, 2024
CVE-2024-43791
7.8 HIGH

RequestStore provides per-request global storage for Rack. The files published as part of request_store 1.3.2 have 0666 permissions, meaning that they are world-writable, which allows …

Aug 23, 2024
CVE-2024-43782
7.7 HIGH

This openedx-translations repository contains translation files from Open edX repositories to be kept in sync with Transifex. Before moving to pulling translations from the openedx-translations …

Aug 23, 2024
CVE-2024-42915
8.0 HIGH

A host header injection vulnerability in Staff Appraisal System v1.0 allows attackers to obtain the password reset token via user interaction with a crafted password …

Aug 23, 2024
CVE-2024-42766
5.4 MEDIUM

Kashipara Bus Ticket Reservation System v1.0 0 is vulnerable to Incorrect Access Control via /deleteTicket.php.

Aug 23, 2024
CVE-2024-42765
9.8 CRITICAL

A SQL injection vulnerability in "/login.php" of the Kashipara Bus Ticket Reservation System v1.0 allows remote attackers to execute arbitrary SQL commands and bypass Login …

Aug 23, 2024
CVE-2024-42764
9.4 CRITICAL

Kashipara Bus Ticket Reservation System v1.0 is vulnerable to Cross Site Request Forgery (CSRF) via /deleteTicket.php.

Aug 23, 2024
CVE-2024-42040
8.1 HIGH

Buffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from its initial commit in 2002 (3861aa5) up to today on any platform allows an attacker …

Aug 23, 2024
CVE-2024-41150
6.3 MEDIUM

An Stored Cross-site Scripting vulnerability in request module affects Zohocorp ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP and SupportCenter Plus.This issue affects ServiceDesk Plus versions: through …

Aug 23, 2024
CVE-2024-38869
8.3 HIGH

Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability in remote office deploy configurations.This issue affects Endpoint Central: before 11.3.2416.04 and before 11.3.2400.25.

Aug 23, 2024
CVE-2024-37311
8.2 HIGH

Collabora Online is a collaborative online office suite based on LibreOffice. In affected versions of Collabora Online, https connections from coolwsd to other hosts may …

Aug 23, 2024
CVE-2024-5586
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injection in extranet lockouts report option.

Aug 23, 2024
CVE-2024-5556
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in reports module.

Aug 23, 2024
CVE-2024-5490
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in aggregate reports option.

Aug 23, 2024
CVE-2024-5467
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injection in account lockout report.

Aug 23, 2024
CVE-2024-5466
8.8 HIGH

Zohocorp ManageEngine OpManager and Remote Monitoring and Management versions 128329 and below are vulnerable to the authenticated remote code execution in the deploy agent option.

Aug 23, 2024
CVE-2024-36517
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in alerts module.

Aug 23, 2024
CVE-2024-36516
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in dashboard. Note: This vulnerability is different from another vulnerability (CVE-2024-36515), …

Aug 23, 2024
CVE-2024-36515
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in dashboard. Note: This vulnerability is different from another vulnerability (CVE-2024-36516), …

Aug 23, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.