CVE Database

38976+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-28725
7.1 HIGH

Cross Site Scripting (XSS) vulnerability in YzmCMS 7.0 allows attackers to run arbitrary code via Ads Management, Carousel Management, and System Settings.

May 6, 2024
CVE-2024-33602
7.4 HIGH

nscd: netgroup cache assumes NSS callback uses in-buffer strings The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory when the NSS callback does …

May 6, 2024
CVE-2024-33601
7.3 HIGH

nscd: netgroup cache may terminate daemon on memory allocation failure The Name Service Cache Daemon's (nscd) netgroup cache uses xmalloc or xrealloc and these functions …

May 6, 2024
CVE-2024-33599
8.1 HIGH

nscd: Stack-based buffer overflow in netgroup cache If the Name Service Cache Daemon's (nscd) fixed size cache is exhausted by client requests then a subsequent …

May 6, 2024
CVE-2024-33118
7.5 HIGH

LuckyFrameWeb v3.5.2 was discovered to contain an arbitrary read vulnerability via the fileDownload method in class com.luckyframe.project.common.CommonController.

May 6, 2024
CVE-2024-3661
7.6 HIGH

DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect …

May 6, 2024
CVE-2024-34412
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Parcel Panel ParcelPanel.This issue affects ParcelPanel: from n/a through 3.8.1.

May 6, 2024
CVE-2024-34386
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Lucian Apostol Auto Affiliate Links.This issue affects Auto Affiliate Links: from …

May 6, 2024
CVE-2024-34378
8.6 HIGH

Missing Authorization vulnerability in LeadConnector.This issue affects LeadConnector: from n/a through 1.7.

May 6, 2024
CVE-2024-34369
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webpushr Web Push Notifications Webpushr allows Reflected XSS.This issue affects Webpushr: from n/a …

May 6, 2024
CVE-2024-34367
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Popup Box Team Popup box allows Cross-Site Scripting (XSS).This issue affects Popup box: from n/a through 4.1.2.

May 6, 2024
CVE-2024-33912
7.1 HIGH

Missing Authorization vulnerability in Academy LMS.This issue affects Academy LMS: from n/a through 1.9.16.

May 6, 2024
CVE-2024-34388
7.5 HIGH

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Scribit GDPR Compliance.This issue affects GDPR Compliance: from n/a through 1.2.5.

May 6, 2024
CVE-2024-33410
8.1 HIGH

SQL injection vulnerability in /model/delete_range_grade.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the id parameter.

May 6, 2024
CVE-2024-33406
7.3 HIGH

SQL injection vulnerability in /model/delete_student_grade_subject.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the index parameter.

May 6, 2024
CVE-2024-33405
8.6 HIGH

SQL injection vulnerability in add_friends.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the friend_index parameter.

May 6, 2024
CVE-2024-33404
8.3 HIGH

A SQL injection vulnerability in /model/add_student_first_payment.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the index parameter.

May 6, 2024
CVE-2024-32807
8.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brevo Sendinblue for WooCommerce allows Relative Path Traversal, Manipulating Web Input to …

May 6, 2024
CVE-2024-34251
7.5 HIGH

An out-of-bound memory read vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to cause a denial of service via the …

May 6, 2024
CVE-2024-34246
7.5 HIGH

wasm3 v0.5.0 was discovered to contain an out-of-bound memory read which leads to segmentation fault via the function "main" in wasm3/platforms/app/main.c.

May 6, 2024
CVE-2024-34092
8.8 HIGH

An issue was discovered in Archer Platform 6 before 2024.04. Authentication was mishandled because lock did not terminate an existing session. 6.14 P3 (6.14.0.3) is …

May 6, 2024
CVE-2024-34091
7.3 HIGH

An issue was discovered in Archer Platform 6 before 2024.04. There is a stored cross-site scripting (XSS) vulnerability. A remote authenticated malicious Archer user could …

May 6, 2024
CVE-2024-34090
7.3 HIGH

An issue was discovered in Archer Platform 6 before 2024.04. There is a stored cross-site scripting (XSS) vulnerability. The login banner in the Archer Control …

May 6, 2024
CVE-2024-34089
7.3 HIGH

An issue was discovered in Archer Platform 6 before 2024.04. There is a stored cross-site scripting (XSS) vulnerability. A remote authenticated malicious Archer user could …

May 6, 2024
CVE-2024-34470
8.6 HIGH

An issue was discovered in HSC Mailinspector 5.2.17-3 through v.5.2.18. An Unauthenticated Path Traversal vulnerability exists in the /public/loader.php file. The path parameter does not …

May 6, 2024
CVE-2024-34252
7.5 HIGH

wasm3 v0.5.0 was discovered to contain a global buffer overflow which leads to segmentation fault via the function "PreserveRegisterIfOccupied" in wasm3/source/m3_compile.c.

May 6, 2024
CVE-2024-34069
7.5 HIGH

Werkzeug is a comprehensive WSGI web application library. The debugger in affected versions of Werkzeug can allow an attacker to execute code on a developer's …

May 6, 2024
CVE-2024-33112
7.5 HIGH

D-Link DIR-845L router v1.01KRb03 and before is vulnerable to Command injection via the hnap_main()func.

May 6, 2024
CVE-2024-32982
8.2 HIGH

Litestar and Starlite is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.8.3, 2.7.2, and 2.6.4, a Local File Inclusion (LFI) vulnerability has been …

May 6, 2024
CVE-2024-32972
7.5 HIGH

go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to 1.13.15, a vulnerable node can be made to consume very large …

May 6, 2024
CVE-2024-23354
8.4 HIGH

Memory corruption when the IOCTL call is interrupted by a signal.

May 6, 2024
CVE-2024-23351
8.4 HIGH

Memory corruption as GPU registers beyond the last protected range can be accessed through LPAC submissions.

May 6, 2024
CVE-2024-21480
7.3 HIGH

Memory corruption while playing audio file having large-sized input buffer.

May 6, 2024
CVE-2024-21477
7.5 HIGH

Transient DOS while parsing a protected 802.11az Fine Time Measurement (FTM) frame.

May 6, 2024
CVE-2024-21476
7.8 HIGH

Memory corruption when the channel ID passed by user is not validated and further used.

May 6, 2024
CVE-2024-21475
7.8 HIGH

Memory corruption when the payload received from firmware is not as per the expected protocol size.

May 6, 2024
CVE-2024-21474
8.4 HIGH

Memory corruption when size of buffer from previous call is used without validation or re-initialization.

May 6, 2024
CVE-2024-21471
8.4 HIGH

Memory corruption when IOMMU unmap of a GPU buffer fails in Linux.

May 6, 2024
CVE-2023-43531
8.4 HIGH

Memory corruption while verifying the serialized header when the key pairs are generated.

May 6, 2024
CVE-2023-43529
7.5 HIGH

Transient DOS while processing IKEv2 Informational request messages, when a malformed fragment packet is received.

May 6, 2024
CVE-2023-33119
8.4 HIGH

Memory corruption while loading a VM from a signed VM image that is not coherent in the processor cache.

May 6, 2024
CVE-2024-4549
7.5 HIGH

A denial of service vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior. When processing an 'ICS Restart!' message, CEBC.exe restarts the system.

May 6, 2024
CVE-2024-33830
8.1 HIGH

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/readDeal.php?mudi=clearWebCache.

May 6, 2024
CVE-2024-33788
8.0 HIGH

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the PinCode parameter at /API/info form endpoint.

May 6, 2024
CVE-2024-3576
8.3 HIGH

The NPort 5100A Series firmware version v1.6 and prior versions are affected by web server XSS vulnerability. The vulnerability is caused by not correctly neutralizing …

May 6, 2024
CVE-2024-33753
8.2 HIGH

Section Camera V2.5.5.3116-S50-SMA-B20160811 and earlier versions allow the accounts and passwords of administrators and users to be changed without authorization.

May 6, 2024
CVE-2023-49675
7.8 HIGH

An unauthenticated local attacker may trick a user to open corrupted project files to execute arbitrary code or crash the system due to an out-of-bounds …

May 6, 2024
CVE-2024-3756
7.5 HIGH

The MF Gig Calendar WordPress plugin through 1.2.1 does not have CSRF checks in some places, which could allow attackers to make logged in Contributors …

May 6, 2024
CVE-2024-34538
7.5 HIGH

Mateso PasswordSafe through 8.13.9.26689 has Weak Cryptography.

May 6, 2024
CVE-2024-20064
7.8 HIGH

In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with …

May 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.