CVE Database

9973+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-36103
9.8 CRITICAL

Command Injection vulnerability in goform/SetIPTVCfg interface of Tenda AC15 V15.03.05.20 allows remote attackers to run arbitrary commands via crafted POST request.

Sep 10, 2024
CVE-2023-37231
9.8 CRITICAL

Loftware Spectrum before 4.6 HF14 uses a Hard-coded Password.

Sep 10, 2024
CVE-2023-37227
9.8 CRITICAL

Loftware Spectrum before 4.6 HF13 Deserializes Untrusted Data.

Sep 10, 2024
CVE-2023-37226
9.8 CRITICAL

Loftware Spectrum before 4.6 HF14 has Missing Authentication for a Critical Function.

Sep 10, 2024
CVE-2024-40754
9.8 CRITICAL

Heap-based Buffer Overflow vulnerability in Samsung Open Source Escargot JavaScript engine allows Overflow Buffers.This issue affects Escargot: 4.0.0.

Sep 10, 2024
CVE-2024-45032
10.0 CRITICAL

A vulnerability has been identified in Industrial Edge Management Pro (All versions < V1.9.5), Industrial Edge Management Virtual (All versions < V2.3.1-1). Affected components do …

Sep 10, 2024
CVE-2024-35783
9.1 CRITICAL

A vulnerability has been identified in SIMATIC BATCH V9.1 (All versions), SIMATIC Information Server 2020 (All versions < V2020 SP2 Update 5), SIMATIC Information Server …

Sep 10, 2024
CVE-2024-33698
9.8 CRITICAL

A vulnerability has been identified in Opcenter Quality (All versions < V2406), Opcenter RDnL (All versions < V2410), SIMATIC PCS neo V4.0 (All versions), SIMATIC …

Sep 10, 2024
CVE-2024-6596
9.8 CRITICAL

An unauthenticated remote attacker can run malicious c# code included in curve files and execute commands in the users context.

Sep 10, 2024
CVE-2024-6342
9.8 CRITICAL

**UNSUPPORTED WHEN ASSIGNED** A command injection vulnerability in the export-cgi program of Zyxel NAS326 firmware versions through V5.21(AAZF.18)C0 and NAS542 firmware versions through V5.21(ABAG.15)C0 could …

Sep 10, 2024
CVE-2024-44411
9.8 CRITICAL

D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the msp_info_htm function.

Sep 9, 2024
CVE-2024-44410
9.8 CRITICAL

D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the upgrade_filter_asp function.

Sep 9, 2024
CVE-2024-6795
10.0 CRITICAL

In Connex health portal released before8/30/2024, SQL injection vulnerabilities were found that could have allowed an unauthenticated attacker to gain unauthorized access to Connex portal's …

Sep 9, 2024
CVE-2024-44902
9.8 CRITICAL

A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.

Sep 9, 2024
CVE-2024-42500
9.3 CRITICAL

HPE has identified a denial of service vulnerability in HPE HP-UX System's Network File System (NFSv4) services.

Sep 9, 2024
CVE-2024-44849
9.8 CRITICAL

Qualitor up to 8.24 is vulnerable to Remote Code Execution (RCE) via Arbitrary File Upload in checkAcesso.php.

Sep 9, 2024
CVE-2024-44721
9.8 CRITICAL

SeaCMS v13.1 was discovered to a Server-Side Request Forgery (SSRF) via the url parameter at /admin_reslib.php.

Sep 9, 2024
CVE-2024-40643
9.6 CRITICAL

Joplin is a free, open source note taking and to-do application. Joplin fails to take into account that "<" followed by a non letter character …

Sep 9, 2024
CVE-2024-7015
9.8 CRITICAL

Missing Authentication for Critical Function vulnerability in Profelis Informatics and Consulting PassBox allows Authentication Abuse.This issue affects PassBox: before v1.2.

Sep 9, 2024
CVE-2024-37288
9.9 CRITICAL

A deserialization issue in Kibana can lead to arbitrary code execution when Kibana attempts to parse a YAML document containing a crafted payload. This issue …

Sep 9, 2024
CVE-2024-8584
9.8 CRITICAL

Orca HCM from LEARNING DIGITAL has an Missing Authentication vulnerability, allowing unauthenticated remote attacker to exploit this functionality to create an account with administrator privilege …

Sep 9, 2024
CVE-2024-6928
9.8 CRITICAL

The Opti Marketing WordPress plugin through 2.0.9 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX …

Sep 8, 2024
CVE-2024-6924
9.8 CRITICAL

The TrueBooker WordPress plugin before 1.0.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action …

Sep 8, 2024
CVE-2024-40711
9.8 CRITICAL KEV

A deserialization of untrusted data vulnerability with a malicious payload can allow an unauthenticated remote code execution (RCE).

Sep 7, 2024
CVE-2024-39714
9.9 CRITICAL

A code injection vulnerability that permits a low-privileged user to upload arbitrary files to the server, leading to remote code execution on VSPC server.

Sep 7, 2024
CVE-2024-38650
9.9 CRITICAL

An authentication bypass vulnerability can allow a low privileged attacker to access the NTLM hash of service account on the VSPC server.

Sep 7, 2024
CVE-2024-45771
9.8 CRITICAL

RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the password parameter at /resource/runlogin.php.

Sep 6, 2024
CVE-2024-44839
9.8 CRITICAL

RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the articleid parameter at /default/article.php.

Sep 6, 2024
CVE-2024-44838
9.8 CRITICAL

RapidCMS v1.3.1 was discovered to contain a SQL injection vulnerability via the username parameter at /resource/runlogin.php.

Sep 6, 2024
CVE-2024-8517
9.8 CRITICAL

SPIP before 4.3.2, 4.2.16, and 4.1.18 is vulnerable to a command injection issue. A remote and unauthenticated attacker can execute arbitrary operating system commands by …

Sep 6, 2024
CVE-2024-45758
9.1 CRITICAL

H2O.ai H2O through 3.46.0.4 allows attackers to arbitrarily set the JDBC URL, leading to deserialization attacks, file reads, and command execution. Exploitation can occur when …

Sep 6, 2024
CVE-2024-44402
9.8 CRITICAL

D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via msp_info.htm.

Sep 6, 2024
CVE-2024-44401
9.8 CRITICAL

D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via sub47A60C function in the upgrade_filter.asp file

Sep 6, 2024
CVE-2024-7493
9.8 CRITICAL

The WPCOM Member plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.5.2.1. This is due to the plugin …

Sep 6, 2024
CVE-2024-8292
9.8 CRITICAL

The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to privilege escalation/account takeover in all versions up to, and including, 16.26.8. …

Sep 6, 2024
CVE-2024-8395
9.8 CRITICAL

FlyCASS CASS and KCM systems did not correctly filter SQL queries, which made them vulnerable to attack by outside attackers with no authentication.

Sep 5, 2024
CVE-2024-45159
9.8 CRITICAL

An issue was discovered in Mbed TLS 3.x before 3.6.1. With TLS 1.3, when a server enables optional authentication of the client, if the client-provided …

Sep 5, 2024
CVE-2024-45158
9.8 CRITICAL

An issue was discovered in Mbed TLS 3.6 before 3.6.1. A stack buffer overflow in mbedtls_ecdsa_der_to_raw() and mbedtls_ecdsa_raw_to_der() can occur when the bits parameter is …

Sep 5, 2024
CVE-2024-7591
10.0 CRITICAL

Improper Input Validation vulnerability in Progress LoadMaster allows OS Command Injection.This issue affects: * LoadMaster: 7.2.40.0 and above * ECS: All versions * Multi-Tenancy: 7.1.35.4 …

Sep 5, 2024
CVE-2024-44727
9.8 CRITICAL

Sourcecodehero Event Management System1.0 is vulnerable to SQL Injection via the parameter 'username' in /event/admin/login.php.

Sep 5, 2024
CVE-2024-24759
9.3 CRITICAL

MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 23.12.4.2, a threat actor can bypass the server-side request forgery protection …

Sep 5, 2024
CVE-2024-42885
9.1 CRITICAL

SQL Injection vulnerability in ESAFENET CDG 5.6 and before allows an attacker to execute arbitrary code via the id parameter of the data.jsp page.

Sep 5, 2024
CVE-2024-8470
9.8 CRITICAL

SQL injection vulnerability, by which an attacker could send a specially designed query through CATEGORY parameter in /jobportal/admin/vacancy/controller.php, and retrieve all the information stored in …

Sep 5, 2024
CVE-2024-8469
9.8 CRITICAL

SQL injection vulnerability, by which an attacker could send a specially designed query through id parameter in /jobportal/admin/employee/index.php, and retrieve all the information stored in …

Sep 5, 2024
CVE-2024-8468
9.8 CRITICAL

SQL injection vulnerability, by which an attacker could send a specially designed query through search parameter in /jobportal/index.php, and retrieve all the information stored in …

Sep 5, 2024
CVE-2024-8467
9.8 CRITICAL

SQL injection vulnerability, by which an attacker could send a specially designed query through id parameter in /jobportal/admin/category/index.php, and retrieve all the information stored in …

Sep 5, 2024
CVE-2024-8466
9.8 CRITICAL

SQL injection vulnerability, by which an attacker could send a specially designed query through CATEGORY parameter in /jobportal/admin/category/controller.php, and retrieve all the information stored in …

Sep 5, 2024
CVE-2024-8465
9.8 CRITICAL

SQL injection vulnerability, by which an attacker could send a specially designed query through user_id parameter in /jobportal/admin/user/controller.php, and retrieve all the information stored in …

Sep 5, 2024
CVE-2024-8464
9.8 CRITICAL

SQL injection vulnerability, by which an attacker could send a specially designed query through JOBREGID parameter in /jobportal/admin/applicants/controller.php, and retrieve all the information stored in …

Sep 5, 2024
CVE-2024-8463
9.9 CRITICAL

File upload restriction bypass vulnerability in PHPGurukul Job Portal 1.0, the exploitation of which could allow an authenticated user to execute an RCE via webshell.

Sep 5, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.