CVE Database

38969+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-47846
8.8 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in The Wikimedia Foundation Mediawiki - Cargo allows Cross Site Request Forgery.This issue affects Mediawiki - Cargo: from 3.6.X before …

Oct 5, 2024
CVE-2024-47845
8.2 HIGH

Improper Encoding or Escaping of Output vulnerability in The Wikimedia Foundation Mediawiki - CSS Extension allows Code Injection.This issue affects Mediawiki - CSS Extension: from …

Oct 5, 2024
CVE-2024-47910
7.2 HIGH

An issue was discovered in SonarSource SonarQube before 9.9.5 LTA and 10.x before 10.5. A SonarQube user with the Administrator role can modify an existing …

Oct 4, 2024
CVE-2024-37869
8.8 HIGH

File Upload vulnerability in Itsourcecode Online Discussion Forum Project v.1.0 allows a remote attacker to execute arbitrary code via the "poster.php" file, and the uploaded …

Oct 4, 2024
CVE-2024-37868
8.8 HIGH

File Upload vulnerability in Itsourcecode Online Discussion Forum Project v.1.0 allows a remote attacker to execute arbitrary code via the "sendreply.php" file, and the uploaded …

Oct 4, 2024
CVE-2024-9054
8.8 HIGH

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Microchip TimeProvider …

Oct 4, 2024
CVE-2024-43684
8.8 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Microchip TimeProvider 4100 allows Cross Site Request Forgery, Cross-Site Scripting (XSS).This issue affects TimeProvider 4100: from 1.0.

Oct 4, 2024
CVE-2024-46078
7.5 HIGH

itsourcecode Sports Management System Project 1.0 is vulnerable to SQL Injection in the function delete_category of the file sports_scheduling/player.php via the argument id.

Oct 4, 2024
CVE-2024-41512
8.8 HIGH

A SQL Injection vulnerability in "ccHandler.aspx" in all versions of CADClick v.1.11.0 and before allows remote attackers to execute arbitrary SQL commands via the "bomid" …

Oct 4, 2024
CVE-2024-38040
7.5 HIGH

There is a local file inclusion vulnerability in Esri Portal for ArcGIS 11.2 and below that may allow a remote, unauthenticated attacker to craft a …

Oct 4, 2024
CVE-2024-46486
8.0 HIGH

TP-LINK TL-WDR5620 v2.3 was discovered to contain a remote code execution (RCE) vulnerability via the httpProcDataSrv function.

Oct 4, 2024
CVE-2024-47769
7.5 HIGH

IDURAR is open source ERP CRM accounting invoicing software. The vulnerability exists in the corePublicRouter.js file. Using the reference usage here, it is identified that …

Oct 4, 2024
CVE-2024-47768
8.1 HIGH

Lif Authentication Server is a server used by Lif to do various tasks regarding Lif accounts. This vulnerability has to do with the account recovery …

Oct 4, 2024
CVE-2024-47183
8.1 HIGH

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. If the Parse Server option allowCustomObjectId: true …

Oct 4, 2024
CVE-2024-9515
8.8 HIGH

A vulnerability was found in D-Link DIR-605L 2.13B01 BETA. It has been classified as critical. This affects the function formSetQoS of the file /goform/formSetQoS. The …

Oct 4, 2024
CVE-2024-9514
8.8 HIGH

A vulnerability was found in D-Link DIR-605L 2.13B01 BETA. It has been declared as critical. This vulnerability affects the function formSetDomainFilter of the file /goform/formSetDomainFilter. …

Oct 4, 2024
CVE-2024-47655
8.8 HIGH

This vulnerability exists in the Shilpi Client Dashboard due to improper validation of files being uploaded other than the specified extension. An authenticated remote attacker …

Oct 4, 2024
CVE-2024-47654
7.5 HIGH

This vulnerability exists in Shilpi Client Dashboard due to lack of rate limiting and Captcha protection for OTP requests in certain API endpoint. An unauthenticated …

Oct 4, 2024
CVE-2024-47652
8.1 HIGH

This vulnerability exists in Shilpi Client Dashboard due to implementation of inadequate authentication mechanism in the login module wherein access to any users account is …

Oct 4, 2024
CVE-2024-6400
7.5 HIGH

Cleartext Storage of Sensitive Information, Exposure of Sensitive Information Through Data Queries vulnerability in Finrota Netahsilat allows Retrieve Embedded Sensitive Data, Authentication Bypass, IMAP/SMTP Command …

Oct 4, 2024
CVE-2024-47850
7.5 HIGH

CUPS cups-browsed before 2.5b1 will send an HTTP POST request to an arbitrary destination and port in response to a single IPP UDP packet requesting …

Oct 4, 2024
CVE-2024-42417
8.8 HIGH

Delta Electronics DIAEnergie is vulnerable to an SQL injection in the script Handler_CFG.ashx. An authenticated attacker may be able to exploit this issue to cause …

Oct 3, 2024
CVE-2024-46658
8.0 HIGH

Syrotech SY-GOPON-8OLT-L3 v1.6.0_240629 was discovered to contain an authenticated command injection vulnerability.

Oct 3, 2024
CVE-2024-41596
8.0 HIGH

Buffer Overflow vulnerabilities exist in DrayTek Vigor310 devices through 4.3.2.6 (in the Vigor management UI) because of improper retrieval and handling of the CGI form …

Oct 3, 2024
CVE-2024-41595
8.0 HIGH

DrayTek Vigor310 devices through 4.3.2.6 allow a remote attacker to change settings or cause a denial of service via .cgi pages because of missing bounds …

Oct 3, 2024
CVE-2024-41594
7.5 HIGH

An issue in DrayTek Vigor310 devices through 4.3.2.6 allows an attacker to obtain sensitive information because the httpd server of the Vigor management UI uses …

Oct 3, 2024
CVE-2024-41592
8.0 HIGH

DrayTek Vigor3910 devices through 4.3.2.6 have a stack-based overflow when processing query string parameters because GetCGI mishandles extraneous ampersand characters and long key-value pairs.

Oct 3, 2024
CVE-2024-41590
8.0 HIGH

Several CGI endpoints are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on parameters passed through POST requests to the strcpy …

Oct 3, 2024
CVE-2024-41589
8.8 HIGH

DrayTek Vigor310 devices through 4.3.2.6 use unencrypted HTTP for authentication requests.

Oct 3, 2024
CVE-2024-41588
8.0 HIGH

The CGI endpoints v2x00.cgi and cgiwcg.cgi of DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking …

Oct 3, 2024
CVE-2024-41586
8.0 HIGH

A stack-based Buffer Overflow vulnerability in DrayTek Vigor310 devices through 4.3.2.6 allows a remote attacker to execute arbitrary code via a long query string to …

Oct 3, 2024
CVE-2023-37822
8.2 HIGH

The Eufy Homebase 2 before firmware version 3.3.4.1h creates a dedicated wireless network for its ecosystem, which serves as a proxy to the end user's …

Oct 3, 2024
CVE-2024-42415
8.4 HIGH

An integer overflow vulnerability exists in the Compound Document Binary File format parser of v1.14.52 of the GNOME Project G Structured File Library (libgsf). A …

Oct 3, 2024
CVE-2024-41922
7.5 HIGH

A directory traversal vulnerability exists in the log files download functionality of Veertu Anka Build 1.42.0. A specially crafted HTTP request can lead to a …

Oct 3, 2024
CVE-2024-41163
7.5 HIGH

A directory traversal vulnerability exists in the archive functionality of Veertu Anka Build 1.42.0. A specially crafted HTTP request can lead to a disclosure of …

Oct 3, 2024
CVE-2024-39755
7.8 HIGH

A privilege escalation vulnerability exists in the node update functionality of Veertu Anka Build 1.42.0. A specially crafted PKG file can lead to execute priviledged …

Oct 3, 2024
CVE-2024-36474
8.4 HIGH

An integer overflow vulnerability exists in the Compound Document Binary File format parser of the GNOME Project G Structured File Library (libgsf) version v1.14.52. A …

Oct 3, 2024
CVE-2024-25590
7.5 HIGH

An attacker can publish a zone containing specific Resource Record Sets. Repeatedly processing and caching results for these sets can lead to a denial of …

Oct 3, 2024
CVE-2024-9460
7.3 HIGH

A vulnerability was found in Codezips Online Shopping Portal 1.0. It has been classified as critical. Affected is an unknown function of the file index.php. …

Oct 3, 2024
CVE-2024-5803
7.5 HIGH

The AVGUI.exe of AVG/Avast Antivirus before versions before 24.1 can allow a local attacker to escalate privileges via an COM hijack in a time-of-check to …

Oct 3, 2024
CVE-2024-47614
7.5 HIGH

async-graphql is a GraphQL server library implemented in Rust. async-graphql before 7.0.10 does not limit the number of directives for a field. This can lead …

Oct 3, 2024
CVE-2024-9313
8.8 HIGH

Authd PAM module before version 0.3.5 can allow broker-managed users to impersonate any other user managed by the same broker and perform any PAM operation …

Oct 3, 2024
CVE-2024-47561
7.3 HIGH

Schema parsing in the Java SDK of Apache Avro 1.11.3 and previous versions allows bad actors to execute arbitrary code. Users are recommended to upgrade …

Oct 3, 2024
CVE-2024-8352
7.5 HIGH

The Social Web Suite – Social Media Auto Post, Social Media Auto Publish plugin for WordPress is vulnerable to Directory Traversal in all versions up …

Oct 3, 2024
CVE-2024-47136
7.8 HIGH

Out-of-bounds read vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) Version 1.6.14.0 and earlier. Having a user open a specially …

Oct 3, 2024
CVE-2024-47135
7.8 HIGH

Stack-based buffer overflow vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) Version 1.6.14.0 and earlier. Having a user open a …

Oct 3, 2024
CVE-2024-47134
7.8 HIGH

Out-of-bounds write vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) Version 1.6.14.0 and earlier. Having a user open a specially …

Oct 3, 2024
CVE-2024-28888
8.8 HIGH

A use-after-free vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a checkbox field object. A specially crafted Javascript code inside a malicious PDF document …

Oct 2, 2024
CVE-2024-8733
8.0 HIGH

A potential security vulnerability has been identified in the HP One Agent for certain HP PC products, which might allow for escalation of privilege. HP …

Oct 2, 2024
CVE-2024-20501
8.6 HIGH

Multiple vulnerabilities in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote …

Oct 2, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.