CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-30353
7.8 HIGH

Foxit PDF Reader AcroForm Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF …

Apr 2, 2024
CVE-2024-30352
7.8 HIGH

Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. …

Apr 2, 2024
CVE-2024-30351
7.8 HIGH

Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. …

Apr 2, 2024
CVE-2024-30350
3.3 LOW

Foxit PDF Reader Annotation Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. …

Apr 2, 2024
CVE-2024-30349
7.8 HIGH

Foxit PDF Reader U3D File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Apr 2, 2024
CVE-2024-30348
7.8 HIGH

Foxit PDF Reader U3D File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Apr 2, 2024
CVE-2024-30347
3.3 LOW

Foxit PDF Reader U3D File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit …

Apr 2, 2024
CVE-2024-30346
7.8 HIGH

Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. …

Apr 2, 2024
CVE-2024-30345
7.8 HIGH

Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. …

Apr 2, 2024
CVE-2024-30344
7.8 HIGH

Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. …

Apr 2, 2024
CVE-2024-29432
9.8 CRITICAL

Alldata v0.4.6 was discovered to contain a SQL injection vulnerability via the tablename parameter at /data/masterdata/datas.

Apr 2, 2024
CVE-2024-27605
7.5 HIGH

Alldata V0.4.6 is vulnerable to Insecure Permissions. Using users (test) can query information about the users in the system.

Apr 2, 2024
CVE-2024-27604
9.8 CRITICAL

Alldata V0.4.6 is vulnerable to Command execution vulnerability. System commands can be deserialized.

Apr 2, 2024
CVE-2024-27602
9.1 CRITICAL

Alldata V0.4.6 is vulnerable to Incorrect Access Control. A total of many modules interface documents have been leaked.For example, the /api/system/v2/api-docs module.

Apr 2, 2024
CVE-2024-25075
5.1 MEDIUM

An issue was discovered in Softing uaToolkit Embedded before 1.41.1. When a subscription with a very low MaxNotificationPerPublish parameter is created, a publish response is …

Apr 2, 2024
CVE-2024-30343
7.8 HIGH

Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. …

Apr 2, 2024
CVE-2024-30342
7.8 HIGH

Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. …

Apr 2, 2024
CVE-2024-30341
7.8 HIGH

Foxit PDF Reader Doc Object Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit …

Apr 2, 2024
CVE-2024-30340
3.3 LOW

Foxit PDF Reader Annotation Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. …

Apr 2, 2024
CVE-2024-30339
7.8 HIGH

Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. …

Apr 2, 2024
CVE-2024-30338
7.8 HIGH

Foxit PDF Reader Doc Object Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF …

Apr 2, 2024
CVE-2024-30337
7.8 HIGH

Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. …

Apr 2, 2024
CVE-2024-30336
7.8 HIGH

Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. …

Apr 2, 2024
CVE-2024-29834
6.4 MEDIUM

This vulnerability allows authenticated users with produce or consume permissions to perform unauthorized operations on partitioned topics, such as unloading topics and triggering compaction. These …

Apr 2, 2024
CVE-2024-30532
4.9 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in Builderall Team Builderall Builder for WordPress.This issue affects Builderall Builder for WordPress: from n/a through 2.0.1.

Apr 2, 2024
CVE-2024-30531
4.9 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in Nelio Software Nelio Content.This issue affects Nelio Content: from n/a through 3.2.0.

Apr 2, 2024
CVE-2024-24888
6.4 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in StellarWP Gutenberg Blocks by Kadence Blocks kadence-blocks.This issue affects Gutenberg Blocks by Kadence Blocks: from n/a through <= 3.2.25.

Apr 2, 2024
CVE-2024-31109
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Toastie Studio Woocommerce Social Media Share Buttons allows Stored XSS.This issue affects Woocommerce Social Media Share Buttons: from n/a …

Apr 2, 2024
CVE-2024-31105
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Adam Bowen Tax Rate Upload allows Reflected XSS.This issue affects Tax Rate Upload: from n/a through 2.4.5.

Apr 2, 2024
CVE-2024-30809
7.5 HIGH

An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap-use-after-free in Ap4Sample.h in AP4_Sample::GetOffset() const, leading to a Denial of Service (DoS), as demonstrated …

Apr 2, 2024
CVE-2024-30808
2.7 LOW

An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap-use-after-free in AP4_SubStream::~AP4_SubStream at Ap4ByteStream.cpp, leading to a Denial of Service (DoS), as demonstrated by …

Apr 2, 2024
CVE-2024-30807
7.5 HIGH

An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap-use-after-free in AP4_UnknownAtom::~AP4_UnknownAtom at Ap4Atom.cpp, leading to a Denial of Service (DoS), as demonstrated by …

Apr 2, 2024
CVE-2024-30806
6.5 MEDIUM

An issue was discovered in Bento4 v1.6.0-641-2-g1529b83. There is a heap overflow in AP4_Dec3Atom::AP4_Dec3Atom at Ap4Dec3Atom.cpp, leading to a Denial of Service (DoS), as demonstrated …

Apr 2, 2024
CVE-2024-30335
7.1 HIGH

Foxit PDF Reader AcroForm Annotation Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF …

Apr 2, 2024
CVE-2024-3151
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in Bdtask Multi-Store Inventory Management System up to 20240325. Affected is an unknown function of the …

Apr 2, 2024
CVE-2024-2435
4.3 MEDIUM

For an attacker with pre-existing access to send a signal to a workflow, the attacker can make the signal name a script that executes when …

Apr 2, 2024
CVE-2024-28287
7.3 HIGH

A DOM-based open redirection in the returnUrl parameter of INSTINCT UI Web Client 6.5.0 allows attackers to redirect users to malicious sites via a crafted …

Apr 2, 2024
CVE-2024-22248
7.1 HIGH

VMware SD-WAN Orchestrator contains an open redirect vulnerability. A malicious actor may be able to redirect a victim to an attacker controlled domain due to …

Apr 2, 2024
CVE-2024-22247
4.8 MEDIUM

VMware SD-WAN Edge contains a missing authentication and protection mechanism vulnerability. A malicious actor with physical access to the SD-WAN Edge appliance during activation can …

Apr 2, 2024
CVE-2024-22246
7.4 HIGH

VMware SD-WAN Edge contains an unauthenticated command injection vulnerability potentially leading to remote code execution. A malicious actor with local access to the Edge Router …

Apr 2, 2024
CVE-2024-30248
7.7 HIGH

Piccolo Admin is an admin interface/content management system for Python, built on top of Piccolo. Piccolo's admin panel allows media files to be uploaded. As …

Apr 2, 2024
CVE-2024-22780
6.1 MEDIUM

Cross Site Scripting vulnerability in CA17 TeamsACS v.1.0.1 allows a remote attacker to execute arbitrary code via a crafted script to the errmsg parameter.

Apr 2, 2024
CVE-2024-30965
8.8 HIGH

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/member_scores.php.

Apr 2, 2024
CVE-2024-30621
9.8 CRITICAL

Tenda AX1803 v1.0.0.1 contains a stack overflow via the serverName parameter in the function fromAdvSetMacMtuWan.

Apr 2, 2024
CVE-2024-30620
9.8 CRITICAL

Tenda AX1803 v1.0.0.1 contains a stack overflow via the serviceName parameter in the function fromAdvSetMacMtuWan.

Apr 2, 2024
CVE-2024-30946
5.5 MEDIUM

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/co_do.php.

Apr 2, 2024
CVE-2024-2389
10.0 CRITICAL

In Flowmon versions prior to 11.1.14 and 12.3.5, an operating system command injection vulnerability has been identified. An unauthenticated user can gain entry to the …

Apr 2, 2024
CVE-2024-29514
8.8 HIGH

File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP file.

Apr 2, 2024
CVE-2023-50313
5.3 MEDIUM

IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security for outbound TLS connections caused by a failure to honor user configuration. …

Apr 2, 2024
CVE-2024-29949
7.2 HIGH

There is a command injection vulnerability in some Hikvision NVRs. This could allow an authenticated user with administrative rights to execute arbitrary commands.

Apr 2, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.