CVE Database

39204+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-30381
8.4 HIGH

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Juniper Networks Paragon Active Assurance Control Center allows a network-adjacent attacker with root access …

Apr 12, 2024
CVE-2024-21598
7.5 HIGH

An Improper Validation of Syntactic Correctness of Input vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows …

Apr 12, 2024
CVE-2023-51515
8.8 HIGH

Missing Authorization vulnerability in Undsgn Uncode Core allows Privilege Escalation.This issue affects Uncode Core: from n/a through 2.8.8.

Apr 12, 2024
CVE-2024-3705
8.8 HIGH

Unrestricted file upload vulnerability in OpenGnsys affecting version 1.1.1d (Espeto). This vulnerability allows an attacker to send a POST request to the endpoint '/opengnsys/images/M_Icons.php' modifying …

Apr 12, 2024
CVE-2024-25545
7.8 HIGH

An issue in Weave Weave Desktop v.7.78.10 allows a local attacker to execute arbitrary code via a crafted script to the nwjs framework component.

Apr 12, 2024
CVE-2020-8006
8.8 HIGH

The server in Circontrol Raption through 5.11.2 has a pre-authentication stack-based buffer overflow that can be exploited to gain run-time control of the device as …

Apr 12, 2024
CVE-2024-3211
8.8 HIGH

The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to SQL Injection via the 'productid' attribute of the ec_addtocart shortcode in all versions …

Apr 12, 2024
CVE-2024-3054
7.2 HIGH

WPvivid Backup & Migration Plugin for WordPress is vulnerable to PHAR Deserialization in all versions up to, and including, 0.9.99 via deserialization of untrusted input …

Apr 12, 2024
CVE-2024-29400
7.5 HIGH

An issue was discovered in RuoYi v4.5.1, allows attackers to obtain sensitive information via the status parameter.

Apr 12, 2024
CVE-2024-27309
7.4 HIGH

While an Apache Kafka cluster is being migrated from ZooKeeper mode to KRaft mode, in some cases ACLs will not be correctly enforced. Two preconditions …

Apr 12, 2024
CVE-2023-49528
8.0 HIGH

Buffer Overflow vulnerability in FFmpeg version n6.1-3-g466799d4f5, allows a local attacker to execute arbitrary code and cause a denial of service (DoS) via the af_dialoguenhance.c:261:5 …

Apr 12, 2024
CVE-2023-44857
8.1 HIGH

An issue in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a crafted script to the sub_21D24 function in …

Apr 12, 2024
CVE-2023-44852
8.2 HIGH

Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a crafted script to the …

Apr 12, 2024
CVE-2024-3092
8.7 HIGH

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 before 16.9.4, all versions starting from 16.10 before 16.10.2. A payload …

Apr 12, 2024
CVE-2024-2279
8.7 HIGH

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.7 to 16.8.6 all versions starting from 16.9 before 16.9.4, all versions …

Apr 12, 2024
CVE-2024-28458
7.5 HIGH

Null Pointer Dereference vulnerability in swfdump in swftools 0.9.2 allows attackers to crash the appliation via the function compileSWFActionCode in action/actioncompiler.c.

Apr 11, 2024
CVE-2024-25852
8.8 HIGH

Linksys RE7000 v2.0.9, v2.0.11, and v2.0.15 have a command execution vulnerability in the "AccessControlList" parameter of the access control function point. An attacker can use …

Apr 11, 2024
CVE-2024-25376
7.8 HIGH

An issue discovered in Thesycon Software Solutions Gmbh & Co. KG TUSBAudio MSI-based installers before 5.68.0 allows a local attacker to execute arbitrary code via …

Apr 11, 2024
CVE-2024-22722
7.2 HIGH

Server Side Template Injection (SSTI) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary commands via the Group Name field under the add forms …

Apr 11, 2024
CVE-2024-22719
8.1 HIGH

SQL Injection vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary SQL commands via the 'keyword' when searching for a client.

Apr 11, 2024
CVE-2023-5394
7.4 HIGH

Server receiving a malformed message that where the GCL message hostname may be too large which may cause a stack overflow; resulting in possible remote …

Apr 11, 2024
CVE-2023-5393
7.4 HIGH

Server receiving a malformed message that causes a disconnect to a hostname may causing a stack overflow resulting in possible remote code execution. Honeywell recommends …

Apr 11, 2024
CVE-2023-5392
7.5 HIGH

C300 information leak due to an analysis feature which allows extracting more memory over the network than required by the function. Honeywell recommends updating to …

Apr 11, 2024
CVE-2024-30273
7.8 HIGH

Illustrator versions 28.3, 27.9.2 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of …

Apr 11, 2024
CVE-2024-30272
7.8 HIGH

Illustrator versions 28.3, 27.9.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the …

Apr 11, 2024
CVE-2024-30271
7.8 HIGH

Illustrator versions 28.3, 27.9.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the …

Apr 11, 2024
CVE-2023-29483
7.0 HIGH

eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from …

Apr 11, 2024
CVE-2024-31285
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Tooltip WordPress Tooltips allows Stored XSS.This issue affects WordPress Tooltips: from n/a through 9.5.3.

Apr 11, 2024
CVE-2024-20797
7.8 HIGH

Animate versions 23.0.4, 24.0.1 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past …

Apr 11, 2024
CVE-2024-20795
7.8 HIGH

Animate versions 23.0.4, 24.0.1 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context …

Apr 11, 2024
CVE-2024-30916
7.1 HIGH

An issue was discovered in eProsima FastDDS v.2.14.0 and before, allows a local attacker to cause a denial of service (DoS) and obtain sensitive information …

Apr 11, 2024
CVE-2024-29399
7.6 HIGH

An issue was discovered in GNU Savane v.3.13 and before, allows a remote attacker to execute arbitrary code and escalate privileges via a crafted file …

Apr 11, 2024
CVE-2024-30884
7.1 HIGH

Reflected Cross-Site Scripting (XSS) vulnerability in Discuz! version X3.4 20220811, allows remote attackers to execute arbitrary code and obtain sensitive information via crafted payload to …

Apr 11, 2024
CVE-2024-25572
8.8 HIGH

Cross-site request forgery (CSRF) vulnerability exists in Ninja Forms prior to 3.4.31. If a website administrator views a malicious page while logging in, unintended operations …

Apr 11, 2024
CVE-2023-6811
7.2 HIGH

The Language Translate Widget for WordPress – ConveyThis plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'api_key’ parameter in all versions up …

Apr 11, 2024
CVE-2024-2741
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Planet IGS-4215-16T2S, affecting firmware version 1.305b210528. This vulnerability could allow a remote attacker to trick some authenticated users into …

Apr 11, 2024
CVE-2024-2740
7.7 HIGH

Information exposure vulnerability in Planet IGS-4215-16T2S, affecting firmware version 1.305b210528. This vulnerability could allow a remote attacker to access some administrative resources due to lack …

Apr 11, 2024
CVE-2024-29019
8.1 HIGH

ESPHome is a system to control microcontrollers remotely through Home Automation systems. API endpoints in dashboard component of ESPHome version 2023.12.9 (command line installation) are …

Apr 11, 2024
CVE-2024-27992
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Link Whisper Link Whisper Free allows Reflected XSS.This issue affects Link Whisper Free: …

Apr 11, 2024
CVE-2023-51672
7.5 HIGH

Missing Authorization vulnerability in FunnelKit FunnelKit Checkout.This issue affects FunnelKit Checkout: from n/a through 3.10.3.

Apr 11, 2024
CVE-2023-51142
7.5 HIGH

An issue in ZKTeco BioTime v.8.5.4 and before allows a remote attacker to obtain sensitive information.

Apr 11, 2024
CVE-2024-31999
7.4 HIGH

@festify/secure-session creates a secure stateless cookie session for Fastify. At the end of the request handling, it will encrypt all data in the session with …

Apr 10, 2024
CVE-2024-29504
7.6 HIGH

Cross Site Scripting vulnerability in Summernote v.0.8.18 and before allows a remote attacker to execute arbtirary code via a crafted payload to the codeview parameter.

Apr 10, 2024
CVE-2024-26362
8.8 HIGH

HTML injection vulnerability in Enpass Password Manager Desktop Client 6.9.2 for Windows and Linux allows attackers to run arbitrary HTML code via creation of crafted …

Apr 10, 2024
CVE-2024-29269
8.8 HIGH

An issue discovered in Telesquare TLR-2005Ksh 1.0.0 and 1.1.4 allows attackers to run arbitrary system commands via the Cmd parameter.

Apr 10, 2024
CVE-2024-23077
7.5 HIGH

JFreeChart v1.5.4 was discovered to be vulnerable to ArrayIndexOutOfBounds via the component /chart/plot/CompassPlot.java. NOTE: this is disputed by multiple third parties who believe there was …

Apr 10, 2024
CVE-2023-52070
8.4 HIGH

JFreeChart v1.5.4 was discovered to be vulnerable to ArrayIndexOutOfBounds via the 'setSeriesNeedle(int index, int type)' method. NOTE: this is disputed by multiple third parties who …

Apr 10, 2024
CVE-2021-47219
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: scsi: scsi_debug: Fix out-of-bound read in resp_report_tgtpgs() The following issue was observed running syzkaller: BUG: …

Apr 10, 2024
CVE-2021-47204
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: dpaa2-eth: fix use-after-free in dpaa2_eth_remove Access to netdev after free_netdev() will cause use-after-free bug. …

Apr 10, 2024
CVE-2021-47200
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/prime: Fix use after free in mmap with drm_gem_ttm_mmap drm_gem_ttm_mmap() drops a reference to the …

Apr 10, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.