CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-46549
7.6 HIGH

An issue in the TP-Link MQTT Broker and API gateway of TP-Link Kasa KP125M v1.0.3 allows attackers to establish connections by impersonating devices owned by …

Sep 30, 2024
CVE-2024-46548
6.3 MEDIUM

TP-Link Tapo P125M and Kasa KP125M v1.0.3 was discovered to improperly validate certificates, allowing attackers to eavesdrop on communications and access sensitive information via a …

Sep 30, 2024
CVE-2024-46540
6.3 MEDIUM

A remote code execution (RCE) vulnerability in the component /admin/store.php of Emlog Pro before v2.3.15 allows attackers to use remote file downloads and self-extract fucntions …

Sep 30, 2024
CVE-2024-45993
6.5 MEDIUM

Giflib Project v5.2.2 is vulnerable to a heap buffer overflow via gif2rgb.

Sep 30, 2024
CVE-2024-47532
6.5 MEDIUM

RestrictedPython is a restricted execution environment for Python to run untrusted code. A user can gain access to protected (and potentially sensible) information indirectly via …

Sep 30, 2024
CVE-2024-47531
4.6 MEDIUM

Scout is a web-based visualizer for VCF-files. Due to the lack of sanitization in the filename, it is possible bypass intended file extension and make …

Sep 30, 2024
CVE-2024-47530
5.4 MEDIUM

Scout is a web-based visualizer for VCF-files. Open redirect vulnerability allows performing phishing attacks on users by redirecting them to malicious page. /login API endpoint …

Sep 30, 2024
CVE-2024-47178
5.3 MEDIUM

basic-auth-connect is Connect's Basic Auth middleware in its own module. basic-auth-connect < 1.1.0 uses a timing-unsafe equality comparison that can leak timing information. This issue …

Sep 30, 2024
CVE-2024-47067
6.1 MEDIUM

AList is a file list program that supports multiple storages. AList contains a reflected cross-site scripting vulnerability in helper.go. The endpoint /i/:link_name takes in a …

Sep 30, 2024
CVE-2024-46869
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btintel_pcie: Allocate memory for driver private data Fix driver not allocating memory for struct …

Sep 30, 2024
CVE-2024-46510
7.6 HIGH

ESAFENET CDG v5 was discovered to contain a SQL injection vulnerability via the id parameter in the NavigationAjax interface

Sep 30, 2024
CVE-2024-46475
4.8 MEDIUM

A reflected cross-site scripting (XSS) vulnerability on the homepage of Metronic Admin Dashboard Template v2.0 allows attackers to execute arbitrary code in the context of …

Sep 30, 2024
CVE-2024-47172
5.4 MEDIUM

Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. An attacker with a CVAT account may retrieve certain …

Sep 30, 2024
CVE-2024-47064
6.1 MEDIUM

Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. If an attacker can trick a logged-in CVAT user …

Sep 30, 2024
CVE-2024-47063
6.1 MEDIUM

Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. If a malicious CVAT user with permissions to either …

Sep 30, 2024
CVE-2024-46313
8.0 HIGH

TP-Link WR941ND V6 has a stack overflow vulnerability in the ssid parameter in /userRpm/popupSiteSurveyRpm.htm.

Sep 30, 2024
CVE-2024-46293
9.8 CRITICAL

Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Incorrect Access Control. There is a lack of authorization checks for admin operations. Specifically, an attacker …

Sep 30, 2024
CVE-2024-46280
8.8 HIGH

PIX-LINK LV-WR22 RE3002-P1-01_V117.0 is vulnerable to Improper Access Control. The TELNET service is enabled with weak credentials for a root-level account, without the possibility of …

Sep 30, 2024
CVE-2024-45792
6.5 MEDIUM

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Using a crafted POST request, an unprivileged, registered user is able to retrieve information about …

Sep 30, 2024
CVE-2024-6051

Cross Application Scripting vulnerability in Vercom S.A. Redlink SDK in specific situations allows local code injection and to manipulate the view of a vulnerable application.This …

Sep 30, 2024
CVE-2024-47641
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Muhammad Shakeel Confetti Fall Animation confetti-fall-animation allows Stored XSS.This issue affects Confetti Fall …

Sep 30, 2024
CVE-2024-45920
5.4 MEDIUM

A Stored Cross-Site Scripting (XSS) vulnerability in Solvait 24.4.2 allows remote attackers to inject malicious scripts into the application. This issue arises due to insufficient …

Sep 30, 2024
CVE-2024-45772
5.1 MEDIUM

Deserialization of Untrusted Data vulnerability in Apache Lucene Replicator. This issue affects Apache Lucene's replicator module: from 4.4.0 before 9.12.0. The deprecated org.apache.lucene.replicator.http package is …

Sep 30, 2024
CVE-2024-9329
6.1 MEDIUM

In Eclipse Glassfish versions before 7.0.17, The Host HTTP parameter could cause the web application to redirect to the specified URL, when the requested endpoint …

Sep 30, 2024
CVE-2024-8459
7.2 HIGH

Certain switch models from PLANET Technology store SNMPv3 users' passwords in plaintext within the configuration files, allowing remote attackers with administrator privileges to read the …

Sep 30, 2024
CVE-2024-8458
8.8 HIGH

Certain switch models from PLANET Technology have a web application that is vulnerable to Cross-Site Request Forgery (CSRF). An unauthenticated remote attacker can trick a …

Sep 30, 2024
CVE-2024-8457
4.8 MEDIUM

Certain switch models from PLANET Technology have a web application that does not properly validate specific parameters, allowing remote authenticated users with administrator privileges to …

Sep 30, 2024
CVE-2024-8456
9.8 CRITICAL

Certain switch models from PLANET Technology lack proper access control in firmware upload and download functionality, allowing unauthenticated remote attackers to download and upload firmware …

Sep 30, 2024
CVE-2024-8455
8.1 HIGH

The swctrl service is used to detect and remotely manage PLANET Technology devices. For certain switch models, the authentication tokens used during communication with this …

Sep 30, 2024
CVE-2024-8454
5.3 MEDIUM

The swctrl service is used to detect and remotely manage PLANET Technology devices. Certain switch models have a Denial-of-Service vulnerability in the swctrl service, allowing …

Sep 30, 2024
CVE-2024-8453
4.9 MEDIUM

Certain switch models from PLANET Technology use an insecure hashing function to hash user passwords without being salted. Remote attackers with administrator privileges can read …

Sep 30, 2024
CVE-2024-6394
7.5 HIGH

A Local File Inclusion vulnerability exists in parisneo/lollms-webui versions below v9.8. The vulnerability is due to unverified path concatenation in the `serve_js` function in `app.py`, …

Sep 30, 2024
CVE-2024-45200
6.3 MEDIUM

In Nintendo Mario Kart 8 Deluxe before 3.0.3, the LAN/LDN local multiplayer implementation allows a remote attacker to exploit a stack-based buffer overflow upon deserialization …

Sep 30, 2024
CVE-2024-42496
2.4 LOW

Smart-tab Android app installed April 2023 or earlier contains an issue with plaintext storage of a password. If this vulnerability is exploited, an attacker with …

Sep 30, 2024
CVE-2024-41999
6.8 MEDIUM

Smart-tab Android app installed April 2023 or earlier contains an active debug code vulnerability. If this vulnerability is exploited, an attacker with physical access to …

Sep 30, 2024
CVE-2024-8452
7.5 HIGH

Certain switch models from PLANET Technology only support obsolete algorithms for authentication protocol and encryption protocol in the SNMPv3 service, allowing attackers to obtain plaintext …

Sep 30, 2024
CVE-2024-8451
7.5 HIGH

Certain switch models from PLANET Technology have an SSH service that improperly handles insufficiently authenticated connection requests, allowing unauthorized remote attackers to exploit this weakness …

Sep 30, 2024
CVE-2024-8450
8.6 HIGH

Certain switch models from PLANET Technology have a Hard-coded community string in the SNMPv1 service, allowing unauthorized remote attackers to use this community string to …

Sep 30, 2024
CVE-2024-8449
6.8 MEDIUM

Certain switch models from PLANET Technology have a Hard-coded Credential in the password recovering functionality, allowing an unauthenticated attacker to connect to the device via …

Sep 30, 2024
CVE-2024-8448
8.8 HIGH

Certain switch models from PLANET Technology have a hard-coded credential in the specific command-line interface, allowing remote attackers with regular privilege to log in with …

Sep 30, 2024
CVE-2024-8536
5.4 MEDIUM

The Ultimate Blocks WordPress plugin before 3.2.2 does not validate and escape some of its block attributes before outputting them back in a page/post where …

Sep 30, 2024
CVE-2024-8379
7.2 HIGH

The Cost Calculator Builder WordPress plugin before 3.2.29 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to …

Sep 30, 2024
CVE-2024-8283
4.8 MEDIUM

The Slider by 10Web WordPress plugin before 1.2.59 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Sep 30, 2024
CVE-2024-8239
5.4 MEDIUM

The Starbox WordPress plugin before 3.5.3 does not properly render social media profiles URLs in certain contexts, like the malicious user's profile or pages where …

Sep 30, 2024
CVE-2024-3635
4.8 MEDIUM

The Post Grid WordPress plugin before 7.5.0 does not sanitise and escape some of its Grid settings, which could allow high privilege users such as …

Sep 30, 2024
CVE-2024-9328
6.3 MEDIUM

A vulnerability was found in SourceCodester Advocate Office Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the …

Sep 29, 2024
CVE-2024-9327
6.3 MEDIUM

A vulnerability was found in code-projects Blood Bank System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /forgot.php. …

Sep 29, 2024
CVE-2024-9326
7.3 HIGH

A vulnerability classified as critical was found in PHPGurukul Online Shopping Portal 2.0. This vulnerability affects unknown code of the file /shopping/admin/index.php of the component …

Sep 29, 2024
CVE-2024-9325
7.8 HIGH

A vulnerability classified as critical has been found in Intelbras InControl up to 2.21.56. This affects an unknown part of the file C:\Program Files (x86)\Intelbras\Incontrol …

Sep 29, 2024
CVE-2024-9324
6.3 MEDIUM

A vulnerability was found in Intelbras InControl up to 2.21.57. It has been rated as critical. Affected by this issue is some unknown functionality of …

Sep 29, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.