CVE Database

38893+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-51246
8.0 HIGH

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPTP function.

Nov 4, 2024
CVE-2024-50528
7.5 HIGH

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Retrieve Embedded Sensitive Data.This issue affects …

Nov 4, 2024
CVE-2024-45164
7.1 HIGH

Akamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the latest 19.2.0 patch and Apps Portal before 19.2.0.3 or 19.2.0.20240814, …

Nov 4, 2024
CVE-2024-51561
7.5 HIGH

This vulnerability exists in Aero due to improper implementation of OTP validation mechanism in certain API endpoints. An authenticated remote attacker could exploit this vulnerability …

Nov 4, 2024
CVE-2024-36485
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to SQL Injection in Technician reports option.

Nov 4, 2024
CVE-2024-48878
8.3 HIGH

Zohocorp ManageEngine ADManager Plus versions 7241 and prior are vulnerable to SQL Injection in Archived Audit Report.

Nov 4, 2024
CVE-2024-10389
7.5 HIGH

There exists a Path Traversal vulnerability in Safearchive on Platforms with Case-Insensitive Filesystems (e.g., NTFS). This allows Attackers to Write Arbitrary Files via Archive Extraction …

Nov 4, 2024
CVE-2024-38424
7.8 HIGH

Memory corruption during GNSS HAL process initialization.

Nov 4, 2024
CVE-2024-38423
7.8 HIGH

Memory corruption while processing GPU page table switch.

Nov 4, 2024
CVE-2024-38422
7.8 HIGH

Memory corruption while processing voice packet with arbitrary data received from ADSP.

Nov 4, 2024
CVE-2024-38421
7.8 HIGH

Memory corruption while processing GPU commands.

Nov 4, 2024
CVE-2024-38419
7.8 HIGH

Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node.

Nov 4, 2024
CVE-2024-38415
7.8 HIGH

Memory corruption while handling session errors from firmware.

Nov 4, 2024
CVE-2024-38410
7.8 HIGH

Memory corruption while IOCLT is called when device is in invalid state and the WMI command buffer may be freed twice.

Nov 4, 2024
CVE-2024-38409
7.8 HIGH

Memory corruption while station LL statistic handling.

Nov 4, 2024
CVE-2024-38408
8.2 HIGH

Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.

Nov 4, 2024
CVE-2024-38407
7.8 HIGH

Memory corruption while processing input parameters for any IOCTL call in the JPEG Encoder driver.

Nov 4, 2024
CVE-2024-38406
7.8 HIGH

Memory corruption while handling IOCTL calls in JPEG Encoder driver.

Nov 4, 2024
CVE-2024-38405
7.5 HIGH

Transient DOS while processing the CU information from RNR IE.

Nov 4, 2024
CVE-2024-38403
7.5 HIGH

Transient DOS while parsing BTM ML IE when per STA profile is not included.

Nov 4, 2024
CVE-2024-33068
7.5 HIGH

Transient DOS while parsing fragments of MBSSID IE from beacon frame.

Nov 4, 2024
CVE-2024-23385
7.5 HIGH

Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.

Nov 4, 2024
CVE-2024-10758
7.3 HIGH

A vulnerability, which was classified as critical, was found in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. This affects an unknown part of the file …

Nov 4, 2024
CVE-2024-20104
8.4 HIGH

In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Nov 4, 2024
CVE-2024-10752
7.3 HIGH

A vulnerability was found in Codezips Pet Shop Management System 1.0. It has been classified as critical. This affects an unknown part of the file …

Nov 4, 2024
CVE-2024-10741
7.3 HIGH

A vulnerability has been found in code-projects E-Health Care System 1.0 and classified as critical. This vulnerability affects unknown code of the file /Users/registration.php. The …

Nov 3, 2024
CVE-2024-10739
7.3 HIGH

A vulnerability, which was classified as critical, has been found in code-projects E-Health Care System 1.0. Affected by this issue is some unknown functionality of …

Nov 3, 2024
CVE-2024-10737
7.3 HIGH

A vulnerability classified as critical has been found in Codezips Free Exam Hall Seating Management System 1.0. Affected is an unknown function of the file …

Nov 3, 2024
CVE-2024-10736
7.3 HIGH

A vulnerability was found in Codezips Free Exam Hall Seating Management System 1.0. It has been rated as critical. This issue affects some unknown processing …

Nov 3, 2024
CVE-2024-10733
7.3 HIGH

A vulnerability was found in code-projects Restaurant Order System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Nov 3, 2024
CVE-2024-10702
7.3 HIGH

A vulnerability classified as critical has been found in code-projects Simple Car Rental System 1.0. Affected is an unknown function of the file /signup.php. The …

Nov 2, 2024
CVE-2024-10699
7.3 HIGH

A vulnerability was found in code-projects Wazifa System 1.0. It has been classified as critical. This affects an unknown part of the file /controllers/logincontrol.php. The …

Nov 2, 2024
CVE-2024-10698
8.8 HIGH

A vulnerability was found in Tenda AC6 15.03.05.19 and classified as critical. Affected by this issue is the function formSetDeviceName of the file /goform/SetOnlineDevName. The …

Nov 2, 2024
CVE-2024-51774
8.1 HIGH

qBittorrent before 5.0.1 proceeds with use of https URLs even after certificate validation errors.

Nov 2, 2024
CVE-2024-9191
7.1 HIGH

The Okta Device Access features, provided by the Okta Verify agent for Windows, provides access to the OktaDeviceAccessPipe, which enables attackers in a compromised device …

Nov 1, 2024
CVE-2024-48353
7.5 HIGH

Yealink Meeting Server before V26.0.0.67 allows attackers to obtain static key information from a front-end JS file and decrypt the plaintext passwords based on the …

Nov 1, 2024
CVE-2024-51492
8.8 HIGH

Zusam is a free and open-source way to self-host private forums. Prior to version 0.5.6, specially crafted SVG files uploaded to the service as images …

Nov 1, 2024
CVE-2024-51248
8.8 HIGH

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the modifyrow function.

Nov 1, 2024
CVE-2024-51247
8.8 HIGH

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPPo function.

Nov 1, 2024
CVE-2024-51245
8.8 HIGH

In DrayTek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the rename_table function.

Nov 1, 2024
CVE-2024-51244
8.8 HIGH

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doIPSec function.

Nov 1, 2024
CVE-2024-48352
7.5 HIGH

Yealink Meeting Server before V26.0.0.67 is vulnerable to sensitive data exposure in the server response via sending HTTP request with enterprise ID.

Nov 1, 2024
CVE-2024-48217
8.8 HIGH

An Insecure Direct Object Reference (IDOR) in the dashboard of SiSMART v7.4.0 allows attackers to execute a horizontal-privilege escalation.

Nov 1, 2024
CVE-2024-40490
7.5 HIGH

An issue in Sourcebans++ before v.1.8.0 allows a remote attacker to obtain sensitive information via a crafted XAJAX call to the Forgot Password function.

Nov 1, 2024
CVE-2024-22733
7.5 HIGH

TP Link MR200 V4 Firmware version 210201 was discovered to contain a null-pointer-dereference in the web administration panel on /cgi/login via the sign, Action or …

Nov 1, 2024
CVE-2024-10662
8.8 HIGH

A vulnerability was found in Tenda AC15 15.03.05.19 and classified as critical. This issue affects the function formSetDeviceName of the file /goform/SetOnlineDevName. The manipulation of …

Nov 1, 2024
CVE-2024-10661
8.8 HIGH

A vulnerability has been found in Tenda AC15 15.03.05.19 and classified as critical. This vulnerability affects the function SetDlnaCfg of the file /goform/SetDlnaCfg. The manipulation …

Nov 1, 2024
CVE-2024-47314
7.1 HIGH

Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through …

Nov 1, 2024
CVE-2024-43982
8.8 HIGH

Missing Authorization vulnerability in Geek Code Lab Login As Users allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Login As Users: from n/a …

Nov 1, 2024
CVE-2024-43235
7.1 HIGH

Missing Authorization vulnerability in MetaBox.Io Meta Box – WordPress Custom Fields Framework allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Meta Box – …

Nov 1, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.