CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-2999
6.3 MEDIUM

A vulnerability classified as critical has been found in Campcodes Online Art Gallery Management System 1.0. This affects an unknown part of the file /admin/adminHome.php. …

Mar 27, 2024
CVE-2024-2998
2.4 LOW

A vulnerability was found in Bdtask Multi-Store Inventory Management System up to 20240320. It has been rated as problematic. Affected by this issue is some …

Mar 27, 2024
CVE-2024-2997
2.4 LOW

A vulnerability was found in Bdtask Multi-Store Inventory Management System up to 20240320. It has been declared as problematic. Affected by this vulnerability is an …

Mar 27, 2024
CVE-2024-2996
2.4 LOW

A vulnerability was found in Bdtask Multi-Store Inventory Management System up to 20240320. It has been classified as problematic. Affected is an unknown function of …

Mar 27, 2024
CVE-2024-2995
5.4 MEDIUM

A vulnerability was found in NUUO Camera up to 20240319 and classified as problematic. This issue affects some unknown processing of the file /deletefile.php. The …

Mar 27, 2024
CVE-2024-2994
8.8 HIGH

A vulnerability was found in Tenda FH1203 2.0.1.6. It has been declared as critical. Affected by this vulnerability is the function GetParentControlInfo of the file …

Mar 27, 2024
CVE-2024-2993
8.8 HIGH

A vulnerability was found in Tenda FH1203 2.0.1.6. It has been classified as critical. Affected is the function formQuickIndex of the file /goform/QuickIndex. The manipulation …

Mar 27, 2024
CVE-2024-29892
6.1 MEDIUM

ZITADEL, open source authentication management software, uses Go templates to render the login UI. Under certain circumstances an action could set reserved claims managed by …

Mar 27, 2024
CVE-2024-29891
8.7 HIGH

ZITADEL users can upload their own avatar image and various image types are allowed. Due to a missing check, an attacker could upload HTML and …

Mar 27, 2024
CVE-2024-2992
8.8 HIGH

A vulnerability was found in Tenda FH1203 2.0.1.6 and classified as critical. This issue affects the function formSetCfm of the file /goform/setcfm. The manipulation of …

Mar 27, 2024
CVE-2024-2991
6.3 MEDIUM

A vulnerability has been found in Tenda FH1203 2.0.1.6 and classified as critical. This vulnerability affects the function formWriteFacMac of the file /goform/WriteFacMac. The manipulation …

Mar 27, 2024
CVE-2024-2990
8.8 HIGH

A vulnerability, which was classified as critical, was found in Tenda FH1203 2.0.1.6. This affects the function formexeCommand of the file /goform/execCommand. The manipulation of …

Mar 27, 2024
CVE-2024-29888
4.2 MEDIUM

Saleor is an e-commerce platform that serves high-volume companies. When using `Pickup: Local stock only` click-and-collect as a delivery method in specific conditions the customer …

Mar 27, 2024
CVE-2024-29887
7.4 HIGH

Serverpod is an app and web server, built for the Flutter and Dart ecosystem. This bug bypassed the validation of TSL certificates on all none …

Mar 27, 2024
CVE-2024-29886
5.3 MEDIUM

Serverpod is an app and web server, built for the Flutter and Dart ecosystem. An issue was identified with the old password hash algorithm that …

Mar 27, 2024
CVE-2024-28860
8.0 HIGH

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Users of IPsec transparent encryption in Cilium may be vulnerable to cryptographic attacks …

Mar 27, 2024
CVE-2024-28247
7.6 HIGH

The Pi-hole is a DNS sinkhole that protects your devices from unwanted content without installing any client-side software. A vulnerability has been discovered in Pihole …

Mar 27, 2024
CVE-2024-28233
8.1 HIGH

JupyterHub is an open source multi-user server for Jupyter notebooks. By tricking a user into visiting a malicious subdomain, the attacker can achieve an XSS …

Mar 27, 2024
CVE-2024-28085
3.3 LOW

wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape sequences to be sent to other users' terminals through argv. (Specifically, escape …

Mar 27, 2024
CVE-2024-2989
8.8 HIGH

A vulnerability, which was classified as critical, has been found in Tenda FH1203 2.0.1.6. Affected by this issue is the function fromNatStaticSetting of the file …

Mar 27, 2024
CVE-2024-2988
8.8 HIGH

A vulnerability classified as critical was found in Tenda FH1203 2.0.1.6. Affected by this vulnerability is the function fromSetRouteStatic of the file /goform/fromRouteStatic. The manipulation …

Mar 27, 2024
CVE-2024-23451
4.4 MEDIUM

Incorrect Authorization issue exists in the API key based security model for Remote Cluster Security, which is currently in Beta, in Elasticsearch 8.10.0 and before …

Mar 27, 2024
CVE-2024-20308
8.6 HIGH

A vulnerability in the IKEv1 fragmentation code of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a …

Mar 27, 2024
CVE-2024-20307
6.8 MEDIUM

A vulnerability in the IKEv1 fragmentation code of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a …

Mar 27, 2024
CVE-2023-0582
8.1 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ForgeRock Access Management allows Authorization Bypass. This issue affects access management: before …

Mar 27, 2024
CVE-2024-2987
8.8 HIGH

A vulnerability classified as critical has been found in Tenda FH1202 1.2.0.14(408). Affected is the function GetParentControlInfo of the file /goform/GetParentControlInfo. The manipulation of the …

Mar 27, 2024
CVE-2024-2986
8.8 HIGH

A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been rated as critical. This issue affects the function formSetSpeedWan of the file /goform/SetSpeedWan. The …

Mar 27, 2024
CVE-2024-2985
8.8 HIGH

A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been declared as critical. This vulnerability affects the function formQuickIndex of the file /goform/QuickIndex. The …

Mar 27, 2024
CVE-2024-29946
8.1 HIGH

In Splunk Enterprise versions below 9.2.1, 9.1.4, and 9.0.9, the Dashboard Examples Hub lacks protections for risky SPL commands. This could let attackers bypass SPL …

Mar 27, 2024
CVE-2024-29945
7.2 HIGH

In Splunk Enterprise versions below 9.2.1, 9.1.4, and 9.0.9, the software potentially exposes authentication tokens during the token validation process. This exposure happens when either …

Mar 27, 2024
CVE-2024-23450
4.9 MEDIUM

A flaw was discovered in Elasticsearch, where processing a document in a deeply nested pipeline on an ingest node could cause the Elasticsearch node to …

Mar 27, 2024
CVE-2024-20354
4.7 MEDIUM

A vulnerability in the handling of encrypted wireless frames of Cisco Aironet Access Point (AP) Software could allow an unauthenticated, adjacent attacker to cause a …

Mar 27, 2024
CVE-2024-20333
4.3 MEDIUM

A vulnerability in the web-based management interface of Cisco Catalyst Center, formerly Cisco DNA Center, could allow an authenticated, remote attacker to change specific data …

Mar 27, 2024
CVE-2024-20324
5.5 MEDIUM

A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, low-privileged, local attacker to access WLAN configuration details including passwords. This …

Mar 27, 2024
CVE-2024-20316
5.8 MEDIUM

A vulnerability in the data model interface (DMI) services of Cisco IOS XE Software could allow an unauthenticated, remote attacker to access resources that should …

Mar 27, 2024
CVE-2024-20314
8.6 HIGH

A vulnerability in the IPv4 Software-Defined Access (SD-Access) fabric edge node feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause …

Mar 27, 2024
CVE-2024-20312
7.4 HIGH

A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to …

Mar 27, 2024
CVE-2024-20311
8.6 HIGH

A vulnerability in the Locator ID Separation Protocol (LISP) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker …

Mar 27, 2024
CVE-2024-20309
5.6 MEDIUM

A vulnerability in auxiliary asynchronous port (AUX) functions of Cisco IOS XE Software could allow an authenticated, local attacker to cause an affected device to …

Mar 27, 2024
CVE-2024-20306
6.0 MEDIUM

A vulnerability in the Unified Threat Defense (UTD) configuration CLI of Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrary commands …

Mar 27, 2024
CVE-2024-20303
7.4 HIGH

A vulnerability in the multicast DNS (mDNS) gateway feature of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, adjacent attacker …

Mar 27, 2024
CVE-2024-20278
6.5 MEDIUM

A vulnerability in the NETCONF feature of Cisco IOS XE Software could allow an authenticated, remote attacker to elevate privileges to root on an affected …

Mar 27, 2024
CVE-2024-20276
7.4 HIGH

A vulnerability in Cisco IOS Software for Cisco Catalyst 6000 Series Switches could allow an unauthenticated, adjacent attacker to cause an affected device to reload …

Mar 27, 2024
CVE-2024-20271
8.6 HIGH

A vulnerability in the IP packet processing of Cisco Access Point (AP) Software could allow an unauthenticated, remote attacker to cause a denial of service …

Mar 27, 2024
CVE-2024-20265
5.9 MEDIUM

A vulnerability in the boot process of Cisco Access Point (AP) Software could allow an unauthenticated, physical attacker to bypass the Cisco Secure Boot functionality …

Mar 27, 2024
CVE-2024-20259
8.6 HIGH

A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload …

Mar 27, 2024
CVE-2024-2984
8.8 HIGH

A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been classified as critical. This affects the function formSetCfm of the file /goform/setcfm. The manipulation …

Mar 27, 2024
CVE-2024-2983
8.8 HIGH

A vulnerability was found in Tenda FH1202 1.2.0.14(408) and classified as critical. Affected by this issue is the function formSetClientState of the file /goform/SetClientState. The …

Mar 27, 2024
CVE-2024-2982
5.5 MEDIUM

A vulnerability has been found in Tenda FH1202 1.2.0.14(408) and classified as critical. Affected by this vulnerability is the function formWriteFacMac of the file /goform/WriteFacMac. …

Mar 27, 2024
CVE-2024-1540
8.2 HIGH

A command injection vulnerability exists in the deploy+test-visual.yml workflow of the gradio-app/gradio repository, due to improper neutralization of special elements used in a command. This …

Mar 27, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.