CVE Database

38976+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-28749
7.2 HIGH

A remote attacker with high privileges may use a writing file function to inject OS commands.

Jul 9, 2024
CVE-2024-28748
7.2 HIGH

A remote attacker with high privileges may use a reading file function to inject OS commands.

Jul 9, 2024
CVE-2024-5441
8.8 HIGH

The Modern Events Calendar plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the set_featured_image function in all …

Jul 9, 2024
CVE-2024-6166
8.8 HIGH

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to time-based SQL Injection via the ‘addons_order’ parameter in all versions …

Jul 9, 2024
CVE-2024-39597
7.2 HIGH

In SAP Commerce, a user can misuse the forgotten password functionality to gain access to a Composable Storefront B2B site for which early login and …

Jul 9, 2024
CVE-2024-39592
7.7 HIGH

Elements of PDCE does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This allows an attacker to read sensitive …

Jul 9, 2024
CVE-2024-5974
7.2 HIGH

A buffer overflow in WatchGuard Fireware OS could may allow an authenticated remote attacker with privileged management access to execute arbitrary code with system privileges …

Jul 9, 2024
CVE-2024-4944
7.8 HIGH

A local privilege escalation vlnerability in the WatchGuard Mobile VPN with SSL client on Windows enables a local user to execute arbitrary commands with elevated …

Jul 9, 2024
CVE-2024-5793
8.8 HIGH

The Houzez Theme - Functionality plugin for WordPress is vulnerable to SQL Injection via the ‘currency_code’ parameter in all versions up to, and including, 3.2.2 …

Jul 9, 2024
CVE-2024-5549
8.1 HIGH

A CORS misconfiguration in the stitionai/devika repository allows attackers to steal sensitive information such as logs, browser sessions, and settings containing private API keys from …

Jul 9, 2024
CVE-2024-5971
7.5 HIGH

A vulnerability was found in Undertow, where the chunked response hangs after the body was flushed. The response headers and body were sent but the …

Jul 8, 2024
CVE-2024-6227
7.5 HIGH

A vulnerability in aimhubio/aim version 3.19.3 allows an attacker to cause an infinite loop by configuring the remote tracking server to point at itself. This …

Jul 8, 2024
CVE-2024-6409
7.0 HIGH

A race condition vulnerability was discovered in how signals are handled by OpenSSH's server (sshd). If a remote attacker does not authenticate within a set …

Jul 8, 2024
CVE-2024-39896
7.5 HIGH

Directus is a real-time API and App dashboard for managing SQL database content. When relying on SSO providers in combination with local authentication it can …

Jul 8, 2024
CVE-2024-6563
7.5 HIGH

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Renesas arm-trusted-firmware allows Local Execution of Code. This vulnerability is associated with program …

Jul 8, 2024
CVE-2024-39202
8.8 HIGH

D-Link DIR-823X firmware - 240126 was discovered to contain a remote command execution (RCE) vulnerability via the dhcpd_startip parameter at /goform/set_lan_settings.

Jul 8, 2024
CVE-2024-31504
7.5 HIGH

Buffer Overflow vulnerability in SILA Embedded Solutions GmbH freemodbus v.2018-09-12 allows a remtoe attacker to cause a denial of service via the LINUXTCP server component.

Jul 8, 2024
CVE-2024-21778
7.2 HIGH

A heap-based buffer overflow vulnerability exists in the configuration file mib_init_value_array functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted .dat file can lead …

Jul 8, 2024
CVE-2023-50383
7.2 HIGH

Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can …

Jul 8, 2024
CVE-2023-50382
7.2 HIGH

Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can …

Jul 8, 2024
CVE-2023-50381
7.2 HIGH

Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can …

Jul 8, 2024
CVE-2023-50330
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the boa getInfo functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can …

Jul 8, 2024
CVE-2023-50244
7.2 HIGH

Two stack-based buffer overflow vulnerabilities exist in the boa formIpQoS functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can …

Jul 8, 2024
CVE-2023-50243
7.2 HIGH

Two stack-based buffer overflow vulnerabilities exist in the boa formIpQoS functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can …

Jul 8, 2024
CVE-2023-50240
7.2 HIGH

Two stack-based buffer overflow vulnerabilities exist in the boa set_RadvdInterfaceParam functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can …

Jul 8, 2024
CVE-2023-50239
7.2 HIGH

Two stack-based buffer overflow vulnerabilities exist in the boa set_RadvdInterfaceParam functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can …

Jul 8, 2024
CVE-2023-49867
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can …

Jul 8, 2024
CVE-2023-49595
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the boa rollback_control_code functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can …

Jul 8, 2024
CVE-2023-49593
7.2 HIGH

Leftover debug code exists in the boa formSysCmd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623. A specially crafted network request can lead to arbitrary command execution.

Jul 8, 2024
CVE-2023-49073
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the boa formFilter functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can …

Jul 8, 2024
CVE-2023-48270
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the boa formDnsv6 functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can …

Jul 8, 2024
CVE-2023-47856
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the boa set_RadvdPrefixParam functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can …

Jul 8, 2024
CVE-2023-47677
8.8 HIGH

A cross-site request forgery (csrf) vulnerability exists in the boa CSRF protection functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted network request can …

Jul 8, 2024
CVE-2023-45742
7.2 HIGH

An integer overflow vulnerability exists in the boa updateConfigIntoFlash functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead …

Jul 8, 2024
CVE-2023-45215
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the boa setRepeaterSsid functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can …

Jul 8, 2024
CVE-2023-41251
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the boa formRoute functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can …

Jul 8, 2024
CVE-2023-34435
7.2 HIGH

A firmware update vulnerability exists in the boa formUpload functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted network packets can lead to arbitrary …

Jul 8, 2024
CVE-2024-39742
8.1 HIGH

IBM MQ Operator 3.2.2 and IBM MQ Operator 2.0.24 could allow a user to bypass authentication under certain configurations due to a partial string comparison …

Jul 8, 2024
CVE-2024-37999
7.8 HIGH

A vulnerability has been identified in Medicalis Workflow Orchestrator (All versions). The affected application executes as a trusted account with high privileges and network access. …

Jul 8, 2024
CVE-2024-27459
7.8 HIGH

The interactive service in OpenVPN 2.6.9 and earlier allows an attacker to send data causing a stack overflow which can be used to execute arbitrary …

Jul 8, 2024
CVE-2024-24974
7.5 HIGH

The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service pipe to be accessed remotely, which allows a remote attacker to interact with …

Jul 8, 2024
CVE-2024-38330
7.0 HIGH

IBM System Management for i 7.2, 7.3, and 7.4 could allow a local user to gain elevated privileges due to an unqualified library program call. …

Jul 8, 2024
CVE-2024-3651
7.5 HIGH

A vulnerability was identified in the kjd/idna library, specifically within the `idna.encode()` function, affecting version 3.6. The issue arises from the function's handling of crafted …

Jul 7, 2024
CVE-2024-40597
7.5 HIGH

An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. It can expose suppressed information for log events. (The log_deleted attribute is not …

Jul 7, 2024
CVE-2024-39486
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/drm_file: Fix pid refcounting race <[email protected]>, Maxime Ripard <[email protected]>, Thomas Zimmermann <[email protected]> filp->pid is supposed …

Jul 6, 2024
CVE-2024-37260
7.2 HIGH

Server-Side Request Forgery (SSRF) vulnerability in Theme-Ruby Foxiz.This issue affects Foxiz: from n/a through 2.3.5.

Jul 6, 2024
CVE-2024-39182
7.5 HIGH

An information disclosure vulnerability in ISPmanager v6.98.0 allows attackers to access sensitive details of the root user's session via an arbitrary command (ISP6-1779).

Jul 5, 2024
CVE-2024-33862
7.5 HIGH

A buffer-management vulnerability in OPC Foundation OPCFoundation.NetStandard.Opc.Ua.Core before 1.05.374.54 could allow remote attackers to exhaust memory resources. It is triggered when the system receives an …

Jul 5, 2024
CVE-2024-5753
7.5 HIGH

vanna-ai/vanna version v0.3.4 is vulnerable to SQL injection in some file-critical functions such as `pg_read_file()`. This vulnerability allows unauthenticated remote users to read arbitrary local …

Jul 5, 2024
CVE-2024-39696
8.8 HIGH

Evmos is a decentralized Ethereum Virtual Machine chain on the Cosmos Network. Prior to version 19.0.0, a user can create a vesting account with a …

Jul 5, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.