CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-23158
7.8 HIGH

A maliciously crafted IGES file, when parsed in ASMImport229A.dll through Autodesk applications, can be used to cause a use-after-free vulnerability. A malicious actor can leverage …

Jun 25, 2024
CVE-2024-23157
7.8 HIGH

A maliciously crafted SLDASM or SLDPRT file, when parsed in ODXSW_DLL.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. …

Jun 25, 2024
CVE-2024-23156
7.8 HIGH

A maliciously crafted 3DM file, when parsed in opennurbs.dll and ASMkern229A.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. …

Jun 25, 2024
CVE-2024-23155
7.8 HIGH

A maliciously crafted MODEL file, when parsed in atf_asm_interface.dll through Autodesk applications, can be used to cause a Heap-based Buffer Overflow. A malicious actor can …

Jun 25, 2024
CVE-2024-23154
7.8 HIGH

A maliciously crafted SLDPRT file, when parsed in ODXSW_DLL.dll through Autodesk applications, can be used to cause a Heap-based Overflow. A malicious actor can leverage …

Jun 25, 2024
CVE-2024-23153
7.8 HIGH

A maliciously crafted MODEL file, when parsed in libodx.dll through Autodesk applications, can force an Out-of-Bounds Read. A malicious actor can leverage this vulnerability to …

Jun 25, 2024
CVE-2024-23152
7.8 HIGH

A maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk applications, can force an Out-of-Bounds Read. A malicious actor can leverage this vulnerability to …

Jun 25, 2024
CVE-2024-23151
7.8 HIGH

A maliciously crafted 3DM file, when parsed in ASMkern229A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability …

Jun 25, 2024
CVE-2024-23150
7.8 HIGH

A maliciously crafted PRT file, when parsed in odxug_dll.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability …

Jun 25, 2024
CVE-2024-6295
3.9 LOW

udn News Android APP stores the unencrypted user session in the local database when user log into the application. A malicious APP or an attacker …

Jun 25, 2024
CVE-2024-37002
7.8 HIGH

A maliciously crafted MODEL file, when parsed in ASMkern229A.dllthrough Autodesk applications, can be used to uninitialized variables. This vulnerability, along with other vulnerabilities, could lead …

Jun 25, 2024
CVE-2024-37001
7.8 HIGH

A maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk applications, can be used to cause a Heap-based Overflow. A malicious actor can leverage …

Jun 25, 2024
CVE-2024-37000
7.8 HIGH

A maliciously crafted X_B file, when parsed in pskernel.DLL through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, …

Jun 25, 2024
CVE-2024-23149
7.8 HIGH

A maliciously crafted SLDDRW file, when parsed in ODXSW_DLL.dll through Autodesk applications, can force an Out-of-Bound Read. A malicious actor can leverage this vulnerability to …

Jun 25, 2024
CVE-2024-23148
7.8 HIGH

A maliciously crafted CATPRODUCT file, when parsed in CC5Dll.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, …

Jun 25, 2024
CVE-2024-23147
7.8 HIGH

A maliciously crafted CATPART, X_B and STEP, when parsed in ASMKERN228A.dll and ASMKERN229A.dll through Autodesk applications, can lead to a memory corruption vulnerability by write …

Jun 25, 2024
CVE-2024-23146
7.8 HIGH

A maliciously crafted X_B and X_T file, when parsed in pskernel.DLL through through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may …

Jun 25, 2024
CVE-2024-23145
7.8 HIGH

A maliciously crafted PRT file, when parsed in opennurbs.dll through Autodesk applications, can force an Out-of-Bound Read. A malicious actor can leverage this vulnerability to …

Jun 25, 2024
CVE-2023-5038
7.5 HIGH

badmonkey, a Security Researcher has found a flaw that allows for a unauthenticated DoS attack on the camera. An attacker runs a crafted URL, nobody …

Jun 25, 2024
CVE-2024-6294
3.9 LOW

udn News Android APP stores the user session in logcat file when user log into the APP. A malicious APP or an attacker with physical …

Jun 25, 2024
CVE-2024-23144
7.8 HIGH

A maliciously crafted CATPART file, when parsed in CC5Dll.dll and ASMBASE228A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage …

Jun 25, 2024
CVE-2024-23143
7.8 HIGH

A maliciously crafted 3DM, MODEL and X_B file, when parsed in ASMkern229A.dll and ASMBASE229A.dll through Autodesk applications, can force an Out-of-Bound Read and/or Out-of-Bound Write. …

Jun 25, 2024
CVE-2024-23142
7.8 HIGH

A maliciously crafted CATPART, STP, and MODEL file, when parsed in atf_dwg_consumer.dll, rose_x64_vc15.dll and libodxdll through Autodesk applications, can cause a use-after-free vulnerability. This vulnerability, …

Jun 25, 2024
CVE-2024-23141
7.8 HIGH

A maliciously crafted MODEL file, when parsed in libodxdll through Autodesk applications, can cause a double free. This vulnerability, along with other vulnerabilities, can lead …

Jun 25, 2024
CVE-2024-23140
7.8 HIGH

A maliciously crafted 3DM and MODEL file, when parsed in opennurbs.dll and atf_api.dll through Autodesk applications, can force an Out-of-Bound Read. A malicious actor can …

Jun 25, 2024
CVE-2024-22385
4.4 MEDIUM

Incorrect Default Permissions vulnerability in Hitachi Storage Provider for VMware vCenter allows local users to read and write specific files.This issue affects Hitachi Storage Provider …

Jun 25, 2024
CVE-2023-6198
9.3 CRITICAL

Use of Hard-coded Credentials vulnerability in Baicells Snap Router BaiCE_BMI on EP3011 (User Passwords modules) allows unauthorized access to the device.

Jun 25, 2024
CVE-2024-36683
7.3 HIGH

SQL injection vulnerability in the module "Products Alert" (productsalert) before 1.7.4 from Smart Modules for PrestaShop allows attackers to obtain sensitive information and cause other …

Jun 24, 2024
CVE-2024-36681
9.8 CRITICAL

SQL Injection vulnerability in the module "Isotope" (pk_isotope) <=1.7.3 from Promokit.eu for PrestaShop allows attackers to obtain sensitive information and cause other impacts via `pk_isotope::saveData` …

Jun 24, 2024
CVE-2024-34992
8.8 HIGH

SQL Injection vulnerability in the module "Help Desk - Customer Support Management System" (helpdesk) up to version 2.4.0 from FME Modules for PrestaShop allows attackers …

Jun 24, 2024
CVE-2024-34988
9.8 CRITICAL

SQL injection vulnerability in the module "Complete for Create a Quote in Frontend + Backend Pro" (askforaquotemodul) <= 1.0.51 from Buy Addons for PrestaShop allows …

Jun 24, 2024
CVE-2024-22168

A Cross-Site Scripting (XSS) vulnerability on the My Cloud, My Cloud Home, SanDisk ibi, and WD Cloud web apps was found which could allow an …

Jun 24, 2024
CVE-2023-50029
10.0 CRITICAL

PHP Injection vulnerability in the module "M4 PDF Extensions" (m4pdf) up to version 3.3.2 from PrestaAddons for PrestaShop allows attackers to run arbitrary code via …

Jun 24, 2024
CVE-2024-6293
8.8 HIGH

Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Jun 24, 2024
CVE-2024-6292
8.8 HIGH

Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Jun 24, 2024
CVE-2024-6291
8.8 HIGH

Use after free in Swiftshader in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Jun 24, 2024
CVE-2024-6290
8.8 HIGH

Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Jun 24, 2024
CVE-2024-36682
7.5 HIGH

In the module "Theme settings" (pk_themesettings) <= 1.8.8 from Promokit.eu for PrestaShop, a guest can download all email collected while SHOP is in maintenance mode. …

Jun 24, 2024
CVE-2024-34991
7.5 HIGH

In the module "Axepta" (axepta) before 1.3.4 from Quadra Informatique for PrestaShop, a guest can download partial credit card information (expiry date) / postal address …

Jun 24, 2024
CVE-2024-33898
9.8 CRITICAL

Axiros AXESS Auto Configuration Server (ACS) 4.x and 5.0.0 is affected by an Incorrect Access Control vulnerability. An authorization bypass allows remote attackers to achieve …

Jun 24, 2024
CVE-2023-45195
5.3 MEDIUM

Adminer and AdminerEvo are vulnerable to SSRF via database connection fields. This could allow an unauthenticated remote attacker to enumerate or access systems the attacker …

Jun 24, 2024
CVE-2024-38903
4.1 MEDIUM

H3C Magic R230 V100R002's udpserver opens port 9034, allowing attackers to execute arbitrary commands.

Jun 24, 2024
CVE-2024-38902
9.8 CRITICAL

H3C Magic R230 V100R002 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.

Jun 24, 2024
CVE-2024-38897
5.3 MEDIUM

WAVLINK WN551K1'live_check.shtml enables attackers to obtain sensitive router information.

Jun 24, 2024
CVE-2024-38896
5.3 MEDIUM

WAVLINK WN551K1 found a command injection vulnerability through the start_hour parameter of /cgi-bin/nightled.cgi.

Jun 24, 2024
CVE-2024-38895
5.3 MEDIUM

WAVLINK WN551K1'live_mfg.shtml enables attackers to obtain sensitive router information.

Jun 24, 2024
CVE-2024-38894
5.3 MEDIUM

WAVLINK WN551K1 found a command injection vulnerability through the IP parameter of /cgi-bin/touchlist_sync.cgi.

Jun 24, 2024
CVE-2024-38892
6.5 MEDIUM

An issue in Wavlink WN551K1 allows a remote attacker to obtain sensitive information via the ExportAllSettings.sh component.

Jun 24, 2024
CVE-2024-37759
9.8 CRITICAL

DataGear v5.0.0 and earlier was discovered to contain a SpEL (Spring Expression Language) expression injection vulnerability via the Data Viewing interface.

Jun 24, 2024
CVE-2023-45196
7.5 HIGH

Adminer and AdminerEvo allow an unauthenticated remote attacker to cause a denial of service by connecting to an attacker-controlled service that responds with HTTP redirects. …

Jun 24, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.