CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-33122
6.3 MEDIUM

Roothub v2.6 was discovered to contain a SQL injection vulnerability via the topic parameter in the list() function.

May 7, 2024
CVE-2024-33120
9.8 CRITICAL

Roothub v2.5 was discovered to contain an arbitrary file upload vulnerability via the customPath parameter in the upload() function. This vulnerability allows attackers to execute …

May 7, 2024
CVE-2024-32867
5.3 MEDIUM

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.5 and 6.0.19, various problems in handling of …

May 7, 2024
CVE-2024-32664
5.3 MEDIUM

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.5 and 6.0.19, specially crafted traffic or datasets …

May 7, 2024
CVE-2024-32663
7.5 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.5 and 6.0.19, a small amount of HTTP/2 …

May 7, 2024
CVE-2024-32371
7.5 HIGH

An issue in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a regular user account to escalate their privileges and gain administrative access by changing …

May 7, 2024
CVE-2024-32370
9.8 CRITICAL

An issue in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a remote attacker to obtain sensitive information via a crafted payload to the id …

May 7, 2024
CVE-2024-32369
4.3 MEDIUM

SQL Injection vulnerability in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a remote attacker to obtain sensitive information via a crafted payload to the …

May 7, 2024
CVE-2024-4593
4.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in DedeCMS 5.7. This issue affects some unknown processing of the file /src/dede/sys_multiserv.php. The manipulation …

May 7, 2024
CVE-2024-4592
4.3 MEDIUM

A vulnerability classified as problematic was found in DedeCMS 5.7. This vulnerability affects unknown code of the file /src/dede/sys_group_edit.php. The manipulation leads to cross-site request …

May 7, 2024
CVE-2024-4591
4.3 MEDIUM

A vulnerability classified as problematic has been found in DedeCMS 5.7. This affects an unknown part of the file /src/dede/sys_group_add.php. The manipulation leads to cross-site …

May 7, 2024
CVE-2024-4590
4.3 MEDIUM

A vulnerability was found in DedeCMS 5.7. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /src/dede/sys_info.php. …

May 7, 2024
CVE-2024-33783
6.5 MEDIUM

MP-SPDZ v0.3.8 was discovered to contain a segmentation violation via the function osuCrypto::SilentMultiPprfReceiver::expand in /Tools/SilentPprf.cpp. This vulnerability allows attackers to cause a Denial of Service …

May 7, 2024
CVE-2024-33782
7.5 HIGH

MP-SPDZ v0.3.8 was discovered to contain a stack overflow via the function OTExtensionWithMatrix::extend in /OT/OTExtensionWithMatrix.cpp. This vulnerability allows attackers to cause a Denial of Service …

May 7, 2024
CVE-2024-33781
7.5 HIGH

MP-SPDZ v0.3.8 was discovered to contain a stack overflow via the function octetStream::get_bytes in /Tools/octetStream.cpp. This vulnerability allows attackers to cause a Denial of Service …

May 7, 2024
CVE-2024-33780
6.5 MEDIUM

MP-SPDZ v0.3.8 was discovered to contain a segmentation violation via the function osuCrypto::copyOut at /Tools/SilentPprf.cpp. This vulnerability allows attackers to cause a Denial of Service …

May 7, 2024
CVE-2024-33434
9.8 CRITICAL

An issue in tiagorlampert CHAOS v5.0.1 before 1b451cf62582295b7225caf5a7b506f0bad56f6b and 24c9e109b5be34df7b2bce8368eae669c481ed5e allows a remote attacker to execute arbitrary code via the unsafe concatenation of the `filename` …

May 7, 2024
CVE-2024-31456
7.7 HIGH

GLPI is a Free Asset and IT Management Software package. Prior to 10.0.15, an authenticated user can exploit a SQL injection vulnerability from map search. …

May 7, 2024
CVE-2024-29889
7.1 HIGH

GLPI is a Free Asset and IT Management Software package. Prior to 10.0.15, an authenticated user can exploit a SQL injection vulnerability in the saved …

May 7, 2024
CVE-2024-28148
4.3 MEDIUM

An authenticated user could potentially access metadata for a datasource they are not authorized to view by submitting a targeted REST API request.This issue affects …

May 7, 2024
CVE-2023-46012
9.8 CRITICAL

Buffer Overflow vulnerability LINKSYS EA7500 3.0.1.207964 allows a remote attacker to execute arbitrary code via an HTTP request to the IGD UPnP.

May 7, 2024
CVE-2024-4589
4.3 MEDIUM

A vulnerability was found in DedeCMS 5.7. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /src/dede/mytag_edit.php. …

May 7, 2024
CVE-2024-4588
4.3 MEDIUM

A vulnerability was found in DedeCMS 5.7. It has been classified as problematic. Affected is an unknown function of the file /src/dede/mytag_add.php. The manipulation leads …

May 7, 2024
CVE-2024-4587
4.3 MEDIUM

A vulnerability was found in DedeCMS 5.7 and classified as problematic. This issue affects some unknown processing of the file /src/dede/tpl.php. The manipulation leads to …

May 7, 2024
CVE-2024-4586
4.3 MEDIUM

A vulnerability has been found in DedeCMS 5.7 and classified as problematic. This vulnerability affects unknown code of the file /src/dede/shops_delivery.php. The manipulation leads to …

May 7, 2024
CVE-2024-4536
6.8 MEDIUM

In Eclipse Dataspace Components from version 0.2.1 to 0.6.2, in the EDC Connector component ( https://github.com/eclipse-edc/Connector ), an attacker might obtain OAuth2 client secrets from …

May 7, 2024
CVE-2023-7240
5.8 MEDIUM

An improper authorization level has been detected in the login panel. It may lead to unauthenticated Server Side Request Forgery and allows to perform open …

May 7, 2024
CVE-2023-31234
6.3 MEDIUM

Missing Authorization vulnerability in Tilda Publishing.This issue affects Tilda Publishing: from n/a through 0.3.23.

May 7, 2024
CVE-2024-4601
6.7 MEDIUM

An incorrect authentication vulnerability has been found in Socomec Net Vision affecting version 7.20. This vulnerability allows an attacker to perform a brute force attack …

May 7, 2024
CVE-2024-4600
7.1 HIGH

Cross-Site Request Forgery vulnerability in Socomec Net Vision, version 7.20. This vulnerability could allow an attacker to trick registered users into performing critical actions, such …

May 7, 2024
CVE-2024-4585
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in DedeCMS 5.7. This affects an unknown part of the file /src/dede/member_type.php. The manipulation leads to …

May 7, 2024
CVE-2024-4584
5.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in Faraday GM8181 and GM828x up to 20240429. Affected by this issue is some unknown …

May 7, 2024
CVE-2024-4538
7.5 HIGH

IDOR vulnerability in Janto Ticketing Software affecting version 4.3r10. This vulnerability could allow a remote user to obtain a user's event ticket by creating a …

May 7, 2024
CVE-2024-4537
7.5 HIGH

IDOR vulnerability in Janto Ticketing Software affecting version 4.3r10. This vulnerability could allow a remote user to obtain the download URL of another user to …

May 7, 2024
CVE-2024-4599
7.5 HIGH

Remote denial of service vulnerability in LAN Messenger affecting version 3.4.0. This vulnerability allows an attacker to crash the LAN Messenger service by sending a …

May 7, 2024
CVE-2024-4583
5.3 MEDIUM

A vulnerability classified as problematic was found in Faraday GM8181 and GM828x up to 20240429. Affected by this vulnerability is an unknown functionality of the …

May 7, 2024
CVE-2024-4582
7.3 HIGH

A vulnerability classified as critical has been found in Faraday GM8181 and GM828x up to 20240429. Affected is an unknown function of the component NTP …

May 7, 2024
CVE-2023-6810
4.3 MEDIUM

The ClickCease Click Fraud Protection plugin for WordPress is vulnerable to unauthorized access of data due to an improper capability check on the get_settings function …

May 7, 2024
CVE-2024-4346
9.1 CRITICAL

The Startklar Elementor Addons plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 1.7.13. This is due to …

May 7, 2024
CVE-2024-4345
9.8 CRITICAL

The Startklar Elementor Addons plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'process' function in the …

May 7, 2024
CVE-2024-3759
6.5 MEDIUM

in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in TCB through use after free.

May 7, 2024
CVE-2024-3758
6.5 MEDIUM

in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in TCB through heap buffer overflow.

May 7, 2024
CVE-2024-3757
3.3 LOW

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause service crash through integer overflow.

May 7, 2024
CVE-2024-31078
3.3 LOW

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause service crash through NULL pointer dereference.

May 7, 2024
CVE-2024-27217
6.5 MEDIUM

in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free.

May 7, 2024
CVE-2024-23808
5.2 MEDIUM

in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free or cause DOS through NULL …

May 7, 2024
CVE-2024-4186
9.8 CRITICAL

The Edwiser Bridge plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.0.5. This is due to the 'eb_user_email_verification_key' default …

May 7, 2024
CVE-2024-3628
3.8 LOW

The EasyEvent WordPress plugin through 1.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

May 7, 2024
CVE-2024-22472
8.1 HIGH

A buffer Overflow vulnerability in Silicon Labs 500 Series Z-Wave devices may allow Denial of Service, and potential Remote Code execution This issue affects all …

May 7, 2024
CVE-2024-20872
6.2 MEDIUM

Improper handling of insufficient privileges vulnerability in TalkbackSE prior to version Android 14 allows local attackers to modify setting value of TalkbackSE.

May 7, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.