CVE Database

38969+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-8228
8.8 HIGH

A vulnerability was found in Tenda O5 1.0.0.8(5017). It has been classified as critical. This affects the function fromSafeSetMacFilter of the file /goform/setMacFilterList. The manipulation …

Aug 28, 2024
CVE-2024-8227
8.8 HIGH

A vulnerability was found in Tenda O1 1.0.0.7(10648) and classified as critical. Affected by this issue is the function fromDhcpSetSer of the file /goform/DhcpSetSer. The …

Aug 28, 2024
CVE-2024-8226
8.8 HIGH

A vulnerability has been found in Tenda O1 1.0.0.7(10648) and classified as critical. Affected by this vulnerability is the function formSetCfm of the file /goform/setcfm. …

Aug 28, 2024
CVE-2024-8225
8.8 HIGH

A vulnerability, which was classified as critical, was found in Tenda G3 15.11.0.20. Affected is the function formSetSysTime of the file /goform/SetSysTimeCfg. The manipulation of …

Aug 27, 2024
CVE-2024-8224
8.8 HIGH

A vulnerability, which was classified as critical, has been found in Tenda G3 15.11.0.20. This issue affects the function formSetDebugCfg of the file /goform/setDebugCfg. The …

Aug 27, 2024
CVE-2024-8219
7.3 HIGH

A vulnerability was found in code-projects Responsive Hotel Site 1.0. It has been classified as critical. Affected is an unknown function of the file index.php. …

Aug 27, 2024
CVE-2024-8218
7.3 HIGH

A vulnerability was found in code-projects Online Quiz Site 1.0 and classified as critical. This issue affects some unknown processing of the file index.php. The …

Aug 27, 2024
CVE-2024-8217
7.3 HIGH

A vulnerability has been found in SourceCodester E-Commerce Website 1.0 and classified as critical. This vulnerability affects unknown code of the file /Admin/registration.php. The manipulation …

Aug 27, 2024
CVE-2024-45049
7.5 HIGH

Hydra is a Continuous Integration service for Nix based projects. It is possible to trigger evaluations in Hydra without any authentication. Depending on the size …

Aug 27, 2024
CVE-2024-45038
7.5 HIGH

Meshtastic device firmware is a firmware for meshtastic devices to run an open source, off-grid, decentralized, mesh network built to run on affordable, low-power devices. …

Aug 27, 2024
CVE-2024-5991
7.5 HIGH

In function MatchDomainName(), input param str is treated as a NULL terminated string despite being user provided and unchecked. Specifically, the function X509_check_host() takes in …

Aug 27, 2024
CVE-2022-39997
8.0 HIGH

A weak password requirement issue was discovered in Teldats Router RS123, RS123w allows a remote attacker to escalate privileges

Aug 27, 2024
CVE-2024-43783
7.5 HIGH

The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. Instances of …

Aug 27, 2024
CVE-2024-43414
7.5 HIGH

Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Each team can own their slice of the graph independently, empowering them …

Aug 27, 2024
CVE-2024-42851
7.8 HIGH

Buffer Overflow vulnerability in open source exiftags v.1.01 allows a local attacker to execute arbitrary code via the paresetag function.

Aug 27, 2024
CVE-2024-45264
8.8 HIGH

A cross-site request forgery (CSRF) vulnerability in the admin panel in SkySystem Arfa-CMS before 5.1.3124 allows remote attackers to add a new administrator, leading to …

Aug 27, 2024
CVE-2024-44340
8.8 HIGH

D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via keys smartqos_express_devices and smartqos_normal_devices in SetSmartQoSSettings.

Aug 27, 2024
CVE-2024-6632
7.2 HIGH

A vulnerability exists in FileCatalyst Workflow whereby a field accessible to the super admin can be used to perform an SQL injection attack which can …

Aug 27, 2024
CVE-2024-8182
7.5 HIGH

An Unauthenticated Denial of Service (DoS) vulnerability exists in Flowise version 1.8.2 leading to a complete crash of the instance running a vulnerable version due …

Aug 27, 2024
CVE-2024-7940
8.3 HIGH

The product exposes a service that is intended for local only to all network interfaces without any authentication.

Aug 27, 2024
CVE-2024-3982
8.2 HIGH

An attacker with local access to machine where MicroSCADA X SYS600 is installed, could enable the session logging supporting the product and try to exploit …

Aug 27, 2024
CVE-2024-41176
7.3 HIGH

The MPD package included in TwinCAT/BSD allows an authenticated, low-privileged local attacker to induce a Denial-of-Service (DoS) condition on the daemon and execute code in …

Aug 27, 2024
CVE-2024-41174
7.3 HIGH

The IPC-Diagnostics package in TwinCAT/BSD is susceptible to improper input neutralization by a low-privileged local attacker.

Aug 27, 2024
CVE-2024-41173
7.8 HIGH

The IPC-Diagnostics package included in TwinCAT/BSD is vulnerable to a local authentication bypass by a low privileged attacker.

Aug 27, 2024
CVE-2024-7125
7.8 HIGH

Authentication Bypass vulnerability in Hitachi Ops Center Common Services.This issue affects Hitachi Ops Center Common Services: from 10.9.3-00 before 11.0.2-01.

Aug 27, 2024
CVE-2024-45321
8.1 HIGH

The App::cpanminus package through 1.7047 for Perl downloads code via insecure HTTP, enabling code execution for network attackers.

Aug 27, 2024
CVE-2024-43798
8.6 HIGH

Chisel is a fast TCP/UDP tunnel, transported over HTTP, secured via SSH. The Chisel server doesn't ever read the documented `AUTH` environment variable used to …

Aug 26, 2024
CVE-2024-43301
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Fonts Plugin Fonts allows Stored XSS.This issue affects Fonts: from n/a through 3.7.7.

Aug 26, 2024
CVE-2024-43255
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zookatron MyBookTable Bookstore mybooktable.This issue affects MyBookTable Bookstore: from n/a through <= 3.3.9.

Aug 26, 2024
CVE-2024-28077
7.5 HIGH

A denial-of-service issue was discovered on certain GL-iNet devices. Some websites can detect devices exposed to the external network through DDNS, and consequently obtain the …

Aug 26, 2024
CVE-2024-7401
7.5 HIGH

Netskope was notified about a security gap in Netskope Client enrollment process where NSClient is using a static token “Orgkey” as authentication parameter. Since this …

Aug 26, 2024
CVE-2024-8173
7.3 HIGH

A vulnerability, which was classified as critical, was found in code-projects Blood Bank System 1.0. Affected is an unknown function of the file /login.php of …

Aug 26, 2024
CVE-2024-43289
7.5 HIGH

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in gVectors Team wpForo Forum.This issue affects wpForo Forum: from n/a through 2.3.4.

Aug 26, 2024
CVE-2024-42791
8.8 HIGH

A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via /music/ajax.php?action=delete_genre.

Aug 26, 2024
CVE-2024-8169
7.3 HIGH

A vulnerability was found in code-projects Online Quiz Site 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Aug 26, 2024
CVE-2024-8168
7.3 HIGH

A vulnerability was found in code-projects Online Bus Reservation Site 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Aug 26, 2024
CVE-2024-8167
7.3 HIGH

A vulnerability was found in code-projects Job Portal 1.0. It has been classified as critical. Affected is an unknown function of the file /forget.php. The …

Aug 26, 2024
CVE-2024-7987
7.8 HIGH

A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™ that allows a threat actor to execute arbitrary code with System privileges. To …

Aug 26, 2024
CVE-2024-43966
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stark Digital WP Testimonial Widget.This issue affects WP Testimonial Widget: from …

Aug 26, 2024
CVE-2024-44942
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to do sanity check on F2FS_INLINE_DATA flag in inode during GC syzbot reports …

Aug 26, 2024
CVE-2024-44941
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to cover read extent cache access with lock syzbot reports a f2fs bug …

Aug 26, 2024
CVE-2024-44940
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: fou: remove warn in gue_gro_receive on unsupported protocol Drop the WARN_ON_ONCE inn gue_gro_receive if the …

Aug 26, 2024
CVE-2024-41879
7.8 HIGH

Acrobat Reader versions 127.0.2651.105 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the …

Aug 26, 2024
CVE-2024-44934
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: bridge: mcast: wait for previous gc cycles when removing port syzbot hit a use-after-free[1] …

Aug 26, 2024
CVE-2024-44932
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: idpf: fix UAFs when destroying the queues The second tagged commit started sometimes (very rarely, …

Aug 26, 2024
CVE-2024-43900
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: media: xc2028: avoid use-after-free in load_firmware_cb() syzkaller reported use-after-free in load_firmware_cb() [1]. The reason is …

Aug 26, 2024
CVE-2024-43888
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: mm: list_lru: fix UAF for memory cgroup The mem_cgroup_from_slab_obj() is supposed to be called under …

Aug 26, 2024
CVE-2024-43444
8.2 HIGH

Passwords of agents and customers are displayed in plain text in the OTRS admin log module if certain configurations regarding the authentication sources match and …

Aug 26, 2024
CVE-2024-45241
7.5 HIGH

A traversal vulnerability in GeneralDocs.aspx in CentralSquare CryWolf (False Alarm Management) through 2024-08-09 allows unauthenticated attackers to read files outside of the working web directory …

Aug 26, 2024
CVE-2024-41996
7.5 HIGH

Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the …

Aug 26, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.