CVE Database

38969+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-37230
8.8 HIGH

Loftware Spectrum (testDeviceConnection) before 5.1 allows SSRF.

Sep 10, 2024
CVE-2023-37229
8.8 HIGH

Loftware Spectrum before 5.1 allows SSRF.

Sep 10, 2024
CVE-2024-7770
8.8 HIGH

The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to arbitrary file …

Sep 10, 2024
CVE-2024-44087
8.6 HIGH

A vulnerability has been identified in Automation License Manager V5 (All versions), Automation License Manager V6.0 (All versions < V6.0 SP12 Upd3), Automation License Manager …

Sep 10, 2024
CVE-2024-43647
7.5 HIGH

A vulnerability has been identified in SIMATIC S7-200 SMART CPU CR40 (6ES7288-1CR40-0AA0) (All versions), SIMATIC S7-200 SMART CPU CR60 (6ES7288-1CR60-0AA0) (All versions), SIMATIC S7-200 SMART …

Sep 10, 2024
CVE-2024-41171
8.8 HIGH

A vulnerability has been identified in SINUMERIK 828D V4 (All versions), SINUMERIK 828D V5 (All versions < V5.24), SINUMERIK 840D sl V4 (All versions), SINUMERIK …

Sep 10, 2024
CVE-2024-41170
7.8 HIGH

A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0015), Tecnomatix Plant Simulation V2404 (All versions < V2404.0004). The affected applications …

Sep 10, 2024
CVE-2024-8258
7.8 HIGH

Improper Control of Generation of Code ('Code Injection') in Electron Fuses in Logitech Options Plus version 1.60.496306 on macOS allows attackers to execute arbitrary code …

Sep 10, 2024
CVE-2024-7699
8.8 HIGH

An low privileged remote attacker can execute OS commands with root privileges due to improper neutralization of special elements in user data.

Sep 10, 2024
CVE-2024-43393
8.1 HIGH

A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the …

Sep 10, 2024
CVE-2024-43392
8.1 HIGH

A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the …

Sep 10, 2024
CVE-2024-43391
8.1 HIGH

A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the …

Sep 10, 2024
CVE-2024-43390
8.1 HIGH

A low privileged remote attacker can perform configuration changes of the firewall services, including packet forwarding or NAT through the FW_NAT.IN_IP environment variable which can …

Sep 10, 2024
CVE-2024-43389
8.1 HIGH

A low privileged remote attacker can perform configuration changes of the ospf service through OSPF_INTERFACE.SIMPLE_KEY, OSPF_INTERFACE.DIGEST_KEY environment variables which can lead to a DoS.

Sep 10, 2024
CVE-2024-43388
8.8 HIGH

A low privileged remote attacker with write permissions can reconfigure the SNMP service due to improper input validation.

Sep 10, 2024
CVE-2024-43387
8.8 HIGH

A low privileged remote attacker can read and write files as root due to improper neutralization of special elements in the variable EMAIL_RELAY_PASSWORD in mGuard …

Sep 10, 2024
CVE-2024-43386
8.8 HIGH

A low privileged remote attacker can trigger the execution of arbitrary OS commands as root due to improper neutralization of special elements in the variable …

Sep 10, 2024
CVE-2024-43385
8.8 HIGH

A low privileged remote attacker can trigger the execution of arbitrary OS commands as root due to improper neutralization of special elements in the variable …

Sep 10, 2024
CVE-2024-39583
8.1 HIGH

Dell PowerScale InsightIQ, versions 5.0 through 5.1, contains a Use of a Broken or Risky Cryptographic Algorithm vulnerability. An unauthenticated attacker with remote access could …

Sep 10, 2024
CVE-2024-39581
7.3 HIGH

Dell PowerScale InsightIQ, versions 5.0 through 5.1, contains a File or Directories Accessible to External Parties vulnerability. An unauthenticated attacker with remote access could potentially …

Sep 10, 2024
CVE-2024-42427
7.6 HIGH

Dell ThinOS versions 2402 and 2405, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with physical …

Sep 10, 2024
CVE-2024-8478
7.3 HIGH

The The Affiliate Super Assistent plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.5.3. This is due …

Sep 10, 2024
CVE-2024-8268
8.8 HIGH

The Frontend Dashboard plugin for WordPress is vulnerable to unauthorized code execution due to insufficient filtering on callable methods/functions via the ajax_request() function in all …

Sep 10, 2024
CVE-2024-6796
8.2 HIGH

In Baxter Connex health portal released before 8/30/2024, an improper access control vulnerability has been found that could allow an unauthenticated attacker to gain unauthorized …

Sep 9, 2024
CVE-2024-44725
7.2 HIGH

AutoCMS v5.4 was discovered to contain a SQL injection vulnerability via the sidebar parameter at /admin/robot.php.

Sep 9, 2024
CVE-2024-44724
7.2 HIGH

AutoCMS v5.4 was discovered to contain a PHP code injection vulnerability via the txtsite_url parameter at /admin/site_add.php. This vulnerability allows attackers to execute arbitrary PHP …

Sep 9, 2024
CVE-2024-7341
7.1 HIGH

A session fixation issue was discovered in the SAML adapters provided by Keycloak. The session ID and JSESSIONID cookie are not changed at login time, …

Sep 9, 2024
CVE-2024-45411
8.5 HIGH

Twig is a template language for PHP. Under some circumstances, the sandbox security checks are not run which allows user-contributed templates to bypass the sandbox …

Sep 9, 2024
CVE-2024-45296
7.5 HIGH

path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. …

Sep 9, 2024
CVE-2024-44335
8.8 HIGH

D-Link DI-7003G v19.12.24A1, DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution (RCE) via version_upgrade.asp.

Sep 9, 2024
CVE-2024-44334
8.8 HIGH

D-Link DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution due to insufficient parameter filtering …

Sep 9, 2024
CVE-2024-44333
8.8 HIGH

D-Link DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution. An attacker can achieve arbitrary …

Sep 9, 2024
CVE-2024-44720
7.5 HIGH

SeaCMS v13.1 was discovered to an arbitrary file read vulnerability via the component admin_safe.php.

Sep 9, 2024
CVE-2024-45041
8.3 HIGH

External Secrets Operator is a Kubernetes operator that integrates external secret management systems. The external-secrets has a deployment called default-external-secrets-cert-controller, which is bound with a …

Sep 9, 2024
CVE-2024-44375
7.5 HIGH

D-Link DI-8100 v16.07.26A1 has a stack overflow vulnerability in the dbsrv_asp function.

Sep 9, 2024
CVE-2024-6572
7.4 HIGH

Improper host key checking in active check 'Check SFTP Service' and special agent 'VNX quotas and filesystem' in Checkmk before Checkmk 2.3.0p15, 2.2.0p33, 2.1.0p48 and …

Sep 9, 2024
CVE-2024-8580
8.1 HIGH

A vulnerability classified as critical was found in TOTOLINK AC1200 T8 4.1.5cu.861_B20230220. This vulnerability affects unknown code of the file /etc/shadow.sample. The manipulation leads to …

Sep 8, 2024
CVE-2024-8579
8.8 HIGH

A vulnerability classified as critical has been found in TOTOLINK AC1200 T8 4.1.5cu.861_B20230220. This affects the function setWiFiRepeaterCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of …

Sep 8, 2024
CVE-2024-8578
8.8 HIGH

A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.861_B20230220. It has been rated as critical. Affected by this issue is the function setWiFiMeshName of the …

Sep 8, 2024
CVE-2024-8577
8.8 HIGH

A vulnerability was found in TOTOLINK AC1200 T8 and AC1200 T10 4.1.5cu.861_B20230220/4.1.8cu.5207. It has been declared as critical. Affected by this vulnerability is the function …

Sep 8, 2024
CVE-2024-8576
8.8 HIGH

A vulnerability was found in TOTOLINK AC1200 T8 and AC1200 T10 4.1.5cu.861_B20230220/4.1.8cu.5207. It has been classified as critical. Affected is the function setIpPortFilterRules of the …

Sep 8, 2024
CVE-2024-8575
8.8 HIGH

A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.861_B20230220 and classified as critical. This issue affects the function setWiFiScheduleCfg of the file /cgi-bin/cstecgi.cgi. The manipulation …

Sep 8, 2024
CVE-2024-8573
8.8 HIGH

A vulnerability, which was classified as critical, was found in TOTOLINK AC1200 T8 and AC1200 T10 4.1.5cu.861_B20230220/4.1.8cu.5207. This affects the function setParentalRules of the file …

Sep 8, 2024
CVE-2024-8569
7.3 HIGH

A vulnerability has been found in code-projects Hospital Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Sep 8, 2024
CVE-2024-8567
7.3 HIGH

A vulnerability, which was classified as critical, has been found in itsourcecode Payroll Management System 1.0. This issue affects some unknown processing of the file …

Sep 8, 2024
CVE-2024-8565
7.3 HIGH

A vulnerability was found in SourceCodesters Clinics Patient Management System 2.0. It has been rated as critical. This issue affects some unknown processing of the …

Sep 7, 2024
CVE-2024-42024
8.8 HIGH

A vulnerability that allows an attacker in possession of the Veeam ONE Agent service account credentials to perform remote code execution on the machine where …

Sep 7, 2024
CVE-2024-42023
8.8 HIGH

An improper access control vulnerability allows low-privileged users to execute code with Administrator privileges remotely.

Sep 7, 2024
CVE-2024-42019
8.0 HIGH

A vulnerability that allows an attacker to access the NTLM hash of the Veeam Reporter Service service account. This attack requires user interaction and data …

Sep 7, 2024
CVE-2024-40718
8.8 HIGH

A server side request forgery vulnerability allows a low-privileged user to perform local privilege escalation through exploiting an SSRF vulnerability.

Sep 7, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.