CVE Database

10843+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-34955
9.8 CRITICAL

Code-projects Budget Management 1.0 is vulnerable to SQL Injection via the delete parameter.

May 15, 2024
CVE-2024-4893
9.8 CRITICAL

DigiWin EasyFlow .NET lacks validation for certain input parameters, allowing remote attackers to inject arbitrary SQL commands. This vulnerability enables unauthorized access to read, modify, …

May 15, 2024
CVE-2024-32888
10.0 CRITICAL

The Amazon JDBC Driver for Redshift is a Type 4 JDBC driver that provides database connectivity through the standard JDBC application program interfaces (APIs) available …

May 15, 2024
CVE-2024-31473
9.8 CRITICAL

There is a command injection vulnerability in the underlying deauthentication service that could lead to unauthenticated remote code execution by sending specially crafted packets destined …

May 14, 2024
CVE-2024-31472
9.8 CRITICAL

There are command injection vulnerabilities in the underlying Soft AP Daemon service that could lead to unauthenticated remote code execution by sending specially crafted packets …

May 14, 2024
CVE-2024-31471
9.8 CRITICAL

There is a command injection vulnerability in the underlying Central Communications service that could lead to unauthenticated remote code execution by sending specially crafted packets …

May 14, 2024
CVE-2024-31470
9.8 CRITICAL

There is a buffer overflow vulnerability in the underlying SAE (Simultaneous Authentication of Equals) service that could lead to unauthenticated remote code execution by sending …

May 14, 2024
CVE-2024-31469
9.8 CRITICAL

There are buffer overflow vulnerabilities in the underlying Central Communications service that could lead to unauthenticated remote code execution by sending specially crafted packets destined …

May 14, 2024
CVE-2024-31468
9.8 CRITICAL

There are buffer overflow vulnerabilities in the underlying Central Communications service that could lead to unauthenticated remote code execution by sending specially crafted packets destined …

May 14, 2024
CVE-2024-31467
9.8 CRITICAL

There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to …

May 14, 2024
CVE-2024-31466
9.8 CRITICAL

There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to …

May 14, 2024
CVE-2024-32002
9.0 CRITICAL

Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, repositories with submodules can be crafted in a …

May 14, 2024
CVE-2024-4778
9.8 CRITICAL

Memory safety bugs present in Firefox 125. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of …

May 14, 2024
CVE-2024-4764
9.8 CRITICAL

Multiple WebRTC threads could have claimed a newly connected audio input leading to use-after-free. This vulnerability affects Firefox < 126.

May 14, 2024
CVE-2024-33485
9.8 CRITICAL

SQL Injection vulnerability in CASAP Automated Enrollment System using PHP/MySQLi with Source Code V1.0 allows a remote attacker to obtain sensitive information via a crafted …

May 14, 2024
CVE-2024-27107
9.6 CRITICAL

Weak account password in GE HealthCare EchoPAC products

May 14, 2024
CVE-2024-34716
9.6 CRITICAL

PrestaShop is an open source e-commerce web application. A cross-site scripting (XSS) vulnerability that only affects PrestaShops with customer-thread feature flag enabled is present starting …

May 14, 2024
CVE-2024-34256
9.8 CRITICAL

OFCMS V1.1.2 is vulnerable to SQL Injection via the new table function.

May 14, 2024
CVE-2024-33868
9.8 CRITICAL

An issue was discovered in linqi before 1.4.0.1 on Windows. There is LDAP injection.

May 14, 2024
CVE-2024-33863
9.8 CRITICAL

An issue was discovered in linqi before 1.4.0.1 on Windows. There is /api/Cdn/GetFile local file inclusion.

May 14, 2024
CVE-2024-33499
9.1 CRITICAL

A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions < V3.0.1.1), SIMATIC …

May 14, 2024
CVE-2024-33006
9.6 CRITICAL

An unauthenticated attacker can upload a malicious file to the server which when accessed by a victim can allow an attacker to completely compromise system.

May 14, 2024
CVE-2024-32741
10.0 CRITICAL

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains hard coded password which is used for the …

May 14, 2024
CVE-2024-32740
9.8 CRITICAL

A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains undocumented users and credentials. An attacker could misuse …

May 14, 2024
CVE-2024-32353
9.8 CRITICAL

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'port' parameter in the setSSServer function at /cgi-bin/cstecgi.cgi.

May 14, 2024
CVE-2024-30209
9.6 CRITICAL

A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions < V3.0.1.1), SIMATIC …

May 14, 2024
CVE-2024-30207
10.0 CRITICAL

A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All versions < V3.0.1.1), SIMATIC RTLS Locating Manager (6GT2780-0DA10) (All versions < V3.0.1.1), SIMATIC …

May 14, 2024
CVE-2024-27939
9.8 CRITICAL

A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected systems allow the upload of arbitrary files of any unauthenticated user. …

May 14, 2024
CVE-2024-22267
9.3 CRITICAL

VMware Workstation and Fusion contain a use-after-free vulnerability in the vbluetooth device. A malicious actor with local administrative privileges on a virtual machine may exploit …

May 14, 2024
CVE-2024-4825
9.8 CRITICAL

A vulnerability has been discovered in Agentejo Cockpit CMS v0.5.5 that consists in an arbitrary file upload in ‘/media/api’ parameter via post request. An attacker …

May 14, 2024
CVE-2024-4824
9.8 CRITICAL

Vulnerability in School ERP Pro+Responsive 1.0 that allows SQL injection through the '/SchoolERP/office_admin/' index in the parameters groups_id, examname, classes_id, es_voucherid, es_class, etc. This vulnerability …

May 14, 2024
CVE-2024-4701
9.9 CRITICAL

A path traversal issue potentially leading to remote code execution in Genie for all versions prior to 4.3.18

May 14, 2024
CVE-2024-4671
9.6 CRITICAL KEV

Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to potentially perform a …

May 14, 2024
CVE-2024-4560
9.8 CRITICAL

The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the chatbot_chatgpt_upload_file_to_assistant function in …

May 14, 2024
CVE-2024-4434
9.8 CRITICAL

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the ‘term_id’ parameter in versions up to, and including, …

May 14, 2024
CVE-2024-4413
9.8 CRITICAL

The Hotel Booking Lite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.11.1 via deserialization of untrusted …

May 14, 2024
CVE-2024-3806
9.8 CRITICAL

The Porto theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.1.0 via the 'porto_ajax_posts' function. This makes …

May 14, 2024
CVE-2024-3263
9.8 CRITICAL

YMS VIS Pro is an information system for veterinary and food administration, veterinarians and farm. Due to a combination of improper method for system credentials …

May 14, 2024
CVE-2024-3070
9.8 CRITICAL

The Last Viewed Posts by WPBeginner plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.0 via deserialization …

May 14, 2024
CVE-2024-3016
9.1 CRITICAL

NEC Platforms DT900 and DT900S Series 5.0.0.0 – v5.3.4.4, v5.4.0.0 – v5.6.0.20 allows an attacker to access a non-documented the system settings to change settings …

May 14, 2024
CVE-2024-35099
9.8 CRITICAL

TOTOLINK LR350 V9.3.5u.6698_B20230810 was discovered to contain a stack overflow via the password parameter in the function loginAuth.

May 14, 2024
CVE-2024-35049
9.1 CRITICAL

SurveyKing v1.3.1 was discovered to keep users' sessions active after logout. Related to an incomplete fix for CVE-2022-25590.

May 14, 2024
CVE-2024-34945
9.8 CRITICAL

Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the PPW parameter at ip/goform/WizardHandle.

May 14, 2024
CVE-2024-34943
9.8 CRITICAL

Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the page parameter at ip/goform/NatStaticSetting.

May 14, 2024
CVE-2024-34706
9.8 CRITICAL

Valtimo is an open source business process and case management platform. When opening a form in Valtimo, the access token (JWT) of the user is …

May 14, 2024
CVE-2024-34555
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in URBAN BASE Z-Downloads.This issue affects Z-Downloads: from n/a through 1.11.3.

May 14, 2024
CVE-2024-34440
9.1 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 2.2.63.

May 14, 2024
CVE-2024-34416
9.1 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Pk Favicon Manager.This issue affects Pk Favicon Manager: from n/a through 2.1.

May 14, 2024
CVE-2024-34411
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Thomas Scholl canvasio3D Light.This issue affects canvasio3D Light: from n/a through 2.5.0.

May 14, 2024
CVE-2024-34365
9.1 CRITICAL

** UNSUPPORTED WHEN ASSIGNED ** Improper Input Validation vulnerability in Apache Karaf Cave.This issue affects all versions of Apache Karaf Cave. As this project is …

May 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.