CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-27096
7.7 HIGH

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An authenticated user can …

Mar 18, 2024
CVE-2024-2390
7.8 HIGH

As a part of Tenable’s vulnerability disclosure program, a vulnerability in a Nessus plugin was identified and reported. This vulnerability could allow a malicious actor …

Mar 18, 2024
CVE-2024-2229
7.8 HIGH

CWE-502: Deserialization of Untrusted Data vulnerability exists that could cause remote code execution when a malicious project file is loaded into the application by a …

Mar 18, 2024
CVE-2024-2052
7.5 HIGH

CWE-552: Files or Directories Accessible to External Parties vulnerability exists that could allow unauthenticated files and logs exfiltration and download of files when an attacker …

Mar 18, 2024
CVE-2024-2051
9.8 CRITICAL

CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could cause account takeover and unauthorized access to the system when an attacker conducts brute-force …

Mar 18, 2024
CVE-2024-2050
8.2 HIGH

CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability exists when an attacker injects then executes arbitrary malicious JavaScript code within the …

Mar 18, 2024
CVE-2024-27937
6.5 MEDIUM

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An authenticated user can …

Mar 18, 2024
CVE-2024-27930
6.5 MEDIUM

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An authenticated user can …

Mar 18, 2024
CVE-2024-20757
5.5 MEDIUM

Bridge versions 13.0.5, 14.0.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage …

Mar 18, 2024
CVE-2024-20756
7.8 HIGH

Bridge versions 13.0.5, 14.0.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the …

Mar 18, 2024
CVE-2024-20755
7.8 HIGH

Bridge versions 13.0.5, 14.0.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of …

Mar 18, 2024
CVE-2024-20752
7.8 HIGH

Bridge versions 13.0.5, 14.0.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of …

Mar 18, 2024
CVE-2024-1658
5.4 MEDIUM

The Grid Shortcodes WordPress plugin before 1.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where …

Mar 18, 2024
CVE-2024-1333
5.4 MEDIUM

The Responsive Pricing Table WordPress plugin before 5.1.11 does not validate and escape some of its Pricing Table options before outputting them back in a …

Mar 18, 2024
CVE-2024-1331
6.1 MEDIUM

The Team Members WordPress plugin before 5.3.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where …

Mar 18, 2024
CVE-2024-22257
8.2 HIGH

In Spring Security, versions 5.7.x prior to 5.7.12, 5.8.x prior to 5.8.11, versions 6.0.x prior to 6.0.9, versions 6.1.x prior to 6.1.8, versions 6.2.x prior …

Mar 18, 2024
CVE-2024-20746
7.8 HIGH

Premiere Pro versions 24.1, 23.6.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Mar 18, 2024
CVE-2024-20745
7.8 HIGH

Premiere Pro versions 24.1, 23.6.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Mar 18, 2024
CVE-2024-1753
8.6 HIGH

A flaw was found in Buildah (and subsequently Podman Build) which allows containers to mount arbitrary locations on the host filesystem into build containers. A …

Mar 18, 2024
CVE-2024-2599
9.9 CRITICAL

File upload restriction evasion vulnerability in AMSS++ version 4.31. This vulnerability could allow an authenticated user to potentially obtain RCE through webshell, compromising the entire …

Mar 18, 2024
CVE-2024-2598
7.1 HIGH

Vulnerability in AMSS++ version 4.31, which does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /amssplus/modules/book/main/select_send_2.php, in multiple parameters. This …

Mar 18, 2024
CVE-2024-2597
7.1 HIGH

Vulnerability in AMSS++ version 4.31, which does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /amssplus/modules/book/main/bookdetail_school_person.php, in the 'b_id' parameter. …

Mar 18, 2024
CVE-2024-2596
7.1 HIGH

Vulnerability in AMSS++ version 4.31, which does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /amssplus/modules/mail/main/select_send.php, in multiple parameters. This …

Mar 18, 2024
CVE-2024-2595
7.1 HIGH

Vulnerability in AMSS++ version 4.31, which does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /amssplus/modules/book/main/bookdetail_khet_person.php, in the 'b_id' parameter. …

Mar 18, 2024
CVE-2024-2594
7.1 HIGH

Vulnerability in AMSS++ version 4.31, which does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /amssplus/admin/index.php, in multiple parameters. This …

Mar 18, 2024
CVE-2024-2593
7.1 HIGH

Vulnerability in AMSS++ version 4.31, which does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /amssplus/modules/book/main/bookdetail_group.php, in the 'b_id' parameter. …

Mar 18, 2024
CVE-2024-2592
8.2 HIGH

Vulnerability in AMSS++ version 4.31 that allows SQL injection through /amssplus/modules/person/pic_show.php, in the 'person_id' parameter. This vulnerability could allow a remote attacker to send a …

Mar 18, 2024
CVE-2024-2591
8.2 HIGH

Vulnerability in AMSS++ version 4.31 that allows SQL injection through /amssplus/modules/book/main/bookdetail_group.php, in multiple parameters. This vulnerability could allow a remote attacker to send a specially …

Mar 18, 2024
CVE-2024-2590
8.2 HIGH

Vulnerability in AMSS++ version 4.31 that allows SQL injection through /amssplus/modules/mail/main/select_send.php, in the 'sd_index' parameter. This vulnerability could allow a remote attacker to send a …

Mar 18, 2024
CVE-2024-2589
8.2 HIGH

Vulnerability in AMSS++ version 4.31 that allows SQL injection through /amssplus/modules/book/main/bookdetail_school_person.php, in multiple parameters. This vulnerability could allow a remote attacker to send a specially …

Mar 18, 2024
CVE-2024-2588
8.2 HIGH

Vulnerability in AMSS++ version 4.31 that allows SQL injection through /amssplus/admin/index.php, in the 'id' parameter. This vulnerability could allow a remote attacker to send a …

Mar 18, 2024
CVE-2024-2587
8.2 HIGH

Vulnerability in AMSS++ version 4.31 that allows SQL injection through /amssplus/modules/book/main/bookdetail_khet_person.php, in multiple parameters. This vulnerability could allow a remote attacker to send a specially …

Mar 18, 2024
CVE-2024-2586
8.2 HIGH

Vulnerability in AMSS++ version 4.31 that allows SQL injection through /amssplus/index.php, in the 'username' parameter. This vulnerability could allow a remote attacker to send a …

Mar 18, 2024
CVE-2024-2585
8.2 HIGH

Vulnerability in AMSS++ version 4.31 that allows SQL injection through /amssplus/modules/book/main/select_send_2.php, in the 'sd_index' parameter. This vulnerability could allow a remote attacker to send a …

Mar 18, 2024
CVE-2024-2584
8.2 HIGH

Vulnerability in AMSS++ version 4.31 that allows SQL injection through /amssplus/modules/book/main/select_send.php, in the 'sd_index' parameter. This vulnerability could allow a remote attacker to send a …

Mar 18, 2024
CVE-2024-28547
6.5 MEDIUM

Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the firewallEn parameter of formSetFirewallCfg function.

Mar 18, 2024
CVE-2024-28537
9.8 CRITICAL

Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the page parameter of fromNatStaticSetting function.

Mar 18, 2024
CVE-2024-27774
7.5 HIGH

Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-259: Use of Hard-coded Password may allow disclosing Sensitive Information Embedded inside Device's Firmware

Mar 18, 2024
CVE-2024-27773
8.8 HIGH

Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-348: Use of Less Trusted Source may allow RCE

Mar 18, 2024
CVE-2024-27772
8.8 HIGH

Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-78: 'OS Command Injection' may allow RCE

Mar 18, 2024
CVE-2024-27771
8.8 HIGH

Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-22: 'Path Traversal' may allow RCE

Mar 18, 2024
CVE-2024-27770
8.8 HIGH

Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-23: Relative Path Traversal

Mar 18, 2024
CVE-2024-27769
8.8 HIGH

Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor may allow Taking Ownership Over Devices

Mar 18, 2024
CVE-2024-27768
9.8 CRITICAL

Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-22: 'Path Traversal' may allow RCE

Mar 18, 2024
CVE-2024-27767
10.0 CRITICAL

CWE-287: Improper Authentication may allow Authentication Bypass

Mar 18, 2024
CVE-2024-2496
5.0 MEDIUM

A NULL pointer dereference flaw was found in the udevConnectListAllInterfaces() function in libvirt. This issue can occur when detaching a host interface while at the …

Mar 18, 2024
CVE-2024-2002
7.5 HIGH

A double-free vulnerability was found in libdwarf. In a multiply-corrupted DWARF object, libdwarf may try to dealloc(free) an allocation twice, potentially causing unpredictable and various …

Mar 18, 2024
CVE-2024-28550
4.3 MEDIUM

Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the filePath parameter of formExpandDlnaFile function.

Mar 18, 2024
CVE-2023-7250
5.3 MEDIUM

A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can send less …

Mar 18, 2024
CVE-2024-20767
7.4 HIGH KEV

ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could …

Mar 18, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.