CVE Database

11833+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-38124
9.0 CRITICAL

Windows Netlogon Elevation of Privilege Vulnerability

Oct 8, 2024
CVE-2024-45918
9.8 CRITICAL

Fujian Kelixin Communication Command and Dispatch Platform <=7.6.6.4391 is vulnerable to SQL Injection via /client/get_gis_fence.php.

Oct 8, 2024
CVE-2024-44349
9.8 CRITICAL

A SQL injection vulnerability in login portal in AnteeoWMS before v4.7.34 allows unauthenticated attackers to execute arbitrary SQL commands via the username parameter and disclosure …

Oct 8, 2024
CVE-2024-3057
9.8 CRITICAL

A flaw exists whereby a user can make a specific call to a FlashArray endpoint allowing privilege escalation.

Oct 8, 2024
CVE-2024-8884
9.8 CRITICAL

CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause exposure of credentials when attacker has access to application on network …

Oct 8, 2024
CVE-2024-8943
9.8 CRITICAL

The LatePoint plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.0.12. This is due to insufficient verification on the …

Oct 8, 2024
CVE-2024-8911
9.8 CRITICAL

The LatePoint plugin for WordPress is vulnerable to Arbitrary User Password Change via SQL Injection in versions up to, and including, 5.0.11. This is due …

Oct 8, 2024
CVE-2024-47553
9.9 CRITICAL

A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate user input to the ```ssmctl-client``` …

Oct 8, 2024
CVE-2024-41798
9.8 CRITICAL

A vulnerability has been identified in SENTRON 7KM PAC3200 (All versions). Affected devices only provide a 4-digit PIN to protect from administrative access via Modbus …

Oct 8, 2024
CVE-2024-45874
9.8 CRITICAL

A DLL hijacking vulnerability in VegaBird Vooki 5.2.9 allows attackers to execute arbitrary code / maintain persistence via placing a crafted DLL file in the …

Oct 7, 2024
CVE-2024-45873
9.8 CRITICAL

A DLL hijacking vulnerability in VegaBird Yaazhini 2.0.2 allows attackers to execute arbitrary code / maintain persistence via placing a crafted DLL file in the …

Oct 7, 2024
CVE-2024-46076
9.8 CRITICAL

RuoYi v4.7.9 and before has a security flaw that allows escaping from comments within the code generation feature, enabling the injection of malicious code.

Oct 7, 2024
CVE-2024-46446
9.8 CRITICAL

Mecha CMS 3.0.0 is vulnerable to Directory Traversal. An attacker can construct cookies and URIs that bypass user identity checks. Parameters can then be passed …

Oct 7, 2024
CVE-2024-9574
9.8 CRITICAL

SQL injection vulnerability in SOPlanning <1.45, via /soplanning/www/user_groupes.php in the by parameter, which could allow a remote user to submit a specially crafted query, allowing …

Oct 7, 2024
CVE-2024-33066
9.8 CRITICAL

Memory corruption while redirecting log file to any file location with any file name.

Oct 7, 2024
CVE-2024-20103
9.8 CRITICAL

In wlan firmware, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no …

Oct 7, 2024
CVE-2024-20101
9.8 CRITICAL

In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no …

Oct 7, 2024
CVE-2024-20100
9.8 CRITICAL

In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no …

Oct 7, 2024
CVE-2024-47350
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YITHEMES YITH WooCommerce Ajax Search yith-woocommerce-ajax-search.This issue affects YITH WooCommerce Ajax …

Oct 6, 2024
CVE-2024-45252
9.8 CRITICAL

Elsight – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Oct 6, 2024
CVE-2024-45251
9.8 CRITICAL

Elsight – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Oct 6, 2024
CVE-2024-45249
9.8 CRITICAL

Cavok – CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Oct 6, 2024
CVE-2024-44014
9.6 CRITICAL

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Vmax Studio Vmax Project Manager vmax-project-manager allows PHP Local File Inclusion.This issue …

Oct 5, 2024
CVE-2024-47849
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in The Wikimedia Foundation Mediawiki - Cargo allows SQL Injection.This issue affects …

Oct 5, 2024
CVE-2024-43685
9.8 CRITICAL

Improper Authentication vulnerability in Microchip TimeProvider 4100 (login modules) allows Session Hijacking.This issue affects TimeProvider 4100: from 1.0 before 2.4.7.

Oct 4, 2024
CVE-2023-26770
9.8 CRITICAL

TaskCafe 0.3.2 lacks validation in the Cookie value. Any unauthenticated attacker who knows a registered UserID can change the password of that user.

Oct 4, 2024
CVE-2024-47656
9.8 CRITICAL

This vulnerability exists in Shilpi Client Dashboard due to missing restrictions for incorrect login attempts on its API based login. A remote attacker could exploit …

Oct 4, 2024
CVE-2024-45367
9.1 CRITICAL

The web server for ONS-S8 - Spectra Aggregation Switch includes an incomplete authentication process, which can lead to an attacker authenticating without a password.

Oct 3, 2024
CVE-2024-43699
9.8 CRITICAL

Delta Electronics DIAEnergie is vulnerable to an SQL injection in the script AM_RegReport.aspx. An unauthenticated attacker may be able to exploit this issue to obtain …

Oct 3, 2024
CVE-2024-41925
9.8 CRITICAL

The web service for ONS-S8 - Spectra Aggregation Switch includes functions which do not properly validate user input, allowing an attacker to traverse directories, bypass …

Oct 3, 2024
CVE-2024-41593
9.8 CRITICAL

DrayTek Vigor310 devices through 4.3.2.6 allow a remote attacker to execute arbitrary code via the function ft_payload_dns(), because a byte sign-extension operation occurs for the …

Oct 3, 2024
CVE-2024-7826
9.8 CRITICAL

Improper Check for Unusual or Exceptional Conditions vulnerability in Webroot SecureAnywhere - Web Shield on Windows, ARM, 64 bit, 32 bit (wrURL.Dll modules) allows Functionality …

Oct 3, 2024
CVE-2024-7825
9.8 CRITICAL

Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Webroot SecureAnywhere - Web Shield on Windows, ARM, 64 bit, 32 bit (wrUrl.Dll modules) allows …

Oct 3, 2024
CVE-2024-7824
9.8 CRITICAL

Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Webroot SecureAnywhere - Web Shield on Windows, ARM, 64 bit, 32 bit (wrUrl.Dll modules) allows …

Oct 3, 2024
CVE-2024-45519
10.0 CRITICAL KEV

The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1 sometimes allows …

Oct 2, 2024
CVE-2024-24117
9.8 CRITICAL

Insecure Permissions vulnerability in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release (9736) allows a remote attacker to gain privileges via the login check state component.

Oct 2, 2024
CVE-2024-9441
9.8 CRITICAL

The Linear eMerge e3-Series through version 1.00-07 is vulnerable to an OS command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary OS commands …

Oct 2, 2024
CVE-2024-24116
9.8 CRITICAL

An issue in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release(9736) allows a remote attacker to gain privileges via the system/config_menu.htm.

Oct 2, 2024
CVE-2024-20432
9.9 CRITICAL

A vulnerability in the REST API and web UI of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, low-privileged, remote attacker to perform …

Oct 2, 2024
CVE-2024-6360
9.8 CRITICAL

Incorrect Permission Assignment for Critical Resource vulnerability in OpenText™ Vertica could allow Privilege Abuse and result in unauthorized access or privileges to Vertica agent apikey. …

Oct 2, 2024
CVE-2024-44097
9.8 CRITICAL

According to the researcher: "The TLS connections are encrypted against tampering or eavesdropping. However, the application does not validate the server certificate properly while initializing …

Oct 2, 2024
CVE-2024-35293
9.1 CRITICAL

An unauthenticated remote attacker may use a missing authentication for critical function vulnerability to reboot or erase the affected devices resulting in data loss and/or …

Oct 2, 2024
CVE-2024-45186
9.8 CRITICAL

FileSender before 2.49 allows server-side template injection (SSTI) for retrieving credentials.

Oct 2, 2024
CVE-2024-45999
9.8 CRITICAL

A SQL Injection vulnerability was discovered in Cloudlog 2.6.15, specifically within the get_station_info()function located in the file /application/models/Oqrs_model.php. The vulnerability is exploitable via the station_id …

Oct 1, 2024
CVE-2024-47608
9.8 CRITICAL

Logicytics is designed to harvest and collect data for forensic analysis. Logicytics has a basic vuln affecting compromised devices from shell injections. This vulnerability is …

Oct 1, 2024
CVE-2024-9402
9.8 CRITICAL

Memory safety bugs present in Firefox 130, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence of memory corruption and we presume …

Oct 1, 2024
CVE-2024-9401
9.8 CRITICAL

Memory safety bugs present in Firefox 130, Firefox ESR 115.15, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence of memory corruption …

Oct 1, 2024
CVE-2024-9392
9.8 CRITICAL

A compromised content process could have allowed for the arbitrary loading of cross-origin pages. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox …

Oct 1, 2024
CVE-2024-25660
9.0 CRITICAL

The WebDAV service in Infinera TNMS (Transcend Network Management System) 19.10.3 allows a low-privileged remote attacker to conduct unauthorized file operations, because of execution with …

Oct 1, 2024
CVE-2024-41276
9.8 CRITICAL

A vulnerability in Kaiten version 57.131.12 and earlier allows attackers to bypass the PIN code authentication mechanism. The application requires users to input a 6-digit …

Oct 1, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.