CVE Database

38976+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-34217
7.7 HIGH

TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the addWlProfileClientMode function.

May 14, 2024
CVE-2024-34215
7.3 HIGH

TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setUrlFilterRules function.

May 14, 2024
CVE-2024-34212
7.3 HIGH

TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the CloudACMunualUpdate function.

May 14, 2024
CVE-2024-34211
8.8 HIGH

TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in as root.

May 14, 2024
CVE-2024-34210
7.3 HIGH

TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the CloudACMunualUpdate function via the FileName parameter.

May 14, 2024
CVE-2024-34207
8.8 HIGH

TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setStaticDhcpConfig function.

May 14, 2024
CVE-2024-34205
7.3 HIGH

TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the download_firmware function.

May 14, 2024
CVE-2024-34201
7.3 HIGH

TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the getSaveConfig function.

May 14, 2024
CVE-2024-34200
8.8 HIGH

TOTOLINK CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setIpQosRules function.

May 14, 2024
CVE-2024-34199
8.6 HIGH

TinyWeb 1.94 and below allows unauthenticated remote attackers to cause a denial of service (Buffer Overflow) when sending excessively large elements in the request line.

May 14, 2024
CVE-2024-34196
8.8 HIGH

Totolink AC1200 Wireless Dual Band Gigabit Router A3002RU_V3 Firmware V3.0.0-B20230809.1615 is vulnerable to Buffer Overflow. The "boa" program allows attackers to modify the value of …

May 14, 2024
CVE-2024-34077
7.3 HIGH

MantisBT (Mantis Bug Tracker) is an open source issue tracker. Insufficient access control in the registration and password reset process allows an attacker to reset …

May 14, 2024
CVE-2024-33877
8.8 HIGH

HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5T__conv_struct_opt in H5Tconv.c.

May 14, 2024
CVE-2024-33873
8.8 HIGH

HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5D__scatter_mem in H5Dscatgath.c.

May 14, 2024
CVE-2024-33818
7.5 HIGH

Globitel KSA SpeechLog v8.1 was discovered to contain an Insecure Direct Object Reference (IDOR) via the userID parameter.

May 14, 2024
CVE-2024-33250
7.2 HIGH

An issue in Open-Source Technology Committee SRS real-time video server RS/4.0.268(Leo) and SRS/4.0.195(Leo) allows a remote attacker to execute arbitrary code via a crafted request.

May 14, 2024
CVE-2024-32997
8.4 HIGH

Race condition vulnerability in the binder driver module Impact: Successful exploitation of this vulnerability will affect availability.

May 14, 2024
CVE-2024-32992
7.5 HIGH

Insufficient verification vulnerability in the baseband module Impact: Successful exploitation of this vulnerability will affect availability.

May 14, 2024
CVE-2024-32991
7.5 HIGH

Permission verification vulnerability in the wpa_supplicant module Impact: Successful exploitation of this vulnerability will affect availability.

May 14, 2024
CVE-2024-32739
7.5 HIGH

A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_ptask_verbose" function within …

May 14, 2024
CVE-2024-32738
7.5 HIGH

A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_ptask_lean" function within …

May 14, 2024
CVE-2024-32737
7.5 HIGH

A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_contract_result" function within …

May 14, 2024
CVE-2024-32736
7.5 HIGH

A sql injection vulnerability exists in CyberPower PowerPanel Enterprise prior to v2.8.3. An unauthenticated remote attacker can leak sensitive information via the "query_utask_verbose" function within …

May 14, 2024
CVE-2024-32724
7.5 HIGH

Missing Authorization vulnerability in Woo product importer Sharkdropship dropshipping for Aliexpress, eBay, Amazon, etsy.This issue affects Sharkdropship dropshipping for Aliexpress, eBay, Amazon, etsy: from n/a …

May 14, 2024
CVE-2024-32712
7.5 HIGH

Missing Authorization vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher: from n/a through 4.0.14.

May 14, 2024
CVE-2024-32655
8.1 HIGH

Npgsql is the .NET data provider for PostgreSQL. The `WriteBind()` method in `src/Npgsql/Internal/NpgsqlConnector.FrontendMessages.cs` uses `int` variables to store the message length and the sum of …

May 14, 2024
CVE-2024-32624
7.4 HIGH

HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T__ref_mem_setnull in H5Tref.c (called from H5T__conv_ref in H5Tconv.c), resulting in the corruption of the instruction …

May 14, 2024
CVE-2024-32623
8.8 HIGH

HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5VM_array_fill in H5VM.c (called from H5S_select_elements in H5Spoint.c).

May 14, 2024
CVE-2024-32620
7.4 HIGH

HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5F_addr_decode_len in H5Fint.c, resulting in the corruption of the instruction pointer.

May 14, 2024
CVE-2024-32619
7.4 HIGH

HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T_copy_reopen in H5T.c, resulting in the corruption of the instruction pointer.

May 14, 2024
CVE-2024-32618
7.4 HIGH

HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T__get_native_type in H5Tnative.c, resulting in the corruption of the instruction pointer.

May 14, 2024
CVE-2024-32617
8.8 HIGH

HDF5 Library through 1.14.3 contains a heap-based buffer over-read caused by the unsafe use of strdup in H5MM_xstrdup in H5MM.c (called from H5G__ent_to_link in H5Glink.c).

May 14, 2024
CVE-2024-32616
7.4 HIGH

HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5O__dtype_encode_helper in H5Odtype.c.

May 14, 2024
CVE-2024-32614
8.8 HIGH

HDF5 Library through 1.14.3 has a SEGV in H5VM_memcpyvv in H5VM.c.

May 14, 2024
CVE-2024-32613
7.4 HIGH

HDF5 Library through 1.14.3 contains a heap-based buffer over-read in the function H5HL__fl_deserialize in H5HLcache.c, a different vulnerability than CVE-2024-32612.

May 14, 2024
CVE-2024-32612
7.4 HIGH

HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5HL__fl_deserialize in H5HLcache.c, resulting in the corruption of the instruction pointer, a different vulnerability than …

May 14, 2024
CVE-2024-32609
7.5 HIGH

HDF5 Library through 1.14.3 allows stack consumption in the function H5E_printf_stack in H5Eint.c.

May 14, 2024
CVE-2024-32605
8.8 HIGH

HDF5 Library through 1.14.3 has a heap-based buffer over-read in H5VM_memcpyvv in H5VM.c (called from H5D__compact_readvv in H5Dcompact.c).

May 14, 2024
CVE-2024-31954
7.3 HIGH

An issue was discovered in the installer in Samsung Portable SSD for T5 1.6.10 on Windows. Because it is possible to tamper with the directory …

May 14, 2024
CVE-2024-31771
7.8 HIGH

Insecure Permission vulnerability in TotalAV v.6.0.740 allows a local attacker to escalate privileges via a crafted file

May 14, 2024
CVE-2024-31459
8.0 HIGH

Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, there is a file inclusion issue in the `lib/plugin.php` file. Combined with …

May 14, 2024
CVE-2024-31445
8.8 HIGH

Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, a SQL injection vulnerability in `automation_get_new_graphs_sql` function of `api_automation.php` allows authenticated users …

May 14, 2024
CVE-2024-31441
7.5 HIGH

DataEase is an open source data visualization analysis tool. Due to the lack of restrictions on the connection parameters for the ClickHouse data source, it …

May 14, 2024
CVE-2024-30259
8.2 HIGH

FastDDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to versions 2.14.1, 2.13.5, 2.10.4, and …

May 14, 2024
CVE-2024-30258
8.2 HIGH

FastDDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to versions 2.14.1, 2.13.5, 2.10.4, and …

May 14, 2024
CVE-2024-30172
7.5 HIGH

An issue was discovered in Bouncy Castle Java Cryptography APIs before 1.78. An Ed25519 verification code infinite loop can occur via a crafted signature and …

May 14, 2024
CVE-2024-2662
7.2 HIGH

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to command injection in all versions up to, and including, 1.5.102. …

May 14, 2024
CVE-2024-2441
8.1 HIGH

The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.6.8 allows direct access to menus, allowing an authenticated user with subscriber privileges or above, …

May 14, 2024
CVE-2024-2290
7.2 HIGH

The Advanced Ads plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.52.1 via deserialization of untrusted input …

May 14, 2024
CVE-2024-29857
7.5 HIGH

An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and …

May 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.