CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-2485
8.8 HIGH

A vulnerability was found in Tenda AC18 15.03.05.05 and classified as critical. Affected by this issue is the function formSetSpeedWan of the file /goform/SetSpeedWan. The …

Mar 15, 2024
CVE-2024-2483
4.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in Surya2Developer Hostel Management Service 1.0. This issue affects some unknown processing of the file …

Mar 15, 2024
CVE-2024-2482
3.7 LOW

A vulnerability has been found in Surya2Developer Hostel Management Service 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the …

Mar 15, 2024
CVE-2024-2399
6.4 MEDIUM

The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, …

Mar 15, 2024
CVE-2024-27756
8.8 HIGH

GLPI through 10.0.12 allows CSV injection by an attacker who is able to create an asset with a crafted title.

Mar 15, 2024
CVE-2024-1796
6.4 MEDIUM

The HUSKY – Products Filter for WooCommerce Professional plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'woof' shortcode in all versions …

Mar 15, 2024
CVE-2024-1795
8.8 HIGH

The HUSKY – Products Filter for WooCommerce Professional plugin for WordPress is vulnerable to SQL Injection via the 'name' parameter in the woof shortcode in …

Mar 15, 2024
CVE-2024-2481
6.5 MEDIUM

A vulnerability, which was classified as critical, was found in Surya2Developer Hostel Management System 1.0. Affected is an unknown function of the file /admin/manage-students.php. The …

Mar 15, 2024
CVE-2024-2480
6.3 MEDIUM

A vulnerability classified as critical was found in MHA Sistemas arMHAzena 9.6.0.0. This vulnerability affects unknown code of the component Executa Page. The manipulation of …

Mar 15, 2024
CVE-2024-2479
3.5 LOW

A vulnerability classified as problematic has been found in MHA Sistemas arMHAzena 9.6.0.0. This affects an unknown part of the component Cadastro Page. The manipulation …

Mar 15, 2024
CVE-2024-2478
6.3 MEDIUM

A vulnerability was found in BradWenqiang HR 2.0. It has been rated as critical. Affected by this issue is the function selectAll of the file …

Mar 15, 2024
CVE-2024-25227
9.8 CRITICAL

SQL Injection vulnerability in ABO.CMS version 5.8, allows remote attackers to execute arbitrary code, cause a denial of service (DoS), escalate privileges, and obtain sensitive …

Mar 15, 2024
CVE-2024-2204
5.5 MEDIUM

Zemana AntiLogger v2.74.204.664 is vulnerable to a Denial of Service (DoS) vulnerability by triggering the 0x80002004 and 0x80002010 IOCTL codes of the zam64.sys and zamguard64.sys …

Mar 15, 2024
CVE-2024-2180
5.5 MEDIUM

Zemana AntiLogger v2.74.204.664 is vulnerable to a Memory Information Leak vulnerability by triggering the 0x80002020 IOCTL code of the zam64.sys and zamguard64.sys drivers

Mar 15, 2024
CVE-2024-26540
7.8 HIGH

A heap-based buffer overflow in Clmg before 3.3.3 can occur via a crafted file to cimg_library::CImg<unsigned char>::_load_analyze.

Mar 15, 2024
CVE-2024-26454
5.4 MEDIUM

A Cross Site Scripting vulnerability in Healthcare-Chatbot through 9b7058a can occur via a crafted payload to the email1 or pwd1 parameter in login.php.

Mar 15, 2024
CVE-2024-1917
9.8 CRITICAL

Integer Overflow or Wraparound vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remote unauthenticated attacker to execute malicious code …

Mar 15, 2024
CVE-2024-1916
9.8 CRITICAL

Integer Overflow or Wraparound vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remote unauthenticated attacker to execute malicious code …

Mar 15, 2024
CVE-2024-1915
9.8 CRITICAL

Incorrect Pointer Scaling vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remote unauthenticated attacker to execute malicious code on …

Mar 15, 2024
CVE-2024-0803
9.8 CRITICAL

Integer Overflow or Wraparound vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remote unauthenticated attacker to execute malicious code …

Mar 15, 2024
CVE-2024-0802
9.8 CRITICAL

Incorrect Pointer Scaling vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remote unauthenticated attacker to read arbitrary information from …

Mar 15, 2024
CVE-2024-26246
3.9 LOW

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

Mar 14, 2024
CVE-2024-26163
4.7 MEDIUM

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

Mar 14, 2024
CVE-2024-1853
5.5 MEDIUM

Zemana AntiLogger v2.74.204.664 is vulnerable to an Arbitrary Process Termination vulnerability by triggering the 0x80002048 IOCTL code of the zam64.sys and zamguard64.sys drivers.

Mar 14, 2024
CVE-2024-2249
6.4 MEDIUM

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the LinkWrapper attribute found in several widgets in all …

Mar 14, 2024
CVE-2024-26503
9.1 CRITICAL

Unrestricted File Upload vulnerability in Greek Universities Network Open eClass v.3.15 and earlier allows attackers to run arbitrary code via upload of crafted file to …

Mar 14, 2024
CVE-2024-26475
5.5 MEDIUM

An issue in radareorg radare2 v.0.9.7 through v.5.8.6 and fixed in v.5.8.8 allows a local attacker to cause a denial of service via the grub_sfs_read_extent …

Mar 14, 2024
CVE-2023-50677
8.8 HIGH

An issue in NETGEAR-DGND4000 v.1.1.00.15_1.00.15 allows a remote attacker to escalate privileges via the next_file parameter to the /setup.cgi component.

Mar 14, 2024
CVE-2023-42286
9.8 CRITICAL

There is a PHP file inclusion vulnerability in the template configuration of eyoucms v1.6.4, allowing attackers to execute code or system commands through a carefully …

Mar 14, 2024
CVE-2024-2256
6.4 MEDIUM

The oik plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes such as bw_contact_button and bw_button shortcodes in all versions up …

Mar 14, 2024
CVE-2024-1713
7.2 HIGH

A user who can create objects in a database with plv8 3.2.1 installed is able to cause deferred triggers to execute as the Superuser during …

Mar 14, 2024
CVE-2024-0860
8.0 HIGH

The affected product is vulnerable to a cleartext transmission of sensitive information vulnerability, which may allow an attacker to capture packets to craft their own …

Mar 14, 2024
CVE-2024-28425
7.5 HIGH

greykite v1.0.0 was discovered to contain an arbitrary file upload vulnerability in the load_obj function at /templates/pickle_utils.py. This vulnerability allows attackers to execute arbitrary code …

Mar 14, 2024
CVE-2024-28424
8.8 HIGH

zenml v0.55.4 was discovered to contain an arbitrary file upload vulnerability in the load function at /materializers/cloudpickle_materializer.py. This vulnerability allows attackers to execute arbitrary code …

Mar 14, 2024
CVE-2024-28423
9.8 CRITICAL

Airflow-Diagrams v2.1.0 was discovered to contain an arbitrary file upload vulnerability in the unsafe_load function at cli.py. This vulnerability allows attackers to execute arbitrary code …

Mar 14, 2024
CVE-2024-27301
7.3 HIGH

Support App is an opensource application specialized in managing Apple devices. It's possible to abuse a vulnerability inside the postinstall installer script to make the …

Mar 14, 2024
CVE-2024-27266
8.2 HIGH

IBM Maximo Application Suite 7.6.1.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this …

Mar 14, 2024
CVE-2024-27265
4.5 MEDIUM

IBM Integration Bus for z/OS 10.1 through 10.1.0.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions …

Mar 14, 2024
CVE-2024-24770
5.3 MEDIUM

vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Learning and Multi-Party Computation. Much like GHSA-45gq-q4xh-cp53, it …

Mar 14, 2024
CVE-2024-24562
5.4 MEDIUM

vantage6-UI is the official user interface for the vantage6 server. In affected versions a number of security headers are not set. This issue has been …

Mar 14, 2024
CVE-2024-23823
4.2 MEDIUM

vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Learning and Multi-Party Computation. The vantage6 server has …

Mar 14, 2024
CVE-2024-22346
8.4 HIGH

Db2 for IBM i 7.2, 7.3, 7.4, and 7.5 infrastructure could allow a local user to gain elevated privileges due to an unqualified library call. …

Mar 14, 2024
CVE-2023-42938
7.8 HIGH

A logic issue was addressed with improved checks. This issue is fixed in iTunes 12.13.1 for Windows. A local attacker may be able to elevate …

Mar 14, 2024
CVE-2024-28181
8.1 HIGH

turbo_boost-commands is a set of commands to help you build robust reactive applications with Rails & Hotwire. TurboBoost Commands has existing protections in place to …

Mar 14, 2024
CVE-2024-28849
6.5 MEDIUM

follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects. In affected versions follow-redirects only clears authorization header …

Mar 14, 2024
CVE-2023-43490
5.3 MEDIUM

Incorrect calculation in microcode keying mechanism for some Intel(R) Xeon(R) D Processors with Intel(R) SGX may allow a privileged user to potentially enable information disclosure …

Mar 14, 2024
CVE-2023-39368
6.5 MEDIUM

Protection mechanism failure of bus lock regulator for some Intel(R) Processors may allow an unauthenticated user to potentially enable denial of service via network access.

Mar 14, 2024
CVE-2023-38575
5.5 MEDIUM

Non-transparent sharing of return predictor targets between contexts in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.

Mar 14, 2024
CVE-2023-35191
6.8 MEDIUM

Uncontrolled resource consumption for some Intel(R) SPS firmware versions may allow a privileged user to potentially enable denial of service via network access.

Mar 14, 2024
CVE-2023-32666
7.2 HIGH

On-chip debug and test interface with improper access control in some 4th Generation Intel(R) Xeon(R) Processors when using Intel(R) SGX or Intel(R) TDX may allow …

Mar 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.