CVE Database

9973+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-42465
9.8 CRITICAL

Improper Restriction of Excessive Authentication Attempts vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Abuse.This issue affects upKeeper Manager: through 5.1.9.

Aug 16, 2024
CVE-2024-42462
9.8 CRITICAL

Improper Authentication vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Bypass.This issue affects upKeeper Manager: through 5.1.9.

Aug 16, 2024
CVE-2024-6460
9.8 CRITICAL

The Grow by Tradedoubler WordPress plugin through 2.0.21 is vulnerable to Local File Inclusion via the component parameter. This makes it possible for attackers to …

Aug 16, 2024
CVE-2024-42757
9.8 CRITICAL

Command injection vulnerability in Asus RT-N15U 3.0.0.4.376_3754 allows a remote attacker to execute arbitrary code via the netstat function page.

Aug 15, 2024
CVE-2024-42472
10.0 CRITICAL

Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.14.0 and 1.15.10, a malicious or compromised Flatpak app using persistent directories could …

Aug 15, 2024
CVE-2024-27730
9.8 CRITICAL

Insecure Permissions vulnerability in Friendica v.2023.12 allows a remote attacker to obtain sensitive information and execute arbitrary code via the cid parameter of the calendar …

Aug 15, 2024
CVE-2024-23168
9.8 CRITICAL

Vulnerability in Xiexe XSOverlay before build 647 allows non-local websites to send the malicious commands to the WebSocket API, resulting in the arbitrary code execution.

Aug 15, 2024
CVE-2024-42978
9.8 CRITICAL

An issue in the handler function in /goform/telnet of Tenda FH1206 v02.03.01.35 allows attackers to execute arbitrary commands via a crafted HTTP request.

Aug 15, 2024
CVE-2024-42967
9.8 CRITICAL

Incorrect access control in TOTOLINK LR350 V9.3.5u.6369_B20220309 allows attackers to obtain the apmib configuration file, which contains the username and the password, via a crafted …

Aug 15, 2024
CVE-2024-42966
9.8 CRITICAL

Incorrect access control in TOTOLINK N350RT V9.3.5u.6139_B20201216 allows attackers to obtain the apmib configuration file, which contains the username and the password, via a crafted …

Aug 15, 2024
CVE-2024-42947
9.8 CRITICAL

An issue in the handler function in /goform/telnet of Tenda FH1201 v1.2.0.14 (408) allows attackers to execute arbitrary commands via a crafted HTTP request.

Aug 15, 2024
CVE-2024-42843
9.8 CRITICAL

Projectworlds Online Examination System v1.0 is vulnerable to SQL Injection via the subject parameter in feed.php.

Aug 15, 2024
CVE-2024-42360
9.8 CRITICAL

SequenceServer lets you rapidly set up a BLAST+ server with an intuitive user interface for personal or group use. Several HTTP endpoints did not properly …

Aug 14, 2024
CVE-2024-5914
9.8 CRITICAL

A command injection issue in Palo Alto Networks Cortex XSOAR CommonScripts Pack allows an unauthenticated attacker to execute arbitrary commands within the context of an …

Aug 14, 2024
CVE-2024-39397
9.0 CRITICAL

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in …

Aug 14, 2024
CVE-2024-7732
9.8 CRITICAL

Dr.ID Access Control System from SECOM does not properly validate a specific page parameter, allowing unauthenticated remote attackers to inject SQL commands to read, modify, …

Aug 14, 2024
CVE-2024-7731
9.8 CRITICAL

Dr.ID Access Control System from SECOM does not properly validate a specific page parameter, allowing unauthenticated remote attackers to inject SQL commands to read, modify, …

Aug 14, 2024
CVE-2024-38652
9.1 CRITICAL

Path traversal in the skin management component of Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to achieve denial of service via arbitrary file deletion.

Aug 14, 2024
CVE-2024-20083
9.8 CRITICAL

In venc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Aug 14, 2024
CVE-2024-20082
9.8 CRITICAL

In Modem, there is a possible memory corruption due to a missing bounds check. This could lead to remote code execution with no additional execution …

Aug 14, 2024
CVE-2024-28986
9.8 CRITICAL KEV

SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to …

Aug 13, 2024
CVE-2024-7593
9.8 CRITICAL KEV

Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the …

Aug 13, 2024
CVE-2024-7569
9.6 CRITICAL

An information disclosure vulnerability in Ivanti ITSM on-prem and Neurons for ITSM versions 2023.4 and earlier allows an unauthenticated attacker to obtain the OIDC client …

Aug 13, 2024
CVE-2024-38199
9.8 CRITICAL

Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability

Aug 13, 2024
CVE-2024-38160
9.1 CRITICAL

Windows Network Virtualization Remote Code Execution Vulnerability

Aug 13, 2024
CVE-2024-38159
9.1 CRITICAL

Windows Network Virtualization Remote Code Execution Vulnerability

Aug 13, 2024
CVE-2024-38140
9.8 CRITICAL

Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability

Aug 13, 2024
CVE-2024-38109
9.1 CRITICAL

An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in Microsoft Azure Health Bot to elevate privileges over a network.

Aug 13, 2024
CVE-2024-38108
9.3 CRITICAL

Azure Stack Hub Spoofing Vulnerability

Aug 13, 2024
CVE-2024-38063
9.8 CRITICAL

Windows TCP/IP Remote Code Execution Vulnerability

Aug 13, 2024
CVE-2024-7746
9.8 CRITICAL

Use of Default Credentials vulnerability in Tananaev Solutions Traccar Server on Administrator Panel modules allows Authentication Abuse.This issue affects the privileged transactions implemented by the …

Aug 13, 2024
CVE-2024-41623
9.8 CRITICAL

An issue in D3D Security D3D IP Camera (D8801) v.V9.1.17.1.4-20180428 allows a local attacker to execute arbitrary code via a crafted payload

Aug 13, 2024
CVE-2024-43160
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in BerqWP allows Code Injection.This issue affects BerqWP: from n/a through 1.7.6.

Aug 13, 2024
CVE-2024-43153
9.8 CRITICAL

Incorrect Privilege Assignment vulnerability in WofficeIO Woffice woffice.This issue affects Woffice: from n/a through <= 5.4.10.

Aug 13, 2024
CVE-2024-43141
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in Roland Barker, xnau webdesign Participants Database allows Object Injection.This issue affects Participants Database: from n/a through 2.5.9.2.

Aug 13, 2024
CVE-2024-37287
9.1 CRITICAL

A flaw allowing arbitrary code execution was discovered in Kibana. An attacker with access to ML and Alerting connector features, as well as write access …

Aug 13, 2024
CVE-2024-43121
9.1 CRITICAL

Improper Privilege Management vulnerability in realmag777 HUSKY allows Privilege Escalation.This issue affects HUSKY: from n/a through 1.3.6.1.

Aug 13, 2024
CVE-2024-41940
9.1 CRITICAL

A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application does not properly validate user input to a privileged command …

Aug 13, 2024
CVE-2024-41730
9.8 CRITICAL

In SAP BusinessObjects Business Intelligence Platform, if Single Signed On is enabled on Enterprise authentication, an unauthorized user can get a logon token using a …

Aug 13, 2024
CVE-2024-7094
9.8 CRITICAL

The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to PHP Code Injection leading to Remote Code …

Aug 13, 2024
CVE-2024-43360
9.8 CRITICAL

ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder is affected by a time-based SQL Injection vulnerability. This vulnerability is fixed in 1.36.34 …

Aug 12, 2024
CVE-2024-42547
9.8 CRITICAL

TOTOLINK A3100R V4.1.2cu.5050_B20200504 has a buffer overflow vulnerability in the http_host parameter in the loginauth function.

Aug 12, 2024
CVE-2024-42546
9.8 CRITICAL

TOTOLINK A3100R V4.1.2cu.5050_B20200504 has a buffer overflow vulnerability in the password parameter in the loginauth function.

Aug 12, 2024
CVE-2024-42545
9.8 CRITICAL

TOTOLINK A3700R v9.1.2u.5822_B20200513 has a buffer overflow vulnerability in the ssid parameter in setWizardCfg function.

Aug 12, 2024
CVE-2024-42543
9.8 CRITICAL

TOTOLINK A3700R v9.1.2u.5822_B20200513 has a buffer overflow vulnerability in the http_host parameter in the loginauth function.

Aug 12, 2024
CVE-2024-42489
10.0 CRITICAL

Pro Macros provides XWiki rendering macros. Missing escaping in the Viewpdf macro allows any user with view right on the `CKEditor.HTMLConverter` page or edit or …

Aug 12, 2024
CVE-2023-7249
9.8 CRITICAL

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText OpenText Directory Services allows Path Traversal.This issue affects OpenText Directory Services: …

Aug 12, 2024
CVE-2024-6917
9.8 CRITICAL

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Veribilim Software Veribase Order Management allows OS Command Injection.This issue …

Aug 12, 2024
CVE-2024-42520
9.8 CRITICAL

TOTOLINK A3002R v4.0.0-B20230531.1404 contains a buffer overflow vulnerability in /bin/boa via formParentControl.

Aug 12, 2024
CVE-2024-42479
10.0 CRITICAL

llama.cpp provides LLM inference in C/C++. The unsafe `data` pointer member in the `rpc_tensor` structure can cause arbitrary address writing. This vulnerability is fixed in …

Aug 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.