CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-7329
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in YouDianCMS 7. Affected is an unknown function of the file /Public/ckeditor/plugins/multiimage/dialogs/image_upload.php. The manipulation of the …

Jul 31, 2024
CVE-2024-7328
5.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in YouDianCMS 7. This issue affects some unknown processing of the file /t.php?action=phpinfo. The manipulation …

Jul 31, 2024
CVE-2024-38182
9.0 CRITICAL

Weak authentication in Microsoft Dynamics 365 allows an unauthenticated attacker to elevate privileges over a network.

Jul 31, 2024
CVE-2024-7327
6.3 MEDIUM

A vulnerability classified as critical was found in Xinhu RockOA 2.6.2. This vulnerability affects the function dataAction of the file /webmain/task/openapi/openmodhetongAction.php. The manipulation of the …

Jul 31, 2024
CVE-2024-41262
7.4 HIGH

mmudb v1.9.3 was discovered to use the HTTP protocol in the ShowMetricsRaw and ShowMetricsAsText functions, possibly allowing attackers to intercept communications via a man-in-the-middle attack.

Jul 31, 2024
CVE-2024-7326
7.8 HIGH

A vulnerability classified as critical has been found in IObit DualSafe Password Manager 1.4.0.3. This affects an unknown part in the library RTL120.BPL of the …

Jul 31, 2024
CVE-2024-4187
5.4 MEDIUM

Stored XSS vulnerability has been discovered in OpenText™ Filr product, affecting versions 24.1.1 and 24.2. The vulnerability could cause users to not be warned when …

Jul 31, 2024
CVE-2024-41258
5.3 MEDIUM

An issue was discovered in filestash v0.4. The usage of the ssh.InsecureIgnoreHostKey() disables host key verification, possibly allowing attackers to obtain sensitive information via a …

Jul 31, 2024
CVE-2024-41256
5.9 MEDIUM

Default configurations in the ShareProofVerifier function of filestash v0.4 causes the application to skip the TLS certificate verification process when sending out email verification codes, …

Jul 31, 2024
CVE-2024-41255
7.5 HIGH

filestash v0.4 is configured to skip TLS certificate verification when using the FTPS protocol, possibly allowing attackers to execute a man-in-the-middle attack via the Init …

Jul 31, 2024
CVE-2024-41254
5.3 MEDIUM

An issue was discovered in litestream v0.3.13. The usage of the ssh.InsecureIgnoreHostKey() disables host key verification, possibly allowing attackers to obtain sensitive information via a …

Jul 31, 2024
CVE-2024-41253
7.1 HIGH

goframe v2.7.2 is configured to skip TLS certificate verification, possibly allowing attackers to execute a man-in-the-middle attack via the gclient component.

Jul 31, 2024
CVE-2024-40465
8.8 HIGH

An issue in beego v.2.2.0 and before allows a remote attacker to escalate privileges via the getCacheFileName function in file.go file

Jul 31, 2024
CVE-2024-40464
8.8 HIGH

An issue in beego v.2.2.0 and before allows a remote attacker to escalate privileges via the sendMail function located in beego/core/logs/smtp.go file

Jul 31, 2024
CVE-2023-1577
7.8 HIGH

A path hijacking vulnerability was reported in Lenovo Driver Manager prior to version 3.1.1307.1308 that could allow a local user to execute code with elevated …

Jul 31, 2024
CVE-2022-4003
2.7 LOW

A denial-of-service vulnerability could allow an authenticated user to trigger an internal service restart via a specially crafted API request.

Jul 31, 2024
CVE-2022-4002
7.2 HIGH

A command injection vulnerability could allow an authenticated user to execute operating system commands as root via a specially crafted API request.

Jul 31, 2024
CVE-2022-4001
7.3 HIGH

An authentication bypass vulnerability could allow an attacker to access API functions without authentication.

Jul 31, 2024
CVE-2019-6198
7.8 HIGH

A vulnerability was reported in Lenovo PC Manager prior to version 2.8.90.11211 that could allow a local attacker to escalate privileges.

Jul 31, 2024
CVE-2019-6197
7.8 HIGH

A vulnerability was reported in Lenovo PC Manager prior to version 2.8.90.11211 that could allow a local attacker to escalate privileges.

Jul 31, 2024
CVE-2017-3772
5.5 MEDIUM

A vulnerability was reported in Lenovo PC Manager versions prior to 2.6.40.3154 that could allow an attacker to cause a system reboot.

Jul 31, 2024
CVE-2024-7325
7.8 HIGH

A vulnerability was found in IObit Driver Booster 11.0.0.0. It has been rated as critical. Affected by this issue is some unknown functionality in the …

Jul 31, 2024
CVE-2024-41955
5.2 MEDIUM

Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mobile. An open redirect vulnerability exist in MobSF …

Jul 31, 2024
CVE-2024-41954
5.3 MEDIUM

FOG is a cloning/imaging/rescue suite/inventory management system. The application stores plaintext service account credentials in the "/opt/fog/.fogsettings" file. This file is by default readable by …

Jul 31, 2024
CVE-2024-41951
4.4 MEDIUM

Pheonix App is a Python application designed to streamline various tasks, from managing files to playing mini-games. The issue is that the map of encoding/decoding …

Jul 31, 2024
CVE-2024-41660
9.8 CRITICAL

slpd-lite is a unicast SLP UDP server. Any OpenBMC system that includes the slpd-lite package is impacted. Installing this package is the default when building …

Jul 31, 2024
CVE-2024-41630
7.6 HIGH

Stack-based buffer overflow vulnerability in Tenda AC18 V15.03.3.10_EN allows a remote attacker to execute arbitrary code via the ssid parameter at ip/goform/fast_setting_wifi_set.

Jul 31, 2024
CVE-2024-41108
7.5 HIGH

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. The hostinfo page has missing/improper access control since only the host's mac address is required to …

Jul 31, 2024
CVE-2024-40645
8.8 HIGH

FOG is a cloning/imaging/rescue suite/inventory management system. An improperly restricted file upload feature allows authenticated users to execute arbitrary code on the fogproject server. The …

Jul 31, 2024
CVE-2023-28149
6.1 MEDIUM

An issue was discovered in the IhisiServiceSmm module in Insyde InsydeH2O with kernel 5.2 before 05.28.42, 5.3 before 05.37.42, 5.4 before 05.45.39, 5.5 before 05.53.39, …

Jul 31, 2024
CVE-2024-7324
7.8 HIGH

A vulnerability was found in IObit iTop Data Recovery Pro 4.4.0.687. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Jul 31, 2024
CVE-2024-23444
4.9 MEDIUM

It was discovered by Elastic engineering that when elasticsearch-certutil CLI tool is used with the csr option in order to create a new Certificate Signing …

Jul 31, 2024
CVE-2024-6978
5.6 MEDIUM

Cato Networks Windows SDP Client Local root certificates can be installed by low-privileged users.This issue affects SDP Client: before 5.10.28.

Jul 31, 2024
CVE-2024-6977
6.5 MEDIUM

A vulnerability in Cato Networks SDP Client on Windows allows the insertion of sensitive information into the log file, which can lead to an account …

Jul 31, 2024
CVE-2024-6975
8.8 HIGH

Cato Networks Windows SDP Client Local Privilege Escalation via openssl configuration file. This issue affects SDP Client before 5.10.34.

Jul 31, 2024
CVE-2024-6974
8.8 HIGH

Cato Networks Windows SDP Client Local Privilege Escalation via self-upgradeThis issue affects SDP Client: before 5.10.34.

Jul 31, 2024
CVE-2024-6973
7.5 HIGH

Remote Code Execution in Cato Windows SDP client via crafted URLs. This issue affects Windows SDP Client before 5.10.34.

Jul 31, 2024
CVE-2024-41953
4.3 MEDIUM

Zitadel is an open source identity management system. ZITADEL uses HTML for emails and renders certain information such as usernames dynamically. That information can be …

Jul 31, 2024
CVE-2024-41952
5.3 MEDIUM

Zitadel is an open source identity management system. ZITADEL administrators can enable a setting called "Ignoring unknown usernames" which helps mitigate attacks that try to …

Jul 31, 2024
CVE-2024-41950
7.5 HIGH

Haystack is an end-to-end LLM framework that allows you to build applications powered by LLMs, Transformer models, vector search and more. Haystack clients that let …

Jul 31, 2024
CVE-2024-41947
9.0 CRITICAL

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. By creating a conflict when another user with …

Jul 31, 2024
CVE-2024-39694
4.7 MEDIUM

Duende IdentityServer is an OpenID Connect and OAuth 2.x framework for ASP.NET Core. It is possible for an attacker to craft malicious Urls that certain …

Jul 31, 2024
CVE-2024-39318
5.4 MEDIUM

The Ibexa Admin UI Bundle contains all the necessary parts to run the Ibexa DXP Back Office interface. The file upload widget is vulnerable to …

Jul 31, 2024
CVE-2024-37901
9.9 CRITICAL

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit right on any page …

Jul 31, 2024
CVE-2024-37900
6.4 MEDIUM

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When uploading an attachment with a malicious filename, …

Jul 31, 2024
CVE-2024-37898
4.3 MEDIUM

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When a user has view but not edit …

Jul 31, 2024
CVE-2024-7340
8.8 HIGH

The Weave server API allows remote users to fetch files from a specific directory, but due to a lack of input validation, it is possible …

Jul 31, 2024
CVE-2024-3083
8.3 HIGH

A “CWE-352: Cross-Site Request Forgery (CSRF)” can be exploited by remote attackers to perform state-changing operations with administrative privileges by luring authenticated victims into visiting …

Jul 31, 2024
CVE-2024-3082
4.2 MEDIUM

A “CWE-256: Plaintext Storage of a Password” affecting the administrative account allows an attacker with physical access to the machine to retrieve the password in …

Jul 31, 2024
CVE-2024-37135
3.3 LOW

DM5500 5.16.0.0, contains an information disclosure vulnerability. A local attacker with high privileges could potentially exploit this vulnerability, leading to the disclosure of certain user …

Jul 31, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.