CVE Database

39204+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-4244
8.8 HIGH

A vulnerability classified as critical was found in Tenda W9 1.0.0.7(4456). Affected by this vulnerability is the function fromDhcpSetSer of the file /goform/DhcpSetSer. The manipulation …

Apr 26, 2024
CVE-2024-4243
8.8 HIGH

A vulnerability classified as critical has been found in Tenda W9 1.0.0.7(4456). Affected is the function formwrlSSIDset of the file /goform/wifiSSIDset. The manipulation of the …

Apr 26, 2024
CVE-2024-3052
7.5 HIGH

Malformed S2 Nonce Get command classes can be sent to crash the gateway. A hard reset is required to recover the gateway.

Apr 26, 2024
CVE-2024-3051
7.5 HIGH

Malformed Device Reset Locally command classes can be sent to temporarily deny service to an end device. Any frames sent by the end device will …

Apr 26, 2024
CVE-2024-31551
7.5 HIGH

Directory Traversal vulnerability in lib/admin/image.admin.php in cmseasy v7.7.7.9 20240105 allows attackers to delete arbitrary files via crafted GET request.

Apr 26, 2024
CVE-2024-4242
8.8 HIGH

A vulnerability was found in Tenda W9 1.0.0.7(4456). It has been rated as critical. This issue affects the function formwrlSSIDget of the file /goform/wifiSSIDget. The …

Apr 26, 2024
CVE-2024-4241
8.8 HIGH

A vulnerability was found in Tenda W9 1.0.0.7(4456). It has been declared as critical. This vulnerability affects the function formQosManageDouble_auto. The manipulation of the argument …

Apr 26, 2024
CVE-2024-4240
8.8 HIGH

A vulnerability was found in Tenda W9 1.0.0.7(4456). It has been classified as critical. This affects the function formQosManageDouble_user. The manipulation of the argument ssidIndex …

Apr 26, 2024
CVE-2024-4239
8.8 HIGH

A vulnerability was found in Tenda AX1806 1.0.0.1 and classified as critical. Affected by this issue is the function formSetRebootTimer of the file /goform/SetRebootTimer. The …

Apr 26, 2024
CVE-2024-32883
7.7 HIGH

MCUboot is a secure bootloader for 32-bits microcontrollers. MCUboot uses a TLV (tag-length-value) structure to represent the meta data associated with an image. The TLVs …

Apr 26, 2024
CVE-2024-32878
7.1 HIGH

Llama.cpp is LLM inference in C/C++. There is a use of uninitialized heap variable vulnerability in gguf_init_from_file, the code will free this uninitialized variable later. …

Apr 26, 2024
CVE-2024-31502
8.1 HIGH

An issue in Insurance Management System v.1.0.0 and before allows a remote attacker to escalate privileges via a crafted POST request to /admin/core/new_staff.

Apr 26, 2024
CVE-2024-4238
8.8 HIGH

A vulnerability has been found in Tenda AX1806 1.0.0.1 and classified as critical. Affected by this vulnerability is the function formSetDeviceName of the file /goform/SetOnlineDevName. …

Apr 26, 2024
CVE-2022-48611
7.8 HIGH

A logic issue was addressed with improved checks. This issue is fixed in iTunes 12.12.4 for Windows. A local attacker may be able to elevate …

Apr 26, 2024
CVE-2024-4237
8.8 HIGH

A vulnerability, which was classified as critical, was found in Tenda AX1806 1.0.0.1. Affected is the function R7WebsSecurityHandler of the file /goform/execCommand. The manipulation of …

Apr 26, 2024
CVE-2024-28327
8.4 HIGH

Asus RT-N12+ B1 router stores user passwords in plaintext, which could allow local attackers to obtain unauthorized access and modify router settings.

Apr 26, 2024
CVE-2024-4236
8.8 HIGH

A vulnerability, which was classified as critical, has been found in Tenda AX1803 1.0.0.1. This issue affects the function formSetSysToolDDNS of the file /goform/SetDDNSCfg. The …

Apr 26, 2024
CVE-2024-33343
8.8 HIGH

D-Link DIR-822+ V1.0.5 was found to contain a command injection in ChgSambaUserSettings function of prog.cgi, which allows remote attackers to execute arbitrary commands via shell.

Apr 26, 2024
CVE-2024-33342
7.5 HIGH

D-Link DIR-822+ V1.0.5 was found to contain a command injection in SetPlcNetworkpwd function of prog.cgi, which allows remote attackers to execute arbitrary commands via shell.

Apr 26, 2024
CVE-2024-33258
7.1 HIGH

Jerryscript commit ff9ff8f was discovered to contain a segmentation violation via the component vm_loop at jerry-core/vm/vm.c.

Apr 26, 2024
CVE-2024-27124
7.5 HIGH

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands …

Apr 26, 2024
CVE-2023-51794
7.8 HIGH

Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/af_stereowiden.c:120:69.

Apr 26, 2024
CVE-2023-51365
8.7 HIGH

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to read the contents …

Apr 26, 2024
CVE-2023-51364
8.7 HIGH

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to read the contents …

Apr 26, 2024
CVE-2023-50363
7.4 HIGH

An incorrect authorization vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to bypass intended …

Apr 26, 2024
CVE-2024-1789
7.2 HIGH

The WP SMTP plugin for WordPress is vulnerable to SQL Injection via the 'search' parameter in versions 1.2 to 1.2.6 due to insufficient escaping on …

Apr 26, 2024
CVE-2023-6116
8.9 HIGH

Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the camera. An attacker could inject malicious …

Apr 26, 2024
CVE-2023-6096
7.4 HIGH

Vladimir Kononovich, a Security Researcher has found a flaw that using a inappropriate encryption logic on the DVR. firmware encryption is broken and allows to …

Apr 26, 2024
CVE-2023-6095
8.9 HIGH

Vladimir Kononovich, a Security Researcher has found a flaw that allows for a remote code execution on the DVR. An attacker could inject malicious HTTP …

Apr 26, 2024
CVE-2024-4056
7.5 HIGH

Denial of service condition in M-Files Server in versions before 24.4.13592.4 and after 23.11 (excluding 24.2 LTS) allows unauthenticated user to consume computing resources.

Apr 26, 2024
CVE-2024-3075
8.1 HIGH

The MM-email2image WordPress plugin through 0.2.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the …

Apr 26, 2024
CVE-2024-3154
7.2 HIGH

A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation. Any user who can create a pod …

Apr 26, 2024
CVE-2024-32406
7.5 HIGH

Server-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1 allows a remote attacker to execute arbitrary code via a crafted payload to the Batch-Issue …

Apr 26, 2024
CVE-2024-4163
8.0 HIGH

The Skylab IGX IIoT Gateway allowed users to connect to it via a limited shell terminal (IGX). However, it was discovered that the process was …

Apr 26, 2024
CVE-2024-31755
7.6 HIGH

cJSON v1.7.17 was discovered to contain a segmentation violation, which can trigger through the second parameter of function cJSON_SetValuestring at cJSON.c.

Apr 26, 2024
CVE-2024-33673
7.8 HIGH

An issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. Improper access controls allow for DLL Hijacking in the Windows DLL Search path.

Apr 26, 2024
CVE-2024-33672
7.7 HIGH

An issue was discovered in Veritas NetBackup before 10.4. The Multi-Threaded Agent used in NetBackup can be leveraged to perform arbitrary file deletion on protected …

Apr 26, 2024
CVE-2024-33671
7.7 HIGH

An issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. The Backup Exec Deduplication Multi-threaded Streaming Agent can be leveraged to perform arbitrary …

Apr 26, 2024
CVE-2024-33666
8.6 HIGH

An issue was discovered in Zammad before 6.3.0. Users with customer access to a ticket could have accessed time accounting details of this ticket via …

Apr 26, 2024
CVE-2024-31609
7.1 HIGH

Cross Site Scripting (XSS) vulnerability in BOSSCMS v3.10 allows attackers to run arbitrary code via the header code and footer code fields in code configuration.

Apr 25, 2024
CVE-2024-32324
7.8 HIGH

Buffer Overflow vulnerability in Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 v.3.2 allows a local attacker to execute arbitrary code via the vpn_client_ip variable of the …

Apr 25, 2024
CVE-2024-3625
7.3 HIGH

A flaw was found in Quay, where Quay's database is stored in plain text in mirror-registry on Jinja's config.yaml file. This issue leaves the possibility …

Apr 25, 2024
CVE-2024-3624
7.3 HIGH

A flaw was found in how Quay's database is stored in plain-text in mirror-registry on the jinja's config.yaml file. This flaw allows a malicious actor …

Apr 25, 2024
CVE-2024-3622
8.8 HIGH

A flaw was found when using mirror-registry to install Quay. It uses a default secret, which is stored in plain-text format in one of the …

Apr 25, 2024
CVE-2024-32358
7.5 HIGH

An issue in Jpress v.5.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the custom plug-in module function, a different …

Apr 25, 2024
CVE-2024-28241
7.3 HIGH

The GLPI Agent is a generic management agent. Prior to version 1.7.2, a local user can modify GLPI-Agent code or used DLLs to modify agent …

Apr 25, 2024
CVE-2024-28240
7.3 HIGH

The GLPI Agent is a generic management agent. A vulnerability that only affects GLPI-Agent installed on windows via MSI packaging can allow a local user …

Apr 25, 2024
CVE-2024-1657
8.1 HIGH

A flaw was found in the ansible automation platform. An insecure WebSocket connection was being used in installation from the Ansible rulebook EDA server. An …

Apr 25, 2024
CVE-2024-1139
7.7 HIGH

A credentials leak vulnerability was found in the cluster monitoring operator in OCP. This issue may allow a remote attacker who has basic login credentials …

Apr 25, 2024
CVE-2023-6596
7.5 HIGH

An incomplete fix was shipped for the Rapid Reset (CVE-2023-44487/CVE-2023-39325) vulnerability for an OpenShift Containers.

Apr 25, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.