CVE Database

38976+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-41118
7.5 HIGH

streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `url` variable on line 47 of `pages/7_📦_Web_Map_Service.py` takes user input, which …

Jul 26, 2024
CVE-2024-40116
8.1 HIGH

An issue in Solar-Log 1000 before v2.8.2 and build 52-23.04.2013 was discovered to store plaintext passwords in the export.html, email.html, and sms.html files -- fixed …

Jul 26, 2024
CVE-2024-38512
7.2 HIGH

A privilege escalation vulnerability was discovered in XCC that could allow an authenticated XCC user with elevated privileges to perform command injection via specially crafted …

Jul 26, 2024
CVE-2024-38511
7.2 HIGH

A privilege escalation vulnerability was discovered in an upload processing functionality of XCC that could allow an authenticated XCC user with elevated privileges to perform …

Jul 26, 2024
CVE-2024-38510
7.2 HIGH

A privilege escalation vulnerability was discovered in the SSH captive command shell interface that could allow an authenticated XCC user with elevated privileges to perform …

Jul 26, 2024
CVE-2024-38509
7.2 HIGH

A privilege escalation vulnerability was discovered in XCC that could allow an authenticated XCC user with elevated privileges to execute arbitrary code via a specially …

Jul 26, 2024
CVE-2024-38508
7.2 HIGH

A privilege escalation vulnerability was discovered in the web interface or SSH captive command shell interface of XCC that could allow an authenticated XCC user …

Jul 26, 2024
CVE-2024-39304
8.8 HIGH

ChurchCRM is an open-source church management system. Versions of the application prior to 5.9.2 are vulnerable to an authenticated SQL injection due to an improper …

Jul 26, 2024
CVE-2024-38872
8.3 HIGH

Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection in the monitoring module.

Jul 26, 2024
CVE-2024-38871
8.3 HIGH

Zohocorp ManageEngine Exchange Reporter Plus versions 5717 and below are vulnerable to the authenticated SQL injection in the reports module.

Jul 26, 2024
CVE-2024-41813
7.5 HIGH

txtdot is an HTTP proxy that parses only text, links, and pictures from pages, removing ads and heavy scripts. Starting in version 1.4.0 and prior …

Jul 26, 2024
CVE-2024-41812
7.5 HIGH

txtdot is an HTTP proxy that parses only text, links, and pictures from pages, removing ads and heavy scripts. Prior to version 1.7.0, a Server-Side …

Jul 26, 2024
CVE-2024-41354
7.1 HIGH

phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/widgets/edit.php

Jul 26, 2024
CVE-2024-41353
7.1 HIGH

phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\groups\edit-group.php

Jul 26, 2024
CVE-2024-24257
7.5 HIGH

An issue in skteco.com Central Control Attendance Machine web management platform v.3.0 allows an attacker to obtain sensitive information via a crafted script to the …

Jul 26, 2024
CVE-2023-50700
7.8 HIGH

Insecure Permissions vulnerability in Deepin dde-file-manager 6.0.54 and earlier allows privileged operations to be called by unprivileged users via the D-Bus method.

Jul 26, 2024
CVE-2024-41357
7.1 HIGH

phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/powerDNS/record-edit.php.

Jul 26, 2024
CVE-2024-41670
7.5 HIGH

In the module "PayPal Official" for PrestaShop 7+ releases prior to version 6.4.2 and for PrestaShop 1.6 releases prior to version 3.18.1, a malicious customer …

Jul 26, 2024
CVE-2024-7062
8.8 HIGH

Nimble Commander suffers from a privilege escalation vulnerability due to the server (info.filesmanager.Files.PrivilegedIOHelperV2) performing improper/insufficient validation of a client’s authorization before executing an operation. Consequently, …

Jul 26, 2024
CVE-2024-41687
7.5 HIGH

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to transmission of password in plain text. A remote attacker could exploit this vulnerability by intercepting transmission …

Jul 26, 2024
CVE-2024-41685
7.5 HIGH

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to missing HTTPOnly flag for the session cookies associated with the router's web management interface. An attacker …

Jul 26, 2024
CVE-2024-35296
8.2 HIGH

Invalid Accept-Encoding header can cause Apache Traffic Server to fail cache lookup and force forwarding requests. This issue affects Apache Traffic Server: from 8.0.0 through …

Jul 26, 2024
CVE-2024-35161
7.5 HIGH

Apache Traffic Server forwards malformed HTTP chunked trailer section to origin servers. This can be utilized for request smuggling and may also lead cache poisoning …

Jul 26, 2024
CVE-2023-38522
7.5 HIGH

Apache Traffic Server accepts characters that are not allowed for HTTP field names and forwards malformed requests to origin servers. This can be utilized for …

Jul 26, 2024
CVE-2024-24623
8.8 HIGH

Softaculous Webuzo contains a command injection vulnerability in the FTP management functionality. A remote, authenticated attacker can exploit this vulnerability to gain code execution on …

Jul 25, 2024
CVE-2024-24622
8.8 HIGH

Softaculous Webuzo contains a command injection in the password reset functionality. A remote, authenticated attacker can exploit this vulnerability to gain code execution on the …

Jul 25, 2024
CVE-2024-41809
7.2 HIGH

OpenObserve is an open-source observability platform. Starting in version 0.4.4 and prior to version 0.10.0, OpenObserve contains a cross-site scripting vulnerability in line 32 of …

Jul 25, 2024
CVE-2024-41808
8.8 HIGH

The OpenObserve open-source observability platform provides the ability to filter logs in a dashboard by the values uploaded in a given log. However, all versions …

Jul 25, 2024
CVE-2024-38288
7.2 HIGH

A command-injection issue in the Certificate Signing Request (CSR) functionality in R-HUB TurboMeeting through 8.x allows authenticated attackers with administrator privileges to execute arbitrary commands …

Jul 25, 2024
CVE-2024-40318
7.2 HIGH

An arbitrary file upload vulnerability in Webkul Qloapps v1.6.0.0 allows attackers to execute arbitrary code via uploading a crafted file.

Jul 25, 2024
CVE-2024-40872
8.4 HIGH

There is an elevation of privilege vulnerability in server and client components of Absolute Secure Access prior to version 13.07. Attackers with local access and …

Jul 25, 2024
CVE-2024-36542
8.8 HIGH

Insecure permissions in kuma v2.7.0 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.

Jul 25, 2024
CVE-2024-7101
7.3 HIGH

A vulnerability, which was classified as critical, has been found in ForIP Tecnologia Administração PABX 1.x. This issue affects some unknown processing of the file …

Jul 25, 2024
CVE-2024-39672
8.4 HIGH

Memory request logic vulnerability in the memory module. Impact: Successful exploitation of this vulnerability will affect integrity and availability.

Jul 25, 2024
CVE-2024-6589
8.8 HIGH

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.2.6.8.2 via the …

Jul 25, 2024
CVE-2024-41706
7.3 HIGH

A stored XSS issue was discovered in Archer Platform 6 before version 2024.06. A remote authenticated malicious Archer user could potentially exploit this to store …

Jul 25, 2024
CVE-2024-41705
7.1 HIGH

A stored XSS issue was discovered in Archer Platform 6.8 before 2024.06. A remote authenticated malicious Archer user could potentially exploit this to store malicious …

Jul 25, 2024
CVE-2024-7047
7.7 HIGH

A cross site scripting vulnerability exists in GitLab CE/EE affecting all versions from 16.6 prior to 17.0.5, 17.1 prior to 17.1.3, 17.2 prior to 17.2.1 …

Jul 25, 2024
CVE-2024-41466
7.5 HIGH

Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the page parameter at ip/goform/NatStaticSetting.

Jul 24, 2024
CVE-2024-41465
7.5 HIGH

Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the funcpara1 parameter at ip/goform/setcfm.

Jul 24, 2024
CVE-2024-41464
7.5 HIGH

Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the mitInterface parameter in ip/goform/RouteStatic

Jul 24, 2024
CVE-2024-41463
7.5 HIGH

Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the entrys parameter at ip/goform/addressNat.

Jul 24, 2024
CVE-2024-41462
7.5 HIGH

Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the page parameter at ip/goform/DhcpListClient.

Jul 24, 2024
CVE-2024-41550
7.2 HIGH

CampCodes Supplier Management System v1.0 is vulnerable to SQL injection via Supply_Management_System/admin/view_invoice_items.php?id= .

Jul 24, 2024
CVE-2024-41135
7.2 HIGH

A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remote authenticated users to run arbitrary commands on the …

Jul 24, 2024
CVE-2024-41134
7.2 HIGH

A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remote authenticated users to run arbitrary commands on the …

Jul 24, 2024
CVE-2024-41133
7.2 HIGH

A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remote authenticated users to run arbitrary commands on the …

Jul 24, 2024
CVE-2024-36534
8.4 HIGH

Insecure permissions in hwameistor v0.14.3 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.

Jul 24, 2024
CVE-2024-33519
7.2 HIGH

A vulnerability in the web-based management interface of HPE Aruba Networking EdgeConnect SD-WAN gateway could allow an authenticated remote attacker to conduct a server-side prototype …

Jul 24, 2024
CVE-2024-40495
8.0 HIGH

A vulnerability was discovered in Linksys Router E2500 with firmware 2.0.00, allows authenticated attackers to execute arbitrary code via the hnd_parentalctrl_unblock function.

Jul 24, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.