CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-3737
6.3 MEDIUM

A vulnerability was found in cym1102 nginxWebUI up to 3.9.9. It has been rated as critical. Affected by this issue is the function findCountByQuery of …

Apr 13, 2024
CVE-2024-32487
8.6 HIGH

less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically …

Apr 13, 2024
CVE-2024-3736
4.3 MEDIUM

A vulnerability was found in cym1102 nginxWebUI up to 3.9.9. It has been declared as problematic. Affected by this vulnerability is the function upload of …

Apr 13, 2024
CVE-2024-3735
3.7 LOW

A vulnerability was found in Smart Office up to 20240405. It has been classified as problematic. Affected is an unknown function of the file Main.aspx. …

Apr 13, 2024
CVE-2024-3721
6.3 MEDIUM

A vulnerability was found in TBK DVR-4104 and DVR-4216 up to 20240412 and classified as critical. This issue affects some unknown processing of the file …

Apr 13, 2024
CVE-2024-3720
6.3 MEDIUM

A vulnerability has been found in Tianwell Fire Intelligent Command Platform 1.1.1.1 and classified as critical. This vulnerability affects unknown code of the file /mfsNotice/page …

Apr 13, 2024
CVE-2024-26817
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: amdkfd: use calloc instead of kzalloc to avoid integer overflow This uses calloc instead of …

Apr 13, 2024
CVE-2024-3719
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Campcodes House Rental Management System 1.0. This affects an unknown part of the file ajax.php. …

Apr 13, 2024
CVE-2024-3662
4.3 MEDIUM

The WPZOOM Social Feed Widget & Block plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpzoom_instagram_clear_data() function …

Apr 13, 2024
CVE-2023-6494
4.4 MEDIUM

The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and …

Apr 13, 2024
CVE-2024-2583
5.4 MEDIUM

The WP Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 7.0.5 does not properly escape some of its shortcodes attributes before they are echoed back …

Apr 13, 2024
CVE-2024-3027
6.4 MEDIUM

The Smart Slider 3 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the upload function in …

Apr 13, 2024
CVE-2024-1957
6.4 MEDIUM

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'give_form' shortcode in all versions …

Apr 13, 2024
CVE-2024-32028
4.1 MEDIUM

OpenTelemetry dotnet is a dotnet telemetry framework. In affected versions of `OpenTelemetry.Instrumentation.Http` and `OpenTelemetry.Instrumentation.AspNetCore` the `url.full` writes attribute/tag on spans (`Activity`) when tracing is enabled …

Apr 12, 2024
CVE-2024-31462
6.3 MEDIUM

stable-diffusion-webui is a web interface for Stable Diffusion, implemented using Gradio library. Stable-diffusion-webui 1.7.0 is vulnerable to a limited file write affecting Windows systems. The …

Apr 12, 2024
CVE-2024-28869
7.5 HIGH

Traefik is an HTTP reverse proxy and load balancer. In affected versions sending a GET request to any Traefik endpoint with the "Content-length" request header …

Apr 12, 2024
CVE-2024-32019
8.8 HIGH

Netdata is an open source observability tool. In affected versions the `ndsudo` tool shipped with affected versions of the Netdata Agent allows an attacker to …

Apr 12, 2024
CVE-2024-32005
8.2 HIGH

NiceGUI is an easy-to-use, Python-based UI framework. A local file inclusion is present in the NiceUI leaflet component when requesting resource files under the `/_nicegui/{__version__}/resources/{key}/{path:path}` …

Apr 12, 2024
CVE-2024-32003
8.8 HIGH

wn-dusk-plugin (Dusk plugin) is a plugin which integrates Laravel Dusk browser testing into Winter CMS. The Dusk plugin provides some special routes as part of …

Apr 12, 2024
CVE-2024-29023
7.2 HIGH

Xibo is an Open Source Digital Signage platform with a web content management system and Windows display player software. Session tokens are exposed in the …

Apr 12, 2024
CVE-2024-29022
8.8 HIGH

Xibo is an Open Source Digital Signage platform with a web content management system and Windows display player software. In affected versions some request headers …

Apr 12, 2024
CVE-2024-32000
4.3 MEDIUM

matrix-appservice-irc is a Node.js IRC bridge for the Matrix messaging protocol. matrix-appservice-irc before version 2.0.0 can be exploited to leak the truncated body of a …

Apr 12, 2024
CVE-2024-3698
6.3 MEDIUM

A vulnerability was found in Campcodes House Rental Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Apr 12, 2024
CVE-2024-3697
6.3 MEDIUM

A vulnerability was found in Campcodes House Rental Management System 1.0. It has been classified as critical. Affected is an unknown function of the file …

Apr 12, 2024
CVE-2024-22359
6.1 MEDIUM

IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4 and IBM DevOps Deploy 8.0 through 8.0.0.1 are vulnerable …

Apr 12, 2024
CVE-2024-22358
6.3 MEDIUM

IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4 and IBM DevOps Deploy 8.0 through 8.0.0.1 does not …

Apr 12, 2024
CVE-2024-22339
4.3 MEDIUM

IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4 and IBM DevOps Deploy 8.0 through 8.0.0.1 is vulnerable …

Apr 12, 2024
CVE-2024-22334
4.4 MEDIUM

IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4 and IBM DevOps Deploy 8.0 through 8.0.0.1 could be …

Apr 12, 2024
CVE-2024-0157
5.9 MEDIUM

Dell Storage Resource Manager, 4.9.0.0 and below, contain(s) a Session Fixation Vulnerability in SRM Windows Host Agent. An adjacent network unauthenticated attacker could potentially exploit …

Apr 12, 2024
CVE-2024-3696
6.3 MEDIUM

A vulnerability was found in Campcodes House Rental Management System 1.0 and classified as critical. This issue affects some unknown processing of the file view_payment.php. …

Apr 12, 2024
CVE-2024-3695
3.5 LOW

A vulnerability has been found in SourceCodester Computer Laboratory Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /classes/Users.php. …

Apr 12, 2024
CVE-2024-3691
7.3 HIGH

A vulnerability, which was classified as critical, has been found in PHPGurukul Small CRM 3.0. Affected by this issue is some unknown functionality of the …

Apr 12, 2024
CVE-2024-31069
7.4 HIGH

IO-1020 Micro ELD web server uses a default password for authentication.

Apr 12, 2024
CVE-2024-30403
6.5 MEDIUM

A NULL Pointer Dereference vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved allows an unauthenticated, adjacent attacker to cause a …

Apr 12, 2024
CVE-2024-30402
5.9 MEDIUM

An Improper Check for Unusual or Exceptional Conditions vulnerability in the Layer 2 Address Learning Daemon (l2ald) of Juniper Networks Junos OS and Junos OS …

Apr 12, 2024
CVE-2024-30401
5.9 MEDIUM

An Out-of-bounds Read vulnerability in the advanced forwarding management process aftman of Juniper Networks Junos OS on MX Series with MPC10E, MPC11, MX10K-LC9600 line cards, …

Apr 12, 2024
CVE-2024-30398
7.5 HIGH

An Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows …

Apr 12, 2024
CVE-2024-30397
7.5 HIGH

An Improper Check for Unusual or Exceptional Conditions vulnerability in the the Public Key Infrastructure daemon (pkid) of Juniper Networks Junos OS allows an unauthenticated …

Apr 12, 2024
CVE-2024-30392
7.5 HIGH

A Stack-based Buffer Overflow vulnerability in Flow Processing Daemon (flowd) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause Denial of Service …

Apr 12, 2024
CVE-2024-30391
4.8 MEDIUM

A Missing Authentication for Critical Function vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series with SPC3, and SRX …

Apr 12, 2024
CVE-2024-30390
5.3 MEDIUM

An Improper Restriction of Excessive Authentication Attempts vulnerability in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause a limited Denial of …

Apr 12, 2024
CVE-2024-30389
5.8 MEDIUM

An Incorrect Behavior Order vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on EX4300 Series allows an unauthenticated, network-based attacker to …

Apr 12, 2024
CVE-2024-30388
6.5 MEDIUM

An Improper Isolation or Compartmentalization vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on QFX5000 Series and EX Series allows an …

Apr 12, 2024
CVE-2024-30387
6.5 MEDIUM

A Missing Synchronization vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on ACX5448 and ACX710 allows an unauthenticated, adjacent attacker to …

Apr 12, 2024
CVE-2024-30386
5.3 MEDIUM

A Use-After-Free vulnerability in the Layer 2 Address Learning Daemon (l2ald) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker …

Apr 12, 2024
CVE-2024-30384
5.5 MEDIUM

An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on EX4300 Series allows a …

Apr 12, 2024
CVE-2024-30382
7.5 HIGH

An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based, …

Apr 12, 2024
CVE-2024-30210
7.4 HIGH

IO-1020 Micro ELD uses a default WIFI password that could allow an adjacent attacker to connect to the device.

Apr 12, 2024
CVE-2024-28878
9.6 CRITICAL

IO-1020 Micro ELD downloads source code or an executable from an adjacent location and executes the code without sufficiently verifying the origin or integrity of …

Apr 12, 2024
CVE-2024-3690
6.3 MEDIUM

A vulnerability classified as critical was found in PHPGurukul Small CRM 3.0. Affected by this vulnerability is an unknown functionality of the component Change Password …

Apr 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.