CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-25390
8.4 HIGH

A heap buffer overflow occurs in finsh/msh_file.c and finsh/msh.c in RT-Thread through 5.0.2.

Mar 27, 2024
CVE-2024-25389
7.5 HIGH

RT-Thread through 5.0.2 generates random numbers with a weak algorithm of "seed = 214013L * seed + 2531011L; return (seed >> 16) & 0x7FFF;" in …

Mar 27, 2024
CVE-2024-25388
8.4 HIGH

drivers/wlan/wlan_mgmt,c in RT-Thread through 5.0.2 has an integer signedness error and resultant buffer overflow.

Mar 27, 2024
CVE-2024-24335
8.4 HIGH

A heap buffer overflow occurs in the dfs_v2 romfs filesystem RT-Thread through 5.0.2.

Mar 27, 2024
CVE-2024-24334
8.4 HIGH

A heap buffer overflow occurs in dfs_v2 dfs_file in RT-Thread through 5.0.2.

Mar 27, 2024
CVE-2024-1532
6.8 MEDIUM

A vulnerability exists in the stb-language file handling that affects the RTU500 series product versions listed below. A malicious actor could enforce diagnostic texts being …

Mar 27, 2024
CVE-2024-0400
7.5 HIGH

SCM Software is a client and server application. An Authenticated System manager client can execute LINQ query in the SCM server, for customized filtering. An …

Mar 27, 2024
CVE-2024-2940
3.5 LOW

A vulnerability classified as problematic was found in Campcodes Online Examination System 1.0. Affected by this vulnerability is an unknown functionality of the file /adminpanel/admin/facebox_modal/updateCourse.php. …

Mar 27, 2024
CVE-2024-2244
5.3 MEDIUM

REST service authentication anomaly with “valid username/no password” credential combination for batch job processing resulting in successful service invocation. The anomaly doesn’t exist with other …

Mar 27, 2024
CVE-2024-1531
8.2 HIGH

A vulnerability exists in the stb-language file handling that affects the RTU500 series product versions listed below. A malicious actor could print random memory content …

Mar 27, 2024
CVE-2024-2939
3.5 LOW

A vulnerability classified as problematic has been found in Campcodes Online Examination System 1.0. Affected is an unknown function of the file /adminpanel/admin/facebox_modal/updateExaminee.php. The manipulation …

Mar 27, 2024
CVE-2024-2938
6.3 MEDIUM

A vulnerability was found in Campcodes Online Examination System 1.0. It has been rated as critical. This issue affects some unknown processing of the file …

Mar 27, 2024
CVE-2024-2935
3.5 LOW

A vulnerability, which was classified as problematic, has been found in SourceCodester Todo List in Kanban Board 1.0. Affected by this issue is some unknown …

Mar 27, 2024
CVE-2024-2934
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Todo List in Kanban Board 1.0. Affected by this vulnerability is an unknown functionality of the …

Mar 27, 2024
CVE-2024-2932
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Online Chatting System 1.0. Affected is an unknown function of the file admin/update_room.php. The manipulation …

Mar 27, 2024
CVE-2024-2206
6.5 MEDIUM

An SSRF vulnerability exists in the gradio-app/gradio due to insufficient validation of user-supplied URLs in the `/proxy` route. Attackers can exploit this vulnerability by manipulating …

Mar 27, 2024
CVE-2024-2930
7.3 HIGH

A vulnerability was found in SourceCodester Music Gallery Site 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Mar 27, 2024
CVE-2024-2209
6.3 MEDIUM

A user with administrative privileges can create a compromised dll file of the same name as the original dll within the HP printer’s Firmware Update …

Mar 27, 2024
CVE-2017-20190

Some Microsoft technologies as used in Windows 8 through 11 allow a temporary client-side performance degradation during processing of multiple Unicode combining characters, aka a …

Mar 27, 2024
CVE-2024-2927
7.3 HIGH

A vulnerability was found in code-projects Mobile Shop 1.0. It has been classified as critical. Affected is an unknown function of the file Details.php of …

Mar 26, 2024
CVE-2024-2917
5.4 MEDIUM

A vulnerability was found in Campcodes House Rental Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Mar 26, 2024
CVE-2024-2916
7.3 HIGH

A vulnerability was found in Campcodes House Rental Management System 1.0. It has been classified as critical. Affected is an unknown function of the file …

Mar 26, 2024
CVE-2024-26577
7.5 HIGH

VSeeFace through 1.13.38.c2 allows attackers to cause a denial of service (application hang) via a spoofed UDP packet containing at least 10 digits in JSON …

Mar 26, 2024
CVE-2024-25138
6.5 MEDIUM

In AutomationDirect C-MORE EA9 HMI, credentials used by the platform are stored as plain text on the device.

Mar 26, 2024
CVE-2024-25137
4.3 MEDIUM

In AutomationDirect C-MORE EA9 HMI there is a program that copies a buffer of a size controlled by the user into a limited sized buffer …

Mar 26, 2024
CVE-2024-25136
7.5 HIGH

There is a function in AutomationDirect C-MORE EA9 HMI that allows an attacker to send a relative path in the URL without proper sanitizing of …

Mar 26, 2024
CVE-2023-50702
8.8 HIGH

Sikka SSCWindowsService 5 2023-09-14 executes a program as LocalSystem but allows full control by low-privileged users (and low-privileged users have write access to %PROGRAMDATA%\SSCService). Consequently, …

Mar 26, 2024
CVE-2024-2971
2.9 LOW

Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by negative object number in indirect reference in the input PDF file.

Mar 26, 2024
CVE-2024-2911
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in Tianjin PubliCMS 4.0.202302.e. This affects an unknown part. The manipulation leads to cross-site request forgery. …

Mar 26, 2024
CVE-2023-51147
8.0 HIGH

Buffer Overflow vulnerability in TRENDnet Trendnet AC1200 TEW-821DAP with firmware version 3.00b06 allows an attacker to execute arbitrary code via the adm_mod_pwd action.

Mar 26, 2024
CVE-2023-51146
8.0 HIGH

Buffer Overflow vulnerability in TRENDnet AC1200 TEW-821DAP with firmware version 3.00b06 allows an attacker to execute arbitrary code via the adm_add_user action.

Mar 26, 2024
CVE-2024-2910
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Ruijie RG-EG350 up to 20240318. Affected by this issue is the function vpnAction of …

Mar 26, 2024
CVE-2024-2909
8.8 HIGH

A vulnerability classified as critical was found in Ruijie RG-EG350 up to 20240318. Affected by this vulnerability is the function setAction of the file /itbox_pi/networksafe.php?a=set …

Mar 26, 2024
CVE-2024-2903
8.8 HIGH

A vulnerability was found in Tenda AC7 15.03.06.44. It has been classified as critical. Affected is the function GetParentControlInfo of the file /goform/GetParentControlInfo. The manipulation …

Mar 26, 2024
CVE-2024-2887
7.7 HIGH

Type Confusion in WebAssembly in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security …

Mar 26, 2024
CVE-2024-2886
7.5 HIGH

Use after free in WebCodecs in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium …

Mar 26, 2024
CVE-2024-2885
8.8 HIGH

Use after free in Dawn in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Mar 26, 2024
CVE-2024-2883
8.8 HIGH

Use after free in ANGLE in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Mar 26, 2024
CVE-2024-28551
7.5 HIGH

Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the ssid parameter of form_fast_setting_wifi_set function.

Mar 26, 2024
CVE-2024-28545
9.8 CRITICAL

Tenda AC18 V15.03.05.05 contains a command injection vulnerablility in the deviceName parameter of formsetUsbUnload function.

Mar 26, 2024
CVE-2024-27521
8.0 HIGH

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain an unauthenticated remote command execution (RCE) vulnerability via multiple parameters in the "setOpModeCfg" function. This security issue allows …

Mar 26, 2024
CVE-2024-26303
4.9 MEDIUM

Authenticated Denial of Service Vulnerability in ArubaOS-Switch SSH Daemon

Mar 26, 2024
CVE-2024-25421
9.8 CRITICAL

An issue in Ignite Realtime Openfire v.4.9.0 and before allows a remote attacker to escalate privileges via the ROOM_CACHE component.

Mar 26, 2024
CVE-2024-25420
7.2 HIGH

An issue in Ignite Realtime Openfire before 4.8.1 allows a remote attacker to escalate privileges via the admin.authorizedJIDs system property component.

Mar 26, 2024
CVE-2023-51148
8.0 HIGH

An issue in TRENDnet Trendnet AC1200 Dual Band PoE Indoor Wireless Access Point TEW-821DAP v.3.00b06 allows an attacker to execute arbitrary code via the 'mycli' …

Mar 26, 2024
CVE-2023-48777
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Elementor.Com Elementor Website Builder.This issue affects Elementor Website Builder: from 3.3.0 through 3.18.1.

Mar 26, 2024
CVE-2023-48275
8.0 HIGH

Unrestricted Upload of File with Dangerous Type vulnerability in Trustindex.Io Widgets for Google Reviews.This issue affects Widgets for Google Reviews: from n/a through 11.0.2.

Mar 26, 2024
CVE-2023-47873
9.1 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in WEN Solutions WP Child Theme Generator.This issue affects WP Child Theme Generator: from n/a through 1.0.9.

Mar 26, 2024
CVE-2023-47846
9.1 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Terry Lin WP Githuber MD.This issue affects WP Githuber MD: from n/a through 1.16.2.

Mar 26, 2024
CVE-2023-47842
9.1 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Zachary Segal CataBlog.This issue affects CataBlog: from n/a through 1.7.0.

Mar 26, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.