CVE Database

9973+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-7098
9.8 CRITICAL

Improper Restriction of XML External Entity Reference vulnerability in SFS Consulting ww.Winsure allows XML Injection.This issue affects ww.Winsure: before 4.6.2.

Sep 16, 2024
CVE-2024-6401
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SFS Consulting InsureE GL allows SQL Injection.This issue affects InsureE GL: …

Sep 16, 2024
CVE-2024-46419
9.8 CRITICAL

TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the setWizardCfg function via the ssid5g parameter.

Sep 16, 2024
CVE-2024-46451
9.8 CRITICAL

TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the setWiFiAclRules function via the desc parameter.

Sep 16, 2024
CVE-2024-22399
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in Apache Seata. When developers disable authentication on the Seata-Server and do not use the Seata client SDK dependencies, they …

Sep 16, 2024
CVE-2024-45698
9.8 CRITICAL

Certain models of D-Link wireless routers do not properly validate user input in the telnet service, allowing unauthenticated remote attackers to use hard-coded credentials to …

Sep 16, 2024
CVE-2024-45697
9.8 CRITICAL

Certain models of D-Link wireless routers have a hidden functionality where the telnet service is enabled when the WAN port is plugged in. Unauthorized remote …

Sep 16, 2024
CVE-2024-45695
9.8 CRITICAL

The web service of certain models of D-Link wireless routers contains a Stack-based Buffer Overflow vulnerability, which allows unauthenticated remote attackers to exploit this vulnerability …

Sep 16, 2024
CVE-2024-45694
9.8 CRITICAL

The web service of certain models of D-Link wireless routers contains a Stack-based Buffer Overflow vulnerability, which allows unauthenticated remote attackers to exploit this vulnerability …

Sep 16, 2024
CVE-2024-46958
9.1 CRITICAL

In Nextcloud Desktop Client 3.13.1 through 3.13.3 on Linux, synchronized files (between the server and client) may become world writable or world readable. This is …

Sep 16, 2024
CVE-2024-8669
9.1 CRITICAL

The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to SQL Injection via the 'options' parameter passed to the backuply_wp_clone_sql() function …

Sep 14, 2024
CVE-2024-8039
9.8 CRITICAL

Improper permission configurationDomain configuration vulnerability of the mobile application (com.afmobi.boomplayer) can lead to account takeover risks.

Sep 14, 2024
CVE-2024-44430
9.8 CRITICAL

SQL Injection vulnerability in Best Free Law Office Management Software-v1.0 allows an attacker to execute arbitrary code and obtain sensitive information via a crafted payload …

Sep 13, 2024
CVE-2024-46049
9.8 CRITICAL

Tenda O6 V3.0 firmware V1.0.0.7(2054) contains a stack overflow vulnerability in the formexeCommand function.

Sep 13, 2024
CVE-2024-46048
9.8 CRITICAL

Tenda FH451 v1.0.0.9 has a command injection vulnerability in the formexeCommand function i

Sep 13, 2024
CVE-2024-46046
9.8 CRITICAL

Tenda FH451 v1.0.0.9 has a stack overflow vulnerability located in the RouteStatic function.

Sep 13, 2024
CVE-2024-46045
9.8 CRITICAL

Tenda CH22 V1.0.0.6(468) has a stack overflow vulnerability located in the frmL7PlotForm function.

Sep 13, 2024
CVE-2024-46044
9.8 CRITICAL

CH22 V1.0.0.6(468) has a stack overflow vulnerability located in the fromqossetting function.

Sep 13, 2024
CVE-2024-41874
9.8 CRITICAL

ColdFusion versions 2023.9, 2021.15 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context …

Sep 13, 2024
CVE-2024-6656
9.8 CRITICAL

Use of Hard-coded Credentials vulnerability in TNB Mobile Solutions Cockpit Software allows Read Sensitive Strings Within an Executable.This issue affects Cockpit Software: before v2.13.

Sep 13, 2024
CVE-2024-7961
9.8 CRITICAL

A path traversal vulnerability exists in the Rockwell Automation affected product. If exploited, the threat actor could upload arbitrary files to the server that could …

Sep 12, 2024
CVE-2024-7960
9.1 CRITICAL

The Rockwell Automation affected product contains a vulnerability that allows a threat actor to view sensitive information and change settings. The vulnerability exists due to …

Sep 12, 2024
CVE-2024-6678
9.9 CRITICAL

An issue was discovered in GitLab CE/EE affecting all versions starting from 8.14 prior to 17.1.7, starting from 17.2 prior to 17.2.5, and starting from …

Sep 12, 2024
CVE-2024-8696
9.8 CRITICAL

A remote code execution (RCE) vulnerability via crafted extension publisher-url/additional-urls could be abused by a malicious extension in Docker Desktop before 4.34.2.

Sep 12, 2024
CVE-2024-8695
9.8 CRITICAL

A remote code execution (RCE) vulnerability via crafted extension description/changelog could be abused by a malicious extension in Docker Desktop before 4.34.2.

Sep 12, 2024
CVE-2024-45824
9.8 CRITICAL

CVE-2024-45824 IMPACT A remote code vulnerability exists in the affected products. The vulnerability occurs when chained with Path Traversal, Command Injection, and XSS Vulnerabilities and …

Sep 12, 2024
CVE-2024-40457
9.1 CRITICAL

No-IP Dynamic Update Client (DUC) v3.x uses cleartext credentials that may occur on a command line or in a file. NOTE: the vendor's position is …

Sep 12, 2024
CVE-2024-28991
9.0 CRITICAL

SolarWinds Access Rights Manager (ARM) was found to be susceptible to a remote code execution vulnerability. If exploited, this vulnerability would allow an authenticated user …

Sep 12, 2024
CVE-2024-45856
9.0 CRITICAL

A cross-site scripting (XSS) vulnerability exists in all versions of the MindsDB platform, enabling the execution of a JavaScript payload whenever a user enumerates an …

Sep 12, 2024
CVE-2024-8529
10.0 CRITICAL

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_fields' parameter of the /wp-json/lp/v1/courses/archive-course REST API endpoint in …

Sep 12, 2024
CVE-2024-8522
10.0 CRITICAL

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_only_fields' parameter of the /wp-json/learnpress/v1/courses REST API endpoint in …

Sep 12, 2024
CVE-2024-29847
9.8 CRITICAL

Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to …

Sep 12, 2024
CVE-2024-44541
9.8 CRITICAL

evilnapsis Inventio Lite Versions v4 and before is vulnerable to SQL Injection via the "username" parameter in "/?action=processlogin."

Sep 11, 2024
CVE-2024-44466
9.8 CRITICAL

COMFAST CF-XR11 V2.7.2 has a command injection vulnerability in function sub_424CB4. Attackers can send POST request messages to /usr/bin/webmgnt and inject commands into parameter iface.

Sep 11, 2024
CVE-2024-27115
9.8 CRITICAL

A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. With this vulnerability, an attacker can upload executable files …

Sep 11, 2024
CVE-2024-27114
9.8 CRITICAL

A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. If the public view setting is enabled, a attacker …

Sep 11, 2024
CVE-2024-27113
9.8 CRITICAL

An unauthenticated Insecure Direct Object Reference (IDOR) to the database has been found in the SO Planning tool that occurs when the public view setting …

Sep 11, 2024
CVE-2024-27112
9.8 CRITICAL

A unauthenticated SQL Injection has been found in the SO Planning tool that occurs when the public view setting is enabled. An attacker could use …

Sep 11, 2024
CVE-2024-6091
9.8 CRITICAL

A vulnerability in significant-gravitas/autogpt version 0.5.1 allows an attacker to bypass the shell commands denylist settings. The issue arises when the denylist is configured to …

Sep 11, 2024
CVE-2024-45790
9.8 CRITICAL

This vulnerability exists in Reedos aiM-Star version 2.0.1 due to missing restrictions for excessive failed authentication attempts on its API based login. A remote attacker …

Sep 11, 2024
CVE-2024-8277
9.8 CRITICAL

The WooCommerce Photo Reviews Premium plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.3.13.2. This is due to …

Sep 11, 2024
CVE-2024-8503
9.8 CRITICAL

An unauthenticated attacker can leverage a time-based SQL injection vulnerability in VICIdial to enumerate database records. By default, VICIdial stores plaintext credentials within the database.

Sep 10, 2024
CVE-2024-43040
9.1 CRITICAL

Renwoxing Enterprise Intelligent Management System before v3.0 was discovered to contain a SQL injection vulnerability via the parid parameter at /fx/baseinfo/SearchInfo.

Sep 10, 2024
CVE-2024-45409
10.0 CRITICAL

The Ruby SAML library is for implementing the client side of a SAML authorization. Ruby-SAML in <= 12.2 and 1.13.0 <= 1.16.0 does not properly …

Sep 10, 2024
CVE-2024-44893
9.8 CRITICAL

An issue in the component /jeecg-boot/jmreport/dict/list of JimuReport v1.7.8 allows attacker to escalate privileges via a crafted GET request.

Sep 10, 2024
CVE-2024-43491
9.8 CRITICAL

Microsoft is aware of a vulnerability in Servicing Stack that has rolled back the fixes for some vulnerabilities affecting Optional Components on Windows 10, version …

Sep 10, 2024
CVE-2024-38220
9.0 CRITICAL

Azure Stack Hub Elevation of Privilege Vulnerability

Sep 10, 2024
CVE-2024-45593
9.0 CRITICAL

Nix is a package manager for Linux and other Unix systems. A bug in Nix 2.24 prior to 2.24.6 allows a substituter or malicious user …

Sep 10, 2024
CVE-2024-44677
9.8 CRITICAL

eladmin v2.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an attacker to execute arbitrary code via the DatabaseController.java component.

Sep 10, 2024
CVE-2023-37234
9.8 CRITICAL

Loftware Spectrum through 4.6 has unprotected JMX Registry.

Sep 10, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.