CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-6580
6.5 MEDIUM

The /n software IPWorks SSH library SFTPServer component can be induced to make unintended filesystem or network path requests when loading a SSH public key …

Jul 8, 2024
CVE-2024-6227
7.5 HIGH

A vulnerability in aimhubio/aim version 3.19.3 allows an attacker to cause an infinite loop by configuring the remote tracking server to point at itself. This …

Jul 8, 2024
CVE-2024-6409
7.0 HIGH

A race condition vulnerability was discovered in how signals are handled by OpenSSH's server (sshd). If a remote attacker does not authenticate within a set …

Jul 8, 2024
CVE-2024-4882

The user may be redirected to an arbitrary site in Sitefinity 15.1.8321.0 and previous versions.

Jul 8, 2024
CVE-2024-39896
7.5 HIGH

Directus is a real-time API and App dashboard for managing SQL database content. When relying on SSO providers in combination with local authentication it can …

Jul 8, 2024
CVE-2024-1305
9.8 CRITICAL

tap-windows6 driver version 9.26 and earlier does not properly check the size data of incomming write operations which an attacker can use to overflow memory …

Jul 8, 2024
CVE-2024-39895
6.5 MEDIUM

Directus is a real-time API and App dashboard for managing SQL database content. A denial of service (DoS) attack by field duplication in GraphQL is …

Jul 8, 2024
CVE-2024-39701
6.3 MEDIUM

Directus is a real-time API and App dashboard for managing SQL database content. Directus >=9.23.0, <=v10.5.3 improperly handles _in, _nin operators. It evaluates empty arrays …

Jul 8, 2024
CVE-2024-39312
5.3 MEDIUM

Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier or using explicit encoding of the parameters. A …

Jul 8, 2024
CVE-2024-34702
5.3 MEDIUM

Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier or using explicit encoding of the parameters. Prior …

Jul 8, 2024
CVE-2024-6564
6.7 MEDIUM

Buffer overflow in "rcar_dev_init" due to using due to using untrusted data (rcar_image_number) as a loop counter before verifying it against RCAR_MAX_BL3X_IMAGE. This could lead …

Jul 8, 2024
CVE-2024-6563
7.5 HIGH

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Renesas arm-trusted-firmware allows Local Execution of Code. This vulnerability is associated with program …

Jul 8, 2024
CVE-2024-39699
5.0 MEDIUM

Directus is a real-time API and App dashboard for managing SQL database content. There was already a reported SSRF vulnerability via file import. It was …

Jul 8, 2024
CVE-2024-39695
5.3 MEDIUM

Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in …

Jul 8, 2024
CVE-2024-39203
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in the Backend Theme Management module of Z-BlogPHP v1.7.3 allows attackers to execute arbitrary web scripts or HTML via a …

Jul 8, 2024
CVE-2024-39202
8.8 HIGH

D-Link DIR-823X firmware - 240126 was discovered to contain a remote command execution (RCE) vulnerability via the dhcpd_startip parameter at /goform/set_lan_settings.

Jul 8, 2024
CVE-2024-31504
7.5 HIGH

Buffer Overflow vulnerability in SILA Embedded Solutions GmbH freemodbus v.2018-09-12 allows a remtoe attacker to cause a denial of service via the LINUXTCP server component.

Jul 8, 2024
CVE-2024-23562
5.3 MEDIUM

A security vulnerability in HCL Domino could allow disclosure of sensitive configuration information. A remote unauthenticated attacker could exploit this vulnerability to obtain information to …

Jul 8, 2024
CVE-2024-21778
7.2 HIGH

A heap-based buffer overflow vulnerability exists in the configuration file mib_init_value_array functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted .dat file can lead …

Jul 8, 2024
CVE-2023-50383
7.2 HIGH

Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can …

Jul 8, 2024
CVE-2023-50382
7.2 HIGH

Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can …

Jul 8, 2024
CVE-2023-50381
7.2 HIGH

Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can …

Jul 8, 2024
CVE-2023-50330
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the boa getInfo functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can …

Jul 8, 2024
CVE-2023-50244
7.2 HIGH

Two stack-based buffer overflow vulnerabilities exist in the boa formIpQoS functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can …

Jul 8, 2024
CVE-2023-50243
7.2 HIGH

Two stack-based buffer overflow vulnerabilities exist in the boa formIpQoS functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can …

Jul 8, 2024
CVE-2023-50240
7.2 HIGH

Two stack-based buffer overflow vulnerabilities exist in the boa set_RadvdInterfaceParam functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can …

Jul 8, 2024
CVE-2023-50239
7.2 HIGH

Two stack-based buffer overflow vulnerabilities exist in the boa set_RadvdInterfaceParam functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can …

Jul 8, 2024
CVE-2023-49867
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can …

Jul 8, 2024
CVE-2023-49595
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the boa rollback_control_code functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can …

Jul 8, 2024
CVE-2023-49593
7.2 HIGH

Leftover debug code exists in the boa formSysCmd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623. A specially crafted network request can lead to arbitrary command execution.

Jul 8, 2024
CVE-2023-49073
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the boa formFilter functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can …

Jul 8, 2024
CVE-2023-48270
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the boa formDnsv6 functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can …

Jul 8, 2024
CVE-2023-47856
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the boa set_RadvdPrefixParam functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can …

Jul 8, 2024
CVE-2023-47677
8.8 HIGH

A cross-site request forgery (csrf) vulnerability exists in the boa CSRF protection functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted network request can …

Jul 8, 2024
CVE-2023-46685
9.8 CRITICAL

A hard-coded password vulnerability exists in the telnetd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623. A set of specially crafted network packets can lead to arbitrary command …

Jul 8, 2024
CVE-2023-45742
7.2 HIGH

An integer overflow vulnerability exists in the boa updateConfigIntoFlash functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead …

Jul 8, 2024
CVE-2023-45215
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the boa setRepeaterSsid functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can …

Jul 8, 2024
CVE-2023-41251
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the boa formRoute functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can …

Jul 8, 2024
CVE-2023-34435
7.2 HIGH

A firmware update vulnerability exists in the boa formUpload functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted network packets can lead to arbitrary …

Jul 8, 2024
CVE-2024-39677
5.9 MEDIUM

NHibernate is an object-relational mapper for the .NET framework. A SQL injection vulnerability exists in some types implementing ILiteralType.ObjectToSQLString. Callers of these methods are exposed …

Jul 8, 2024
CVE-2024-39308
5.4 MEDIUM

RailsAdmin is a Rails engine that provides an interface for managing data. RailsAdmin list view has the XSS vulnerability, caused by improperly-escaped HTML title attribute. …

Jul 8, 2024
CVE-2024-25639
5.9 MEDIUM

Khoj is an application that creates personal AI agents. The Khoj Obsidian, Desktop and Web clients inadequately sanitize the AI model's response and user inputs. …

Jul 8, 2024
CVE-2024-4341
6.5 MEDIUM

Authorization Bypass Through User-Controlled Key, Missing Authorization vulnerability in ExtremePacs Extreme XDS allows Collect Data as Provided by Users.This issue affects Extreme XDS: before 3928.

Jul 8, 2024
CVE-2024-39743
5.9 MEDIUM

IBM MQ Operator 3.2.2 and IBM MQ Operator 2.0.24 IBM MQ Container Developer Edition is vulnerable to denial of service caused by incorrect memory de-allocation. …

Jul 8, 2024
CVE-2024-39742
8.1 HIGH

IBM MQ Operator 3.2.2 and IBM MQ Operator 2.0.24 could allow a user to bypass authentication under certain configurations due to a partial string comparison …

Jul 8, 2024
CVE-2024-6163
5.3 MEDIUM

Certain http endpoints of Checkmk in Checkmk < 2.3.0p10 < 2.2.0p31, < 2.1.0p46, <= 2.0.0p39 allows remote attacker to bypass authentication and access data

Jul 8, 2024
CVE-2024-37999
7.8 HIGH

A vulnerability has been identified in Medicalis Workflow Orchestrator (All versions). The affected application executes as a trusted account with high privileges and network access. …

Jul 8, 2024
CVE-2024-27903
9.8 CRITICAL

OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in which …

Jul 8, 2024
CVE-2024-27459
7.8 HIGH

The interactive service in OpenVPN 2.6.9 and earlier allows an attacker to send data causing a stack overflow which can be used to execute arbitrary …

Jul 8, 2024
CVE-2024-24974
7.5 HIGH

The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service pipe to be accessed remotely, which allows a remote attacker to interact with …

Jul 8, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.