CVE Database

10843+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-33512
9.8 CRITICAL

There is a buffer overflow vulnerability in the underlying Local User Authentication Database service that could lead to unauthenticated remote code execution by sending specially …

May 1, 2024
CVE-2024-33511
9.8 CRITICAL

There is a buffer overflow vulnerability in the underlying Automatic Reporting service that could lead to unauthenticated remote code execution by sending specially crafted packets …

May 1, 2024
CVE-2024-26305
9.8 CRITICAL

There is a buffer overflow vulnerability in the underlying Utility daemon that could lead to unauthenticated remote code execution by sending specially crafted packets destined …

May 1, 2024
CVE-2024-26304
9.8 CRITICAL

There is a buffer overflow vulnerability in the underlying L2/L3 Management service that could lead to unauthenticated remote code execution by sending specially crafted packets …

May 1, 2024
CVE-2024-33775
9.8 CRITICAL

An issue with the Autodiscover component in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted Dashlet.

May 1, 2024
CVE-2024-27053
9.1 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: wifi: wilc1000: fix RCU usage in connect path With lockdep enabled, calls to the connect …

May 1, 2024
CVE-2024-33835
9.8 CRITICAL

Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the remoteIp parameter from formSetSafeWanWebMan function.

May 1, 2024
CVE-2024-32017
9.8 CRITICAL

RIOT is a real-time multi-threading operating system that supports a range of devices that are typically 8-bit, 16-bit and 32-bit microcontrollers. The size check in …

May 1, 2024
CVE-2024-33768
9.8 CRITICAL

lunasvg v2.3.9 was discovered to contain a segmentation violation via the component composition_solid_source_over.

May 1, 2024
CVE-2024-3411
9.1 CRITICAL

Implementations of IPMI Authenticated sessions does not provide enough randomness to protect from session hijacking, allowing an attacker to use either predictable IPMI Session ID …

Apr 30, 2024
CVE-2023-49473
9.8 CRITICAL

Shenzhen JF6000 Cloud Media Collaboration Processing Platform firmware version V1.2.0 and software version V2.0.0 build 6245 is vulnerable to Incorrect Access Control.

Apr 30, 2024
CVE-2019-19755
9.1 CRITICAL

ethOS through 1.3.3 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks and makes identification of all public IPv4 nodes …

Apr 30, 2024
CVE-2019-19753
9.1 CRITICAL

SimpleMiningOS through v1259 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks and makes identification of all public IPv4 nodes …

Apr 30, 2024
CVE-2019-19752
9.8 CRITICAL

nvOC through 3.2 ships with SSH host keys baked into the installation image, which allows man-in-the-middle attacks and makes identification of all public IPv4 nodes …

Apr 30, 2024
CVE-2024-33308
9.1 CRITICAL

An issue in TVS Motor Company Limited TVS Connet Android v.4.5.1 and iOS v.5.0.0 allows a remote attacker to escalate privileges via the Emergency Contact …

Apr 30, 2024
CVE-2024-33275
9.8 CRITICAL

SQL injection vulnerability in Webbax supernewsletter v.1.4.21 and before allows a remote attacker to escalate privileges via the Super Newsletter module in the product_search.php components.

Apr 30, 2024
CVE-2024-33273
9.8 CRITICAL

SQL injection vulnerability in shipup before v.3.3.0 allows a remote attacker to escalate privileges via the getShopID function.

Apr 30, 2024
CVE-2024-33267
9.8 CRITICAL

SQL Injection vulnerability in Hero hfheropayment v.1.2.5 and before allows an attacker to escalate privileges via the HfHeropaymentGatewayBackModuleFrontController::initContent() function.

Apr 30, 2024
CVE-2024-34048
9.8 CRITICAL

O-RAN RIC I-Release e2mgr lacks array size checks in E2nodeConfigUpdateNotificationHandler.

Apr 30, 2024
CVE-2023-50434
9.8 CRITICAL

emdns_resolve_raw in emdns.c in emdns through fbd1eef calls strlen with an input that may not be '\0' terminated, leading to a stack-based buffer over-read. This …

Apr 29, 2024
CVE-2024-33350
9.8 CRITICAL

Directory Traversal vulnerability in TaoCMS v.3.0.2 allows a remote attacker to execute arbitrary code and obtain sensitive information via the include/model/file.php component.

Apr 29, 2024
CVE-2024-33435
9.8 CRITICAL

Insecure Permissions vulnerability in Guangzhou Yingshi Electronic Technology Co. Ncast Yingshi high-definition intelligent recording and playback system 2007-2017 allows a remote attacker to execute arbitrary …

Apr 29, 2024
CVE-2024-33276
9.8 CRITICAL

SQL Injection vulnerability in FME Modules preorderandnotication v.3.1.0 and before allows a remote attacker to run arbitrary SQL commands via the PreorderModel::getIdProductAttributesByIdAttributes() method.

Apr 29, 2024
CVE-2024-33269
9.8 CRITICAL

SQL Injection vulnerability in Prestaddons flashsales 1.9.7 and before allows an attacker to run arbitrary SQL commands via the FsModel::getFlashSales method.

Apr 29, 2024
CVE-2024-33268
9.8 CRITICAL

SQL Injection vulnerability in Digincube mdgiftproduct before 1.4.1 allows an attacker to run arbitrary SQL commands via the MdGiftRule::addGiftToCart method.

Apr 29, 2024
CVE-2024-33266
9.8 CRITICAL

SQL Injection vulnerability in Helloshop deliveryorderautoupdate v.2.8.1 and before allows an attacker to run arbitrary SQL commands via the DeliveryorderautoupdateOrdersModuleFrontController::initContent function.

Apr 29, 2024
CVE-2024-31822
9.8 CRITICAL

An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the saveLanguageFiles method of the Languages.php component.

Apr 29, 2024
CVE-2024-31820
9.8 CRITICAL

An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the getLangFolderForEdit method of the Languages.php component.

Apr 29, 2024
CVE-2024-31705
9.8 CRITICAL

An issue in Infotel Conseil GLPI v.10.X.X and after allows a remote attacker to execute arbitrary code via the insufficient validation of user-supplied input.

Apr 29, 2024
CVE-2024-33449
9.8 CRITICAL

An SSRF issue in the PDFMyURL service allows a remote attacker to obtain sensitive information and execute arbitrary code via a POST request in the …

Apr 29, 2024
CVE-2024-33445
9.8 CRITICAL

An issue in hisiphp v2.0.111 allows a remote attacker to execute arbitrary code via a crafted script to the SystemPlugins::mkInfo parameter in the SystemPlugins.php component.

Apr 29, 2024
CVE-2024-33444
9.8 CRITICAL

SQL injection vulnerability in onethink v.1.1 allows a remote attacker to escalate privileges via a crafted script to the ModelModel.class.php component.

Apr 29, 2024
CVE-2024-32491
9.8 CRITICAL

An issue was discovered in Znuny and Znuny LTS 6.0.31 through 6.5.7 and Znuny 7.0.1 through 7.0.16 where a logged-in user can upload a file …

Apr 29, 2024
CVE-2024-4306
9.9 CRITICAL

Critical unrestricted file upload vulnerability in HubBank affecting version 1.0.2. This vulnerability allows a registered user to upload malicious PHP files via upload document fields, …

Apr 29, 2024
CVE-2024-3375
9.4 CRITICAL

Incorrect Permission Assignment for Critical Resource vulnerability in Havelsan Inc. Dialogue allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Dialogue: from v1.83 before …

Apr 29, 2024
CVE-2024-33566
10.0 CRITICAL

Missing Authorization vulnerability in N-Media OrderConvo allows OS Command Injection.This issue affects OrderConvo: from n/a through 12.4.

Apr 29, 2024
CVE-2024-33553
9.0 CRITICAL

Deserialization of Untrusted Data vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.5.

Apr 29, 2024
CVE-2024-3191
9.8 CRITICAL

A vulnerability, which was classified as critical, has been found in MailCleaner up to 2023.03.14. This issue affects some unknown processing of the component Email …

Apr 29, 2024
CVE-2024-33546
9.6 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team WZone allows SQL Injection.This issue affects WZone: from n/a through …

Apr 29, 2024
CVE-2024-33544
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team WZone allows SQL Injection.This issue affects WZone: from n/a through …

Apr 29, 2024
CVE-2024-33559
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 8theme XStore allows SQL Injection.This issue affects XStore: from n/a through …

Apr 29, 2024
CVE-2024-33551
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 8theme XStore Core allows SQL Injection.This issue affects XStore Core: from …

Apr 29, 2024
CVE-2024-4300
9.8 CRITICAL

E-WEBInformationCo. FS-EZViewer(Web) exposes sensitive information in the service. A remote attacker can obtain the database configuration file path through the webpage source code without login. …

Apr 29, 2024
CVE-2024-1874
9.4 CRITICAL

In PHP versions 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, when using proc_open() command with array syntax, due to insufficient escaping, if the …

Apr 29, 2024
CVE-2024-3342
9.9 CRITICAL

The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to SQL Injection via the 'events' attribute of the 'mp-timetable' shortcode in all …

Apr 27, 2024
CVE-2024-30804
9.8 CRITICAL

An issue discovered in the DeviceIoControl component in ASUS Fan_Xpert before v.10013 allows an attacker to execute arbitrary code via crafted IOCTL requests.

Apr 26, 2024
CVE-2024-28322
9.8 CRITICAL

SQL Injection vulnerability in /event-management-master/backend/register.php in PuneethReddyHC Event Management 1.0 allows attackers to run arbitrary SQL commands via the event_id parameter in a crafted POST …

Apr 26, 2024
CVE-2024-32881
9.8 CRITICAL

Danswer is the AI Assistant connected to company's docs, apps, and people. Danswer is vulnerable to unauthorized access to GET/SET of Slack Bot Tokens. Anyone …

Apr 26, 2024
CVE-2024-31601
9.8 CRITICAL

An issue in Beijing Panabit Network Software Co., Ltd Panalog big data analysis platform v. 20240323 and before allows attackers to execute arbitrary code via …

Apr 26, 2024
CVE-2024-25343
9.1 CRITICAL

Tenda N300 F3 router vulnerability allows users to bypass intended security policy and create weak passwords.

Apr 26, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.