CVE Database

9973+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-28751
9.1 CRITICAL

An high privileged remote attacker can enable telnet access that accepts hardcoded credentials.

Jul 9, 2024
CVE-2024-28747
9.8 CRITICAL

An unauthenticated remote attacker can use the hard-coded credentials to access the SmartSPS devices with high privileges.

Jul 9, 2024
CVE-2024-5488
9.8 CRITICAL

The SEOPress WordPress plugin before 7.9 does not properly protect some of its REST API routes, which combined with another Object Injection vulnerability can allow …

Jul 9, 2024
CVE-2024-6365
9.8 CRITICAL

The Product Table by WBW plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.1 via the 'saveCustomTitle' …

Jul 9, 2024
CVE-2024-1305
9.8 CRITICAL

tap-windows6 driver version 9.26 and earlier does not properly check the size data of incomming write operations which an attacker can use to overflow memory …

Jul 8, 2024
CVE-2023-46685
9.8 CRITICAL

A hard-coded password vulnerability exists in the telnetd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623. A set of specially crafted network packets can lead to arbitrary command …

Jul 8, 2024
CVE-2024-27903
9.8 CRITICAL

OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in which …

Jul 8, 2024
CVE-2024-40614
9.8 CRITICAL

EGroupware before 23.1.20240624 mishandles an ORDER BY clause. This leads to json.php?menuaction=EGroupware\Api\Etemplate\Widget\Nextmatch::ajax_get_rows sort.id SQL injection by authenticated users for Address Book or InfoLog sorting.

Jul 7, 2024
CVE-2024-27712
9.8 CRITICAL

An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via the User Account Mangemnt component …

Jul 5, 2024
CVE-2024-27710
9.8 CRITICAL

An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via the authentication mechanism.

Jul 5, 2024
CVE-2024-27709
9.8 CRITICAL

SQL Injection vulnerability in Eskooly Web Product v.3.0 allows a remote attacker to execute arbitrary code via the searchby parameter of the allstudents.php component and …

Jul 5, 2024
CVE-2024-37768
9.1 CRITICAL

14Finger v1.1 was discovered to contain an arbitrary user deletion vulnerability via the component /api/admin/user?id.

Jul 5, 2024
CVE-2024-29319
9.8 CRITICAL

Volmarg Personal Management System 1.4.64 is vulnerable to SSRF (Server Side Request Forgery) via uploading a SVG file. The server can make unintended HTTP and …

Jul 5, 2024
CVE-2024-23998
9.6 CRITICAL

goanother Another Redis Desktop Manager =<1.6.1 is vulnerable to Cross Site Scripting (XSS) via src/components/Setting.vue.

Jul 5, 2024
CVE-2024-23997
9.6 CRITICAL

Lukas Bach yana =<1.0.16 is vulnerable to Cross Site Scripting (XSS) via src/electron-main.ts.

Jul 5, 2024
CVE-2024-39864
9.8 CRITICAL

The CloudStack integration API service allows running its unauthenticated API server (usually on port 8096 when configured and enabled via integration.api.port global setting) for internal …

Jul 5, 2024
CVE-2024-39028
9.8 CRITICAL

An issue was discovered in SeaCMS <=12.9 which allows remote attackers to execute arbitrary code via admin_ping.php.

Jul 5, 2024
CVE-2024-38346
9.8 CRITICAL

The CloudStack cluster service runs on unauthenticated port (default 9090) that can be misused to run arbitrary commands on targeted hypervisors and CloudStack management server …

Jul 5, 2024
CVE-2024-6298
10.0 CRITICAL

Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to execute arbitrary code …

Jul 5, 2024
CVE-2024-6209
10.0 CRITICAL

Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to access files unauthorized

Jul 5, 2024
CVE-2024-39943
9.9 CRITICAL

rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote authenticated users (if they have …

Jul 4, 2024
CVE-2024-39932
9.9 CRITICAL

Gogs through 0.13.0 allows argument injection during the previewing of changes.

Jul 4, 2024
CVE-2024-39931
9.9 CRITICAL

Gogs through 0.13.0 allows deletion of internal files.

Jul 4, 2024
CVE-2024-39930
9.9 CRITICAL

The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution. Authenticated attackers can exploit this by opening …

Jul 4, 2024
CVE-2024-39165
9.8 CRITICAL

QR/demoapp/qr_image.php in Asial JpGraph Professional through 4.2.6-pro allows remote attackers to execute arbitrary code via a PHP payload in the data parameter in conjunction with …

Jul 4, 2024
CVE-2024-39844
9.8 CRITICAL

In ZNC before 1.9.1, remote code execution can occur in modtcl via a KICK.

Jul 3, 2024
CVE-2024-39223
9.8 CRITICAL

An authentication bypass in the SSH service of gost v2.11.5 allows attackers to intercept communications via setting the HostKeyCallback function to ssh.InsecureIgnoreHostKey

Jul 3, 2024
CVE-2024-37082
9.1 CRITICAL

When deploying Cloud Foundry together with the haproxy-boshrelease and using a non default configuration, it might be possible to craft HTTP requests that bypass mTLS …

Jul 3, 2024
CVE-2024-4708
9.8 CRITICAL

mySCADA myPRO uses a hard-coded password which could allow an attacker to remotely execute code on the affected device.

Jul 2, 2024
CVE-2023-24531
9.8 CRITICAL

Command go env is documented as outputting a shell script containing the Go environment. However, go env doesn't sanitize values, so executing its output as …

Jul 2, 2024
CVE-2024-36404
9.8 CRITICAL

GeoTools is an open source Java library that provides tools for geospatial data. Prior to versions 31.2, 30.4, and 29.6, Remote Code Execution (RCE) is …

Jul 2, 2024
CVE-2024-32755
9.1 CRITICAL

Under certain circumstances the web interface will accept characters unrelated to the expected input.

Jul 2, 2024
CVE-2023-41921
9.8 CRITICAL

A vulnerability allows attackers to download source code or an executable from a remote location and execute the code without sufficiently verifying the origin and …

Jul 2, 2024
CVE-2023-41920
9.8 CRITICAL

The vulnerability allows attackers access to the root account without having to authenticate. Specifically, if the device is configured with the IP address of 10.10.10.10, …

Jul 2, 2024
CVE-2023-41919
9.8 CRITICAL

Hardcoded credentials are discovered within the application's source code, creating a potential security risk for unauthorized access.

Jul 2, 2024
CVE-2023-41918
10.0 CRITICAL

A vulnerability allows unauthorized access to functionality inadequately constrained by ACLs. Attackers may exploit this to unauthenticated execute commands potentially leading to unauthorized data manipulation, …

Jul 2, 2024
CVE-2023-41917
10.0 CRITICAL

Inadequate input validation exposes the system to potential remote code execution (RCE) risks. Attackers can exploit this vulnerability by appending shell commands to the Speed-Measurement …

Jul 2, 2024
CVE-2024-6172
9.8 CRITICAL

The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via …

Jul 2, 2024
CVE-2024-39309
9.8 CRITICAL

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A vulnerability in versions prior to 6.5.7 …

Jul 1, 2024
CVE-2024-37762
9.9 CRITICAL

MachForm up to version 21 is affected by an authenticated unrestricted file upload which leads to a remote code execution.

Jul 1, 2024
CVE-2024-5322
9.1 CRITICAL

The N-central server is vulnerable to session rebinding of already authenticated users when using Entra SSO, which can lead to authentication bypass. This vulnerability is …

Jul 1, 2024
CVE-2024-38368
9.3 CRITICAL

trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. A vulnerability affected older pods which migrated from the pre-2014 pull request workflow to trunk. …

Jul 1, 2024
CVE-2024-38366
10.0 CRITICAL

trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. The part of trunk which verifies whether a user has a real email address on …

Jul 1, 2024
CVE-2024-28200
9.1 CRITICAL

The N-central server is vulnerable to an authentication bypass of the user interface. This vulnerability is present in all deployments of N-central prior to 2024.2. …

Jul 1, 2024
CVE-2024-39251
10.0 CRITICAL

An issue in the component ControlCenter.sys/ControlCenter64.sys of ThundeRobot Control Center v2.0.0.10 allows attackers to access sensitive information, execute arbitrary code, or escalate privileges via sending …

Jul 1, 2024
CVE-2024-39236
9.8 CRITICAL

Gradio v4.36.1 was discovered to contain a code injection vulnerability via the component /gradio/component_meta.py. This vulnerability is triggered via a crafted input. NOTE: the supplier …

Jul 1, 2024
CVE-2024-38513
10.0 CRITICAL

Fiber is an Express-inspired web framework written in Go A vulnerability present in versions prior to 2.52.5 is a session middleware issue in GoFiber versions …

Jul 1, 2024
CVE-2024-38476
9.8 CRITICAL

Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response …

Jul 1, 2024
CVE-2024-38475
9.1 CRITICAL KEV

Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted …

Jul 1, 2024
CVE-2024-38474
9.8 CRITICAL

Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not …

Jul 1, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.