CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-31139
5.9 MEDIUM

In JetBrains TeamCity before 2024.03 xXE was possible in the Maven build steps detector

Mar 28, 2024
CVE-2024-31138
4.6 MEDIUM

In JetBrains TeamCity before 2024.03 xSS was possible via Agent Distribution settings

Mar 28, 2024
CVE-2024-31137
6.8 MEDIUM

In JetBrains TeamCity before 2024.03 reflected XSS was possible via Space connection configuration

Mar 28, 2024
CVE-2024-31136
7.4 HIGH

In JetBrains TeamCity before 2024.03 2FA could be bypassed by providing a special URL parameter

Mar 28, 2024
CVE-2024-31135
6.1 MEDIUM

In JetBrains TeamCity before 2024.03 open redirect was possible on the login page

Mar 28, 2024
CVE-2024-31134
6.5 MEDIUM

In JetBrains TeamCity before 2024.03 authenticated users without administrative permissions could register other users when self-registration was disabled

Mar 28, 2024
CVE-2024-30612
8.1 HIGH

Tenda AC10U v15.03.06.48 has a stack overflow vulnerability in the deviceId, limitSpeed, limitSpeedUp parameter from formSetClientState function.

Mar 28, 2024
CVE-2024-30604
7.5 HIGH

Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the list1 parameter of the fromDhcpListClient function.

Mar 28, 2024
CVE-2024-30603
6.5 MEDIUM

Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the urls parameter of the saveParentControlInfo function.

Mar 28, 2024
CVE-2024-30602
9.8 CRITICAL

Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the schedStartTime parameter of the setSchedWifi function.

Mar 28, 2024
CVE-2024-30601
8.0 HIGH

Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the time parameter of the saveParentControlInfo function.

Mar 28, 2024
CVE-2024-30600
8.0 HIGH

Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the schedEndTime parameter of the setSchedWifi function.

Mar 28, 2024
CVE-2024-30599
8.8 HIGH

Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the deviceMac parameter of the addWifiMacFilter function.

Mar 28, 2024
CVE-2024-30598
6.5 MEDIUM

Tenda FH1203 v2.0.1.6 firmware has a stack overflow vulnerability in the security_5g parameter of the formWifiBasicSet function.

Mar 28, 2024
CVE-2024-30597
6.5 MEDIUM

Tenda FH1203 v2.0.1.6 firmware has a stack overflow vulnerability in the security parameter of the formWifiBasicSet function.

Mar 28, 2024
CVE-2024-0259
7.3 HIGH

Fortra's Robot Schedule Enterprise Agent for Windows prior to version 3.04 is susceptible to privilege escalation. A low-privileged user can overwrite the service executable. When …

Mar 28, 2024
CVE-2023-45715
3.5 LOW

The console may experience a service interruption when processing file names with invalid characters.

Mar 28, 2024
CVE-2023-45706
2.0 LOW

An administrative user of WebReports may perform a Cross Site Scripting (XSS) and/or Man in the Middle (MITM) exploit through SAML configuration.

Mar 28, 2024
CVE-2023-45705
3.5 LOW

An administrative user of WebReports may perform a Server Side Request Forgery (SSRF) exploit through SMTP configuration options.

Mar 28, 2024
CVE-2024-30607
8.0 HIGH

Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the deviceId parameter of the saveParentControlInfo function.

Mar 28, 2024
CVE-2024-30606
8.0 HIGH

Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the page parameter of the fromDhcpListClient function.

Mar 28, 2024
CVE-2024-30592
8.0 HIGH

Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the page parameter of the fromAddressNat function.

Mar 28, 2024
CVE-2024-30591
8.8 HIGH

Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the time parameter of the saveParentControlInfo function.

Mar 28, 2024
CVE-2024-30590
6.5 MEDIUM

Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the schedEndTime parameter of the setSchedWifi function.

Mar 28, 2024
CVE-2024-30589
9.8 CRITICAL

Tenda FH1202 v1.2.0.14(408) firmware has a stack overflow vulnerability in the entrys parameter of the fromAddressNat function.

Mar 28, 2024
CVE-2024-30588
4.3 MEDIUM

Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the schedStartTime parameter of the setSchedWifi function.

Mar 28, 2024
CVE-2024-30587
9.8 CRITICAL

Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the urls parameter of the saveParentControlInfo function.

Mar 28, 2024
CVE-2024-30586
6.5 MEDIUM

Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the security_5g parameter of the formWifiBasicSet function.

Mar 28, 2024
CVE-2024-30585
6.5 MEDIUM

Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceId parameter of the saveParentControlInfo function.

Mar 28, 2024
CVE-2024-30584
9.8 CRITICAL

Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the security parameter of the formWifiBasicSet function.

Mar 28, 2024
CVE-2024-30583
8.0 HIGH

Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the mitInterface parameter of the fromAddressNat function.

Mar 28, 2024
CVE-2024-29898
4.9 MEDIUM

CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. An oversight during the writing of the patch for CVE-2024-29897 may have exposed suppressed wiki …

Mar 28, 2024
CVE-2024-29897
4.9 MEDIUM

CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. It is possible for users with (delete) or (suppressrevision) on any wiki in the farm …

Mar 28, 2024
CVE-2024-29882
7.2 HIGH

SRS is a simple, high-efficiency, real-time video server. SRS's `/api/v1/vhosts/vid-<id>?callback=<payload>` endpoint didn't filter the callback function name which led to injecting malicious javascript payloads and …

Mar 28, 2024
CVE-2024-29200
6.8 MEDIUM

Kimai is a web-based multi-user time-tracking application. The permission `view_other_timesheet` performs differently for the Kimai UI and the API, thus returning unexpected data through the …

Mar 28, 2024
CVE-2024-28109
8.1 HIGH

veraPDF-library is a PDF/A validation library. Executing policy checks using custom schematron files invokes an XSL transformation that could lead to a remote code execution …

Mar 28, 2024
CVE-2023-6437
9.8 CRITICAL

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TP-Link TP-Link EX20v AX1800, Tp-Link Archer C5v AC1200, Tp-Link TD-W9970, …

Mar 28, 2024
CVE-2024-30596
9.8 CRITICAL

Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceId parameter of the formSetDeviceName function.

Mar 28, 2024
CVE-2024-30594
6.5 MEDIUM

Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceMac parameter of the addWifiMacFilter function.

Mar 28, 2024
CVE-2024-30593
9.8 CRITICAL

Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability located in the deviceName parameter of the formSetDeviceName function.

Mar 28, 2024
CVE-2024-29896
7.5 HIGH

Astro-Shield is a library to compute the subresource integrity hashes for your JS scripts and CSS stylesheets. When automated CSP headers generation for SSR content …

Mar 28, 2024
CVE-2024-27775
7.2 HIGH

SysAid before version 23.2.14 b18 - CWE-918: Server-Side Request Forgery (SSRF) may allow exposing the local OS user's NTLMv2 hash

Mar 28, 2024
CVE-2024-30595
9.8 CRITICAL

Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceId parameter of the addWifiMacFilter function.

Mar 28, 2024
CVE-2024-30422
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPVibes Elementor Addon Elements addon-elements-for-elementor-page-builder.This issue affects Elementor Addon Elements: from n/a through …

Mar 28, 2024
CVE-2024-30421
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Pixelite Events Manager.This issue affects Events Manager: from n/a through 6.4.7.1.

Mar 28, 2024
CVE-2024-2818
4.3 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions before 16.8.5, all versions starting from 16.9 before 16.9.3, all versions starting from 16.10 …

Mar 28, 2024
CVE-2023-6371
8.7 HIGH

An issue has been discovered in GitLab CE/EE affecting all versions before 16.8.5, all versions starting from 16.9 before 16.9.3, all versions starting from 16.10 …

Mar 28, 2024
CVE-2023-52628
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: netfilter: nftables: exthdr: fix 4-byte stack OOB write If priv->len is a multiple of 4, …

Mar 28, 2024
CVE-2024-2890
9.1 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Tumult Inc. Tumult Hype Animations.This issue affects Tumult Hype Animations: from n/a through 1.9.12.

Mar 28, 2024
CVE-2024-29241
9.9 CRITICAL

Missing authorization vulnerability in System webapi component in Synology Surveillance Station before 9.2.0-9289 and 9.2.0-11289 allows remote authenticated users to obtain non-sensitive information, write sensitive …

Mar 28, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.