CVE Database

10843+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-35375
9.8 CRITICAL

There is an arbitrary file upload vulnerability on the media add .php page in the backend of the website in version 5.7.114 of DedeCMS

May 23, 2024
CVE-2024-35080
9.8 CRITICAL

An arbitrary file upload vulnerability in the gok4 method of inxedu v2024.4 allows attackers to execute arbitrary code via uploading a crafted .jsp file.

May 23, 2024
CVE-2024-35079
9.8 CRITICAL

An arbitrary file upload vulnerability in the uploadAudio method of inxedu v2024.4 allows attackers to execute arbitrary code via uploading a crafted .jsp file.

May 23, 2024
CVE-2024-35091
9.8 CRITICAL

J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysTenantMapper.xml.

May 23, 2024
CVE-2024-35086
9.8 CRITICAL

J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in BpmTaskFromMapper.xml .

May 23, 2024
CVE-2024-35084
9.8 CRITICAL

J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysMsgPushMapper.xml.

May 23, 2024
CVE-2024-34935
9.8 CRITICAL

A SQL injection vulnerability in /view/conversation_history_admin.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the conversation_id …

May 23, 2024
CVE-2024-34934
9.8 CRITICAL

A SQL injection vulnerability in /view/emarks_range_grade_update_form.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the conversation_id …

May 23, 2024
CVE-2024-34932
9.8 CRITICAL

A SQL injection vulnerability in /model/update_exam.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the name …

May 23, 2024
CVE-2024-34931
9.8 CRITICAL

A SQL injection vulnerability in /model/update_subject.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the name …

May 23, 2024
CVE-2024-34929
9.8 CRITICAL

A SQL injection vulnerability in /view/find_friends.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the my_index …

May 23, 2024
CVE-2024-34927
9.8 CRITICAL

A SQL injection vulnerability in /model/update_classroom.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the name …

May 23, 2024
CVE-2024-5084
9.8 CRITICAL

The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in …

May 23, 2024
CVE-2024-5168
9.8 CRITICAL

Improper access control vulnerability in Prodys' Quantum Audio codec affecting versions 2.3.4t and below. This vulnerability could allow an unauthenticated user to bypass authentication entirely …

May 23, 2024
CVE-2024-4399
9.1 CRITICAL

The does not validate a parameter before making a request to it, which could allow unauthenticated users to perform SSRF attack

May 23, 2024
CVE-2024-29849
9.8 CRITICAL

Veeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface.

May 22, 2024
CVE-2024-4267
9.8 CRITICAL

A remote code execution (RCE) vulnerability exists in the parisneo/lollms-webui, specifically within the 'open_file' module, version 9.5. The vulnerability arises due to improper neutralization of …

May 22, 2024
CVE-2023-51637
9.8 CRITICAL

Sante PACS Server PG Patient Query SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

May 22, 2024
CVE-2024-25738
9.1 CRITICAL

A Server-Side Request Forgery (SSRF) vulnerability in the /Upgrade/FixConfig route in Open Library Foundation VuFind 2.0 through 9.1 before 9.1.1 allows a remote attacker to …

May 22, 2024
CVE-2024-33226
9.9 CRITICAL

An issue in the component Access64.sys of Wistron Corporation TBT Force Power Control v1.0.0.0 allows attackers to escalate privileges and execute arbitrary code via sending …

May 22, 2024
CVE-2024-35409
9.8 CRITICAL

WeBid 1.1.2 is vulnerable to SQL Injection via admin/tax.php.

May 22, 2024
CVE-2024-3495
9.8 CRITICAL

The Country State City Dropdown CF7 plugin for WordPress is vulnerable to SQL Injection via the ‘cnt’ and 'sid' parameters in versions up to, and …

May 22, 2024
CVE-2024-5147
9.8 CRITICAL

The WPZOOM Addons for Elementor (Templates, Widgets) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1.37 via …

May 22, 2024
CVE-2024-4443
9.8 CRITICAL

The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘listingfields’ parameter in all …

May 22, 2024
CVE-2024-31989
9.0 CRITICAL

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. It has been discovered that an unprivileged pod in a different namespace on the …

May 21, 2024
CVE-2024-35056
9.8 CRITICAL

NASA AIT-Core v2.5.2 was discovered to contain multiple SQL injection vulnerabilities via the query_packets and insert functions.

May 21, 2024
CVE-2023-52832
9.1 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: don't return unset power in ieee80211_get_tx_power() We can get a UBSAN warning if …

May 21, 2024
CVE-2023-52801
9.1 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: iommufd: Fix missing update of domains_itree after splitting iopt_area In iopt_area_split(), if the original iopt_area …

May 21, 2024
CVE-2023-52735
9.1 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Don't let sock_map_{close,destroy,unhash} call itself sock_map proto callbacks should never call themselves by …

May 21, 2024
CVE-2021-47378
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: nvme-rdma: destroy cm id before destroy qp to avoid use after free We should always …

May 21, 2024
CVE-2021-47354
9.1 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: drm/sched: Avoid data corruptions Wait for all dependencies of a job to complete before killing …

May 21, 2024
CVE-2021-47348
9.1 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Avoid HDCP over-read and corruption Instead of reading the desired 5 bytes of the …

May 21, 2024
CVE-2021-47274
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: tracing: Correct the length check which causes memory corruption We've suffered from severe kernel crashes …

May 21, 2024
CVE-2023-3943
10.0 CRITICAL

Stack-based Buffer Overflow vulnerability in ZkTeco-based OEM devices allows, in some cases, the execution of arbitrary code. Due to the lack of protection mechanisms such …

May 21, 2024
CVE-2024-35361
9.8 CRITICAL

MTab Bookmark v1.9.5 has an SQL injection vulnerability in /LinkStore/getIcon. An attacker can execute arbitrary SQL statements through this vulnerability without requiring any user rights.

May 21, 2024
CVE-2023-3941
10.0 CRITICAL

Relative Path Traversal vulnerability in ZkTeco-based OEM devices allows an attacker to write any file on the system with root privileges. This issue affects ZkTeco-based …

May 21, 2024
CVE-2023-3939
10.0 CRITICAL

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in ZkTeco-based OEM devices allows OS Command Injection. Since all the …

May 21, 2024
CVE-2024-4442
9.1 CRITICAL

The Salon booking system plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 9.8. This is due to …

May 21, 2024
CVE-2024-4985
9.8 CRITICAL

An authentication bypass vulnerability was present in the GitHub Enterprise Server (GHES) when utilizing SAML single sign-on authentication with the optional encrypted assertions feature. This …

May 20, 2024
CVE-2024-35580
9.8 CRITICAL

Tenda AX1806 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formSetIptv.

May 20, 2024
CVE-2024-35571
9.8 CRITICAL

Tenda AX1806 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formSetIptv.

May 20, 2024
CVE-2024-34947
9.4 CRITICAL

Quanxun Huiju Network Technology (Beijing) Co.,Ltd IK-Q3000 3.7.10 x64 Build202401261655 was discovered to be vulnerable to an ICMP redirect attack.

May 20, 2024
CVE-2024-24294
9.8 CRITICAL

A Prototype Pollution issue in Blackprint @blackprint/engine v.0.9.0 allows an attacker to execute arbitrary code via the _utils.setDeepProperty function of engine.min.js.

May 20, 2024
CVE-2024-4323
9.8 CRITICAL

A memory corruption vulnerability in Fluent Bit versions 2.0.7 thru 3.0.3. This issue lies in the embedded http server’s parsing of trace requests and may …

May 20, 2024
CVE-2024-35960
9.1 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Properly link new fs rules into the tree Previously, add_rule_fg would only add newly …

May 20, 2024
CVE-2024-36081
9.8 CRITICAL

Westermo EDW-100 devices through 2024-05-03 allow an unauthenticated user to download a configuration file containing a cleartext password. NOTE: this is a serial-to-Ethernet converter that …

May 19, 2024
CVE-2024-36080
9.8 CRITICAL

Westermo EDW-100 devices through 2024-05-03 have a hidden root user account with a hardcoded password that cannot be changed. NOTE: this is a serial-to-Ethernet converter …

May 19, 2024
CVE-2024-36053
9.0 CRITICAL

In the mintupload package through 4.2.0 for Linux Mint, service-name mishandling leads to command injection via shell metacharacters in check_connection, drop_data_received_cb, and Service.remove. A user …

May 19, 2024
CVE-2024-28064
9.8 CRITICAL

Kiteworks Totemomail 7.x and 8.x before 8.3.0 allows /responsiveUI/EnvelopeOpenServlet messageId directory traversal for unauthenticated file read and delete operations (with displayLoginChunkedImages) and write operations (with …

May 18, 2024
CVE-2024-36048
9.8 CRITICAL

QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.6, and 6.6.x through 6.7.x before 6.7.1 uses only …

May 18, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.