CVE Database

10843+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-2692
9.0 CRITICAL

SiYuan version 3.0.3 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to Server Side XSS.

Apr 4, 2024
CVE-2024-3272
9.8 CRITICAL KEV

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as very critical, has been found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to …

Apr 4, 2024
CVE-2023-44039
9.1 CRITICAL

In VeridiumID before 3.5.0, the WebAuthn API allows an internal unauthenticated attacker (who can pass enrollment verifications and is allowed to enroll a FIDO key) …

Apr 3, 2024
CVE-2024-30568
9.8 CRITICAL

Netgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the c4-IPAddr parameter.

Apr 3, 2024
CVE-2024-25096
10.0 CRITICAL

Improper Control of Generation of Code ('Code Injection') vulnerability in Canto Inc. Canto allows Code Injection.This issue affects Canto: from n/a through 3.0.7.

Apr 3, 2024
CVE-2024-24707
9.9 CRITICAL

Improper Control of Generation of Code ('Code Injection') vulnerability in Cwicly Builder, SL. Cwicly allows Code Injection.This issue affects Cwicly: from n/a through 1.4.0.2.

Apr 3, 2024
CVE-2023-25699
9.0 CRITICAL

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in VideoWhisper.Com VideoWhisper Live Streaming Integration allows OS Command Injection.This issue …

Apr 3, 2024
CVE-2024-31390
9.9 CRITICAL

: Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Breakdance allows : Code Injection.This issue affects Breakdance: from n/a through 1.7.2.

Apr 3, 2024
CVE-2024-31380
9.9 CRITICAL

Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Oxygen Builder allows Code Injection. Vendor is ignoring report, refuses to patch the issue.This …

Apr 3, 2024
CVE-2024-27972
9.9 CRITICAL

Improper Control of Generation of Code ('Code Injection') vulnerability in Jack Arturo WP Fusion Lite wp-fusion-lite.This issue affects WP Fusion Lite: from n/a through <= …

Apr 3, 2024
CVE-2024-27951
9.1 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Themeisle Multiple Page Generator Plugin – MPG allows Upload a Web Shell to a Web Server.This …

Apr 3, 2024
CVE-2024-25918
9.9 CRITICAL

Improper Control of Generation of Code ('Code Injection') vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.8.

Apr 3, 2024
CVE-2024-28515
9.8 CRITICAL

Buffer Overflow vulnerability in CSAPP_Lab CSAPP Lab3 15-213 Fall 20xx allows a remote attacker to execute arbitrary code via the lab3 of csapp,lab3/buflab-update.pl component.

Apr 3, 2024
CVE-2024-30998
9.8 CRITICAL

SQL Injection vulnerability in PHPGurukul Men Salon Management System v.2.0, allows remote attackers to execute arbitrary code and obtain sensitive information via the email parameter …

Apr 3, 2024
CVE-2021-27312
9.4 CRITICAL

Server Side Request Forgery (SSRF) vulnerability in Gleez Cms 1.2.0, allows remote attackers to execute arbitrary code and obtain sensitive information via modules/gleez/classes/request.php.

Apr 3, 2024
CVE-2024-31011
9.8 CRITICAL

Arbitrary file write vulnerability in beescms v.4.0, allows a remote attacker to execute arbitrary code via a file path that was not isolated and the …

Apr 3, 2024
CVE-2024-31012
9.8 CRITICAL

An issue was discovered in SEMCMS v.4.8, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via the upload.php file.

Apr 3, 2024
CVE-2024-2879
9.8 CRITICAL

The LayerSlider plugin for WordPress is vulnerable to SQL Injection via the ls_get_popup_markup action in versions 7.9.11 and 7.10.0 due to insufficient escaping on the …

Apr 3, 2024
CVE-2024-30166
9.1 CRITICAL

In Mbed TLS 3.3.0 through 3.5.2 before 3.6.0, a malicious client can cause information disclosure or a denial of service because of a stack buffer …

Apr 3, 2024
CVE-2024-25864
9.1 CRITICAL

Server Side Request Forgery (SSRF) vulnerability in Friendica versions after v.2023.12, allows a remote attacker to execute arbitrary code and obtain sensitive information via the …

Apr 3, 2024
CVE-2024-24724
9.8 CRITICAL

Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Remote Code Execution because input is passed to the Twig template engine (messengerSettings.php) without …

Apr 3, 2024
CVE-2024-29432
9.8 CRITICAL

Alldata v0.4.6 was discovered to contain a SQL injection vulnerability via the tablename parameter at /data/masterdata/datas.

Apr 2, 2024
CVE-2024-27604
9.8 CRITICAL

Alldata V0.4.6 is vulnerable to Command execution vulnerability. System commands can be deserialized.

Apr 2, 2024
CVE-2024-27602
9.1 CRITICAL

Alldata V0.4.6 is vulnerable to Incorrect Access Control. A total of many modules interface documents have been leaked.For example, the /api/system/v2/api-docs module.

Apr 2, 2024
CVE-2024-30621
9.8 CRITICAL

Tenda AX1803 v1.0.0.1 contains a stack overflow via the serverName parameter in the function fromAdvSetMacMtuWan.

Apr 2, 2024
CVE-2024-30620
9.8 CRITICAL

Tenda AX1803 v1.0.0.1 contains a stack overflow via the serviceName parameter in the function fromAdvSetMacMtuWan.

Apr 2, 2024
CVE-2024-2389
10.0 CRITICAL

In Flowmon versions prior to 11.1.14 and 12.3.5, an operating system command injection vulnerability has been identified. An unauthenticated user can gain entry to the …

Apr 2, 2024
CVE-2024-31004
9.8 CRITICAL

An issue in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the Ap4StsdAtom.cpp,AP4_StsdAtom::AP4_StsdAtom,mp4fragment.

Apr 2, 2024
CVE-2024-31002
9.8 CRITICAL

Buffer Overflow vulnerability in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the AP4 BitReader::ReadCache() at Ap4Utils.cpp component.

Apr 2, 2024
CVE-2024-29276
9.8 CRITICAL

An issue was discovered in seeyonOA version 8, allows remote attackers to execute arbitrary code via the importProcess method in WorkFlowDesignerController.class component.

Apr 2, 2024
CVE-2024-1863
9.8 CRITICAL

Sante PACS Server Token Endpoint SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante …

Apr 1, 2024
CVE-2023-51573
9.8 CRITICAL

Voltronic Power ViewPower Pro updateManagerPassword Exposed Dangerous Function Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Voltronic Power …

Apr 1, 2024
CVE-2023-51572
9.8 CRITICAL

Voltronic Power ViewPower Pro getMacAddressByIp Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Voltronic …

Apr 1, 2024
CVE-2023-51570
9.8 CRITICAL

Voltronic Power ViewPower Pro Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Apr 1, 2024
CVE-2024-29433
9.8 CRITICAL

A deserialization vulnerability in the FASTJSON component of Alldata v0.4.6 allows attackers to execute arbitrary commands via supplying crafted data.

Apr 1, 2024
CVE-2024-30867
9.8 CRITICAL

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/edit_virtual_site_info.php.

Apr 1, 2024
CVE-2024-30858
9.8 CRITICAL

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/edit_fire_wall.php.

Apr 1, 2024
CVE-2024-30865
9.8 CRITICAL

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/edit_user_login.php.

Apr 1, 2024
CVE-2024-21473
9.8 CRITICAL

Memory corruption while redirecting log file to any file location with any file name.

Apr 1, 2024
CVE-2024-30868
9.8 CRITICAL

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/add_getlogin.php.

Apr 1, 2024
CVE-2023-51803
9.8 CRITICAL

LinuxServer.io Heimdall before 2.5.7 does not prevent use of icons that have non-image data such as the "<?php ?>" substring.

Apr 1, 2024
CVE-2024-31115
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in QuanticaLabs Chauffeur Taxi Booking System for WordPress.This issue affects Chauffeur Taxi Booking System for WordPress: from …

Mar 31, 2024
CVE-2024-31114
9.1 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in biplob018 Shortcode Addons.This issue affects Shortcode Addons: from n/a through 3.2.5.

Mar 31, 2024
CVE-2023-46808
9.9 CRITICAL

An file upload vulnerability in Ivanti ITSM before 2023.4, allows an authenticated remote user to perform file writes to the server. Successful exploitation may lead …

Mar 31, 2024
CVE-2024-2086
10.0 CRITICAL

The Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Your WordPress Site plugin for WordPress …

Mar 30, 2024
CVE-2024-28288
9.8 CRITICAL

Ruijie RG-NBR700GW 10.3(4b12) router lacks cookie verification when resetting the password, resulting in an administrator password reset vulnerability. An attacker can use this vulnerability to …

Mar 30, 2024
CVE-2024-29667
9.8 CRITICAL

SQL Injection vulnerability in Tongtianxing Technology Co., Ltd CMSV6 v.7.31.0.2 through v.7.31.0.3 allows a remote attacker to escalate privileges and obtain sensitive information via the …

Mar 29, 2024
CVE-2024-3094
10.0 CRITICAL

Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma build process extracts …

Mar 29, 2024
CVE-2024-31032
9.8 CRITICAL

An issue in Huashi Private Cloud CDN Live Streaming Acceleration Server hgateway-sixport v.1.1.2 allows a remote attacker to execute arbitrary code via the manager/ipping.php component.

Mar 29, 2024
CVE-2024-29640
9.8 CRITICAL

An issue in aliyundrive-webdav v.2.3.3 and before allows a remote attacker to execute arbitrary code via a crafted payload to the sid parameter in the …

Mar 29, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.