CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-2659
7.2 HIGH

A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevated privileges to execute system commands when performing …

Apr 15, 2024
CVE-2024-28056
9.8 CRITICAL

Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify projects. When the Authentication component is removed …

Apr 15, 2024
CVE-2024-23594
6.4 MEDIUM

A buffer overflow vulnerability was reported in a system recovery bootloader that was part of the Lenovo preloaded Windows 7 and 8 operating systems from …

Apr 15, 2024
CVE-2024-23593
6.7 MEDIUM

A vulnerability was reported in a system recovery bootloader that was part of the Lenovo preloaded Windows 7 and 8 operating systems from 2012 to …

Apr 15, 2024
CVE-2024-23559
6.1 MEDIUM

HCL DevOps Deploy / Launch is generating an obsolete HTTP header.

Apr 15, 2024
CVE-2024-22014
8.8 HIGH

An issue discovered in 360 Total Security Antivirus through 11.0.0.1061 for Windows allows attackers to gain escalated privileges via Symbolic Link Follow to Arbitrary File …

Apr 15, 2024
CVE-2023-4857
7.5 HIGH

An authentication bypass vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user to execute certain IPMI calls that could lead to …

Apr 15, 2024
CVE-2023-4856
8.8 HIGH

A format string vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user to execute arbitrary commands on a specific API endpoint.

Apr 15, 2024
CVE-2023-4855
7.2 HIGH

A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevated privileges to execute unauthorized commands via IPMI.

Apr 15, 2024
CVE-2023-48710
9.8 CRITICAL

iTop is an IT service management platform. Files from the `env-production` folder can be retrieved even though they should have restricted access. Hopefully, there is …

Apr 15, 2024
CVE-2023-48709
8.0 HIGH

iTop is an IT service management platform. When exporting data from backoffice or portal in CSV or Excel files, users' inputs may include malicious formulas …

Apr 15, 2024
CVE-2023-47626
8.8 HIGH

iTop is an IT service management platform. When displaying/editing the user's personal tokens, XSS attacks are possible. This vulnerability is fixed in 3.1.1.

Apr 15, 2024
CVE-2023-47622
8.8 HIGH

iTop is an IT service management platform. When dashlet are refreshed, XSS attacks are possible. This vulnerability is fixed in 3.0.4 and 3.1.1.

Apr 15, 2024
CVE-2023-47123
8.7 HIGH

iTop is an IT service management platform. By filling malicious code in an object friendlyname / complementary name, an XSS attack can be performed when …

Apr 15, 2024
CVE-2023-45808
4.1 MEDIUM

iTop is an IT service management platform. When creating or updating an object, extkey values aren't checked to be in the current user silo. In …

Apr 15, 2024
CVE-2023-44396
6.8 MEDIUM

iTop is an IT service management platform. Dashlet edits ajax endpoints can be used to produce XSS. Fixed in iTop 2.7.10, 3.0.4, and 3.1.1.

Apr 15, 2024
CVE-2023-43790
5.7 MEDIUM

iTop is an IT service management platform. By manipulating HTTP queries, a user can inject malicious content in the fields used for the object friendlyname …

Apr 15, 2024
CVE-2023-38511
5.0 MEDIUM

iTop is an IT service management platform. Dashboard editor : can load multiple files and URL, and full path disclosure on dashboard config file. This …

Apr 15, 2024
CVE-2024-3797
6.3 MEDIUM

A vulnerability was found in SourceCodester QR Code Bookmark System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file …

Apr 15, 2024
CVE-2024-31576

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not …

Apr 15, 2024
CVE-2024-3786
6.6 MEDIUM

Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through Device Synchronizations (/admin/DeviceReplication). Exploitation of this vulnerability could allow a remote user …

Apr 15, 2024
CVE-2024-3785
6.6 MEDIUM

Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through Device NAS shared section (/admin/DeviceNAS). Exploitation of this vulnerability could allow a …

Apr 15, 2024
CVE-2024-3784
6.6 MEDIUM

Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through S3 Accounts (/admin/CloudAccounts). Exploitation of this vulnerability could allow a remote user …

Apr 15, 2024
CVE-2024-3783
7.7 HIGH

The Backup Agents section in WBSAirback 21.02.04 is affected by a Path Traversal vulnerability, allowing a user with low privileges to download files from the …

Apr 15, 2024
CVE-2024-3782
8.8 HIGH

Cross-Site Request Forgery vulnerability in WBSAirback 21.02.04, which could allow an attacker to create a manipulated HTML form to perform privileged actions once it is …

Apr 15, 2024
CVE-2024-3781
9.1 CRITICAL

Command injection vulnerability in the operating system. Improper neutralisation of special elements in Active Directory integration allows the intended command to be modified when sent …

Apr 15, 2024
CVE-2024-3780
7.8 HIGH

A vulnerability of Information Exposure has been found on Technicolor CGA2121 affecting the version 1.01, this vulnerability allows a local attacker to obtain sensitive information …

Apr 15, 2024
CVE-2024-24898
6.0 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in openEuler kernel on Linux allows Resource Leak Exposure. This vulnerability is associated with program files …

Apr 15, 2024
CVE-2024-24891
6.0 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in openEuler kernel on Linux allows Resource Leak Exposure. This vulnerability is associated with program files …

Apr 15, 2024
CVE-2024-3802

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Apr 15, 2024
CVE-2024-32129
4.7 MEDIUM

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Freshworks Freshdesk (official).This issue affects Freshdesk (official): from n/a through 2.3.6.

Apr 15, 2024
CVE-2024-31421
4.3 MEDIUM

Missing Authorization vulnerability in supsystic Popup by Supsystic popup-by-supsystic.This issue affects Popup by Supsystic: from n/a through <= 1.10.27.

Apr 15, 2024
CVE-2024-31389
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Ertano MihanPanel.This issue affects MihanPanel: from n/a before 12.7.

Apr 15, 2024
CVE-2024-31388
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Pauple Table & Contact Form 7 Database – Tablesome.This issue affects Table & Contact Form 7 Database – Tablesome: …

Apr 15, 2024
CVE-2024-31385
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Reservation Diary ReDi Restaurant Reservation.This issue affects ReDi Restaurant Reservation: from n/a through 24.0128.

Apr 15, 2024
CVE-2024-31384
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme Spa and Salon.This issue affects Spa and Salon: from n/a through 1.2.7.

Apr 15, 2024
CVE-2024-31383
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Pagelayer PopularFX.This issue affects PopularFX: from n/a through 1.2.4.

Apr 15, 2024
CVE-2024-31382
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in creativethemeshq Blocksy blocksy.This issue affects Blocksy: from n/a through <= 2.0.22.

Apr 15, 2024
CVE-2024-31381
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in RebelCode Spotlight Social Media Feeds.This issue affects Spotlight Social Media Feeds: from n/a through 1.6.10.

Apr 15, 2024
CVE-2024-31379
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Smash Balloon Smash Balloon Social Post Feed.This issue affects Smash Balloon Social Post Feed: from n/a through 4.2.1.

Apr 15, 2024
CVE-2024-31378
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in MailMunch MailChimp Forms by MailMunch.This issue affects MailChimp Forms by MailMunch: from n/a through 3.2.1.

Apr 15, 2024
CVE-2024-31376
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Andrew Dashboard To-Do List dashboard-to-do-list.This issue affects Dashboard To-Do List: from n/a through <= 1.3.1.

Apr 15, 2024
CVE-2024-31374
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Scott Bolinger AppPresser apppresser allows Cross Site Request Forgery.This issue affects AppPresser: from n/a through <= 4.3.0.

Apr 15, 2024
CVE-2024-31373
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in E2Pdf e2pdf e2pdf.This issue affects e2pdf: from n/a through <= 1.20.27.

Apr 15, 2024
CVE-2024-30546
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Pixelite Login With Ajax.This issue affects Login With Ajax: from n/a through 4.1.

Apr 15, 2024
CVE-2024-30220
8.8 HIGH

Command injection vulnerability in PLANEX COMMUNICATIONS wireless LAN routers allows a network-adjacent unauthenticated attacker to execute an arbitrary command by sending a specially crafted request …

Apr 15, 2024
CVE-2024-30219
6.8 MEDIUM

Active debug code vulnerability exists in PLANEX COMMUNICATIONS wireless LAN routers. If a logged-in user who knows how to use the debug function accesses the …

Apr 15, 2024
CVE-2024-29219
7.8 HIGH

Out-of-bounds read vulnerability exists in KV STUDIO Ver.11.64 and earlier and KV REPLAY VIEWER Ver.2.64 and earlier, and VT5-WX15/WX12 Ver.6.02 and earlier, which may lead …

Apr 15, 2024
CVE-2024-29218
8.8 HIGH

Out-of-bounds write vulnerability exists in KV STUDIO Ver.11.64 and earlier, KV REPLAY VIEWER Ver.2.64 and earlier, and VT5-WX15/WX12 Ver.6.02 and earlier, which may lead to …

Apr 15, 2024
CVE-2024-28957
5.3 MEDIUM

Generation of predictable identifiers issue exists in Cente middleware TCP/IP Network Series. If this vulnerability is exploited, a remote unauthenticated attacker may interfere communications by …

Apr 15, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.