CVE Database

38969+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-21234
7.5 HIGH

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability …

Oct 15, 2024
CVE-2024-21215
7.5 HIGH

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability …

Oct 15, 2024
CVE-2024-21214
8.1 HIGH

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Query). Supported versions that are affected are 8.59, 8.60 and 8.61. Easily exploitable vulnerability …

Oct 15, 2024
CVE-2024-21195
7.6 HIGH

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Layout Templates). Supported versions that are affected are 7.0.0.0.0, 7.6.0.0.0 and 12.2.1.4.0. Easily exploitable …

Oct 15, 2024
CVE-2024-21191
7.6 HIGH

Vulnerability in the Oracle Enterprise Manager Fusion Middleware Control product of Oracle Fusion Middleware (component: FMW Control Plugin). The supported version that is affected is …

Oct 15, 2024
CVE-2024-21190
7.5 HIGH

Vulnerability in the Oracle Global Lifecycle Management FMW Installer product of Oracle Fusion Middleware (component: Cloning). The supported version that is affected is 12.2.1.4.0. Easily …

Oct 15, 2024
CVE-2024-41344
7.5 HIGH

A Cross-Site Request Forgery (CSRF) in Codeigniter 3.1.13 allows attackers to arbitrarily change the Administrator password and escalate privileges.

Oct 15, 2024
CVE-2024-35584
8.8 HIGH

SQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in OpenSis Community Edition 9.1 to 8.0, and possibly earlier versions. It is possible …

Oct 15, 2024
CVE-2024-5749
7.5 HIGH

Certain HP DesignJet products may be vulnerable to credential reflection which allow viewing SMTP server credentials.

Oct 15, 2024
CVE-2024-47876
8.8 HIGH

Sakai is a Collaboration and Learning Environment. Starting in version 23.0 and prior to version 23.2, kernel users created with type roleview can log in …

Oct 15, 2024
CVE-2024-9986
7.3 HIGH

A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the …

Oct 15, 2024
CVE-2024-48282
7.6 HIGH

A SQL Injection vulnerability was found in /password-recovery.php of PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers to execute …

Oct 15, 2024
CVE-2024-48280
7.6 HIGH

A SQL Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers to execute …

Oct 15, 2024
CVE-2024-48279
7.6 HIGH

A HTML Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Management System 3.2. This vulnerability allows remote attackers to …

Oct 15, 2024
CVE-2024-49387
7.5 HIGH

Cleartext transmission of sensitive information in acep-collector service. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.

Oct 15, 2024
CVE-2024-45276
7.5 HIGH

An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication.

Oct 15, 2024
CVE-2024-45273
8.4 HIGH

An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used.

Oct 15, 2024
CVE-2024-45272
7.5 HIGH

An unauthenticated remote attacker can perform a brute-force attack on the credentials of the remote service portal with a high chance of success, resulting in …

Oct 15, 2024
CVE-2024-45271
8.4 HIGH

An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation.

Oct 15, 2024
CVE-2024-9983
7.5 HIGH

Enterprise Cloud Database from Ragic does not properly validate a specific page parameter, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system …

Oct 15, 2024
CVE-2024-9981
8.8 HIGH

The ee-class from FormosaSoft does not properly validate a specific page parameter, allowing remote attackers with regular privileges to upload a malicious PHP file first …

Oct 15, 2024
CVE-2024-9980
8.8 HIGH

The ee-class from FormosaSoft does not properly validate a specific page parameter, allowing remote attackers with regular privileges to inject arbitrary SQL commands to read, …

Oct 15, 2024
CVE-2024-9837
7.3 HIGH

The The AADMY – Add Auto Date Month Year Into Posts plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, …

Oct 15, 2024
CVE-2024-46898
7.5 HIGH

SHIRASAGI prior to v1.19.1 processes URLs in HTTP requests improperly, resulting in a path traversal vulnerability. If this vulnerability is exploited, arbitrary files on the …

Oct 15, 2024
CVE-2024-9971
8.8 HIGH

The specific query functionality in the FlowMaster BPM Plus from NewType does not properly restrict user input, allowing remote attackers with regular privileges to inject …

Oct 15, 2024
CVE-2024-9970
8.8 HIGH

The FlowMaster BPM Plus system from NewType has a privilege escalation vulnerability. Remote attackers with regular privileges can elevate their privileges to administrator by tampering …

Oct 15, 2024
CVE-2024-9968
8.8 HIGH

WebEIP v3.0 from NewType does not properly validate user input, allowing remote attackers with regular privilege to inject SQL commands to read, modify, and delete …

Oct 15, 2024
CVE-2024-9687
8.8 HIGH

The WP 2FA with Telegram plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 3.0. This is due to insufficient …

Oct 15, 2024
CVE-2024-9548
7.2 HIGH

The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the resource parameter in all versions up to, and including, 5.2.6 due …

Oct 15, 2024
CVE-2024-35520
8.4 HIGH

Netgear R7000 1.0.11.136 is vulnerable to Command Injection in RMT_invite.cgi via device_name2 parameter.

Oct 14, 2024
CVE-2024-35519
8.4 HIGH

Netgear EX6120 v1.0.0.68, Netgear EX6100 v1.0.2.28, and Netgear EX3700 v1.0.0.96 are vulnerable to command injection in operating_mode.cgi via the ap_mode parameter.

Oct 14, 2024
CVE-2024-35518
8.4 HIGH

Netgear EX6120 v1.0.0.68 is vulnerable to Command Injection in genie_fix2.cgi via the wan_dns1_pri parameter.

Oct 14, 2024
CVE-2024-6207
7.5 HIGH

CVE 2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html and send a specially crafted CIP message to the device. If exploited, a threat actor could help prevent access to the legitimate …

Oct 14, 2024
CVE-2024-48911
7.8 HIGH

OpenCanary, a multi-protocol network honeypot, directly executed commands taken from its config file. Prior to version 0.9.4, where the config file is stored in an …

Oct 14, 2024
CVE-2024-48824
7.5 HIGH

An issue in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a remote attacker to obtain sensitive information via the Racine & FileName parameters in the download-file.php …

Oct 14, 2024
CVE-2024-48822
8.8 HIGH

Privilege escalation in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a remote attacker to escalate privileges via the FtpConfig.php page.

Oct 14, 2024
CVE-2024-48792
7.5 HIGH

An issue in Hideez com.hideez 2.7.8.3 allows a remote attacker to obtain sensitive information via the firmware update process.

Oct 14, 2024
CVE-2024-48791
7.5 HIGH

An issue in Plug n Play Camera com.starvedia.mCamView.zwave 5.5.1 allows a remote attacker to obtain sensitive information via the firmware update process

Oct 14, 2024
CVE-2024-48789
7.5 HIGH

An issue in INATRONIC com.inatronic.drivedeck.home 2.6.23 allows a remote attacker to obtain sensitve information via the firmware update process.

Oct 14, 2024
CVE-2024-48799
7.5 HIGH

An issue in LOREX TECHNOLOGY INC com.lorexcorp.lorexping 1.4.22 allows a remote attacker to obtain sensitive information via the firmware update process.

Oct 14, 2024
CVE-2024-48798
7.5 HIGH

An issue in Hubble Connected (com.hubbleconnected.vervelife) 2.00.81 allows a remote attacker to obtain sensitive information via the firmware update process.

Oct 14, 2024
CVE-2024-48797
7.5 HIGH

An issue in PCS Engineering Preston Cinema (com.prestoncinema.app) 0.2.0 allows a remote attacker to obtain sensitive information via the firmware update process.

Oct 14, 2024
CVE-2024-48796
7.5 HIGH

An issue in EQUES com.eques.plug 1.0.1 allows a remote attacker to obtain sensitive information via the firmware update process.

Oct 14, 2024
CVE-2024-45733
8.8 HIGH

In Splunk Enterprise for Windows versions below 9.2.3 and 9.1.6, a low-privileged user that does not hold the "admin" or "power" Splunk roles could perform …

Oct 14, 2024
CVE-2024-45732
7.1 HIGH

In Splunk Enterprise versions below 9.3.1, and 9.2.0 versions below 9.2.3, and Splunk Cloud Platform versions below 9.2.2403.103, 9.1.2312.200, 9.1.2312.110 and 9.1.2308.208, a low-privileged user …

Oct 14, 2024
CVE-2024-45731
8.0 HIGH

In Splunk Enterprise for Windows versions below 9.3.1, 9.2.3, and 9.1.6, a low-privileged user that does not hold the "admin" or "power" Splunk roles could …

Oct 14, 2024
CVE-2023-50780
8.8 HIGH

Apache ActiveMQ Artemis allows access to diagnostic information and controls through MBeans, which are also exposed through the authenticated Jolokia endpoint. Before version 2.29.0, this …

Oct 14, 2024
CVE-2024-48259
7.3 HIGH

Cloudlog 2.6.15 allows Oqrs.php request_form SQL injection via station_id or callsign.

Oct 14, 2024
CVE-2024-48249
7.3 HIGH

Wavelog 1.8.5 allows Gridmap_model.php get_band_confirmed SQL injection via band, sat, propagation, or mode.

Oct 14, 2024
CVE-2024-7847
7.7 HIGH

VULNERABILITY DETAILS Rockwell Automation used the latest versions of the CVSS scoring system to assess the following vulnerabilities. The following vulnerabilities were reported to us …

Oct 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.