CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-41013
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: xfs: don't walk off the end of a directory data block This adds sanity checks …

Jul 29, 2024
CVE-2024-7186
8.8 HIGH

A vulnerability was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. It has been classified as critical. This affects the function setWiFiAclAddConfig of the file /cgi-bin/cstecgi.cgi. The manipulation …

Jul 29, 2024
CVE-2024-7185
8.8 HIGH

A vulnerability was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102 and classified as critical. Affected by this issue is the function setWebWlanIdx of the file /cgi-bin/cstecgi.cgi. The …

Jul 29, 2024
CVE-2024-6487
5.9 MEDIUM

The Inline Related Posts WordPress plugin before 3.8.0 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Jul 29, 2024
CVE-2024-6366
9.1 CRITICAL

The User Profile Builder WordPress plugin before 3.11.8 does not have proper authorisation, allowing unauthenticated users to upload media files via the async upload functionality …

Jul 29, 2024
CVE-2024-6362
4.6 MEDIUM

The Ultimate Blocks WordPress plugin before 3.2.0 does not validate and escape some of its post-grid block attributes before outputting them back in a page/post …

Jul 29, 2024
CVE-2024-5883
4.7 MEDIUM

The Ultimate Classified Listings WordPress plugin before 1.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Jul 29, 2024
CVE-2024-5882
7.5 HIGH

The Ultimate Classified Listings WordPress plugin before 1.3 does not validate the `ucl_page` and `layout` parameters allowing unauthenticated users to access PHP files on the …

Jul 29, 2024
CVE-2024-5285
5.5 MEDIUM

The wp-affiliate-platform WordPress plugin before 6.5.2 does not have CSRF check in place when deleting affiliates, which could allow attackers to make a logged in …

Jul 29, 2024
CVE-2024-4483
5.4 MEDIUM

The Email Encoder WordPress plugin before 2.2.2 does not escape the WP_Email_Encoder_Bundle_options[protection_text] parameter before outputting it back in an attribute in an admin page, leading …

Jul 29, 2024
CVE-2024-41637
8.3 HIGH

RaspAP before 3.1.5 allows an attacker to escalate privileges: the www-data user has write access to the restapi.service file and also possesses Sudo privileges to …

Jul 29, 2024
CVE-2024-37381
8.0 HIGH

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2024 flat allows an authenticated attacker within the same network to execute arbitrary code.

Jul 29, 2024
CVE-2024-7184
8.8 HIGH

A vulnerability has been found in TOTOLINK A3600R 4.1.2cu.5182_B20201102 and classified as critical. Affected by this vulnerability is the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi. …

Jul 29, 2024
CVE-2024-7183
8.8 HIGH

A vulnerability, which was classified as critical, was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. Affected is the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. The manipulation of …

Jul 29, 2024
CVE-2024-7202
9.8 CRITICAL

The query functionality of WinMatrix3 Web package from Simopro Technology lacks proper validation of user input, allowing unauthenticated remote attackers to inject SQL commands to …

Jul 29, 2024
CVE-2024-7182
8.8 HIGH

A vulnerability, which was classified as critical, has been found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. This issue affects the function setUpgradeFW of the file /cgi-bin/cstecgi.cgi. The …

Jul 29, 2024
CVE-2024-7181
6.3 MEDIUM

A vulnerability classified as critical was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. This vulnerability affects the function setTelnetCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the …

Jul 29, 2024
CVE-2024-7201
9.8 CRITICAL

The login functionality of WinMatrix3 Web package from Simopro Technology lacks proper validation of user input, allowing unauthenticated remote attackers to inject SQL commands to …

Jul 29, 2024
CVE-2024-7180
8.8 HIGH

A vulnerability classified as critical has been found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. This affects the function setPortForwardRules of the file /cgi-bin/cstecgi.cgi. The manipulation of the …

Jul 29, 2024
CVE-2024-7179
8.8 HIGH

A vulnerability was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. It has been rated as critical. Affected by this issue is the function setParentalRules of the file …

Jul 29, 2024
CVE-2024-7178
8.8 HIGH

A vulnerability was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. It has been declared as critical. Affected by this vulnerability is the function setMacQos of the file …

Jul 29, 2024
CVE-2024-5670
9.8 CRITICAL

The web services of Softnext's products, Mail SQR Expert and Mail Archiving Expert do not properly validate user input, allowing unauthenticated remote attackers to inject …

Jul 29, 2024
CVE-2024-32671
9.8 CRITICAL

Heap-based Buffer Overflow vulnerability in Samsung Open Source Escargot JavaScript engine allows Overflow Buffers.This issue affects Escargot: 4.0.0.

Jul 29, 2024
CVE-2024-7177
8.8 HIGH

A vulnerability was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. It has been classified as critical. Affected is the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi. The manipulation …

Jul 29, 2024
CVE-2024-7176
8.8 HIGH

A vulnerability was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102 and classified as critical. This issue affects the function setIpQosRules of the file /cgi-bin/cstecgi.cgi. The manipulation of …

Jul 29, 2024
CVE-2024-7175
6.3 MEDIUM

A vulnerability has been found in TOTOLINK A3600R 4.1.2cu.5182_B20201102 and classified as critical. This vulnerability affects the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi. The manipulation …

Jul 29, 2024
CVE-2024-7174
8.8 HIGH

A vulnerability, which was classified as critical, was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. This affects the function setdeviceName of the file /cgi-bin/cstecgi.cgi. The manipulation of …

Jul 29, 2024
CVE-2024-7173
8.8 HIGH

A vulnerability, which was classified as critical, has been found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. Affected by this issue is the function loginauth of the file …

Jul 29, 2024
CVE-2024-7172
8.8 HIGH

A vulnerability classified as critical was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. Affected by this vulnerability is the function getSaveConfig of the file /cgi-bin/cstecgi.cgi?action=save&setting. The manipulation …

Jul 28, 2024
CVE-2024-7171
6.3 MEDIUM

A vulnerability classified as critical has been found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. Affected is the function NTPSyncWithHost of the file /cgi-bin/cstecgi.cgi. The manipulation of the …

Jul 28, 2024
CVE-2024-7170
3.5 LOW

A vulnerability was found in TOTOLINK A3000RU 5.9c.5185. It has been rated as problematic. This issue affects some unknown processing of the file /web_cste/cgi-bin/product.ini. The …

Jul 28, 2024
CVE-2024-7169
4.3 MEDIUM

A vulnerability classified as problematic has been found in SourceCodester School Fees Payment System 1.0. This affects an unknown part of the file /ajax.php. The …

Jul 28, 2024
CVE-2024-7168
6.3 MEDIUM

A vulnerability was found in SourceCodester School Fees Payment System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

Jul 28, 2024
CVE-2024-7167
6.3 MEDIUM

A vulnerability was found in SourceCodester School Fees Payment System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Jul 28, 2024
CVE-2024-7166
6.3 MEDIUM

A vulnerability was found in SourceCodester School Fees Payment System 1.0. It has been classified as critical. Affected is an unknown function of the file …

Jul 28, 2024
CVE-2024-7165
6.3 MEDIUM

A vulnerability was found in SourceCodester School Fees Payment System 1.0 and classified as critical. This issue affects some unknown processing of the file /view_payment.php. …

Jul 28, 2024
CVE-2024-7164
7.3 HIGH

A vulnerability has been found in SourceCodester School Fees Payment System 1.0 and classified as critical. This vulnerability affects unknown code of the file /ajax.php?action=login. …

Jul 28, 2024
CVE-2024-7163
3.5 LOW

A vulnerability, which was classified as problematic, was found in SeaCMS 12.9. This affects an unknown part of the file /js/player/dmplayer/player/index.php. The manipulation of the …

Jul 28, 2024
CVE-2024-7162
3.5 LOW

A vulnerability, which was classified as problematic, has been found in SeaCMS 12.9/13.0. Affected by this issue is some unknown functionality of the file js/player/dmplayer/admin/post.php?act=setting. …

Jul 28, 2024
CVE-2024-7161
4.3 MEDIUM

A vulnerability classified as problematic was found in SeaCMS 13.0. Affected by this vulnerability is an unknown functionality of the file /member.php?action=chgpwdsubmit of the component …

Jul 28, 2024
CVE-2024-7160
6.3 MEDIUM

A vulnerability classified as critical has been found in TOTOLINK A3700R 9.1.2u.5822_B20200513. Affected is the function setWanCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the …

Jul 28, 2024
CVE-2024-7159
5.5 MEDIUM

A vulnerability was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. It has been rated as critical. This issue affects some unknown processing of the file /web_cste/cgi-bin/product.ini of …

Jul 28, 2024
CVE-2024-7158
6.3 MEDIUM

A vulnerability was found in TOTOLINK A3100R 4.1.2cu.5050_B20200504. It has been declared as critical. This vulnerability affects the function setTelnetCfg of the file /cgi-bin/cstecgi.cgi of …

Jul 28, 2024
CVE-2024-7157
8.8 HIGH

A vulnerability was found in TOTOLINK A3100R 4.1.2cu.5050_B20200504. It has been classified as critical. This affects the function getSaveConfig of the file /cgi-bin/cstecgi.cgi?action=save&setting. The manipulation …

Jul 28, 2024
CVE-2024-7156
5.3 MEDIUM

A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513 and classified as problematic. Affected by this issue is some unknown functionality of the file /cgi-bin/ExportSettings.sh of …

Jul 28, 2024
CVE-2024-7155
2.5 LOW

A vulnerability has been found in TOTOLINK A3300R 17.0.0cu.557_B20221024 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /etc/shadow.sample. …

Jul 28, 2024
CVE-2024-7154
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. Affected is an unknown function of the file /wizard.html of the component …

Jul 28, 2024
CVE-2024-42055
5.4 MEDIUM

Cervantes through 0.5-alpha allows stored XSS.

Jul 28, 2024
CVE-2024-42054
5.4 MEDIUM

Cervantes through 0.5-alpha accepts insecure file uploads.

Jul 28, 2024
CVE-2024-42053
7.8 HIGH

The MSI installer for Splashtop Streamer for Windows before 3.6.0.0 uses a temporary folder with weak permissions during installation. A local user can exploit this …

Jul 28, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.