CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-23624
9.6 CRITICAL

A command injection vulnerability exists in the gena.cgi module of D-Link DAP-1650 devices. An unauthenticated attacker can exploit this vulnerability to gain command execution on …

Jan 26, 2024
CVE-2024-23622
10.0 CRITICAL

A stack-based buffer overflow exists in IBM Merge Healthcare eFilm Workstation license server. A remote, unauthenticated attacker can exploit this vulnerability to achieve remote code …

Jan 26, 2024
CVE-2024-23621
10.0 CRITICAL

A buffer overflow exists in IBM Merge Healthcare eFilm Workstation license server. A remote, unauthenticated attacker can exploit this vulnerability to achieve remote code execution.

Jan 26, 2024
CVE-2024-23620
8.8 HIGH

An improper privilege management vulnerability exists in IBM Merge Healthcare eFilm Workstation. A local, authenticated attacker can exploit this vulnerability to escalate privileges to SYSTEM.

Jan 26, 2024
CVE-2024-23619
9.8 CRITICAL

A hardcoded credential vulnerability exists in IBM Merge Healthcare eFilm Workstation. A remote, unauthenticated attacker can exploit this vulnerability to achieve information disclosure or remote …

Jan 26, 2024
CVE-2024-23618
9.6 CRITICAL

An arbitrary code execution vulnerability exists in Arris SURFboard SGB6950AC2 devices. An unauthenticated attacker can exploit this vulnerability to achieve code execution as root.

Jan 26, 2024
CVE-2024-23617
9.6 CRITICAL

A buffer overflow vulnerability exists in Symantec Data Loss Prevention version 14.0.2 and before. A remote, unauthenticated attacker can exploit this vulnerability by enticing a …

Jan 26, 2024
CVE-2024-23616
10.0 CRITICAL

A buffer overflow vulnerability exists in Symantec Server Management Suite version 7.9 and before. A remote, anonymous attacker can exploit this vulnerability to achieve remote …

Jan 26, 2024
CVE-2024-23615
10.0 CRITICAL

A buffer overflow vulnerability exists in Symantec Messaging Gateway versions 10.5 and before. A remote, anonymous attacker can exploit this vulnerability to achieve remote code …

Jan 26, 2024
CVE-2024-23614
10.0 CRITICAL

A buffer overflow vulnerability exists in Symantec Messaging Gateway versions 9.5 and before. A remote, anonymous attacker can exploit this vulnerability to achieve remote code …

Jan 26, 2024
CVE-2024-23613
10.0 CRITICAL

A buffer overflow vulnerability exists in Symantec Deployment Solution version 7.9 when parsing UpdateComputer tokens. A remote, anonymous attacker can exploit this vulnerability to achieve …

Jan 26, 2024
CVE-2024-21620
8.8 HIGH

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in J-Web of Juniper Networks Junos OS on SRX Series and EX Series …

Jan 25, 2024
CVE-2024-21619
5.3 MEDIUM

A Missing Authentication for Critical Function vulnerability combined with a Generation of Error Message Containing Sensitive Information vulnerability in J-Web of Juniper Networks Junos OS …

Jan 25, 2024
CVE-2024-0891
3.5 LOW

A vulnerability was found in hongmaple octopus 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation of …

Jan 25, 2024
CVE-2024-0890
6.3 MEDIUM

A vulnerability was found in hongmaple octopus 1.0. It has been classified as critical. Affected is an unknown function of the file /system/dept/edit. The manipulation …

Jan 25, 2024
CVE-2024-0889
5.3 MEDIUM

A vulnerability was found in Kmint21 Golden FTP Server 2.02b and classified as problematic. This issue affects some unknown processing of the component PASV Command …

Jan 25, 2024
CVE-2024-23055
6.1 MEDIUM

An issue in Plone Docker Official Image 5.2.13 (5221) open-source software allows for remote code execution via improper validation of input by the HOST headers.

Jan 25, 2024
CVE-2024-22922
9.8 CRITICAL

An issue in Projectworlds Vistor Management Systemin PHP v.1.0 allows a remtoe attacker to escalate privileges via a crafted script to the login page in …

Jan 25, 2024
CVE-2024-0888
5.3 MEDIUM

A vulnerability, which was classified as problematic, was found in BORGChat 1.0.0 Build 438. This affects an unknown part of the component Service Port 7551. …

Jan 25, 2024
CVE-2024-0887
5.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in Mafiatic Blue Server 1.1. Affected by this issue is some unknown functionality of the …

Jan 25, 2024
CVE-2024-0886
3.3 LOW

A vulnerability classified as problematic was found in Poikosoft EZ CD Audio Converter 8.0.7. Affected by this vulnerability is an unknown functionality of the component …

Jan 25, 2024
CVE-2023-51833
8.1 HIGH

A command injection issue in TRENDnet TEW-411BRPplus v.2.07_eu that allows a local attacker to execute arbitrary code via the data1 parameter in the debug.cgi page.

Jan 25, 2024
CVE-2024-24399
7.2 HIGH

An arbitrary file upload vulnerability in LEPTON v7.0.0 allows authenticated attackers to execute arbitrary PHP code by uploading this code to the backend/languages/index.php languages area.

Jan 25, 2024
CVE-2024-22639
6.1 MEDIUM

iGalerie v3.0.22 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Titre (Title) field in the editing interface.

Jan 25, 2024
CVE-2024-22638
9.8 CRITICAL

liveSite v2019.1 was discovered to contain a remote code execution (RCE) vulenrabiity via the component /livesite/edit_designer_region.php or /livesite/add_email_campaign.php.

Jan 25, 2024
CVE-2024-22637
6.1 MEDIUM

Form Tools v3.1.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /form_builder/preview.php?form_id=2.

Jan 25, 2024
CVE-2024-22636
8.8 HIGH

PluXml Blog v5.8.9 was discovered to contain a remote code execution (RCE) vulnerability in the Static Pages feature. This vulnerability is exploited via injecting a …

Jan 25, 2024
CVE-2024-22635
6.1 MEDIUM

WebCalendar v1.3.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /WebCalendarvqsmnseug2/edit_entry.php.

Jan 25, 2024
CVE-2024-0885
5.3 MEDIUM

A vulnerability classified as problematic has been found in SpyCamLizard 1.230. Affected is an unknown function of the component HTTP GET Request Handler. The manipulation …

Jan 25, 2024
CVE-2024-0884
4.7 MEDIUM

A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been rated as critical. This issue affects the function exec …

Jan 25, 2024
CVE-2023-52251
8.8 HIGH

An issue discovered in provectus kafka-ui 0.4.0 through 0.7.1 allows remote attackers to execute arbitrary code via the q parameter of /api/clusters/local/topics/{topic}/messages.

Jan 25, 2024
CVE-2023-52046
4.8 MEDIUM

Cross Site Scripting vulnerability (XSS) in webmin v.2.105 and earlier allows a remote attacker to execute arbitrary code via a crafted payload to the "Execute …

Jan 25, 2024
CVE-2024-23817
7.1 HIGH

Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. Version 18.0.4 has a HTML Injection vulnerability in the Home page …

Jan 25, 2024
CVE-2024-23656
7.5 HIGH

Dex is an identity service that uses OpenID Connect to drive authentication for other apps. Dex 2.37.0 serves HTTPS with insecure TLS 1.0 and TLS …

Jan 25, 2024
CVE-2024-23655
7.5 HIGH

Tuta is an encrypted email service. Starting in version 3.118.12 and prior to version 3.119.10, an attacker is able to send a manipulated email so …

Jan 25, 2024
CVE-2024-21630
4.3 MEDIUM

Zulip is an open-source team collaboration tool. A vulnerability in version 8.0 is similar to CVE-2023-32677, but applies to multi-use invitations, not single-use invitation links …

Jan 25, 2024
CVE-2023-52356
7.5 HIGH

A segment fault (SEGV) flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFReadRGBATileExt() API. This flaw …

Jan 25, 2024
CVE-2023-52355
7.5 HIGH

An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a …

Jan 25, 2024
CVE-2023-41474
6.5 MEDIUM

Directory Traversal vulnerability in Ivanti Avalanche 6.3.4.153 allows a remote authenticated attacker to obtain sensitive information via the javax.faces.resource component.

Jan 25, 2024
CVE-2024-0883
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been declared as critical. This vulnerability affects the function prepare …

Jan 25, 2024
CVE-2024-0882
4.3 MEDIUM

A vulnerability was found in qwdigital LinkWechat 5.1.0. It has been classified as problematic. This affects an unknown part of the file /linkwechat-api/common/download/resource of the …

Jan 25, 2024
CVE-2023-7227
9.8 CRITICAL

SystemK NVR 504/508/516 versions 2.3.5SK.30084998 and prior are vulnerable to a command injection vulnerability in the dynamic domain name system (DDNS) settings that could allow …

Jan 25, 2024
CVE-2023-6267
8.6 HIGH

A flaw was found in the json payload. If annotation based security is used to secure a REST resource, the JSON body that the resource …

Jan 25, 2024
CVE-2024-0880
4.3 MEDIUM

A vulnerability was found in Qidianbang qdbcrm 1.1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /user/edit?id=2 of …

Jan 25, 2024
CVE-2024-22749
7.8 HIGH

GPAC v2.3 was detected to contain a buffer overflow via the function gf_isom_new_generic_sample_description function in the isomedia/isom_write.c:4577

Jan 25, 2024
CVE-2024-22529
9.8 CRITICAL

TOTOLINK X2000R_V2 V2.0.0-B20230727.10434 has a command injection vulnerability in the sub_449040 (handle function of formUploadFile) of /bin/boa.

Jan 25, 2024
CVE-2024-0822
7.5 HIGH

An authentication bypass vulnerability was found in overt-engine. This flaw allows the creation of users in the system without authentication due to a flaw in …

Jan 25, 2024
CVE-2023-52076
8.5 HIGH

Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A path traversal and arbitrary file write vulnerability exists in …

Jan 25, 2024
CVE-2023-40547
8.3 HIGH

A remote code execution vulnerability was found in Shim. The Shim boot support trusts attacker-controlled values when parsing an HTTP response. This flaw allows an …

Jan 25, 2024
CVE-2023-3181
7.8 HIGH

The C:\Program Files (x86)\Splashtop\Splashtop Software Updater\uninst.exe process creates a folder at C:\Windows\Temp~nsu.tmp and copies itself to it as Au_.exe. The C:\Windows\Temp~nsu.tmp\Au_.exe file is automatically launched …

Jan 25, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.