CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-35584
8.8 HIGH

SQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in OpenSis Community Edition 9.1 to 8.0, and possibly earlier versions. It is possible …

Oct 15, 2024
CVE-2024-5749
7.5 HIGH

Certain HP DesignJet products may be vulnerable to credential reflection which allow viewing SMTP server credentials.

Oct 15, 2024
CVE-2024-48915

Agent Dart is an agent library built for Internet Computer for Dart and Flutter apps. Prior to version 1.0.0-dev.29, certificate verification in `lib/agent/certificate.dart` does not …

Oct 15, 2024
CVE-2024-9676
6.5 MEDIUM

A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Buildah, and CRI-O to hang …

Oct 15, 2024
CVE-2024-9506
3.7 LOW

Improper regular expression in Vue's parseHTML function leads to a potential regular expression denial of service vulnerability.

Oct 15, 2024
CVE-2024-48914
9.1 CRITICAL

Vendure is an open-source headless commerce platform. Prior to versions 3.0.5 and 2.3.3, a vulnerability in Vendure's asset server plugin allows an attacker to craft …

Oct 15, 2024
CVE-2024-48913
5.9 MEDIUM

Hono, a web framework, prior to version 4.6.5 is vulnerable to bypass of cross-site request forgery (CSRF) middleware by a request without Content-Type header. Although …

Oct 15, 2024
CVE-2024-48624
5.3 MEDIUM

In segments\edit.php of DomainMOD below v4.12.0, the segid parameter in the GET request can be exploited to cause a reflected Cross Site Scripting (XSS) vulnerability.

Oct 15, 2024
CVE-2024-48623
5.3 MEDIUM

In queue\index.php of DomainMOD below v4.12.0, the list_id and domain_id parameters in the GET request can be exploited to cause a reflected Cross Site Scripting …

Oct 15, 2024
CVE-2024-48622
6.6 MEDIUM

A cross-site scripting (XSS) issue in DomainMOD below v4.12.0 allows remote attackers to inject JavaScript code via admin/domain-fields/edit.php and the cdfid parameter.

Oct 15, 2024
CVE-2024-47876
8.8 HIGH

Sakai is a Collaboration and Learning Environment. Starting in version 23.0 and prior to version 23.2, kernel users created with type roleview can log in …

Oct 15, 2024
CVE-2024-47874

Starlette is an Asynchronous Server Gateway Interface (ASGI) framework/toolkit. Prior to version 0.40.0, Starlette treats `multipart/form-data` parts without a `filename` as text form fields and …

Oct 15, 2024
CVE-2024-47824

matrix-react-sdk is react-based software development kit for inserting a Matrix chat/VOIP client into a web page. Starting in version 3.18.0 and before 3.102.0, matrix-react-sdk allows …

Oct 15, 2024
CVE-2024-47779

Element is a Matrix web client built using the Matrix React SDK. Element Web versions 1.11.70 through 1.11.80 contain a vulnerability which can, under specially …

Oct 15, 2024
CVE-2024-47771

Element Desktop is a Matrix client for desktop platforms. Element Desktop versions 1.11.70 through 1.11.80 contain a vulnerability which can, under specially crafted conditions, lead …

Oct 15, 2024
CVE-2024-47080

matrix-js-sdk is the Matrix Client-Server SDK for JavaScript and TypeScript. In matrix-js-sdk versions versions 9.11.0 through 34.7.0, the method `MatrixClient.sendSharedHistoryKeys` is vulnerable to interception by …

Oct 15, 2024
CVE-2023-31493
6.6 MEDIUM

RCE (Remote Code Execution) exists in ZoneMinder through 1.36.33 as an attacker can create a new .php log file in language folder, while executing a …

Oct 15, 2024
CVE-2024-9979
5.3 MEDIUM

A flaw was found in PyO3. This vulnerability causes a use-after-free issue, potentially leading to memory corruption or crashes via unsound borrowing from weak Python …

Oct 15, 2024
CVE-2024-48948
4.8 MEDIUM

The Elliptic package 6.5.7 for Node.js, in its for ECDSA implementation, does not correctly verify valid signatures if the hash contains at least four leading …

Oct 15, 2024
CVE-2024-9986
7.3 HIGH

A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the …

Oct 15, 2024
CVE-2024-9977
4.7 MEDIUM

A vulnerability, which was classified as critical, was found in MitraStar GPT-2541GNAC BR_g5.6_1.11(WVK.0)b26. Affected is an unknown function of the file /cgi-bin/settings-firewall.cgi of the component …

Oct 15, 2024
CVE-2024-48283
9.8 CRITICAL

Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to SQL Injection in /admin//search-result.php via the searchkey parameter.

Oct 15, 2024
CVE-2024-48282
7.6 HIGH

A SQL Injection vulnerability was found in /password-recovery.php of PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers to execute …

Oct 15, 2024
CVE-2024-48280
7.6 HIGH

A SQL Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers to execute …

Oct 15, 2024
CVE-2024-48279
7.6 HIGH

A HTML Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Management System 3.2. This vulnerability allows remote attackers to …

Oct 15, 2024
CVE-2024-48278
5.5 MEDIUM

Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to Cross Site Request Forgery (CSRF) via /edit-profile.php.

Oct 15, 2024
CVE-2024-9976
6.3 MEDIUM

A vulnerability classified as critical has been found in code-projects Pharmacy Management System 1.0. This affects an unknown part of the file /php/manage_customer.php?action=search. The manipulation …

Oct 15, 2024
CVE-2024-9975
6.3 MEDIUM

A vulnerability was found in SourceCodester Drag and Drop Image Upload 1.0. It has been rated as critical. Affected by this issue is some unknown …

Oct 15, 2024
CVE-2024-49388
9.1 CRITICAL

Sensitive information manipulation due to improper authorization. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.

Oct 15, 2024
CVE-2024-49387
7.5 HIGH

Cleartext transmission of sensitive information in acep-collector service. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.

Oct 15, 2024
CVE-2024-49384
4.3 MEDIUM

Excessive attack surface in acep-collector service due to binding to an unrestricted IP address. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) …

Oct 15, 2024
CVE-2024-49383
4.3 MEDIUM

Excessive attack surface in acep-importer service due to binding to an unrestricted IP address. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) …

Oct 15, 2024
CVE-2024-49382
4.3 MEDIUM

Excessive attack surface in archive-server service due to binding to an unrestricted IP address. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) …

Oct 15, 2024
CVE-2024-47674
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm: avoid leaving partial pfn mappings around in error case As Jann points out, PFN …

Oct 15, 2024
CVE-2024-45276
7.5 HIGH

An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication.

Oct 15, 2024
CVE-2024-45275
9.8 CRITICAL

The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full control of the affected devices.

Oct 15, 2024
CVE-2024-45274
9.8 CRITICAL

An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication.

Oct 15, 2024
CVE-2024-45273
8.4 HIGH

An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used.

Oct 15, 2024
CVE-2024-45272
7.5 HIGH

An unauthenticated remote attacker can perform a brute-force attack on the credentials of the remote service portal with a high chance of success, resulting in …

Oct 15, 2024
CVE-2024-45271
8.4 HIGH

An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation.

Oct 15, 2024
CVE-2024-9974
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Oct 15, 2024
CVE-2024-9973
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/?page=reports …

Oct 15, 2024
CVE-2024-47945
9.8 CRITICAL

The devices are vulnerable to session hijacking due to insufficient entropy in its session ID generation algorithm. The session IDs are predictable, with only 32,768 …

Oct 15, 2024
CVE-2024-9985
10.0 CRITICAL

Enterprise Cloud Database from Ragic does not properly validate the file type for uploads. Attackers with regular privileges can upload a webshell and use it …

Oct 15, 2024
CVE-2024-9984
9.8 CRITICAL

Enterprise Cloud Database from Ragic does not authenticate access to specific functionality, allowing unauthenticated remote attackers to use this functionality to obtain any user's session …

Oct 15, 2024
CVE-2024-9983
7.5 HIGH

Enterprise Cloud Database from Ragic does not properly validate a specific page parameter, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system …

Oct 15, 2024
CVE-2024-9925
9.8 CRITICAL

SQL injection vulnerability in TAI Smart Factory's QPLANT SF version 1.0. Exploitation of this vulnerability could allow a remote attacker to retrieve all database information …

Oct 15, 2024
CVE-2024-9895
6.4 MEDIUM

The Smart Online Order for Clover plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's moo_receipt_link shortcode in all versions up to, …

Oct 15, 2024
CVE-2024-47944
6.8 MEDIUM

The device directly executes .patch firmware upgrade files on a USB stick without any prior authentication in the admin interface. This leads to an unauthenticated …

Oct 15, 2024
CVE-2024-47943
9.8 CRITICAL

The firmware upgrade function in the admin web interface of the Rittal IoT Interface & CMC III Processing Unit devices checks if the patch files …

Oct 15, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.