CVE Database

9973+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-37642
9.1 CRITICAL

TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a command injection vulnerability via the ipv4_ping, ipv6_ping parameter at /formSystemCheck .

Jun 14, 2024
CVE-2024-34539
9.4 CRITICAL

Hardcoded credentials in TerraMaster TOS firmware through 5.1 allow a remote attacker to successfully login to the mail or webmail server. These credentials can also …

Jun 14, 2024
CVE-2024-33375
9.8 CRITICAL

LB-LINK BL-W1210M v2.0 was discovered to store user credentials in plaintext within the router's firmware.

Jun 14, 2024
CVE-2024-33374
9.8 CRITICAL

Incorrect access control in the UART/Serial interface on the LB-LINK BL-W1210M v2.0 router allows attackers to access the root terminal without authentication.

Jun 14, 2024
CVE-2024-5671
9.8 CRITICAL

Insecure Deserialization in some workflows of the IPS Manager allows unauthenticated remote attackers to perform arbitrary code execution and access to the vulnerable Trellix IPS …

Jun 14, 2024
CVE-2024-37637
9.8 CRITICAL

TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid5g in the function setWizardCfg.

Jun 14, 2024
CVE-2024-3912
9.8 CRITICAL

Certain models of ASUS routers have an arbitrary firmware upload vulnerability. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands on …

Jun 14, 2024
CVE-2024-2472
9.1 CRITICAL

The LatePoint Plugin plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the …

Jun 14, 2024
CVE-2024-5577
9.8 CRITICAL

The Where I Was, Where I Will Be plugin for WordPress is vulnerable to Remote File Inclusion in version <= 1.1.1 via the WIW_HEADER parameter …

Jun 14, 2024
CVE-2024-4936
9.8 CRITICAL

The Canto plugin for WordPress is vulnerable to Remote File Inclusion in all versions up to, and including, 3.0.8 via the abspath parameter. This makes …

Jun 14, 2024
CVE-2024-27174
9.8 CRITICAL

Remote Command program allows an attacker to get Remote Code Execution. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute …

Jun 14, 2024
CVE-2024-27173
9.8 CRITICAL

Remote Command program allows an attacker to get Remote Code Execution by overwriting existing Python files containing executable code. This vulnerability can be executed in …

Jun 14, 2024
CVE-2024-27172
9.8 CRITICAL

Remote Command program allows an attacker to get Remote Code Execution. As for the affected products/models/versions, see the reference URL.

Jun 14, 2024
CVE-2024-3080
9.8 CRITICAL

Certain ASUS router models have authentication bypass vulnerability, allowing unauthenticated remote attackers to log in the device.

Jun 14, 2024
CVE-2024-27145
9.8 CRITICAL

The Toshiba printers provide several ways to upload files using the admin web interface. An attacker can remotely compromise any Toshiba printer. An attacker can …

Jun 14, 2024
CVE-2024-27144
9.8 CRITICAL

The Toshiba printers provide several ways to upload files using the web interface without authentication. An attacker can overwrite any insecure files. And the Toshiba …

Jun 14, 2024
CVE-2024-27143
9.8 CRITICAL

Toshiba printers use SNMP for configuration. Using the private community, it is possible to remotely execute commands as root on the remote printer. Using this …

Jun 14, 2024
CVE-2024-31777
9.8 CRITICAL

File Upload vulnerability in openeclass v.3.15 and before allows an attacker to execute arbitrary code via a crafted file to the certbadge.php endpoint.

Jun 13, 2024
CVE-2024-0095
9.0 CRITICAL

NVIDIA Triton Inference Server for Linux and Windows contains a vulnerability where a user can inject forged logs and executable commands by injecting arbitrary data …

Jun 13, 2024
CVE-2024-32913
9.8 CRITICAL

In wl_notify_rx_mgmt_frame of wl_cfg80211.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with …

Jun 13, 2024
CVE-2024-32911
9.8 CRITICAL

There is a possible escalation of privilege due to improperly used crypto. This could lead to remote escalation of privilege with no additional execution privileges …

Jun 13, 2024
CVE-2024-32905
9.8 CRITICAL

In circ_read of link_device_memory_legacy.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution …

Jun 13, 2024
CVE-2024-29786
9.8 CRITICAL

In pktproc_fill_data_addr_without_bm of link_rx_pktproc.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution …

Jun 13, 2024
CVE-2024-37635
9.8 CRITICAL

TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiBasicCfg

Jun 13, 2024
CVE-2024-37634
9.8 CRITICAL

TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid in the function setWiFiEasyCfg.

Jun 13, 2024
CVE-2024-37632
9.8 CRITICAL

TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via the password parameter in function loginAuth .

Jun 13, 2024
CVE-2024-38281
9.8 CRITICAL

An attacker can access the maintenance console using hard coded credentials for a hidden wireless network on the device.

Jun 13, 2024
CVE-2024-22441
9.8 CRITICAL

HPE Cray Parallel Application Launch Service (PALS) is subject to an authentication bypass.

Jun 13, 2024
CVE-2024-37849
9.8 CRITICAL

A SQL Injection vulnerability in itsourcecode Billing System 1.0 allows a local attacker to execute arbitrary code in process.php via the username parameter.

Jun 13, 2024
CVE-2024-30300
9.8 CRITICAL

Adobe Framemaker Publishing Server versions 2020.3, 2022.2 and earlier are affected by an Information Exposure vulnerability (CWE-200) that could lead to privilege escalation. An attacker …

Jun 13, 2024
CVE-2024-30299
10.0 CRITICAL

Adobe Framemaker Publishing Server versions 2020.3, 2022.2 and earlier are affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could …

Jun 13, 2024
CVE-2024-4371
9.0 CRITICAL

The CoDesigner WooCommerce Builder for Elementor – Customize Checkout, Shop, Email, Products & More plugin for WordPress is vulnerable to PHP Object Injection in all …

Jun 13, 2024
CVE-2024-34108
9.1 CRITICAL

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in …

Jun 13, 2024
CVE-2024-34102
9.8 CRITICAL KEV

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result …

Jun 13, 2024
CVE-2024-3552
9.8 CRITICAL

The Web Directory Free WordPress plugin before 1.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX …

Jun 13, 2024
CVE-2024-38295
9.8 CRITICAL

ALCASAR before 3.6.1 allows still_connected.php remote code execution.

Jun 13, 2024
CVE-2024-38294
9.8 CRITICAL

ALCASAR before 3.6.1 allows email_registration_back.php remote code execution.

Jun 13, 2024
CVE-2024-38293
9.6 CRITICAL

ALCASAR before 3.6.1 allows CSRF and remote code execution in activity.php.

Jun 13, 2024
CVE-2024-3922
10.0 CRITICAL

The Dokan Pro plugin for WordPress is vulnerable to SQL Injection via the 'code' parameter in all versions up to, and including, 3.10.3 due to …

Jun 13, 2024
CVE-2024-37036
9.8 CRITICAL

CWE-787: Out-of-bounds Write vulnerability exists that could result in an authentication bypass when sending a malformed POST request and particular configuration parameters are set.

Jun 12, 2024
CVE-2024-36761
9.8 CRITICAL

naga v0.14.0 was discovered to contain a stack overflow via the component /wgsl/parse/mod.rs.

Jun 12, 2024
CVE-2024-36840
9.1 CRITICAL

SQL Injection vulnerability in Boelter Blue System Management v.1.3 allows a remote attacker to execute arbitrary code and obtain sensitive information via the id parameter …

Jun 12, 2024
CVE-2024-36265
9.8 CRITICAL

** UNSUPPORTED WHEN ASSIGNED ** Incorrect Authorization vulnerability in Apache Submarine Server Core. This issue affects Apache Submarine Server Core: from 0.8.0. As this project …

Jun 12, 2024
CVE-2024-36264
9.8 CRITICAL

** UNSUPPORTED WHEN ASSIGNED ** Improper Authentication vulnerability in Apache Submarine Commons Utils. If the user doesn't explicitly set `submarine.auth.default.secret`, a default value will be …

Jun 12, 2024
CVE-2024-1659
9.8 CRITICAL

Arbitrary File Upload vulnerability in MegaBIP software allows attacker to upload any file to the server (including a PHP code file) without an authentication. This …

Jun 12, 2024
CVE-2024-1577
9.8 CRITICAL

Remote Code Execution vulnerability in MegaBIP software allows to execute arbitrary code on the server without requiring authentication by saving crafted by the attacker PHP …

Jun 12, 2024
CVE-2024-1576
9.8 CRITICAL

SQL Injection vulnerability in MegaBIP software allows attacker to obtain site administrator privileges, including access to the administration panel and the ability to change the …

Jun 12, 2024
CVE-2024-4898
9.8 CRITICAL

The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to arbitrary option updates due to a missing authorization checks on …

Jun 12, 2024
CVE-2024-4315
9.1 CRITICAL

parisneo/lollms version 9.5 is vulnerable to Local File Inclusion (LFI) attacks due to insufficient path sanitization. The `sanitize_path_from_endpoint` function fails to properly sanitize Windows-style paths …

Jun 12, 2024
CVE-2024-35225
9.6 CRITICAL

Jupyter Server Proxy allows users to run arbitrary external processes alongside their notebook server and provide authenticated web access to them. Versions of 3.x prior …

Jun 11, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.