CVE Database

9973+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-33350
9.8 CRITICAL

Directory Traversal vulnerability in TaoCMS v.3.0.2 allows a remote attacker to execute arbitrary code and obtain sensitive information via the include/model/file.php component.

Apr 29, 2024
CVE-2024-33435
9.8 CRITICAL

Insecure Permissions vulnerability in Guangzhou Yingshi Electronic Technology Co. Ncast Yingshi high-definition intelligent recording and playback system 2007-2017 allows a remote attacker to execute arbitrary …

Apr 29, 2024
CVE-2024-33276
9.8 CRITICAL

SQL Injection vulnerability in FME Modules preorderandnotication v.3.1.0 and before allows a remote attacker to run arbitrary SQL commands via the PreorderModel::getIdProductAttributesByIdAttributes() method.

Apr 29, 2024
CVE-2024-33269
9.8 CRITICAL

SQL Injection vulnerability in Prestaddons flashsales 1.9.7 and before allows an attacker to run arbitrary SQL commands via the FsModel::getFlashSales method.

Apr 29, 2024
CVE-2024-33268
9.8 CRITICAL

SQL Injection vulnerability in Digincube mdgiftproduct before 1.4.1 allows an attacker to run arbitrary SQL commands via the MdGiftRule::addGiftToCart method.

Apr 29, 2024
CVE-2024-33266
9.8 CRITICAL

SQL Injection vulnerability in Helloshop deliveryorderautoupdate v.2.8.1 and before allows an attacker to run arbitrary SQL commands via the DeliveryorderautoupdateOrdersModuleFrontController::initContent function.

Apr 29, 2024
CVE-2024-31822
9.8 CRITICAL

An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the saveLanguageFiles method of the Languages.php component.

Apr 29, 2024
CVE-2024-31820
9.8 CRITICAL

An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the getLangFolderForEdit method of the Languages.php component.

Apr 29, 2024
CVE-2024-31705
9.8 CRITICAL

An issue in Infotel Conseil GLPI v.10.X.X and after allows a remote attacker to execute arbitrary code via the insufficient validation of user-supplied input.

Apr 29, 2024
CVE-2024-33449
9.8 CRITICAL

An SSRF issue in the PDFMyURL service allows a remote attacker to obtain sensitive information and execute arbitrary code via a POST request in the …

Apr 29, 2024
CVE-2024-33445
9.8 CRITICAL

An issue in hisiphp v2.0.111 allows a remote attacker to execute arbitrary code via a crafted script to the SystemPlugins::mkInfo parameter in the SystemPlugins.php component.

Apr 29, 2024
CVE-2024-33444
9.8 CRITICAL

SQL injection vulnerability in onethink v.1.1 allows a remote attacker to escalate privileges via a crafted script to the ModelModel.class.php component.

Apr 29, 2024
CVE-2024-32491
9.8 CRITICAL

An issue was discovered in Znuny and Znuny LTS 6.0.31 through 6.5.7 and Znuny 7.0.1 through 7.0.16 where a logged-in user can upload a file …

Apr 29, 2024
CVE-2024-4306
9.9 CRITICAL

Critical unrestricted file upload vulnerability in HubBank affecting version 1.0.2. This vulnerability allows a registered user to upload malicious PHP files via upload document fields, …

Apr 29, 2024
CVE-2024-3375
9.4 CRITICAL

Incorrect Permission Assignment for Critical Resource vulnerability in Havelsan Inc. Dialogue allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Dialogue: from v1.83 before …

Apr 29, 2024
CVE-2024-33566
10.0 CRITICAL

Missing Authorization vulnerability in N-Media OrderConvo allows OS Command Injection.This issue affects OrderConvo: from n/a through 12.4.

Apr 29, 2024
CVE-2024-33553
9.0 CRITICAL

Deserialization of Untrusted Data vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.5.

Apr 29, 2024
CVE-2024-3191
9.8 CRITICAL

A vulnerability, which was classified as critical, has been found in MailCleaner up to 2023.03.14. This issue affects some unknown processing of the component Email …

Apr 29, 2024
CVE-2024-33546
9.6 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team WZone allows SQL Injection.This issue affects WZone: from n/a through …

Apr 29, 2024
CVE-2024-33544
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team WZone allows SQL Injection.This issue affects WZone: from n/a through …

Apr 29, 2024
CVE-2024-33559
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 8theme XStore allows SQL Injection.This issue affects XStore: from n/a through …

Apr 29, 2024
CVE-2024-33551
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 8theme XStore Core allows SQL Injection.This issue affects XStore Core: from …

Apr 29, 2024
CVE-2024-4300
9.8 CRITICAL

E-WEBInformationCo. FS-EZViewer(Web) exposes sensitive information in the service. A remote attacker can obtain the database configuration file path through the webpage source code without login. …

Apr 29, 2024
CVE-2024-1874
9.4 CRITICAL

In PHP versions 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, when using proc_open() command with array syntax, due to insufficient escaping, if the …

Apr 29, 2024
CVE-2024-3342
9.9 CRITICAL

The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to SQL Injection via the 'events' attribute of the 'mp-timetable' shortcode in all …

Apr 27, 2024
CVE-2024-30804
9.8 CRITICAL

An issue discovered in the DeviceIoControl component in ASUS Fan_Xpert before v.10013 allows an attacker to execute arbitrary code via crafted IOCTL requests.

Apr 26, 2024
CVE-2024-28322
9.8 CRITICAL

SQL Injection vulnerability in /event-management-master/backend/register.php in PuneethReddyHC Event Management 1.0 allows attackers to run arbitrary SQL commands via the event_id parameter in a crafted POST …

Apr 26, 2024
CVE-2024-32881
9.8 CRITICAL

Danswer is the AI Assistant connected to company's docs, apps, and people. Danswer is vulnerable to unauthorized access to GET/SET of Slack Bot Tokens. Anyone …

Apr 26, 2024
CVE-2024-31601
9.8 CRITICAL

An issue in Beijing Panabit Network Software Co., Ltd Panalog big data analysis platform v. 20240323 and before allows attackers to execute arbitrary code via …

Apr 26, 2024
CVE-2024-25343
9.1 CRITICAL

Tenda N300 F3 router vulnerability allows users to bypass intended security policy and create weak passwords.

Apr 26, 2024
CVE-2024-33344
9.8 CRITICAL

D-Link DIR-822+ V1.0.5 was found to contain a command injection in ftext function of upload_firmware.cgi, which allows remote attackers to execute arbitrary commands via shell.

Apr 26, 2024
CVE-2024-32880
9.1 CRITICAL

pyload is an open-source Download Manager written in pure Python. An authenticated user can change the download folder and upload a crafted template to the …

Apr 26, 2024
CVE-2024-32766
10.0 CRITICAL

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands …

Apr 26, 2024
CVE-2024-32764
9.9 CRITICAL

A missing authentication for critical function vulnerability has been reported to affect myQNAPcloud Link. If exploited, the vulnerability could allow users with the privilege level …

Apr 26, 2024
CVE-2023-47222
9.6 CRITICAL

An exposure of sensitive information vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow users to compromise the security …

Apr 26, 2024
CVE-2024-0740
9.8 CRITICAL

Eclipse Target Management: Terminal and Remote System Explorer (RSE) version <= 4.5.400 has a remote code execution vulnerability that does not require authentication. The fixed …

Apr 26, 2024
CVE-2024-3962
9.8 CRITICAL

The Product Addons & Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ppom_upload_file …

Apr 26, 2024
CVE-2024-22633
9.8 CRITICAL

Setor Informatica Sistema Inteligente para Laboratorios (S.I.L.) 388 was discovered to contain a remote code execution (RCE) vulnerability via the hprinter parameter. This vulnerability is …

Apr 26, 2024
CVE-2024-22632
9.8 CRITICAL

Setor Informatica Sistema Inteligente para Laboratorios (S.I.L.) 388 was discovered to contain a remote code execution (RCE) vulnerability via the hmsg parameter. This vulnerability is …

Apr 26, 2024
CVE-2024-33668
9.1 CRITICAL

An issue was discovered in Zammad before 6.3.0. The Zammad Upload Cache uses insecure, partially guessable FormIDs to identify content. An attacker could try to …

Apr 26, 2024
CVE-2024-33661
9.1 CRITICAL

Portainer before 2.20.0 allows redirects when the target is not index.yaml.

Apr 26, 2024
CVE-2024-32651
10.0 CRITICAL

changedetection.io is an open source web page change detection, website watcher, restock monitor and notification service. There is a Server Side Template Injection (SSTI) in …

Apr 26, 2024
CVE-2024-0916
10.0 CRITICAL

Unauthenticated file upload allows remote code execution. This issue affects UvDesk Community: from 1.0.0 through 1.1.3.

Apr 25, 2024
CVE-2022-36029
9.1 CRITICAL

Greenlight is an end-user interface for BigBlueButton servers. Versions prior to 2.13.0 have an open redirect vulnerability in the Login page due to unchecked the …

Apr 25, 2024
CVE-2022-36028
9.1 CRITICAL

Greenlight is an end-user interface for BigBlueButton servers. Versions prior to 2.13.0 have an open redirect vulnerability in the Login page due to unchecked the …

Apr 25, 2024
CVE-2024-31615
9.8 CRITICAL

ThinkCMF 6.0.9 is vulnerable to File upload via UeditorController.php.

Apr 25, 2024
CVE-2024-31266
9.1 CRITICAL

Improper Control of Generation of Code ('Code Injection') vulnerability in AlgolPlus Advanced Order Export For WooCommerce allows Code Injection.This issue affects Advanced Order Export For …

Apr 25, 2024
CVE-2024-30560
9.6 CRITICAL

Cross-Site Request Forgery (CSRF) vulnerability in 大侠WP DX-Watermark.This issue affects DX-Watermark: from n/a through 1.0.4.

Apr 25, 2024
CVE-2024-22144
9.0 CRITICAL

Improper Control of Generation of Code ('Code Injection') vulnerability in Eli Scheetz Anti-Malware Security and Brute-Force Firewall gotmls allows Code Injection.This issue affects Anti-Malware Security …

Apr 25, 2024
CVE-2023-51484
9.8 CRITICAL

Improper Authentication vulnerability in wp-buy Login as User or Customer (User Switching) allows Privilege Escalation.This issue affects Login as User or Customer (User Switching): from …

Apr 25, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.