CVE Database

38893+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-50399
7.2 HIGH

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers …

Nov 22, 2024
CVE-2024-50398
7.2 HIGH

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers …

Nov 22, 2024
CVE-2024-50397
8.8 HIGH

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers …

Nov 22, 2024
CVE-2024-50396
8.8 HIGH

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers …

Nov 22, 2024
CVE-2024-50395
8.8 HIGH

An authorization bypass through user-controlled key vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow local network attackers to …

Nov 22, 2024
CVE-2024-48861
7.8 HIGH

An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow local network attackers to execute commands. …

Nov 22, 2024
CVE-2024-38647
7.5 HIGH

An exposure of sensitive information vulnerability has been reported to affect QNAP AI Core. If exploited, the vulnerability could allow remote attackers to compromise the …

Nov 22, 2024
CVE-2024-38644
8.8 HIGH

An OS command injection vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote authenticated attackers to execute commands. …

Nov 22, 2024
CVE-2024-37044
7.2 HIGH

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow …

Nov 22, 2024
CVE-2024-37041
7.2 HIGH

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow …

Nov 22, 2024
CVE-2023-24467
8.8 HIGH

Possible Command Injection in iManager GET parameter has been discovered in OpenText™ iManager 3.2.6.0000.

Nov 22, 2024
CVE-2023-24466
7.5 HIGH

Possible XML External Entity Injection in iManager GET parameter has been discovered in OpenText™ iManager 3.2.6.0200.

Nov 22, 2024
CVE-2022-26324
7.6 HIGH

Possible XSS in iManager URL for access Component has been discovered in OpenText™ iManager 3.2.6.0000.

Nov 22, 2024
CVE-2021-38135
8.6 HIGH

Possible External Service Interaction attack in iManager has been discovered in OpenText™ iManager 3.2.6.0000.

Nov 22, 2024
CVE-2021-38117
8.8 HIGH

Possible Command injection Vulnerability in iManager has been discovered in OpenText™ iManager 3.2.4.0000.

Nov 22, 2024
CVE-2021-38116
8.8 HIGH

Possible Elevation of Privilege Vulnerability in iManager has been discovered in OpenText™ iManager. This impacts all versions before 3.2.5

Nov 22, 2024
CVE-2024-7837
8.2 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Firmanet Software ERP allows SQL Injection.This issue affects ERP: through 22.11.2024. …

Nov 22, 2024
CVE-2024-11601
8.1 HIGH

The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart, Blog, Video Gallery) plugin for WordPress is …

Nov 22, 2024
CVE-2024-11104
8.1 HIGH

The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart, Blogs) plugin for WordPress is vulnerable to …

Nov 22, 2024
CVE-2024-31408
8.0 HIGH

OS command injection vulnerability exists in AIPHONE IX SYSTEM and IXG SYSTEM. A network-adjacent authenticated attacker may execute an arbitrary OS command with root privileges …

Nov 22, 2024
CVE-2024-52052
7.2 HIGH

Wowza Streaming Engine below 4.9.1 permits an authenticated Streaming Engine Manager administrator to define a custom application property and poison a stream target for high-privilege …

Nov 21, 2024
CVE-2024-51364
8.8 HIGH

An arbitrary file upload vulnerability in ModbusMechanic v3.0 allows attackers to execute arbitrary code via uploading a crafted .xml file.

Nov 21, 2024
CVE-2024-53095
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: smb: client: Fix use-after-free of network namespace. Recently, we got a customer report that CIFS …

Nov 21, 2024
CVE-2024-53432
7.5 HIGH

While parsing certain malformed PLY files, PCL version 1.14.1 crashes due to an uncaught std::out_of_range exception in PCLPointCloud2::at. This issue could potentially be exploited to …

Nov 21, 2024
CVE-2024-53335
7.8 HIGH

TOTOLINK A810R V4.1.2cu.5182_B20201026 is vulnerable to Buffer Overflow in downloadFlile.cgi.

Nov 21, 2024
CVE-2024-53334
8.8 HIGH

TOTOLINK A810R V4.1.2cu.5182_B20201026 is vulnerable to Buffer Overflow in infostat.cgi.

Nov 21, 2024
CVE-2024-52287
7.2 HIGH

authentik is an open-source identity provider. When using the client_credentials or device_code OAuth grants, it was possible for an attacker to get a token from …

Nov 21, 2024
CVE-2024-48288
8.0 HIGH

TP-Link TL-IPC42C V4.0_20211227_1.0.16 is vulnerable to command injection due to the lack of malicious code verification on both the frontend and backend.

Nov 21, 2024
CVE-2024-48286
8.0 HIGH

Linksys E3000 1.0.06.002_US is vulnerable to command injection via the diag_ping_start function.

Nov 21, 2024
CVE-2024-52803
7.5 HIGH

LLama Factory enables fine-tuning of large language models. A critical remote OS command injection vulnerability has been identified in the LLama Factory training process. This …

Nov 21, 2024
CVE-2024-52799
8.2 HIGH

Argo Workflows Chart is used to set up argo and its needed dependencies through one command. Prior to 0.44.0, the workflow-role has excessive privileges, the …

Nov 21, 2024
CVE-2024-53429
7.5 HIGH

Open62541 v1.4.6 is has an assertion failure in fuzz_binary_decode, which leads to a crash.

Nov 21, 2024
CVE-2024-28027
7.2 HIGH

Three OS command injection vulnerabilities exist in the web interface I/O configuration functionality of MC Technologies MC LR Router 2.10.5. A specially crafted HTTP request …

Nov 21, 2024
CVE-2024-28026
7.2 HIGH

Three OS command injection vulnerabilities exist in the web interface I/O configuration functionality of MC Technologies MC LR Router 2.10.5. A specially crafted HTTP request …

Nov 21, 2024
CVE-2024-28025
7.2 HIGH

Three OS command injection vulnerabilities exist in the web interface I/O configuration functionality of MC Technologies MC LR Router 2.10.5. A specially crafted HTTP request …

Nov 21, 2024
CVE-2024-21786
7.2 HIGH

An OS command injection vulnerability exists in the web interface configuration upload functionality of MC Technologies MC LR Router 2.10.5. A specially crafted HTTP request …

Nov 21, 2024
CVE-2024-11592
7.3 HIGH

A vulnerability has been found in 1000 Projects Beauty Parlour Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file …

Nov 21, 2024
CVE-2024-7026
7.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Teknogis Informatics Closed Circuit Vehicle Tracking Software allows SQL Injection, Blind …

Nov 21, 2024
CVE-2024-11591
7.3 HIGH

A vulnerability, which was classified as critical, was found in 1000 Projects Beauty Parlour Management System 1.0. This affects an unknown part of the file …

Nov 21, 2024
CVE-2024-11590
7.3 HIGH

A vulnerability, which was classified as critical, has been found in 1000 Projects Bookstore Management System 1.0. Affected by this issue is some unknown functionality …

Nov 21, 2024
CVE-2024-7517
7.8 HIGH

A command injection vulnerability in Brocade Fabric OS before 9.2.0c, and 9.2.1 through 9.2.1a on IP extension platforms could allow a local authenticated attacker to …

Nov 21, 2024
CVE-2024-11596
7.8 HIGH

ECMP dissector crash in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture file

Nov 21, 2024
CVE-2024-11595
7.8 HIGH

FiveCo RAP dissector infinite loop in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture file

Nov 21, 2024
CVE-2024-11409
7.2 HIGH

The Grid View Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0 via deserialization of untrusted …

Nov 21, 2024
CVE-2024-10898
8.8 HIGH

The Contact Form 7 Email Add on plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.9 via …

Nov 21, 2024
CVE-2024-10788
7.2 HIGH

The Activity Log – Monitor & Record User Changes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the event parameters in all versions …

Nov 21, 2024
CVE-2024-10403
7.5 HIGH

Brocade Fabric OS versions before 8.2.3e2, versions 9.0.0 through 9.2.0c, and 9.2.1 through 9.2.1a can capture the SFTP/FTP server password used for a firmware download …

Nov 21, 2024
CVE-2024-10400
7.5 HIGH

The Tutor LMS plugin for WordPress is vulnerable to SQL Injection via the ‘rating_filter’ parameter in all versions up to, and including, 2.7.6 due to …

Nov 21, 2024
CVE-2024-9875
7.1 HIGH

Okta Privileged Access server agent (SFTD) versions 1.82.0 to 1.84.0 are affected by a privilege escalation vulnerability when the sudo command bundles feature is enabled. …

Nov 21, 2024
CVE-2024-52581
7.5 HIGH

Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 2.13.0, the multipart form parser shipped with litestar expects the entire request body …

Nov 20, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.