CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-3141
2.4 LOW

A vulnerability has been found in Clavister E10 and E80 up to 14.00.10 and classified as problematic. This vulnerability affects unknown code of the file …

Apr 1, 2024
CVE-2024-3140
3.5 LOW

A vulnerability, which was classified as problematic, was found in SourceCodester Computer Laboratory Management System 1.0. This affects an unknown part of the file /classes/Users.php?f=save. …

Apr 1, 2024
CVE-2024-3139
5.4 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Computer Laboratory Management System 1.0. Affected by this issue is the function save_users …

Apr 1, 2024
CVE-2024-27333
5.5 MEDIUM

Kofax Power PDF GIF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Kofax …

Apr 1, 2024
CVE-2024-3165
4.5 MEDIUM

System->Maintenance-> Log Files in dotCMS dashboard is providing the username/password for database connections in the log output. Nevertheless, this is a moderate issue as it …

Apr 1, 2024
CVE-2024-3164
4.5 MEDIUM

In dotCMS dashboard, the Tools and Log Files tabs under System → Maintenance Portlet, which is and always has been an Admin portlet, is accessible …

Apr 1, 2024
CVE-2024-3138
3.5 LOW

** DISPUTED ** A vulnerability was found in francoisjacquet RosarioSIS 11.5.1. It has been rated as problematic. This issue affects some unknown processing of the …

Apr 1, 2024
CVE-2024-27332
3.3 LOW

PDF-XChange Editor JPG File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. …

Apr 1, 2024
CVE-2024-27331
3.3 LOW

PDF-XChange Editor EMF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. …

Apr 1, 2024
CVE-2024-27330
3.3 LOW

PDF-XChange Editor EMF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. …

Apr 1, 2024
CVE-2024-27329
5.5 MEDIUM

PDF-XChange Editor XPS File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. …

Apr 1, 2024
CVE-2024-27328
5.5 MEDIUM

PDF-XChange Editor EMF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. …

Apr 1, 2024
CVE-2024-27327
7.8 HIGH

PDF-XChange Editor PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange …

Apr 1, 2024
CVE-2024-27326
5.5 MEDIUM

PDF-XChange Editor XPS File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. …

Apr 1, 2024
CVE-2024-27325
5.5 MEDIUM

PDF-XChange Editor EMF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. …

Apr 1, 2024
CVE-2024-27324
5.5 MEDIUM

PDF-XChange Editor TIF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. …

Apr 1, 2024
CVE-2024-27323
7.5 HIGH

PDF-XChange Editor Updater Improper Certificate Validation Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PDF-XChange Editor. …

Apr 1, 2024
CVE-2024-23119
8.8 HIGH

Centreon insertGraphTemplate SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required …

Apr 1, 2024
CVE-2024-23118
7.2 HIGH

Centreon updateContactHostCommands SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required …

Apr 1, 2024
CVE-2024-23117
7.2 HIGH

Centreon updateContactServiceCommands SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required …

Apr 1, 2024
CVE-2024-23116
7.2 HIGH

Centreon updateLCARelation SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required …

Apr 1, 2024
CVE-2024-23115
7.2 HIGH

Centreon updateGroups SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required …

Apr 1, 2024
CVE-2024-1863
9.8 CRITICAL

Sante PACS Server Token Endpoint SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante …

Apr 1, 2024
CVE-2024-1179
8.8 HIGH

TP-Link Omada ER605 DHCPv6 Client Options Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations …

Apr 1, 2024
CVE-2024-0637
8.8 HIGH

Centreon updateDirectory SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required …

Apr 1, 2024
CVE-2023-51573
9.8 CRITICAL

Voltronic Power ViewPower Pro updateManagerPassword Exposed Dangerous Function Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Voltronic Power …

Apr 1, 2024
CVE-2023-51572
9.8 CRITICAL

Voltronic Power ViewPower Pro getMacAddressByIp Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Voltronic …

Apr 1, 2024
CVE-2023-51571
7.5 HIGH

Voltronic Power ViewPower Pro SocketService Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Voltronic Power …

Apr 1, 2024
CVE-2023-51570
9.8 CRITICAL

Voltronic Power ViewPower Pro Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Apr 1, 2024
CVE-2024-29435
4.1 MEDIUM

An issue discovered in Alldata v0.4.6 allows attacker to run arbitrary commands via the processId parameter.

Apr 1, 2024
CVE-2024-29433
9.8 CRITICAL

A deserialization vulnerability in the FASTJSON component of Alldata v0.4.6 allows attackers to execute arbitrary commands via supplying crafted data.

Apr 1, 2024
CVE-2023-48906
4.3 MEDIUM

Stack Overflow vulnerability in Btstack 1.6 and earlier allows attackers to cause a denial of service via crafted input to the char_for_nibble function.

Apr 1, 2024
CVE-2024-3135
6.5 MEDIUM

A Cross-Site Request Forgery (CSRF) vulnerability exists in the mudler/localai application, allowing attackers to craft malicious webpages that, when visited by a victim, perform unauthorized …

Apr 1, 2024
CVE-2024-3131
6.3 MEDIUM

A vulnerability was found in SourceCodester Computer Laboratory Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file …

Apr 1, 2024
CVE-2024-28232
6.2 MEDIUM

Go package IceWhaleTech/CasaOS-UserService provides user management functionalities to CasaOS. The Casa OS Login page has disclosed the username enumeration vulnerability in the login page which …

Apr 1, 2024
CVE-2024-3129
6.3 MEDIUM

A vulnerability was found in SourceCodester Image Accordion Gallery App 1.0. It has been classified as critical. This affects an unknown part of the file …

Apr 1, 2024
CVE-2024-30867
9.8 CRITICAL

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/edit_virtual_site_info.php.

Apr 1, 2024
CVE-2024-30863
6.3 MEDIUM

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /WebPages/history.php.

Apr 1, 2024
CVE-2024-30862
8.8 HIGH

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /3g/index.php.

Apr 1, 2024
CVE-2024-30861
5.3 MEDIUM

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/configguide/ipsec_guide_1.php.

Apr 1, 2024
CVE-2024-30860
8.8 HIGH

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/export_excel_user.php.

Apr 1, 2024
CVE-2024-30859
8.8 HIGH

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/config_ISCGroupSSLCert.php.

Apr 1, 2024
CVE-2024-30858
9.8 CRITICAL

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/edit_fire_wall.php.

Apr 1, 2024
CVE-2024-25574
8.8 HIGH

SQL injection vulnerability exists in GetDIAE_usListParameters.

Apr 1, 2024
CVE-2024-3128
2.4 LOW

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as problematic, has been found in Replify-Messenger 1.0 on Android. This issue affects some unknown …

Apr 1, 2024
CVE-2024-30866
5.4 MEDIUM

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /3g/menu.php.

Apr 1, 2024
CVE-2024-30865
9.8 CRITICAL

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/edit_user_login.php.

Apr 1, 2024
CVE-2024-30864
6.3 MEDIUM

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/config_ISCGroupTimePolicy.php.

Apr 1, 2024
CVE-2024-26655
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Fix memory leak in posix_clock_open() If the clk ops.open() function returns an error, we don't …

Apr 1, 2024
CVE-2024-21473
9.8 CRITICAL

Memory corruption while redirecting log file to any file location with any file name.

Apr 1, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.