CVE Database

120754+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-51646
4.7 MEDIUM

Allegra uploadSimpleFile Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Although authentication is …

Nov 22, 2024
CVE-2023-51645
4.7 MEDIUM

Allegra unzipFile Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Although authentication is …

Nov 22, 2024
CVE-2023-51644
7.3 HIGH

Allegra SiteConfigAction Improper Access Control Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Authentication is …

Nov 22, 2024
CVE-2023-51643
4.7 MEDIUM

Allegra uploadFile Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Although authentication is …

Nov 22, 2024
CVE-2023-51642
6.3 MEDIUM

Allegra loadFieldMatch Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Although …

Nov 22, 2024
CVE-2023-51641
6.3 MEDIUM

Allegra renderFieldMatch Deserialization of Unstrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Although …

Nov 22, 2024
CVE-2023-51640
4.7 MEDIUM

Allegra extarctZippedFile Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Although authentication is …

Nov 22, 2024
CVE-2023-51639
9.8 CRITICAL

Allegra downloadExportedChart Directory Traversal Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Allegra. Authentication is not required to …

Nov 22, 2024
CVE-2023-51638
9.8 CRITICAL

Allegra Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Allegra. Authentication is not required to exploit …

Nov 22, 2024
CVE-2023-51635
8.8 HIGH

NETGEAR RAX30 fing_dil Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 …

Nov 22, 2024
CVE-2023-51634
7.5 HIGH

NETGEAR RAX30 Improper Certificate Validation Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of …

Nov 22, 2024
CVE-2023-39470
7.2 HIGH

PaperCut NG print.script.sandboxed Exposed Dangerous Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PaperCut NG. …

Nov 22, 2024
CVE-2024-52998
5.5 MEDIUM

Substance3D - Stager versions 3.0.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Nov 22, 2024
CVE-2024-52726
7.5 HIGH

CRMEB v5.4.0 is vulnerable to Arbitrary file read in the save_basics function which allows an attacker to obtain sensitive information

Nov 22, 2024
CVE-2024-11618
7.3 HIGH

A vulnerability classified as critical was found in IPC Unigy Management System 04.03.00.08.0027. Affected by this vulnerability is an unknown functionality of the component HTTP …

Nov 22, 2024
CVE-2024-50657
6.8 MEDIUM

An issue in Owncloud android apk v.4.3.1 allows a physically proximate attacker to escalate privileges via the PassCodeViewModel class, specifically in the checkPassCodeIsValid method

Nov 22, 2024
CVE-2024-37783
5.4 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in Gladinet CentreStack v13.12.9934.54690 allows attackers to inject malicious JavaScript into the web browser of a victim via the …

Nov 22, 2024
CVE-2024-37782
9.8 CRITICAL

An LDAP injection vulnerability in the login page of Gladinet CentreStack v13.12.9934.54690 allows attackers to access sensitive data or execute arbitrary commands via a crafted …

Nov 22, 2024
CVE-2024-53438
9.8 CRITICAL

EventAttendance.php in ChurchCRM 5.7.0 is vulnerable to SQL injection. An attacker can exploit this vulnerability by manipulating the 'Event' parameter, which is directly interpolated into …

Nov 22, 2024
CVE-2024-44786
7.5 HIGH

Incorrect access control in Meabilis CMS 1.0 allows attackers to access other users' address books via unspecified vectors.

Nov 22, 2024
CVE-2024-10220
8.1 HIGH

The Kubernetes kubelet component allows arbitrary command execution via specially crafted gitRepo volumes.This issue affects kubelet: through 1.28.11, from 1.29.0 through 1.29.6, from 1.30.0 through …

Nov 22, 2024
CVE-2024-52814
2.8 LOW

Argo Helm is a collection of community maintained charts for `argoproj.github.io` projects. Prior to version 0.45.0, the `workflow-role`) lacks granularity in its privileges, giving permissions …

Nov 22, 2024
CVE-2024-52804
7.5 HIGH

Tornado is a Python web framework and asynchronous networking library. The algorithm used for parsing HTTP cookies in Tornado versions prior to 6.4.2 sometimes has …

Nov 22, 2024
CVE-2024-52802
7.5 HIGH

RIOT is an operating system for internet of things (IoT) devices. In version 2024.04 and prior, the function `_parse_advertise`, located in `/sys/net/application_layer/dhcpv6/client.c`, has no minimum …

Nov 22, 2024
CVE-2024-52793

The Deno Standard Library provides APIs for Deno and the Web. Prior to version 1.0.11, `http/file-server`'s `serveDir` with `showDirListing: true` option is vulnerable to cross-site …

Nov 22, 2024
CVE-2024-52723
9.8 CRITICAL

In TOTOLINK X6000R V9.4.0cu.1041_B20240224 in the shttpd file, the Uci_Set Str function is used without strict parameter filtering. An attacker can achieve arbitrary command execution …

Nov 22, 2024
CVE-2024-51074
6.7 MEDIUM

Incorrect access control in KIA Seltos vehicle instrument cluster with software and hardware v1.0 allows attackers to arbitrarily change odometer readings in the vehicle by …

Nov 22, 2024
CVE-2024-51073
6.7 MEDIUM

An issue in KIA Seltos vehicle instrument cluster with software and hardware v1.0 allows attackers to control or disrupt CAN communication between the instrument cluster …

Nov 22, 2024
CVE-2024-51072
5.3 MEDIUM

An issue in KIA Seltos vehicle instrument cluster with software and hardware v1.0 allows attackers to cause a Denial of Service (DoS) via ECU reset …

Nov 22, 2024
CVE-2024-50965
5.4 MEDIUM

Cross Site Scripting vulnerability in Public Knowledge Project PKP Platform OJS/OMP/OPS- before v.3.3.0.16 allows an attacker to execute arbitrary code and escalate privileges via a …

Nov 22, 2024
CVE-2024-50401
7.2 HIGH

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers …

Nov 22, 2024
CVE-2024-50400
7.2 HIGH

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers …

Nov 22, 2024
CVE-2024-50399
7.2 HIGH

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers …

Nov 22, 2024
CVE-2024-50398
7.2 HIGH

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers …

Nov 22, 2024
CVE-2024-50397
8.8 HIGH

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers …

Nov 22, 2024
CVE-2024-50396
8.8 HIGH

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers …

Nov 22, 2024
CVE-2024-50395
8.8 HIGH

An authorization bypass through user-controlled key vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow local network attackers to …

Nov 22, 2024
CVE-2024-48862
9.8 CRITICAL

A link following vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow remote attackers to traverse the file system to …

Nov 22, 2024
CVE-2024-48861
7.8 HIGH

An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow local network attackers to execute commands. …

Nov 22, 2024
CVE-2024-48860
9.8 CRITICAL

An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow remote attackers to execute commands. We …

Nov 22, 2024
CVE-2024-38647
7.5 HIGH

An exposure of sensitive information vulnerability has been reported to affect QNAP AI Core. If exploited, the vulnerability could allow remote attackers to compromise the …

Nov 22, 2024
CVE-2024-38646
6.0 MEDIUM

An incorrect permission assignment for critical resource vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow local authenticated attackers …

Nov 22, 2024
CVE-2024-38645
6.5 MEDIUM

A server-side request forgery (SSRF) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote authenticated attackers to read …

Nov 22, 2024
CVE-2024-38644
8.8 HIGH

An OS command injection vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote authenticated attackers to execute commands. …

Nov 22, 2024
CVE-2024-38643
9.8 CRITICAL

A missing authentication for critical function vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote attackers to gain …

Nov 22, 2024
CVE-2024-37050
6.5 MEDIUM

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow …

Nov 22, 2024
CVE-2024-37049
6.5 MEDIUM

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow …

Nov 22, 2024
CVE-2024-37048
4.9 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have …

Nov 22, 2024
CVE-2024-37047
6.5 MEDIUM

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow …

Nov 22, 2024
CVE-2024-37046
4.9 MEDIUM

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained …

Nov 22, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.