CVE Database

38969+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-9139
7.2 HIGH

The affected product permits OS command injection through improperly restricted commands, potentially allowing attackers to execute arbitrary code.

Oct 14, 2024
CVE-2024-43701
7.8 HIGH

Software installed and run as a non-privileged user may conduct GPU system calls to read and write freed physical memory from the GPU.

Oct 14, 2024
CVE-2024-38863
7.5 HIGH

Exposure of CSRF tokens in query parameters on specific requests in Checkmk GmbH's Checkmk versions <2.3.0p18, <2.2.0p35 and <2.1.0p48 could lead to a leak of …

Oct 14, 2024
CVE-2024-9922
7.5 HIGH

The Team+ from TEAMPLUS TECHNOLOGY does not properly validate a specific page parameter, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system …

Oct 14, 2024
CVE-2024-8070
8.5 HIGH

CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that exposes test credentials in the firmware binary

Oct 13, 2024
CVE-2024-9916
7.3 HIGH

A vulnerability, which was classified as critical, has been found in HuangDou UTCMS V9. Affected by this issue is some unknown functionality of the file …

Oct 13, 2024
CVE-2024-9915
8.8 HIGH

A vulnerability classified as critical was found in D-Link DIR-619L B1 2.06. Affected by this vulnerability is the function formVirtualServ of the file /goform/formVirtualServ. The …

Oct 13, 2024
CVE-2024-9914
8.8 HIGH

A vulnerability classified as critical has been found in D-Link DIR-619L B1 2.06. Affected is the function formSetWizardSelectMode of the file /goform/formSetWizardSelectMode. The manipulation of …

Oct 13, 2024
CVE-2024-9913
8.8 HIGH

A vulnerability was found in D-Link DIR-619L B1 2.06. It has been rated as critical. This issue affects the function formSetRoute of the file /goform/formSetRoute. …

Oct 13, 2024
CVE-2024-9912
8.8 HIGH

A vulnerability was found in D-Link DIR-619L B1 2.06. It has been declared as critical. This vulnerability affects the function formSetQoS of the file /goform/formSetQoS. …

Oct 13, 2024
CVE-2024-9911
8.8 HIGH

A vulnerability was found in D-Link DIR-619L B1 2.06. It has been classified as critical. This affects the function formSetPortTr of the file /goform/formSetPortTr. The …

Oct 13, 2024
CVE-2024-9910
8.8 HIGH

A vulnerability was found in D-Link DIR-619L B1 2.06 and classified as critical. Affected by this issue is the function formSetPassword of the file /goform/formSetPassword. …

Oct 13, 2024
CVE-2024-9909
8.8 HIGH

A vulnerability has been found in D-Link DIR-619L B1 2.06 and classified as critical. Affected by this vulnerability is the function formSetMuti of the file …

Oct 13, 2024
CVE-2024-6959
7.1 HIGH

A vulnerability in parisneo/lollms-webui version 9.8 allows for a Denial of Service (DOS) attack when uploading an audio file. If an attacker appends a large …

Oct 13, 2024
CVE-2024-49193
7.5 HIGH

Zendesk before 2024-07-02 allows remote attackers to read ticket history via e-mail spoofing, because Cc fields are extracted from incoming e-mail messages and used to …

Oct 12, 2024
CVE-2024-8757
7.2 HIGH

The WP Post Author – Boost Your Blog&#039;s Engagement with Author Box, Social Links, Co-Authors, Guest Authors, Post Rating System, and Custom User Registration Form …

Oct 12, 2024
CVE-2024-9821
8.8 HIGH

The Bot for Telegram on WooCommerce plugin for WordPress is vulnerable to sensitive information disclosure due to missing authorization checks on the 'stm_wpcfto_get_settings' AJAX action …

Oct 12, 2024
CVE-2024-45754
7.2 HIGH

An issue was discovered in the centreon-bi-server component in Centreon BI Server 24.04.x before 24.04.3, 23.10.x before 23.10.8, 23.04.x before 23.04.11, and 22.10.x before 22.10.11. …

Oct 11, 2024
CVE-2024-35522
8.4 HIGH

Netgear EX3700 ' AC750 WiFi Range Extender Essentials Edition before 1.0.0.98 contains an authenticated command injection in operating_mode.cgi via the ap_mode parameter with ap_24g_manual set …

Oct 11, 2024
CVE-2024-35517
8.4 HIGH

Netgear XR1000 v1.0.0.64 is vulnerable to command injection in usb_remote_smb_conf.cgi via the share_name parameter.

Oct 11, 2024
CVE-2024-48938
7.5 HIGH

Znuny before LTS 6.5.1 through 6.5.10 and 7.0.1 through 7.0.16 allows DoS/ReDos via email. Parsing the content of emails where HTML code is copied from …

Oct 11, 2024
CVE-2024-48788
7.5 HIGH

An issue in YESCAM (com.yescom.YesCam.zwave) 1.0.2 allows a remote attacker to obtain sensitive information via the firmware update process.

Oct 11, 2024
CVE-2024-46468
7.5 HIGH

A Server-Side Request Forgery (SSRF) vulnerability exists in the jpress <= v5.1.1, which can be exploited by an attacker to obtain sensitive information, resulting in …

Oct 11, 2024
CVE-2024-48777
7.5 HIGH

LEDVANCE com.ledvance.smartplus.eu 2.1.10 allows a remote attacker to obtain sensitive information via the firmware update process.

Oct 11, 2024
CVE-2024-48776
7.5 HIGH

An issue in Shelly com.home.shelly 1.0.4 allows a remote attacker to obtain sensitive information via the firmware update process

Oct 11, 2024
CVE-2024-48775
7.5 HIGH

An issue in Plug n Play Camera com.ezset.delaney 1.2.0 allows a remote attacker to obtain sensitive information via the firmware update process.

Oct 11, 2024
CVE-2024-48774
7.5 HIGH

An issue in Fermax Asia Pacific Pte Ltd com.fermax.vida 2.4.6 allows a remote attacker to obtain sensitve information via the firmware update process.

Oct 11, 2024
CVE-2024-48773
7.5 HIGH

An issue in WoFit v.7.2.3 allows a remote attacker to obtain sensitive information via the firmware update process

Oct 11, 2024
CVE-2024-48771
7.5 HIGH

An issue in almando GmbH Almando Play APP (com.almando.play) 1.8.2 allows a remote attacker to obtain sensitive information via the firmware update process

Oct 11, 2024
CVE-2024-48770
8.2 HIGH

An issue in Plug n Play Camera com.wisdomcity.zwave 1.1.0 allows a remote attacker to obtain sensitive information via the firmware update process.

Oct 11, 2024
CVE-2024-48768
7.5 HIGH

An issue in almaodo GmbH appinventor.ai_google.almando_control 2.3.1 allows a remote attacker to obtain sensitive information via the firmware update process

Oct 11, 2024
CVE-2024-38365
7.4 HIGH

btcd is an alternative full node bitcoin implementation written in Go (golang). The btcd Bitcoin client (versions 0.10 to 0.24) did not correctly re-implement Bitcoin …

Oct 11, 2024
CVE-2024-8912
7.5 HIGH

An HTTP Request Smuggling vulnerability in Looker allowed an unauthorized attacker to capture HTTP responses destined for legitimate users. There are two Looker versions that …

Oct 11, 2024
CVE-2024-48040
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in tainacan Tainacan tainacan allows SQL Injection.This issue affects Tainacan: from n/a …

Oct 11, 2024
CVE-2024-48020
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in revmakx Backup and Staging by WP Time Capsule wp-time-capsule allows SQL …

Oct 11, 2024
CVE-2024-9859
8.8 HIGH

Type confusion in WebAssembly in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security …

Oct 11, 2024
CVE-2024-47877
7.5 HIGH

Extract is aA Go library to extract archives in zip, tar.gz or tar.bz2 formats. A maliciously crafted archive may allow an attacker to create a …

Oct 11, 2024
CVE-2024-44734
7.5 HIGH

Incorrect access control in Mirotalk before commit 9de226 allows attackers to arbitrarily change usernames via sending a crafted roomAction request to the server.

Oct 11, 2024
CVE-2024-44414
8.8 HIGH

A vulnerability was discovered in FBM_292W-21.03.10V, which has been classified as critical. This issue affects the sub_4901E0 function in the msp_info.htm file. Manipulation of the …

Oct 11, 2024
CVE-2024-44413
8.8 HIGH

A vulnerability was discovered in DI_8200-16.07.26A1, which has been classified as critical. This issue affects the upgrade_filter_asp function in the upgrade_filter.asp file. Manipulation of the …

Oct 11, 2024
CVE-2024-42018
7.7 HIGH

An issue was discovered in Atos Eviden SMC xScale before 1.6.6. During initialization of nodes, some configuration parameters are retrieved from management nodes. These parameters …

Oct 11, 2024
CVE-2024-9046
7.8 HIGH

A DLL hijack vulnerability was reported in Lenovo stARstudio that could allow a local attacker to execute code with elevated privileges.

Oct 11, 2024
CVE-2024-8376
7.5 HIGH

In Eclipse Mosquitto up to version 2.0.18a, an attacker can achieve memory leaking, segmentation fault or heap-use-after-free by sending specific sequences of "CONNECT", "DISCONNECT", "SUBSCRIBE", …

Oct 11, 2024
CVE-2024-4132
7.8 HIGH

A DLL hijack vulnerability was reported in Lenovo Lock Screen that could allow a local attacker to execute code with elevated privileges.

Oct 11, 2024
CVE-2024-4131
7.8 HIGH

A DLL hijack vulnerability was reported in Lenovo Emulator that could allow a local attacker to execute code with elevated privileges.

Oct 11, 2024
CVE-2024-4130
7.8 HIGH

A DLL hijack vulnerability was reported in Lenovo App Store that could allow a local attacker to execute code with elevated privileges.

Oct 11, 2024
CVE-2024-4089
7.8 HIGH

A DLL hijack vulnerability was reported in Lenovo Super File that could allow a local attacker to execute code with elevated privileges.

Oct 11, 2024
CVE-2024-48827
8.8 HIGH

An issue in sbondCo Watcharr v.1.43.0 allows a remote attacker to execute arbitrary code and escalate privileges via the Change Password function.

Oct 11, 2024
CVE-2024-48813
8.8 HIGH

SQL injection vulnerability in employee-management-system-php-and-mysql-free-download.html taskmatic 1.0 allows a remote attacker to execute arbitrary code via the admin_id parameter of the /update-employee.php component.

Oct 11, 2024
CVE-2024-47504
7.5 HIGH

An Improper Validation of Specified Type of Input vulnerability in the packet forwarding engine (pfe) Juniper Networks Junos OS on SRX5000 Series allows an unauthenticated, …

Oct 11, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.