CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-31447
5.3 MEDIUM

Shopware 6 is an open commerce platform based on Symfony Framework and Vue. Starting in version 6.3.5.0 and prior to versions 6.6.1.0 and 6.5.8.8, when …

Apr 8, 2024
CVE-2024-31442
8.8 HIGH

Redon Hub is a Roblox Product Delivery Bot, also known as a Hub. In all hubs before version 1.0.2, all commands are capable of being …

Apr 8, 2024
CVE-2024-31224
9.8 CRITICAL

GPT Academic provides interactive interfaces for large language models. A vulnerability was found in gpt_academic versions 3.64 through 3.73. The server deserializes untrustworthy data from …

Apr 8, 2024
CVE-2024-3444
4.7 MEDIUM

A vulnerability was found in Wangshen SecGate 3600 up to 20240408. It has been classified as critical. This affects an unknown part of the file …

Apr 8, 2024
CVE-2024-3443
3.5 LOW

A vulnerability classified as problematic was found in SourceCodester Prison Management System 1.0. This vulnerability affects unknown code of the file /Employee/apply_leave.php. The manipulation of …

Apr 8, 2024
CVE-2024-3442
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Prison Management System 1.0. This affects an unknown part of the file /Employee/delete_leave.php. The manipulation …

Apr 8, 2024
CVE-2024-31221
5.9 MEDIUM

Sunshine is a self-hosted game stream host for Moonlight. Starting in version 0.10.0 and prior to version 0.23.0, after unpairing all devices in the web …

Apr 8, 2024
CVE-2024-31205
4.2 MEDIUM

Saleor is an e-commerce platform. Starting in version 3.10.0 and prior to versions 3.14.64, 3.15.39, 3.16.39, 3.17.35, 3.18.31, and 3.19.19, an attacker may bypass cross-set …

Apr 8, 2024
CVE-2024-30269
5.3 MEDIUM

DataEase, an open source data visualization and analysis tool, has a database configuration information exposure vulnerability prior to version 2.5.0. Visiting the `/de2api/engine/getEngine;.js` path via …

Apr 8, 2024
CVE-2024-3441
6.3 MEDIUM

A vulnerability was found in SourceCodester Prison Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Apr 8, 2024
CVE-2024-3440
4.7 MEDIUM

A vulnerability was found in SourceCodester Prison Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Apr 8, 2024
CVE-2024-2511
5.9 MEDIUM

Issue summary: Some non-default TLS server configurations can cause unbounded memory growth when processing TLSv1.3 sessions Impact summary: An attacker may exploit certain server configurations …

Apr 8, 2024
CVE-2024-28732
7.5 HIGH

An issue was discovered in OFPMatch in parser.py in Faucet SDN Ryu version 4.34, allows remote attackers to cause a denial of service (DoS) (infinite …

Apr 8, 2024
CVE-2024-31817
7.5 HIGH

In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getSysStatusCfg.

Apr 8, 2024
CVE-2024-31816
7.5 HIGH

In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getEasyWizardCfg.

Apr 8, 2024
CVE-2024-31815
9.1 CRITICAL

In TOTOLINK EX200 V4.0.3c.7314_B20191204, an attacker can obtain the configuration file without authorization through /cgi-bin/ExportSettings.sh

Apr 8, 2024
CVE-2024-31814
8.8 HIGH

TOTOLINK EX200 V4.0.3c.7646_B20201211 allows attackers to bypass login through the Form_Login function.

Apr 8, 2024
CVE-2024-31813
8.4 HIGH

TOTOLINK EX200 V4.0.3c.7646_B20201211 does not contain an authentication mechanism by default.

Apr 8, 2024
CVE-2024-31812
6.5 MEDIUM

In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getWiFiExtenderConfig.

Apr 8, 2024
CVE-2024-31811
8.0 HIGH

TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the langType parameter in the setLanguageCfg function.

Apr 8, 2024
CVE-2024-31809
8.8 HIGH

TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the FileName parameter in the setUpgradeFW function.

Apr 8, 2024
CVE-2024-31808
8.8 HIGH

TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the webWlanIdx parameter in the setWebWlanIdx function.

Apr 8, 2024
CVE-2024-31807
9.8 CRITICAL

TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the hostTime parameter in the NTPSyncWithHost function.

Apr 8, 2024
CVE-2024-31806
6.5 MEDIUM

TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a Denial-of-Service (DoS) vulnerability in the RebootSystem function which can reboot the system without authorization.

Apr 8, 2024
CVE-2024-31805
6.5 MEDIUM

TOTOLINK EX200 V4.0.3c.7646_B20201211 allows attackers to start the Telnet service without authorization via the telnet_enabled parameter in the setTelnetCfg function.

Apr 8, 2024
CVE-2024-2834
8.7 HIGH

A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Management Center and ArcSight Platform. The vulnerability could be remotely exploited.

Apr 8, 2024
CVE-2024-28066
8.8 HIGH

In Unify CP IP Phone firmware 1.10.4.3, Weak Credentials are used (a hardcoded root password).

Apr 8, 2024
CVE-2014-125111
3.5 LOW

A vulnerability was found in namithjawahar Wp-Insert up to 2.0.8 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads …

Apr 8, 2024
CVE-2011-10006
3.5 LOW

A vulnerability was found in GamerZ WP-PostRatings up to 1.64. It has been classified as problematic. This affects an unknown part of the file wp-postratings.php. …

Apr 8, 2024
CVE-2024-3439
7.3 HIGH

A vulnerability was found in SourceCodester Prison Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /Account/login.php. …

Apr 8, 2024
CVE-2024-26574
7.8 HIGH

Insecure Permissions vulnerability in Wondershare Filmora v.13.0.51 allows a local attacker to execute arbitrary code via a crafted script to the WSNativePushService.exe

Apr 8, 2024
CVE-2022-43216
9.1 CRITICAL

AbrhilSoft Employee's Portal before v5.6.2 was discovered to contain a SQL injection vulnerability in the login page.

Apr 8, 2024
CVE-2024-3438
7.3 HIGH

A vulnerability was found in SourceCodester Prison Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /Admin/login.php. The …

Apr 8, 2024
CVE-2024-27897
7.5 HIGH

Input verification vulnerability in the call module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Apr 8, 2024
CVE-2024-27896
7.5 HIGH

Input verification vulnerability in the log module. Impact: Successful exploitation of this vulnerability can affect integrity.

Apr 8, 2024
CVE-2024-27895
7.5 HIGH

Vulnerability of permission control in the window module. Successful exploitation of this vulnerability may affect confidentiality.

Apr 8, 2024
CVE-2024-26811
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate payload size in ipc response If installing malicious ksmbd-tools, ksmbd.mountd can return invalid …

Apr 8, 2024
CVE-2023-52386
7.5 HIGH

Out-of-bounds write vulnerability in the RSMC module. Impact: Successful exploitation of this vulnerability will affect availability.

Apr 8, 2024
CVE-2023-52385
6.2 MEDIUM

Out-of-bounds write vulnerability in the RSMC module. Impact: Successful exploitation of this vulnerability will affect availability.

Apr 8, 2024
CVE-2023-52364
6.3 MEDIUM

Vulnerability of input parameters being not strictly verified in the RSMC module. Impact: Successful exploitation of this vulnerability may cause out-of-bounds write.

Apr 8, 2024
CVE-2024-31375
5.4 MEDIUM

Missing Authorization vulnerability in Saleswonder Team: Tobias WP2LEADS wp2leads.This issue affects WP2LEADS: from n/a through <= 3.2.7.

Apr 8, 2024
CVE-2024-31357
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BdThemes Ultimate Store Kit Elementor Addons allows Stored XSS.This issue affects Ultimate Store …

Apr 8, 2024
CVE-2024-23192
6.1 MEDIUM

RSS feeds that contain malicious data- attributes could be abused to inject script code to a users browser session when reading compromised RSS feeds or …

Apr 8, 2024
CVE-2024-23191
5.4 MEDIUM

Upsell advertisement information of an account can be manipulated to execute script code in the context of the users browser session. To exploit this an …

Apr 8, 2024
CVE-2024-23190
5.4 MEDIUM

Upsell shop information of an account can be manipulated to execute script code in the context of the users browser session. To exploit this an …

Apr 8, 2024
CVE-2024-23189
5.4 MEDIUM

Embedded content references at tasks could be used to temporarily execute script code in the context of the users browser session. To exploit this an …

Apr 8, 2024
CVE-2023-52554
6.5 MEDIUM

Permission control vulnerability in the Bluetooth module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Apr 8, 2024
CVE-2023-52553
7.4 HIGH

Race condition vulnerability in the Wi-Fi module. Impact: Successful exploitation of this vulnerability will affect availability.

Apr 8, 2024
CVE-2023-52552
7.5 HIGH

Input verification vulnerability in the power module. Impact: Successful exploitation of this vulnerability will affect availability.

Apr 8, 2024
CVE-2023-52551
5.3 MEDIUM

Vulnerability of data verification errors in the kernel module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Apr 8, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.