CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-38308
8.8 HIGH

Advantech ADAM 5550's web application includes a "logs" page where all the HTTP requests received are displayed to the user. The device doesn't correctly neutralize …

Sep 27, 2024
CVE-2024-37187
5.7 MEDIUM

Advantech ADAM-5550 share user credentials with a low level of encryption, consisting of base 64 encoding.

Sep 27, 2024
CVE-2024-34542
5.7 MEDIUM

Advantech ADAM-5630 shares user credentials plain text between the device and the user source device during the login process.

Sep 27, 2024
CVE-2024-28948
8.0 HIGH

Advantech ADAM-5630 contains a cross-site request forgery (CSRF) vulnerability. It allows an attacker to partly circumvent the same origin policy, which is designed to prevent …

Sep 27, 2024
CVE-2024-25412
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in Flatpress v1.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email …

Sep 27, 2024
CVE-2024-25411
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in Flatpress v1.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username …

Sep 27, 2024
CVE-2024-9284
6.5 MEDIUM

A vulnerability was found in TP-LINK TL-WR841ND up to 20240920. It has been rated as critical. Affected by this issue is some unknown functionality of …

Sep 27, 2024
CVE-2024-8630
9.4 CRITICAL

Alisonic Sibylla devices are vulnerable to SQL injection attacks, which could allow complete access to the database.

Sep 27, 2024
CVE-2024-8310
9.8 CRITICAL

OPW Fuel Management Systems SiteSentinel could allow an attacker to bypass authentication to the server and obtain full admin privileges.

Sep 27, 2024
CVE-2024-6981
9.8 CRITICAL

OMNTEC Proteus Tank Monitoring OEL8000III Series could allow an attacker to perform administrative actions without proper authentication.

Sep 27, 2024
CVE-2024-46367
9.6 CRITICAL

A Stored Cross-Site Scripting (XSS) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to inject arbitrary JavaScript code by submitting a malicious payload within …

Sep 27, 2024
CVE-2024-46366
8.8 HIGH

A Client-side Template Injection (CSTI) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to execute arbitrary client-side template code by injecting a malicious payload …

Sep 27, 2024
CVE-2024-38809
5.3 MEDIUM

Applications that parse ETags from "If-Match" or "If-None-Match" request headers are vulnerable to DoS attack. Users of affected versions should upgrade to the corresponding fixed …

Sep 27, 2024
CVE-2024-22170

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Western Digital My Cloud ddns-start on Linux allows Overflow Buffers.This issue affects …

Sep 27, 2024
CVE-2024-6983
8.8 HIGH

mudler/localai version 2.17.1 is vulnerable to remote code execution. The vulnerability arises because the localai backend receives inputs not only from the configuration file but …

Sep 27, 2024
CVE-2024-47077
6.5 MEDIUM

authentik is an open-source identity provider. Prior to versions 2024.8.3 and 2024.6.5, access tokens issued to one application can be stolen by that application and …

Sep 27, 2024
CVE-2024-47070
9.0 CRITICAL

authentik is an open-source identity provider. A vulnerability that exists in versions prior to 2024.8.3 and 2024.6.5 allows bypassing password login by adding X-Forwarded-For header …

Sep 27, 2024
CVE-2024-45745
5.0 MEDIUM

TopQuadrant TopBraid EDG before version 8.0.1 allows an authenticated attacker to upload an XML DTD file and execute JavaScript to read local files or access …

Sep 27, 2024
CVE-2024-45744
3.0 LOW

TopQuadrant TopBraid EDG stores external credentials insecurely. An authenticated attacker with file system access can read edg-setup.properites and obtain the secret to decrypt external passwords …

Sep 27, 2024
CVE-2024-46472
8.6 HIGH

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection via the parameter 'email' in the Login Page.

Sep 27, 2024
CVE-2024-46471
7.5 HIGH

The Directory Listing in /uploads/ Folder in CodeAstro Membership Management System 1.0 exposes the structure and contents of directories, potentially revealing sensitive information.

Sep 27, 2024
CVE-2024-46470
6.1 MEDIUM

Cross Site Scripting vulnerability in CodeAstro Membership Management System 1.0 allows attackers to run malicious JavaScript via the membership_type field in the edit-type.php component.

Sep 27, 2024
CVE-2024-46333
4.8 MEDIUM

An authenticated cross-site scripting (XSS) vulnerability in Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the …

Sep 27, 2024
CVE-2024-46331
7.2 HIGH

ModStartCMS v8.8.0 was discovered to contain an open redirect vulnerability in the redirect parameter at /admin/login. This vulnerability allows attackers to redirect users to an …

Sep 27, 2024
CVE-2024-44912
7.5 HIGH

NASA CryptoLib v1.3.0 was discovered to contain an Out-of-Bounds read via the TM subsystem (crypto_tm.c).

Sep 27, 2024
CVE-2024-44911
7.5 HIGH

NASA CryptoLib v1.3.0 was discovered to contain an Out-of-Bounds read via the TC subsystem (crypto_tc.c).

Sep 27, 2024
CVE-2024-44910
7.5 HIGH

NASA CryptoLib v1.3.0 was discovered to contain an Out-of-Bounds read via the AOS subsystem (crypto_aos.c).

Sep 27, 2024
CVE-2024-40510
8.2 HIGH

Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMCommon.asmx function.

Sep 27, 2024
CVE-2024-40509
7.3 HIGH

Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMFinDev.asmx function.

Sep 27, 2024
CVE-2024-3373

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RSM Design Website Template allows SQL Injection.This issue affects Website Template: …

Sep 27, 2024
CVE-2024-9283
3.3 LOW

A vulnerability classified as problematic has been found in RelaxedJS ReLaXed up to 0.2.2. Affected is an unknown function of the component Pug to PDF …

Sep 27, 2024
CVE-2024-7149
8.8 HIGH

The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, …

Sep 27, 2024
CVE-2024-47184
6.1 MEDIUM

Ampache is a web based audio/video streaming application and file manager. Prior to version 6.6.0, the Democratic Playlist Name is vulnerable to a stored cross-site …

Sep 27, 2024
CVE-2024-47182
4.8 MEDIUM

Dozzle is a realtime log viewer for docker containers. Before version 8.5.3, the app uses sha-256 as the hash for passwords, which leaves users susceptible …

Sep 27, 2024
CVE-2024-45863
5.3 MEDIUM

A null-dereference vulnerability involving parsing requests specifying invalid protocols can cause the application to crash or potentially result in other undesirable effects. This issue affects …

Sep 27, 2024
CVE-2024-45773
7.5 HIGH

A use-after-free vulnerability involving upgradeToRocket requests can cause the application to crash or potentially result in code execution or other undesirable effects. This issue affects …

Sep 27, 2024
CVE-2024-40512
7.3 HIGH

Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMReporting.asmx function.

Sep 27, 2024
CVE-2024-40511
7.3 HIGH

Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMServerAdmin.asmx function.

Sep 27, 2024
CVE-2024-9282
4.3 MEDIUM

A vulnerability was found in bg5sbk MiniCMS 1.11. It has been classified as problematic. Affected is an unknown function of the file page-edit.php. The manipulation …

Sep 27, 2024
CVE-2024-9281
4.3 MEDIUM

A vulnerability was found in bg5sbk MiniCMS up to 1.11 and classified as problematic. This issue affects some unknown processing of the file post-edit.php. The …

Sep 27, 2024
CVE-2024-46868
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: firmware: qcom: uefisecapp: Fix deadlock in qcuefi_acquire() If the __qcuefi pointer is not set, then …

Sep 27, 2024
CVE-2024-46867
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/xe/client: fix deadlock in show_meminfo() There is a real deadlock as well as sleeping in …

Sep 27, 2024
CVE-2024-46866
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/xe/client: add missing bo locking in show_meminfo() bo_meminfo() wants to inspect bo state like tt …

Sep 27, 2024
CVE-2024-46865
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: fou: fix initialization of grc The grc must be initialize first. There can be a …

Sep 27, 2024
CVE-2024-46864
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: x86/hyperv: fix kexec crash due to VP assist page corruption commit 9636be85cc5b ("x86/hyperv: Fix hyperv_pcpu_input_arg …

Sep 27, 2024
CVE-2024-46863
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: soc-acpi-intel-lnl-match: add missing empty item There is no links_num in struct snd_soc_acpi_mach {}, …

Sep 27, 2024
CVE-2024-46862
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: soc-acpi-intel-mtl-match: add missing empty item There is no links_num in struct snd_soc_acpi_mach {}, …

Sep 27, 2024
CVE-2024-46861
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usbnet: ipheth: do not stop RX on failing RX callback RX callbacks can fail for …

Sep 27, 2024
CVE-2024-46860
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7921: fix NULL pointer access in mt7921_ipv6_addr_change When disabling wifi mt7921_ipv6_addr_change() is called …

Sep 27, 2024
CVE-2024-46859
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: platform/x86: panasonic-laptop: Fix SINF array out of bounds accesses The panasonic laptop code in various …

Sep 27, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.