CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-4257
6.3 MEDIUM

A vulnerability was found in BlueNet Technology Clinical Browsing System 1.2.1. It has been classified as critical. This affects an unknown part of the file …

Apr 27, 2024
CVE-2024-4256
2.4 LOW

A vulnerability was found in Techkshetra Info Solutions Savsoft Quiz 6.0 and classified as problematic. Affected by this issue is some unknown functionality of the …

Apr 27, 2024
CVE-2024-4255
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in Ruijie RG-UAC up to 20240419. This issue affects some unknown processing of the file …

Apr 27, 2024
CVE-2024-4252
8.8 HIGH

A vulnerability classified as critical has been found in Tenda i22 1.0.0.3(4687). This affects the function formSetUrlFilterRule. The manipulation of the argument groupIndex leads to …

Apr 27, 2024
CVE-2024-4251
8.8 HIGH

A vulnerability was found in Tenda i21 1.0.0.14(4656). It has been rated as critical. Affected by this issue is the function fromDhcpSetSer of the file …

Apr 27, 2024
CVE-2024-4250
8.8 HIGH

A vulnerability was found in Tenda i21 1.0.0.14(4656). It has been declared as critical. Affected by this vulnerability is the function formwrlSSIDset of the file …

Apr 27, 2024
CVE-2024-4249
8.8 HIGH

A vulnerability was found in Tenda i21 1.0.0.14(4656). It has been classified as critical. Affected is the function formwrlSSIDget of the file /goform/wifiSSIDget. The manipulation …

Apr 27, 2024
CVE-2024-25048
7.5 HIGH

IBM MQ Appliance 9.3 CD and LTS are vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote authenticated attacker could overflow …

Apr 27, 2024
CVE-2024-4248
8.8 HIGH

A vulnerability was found in Tenda i21 1.0.0.14(4656) and classified as critical. This issue affects the function formQosManage_user. The manipulation of the argument ssidIndex leads …

Apr 27, 2024
CVE-2024-4247
8.8 HIGH

A vulnerability has been found in Tenda i21 1.0.0.14(4656) and classified as critical. This vulnerability affects the function formQosManage_auto. The manipulation of the argument ssidIndex …

Apr 27, 2024
CVE-2024-3309
6.4 MEDIUM

The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown Widget's attributes in all versions up to, and …

Apr 27, 2024
CVE-2024-4246
8.8 HIGH

A vulnerability, which was classified as critical, was found in Tenda i21 1.0.0.14(4656). This affects the function formQosManageDouble_auto. The manipulation of the argument ssidIndex leads …

Apr 27, 2024
CVE-2024-3342
9.9 CRITICAL

The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to SQL Injection via the 'events' attribute of the 'mp-timetable' shortcode in all …

Apr 27, 2024
CVE-2023-1000
6.3 MEDIUM

A vulnerability was found in cyanomiko dcnnt-py up to 0.9.0. It has been classified as critical. Affected is the function main of the file dcnnt/plugins/notifications.py …

Apr 27, 2024
CVE-2024-4245
8.8 HIGH

A vulnerability, which was classified as critical, has been found in Tenda i21 1.0.0.14(4656). Affected by this issue is the function formQosManageDouble_user. The manipulation of …

Apr 27, 2024
CVE-2024-3034
2.7 LOW

The BackUpWordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.13 via the hmbkp_directory_browse parameter. This makes it …

Apr 27, 2024
CVE-2024-2838
6.4 MEDIUM

The WPC Composite Products for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wooco_components[0][name]' parameter in all versions up to, and …

Apr 27, 2024
CVE-2024-2258
4.4 MEDIUM

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's …

Apr 27, 2024
CVE-2024-2859
6.8 MEDIUM

By default, SANnav OVA is shipped with root user login enabled. While protected by a password, access to root could expose SANnav to a remote …

Apr 27, 2024
CVE-2024-4244
8.8 HIGH

A vulnerability classified as critical was found in Tenda W9 1.0.0.7(4456). Affected by this vulnerability is the function fromDhcpSetSer of the file /goform/DhcpSetSer. The manipulation …

Apr 26, 2024
CVE-2024-4243
8.8 HIGH

A vulnerability classified as critical has been found in Tenda W9 1.0.0.7(4456). Affected is the function formwrlSSIDset of the file /goform/wifiSSIDset. The manipulation of the …

Apr 26, 2024
CVE-2024-3052
7.5 HIGH

Malformed S2 Nonce Get command classes can be sent to crash the gateway. A hard reset is required to recover the gateway.

Apr 26, 2024
CVE-2024-3051
7.5 HIGH

Malformed Device Reset Locally command classes can be sent to temporarily deny service to an end device. Any frames sent by the end device will …

Apr 26, 2024
CVE-2024-31828
6.1 MEDIUM

Cross Site Scripting vulnerability in Lavalite CMS v.10.1.0 allows attackers to execute arbitrary code and obtain sensitive information via a crafted payload to the URL.

Apr 26, 2024
CVE-2024-31741
6.1 MEDIUM

Cross Site Scripting vulnerability in MiniCMS v.1.11 allows a remote attacker to run arbitrary code via crafted string in the URL after login.

Apr 26, 2024
CVE-2024-31551
7.5 HIGH

Directory Traversal vulnerability in lib/admin/image.admin.php in cmseasy v7.7.7.9 20240105 allows attackers to delete arbitrary files via crafted GET request.

Apr 26, 2024
CVE-2024-30804
9.8 CRITICAL

An issue discovered in the DeviceIoControl component in ASUS Fan_Xpert before v.10013 allows an attacker to execute arbitrary code via crafted IOCTL requests.

Apr 26, 2024
CVE-2024-28322
9.8 CRITICAL

SQL Injection vulnerability in /event-management-master/backend/register.php in PuneethReddyHC Event Management 1.0 allows attackers to run arbitrary SQL commands via the event_id parameter in a crafted POST …

Apr 26, 2024
CVE-2024-4242
8.8 HIGH

A vulnerability was found in Tenda W9 1.0.0.7(4456). It has been rated as critical. This issue affects the function formwrlSSIDget of the file /goform/wifiSSIDget. The …

Apr 26, 2024
CVE-2024-4241
8.8 HIGH

A vulnerability was found in Tenda W9 1.0.0.7(4456). It has been declared as critical. This vulnerability affects the function formQosManageDouble_auto. The manipulation of the argument …

Apr 26, 2024
CVE-2024-4240
8.8 HIGH

A vulnerability was found in Tenda W9 1.0.0.7(4456). It has been classified as critical. This affects the function formQosManageDouble_user. The manipulation of the argument ssidIndex …

Apr 26, 2024
CVE-2024-4239
8.8 HIGH

A vulnerability was found in Tenda AX1806 1.0.0.1 and classified as critical. Affected by this issue is the function formSetRebootTimer of the file /goform/SetRebootTimer. The …

Apr 26, 2024
CVE-2024-32887
5.5 MEDIUM

Sidekiq is simple, efficient background processing for Ruby. Sidekiq is reflected XSS vulnerability. The value of substr parameter is reflected in the response without any …

Apr 26, 2024
CVE-2024-32883
7.7 HIGH

MCUboot is a secure bootloader for 32-bits microcontrollers. MCUboot uses a TLV (tag-length-value) structure to represent the meta data associated with an image. The TLVs …

Apr 26, 2024
CVE-2024-32881
9.8 CRITICAL

Danswer is the AI Assistant connected to company's docs, apps, and people. Danswer is vulnerable to unauthorized access to GET/SET of Slack Bot Tokens. Anyone …

Apr 26, 2024
CVE-2024-32878
7.1 HIGH

Llama.cpp is LLM inference in C/C++. There is a use of uninitialized heap variable vulnerability in gguf_init_from_file, the code will free this uninitialized variable later. …

Apr 26, 2024
CVE-2024-31601
9.8 CRITICAL

An issue in Beijing Panabit Network Software Co., Ltd Panalog big data analysis platform v. 20240323 and before allows attackers to execute arbitrary code via …

Apr 26, 2024
CVE-2024-31502
8.1 HIGH

An issue in Insurance Management System v.1.0.0 and before allows a remote attacker to escalate privileges via a crafted POST request to /admin/core/new_staff.

Apr 26, 2024
CVE-2024-4238
8.8 HIGH

A vulnerability has been found in Tenda AX1806 1.0.0.1 and classified as critical. Affected by this vulnerability is the function formSetDeviceName of the file /goform/SetOnlineDevName. …

Apr 26, 2024
CVE-2024-28326
6.8 MEDIUM

Incorrect Access Control in ASUS RT-N12+ B1 and RT-N12 D1 routers allows local attackers to obtain root terminal access via the the UART interface.

Apr 26, 2024
CVE-2024-25343
9.1 CRITICAL

Tenda N300 F3 router vulnerability allows users to bypass intended security policy and create weak passwords.

Apr 26, 2024
CVE-2023-26603
5.9 MEDIUM

JumpCloud Agent before 1.178.0 Creates a Temporary File in a Directory with Insecure Permissions. This allows privilege escalation to SYSTEM via a repair action in …

Apr 26, 2024
CVE-2022-48611
7.8 HIGH

A logic issue was addressed with improved checks. This issue is fixed in iTunes 12.12.4 for Windows. A local attacker may be able to elevate …

Apr 26, 2024
CVE-2024-4237
8.8 HIGH

A vulnerability, which was classified as critical, was found in Tenda AX1806 1.0.0.1. Affected is the function R7WebsSecurityHandler of the file /goform/execCommand. The manipulation of …

Apr 26, 2024
CVE-2024-28327
8.4 HIGH

Asus RT-N12+ B1 router stores user passwords in plaintext, which could allow local attackers to obtain unauthorized access and modify router settings.

Apr 26, 2024
CVE-2024-28325
6.1 MEDIUM

Asus RT-N12+ B1 router stores credentials in cleartext, which could allow local attackers to obtain unauthorized access and modify router settings.

Apr 26, 2024
CVE-2024-4236
8.8 HIGH

A vulnerability, which was classified as critical, has been found in Tenda AX1803 1.0.0.1. This issue affects the function formSetSysToolDDNS of the file /goform/SetDDNSCfg. The …

Apr 26, 2024
CVE-2024-4235
2.7 LOW

A vulnerability classified as problematic was found in Netgear DG834Gv5 1.6.01.34. This vulnerability affects unknown code of the component Web Management Interface. The manipulation leads …

Apr 26, 2024
CVE-2024-33344
9.8 CRITICAL

D-Link DIR-822+ V1.0.5 was found to contain a command injection in ftext function of upload_firmware.cgi, which allows remote attackers to execute arbitrary commands via shell.

Apr 26, 2024
CVE-2024-33343
8.8 HIGH

D-Link DIR-822+ V1.0.5 was found to contain a command injection in ChgSambaUserSettings function of prog.cgi, which allows remote attackers to execute arbitrary commands via shell.

Apr 26, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.