CVE Database

39204+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-23755
8.8 HIGH

ClickUp Desktop before 3.3.77 on macOS and Windows allows code injection because of specific Electron Fuses. There is inadequate protection against code injection through settings …

Mar 23, 2024
CVE-2024-1603
7.5 HIGH

paddlepaddle/paddle 2.6.0 allows arbitrary file read via paddle.vision.ops.read_file.

Mar 23, 2024
CVE-2024-24832
8.2 HIGH

Missing Authorization vulnerability in Metagauss EventPrime.This issue affects EventPrime: from n/a through 3.3.9.

Mar 23, 2024
CVE-2021-33633
7.3 HIGH

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in openEuler aops-ceres on Linux allows Command Injection. This vulnerability is …

Mar 23, 2024
CVE-2024-2025
8.8 HIGH

The "BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages" plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and …

Mar 23, 2024
CVE-2024-29059
7.5 HIGH KEV

.NET Framework Information Disclosure Vulnerability

Mar 23, 2024
CVE-2024-29190
7.5 HIGH

Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. In version 3.9.5 Beta and …

Mar 22, 2024
CVE-2023-5685
7.5 HIGH

A flaw was found in XNIO. The XNIO NotifierState that can cause a Stack Overflow Exception when the chain of notifier states becomes problematically large …

Mar 22, 2024
CVE-2024-29499
7.4 HIGH

Anchor CMS v0.12.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via /anchor/admin/users/delete/2.

Mar 22, 2024
CVE-2024-29366
8.8 HIGH

A command injection vulnerability exists in the cgibin binary in DIR-845L router firmware <= v1.01KRb03.

Mar 22, 2024
CVE-2024-29184
8.0 HIGH

FreeScout is a self-hosted help desk and shared mailbox. A Stored Cross-Site Scripting (XSS) vulnerability has been identified within the Signature Input Field of the …

Mar 22, 2024
CVE-2024-2228
7.1 HIGH

This vulnerability allows an authenticated user to perform a Lifecycle Manager flow or other QuickLink for a target user outside of the defined QuickLink Population.

Mar 22, 2024
CVE-2023-41099
7.8 HIGH

In the Windows installer in Atos Eviden CardOS API before 5.5.5.2811, Local Privilege Escalation can occur.(from a regular user to SYSTEM).

Mar 22, 2024
CVE-2024-2725
7.5 HIGH

Information exposure vulnerability in the CIGESv2 system. A remote attacker might be able to access /vendor/composer/installed.json and retrieve all installed packages used by the application.

Mar 22, 2024
CVE-2024-2449
7.5 HIGH

A cross-site request forgery vulnerability has been identified in LoadMaster. It is possible for a malicious actor, who has prior knowledge of the IP or …

Mar 22, 2024
CVE-2024-2448
8.4 HIGH

An OS command injection vulnerability has been identified in LoadMaster. An authenticated UI user with any permission settings may be able to inject commands into …

Mar 22, 2024
CVE-2024-29944
8.4 HIGH

An attacker was able to inject an event handler into a privileged object that would allow arbitrary JavaScript execution in the parent process. Note: This …

Mar 22, 2024
CVE-2024-28559
8.8 HIGH

SQL injection vulnerability in Niushop B2B2C v.5.3.3 and before allows an attacker to escalate privileges via the setPrice() function of the Goodsbatchset.php component.

Mar 22, 2024
CVE-2024-28824
8.8 HIGH

Least privilege violation and reliance on untrusted inputs in the mk_informix Checkmk agent plugin before Checkmk 2.3.0b4 (beta), 2.2.0p24, 2.1.0p41 and 2.0.0 (EOL) allows local …

Mar 22, 2024
CVE-2024-1848
7.8 HIGH

Heap-based Buffer Overflow, Memory Corruption, Out-Of-Bounds Read, Out-Of-Bounds Write, Stack-based Buffer Overflow, Type Confusion, Uninitialized Variable, Use-After-Free vulnerabilities exist in the file reading procedure in …

Mar 22, 2024
CVE-2024-0638
8.2 HIGH

Least privilege violation in the Checkmk agent plugins mk_oracle, mk_oracle.ps1, and mk_oracle_crs before Checkmk 2.3.0b4 (beta), 2.2.0p24, 2.1.0p41 and 2.0.0 (EOL) allows local users to …

Mar 22, 2024
CVE-2024-2815
8.8 HIGH

A vulnerability classified as critical has been found in Tenda AC15 15.03.20_multi. Affected is the function R7WebsSecurityHandler of the file /goform/execCommand of the component Cookie …

Mar 22, 2024
CVE-2024-2814
8.8 HIGH

A vulnerability was found in Tenda AC15 15.03.20_multi. It has been rated as critical. This issue affects the function fromDhcpListClient of the file /goform/DhcpListClient. The …

Mar 22, 2024
CVE-2024-2813
8.8 HIGH

A vulnerability was found in Tenda AC15 15.03.20_multi. It has been declared as critical. This vulnerability affects the function form_fast_setting_wifi_set of the file /goform/fast_setting_wifi_set. The …

Mar 22, 2024
CVE-2024-2811
8.8 HIGH

A vulnerability was found in Tenda AC15 15.03.20_multi and classified as critical. Affected by this issue is the function formWifiWpsStart of the file /goform/WifiWpsStart. The …

Mar 22, 2024
CVE-2024-2810
8.8 HIGH

A vulnerability has been found in Tenda AC15 15.03.05.18/15.03.20_multi and classified as critical. Affected by this vulnerability is the function formWifiWpsOOB of the file /goform/WifiWpsOOB. …

Mar 22, 2024
CVE-2024-2809
8.8 HIGH

A vulnerability, which was classified as critical, was found in Tenda AC15 15.03.05.18/15.03.20_multi. Affected is the function formSetFirewallCfg of the file /goform/SetFirewallCfg. The manipulation of …

Mar 22, 2024
CVE-2024-2808
8.8 HIGH

A vulnerability, which was classified as critical, has been found in Tenda AC15 15.03.05.18/15.03.20_multi. This issue affects the function formQuickIndex of the file /goform/QuickIndex. The …

Mar 22, 2024
CVE-2024-2807
8.8 HIGH

A vulnerability classified as critical was found in Tenda AC15 15.03.05.18/15.03.20_multi. This vulnerability affects the function formExpandDlnaFile of the file /goform/expandDlnaFile. The manipulation of the …

Mar 22, 2024
CVE-2024-2806
8.8 HIGH

A vulnerability classified as critical has been found in Tenda AC15 15.03.05.18/15.03.20_multi. This affects the function addWifiMacFilter of the file /goform/addWifiMacFilter. The manipulation of the …

Mar 22, 2024
CVE-2024-25808
8.3 HIGH

Cross-site Request Forgery (CSRF) vulnerability in Lychee version 3.1.6, allows remote attackers to execute arbitrary code via the create new album function.

Mar 22, 2024
CVE-2024-2805
8.8 HIGH

A vulnerability was found in Tenda AC15 15.03.05.18/15.03.20_multi. It has been rated as critical. Affected by this issue is the function formSetSpeedWan of the file …

Mar 22, 2024
CVE-2024-29031
7.5 HIGH

Meshery is an open source, cloud native manager that enables the design and management of Kubernetes-based infrastructure and applications. A SQL injection vulnerability in Meshery …

Mar 21, 2024
CVE-2024-28171
8.1 HIGH

It is possible to perform a path traversal attack and write outside of the intended directory. If a file name is specified that already exists …

Mar 21, 2024
CVE-2024-28040
8.8 HIGH

SQL injection vulnerability exists in GetDIAE_astListParameters.

Mar 21, 2024
CVE-2024-25567
8.1 HIGH

Path traversal attack is possible and write outside of the intended directory and may access sensitive information. If a file name is specified that already …

Mar 21, 2024
CVE-2024-23975
8.8 HIGH

SQL injection vulnerability exists in GetDIAE_slogListParameters.

Mar 21, 2024
CVE-2024-23494
8.8 HIGH

SQL injection vulnerability exists in GetDIAE_unListParameters.

Mar 21, 2024
CVE-2024-28891
8.8 HIGH

SQL injection vulnerability exists in the script Handler_CFG.ashx.

Mar 21, 2024
CVE-2024-28521
7.8 HIGH

SQL Injection vulnerability in Netcome NS-ASG Application Security Gateway v.6.3.1 allows a local attacker to execute arbitrary code and obtain sensitive information via a crafted …

Mar 21, 2024
CVE-2024-28119
8.8 HIGH

Grav is an open-source, flat-file content management system. Prior to version 1.7.45, due to the unrestricted access to twig extension class from grav context, an …

Mar 21, 2024
CVE-2024-28118
8.8 HIGH

Grav is an open-source, flat-file content management system. Prior to version 1.7.45, due to the unrestricted access to twig extension class from Grav context, an …

Mar 21, 2024
CVE-2024-28117
8.8 HIGH

Grav is an open-source, flat-file content management system. Prior to version 1.7.45, Grav validates accessible functions through the Utils::isDangerousFunction function, but does not impose restrictions …

Mar 21, 2024
CVE-2024-28116
8.8 HIGH

Grav is an open-source, flat-file content management system. Grav CMS prior to version 1.7.45 is vulnerable to a Server-Side Template Injection (SSTI), which allows any …

Mar 21, 2024
CVE-2024-28029
8.8 HIGH

Privileges are not fully verified server-side, which can be abused by a user with limited privileges to bypass authorization and access privileged functionality.

Mar 21, 2024
CVE-2024-27921
8.8 HIGH

Grav is an open-source, flat-file content management system. A file upload path traversal vulnerability has been identified in the application prior to version 1.7.45, enabling …

Mar 21, 2024
CVE-2024-25937
8.8 HIGH

SQL injection vulnerability exists in the script DIAE_tagHandler.ashx.

Mar 21, 2024
CVE-2024-24272
7.1 HIGH

An issue in iTop DualSafe Password Manager & Digital Vault before 1.4.24 allows a local attacker to obtain sensitive information via leaked credentials as plaintext …

Mar 21, 2024
CVE-2024-2764
8.8 HIGH

A vulnerability, which was classified as critical, was found in Tenda AC10U 15.03.06.48. This affects the function formSetPPTPServer of the file /goform/SetPptpServerCfg. The manipulation of …

Mar 21, 2024
CVE-2024-2763
8.8 HIGH

A vulnerability, which was classified as critical, has been found in Tenda AC10U 15.03.06.48. Affected by this issue is the function formSetCfm of the file …

Mar 21, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.