CVE Database

39369+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-27193
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PayU India PayU India payu-india allows DOM-Based XSS.This issue affects PayU India: from …

Mar 15, 2024
CVE-2024-27192
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Reilly Configure SMTP allows Reflected XSS.This issue affects Configure SMTP: from n/a …

Mar 15, 2024
CVE-2024-25921
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Concerted Action Action Network allows Reflected XSS.This issue affects Action Network: from n/a …

Mar 15, 2024
CVE-2024-27987
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StellarWP GiveWP give.This issue affects GiveWP: from n/a through <= 3.3.1.

Mar 15, 2024
CVE-2024-2490
8.8 HIGH

A vulnerability classified as critical was found in Tenda AC18 15.03.05.05. Affected by this vulnerability is the function setSchedWifi of the file /goform/openSchedWifi. The manipulation …

Mar 15, 2024
CVE-2024-2450
8.8 HIGH

Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to correctly verify account ownership when switching from email …

Mar 15, 2024
CVE-2024-2489
8.8 HIGH

A vulnerability classified as critical has been found in Tenda AC18 15.03.05.05. Affected is the function formSetQosBand of the file /goform/SetNetControlList. The manipulation of the …

Mar 15, 2024
CVE-2024-2488
8.8 HIGH

A vulnerability was found in Tenda AC18 15.03.05.05. It has been rated as critical. This issue affects the function formSetPPTPServer of the file /goform/SetPptpServerCfg. The …

Mar 15, 2024
CVE-2024-2487
8.8 HIGH

A vulnerability was found in Tenda AC18 15.03.05.05. It has been declared as critical. This vulnerability affects the function formSetDeviceName of the file /goform/SetOnlineDevName. The …

Mar 15, 2024
CVE-2024-2486
8.8 HIGH

A vulnerability was found in Tenda AC18 15.03.05.05. It has been classified as critical. This affects the function formQuickIndex of the file /goform/QuickIndex. The manipulation …

Mar 15, 2024
CVE-2024-28353
8.8 HIGH

There is a command injection vulnerability in the TRENDnet TEW-827DRU router with firmware version 2.10B01. An attacker can inject commands into the post request parameters …

Mar 15, 2024
CVE-2024-2485
8.8 HIGH

A vulnerability was found in Tenda AC18 15.03.05.05 and classified as critical. Affected by this issue is the function formSetSpeedWan of the file /goform/SetSpeedWan. The …

Mar 15, 2024
CVE-2024-27756
8.8 HIGH

GLPI through 10.0.12 allows CSV injection by an attacker who is able to create an asset with a crafted title.

Mar 15, 2024
CVE-2024-1795
8.8 HIGH

The HUSKY – Products Filter for WooCommerce Professional plugin for WordPress is vulnerable to SQL Injection via the 'name' parameter in the woof shortcode in …

Mar 15, 2024
CVE-2024-26540
7.8 HIGH

A heap-based buffer overflow in Clmg before 3.3.3 can occur via a crafted file to cimg_library::CImg<unsigned char>::_load_analyze.

Mar 15, 2024
CVE-2023-50677
8.8 HIGH

An issue in NETGEAR-DGND4000 v.1.1.00.15_1.00.15 allows a remote attacker to escalate privileges via the next_file parameter to the /setup.cgi component.

Mar 14, 2024
CVE-2024-1713
7.2 HIGH

A user who can create objects in a database with plv8 3.2.1 installed is able to cause deferred triggers to execute as the Superuser during …

Mar 14, 2024
CVE-2024-0860
8.0 HIGH

The affected product is vulnerable to a cleartext transmission of sensitive information vulnerability, which may allow an attacker to capture packets to craft their own …

Mar 14, 2024
CVE-2024-28425
7.5 HIGH

greykite v1.0.0 was discovered to contain an arbitrary file upload vulnerability in the load_obj function at /templates/pickle_utils.py. This vulnerability allows attackers to execute arbitrary code …

Mar 14, 2024
CVE-2024-28424
8.8 HIGH

zenml v0.55.4 was discovered to contain an arbitrary file upload vulnerability in the load function at /materializers/cloudpickle_materializer.py. This vulnerability allows attackers to execute arbitrary code …

Mar 14, 2024
CVE-2024-27301
7.3 HIGH

Support App is an opensource application specialized in managing Apple devices. It's possible to abuse a vulnerability inside the postinstall installer script to make the …

Mar 14, 2024
CVE-2024-27266
8.2 HIGH

IBM Maximo Application Suite 7.6.1.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this …

Mar 14, 2024
CVE-2024-22346
8.4 HIGH

Db2 for IBM i 7.2, 7.3, 7.4, and 7.5 infrastructure could allow a local user to gain elevated privileges due to an unqualified library call. …

Mar 14, 2024
CVE-2023-42938
7.8 HIGH

A logic issue was addressed with improved checks. This issue is fixed in iTunes 12.13.1 for Windows. A local attacker may be able to elevate …

Mar 14, 2024
CVE-2024-28181
8.1 HIGH

turbo_boost-commands is a set of commands to help you build robust reactive applications with Rails & Hotwire. TurboBoost Commands has existing protections in place to …

Mar 14, 2024
CVE-2023-32666
7.2 HIGH

On-chip debug and test interface with improper access control in some 4th Generation Intel(R) Xeon(R) Processors when using Intel(R) SGX or Intel(R) TDX may allow …

Mar 14, 2024
CVE-2023-32282
7.2 HIGH

Race condition in BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

Mar 14, 2024
CVE-2023-50168
7.7 HIGH

Pega Platform from 6.x to 8.8.4 is affected by an XXE issue with PDF Generation.

Mar 14, 2024
CVE-2024-1623
7.7 HIGH

Insufficient session timeout vulnerability in the FAST3686 V2 Vodafone router from Sagemcom. This vulnerability could allow a local attacker to access the administration panel without …

Mar 14, 2024
CVE-2024-28746
8.1 HIGH

Apache Airflow, versions 2.8.0 through 2.8.2, has a vulnerability that allows an authenticated user with limited permissions to access resources such as variables, connections, etc …

Mar 14, 2024
CVE-2024-22397
8.3 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in the SonicOS SSLVPN portal allows a remote authenticated attacker as a firewall 'admin' user …

Mar 14, 2024
CVE-2024-1882
7.2 HIGH

This vulnerability allows an already authenticated admin user to create a malicious payload that could be leveraged for remote code execution on the server hosting …

Mar 14, 2024
CVE-2024-25652
7.6 HIGH

In Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or with access to Report functionality via UNLIMITED ADMIN …

Mar 14, 2024
CVE-2024-1654
7.2 HIGH

This vulnerability potentially allows unauthorized write operations which may lead to remote code execution. An attacker must already have authenticated admin access and knowledge of …

Mar 14, 2024
CVE-2024-1222
8.6 HIGH

This allows attackers to use a maliciously formed API request to gain access to an API authorization level with elevated privileges. This applies to a …

Mar 14, 2024
CVE-2024-25228
8.8 HIGH

Vinchin Backup and Recovery 7.2 and Earlier is vulnerable to Authenticated Remote Code Execution (RCE) via the getVerifydiyResult function in ManoeuvreHandler.class.php.

Mar 14, 2024
CVE-2023-38534
8.6 HIGH

Improper authentication vulnerability in OpenText™ Exceed Turbo X affecting versions 12.5.0 and 12.5.1. The vulnerability could allow disclosure of restricted information in unauthenticated RPC.

Mar 13, 2024
CVE-2020-11862
8.6 HIGH

Allocation of Resources Without Limits or Throttling vulnerability in OpenText NetIQ Privileged Account Manager on Linux, Windows, 64 bit allows Flooding.This issue affects NetIQ Privileged …

Mar 13, 2024
CVE-2024-24105
7.8 HIGH

SQL Injection vulnerability in Code-projects Computer Science Time Table System 1.0 allows attackers to run arbitrary code via adminFormvalidation.php.

Mar 13, 2024
CVE-2024-22167
7.9 HIGH

A potential DLL hijacking vulnerability in the SanDisk PrivateAccess application for Windows that could lead to arbitrary code execution in the context of the system …

Mar 13, 2024
CVE-2023-41504
8.8 HIGH

SQL Injection vulnerability in Student Enrollment In PHP 1.0 allows attackers to run arbitrary code via the Student Search function.

Mar 13, 2024
CVE-2024-24693
7.2 HIGH

Improper access control in the installer for Zoom Rooms Client for Windows before version 5.17.5 may allow an authenticated user to conduct a denial of …

Mar 13, 2024
CVE-2024-0801
7.5 HIGH

A denial of service vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in ASNative.dll.

Mar 13, 2024
CVE-2024-0800
8.8 HIGH

A path traversal vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in edge-app-base-webui.jar!com.ca.arcserve.edge.app.base.ui.server.servlet.ImportNodeServlet.

Mar 13, 2024
CVE-2024-28195
8.1 HIGH

your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify versions < 1.9.0 do not protect the API and login flow against Cross-Site Request …

Mar 13, 2024
CVE-2024-27952
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Codeus Advanced Sermons allows Reflected XSS.This issue affects Advanced Sermons: from n/a …

Mar 13, 2024
CVE-2024-20327
7.4 HIGH

A vulnerability in the PPP over Ethernet (PPPoE) termination feature of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers could allow …

Mar 13, 2024
CVE-2024-20320
7.8 HIGH

A vulnerability in the SSH client feature of Cisco IOS XR Software for Cisco 8000 Series Routers and Cisco Network Convergence System (NCS) 540 Series …

Mar 13, 2024
CVE-2024-20318
7.4 HIGH

A vulnerability in the Layer 2 Ethernet services of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause the line card network …

Mar 13, 2024
CVE-2024-2194
7.2 HIGH

The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL search parameter in all versions up to, and including, 14.5 …

Mar 13, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.