CVE Database

38969+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-40714
8.3 HIGH

An improper certificate validation vulnerability in TLS certificate validation allows an attacker on the same network to intercept sensitive credentials during restore operations.

Sep 7, 2024
CVE-2024-40713
7.8 HIGH

A vulnerability that allows a user who has been assigned a low-privileged role within Veeam Backup & Replication to alter Multi-Factor Authentication (MFA) settings and …

Sep 7, 2024
CVE-2024-40712
7.8 HIGH

A path traversal vulnerability allows an attacker with a low-privileged account and local access to the system to perform local privilege escalation (LPE).

Sep 7, 2024
CVE-2024-40710
8.8 HIGH

A series of related high-severity vulnerabilities, the most notable enabling remote code execution (RCE) as the service account and extraction of sensitive information (savedcredentials and …

Sep 7, 2024
CVE-2024-40709
7.8 HIGH

A missing authorization vulnerability allows a local low-privileged user on the machine to escalate their privileges to root level.

Sep 7, 2024
CVE-2024-39718
8.1 HIGH

An improper input validation vulnerability that allows a low-privileged user to remotely remove files on the system with permissions equivalent to those of the service …

Sep 7, 2024
CVE-2024-39715
8.5 HIGH

A code injection vulnerability that allows a low-privileged user with REST API access granted to remotely upload arbitrary files to the VSPC server using REST …

Sep 7, 2024
CVE-2024-38651
8.5 HIGH

A code injection vulnerability can allow a low-privileged user to overwrite files on that VSPC server, which can lead to remote code execution on VSPC …

Sep 7, 2024
CVE-2024-36138
8.1 HIGH

Bypass incomplete fix of CVE-2024-27980, that arises from improper handling of batch files with all possible extensions on Windows via child_process.spawn / child_process.spawnSync. A malicious …

Sep 7, 2024
CVE-2023-46809
7.4 HIGH

Node.js versions which bundle an unpatched version of OpenSSL or run against a dynamically linked version of OpenSSL which are unpatched are vulnerable to the …

Sep 7, 2024
CVE-2023-30587
7.5 HIGH

A vulnerability in Node.js version 20 allows for bypassing restrictions set by the --experimental-permission flag using the built-in inspector module (node:inspector). By exploiting the Worker …

Sep 7, 2024
CVE-2023-30584
7.7 HIGH

A vulnerability has been discovered in Node.js version 20, specifically within the experimental permission model. This flaw relates to improper handling of path traversal bypass …

Sep 7, 2024
CVE-2023-30583
7.5 HIGH

fs.openAsBlob() can bypass the experimental permission model when using the file system read restriction with the `--allow-fs-read` flag in Node.js 20. This flaw arises from …

Sep 7, 2024
CVE-2024-40681
7.5 HIGH

IBM MQ 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD could allow an authenticated user in a specifically defined role, …

Sep 7, 2024
CVE-2024-7112
8.8 HIGH

The Pinpoint Booking System – #1 WordPress Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the ‘schedule’ parameter in all versions up …

Sep 7, 2024
CVE-2024-1596
7.2 HIGH

The Ninja Forms - File Uploads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded file (e.g. RTX file) in all versions …

Sep 7, 2024
CVE-2024-45498
8.8 HIGH

Example DAG: example_inlet_event_extra.py shipped with Apache Airflow version 2.10.0 has a vulnerability that allows an authenticated attacker with only DAG trigger permission to execute arbitrary …

Sep 7, 2024
CVE-2024-45034
8.8 HIGH

Apache Airflow versions before 2.10.1 have a vulnerability that allows DAG authors to add local settings to the DAG folder and get it executed by …

Sep 7, 2024
CVE-2024-44845
8.8 HIGH

DrayTek Vigor3900 v1.5.1.6 was discovered to contain an authenticated command injection vulnerability via the value parameter in the filter_string function.

Sep 6, 2024
CVE-2024-44844
8.8 HIGH

DrayTek Vigor3900 v1.5.1.6 was discovered to contain an authenticated command injection vulnerability via the name parameter in the run_command function.

Sep 6, 2024
CVE-2024-34158
7.5 HIGH

Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic due to stack exhaustion.

Sep 6, 2024
CVE-2024-34156
7.5 HIGH

Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion. This is a follow-up to CVE-2022-30635.

Sep 6, 2024
CVE-2024-7652
7.5 HIGH

An error in the ECMA-262 specification relating to Async Generators could have resulted in a type confusion, potentially leading to memory corruption and an exploitable …

Sep 6, 2024
CVE-2024-38642
7.8 HIGH

An improper certificate validation vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow local network users to compromise the security of …

Sep 6, 2024
CVE-2024-38641
7.8 HIGH

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow local network users to …

Sep 6, 2024
CVE-2024-32763
8.8 HIGH

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow …

Sep 6, 2024
CVE-2024-32762
8.2 HIGH

A cross-site scripting (XSS) vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow users to inject malicious code via a …

Sep 6, 2024
CVE-2024-21898
8.8 HIGH

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute …

Sep 6, 2024
CVE-2024-21897
8.9 HIGH

A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to inject …

Sep 6, 2024
CVE-2023-51366
8.7 HIGH

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to read the contents …

Sep 6, 2024
CVE-2023-50360
8.8 HIGH

A SQL injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a …

Sep 6, 2024
CVE-2023-47563
7.4 HIGH

An OS command injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow authenticated users to execute commands via a …

Sep 6, 2024
CVE-2023-39300
7.2 HIGH

An OS command injection vulnerability has been reported to affect legacy QTS. If exploited, the vulnerability could allow authenticated administrators to execute commands via a …

Sep 6, 2024
CVE-2023-39298
7.8 HIGH

A missing authorization vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow local authenticated users to access …

Sep 6, 2024
CVE-2023-34974
8.8 HIGH

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands …

Sep 6, 2024
CVE-2024-8509
7.5 HIGH

A vulnerability was found in Forklift Controller. There is no verification against the authorization header except to ensure it uses bearer authentication. Without an Authorization …

Sep 6, 2024
CVE-2024-45294
8.6 HIGH

The HL7 FHIR Core Artifacts repository provides the java core object handling code, with utilities (including validator), for the Fast Healthcare Interoperability Resources (FHIR) specification. …

Sep 6, 2024
CVE-2024-44408
7.5 HIGH

D-Link DIR-823G v1.0.2B05_20181207 is vulnerable to Information Disclosure. The device allows unauthorized configuration file downloads, and the downloaded configuration files contain plaintext user passwords.

Sep 6, 2024
CVE-2024-8428
8.8 HIGH

The ForumWP – Forum & Discussion Board Plugin plugin for WordPress is vulnerable to Privilege Escalation via Insecure Direct Object Reference in all versions up …

Sep 6, 2024
CVE-2024-6445
7.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in DataFlowX Technology DataDiodeX allows Path Traversal.This issue affects DataDiodeX: from v3.0.0 before …

Sep 6, 2024
CVE-2024-45300
7.5 HIGH

alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5, a race condition allows the user …

Sep 6, 2024
CVE-2024-44739
8.8 HIGH

Sourcecodester Simple Forum Website v1.0 has a SQL injection vulnerability in /php-sqlite-forum/?page=manage_user&id=.

Sep 6, 2024
CVE-2024-1744
7.5 HIGH

Authorization Bypass Through User-Controlled Key, Missing Authorization vulnerability in Ariva Computer Accord ORS allows Retrieve Embedded Sensitive Data.This issue affects Accord ORS: before 7.3.2.1.

Sep 6, 2024
CVE-2023-52916
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: media: aspeed: Fix memory overwrite if timing is 1600x900 When capturing 1600x900, system could crash …

Sep 6, 2024
CVE-2024-7349
7.2 HIGH

The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to blind SQL Injection via the 'order' parameter in …

Sep 6, 2024
CVE-2024-39585
7.9 HIGH

Dell SmartFabric OS10 Software, version(s) 10.5.5.4 through 10.5.5.10 and 10.5.6.x, contain(s) an Use of Hard-coded Password vulnerability. A low privileged attacker with remote access could …

Sep 6, 2024
CVE-2024-38486
7.5 HIGH

Dell SmartFabric OS10 Software, version(s) 10.5.5.4 through 10.5.5.10 and 10.5.6.x , contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. …

Sep 6, 2024
CVE-2024-8480
8.8 HIGH

The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

Sep 6, 2024
CVE-2024-8247
8.8 HIGH

The Newsletters plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.9.9.2. This is due to the plugin not …

Sep 6, 2024
CVE-2024-45401
7.5 HIGH

stripe-cli is a command-line tool for the payment processor Stripe. A vulnerability exists in stripe-cli starting in version 1.11.1 and prior to version 1.21.3 where …

Sep 5, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.