CVE Database

9973+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-41610
9.8 CRITICAL

D-Link DIR-820LW REVB FIRMWARE PATCH 2.03.B01_TC contains hardcoded credentials in the Telnet service, enabling attackers to log in remotely to the Telnet service and perform …

Jul 30, 2024
CVE-2024-39012
9.8 CRITICAL

ais-ltd strategyen v0.4.0 was discovered to contain a prototype pollution via the function mergeObjects. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 30, 2024
CVE-2024-39011
9.8 CRITICAL

Prototype Pollution in chargeover redoc v2.0.9-rc.69 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) and cause other impacts via the …

Jul 30, 2024
CVE-2024-39010
9.8 CRITICAL

chase-moskal snapstate v0.0.9 was discovered to contain a prototype pollution via the function attemptNestedProperty. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 30, 2024
CVE-2024-38986
9.8 CRITICAL

Prototype Pollution in 75lb deep-merge 1.1.1 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) and cause other impacts via merge …

Jul 30, 2024
CVE-2024-38984
9.8 CRITICAL

Prototype Pollution in lukebond json-override 0.2.0 allows attackers to to execute arbitrary code or cause a Denial of Service (DoS) via the __proto__ property.

Jul 30, 2024
CVE-2024-36572
9.8 CRITICAL

Prototype pollution in allpro form-manager 0.7.4 allows attackers to run arbitrary code and cause other impacts via the functions setDefaults, mergeBranch, and Object.setObjectValue.

Jul 30, 2024
CVE-2024-38909
9.8 CRITICAL

Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrary attacker to expose …

Jul 30, 2024
CVE-2024-6699
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mikafon Electronic Inc. Mikafon MA7 allows SQL Injection.This issue affects Mikafon …

Jul 30, 2024
CVE-2024-41702
9.8 CRITICAL

SiberianCMS - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Jul 30, 2024
CVE-2023-48396
9.1 CRITICAL

Web Authentication vulnerability in Apache SeaTunnel. Since the jwt key is hardcoded in the application, an attacker can forge any token to log in any …

Jul 30, 2024
CVE-2024-5975
9.1 CRITICAL

The CZ Loan Management WordPress plugin through 1.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an …

Jul 30, 2024
CVE-2024-5765
9.8 CRITICAL

The WpStickyBar WordPress plugin through 2.1.0 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action …

Jul 30, 2024
CVE-2024-37858
9.8 CRITICAL

SQL Injection vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via the id parameter to php-lfis/admin/categories/manage_category.php.

Jul 29, 2024
CVE-2024-28805
9.1 CRITICAL

An issue was discovered in Italtel i-MCS NFV 12.1.0-20211215. There is Incorrect Access Control.

Jul 29, 2024
CVE-2024-38529
9.0 CRITICAL

Admidio is a free, open source user management system for websites of organizations and groups. In Admidio before version 4.3.10, there is a Remote Code …

Jul 29, 2024
CVE-2024-37906
9.9 CRITICAL

Admidio is a free, open source user management system for websites of organizations and groups. In Admidio before version 4.3.9, there is an SQL Injection …

Jul 29, 2024
CVE-2024-6366
9.1 CRITICAL

The User Profile Builder WordPress plugin before 3.11.8 does not have proper authorisation, allowing unauthenticated users to upload media files via the async upload functionality …

Jul 29, 2024
CVE-2024-7202
9.8 CRITICAL

The query functionality of WinMatrix3 Web package from Simopro Technology lacks proper validation of user input, allowing unauthenticated remote attackers to inject SQL commands to …

Jul 29, 2024
CVE-2024-7201
9.8 CRITICAL

The login functionality of WinMatrix3 Web package from Simopro Technology lacks proper validation of user input, allowing unauthenticated remote attackers to inject SQL commands to …

Jul 29, 2024
CVE-2024-5670
9.8 CRITICAL

The web services of Softnext's products, Mail SQR Expert and Mail Archiving Expert do not properly validate user input, allowing unauthenticated remote attackers to inject …

Jul 29, 2024
CVE-2024-32671
9.8 CRITICAL

Heap-based Buffer Overflow vulnerability in Samsung Open Source Escargot JavaScript engine allows Overflow Buffers.This issue affects Escargot: 4.0.0.

Jul 29, 2024
CVE-2024-42049
9.1 CRITICAL

TightVNC (Server for Windows) before 2.8.84 allows attackers to connect to the control pipe via a network connection.

Jul 28, 2024
CVE-2024-41120
9.8 CRITICAL

streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `url` variable on line 63 of `pages/9_🔲_Vector_Data_Visualization.py` takes user input, which …

Jul 26, 2024
CVE-2024-41119
9.8 CRITICAL

streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `vis_params` variable on line 80 in `8_🏜️_Raster_Data_Visualization.py` takes user input, which …

Jul 26, 2024
CVE-2024-41117
9.8 CRITICAL

streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `vis_params` variable on line 115 in `pages/10_🌍_Earth_Engine_Datasets.py` takes user input, which …

Jul 26, 2024
CVE-2024-41116
9.8 CRITICAL

streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `vis_params` variable on line 1254 in `pages/1_📷_Timelapse.py` takes user input, which …

Jul 26, 2024
CVE-2024-41115
9.8 CRITICAL

streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `palette` variable on line 488 in `pages/1_📷_Timelapse.py` takes user input, which …

Jul 26, 2024
CVE-2024-41114
9.8 CRITICAL

streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `palette` variable on line 430 in `pages/1_📷_Timelapse.py` takes user input, which …

Jul 26, 2024
CVE-2024-41113
9.8 CRITICAL

streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `vis_params` variable on line 383 or line 390 in `pages/1_📷_Timelapse.py` takes …

Jul 26, 2024
CVE-2024-41112
9.8 CRITICAL

streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the palette variable in `pages/1_📷_Timelapse.py` takes user input, which is later used …

Jul 26, 2024
CVE-2024-40117
9.8 CRITICAL

Incorrect access control in Solar-Log 1000 before v2.8.2 and build 52- 23.04.2013 allows attackers to obtain Administrative privileges via connecting to the web administration server. …

Jul 26, 2024
CVE-2024-26520
9.8 CRITICAL

An issue in Hangzhou Xiongwei Technology Development Co., Ltd. Restaurant Digital Comprehensive Management platform v1 allows an attacker to bypass authentication and perform arbitrary password …

Jul 26, 2024
CVE-2024-4447
9.9 CRITICAL

In the System → Maintenance tool, the Logged Users tab surfaces sessionId data for all users via the Direct Web Remoting API (UserSessionAjax.getSessionList.dwr) calls. While …

Jul 26, 2024
CVE-2024-41473
9.8 CRITICAL

Tenda FH1201 v1.2.0.14 was discovered to contain a command injection vulnerability via the mac parameter at ip/goform/WriteFacMac

Jul 25, 2024
CVE-2024-41468
9.8 CRITICAL

Tenda FH1201 v1.2.0.14 was discovered to contain a command injection vulnerability via the cmdinput parameter at /goform/exeCommand

Jul 25, 2024
CVE-2024-24621
9.8 CRITICAL

Softaculous Webuzo contains an authentication bypass vulnerability through the password reset functionality. Remote, anonymous attackers can exploit this vulnerability to gain full server access as …

Jul 25, 2024
CVE-2024-38289
9.8 CRITICAL

A boolean-based SQL injection issue in the Virtual Meeting Password (VMP) endpoint in R-HUB TurboMeeting through 8.x allows unauthenticated remote attackers to extract hashed passwords …

Jul 25, 2024
CVE-2024-38287
9.8 CRITICAL

The password-reset mechanism in the Forgot Password functionality in R-HUB TurboMeeting through 8.x allows unauthenticated remote attackers to force the application into resetting the administrator's …

Jul 25, 2024
CVE-2024-7007
9.8 CRITICAL

Positron Broadcast Signal Processor TRA7005 v1.20 is vulnerable to an authentication bypass exploit that could allow an attacker to have unauthorized access to protected areas …

Jul 25, 2024
CVE-2024-39671
9.3 CRITICAL

Access control vulnerability in the security verification module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jul 25, 2024
CVE-2024-37084
9.8 CRITICAL

In Spring Cloud Data Flow versions prior to 2.11.4, a malicious user who has access to the Skipper server api can use a crafted upload …

Jul 25, 2024
CVE-2024-41461
9.8 CRITICAL

Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the list1 parameter at ip/goform/DhcpListClient.

Jul 24, 2024
CVE-2024-41460
9.8 CRITICAL

Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the entrys parameter at ip/goform/RouteStatic.

Jul 24, 2024
CVE-2024-41459
9.8 CRITICAL

Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the PPPOEPassword parameter at ip/goform/QuickIndex.

Jul 24, 2024
CVE-2024-41551
9.8 CRITICAL

CampCodes Supplier Management System v1.0 is vulnerable to SQL injection via Supply_Management_System/admin/view_order_items.php?id= .

Jul 24, 2024
CVE-2024-36535
9.8 CRITICAL

Insecure permissions in meshery v0.7.51 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.

Jul 24, 2024
CVE-2024-36533
9.8 CRITICAL

Insecure permissions in volcano v1.8.2 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.

Jul 24, 2024
CVE-2024-36536
9.8 CRITICAL

Insecure permissions in fabedge v0.8.1 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.

Jul 24, 2024
CVE-2024-41110
9.9 CRITICAL

Moby is an open-source project created by Docker for software containerization. A security vulnerability has been detected in certain versions of Docker Engine, which could …

Jul 24, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.