CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-29188
7.9 HIGH

WiX toolset lets developers create installers for Windows Installer, the Windows installation engine. The custom action behind WiX's `RemoveFolderEx` functionality could allow a standard user …

Mar 24, 2024
CVE-2024-29187
7.3 HIGH

WiX toolset lets developers create installers for Windows Installer, the Windows installation engine. When a bundle runs as SYSTEM user, Burn uses GetTempPathW which points …

Mar 24, 2024
CVE-2024-29034
6.8 MEDIUM

CarrierWave is a solution for file uploads for Rails, Sinatra and other Ruby web frameworks. The vulnerability CVE-2023-49090 wasn't fully addressed. This vulnerability is caused …

Mar 24, 2024
CVE-2024-29194
8.3 HIGH

OneUptime is a solution for monitoring and managing online services. The vulnerability lies in the improper validation of client-side stored data within the web application. …

Mar 24, 2024
CVE-2020-36825
6.3 MEDIUM

** UNSUPPORTED WHEN ASSIGNED ** ** DISPUTED ** A vulnerability has been found in cyberaz0r WebRAT up to 20191222 and classified as critical. This vulnerability …

Mar 24, 2024
CVE-2024-2856
8.8 HIGH

A vulnerability, which was classified as critical, has been found in Tenda AC10 16.03.10.13/16.03.10.20. Affected by this issue is the function fromSetSysTime of the file …

Mar 24, 2024
CVE-2024-2855
8.8 HIGH

A vulnerability classified as critical was found in Tenda AC15 15.03.05.18/15.03.05.19/15.03.20. Affected by this vulnerability is the function fromSetSysTime of the file /goform/SetSysTimeCfg. The manipulation …

Mar 24, 2024
CVE-2024-2854
6.3 MEDIUM

A vulnerability classified as critical has been found in Tenda AC18 15.03.05.05. Affected is the function formSetSambaConf of the file /goform/setsambacfg. The manipulation of the …

Mar 24, 2024
CVE-2024-2853
6.3 MEDIUM

A vulnerability was found in Tenda AC10U 15.03.06.48/15.03.06.49. It has been rated as critical. This issue affects the function formSetSambaConf of the file /goform/setsambacfg. The …

Mar 24, 2024
CVE-2024-2852
8.8 HIGH

A vulnerability was found in Tenda AC15 15.03.20_multi. It has been declared as critical. This vulnerability affects the function saveParentControlInfo of the file /goform/saveParentControlInfo. The …

Mar 24, 2024
CVE-2024-2851
6.3 MEDIUM

A vulnerability was found in Tenda AC15 15.03.05.18/15.03.20_multi. It has been classified as critical. This affects the function formSetSambaConf of the file /goform/setsambacfg. The manipulation …

Mar 24, 2024
CVE-2024-2850
8.8 HIGH

A vulnerability was found in Tenda AC15 15.03.05.18 and classified as critical. Affected by this issue is the function saveParentControlInfo of the file /goform/saveParentControlInfo. The …

Mar 24, 2024
CVE-2024-30161
6.5 MEDIUM

In Qt 6.5.4, 6.5.5, and 6.6.2, QNetworkReply header data might be accessed via a dangling pointer in Qt for WebAssembly (wasm). (Earlier and later versions …

Mar 24, 2024
CVE-2024-30156
7.5 HIGH

Varnish Cache before 7.3.2 and 7.4.x before 7.4.3 (and before 6.0.13 LTS), and Varnish Enterprise 6 before 6.0.12r6, allows credits exhaustion for an HTTP/2 connection …

Mar 24, 2024
CVE-2020-36827
5.4 MEDIUM

The XAO::Web module before 1.84 for Perl mishandles < and > characters in JSON output during use of json-embed in Web::Action.

Mar 24, 2024
CVE-2018-25100
5.3 MEDIUM

The Mojolicious module before 7.66 for Perl may leak cookies in certain situations related to multiple similar cookies for the same domain. This affects Mojo::UserAgent::CookieJar.

Mar 24, 2024
CVE-2024-24725
8.8 HIGH

Gibbon through 26.0.00 allows remote authenticated users to conduct PHP deserialization attacks via columnOrder in a POST request to the modules/System%20Admin/import_run.php&type=externalAssessment&step=4 URI.

Mar 23, 2024
CVE-2024-23755
8.8 HIGH

ClickUp Desktop before 3.3.77 on macOS and Windows allows code injection because of specific Electron Fuses. There is inadequate protection against code injection through settings …

Mar 23, 2024
CVE-2024-1603
7.5 HIGH

paddlepaddle/paddle 2.6.0 allows arbitrary file read via paddle.vision.ops.read_file.

Mar 23, 2024
CVE-2024-2849
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Simple File Manager 1.0. This vulnerability affects unknown code. The manipulation of the argument photo leads …

Mar 23, 2024
CVE-2024-24840
4.3 MEDIUM

Missing Authorization vulnerability in BdThemes Element Pack Elementor Addons.This issue affects Element Pack Elementor Addons: from n/a through 5.4.11.

Mar 23, 2024
CVE-2024-24835
4.3 MEDIUM

Missing Authorization vulnerability in realmag777 BEAR.This issue affects BEAR: from n/a through 1.1.4.

Mar 23, 2024
CVE-2024-24832
8.2 HIGH

Missing Authorization vulnerability in Metagauss EventPrime.This issue affects EventPrime: from n/a through 3.3.9.

Mar 23, 2024
CVE-2021-33633
7.3 HIGH

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in openEuler aops-ceres on Linux allows Command Injection. This vulnerability is …

Mar 23, 2024
CVE-2024-2832
3.5 LOW

A vulnerability classified as problematic was found in Campcodes Online Shopping System 1.0. This vulnerability affects unknown code of the file /offersmail.php. The manipulation of …

Mar 23, 2024
CVE-2024-2326
4.3 MEDIUM

The Pretty Links – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions …

Mar 23, 2024
CVE-2024-1049
6.4 MEDIUM

The Page Builder Gutenberg Blocks – CoBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Icon Widget's in all versions up …

Mar 23, 2024
CVE-2024-2688
5.4 MEDIUM

The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress …

Mar 23, 2024
CVE-2024-2468
6.4 MEDIUM

The EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor plugin for WordPress …

Mar 23, 2024
CVE-2024-2202
6.4 MEDIUM

The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the legacy Image widget in all versions up to, and …

Mar 23, 2024
CVE-2024-2131
6.4 MEDIUM

The Move Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's infobox and button widget in all versions up …

Mar 23, 2024
CVE-2024-2025
8.8 HIGH

The "BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages" plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and …

Mar 23, 2024
CVE-2024-1697
6.4 MEDIUM

The Custom WooCommerce Checkout Fields Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the save_wcfe_options function in all versions up to, and …

Mar 23, 2024
CVE-2024-29059
7.5 HIGH KEV

.NET Framework Information Disclosure Vulnerability

Mar 23, 2024
CVE-2024-29190
7.5 HIGH

Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. In version 3.9.5 Beta and …

Mar 22, 2024
CVE-2024-29057
4.3 MEDIUM

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Mar 22, 2024
CVE-2024-26247
4.7 MEDIUM

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

Mar 22, 2024
CVE-2024-2828
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in lakernote EasyAdmin up to 20240315. Affected is the function thumbnail of the file src/main/java/com/laker/admin/module/sys/controller/IndexController.java. The …

Mar 22, 2024
CVE-2024-2827
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in lakernote EasyAdmin up to 20240315. This issue affects some unknown processing of the file …

Mar 22, 2024
CVE-2024-2826
6.3 MEDIUM

A vulnerability classified as problematic was found in lakernote EasyAdmin up to 20240315. This vulnerability affects unknown code of the file /ureport/designer/saveReportFile. The manipulation leads …

Mar 22, 2024
CVE-2024-2825
6.3 MEDIUM

A vulnerability classified as critical has been found in lakernote EasyAdmin up to 20240315. This affects an unknown part of the file /ureport/designer/saveReportFile. The manipulation …

Mar 22, 2024
CVE-2023-5685
7.5 HIGH

A flaw was found in XNIO. The XNIO NotifierState that can cause a Stack Overflow Exception when the chain of notifier states becomes problematically large …

Mar 22, 2024
CVE-2024-2824
6.3 MEDIUM

A vulnerability was found in Matthias-Wandel jhead 3.08 and classified as critical. This issue affects the function PrintFormatNumber of the file exif.c. The manipulation leads …

Mar 22, 2024
CVE-2023-4063
5.3 MEDIUM

Certain HP OfficeJet Pro printers are potentially vulnerable to a Denial of Service when using an improper eSCL URL GET request.

Mar 22, 2024
CVE-2024-2823
4.3 MEDIUM

A vulnerability has been found in DedeCMS 5.7 and classified as problematic. This vulnerability affects unknown code of the file /src/dede/mda_main.php. The manipulation leads to …

Mar 22, 2024
CVE-2024-2822
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in DedeCMS 5.7. This affects an unknown part of the file /src/dede/vote_edit.php. The manipulation of the …

Mar 22, 2024
CVE-2024-29499
7.4 HIGH

Anchor CMS v0.12.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via /anchor/admin/users/delete/2.

Mar 22, 2024
CVE-2024-29385
9.0 CRITICAL

DIR-845L router <= v1.01KRb03 has an Unauthenticated remote code execution vulnerability in the cgibin binary via soapcgi_main function.

Mar 22, 2024
CVE-2024-29366
8.8 HIGH

A command injection vulnerability exists in the cgibin binary in DIR-845L router firmware <= v1.01KRb03.

Mar 22, 2024
CVE-2024-29338
2.4 LOW

Anchor CMS v0.12.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via /anchor/admin/categories/delete/2.

Mar 22, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.