CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-10561
7.3 HIGH

A vulnerability was found in Codezips Pet Shop Management System 1.0. It has been classified as critical. This affects an unknown part of the file …

Oct 31, 2024
CVE-2024-10559
5.3 MEDIUM

A vulnerability was found in SourceCodester Airport Booking Management System 1.0 and classified as critical. Affected by this issue is the function Details. The manipulation …

Oct 31, 2024
CVE-2024-10544
5.3 MEDIUM

The Woo Manage Fraud Orders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.1 through publicly exposed …

Oct 31, 2024
CVE-2024-48307
9.8 CRITICAL

JeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalData.

Oct 31, 2024
CVE-2024-10557
4.3 MEDIUM

A vulnerability has been found in code-projects Blood Bank Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of …

Oct 31, 2024
CVE-2024-10556
7.3 HIGH

A vulnerability, which was classified as critical, was found in Codezips Pet Shop Management System 1.0. Affected is an unknown function of the file birdsadd.php. …

Oct 31, 2024
CVE-2024-10086
6.1 MEDIUM

A vulnerability was identified in Consul and Consul Enterprise such that the server response did not explicitly set a Content-Type HTTP header, allowing user-provided inputs …

Oct 30, 2024
CVE-2024-10006
8.3 HIGH

A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using Headers in L7 traffic intentions could bypass HTTP header based access rules.

Oct 30, 2024
CVE-2024-10005
8.1 HIGH

A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using URL paths in L7 traffic intentions could bypass HTTP request path-based access …

Oct 30, 2024
CVE-2024-51427
9.8 CRITICAL

An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an unspecified impact via the …

Oct 30, 2024
CVE-2024-51426
8.8 HIGH

An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an unspecified impact via the …

Oct 30, 2024
CVE-2024-51425
8.8 HIGH

An issue in the WaterToken smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an unspecified impact. NOTE: this …

Oct 30, 2024
CVE-2024-51424
9.8 CRITICAL

An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an unspecified impact via the …

Oct 30, 2024
CVE-2024-51419
6.1 MEDIUM

Cross Site Scripting vulnerability in Shenzhen Interconnection Harbor Network Technology Co., Ltd Ofweek Online Exhibition v.1.0.0 allows a remote attacker to execute arbitrary code.

Oct 30, 2024
CVE-2024-51243
7.2 HIGH

The eladmin v2.7 and before contains a remote code execution (RCE) vulnerability that can control all application deployment servers of this management system via DeployController.java.

Oct 30, 2024
CVE-2024-51242
6.5 MEDIUM

A Server-Side Request Forgery (SSRF) vulnerability has been identified in eladmin 2.7 and earlier in ServerDeployController.java. The manipulation of the HTTP Body ip parameter leads …

Oct 30, 2024
CVE-2024-48807
5.4 MEDIUM

Cross Site Scripting vulnerability in PHPGurukul Doctor Appointment Management System v.1.0 allows a local attacker to execute arbitrary code via the search parameter.

Oct 30, 2024
CVE-2024-48735
7.7 HIGH

Directory Traversal in /SASStudio/sasexec/sessions/{sessionID}/workspace/{InternalPath} in SAS Studio 9.4 allows remote attacker to access internal files by manipulating default path during file download. NOTE: this is …

Oct 30, 2024
CVE-2024-48734
8.8 HIGH

Unrestricted file upload in /SASStudio/SASStudio/sasexec/{sessionID}/{InternalPath} in SAS Studio 9.4 allows remote attacker to upload malicious files. NOTE: this is disputed by the vendor because file …

Oct 30, 2024
CVE-2024-48733
8.8 HIGH

SQL injection vulnerability in /SASStudio/sasexec/sessions/{sessionID}/sql in SAS Studio 9.4 allows remote attacker to execute arbitrary SQL commands via the POST body request. NOTE: this is …

Oct 30, 2024
CVE-2024-48346
6.1 MEDIUM

xtreme1 <= v0.9.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the /api/data/upload path. The vulnerability is triggered through the fileUrl parameter, which allows an …

Oct 30, 2024
CVE-2024-48112
9.8 CRITICAL

A deserialization vulnerability in the component \controller\Index.php of Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.

Oct 30, 2024
CVE-2024-48093
8.0 HIGH

Unrestricted File Upload in the Discussions tab in Operately v.0.1.0 allows a privileged user to achieve Remote Code Execution via uploading and executing malicious files …

Oct 30, 2024
CVE-2024-43382
5.9 MEDIUM

Snowflake JDBC driver versions >= 3.2.6 and <= 3.19.1 have an Incorrect Security Setting that can result in data being uploaded to an encrypted stage …

Oct 30, 2024
CVE-2023-52066
7.2 HIGH

http.zig commit 76cf5 was discovered to contain a CRLF injection vulnerability via the url parameter.

Oct 30, 2024
CVE-2024-48272
6.5 MEDIUM

D-Link DSL6740C v6.TR069.20211230 was discovered to use an insecure default Wifi password, possibly allowing attackers to connect to the device via a bruteforce attack.

Oct 30, 2024
CVE-2024-48271
8.8 HIGH

D-Link DSL6740C v6.TR069.20211230 was discovered to use insecure default credentials for Administrator access, possibly allowing attackers to bypass authentication and escalate privileges on the device …

Oct 30, 2024
CVE-2024-10546
6.3 MEDIUM

A vulnerability classified as critical was found in open-scratch Teaching 在线教学平台 up to 2.7. This vulnerability affects unknown code of the file /api/sys/ng-alain/getDictItemsByTable/ of the …

Oct 30, 2024
CVE-2024-48202
9.8 CRITICAL

icecms <=3.4.7 has a File Upload vulnerability in FileUtils.java,uploadFile.

Oct 30, 2024
CVE-2024-46531
6.3 MEDIUM

phpgurukul Vehicle Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchinputdata parameter at /index.php.

Oct 30, 2024
CVE-2024-9419
7.8 HIGH

Client / Server PCs with the HP Smart Universal Printing Driver installed are potentially vulnerable to Remote Code Execution and/or Elevation of Privilege. A client …

Oct 30, 2024
CVE-2024-48648
6.1 MEDIUM

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Sage 1000 v 7.0.0. This vulnerability allows attackers to inject malicious scripts into URLs, which are …

Oct 30, 2024
CVE-2024-48647
7.2 HIGH

A file disclosure vulnerability exists in Sage 1000 v7.0.0. This vulnerability allows remote attackers to retrieve arbitrary files from the server's file system by manipulating …

Oct 30, 2024
CVE-2024-48646
8.1 HIGH

An Unrestricted File Upload vulnerability exists in Sage 1000 v7.0.0, which allows authorized users to upload files without proper validation. An attacker could exploit this …

Oct 30, 2024
CVE-2024-48569
5.4 MEDIUM

Proactive Risk Manager version 9.1.1.0 is affected by multiple Cross-Site Scripting (XSS) vulnerabilities in the add/edit form fields, at the urls starting with the subpaths: …

Oct 30, 2024
CVE-2024-48241
5.5 MEDIUM

An issue in radare2 v5.8.0 through v5.9.4 allows a local attacker to cause a denial of service via the __bf_div function.

Oct 30, 2024
CVE-2024-48214
8.4 HIGH

KERUI HD 3MP 1080P Tuya Camera 1.0.4 has a command injection vulnerability in the module that connects to the local network via a QR code. …

Oct 30, 2024
CVE-2024-42041
8.1 HIGH

The com.videodownload.browser.videodownloader (aka AppTool-Browser-Video All Video Downloader) application 20-30.05.24 for Android allows an attacker to execute arbitrary JavaScript code via the acr.browser.lightning.DefaultBrowserActivity component.

Oct 30, 2024
CVE-2024-37573
8.4 HIGH

The Talkatone com.talkatone.android application 8.4.6 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted …

Oct 30, 2024
CVE-2024-36060
8.8 HIGH

EnGenius EnStation5-AC A8J-ENS500AC 1.0.0 devices allow blind OS command injection via shell metacharacters in the Ping and Speed Test parameters.

Oct 30, 2024
CVE-2024-31975
4.8 MEDIUM

EnGenius EWS356-Fit devices through 1.1.30 allow a remote attacker to conduct stored XSS attacks via the Wi-Fi SSID parameters. JavaScript embedded into a vulnerable field …

Oct 30, 2024
CVE-2024-31973
5.2 MEDIUM

Hitron CODA-4582 2AHKM-CODA4589 7.2.4.5.1b8 devices allow a remote attacker within Wi-Fi proximity to conduct stored XSS attacks via the 'Network Name (SSID)' input fields to …

Oct 30, 2024
CVE-2024-31972
4.3 MEDIUM

EnGenius ESR580 A8J-EMR5000 devices allow a remote attacker to conduct stored XSS attacks that could lead to arbitrary JavaScript code execution (under the context of …

Oct 30, 2024
CVE-2024-10456
9.8 CRITICAL

Delta Electronics InfraSuite Device Master versions prior to 1.0.12 are affected by a deserialization vulnerability that targets the Device-Gateway, which could allow deserialization of arbitrary …

Oct 30, 2024
CVE-2024-9110
6.4 MEDIUM

A medium severity vulnerability has been identified within Privileged Identity which can allow an attacker to perform reflected cross-site scripting attacks.

Oct 30, 2024
CVE-2024-51258
8.8 HIGH

DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doSSLTunnel function.

Oct 30, 2024
CVE-2024-50344
4.6 MEDIUM

I, Librarian is an open-source version of a PDF managing SaaS. Supplemental Files are allowed to be viewed in the browser, only if they have …

Oct 30, 2024
CVE-2024-50419
5.4 MEDIUM

Incorrect Authorization vulnerability in wpsoul Greenshift greenshift-animation-and-page-builder-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Greenshift: from n/a through <= 9.7.

Oct 30, 2024
CVE-2024-51301
8.8 HIGH

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the packet_monitor function.

Oct 30, 2024
CVE-2024-51300
8.8 HIGH

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the get_rrd function.

Oct 30, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.