CVE Database

39204+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-50677
8.8 HIGH

An issue in NETGEAR-DGND4000 v.1.1.00.15_1.00.15 allows a remote attacker to escalate privileges via the next_file parameter to the /setup.cgi component.

Mar 14, 2024
CVE-2024-1713
7.2 HIGH

A user who can create objects in a database with plv8 3.2.1 installed is able to cause deferred triggers to execute as the Superuser during …

Mar 14, 2024
CVE-2024-0860
8.0 HIGH

The affected product is vulnerable to a cleartext transmission of sensitive information vulnerability, which may allow an attacker to capture packets to craft their own …

Mar 14, 2024
CVE-2024-28425
7.5 HIGH

greykite v1.0.0 was discovered to contain an arbitrary file upload vulnerability in the load_obj function at /templates/pickle_utils.py. This vulnerability allows attackers to execute arbitrary code …

Mar 14, 2024
CVE-2024-28424
8.8 HIGH

zenml v0.55.4 was discovered to contain an arbitrary file upload vulnerability in the load function at /materializers/cloudpickle_materializer.py. This vulnerability allows attackers to execute arbitrary code …

Mar 14, 2024
CVE-2024-27301
7.3 HIGH

Support App is an opensource application specialized in managing Apple devices. It's possible to abuse a vulnerability inside the postinstall installer script to make the …

Mar 14, 2024
CVE-2024-27266
8.2 HIGH

IBM Maximo Application Suite 7.6.1.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this …

Mar 14, 2024
CVE-2024-22346
8.4 HIGH

Db2 for IBM i 7.2, 7.3, 7.4, and 7.5 infrastructure could allow a local user to gain elevated privileges due to an unqualified library call. …

Mar 14, 2024
CVE-2023-42938
7.8 HIGH

A logic issue was addressed with improved checks. This issue is fixed in iTunes 12.13.1 for Windows. A local attacker may be able to elevate …

Mar 14, 2024
CVE-2024-28181
8.1 HIGH

turbo_boost-commands is a set of commands to help you build robust reactive applications with Rails & Hotwire. TurboBoost Commands has existing protections in place to …

Mar 14, 2024
CVE-2023-32666
7.2 HIGH

On-chip debug and test interface with improper access control in some 4th Generation Intel(R) Xeon(R) Processors when using Intel(R) SGX or Intel(R) TDX may allow …

Mar 14, 2024
CVE-2023-32282
7.2 HIGH

Race condition in BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

Mar 14, 2024
CVE-2023-50168
7.7 HIGH

Pega Platform from 6.x to 8.8.4 is affected by an XXE issue with PDF Generation.

Mar 14, 2024
CVE-2024-1623
7.7 HIGH

Insufficient session timeout vulnerability in the FAST3686 V2 Vodafone router from Sagemcom. This vulnerability could allow a local attacker to access the administration panel without …

Mar 14, 2024
CVE-2024-28746
8.1 HIGH

Apache Airflow, versions 2.8.0 through 2.8.2, has a vulnerability that allows an authenticated user with limited permissions to access resources such as variables, connections, etc …

Mar 14, 2024
CVE-2024-22397
8.3 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in the SonicOS SSLVPN portal allows a remote authenticated attacker as a firewall 'admin' user …

Mar 14, 2024
CVE-2024-1882
7.2 HIGH

This vulnerability allows an already authenticated admin user to create a malicious payload that could be leveraged for remote code execution on the server hosting …

Mar 14, 2024
CVE-2024-25652
7.6 HIGH

In Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or with access to Report functionality via UNLIMITED ADMIN …

Mar 14, 2024
CVE-2024-1654
7.2 HIGH

This vulnerability potentially allows unauthorized write operations which may lead to remote code execution. An attacker must already have authenticated admin access and knowledge of …

Mar 14, 2024
CVE-2024-1222
8.6 HIGH

This allows attackers to use a maliciously formed API request to gain access to an API authorization level with elevated privileges. This applies to a …

Mar 14, 2024
CVE-2024-25228
8.8 HIGH

Vinchin Backup and Recovery 7.2 and Earlier is vulnerable to Authenticated Remote Code Execution (RCE) via the getVerifydiyResult function in ManoeuvreHandler.class.php.

Mar 14, 2024
CVE-2023-38534
8.6 HIGH

Improper authentication vulnerability in OpenText™ Exceed Turbo X affecting versions 12.5.0 and 12.5.1. The vulnerability could allow disclosure of restricted information in unauthenticated RPC.

Mar 13, 2024
CVE-2020-11862
8.6 HIGH

Allocation of Resources Without Limits or Throttling vulnerability in OpenText NetIQ Privileged Account Manager on Linux, Windows, 64 bit allows Flooding.This issue affects NetIQ Privileged …

Mar 13, 2024
CVE-2024-24105
7.8 HIGH

SQL Injection vulnerability in Code-projects Computer Science Time Table System 1.0 allows attackers to run arbitrary code via adminFormvalidation.php.

Mar 13, 2024
CVE-2024-22167
7.9 HIGH

A potential DLL hijacking vulnerability in the SanDisk PrivateAccess application for Windows that could lead to arbitrary code execution in the context of the system …

Mar 13, 2024
CVE-2023-41504
8.8 HIGH

SQL Injection vulnerability in Student Enrollment In PHP 1.0 allows attackers to run arbitrary code via the Student Search function.

Mar 13, 2024
CVE-2024-24693
7.2 HIGH

Improper access control in the installer for Zoom Rooms Client for Windows before version 5.17.5 may allow an authenticated user to conduct a denial of …

Mar 13, 2024
CVE-2024-0801
7.5 HIGH

A denial of service vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in ASNative.dll.

Mar 13, 2024
CVE-2024-0800
8.8 HIGH

A path traversal vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in edge-app-base-webui.jar!com.ca.arcserve.edge.app.base.ui.server.servlet.ImportNodeServlet.

Mar 13, 2024
CVE-2024-28195
8.1 HIGH

your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify versions < 1.9.0 do not protect the API and login flow against Cross-Site Request …

Mar 13, 2024
CVE-2024-27952
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Codeus Advanced Sermons allows Reflected XSS.This issue affects Advanced Sermons: from n/a …

Mar 13, 2024
CVE-2024-20327
7.4 HIGH

A vulnerability in the PPP over Ethernet (PPPoE) termination feature of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers could allow …

Mar 13, 2024
CVE-2024-20320
7.8 HIGH

A vulnerability in the SSH client feature of Cisco IOS XR Software for Cisco 8000 Series Routers and Cisco Network Convergence System (NCS) 540 Series …

Mar 13, 2024
CVE-2024-20318
7.4 HIGH

A vulnerability in the Layer 2 Ethernet services of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause the line card network …

Mar 13, 2024
CVE-2024-2194
7.2 HIGH

The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL search parameter in all versions up to, and including, 14.5 …

Mar 13, 2024
CVE-2024-2020
7.2 HIGH

The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form page href parameter in all versions up to, and …

Mar 13, 2024
CVE-2024-2006
8.8 HIGH

The Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget plugin for WordPress is vulnerable to PHP Object Injection in …

Mar 13, 2024
CVE-2024-28673
8.8 HIGH

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/mychannel_edit.php.

Mar 13, 2024
CVE-2024-28671
8.8 HIGH

DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /dede/stepselect_main.php.

Mar 13, 2024
CVE-2024-26630
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: mm: cachestat: fix folio read-after-free in cache walk In cachestat, we access the folio from …

Mar 13, 2024
CVE-2024-24549
7.5 HIGH

Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/2 request, if the request exceeded any …

Mar 13, 2024
CVE-2024-1951
7.5 HIGH

The Logo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid plugin for WordPress is vulnerable to PHP Object Injection in all versions up …

Mar 13, 2024
CVE-2024-1950
7.5 HIGH

The Product Carousel Slider & Grid Ultimate for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, …

Mar 13, 2024
CVE-2024-1935
7.2 HIGH

The Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

Mar 13, 2024
CVE-2024-1862
8.1 HIGH

The WooCommerce Add to Cart Custom Redirect plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing …

Mar 13, 2024
CVE-2024-1793
7.2 HIGH

The AWeber – Free Sign Up Form and Landing Page Builder Plugin for Lead Generation and Email Newsletter Growth plugin for WordPress is vulnerable to …

Mar 13, 2024
CVE-2024-1772
8.8 HIGH

The Play.ht – Make Your Blog Posts Accessible With Text to Speech Audio plugin for WordPress is vulnerable to PHP Object Injection in all versions …

Mar 13, 2024
CVE-2024-1751
8.8 HIGH

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection via the question_id parameter in all versions …

Mar 13, 2024
CVE-2024-1536
7.4 HIGH

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Mar 13, 2024
CVE-2024-1505
8.8 HIGH

The Academy LMS – eLearning and online course solution for WordPress plugin for WordPress is vulnerable to privilege escalation in all versions up to, and …

Mar 13, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.