CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-4493
8.8 HIGH

A vulnerability, which was classified as critical, was found in Tenda i21 1.0.0.14(4656). Affected is the function formSetAutoPing. The manipulation of the argument ping1/ping2 leads …

May 5, 2024
CVE-2024-34490
5.1 MEDIUM

In Maxima through 5.47.0 before 51704c, the plotting facilities make use of predictable names under /tmp. Thus, the contents may be controlled by a local …

May 5, 2024
CVE-2024-34489
7.5 HIGH

OFPHello in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via length=0.

May 5, 2024
CVE-2024-34488
7.5 HIGH

OFPMultipartReply in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via b.length=0.

May 5, 2024
CVE-2024-34487
7.5 HIGH

OFPFlowStats in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via inst.length=0.

May 5, 2024
CVE-2024-34486
7.5 HIGH

OFPPacketQueue in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via OFPQueueProp.len=0.

May 5, 2024
CVE-2024-34484
5.3 MEDIUM

OFPBucket in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via action.len=0.

May 5, 2024
CVE-2024-34483
7.5 HIGH

OFPGroupDescStats in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via OFPBucket.len=0.

May 5, 2024
CVE-2024-4492
8.8 HIGH

A vulnerability, which was classified as critical, has been found in Tenda i21 1.0.0.14(4656). This issue affects the function formOfflineSet of the file /goform/setStaOffline. The …

May 5, 2024
CVE-2024-34478
7.5 HIGH

btcd before 0.24.0 does not correctly implement the consensus rules outlined in BIP 68 and BIP 112, making it susceptible to consensus failures. Specifically, it …

May 5, 2024
CVE-2024-4491
8.8 HIGH

A vulnerability classified as critical was found in Tenda i21 1.0.0.14(4656). This vulnerability affects the function formGetDiagnoseInfo. The manipulation of the argument cmdinput leads to …

May 5, 2024
CVE-2024-34476
5.3 MEDIUM

Open5GS before 2.7.1 is vulnerable to a reachable assertion that can cause an AMF crash via NAS messages from a UE: ogs_nas_encrypt in lib/nas/common/security.c for …

May 5, 2024
CVE-2024-34475
7.5 HIGH

Open5GS before 2.7.1 is vulnerable to a reachable assertion that can cause an AMF crash via NAS messages from a UE: gmm_state_authentication in amf/gmm-sm.c for …

May 5, 2024
CVE-2024-34473
5.3 MEDIUM

An issue was discovered in appmgr in O-RAN Near-RT RIC I-Release. An attacker could register an unintended RMR message type during xApp registration to disrupt …

May 4, 2024
CVE-2023-52729
7.5 HIGH

TCPServer.cpp in SimpleNetwork through 29bc615 has an off-by-one error that causes a buffer overflow when trying to add '\0' to the end of long msg …

May 4, 2024
CVE-2024-34469
7.1 HIGH

Rukovoditel before 3.5.3 allows XSS via user_photo to index.php?module=users/registration&action=save.

May 4, 2024
CVE-2024-34468
6.1 MEDIUM

Rukovoditel before 3.5.3 allows XSS via user_photo to My Page.

May 4, 2024
CVE-2024-34467
6.1 MEDIUM

ThinkPHP 8.0.3 allows remote attackers to exploit XSS due to inadequate filtering of function argument values in think_exception.tpl.

May 4, 2024
CVE-2024-34462
6.1 MEDIUM

Alinto SOGo through 5.10.0 allows XSS during attachment preview.

May 4, 2024
CVE-2023-27283
5.3 MEDIUM

IBM Aspera Orchestrator 4.0.1 could allow a remote attacker to enumerate usernames due to observable response discrepancies. IBM X-Force ID: 248545.

May 4, 2024
CVE-2024-1050
4.3 MEDIUM

The Import and export users and customers plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …

May 4, 2024
CVE-2023-7065
5.4 MEDIUM

The Stop Spammers Security | Block Spam Users, Comments, Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and …

May 4, 2024
CVE-2024-34461
9.8 CRITICAL

Zenario before 9.5.60437 uses Twig filters insecurely in the Twig Snippet plugin, and in the site-wide HEAD and BODY elements, enabling code execution by a …

May 4, 2024
CVE-2024-34460
6.5 MEDIUM

The Tree Explorer tool from Organizer in Zenario before 9.5.60602 is affected by XSS. (This component was removed in 9.5.60602.)

May 4, 2024
CVE-2024-3240
8.8 HIGH

The ConvertPlug plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.5.25 via deserialization of untrusted input from …

May 4, 2024
CVE-2024-3237
5.4 MEDIUM

The ConvertPlug plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the cp_dismiss_notice() function in all versions …

May 4, 2024
CVE-2024-3868
5.4 MEDIUM

The Folders Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's First Name and Last Name in all versions up to, …

May 4, 2024
CVE-2024-34455
7.5 HIGH

Buildroot before 0b2967e lacks the sticky bit for the /dev/shm directory. A fix was released in 2024.02.2.

May 3, 2024
CVE-2023-40695
6.3 MEDIUM

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the …

May 3, 2024
CVE-2022-33010

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not …

May 3, 2024
CVE-2022-22364
5.3 MEDIUM

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to external service interaction attack, caused by improper validation of user-supplied input. A remote attacker could …

May 3, 2024
CVE-2021-20451
6.0 MEDIUM

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the …

May 3, 2024
CVE-2024-34453
4.3 MEDIUM

TwoNav 2.1.13 contains an SSRF vulnerability via the url paramater to index.php?c=api&method=read_data&type=connectivity_test (which reaches /system/api.php).

May 3, 2024
CVE-2024-34075
6.2 MEDIUM

kurwov is a fast, dependency-free library for creating Markov Chains. An unsafe sanitization of dataset contents on the `MarkovData#getNext` method used in `Markov#generate` and `Markov#choose` …

May 3, 2024
CVE-2024-34068
6.4 MEDIUM

Pterodactyl wings is the server control plane for Pterodactyl Panel. An authenticated user who has access to a game server is able to bypass the …

May 3, 2024
CVE-2024-34067
6.1 MEDIUM

Pterodactyl is a free, open-source game server management panel built with PHP, React, and Go. Importing a malicious egg or gaining access to wings instance …

May 3, 2024
CVE-2024-34066
8.4 HIGH

Pterodactyl wings is the server control plane for Pterodactyl Panel. If the Wings token is leaked either by viewing the node configuration or posting it …

May 3, 2024
CVE-2024-31673
9.8 CRITICAL

Kliqqi-CMS 2.0.2 is vulnerable to SQL Injection in load_data.php via the userid parameter.

May 3, 2024
CVE-2024-27453
8.6 HIGH

In Extreme XOS through 22.6.1.4, a read-only user can escalate privileges to root via a crafted HTTP POST request to the python method of the …

May 3, 2024
CVE-2023-40696
5.9 MEDIUM

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force …

May 3, 2024
CVE-2023-38724
6.3 MEDIUM

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the …

May 3, 2024
CVE-2023-28952
5.3 MEDIUM

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to injection attacks in application logging by not sanitizing user provided data. IBM X-Force ID: 251463.

May 3, 2024
CVE-2023-23474
3.7 LOW

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser. …

May 3, 2024
CVE-2022-48705
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7921e: fix crash in chip reset fail In case of drv own fail …

May 3, 2024
CVE-2022-48704
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/radeon: add a force flush to delay work when radeon Although radeon card fence and …

May 3, 2024
CVE-2022-48695
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: scsi: mpt3sas: Fix use-after-free warning Fix the following use-after-free warning which is observed during controller …

May 3, 2024
CVE-2022-48690
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ice: Fix DMA mappings leak Fix leak, when user changes ring parameters. During reallocation of …

May 3, 2024
CVE-2021-20556
5.3 MEDIUM

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 could allow a remote user to enumerate usernames due to differentiating error messages on existing usernames. IBM X-Force …

May 3, 2024
CVE-2024-33793
5.3 MEDIUM

netis-systems MEX605 v2.00.06 allows attackers to execute arbitrary OS commands via a crafted payload to the ping test page.

May 3, 2024
CVE-2024-33792
9.8 CRITICAL

netis-systems MEX605 v2.00.06 allows attackers to execute arbitrary OS commands via a crafted payload to the tracert page.

May 3, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.