CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-27179
4.7 MEDIUM

Admin cookies are written in clear-text in logs. An attacker can retrieve them and bypass the authentication mechanism. As for the affected products/models/versions, see the …

Jun 14, 2024
CVE-2024-27178
7.2 HIGH

An attacker can get Remote Code Execution by overwriting files. Overwriting files is enable by falsifying file name variable. This vulnerability can be executed in …

Jun 14, 2024
CVE-2024-27177
7.2 HIGH

An attacker can get Remote Code Execution by overwriting files. Overwriting files is enable by falsifying package name variable. This vulnerability can be executed in …

Jun 14, 2024
CVE-2024-27176
7.2 HIGH

An attacker can get Remote Code Execution by overwriting files. Overwriting files is enable by falsifying session ID variable. This vulnerability can be executed in …

Jun 14, 2024
CVE-2024-27175
4.4 MEDIUM

Remote Command program allows an attacker to read any file using a Local File Inclusion vulnerability. An attacker can read any file on the printer. …

Jun 14, 2024
CVE-2024-27174
9.8 CRITICAL

Remote Command program allows an attacker to get Remote Code Execution. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute …

Jun 14, 2024
CVE-2024-27173
9.8 CRITICAL

Remote Command program allows an attacker to get Remote Code Execution by overwriting existing Python files containing executable code. This vulnerability can be executed in …

Jun 14, 2024
CVE-2024-27172
9.8 CRITICAL

Remote Command program allows an attacker to get Remote Code Execution. As for the affected products/models/versions, see the reference URL.

Jun 14, 2024
CVE-2024-27171
7.4 HIGH

A remote attacker using the insecure upload functionality will be able to overwrite any Python file and get Remote Code Execution. As for the affected …

Jun 14, 2024
CVE-2024-27170
7.4 HIGH

It was observed that all the Toshiba printers contain credentials used for WebDAV access in the readable file. Then, it is possible to get a …

Jun 14, 2024
CVE-2024-27169
8.4 HIGH

Toshiba printers provides API without authentication for internal access. A local attacker can bypass authentication in applications, providing administrative access. As for the affected products/models/versions, …

Jun 14, 2024
CVE-2024-27168
7.1 HIGH

It appears that some hardcoded keys are used for authentication to internal API. Knowing these private keys may allow attackers to bypass authentication and reach …

Jun 14, 2024
CVE-2024-27167
7.4 HIGH

Toshiba printers use Sendmail to send emails to recipients. Sendmail is used with several insecure directories. A local attacker can inject a malicious Sendmail configuration …

Jun 14, 2024
CVE-2024-27166
7.4 HIGH

Coredump binaries in Toshiba printers have incorrect permissions. A local attacker can steal confidential information. As for the affected products/models/versions, see the reference URL.

Jun 14, 2024
CVE-2024-27165
7.8 HIGH

Toshiba printers contain a suidperl binary and it has a Local Privilege Escalation vulnerability. A local attacker can get root privileges. As for the affected …

Jun 14, 2024
CVE-2024-27164
7.1 HIGH

Toshiba printers contain hardcoded credentials. As for the affected products/models/versions, see the reference URL.

Jun 14, 2024
CVE-2024-27163
6.5 MEDIUM

Toshiba printers will display the password of the admin user in clear-text and additional passwords when sending 2 specific HTTP requests to the internal API. …

Jun 14, 2024
CVE-2024-27162
6.1 MEDIUM

Toshiba printers provide a web interface that will load the JavaScript file. The file contains insecure codes vulnerable to XSS and is loaded inside all …

Jun 14, 2024
CVE-2024-27161
6.2 MEDIUM

all the Toshiba printers have programs containing a hardcoded key used to encrypt files. An attacker can decrypt the encrypted files using the hardcoded key. …

Jun 14, 2024
CVE-2024-27160
6.2 MEDIUM

All the Toshiba printers contain a shell script using the same hardcoded key to encrypt logs. An attacker can decrypt the encrypted files using the …

Jun 14, 2024
CVE-2024-27159
6.2 MEDIUM

All the Toshiba printers contain a shell script using the same hardcoded key to encrypt logs. An attacker can decrypt the encrypted files using the …

Jun 14, 2024
CVE-2024-27158
7.4 HIGH

All the Toshiba printers share the same hardcoded root password. As for the affected products/models/versions, see the reference URL.

Jun 14, 2024
CVE-2024-27157
6.8 MEDIUM

The sessions are stored in clear-text logs. An attacker can retrieve authentication sessions. A remote attacker can retrieve the credentials and bypass the authentication mechanism. …

Jun 14, 2024
CVE-2024-27156
6.8 MEDIUM

The session cookies, used for authentication, are stored in clear-text logs. An attacker can retrieve authentication sessions. A remote attacker can retrieve the credentials and …

Jun 14, 2024
CVE-2024-27155
7.7 HIGH

The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. The programs can be replaced by …

Jun 14, 2024
CVE-2024-0892
4.3 MEDIUM

The Schema App Structured Data plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due …

Jun 14, 2024
CVE-2023-6492
4.3 MEDIUM

The Simple Sitemap – Create a Responsive HTML Sitemap plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, …

Jun 14, 2024
CVE-2024-3080
9.8 CRITICAL

Certain ASUS router models have authentication bypass vulnerability, allowing unauthenticated remote attackers to log in the device.

Jun 14, 2024
CVE-2024-3079
7.2 HIGH

Certain models of ASUS routers have buffer overflow vulnerabilities, allowing remote attackers with administrative privileges to execute arbitrary commands on the device.

Jun 14, 2024
CVE-2024-27154
6.2 MEDIUM

Passwords are stored in clear-text logs. An attacker can retrieve passwords. As for the affected products/models/versions, see the reference URL.

Jun 14, 2024
CVE-2024-27153
7.4 HIGH

The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. As for the affected products/models/versions, see …

Jun 14, 2024
CVE-2024-27152
7.4 HIGH

The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. As for the affected products/models/versions, see …

Jun 14, 2024
CVE-2024-27151
7.4 HIGH

The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. The programs can be replaced by …

Jun 14, 2024
CVE-2024-27150
7.4 HIGH

The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. As for the affected products/models/versions, see …

Jun 14, 2024
CVE-2024-27149
7.4 HIGH

The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. As for the affected products/models/versions, see …

Jun 14, 2024
CVE-2024-27148
7.4 HIGH

The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. As for the affected products/models/versions, see …

Jun 14, 2024
CVE-2024-27147
7.4 HIGH

The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. As for the affected products/models/versions, see …

Jun 14, 2024
CVE-2024-27146
6.7 MEDIUM

The Toshiba printers do not implement privileges separation. As for the affected products/models/versions, see the reference URL.

Jun 14, 2024
CVE-2024-27145
9.8 CRITICAL

The Toshiba printers provide several ways to upload files using the admin web interface. An attacker can remotely compromise any Toshiba printer. An attacker can …

Jun 14, 2024
CVE-2024-27144
9.8 CRITICAL

The Toshiba printers provide several ways to upload files using the web interface without authentication. An attacker can overwrite any insecure files. And the Toshiba …

Jun 14, 2024
CVE-2024-27143
9.8 CRITICAL

Toshiba printers use SNMP for configuration. Using the private community, it is possible to remotely execute commands as root on the remote printer. Using this …

Jun 14, 2024
CVE-2024-27142
5.9 MEDIUM

Toshiba printers use XML communication for the API endpoint provided by the printer. For the endpoint, XML parsing library is used and it is vulnerable …

Jun 14, 2024
CVE-2024-27141
5.9 MEDIUM

Toshiba printers use XML communication for the API endpoint provided by the printer. For the endpoint, XML parsing library is used and it is vulnerable …

Jun 14, 2024
CVE-2024-5985
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Best Online News Portal 1.0. This affects an unknown part of the file /admin/index.php. The …

Jun 14, 2024
CVE-2024-5984
7.3 HIGH

A vulnerability was found in itsourcecode Online Bookstore 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the …

Jun 14, 2024
CVE-2024-5983
7.3 HIGH

A vulnerability was found in itsourcecode Online Bookstore 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the …

Jun 14, 2024
CVE-2024-5981
6.3 MEDIUM

A vulnerability was found in itsourcecode Online House Rental System 1.0. It has been classified as critical. Affected is an unknown function of the file …

Jun 14, 2024
CVE-2023-51523
4.3 MEDIUM

Missing Authorization vulnerability in WriterSystem WooCommerce Easy Duplicate Product.This issue affects WooCommerce Easy Duplicate Product: from n/a through 0.3.0.7.

Jun 14, 2024
CVE-2023-51516
5.4 MEDIUM

Missing Authorization vulnerability in Business Directory Team Business Directory Plugin.This issue affects Business Directory Plugin: from n/a through 6.3.9.

Jun 14, 2024
CVE-2023-51507
5.3 MEDIUM

Missing Authorization vulnerability in ExpressTech Quiz And Survey Master.This issue affects Quiz And Survey Master: from n/a through 8.1.16.

Jun 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.