CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-24334
8.0 HIGH

A stack overflow vulnerability in Tenda AC23 with firmware version US_AC23V1.0re_V16.03.07.45_cn_TDC01 allows attackers to run arbitrary commands via schedStartTime parameter.

Feb 21, 2024
CVE-2023-24333
8.8 HIGH

A stack overflow vulnerability in Tenda AC21 with firmware version US_AC21V1.0re_V16.03.08.15_cn_TDC01 allows attackers to run arbitrary commands via crafted POST request to /goform/openSchedWifi.

Feb 21, 2024
CVE-2023-24332
8.1 HIGH

A stack overflow vulnerability in Tenda AC6 with firmware version US_AC6V5.0re_V03.03.02.01_cn_TDC01 allows attackers to run arbitrary commands via crafted POST request to /goform/PowerSaveSet.

Feb 21, 2024
CVE-2023-24331
9.8 CRITICAL

Command Injection vulnerability in D-Link Dir 816 with firmware version DIR-816_A2_v1.10CNB04 allows attackers to run arbitrary commands via the urlAdd parameter.

Feb 21, 2024
CVE-2023-24330
8.8 HIGH

Command Injection vulnerability in D-Link Dir 882 with firmware version DIR882A1_FW130B06 allows attackers to run arbitrary commands via crafted POST request to /HNAP1/.

Feb 21, 2024
CVE-2024-26311
5.7 MEDIUM

Archer Platform 6.x before 6.14 P2 HF1 (6.14.0.2.1) contains a reflected XSS vulnerability. A remote authenticated malicious Archer user could potentially exploit this by tricking …

Feb 21, 2024
CVE-2024-26310
4.3 MEDIUM

Archer Platform 6.8 before 6.14 P2 (6.14.0.2) contains an improper access control vulnerability. A remote authenticated malicious user could potentially exploit this to gain access …

Feb 21, 2024
CVE-2024-25461
7.5 HIGH

Directory Traversal vulnerability in Terrasoft, Creatio Terrasoft CRM v.7.18.4.1532 allows a remote attacker to obtain sensitive information via a crafted request to the terrasoft.axd component.

Feb 21, 2024
CVE-2024-25249
9.8 CRITICAL

An issue in He3 App for macOS version 2.0.17, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings.

Feb 21, 2024
CVE-2023-6640
6.5 MEDIUM

Malformed S2 Nonce Get Command Class packets can be sent to crash PC Controller v5.54.0 and earlier.

Feb 21, 2024
CVE-2023-6533
6.5 MEDIUM

Malformed Device Reset Locally Command Class packets can be sent to the controller, causing the controller to assume the end device has left the network. …

Feb 21, 2024
CVE-2024-25381
6.1 MEDIUM

There is a Stored XSS Vulnerability in Emlog Pro 2.2.8 Article Publishing, due to non-filtering of quoted content.

Feb 21, 2024
CVE-2024-24479
7.5 HIGH

A Buffer Overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the wsutil/to_str.c, and format_fractional_part_nsecs components. NOTE: this …

Feb 21, 2024
CVE-2024-24476
7.5 HIGH

A buffer overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the pan/addr_resolv.c, and ws_manuf_lookup_str(), size components. NOTE: …

Feb 21, 2024
CVE-2024-22473
6.8 MEDIUM

TRNG is used before initialization by ECDSA signing driver when exiting EM2/EM3 on Virtual Secure Vault (VSE) devices. This defect may allow Signature Spoofing by …

Feb 21, 2024
CVE-2024-1707
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in GARO WALLBOX GLB+ T2EV7 0.5. This affects an unknown part of the file /index.jsp#settings of …

Feb 21, 2024
CVE-2023-50975
8.4 HIGH

The TD Bank TD Advanced Dashboard client through 3.0.3 for macOS allows arbitrary code execution because of the lack of electron::fuses::IsRunAsNodeEnabled (i.e., ELECTRON_RUN_AS_NODE can be …

Feb 21, 2024
CVE-2024-26145
6.5 MEDIUM

Discourse Calendar adds the ability to create a dynamic calendar in the first post of a topic on Discourse. Uninvited users are able to gain …

Feb 21, 2024
CVE-2024-25898
6.1 MEDIUM

A XSS vulnerability was found in the ChurchCRM v.5.5.0 functionality, edit your event, where malicious JS or HTML code can be inserted in the Event …

Feb 21, 2024
CVE-2024-25897
9.8 CRITICAL

ChurchCRM 5.5.0 FRCatalog.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET parameter.

Feb 21, 2024
CVE-2024-25896
5.3 MEDIUM

ChurchCRM 5.5.0 EventEditor.php is vulnerable to Blind SQL Injection (Time-based) via the EID POST parameter.

Feb 21, 2024
CVE-2024-25895
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in ChurchCRM 5.5.0 allows remote attackers to inject arbitrary web script or HTML via the type parameter of /EventAttendance.php

Feb 21, 2024
CVE-2024-25894
9.8 CRITICAL

ChurchCRM 5.5.0 /EventEditor.php is vulnerable to Blind SQL Injection (Time-based) via the EventCount POST parameter.

Feb 21, 2024
CVE-2024-25893
9.1 CRITICAL

ChurchCRM 5.5.0 FRCertificates.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET parameter.

Feb 21, 2024
CVE-2024-25892
8.1 HIGH

ChurchCRM 5.5.0 ConfirmReport.php is vulnerable to Blind SQL Injection (Time-based) via the familyId GET parameter.

Feb 21, 2024
CVE-2024-25891
7.5 HIGH

ChurchCRM 5.5.0 FRBidSheets.php is vulnerable to Blind SQL Injection (Time-based) via the CurrentFundraiser GET parameter.

Feb 21, 2024
CVE-2024-1706
3.5 LOW

A vulnerability was determined in ZKTeco ZKBio Access IVS up to 3.3.2. This impacts an unknown function of the component Department Name Search Bar. This …

Feb 21, 2024
CVE-2024-1705
5.6 MEDIUM

A vulnerability was found in Shopwind up to 4.6. It has been rated as critical. This issue affects the function actionCreate of the file /public/install/controllers/DefaultController.php …

Feb 21, 2024
CVE-2024-1704
5.5 MEDIUM

A vulnerability was found in ZhongBangKeJi CRMEB 5.2.2. It has been declared as critical. This vulnerability affects the function save/delete of the file /adminapi/system/crud. The …

Feb 21, 2024
CVE-2024-1212
10.0 CRITICAL KEV

Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.

Feb 21, 2024
CVE-2024-26138
5.3 MEDIUM

The XWiki licensor application, which manages and enforce application licenses for paid extensions, includes the document `Licenses.Code.LicenseJSON` that provides information for admins regarding active licenses. …

Feb 21, 2024
CVE-2024-26133
5.5 MEDIUM

EventStoreDB (ESDB) is an operational database built to store events. A vulnerability has been identified in the projections subsystem in versions 20 prior to 20.10.6, …

Feb 21, 2024
CVE-2024-26130
7.5 HIGH

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Starting in version 38.0.0 and prior to version 42.0.4, if `pkcs12.serialize_key_and_certificates` …

Feb 21, 2024
CVE-2024-25288
4.9 MEDIUM

SLIMS (Senayan Library Management Systems) 9 Bulian v9.6.1 is vulnerable to SQL Injection via pop-scope-vocabolary.php.

Feb 21, 2024
CVE-2024-25117
6.8 MEDIUM

php-svg-lib is a scalable vector graphics (SVG) file parsing/rendering library. Prior to version 0.5.2, php-svg-lib fails to validate that font-family doesn't contain a PHAR url, …

Feb 21, 2024
CVE-2024-24478
7.5 HIGH

An issue in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the packet-bgp.c, dissect_bgp_open(tvbuff_t*tvb, proto_tree*tree, packet_info*pinfo), optlen components. NOTE: …

Feb 21, 2024
CVE-2024-23346
9.3 CRITICAL

Pymatgen (Python Materials Genomics) is an open-source Python library for materials analysis. A critical security vulnerability exists in the `JonesFaithfulTransformation.from_transformation_str()` method within the `pymatgen` library …

Feb 21, 2024
CVE-2024-20325
5.1 MEDIUM

A vulnerability in the Live Data server of Cisco Unified Intelligence Center could allow an unauthenticated, local attacker to read and modify data in a …

Feb 21, 2024
CVE-2024-1714
7.1 HIGH

An issue exists in all supported versions of IdentityIQ Lifecycle Manager that can result if an entitlement with a value containing leading or trailing whitespace …

Feb 21, 2024
CVE-2024-1703
3.5 LOW

A vulnerability was found in ZhongBangKeJi CRMEB 5.2.2. It has been classified as problematic. This affects the function openfile of the file /adminapi/system/file/openfile. The manipulation …

Feb 21, 2024
CVE-2024-1702
6.3 MEDIUM

A vulnerability was found in keerti1924 PHP-MYSQL-User-Login-System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /edit.php. The …

Feb 21, 2024
CVE-2024-27215

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-1709. Reason: This candidate is a duplicate of CVE-2024-1709. Notes: All CVE users should reference CVE-2024-1709 …

Feb 21, 2024
CVE-2024-22220
6.3 MEDIUM

An issue was discovered in Terminalfour 7.4 through 7.4.0004 QP3 and 8 through 8.3.19, and Formbank through 2.1.10-FINAL. Unauthenticated Stored Cross-Site Scripting can occur, with …

Feb 21, 2024
CVE-2024-1709
10.0 CRITICAL KEV

ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access …

Feb 21, 2024
CVE-2024-1708
8.4 HIGH KEV

ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote code or directly impact confidential …

Feb 21, 2024
CVE-2024-1701
5.3 MEDIUM

A vulnerability has been found in keerti1924 PHP-MYSQL-User-Login-System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /edit.php. …

Feb 21, 2024
CVE-2024-1700
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in keerti1924 PHP-MYSQL-User-Login-System 1.0. Affected is an unknown function of the file /signup.php. The manipulation of …

Feb 21, 2024
CVE-2024-1474
7.5 HIGH

In WS_FTP Server versions before 8.8.5, reflected cross-site scripting issues have been identified on various user supplied inputs on the WS_FTP Server administrative interface.

Feb 21, 2024
CVE-2023-49100
4.4 MEDIUM

Trusted Firmware-A (TF-A) before 2.10 has a potential read out-of-bounds in the SDEI service. The input parameter passed in register x1 is not validated well …

Feb 21, 2024
CVE-2023-46241
9.0 CRITICAL

`discourse-microsoft-auth` is a plugin that enables authentication via Microsoft. On sites with the `discourse-microsoft-auth` plugin enabled, an attack can potentially take control of a victim's …

Feb 21, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.