CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-47076
8.6 HIGH

CUPS is a standards-based, open-source printing system, and `libcupsfilters` contains the code of the filters of the former `cups-filters` package as library functions to be …

Sep 26, 2024
CVE-2024-40508
7.3 HIGH

Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMConference.asmx function.

Sep 26, 2024
CVE-2024-40507
7.3 HIGH

Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMPersonnel.asmx function.

Sep 26, 2024
CVE-2024-40506
7.3 HIGH

Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMHospitality.asmx function.

Sep 26, 2024
CVE-2024-6769
6.7 MEDIUM

A DLL Hijacking caused by drive remapping combined with a poisoning of the activation cache in Microsoft Windows 10, Windows 11, Windows Server 2016, Windows …

Sep 26, 2024
CVE-2024-45986
5.4 MEDIUM

A stored Cross-Site Scripting (XSS) vulnerability was identified in Projectworld Online Voting System 1.0 that occurs when an account is registered with a malicious javascript …

Sep 26, 2024
CVE-2024-7594
7.5 HIGH

Vault’s SSH secrets engine did not require the valid_principals list to contain a value by default. If the valid_principals and default_user fields of the SSH …

Sep 26, 2024
CVE-2024-47180
8.8 HIGH

Shields.io is a service for concise, consistent, and legible badges in SVG and raster format. Shields.io and users self-hosting their own instance of shields using …

Sep 26, 2024
CVE-2024-47179
8.8 HIGH

RSSHub is an RSS network. Prior to commit 64e00e7, RSSHub's `docker-test-cont.yml` workflow is vulnerable to Artifact Poisoning, which could have lead to a full repository …

Sep 26, 2024
CVE-2024-46628
9.8 CRITICAL

Tenda G3 Router firmware v15.03.05.05 was discovered to contain a remote code execution (RCE) vulnerability via the usbPartitionName parameter in the formSetUSBPartitionUmount function.

Sep 26, 2024
CVE-2024-8118

In Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users with permission to write external alert instances to also …

Sep 26, 2024
CVE-2024-47174
5.9 MEDIUM

Nix is a package manager for Linux and other Unix systems. Starting in version 1.11 and prior to versions 2.18.8 and 2.24.8, `<nix/fetchurl.nix>` did not …

Sep 26, 2024
CVE-2024-47171
4.3 MEDIUM

Agnai is an artificial-intelligence-agnostic multi-user, mult-bot roleplaying chat system. A vulnerability in versions prior to 1.0.330 permits attackers to upload image files at attacker-chosen location …

Sep 26, 2024
CVE-2024-47170
4.3 MEDIUM

Agnai is an artificial-intelligence-agnostic multi-user, mult-bot roleplaying chat system. A vulnerability in versions prior to 1.0.330 permits attackers to read arbitrary JSON files at attacker-chosen …

Sep 26, 2024
CVE-2024-47169
8.8 HIGH

Agnai is an artificial-intelligence-agnostic multi-user, mult-bot roleplaying chat system. A vulnerability in versions prior to 1.0.330 permits attackers to upload arbitrary files to attacker-chosen locations …

Sep 26, 2024
CVE-2024-47130
8.8 HIGH

The goTenna Pro App allows unauthenticated attackers to remotely update the local public keys used for P2P and group messages. It is advised to update …

Sep 26, 2024
CVE-2024-47129
4.3 MEDIUM

The goTenna Pro App does not inject extra characters into broadcasted frames to obfuscate the length of messages. This makes it possible to tell the …

Sep 26, 2024
CVE-2024-47128
4.3 MEDIUM

The goTenna Pro App encryption key name is always sent unencrypted when the key is shared over RF through a broadcast message. It is advised …

Sep 26, 2024
CVE-2024-47127
6.5 MEDIUM

In the goTenna Pro App there is a vulnerability that makes it possible to inject any custom message with any GID and Callsign using a …

Sep 26, 2024
CVE-2024-47126
6.5 MEDIUM

The goTenna Pro App does not use SecureRandom when generating passwords for sharing cryptographic keys. The random function in use makes it easier for attackers …

Sep 26, 2024
CVE-2024-47125
8.1 HIGH

The goTenna Pro App does not authenticate public keys which allows an unauthenticated attacker to manipulate messages. It is advised to update your app to …

Sep 26, 2024
CVE-2024-47124
4.3 MEDIUM

The goTenna Pro App does not encrypt callsigns in messages. It is recommended to not use sensitive information in callsigns when using this and previous …

Sep 26, 2024
CVE-2024-47123
5.3 MEDIUM

The goTenna Pro App uses AES CTR type encryption for short, encrypted messages without any additional integrity checking mechanisms. This leaves messages malleable to an …

Sep 26, 2024
CVE-2024-47122
4.3 MEDIUM

In the goTenna Pro App, the encryption keys are stored along with a static IV on the End User Device (EUD). This allows for complete …

Sep 26, 2024
CVE-2024-47121
5.3 MEDIUM

The goTenna Pro App uses a weak password for sharing encryption keys via the key broadcast method. If the broadcasted encryption key is captured over …

Sep 26, 2024
CVE-2024-47075
6.4 MEDIUM

LayUI is a native minimalist modular Web UI component library. Versions prior to 2.9.17 have a DOM Clobbering vulnerability that can lead to Cross-site Scripting …

Sep 26, 2024
CVE-2024-45989
4.0 MEDIUM

Monica AI Assistant desktop application v2.3.0 is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor. A prompt injection allows an attacker to modify …

Sep 26, 2024
CVE-2024-45987
6.5 MEDIUM

Projectworld Online Voting System Version 1.0 is vulnerable to Cross Site Request Forgery (CSRF) via voter.php. This vulnerability allows an attacker to craft a malicious …

Sep 26, 2024
CVE-2024-45985
4.7 MEDIUM

A Cross Site Scripting (XSS) vulnerability in update_contact.php of Blood Bank and Donation Management System v1.0 allows an attacker to inject malicious scripts via the …

Sep 26, 2024
CVE-2024-45984
4.7 MEDIUM

A Cross Site Scripting (XSS) vulnerability in add_donor.php of Blood Bank And Donation Management System 1.0 allows an attacker to inject malicious scripts that will …

Sep 26, 2024
CVE-2024-45838
4.3 MEDIUM

The goTenna Pro ATAK Plugin does not encrypt callsigns in messages. It is advised to not use sensitive information in callsigns when using this and …

Sep 26, 2024
CVE-2024-45723
6.5 MEDIUM

The goTenna Pro ATAK Plugin does not use SecureRandom when generating passwords for sharing cryptographic keys. The random function in use makes it easier for …

Sep 26, 2024
CVE-2024-45374
5.3 MEDIUM

The goTenna Pro ATAK plugin uses a weak password for sharing encryption keys via the key broadcast method. If the broadcasted encryption key is captured …

Sep 26, 2024
CVE-2024-45042
4.4 MEDIUM

Ory Kratos is an identity, user management and authentication system for cloud services. Prior to version 1.3.0, given a number of preconditions, the `highest_available` setting …

Sep 26, 2024
CVE-2024-43814
4.3 MEDIUM

The goTenna Pro ATAK Plugin's default settings are to share Automatic Position, Location, and Information (PLI) updates every 60 seconds once the plugin is active …

Sep 26, 2024
CVE-2024-43694
4.3 MEDIUM

In the goTenna Pro ATAK Plugin application, the encryption keys are stored along with a static IV on the device. This allows for complete decryption …

Sep 26, 2024
CVE-2024-43108
5.3 MEDIUM

The goTenna Pro ATAK Plugin uses AES CTR type encryption for short, encrypted messages without any additional integrity checking mechanisms. This leaves messages malleable to …

Sep 26, 2024
CVE-2024-41931
4.3 MEDIUM

The goTenna Pro ATAK Plugin encryption key name is always sent unencrypted when the key is sent over RF through a broadcast message. It is …

Sep 26, 2024
CVE-2024-41722
6.5 MEDIUM

In the goTenna Pro ATAK Plugin there is a vulnerability that makes it possible to inject any custom message with any GID and Callsign using …

Sep 26, 2024
CVE-2024-41715
4.3 MEDIUM

The goTenna Pro ATAK Plugin does not inject extra characters into broadcasted frames to obfuscate the length of messages. This makes it possible to tell …

Sep 26, 2024
CVE-2024-39577
7.1 HIGH

Dell SmartFabric OS10 Software, versions 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low …

Sep 26, 2024
CVE-2024-9203
2.5 LOW

A vulnerability, which was classified as problematic, has been found in Enpass Password Manager up to 6.9.5 on Windows. This issue affects some unknown processing. …

Sep 26, 2024
CVE-2024-9166

The device enables an unauthorized attacker to execute system commands with elevated privileges. This exploit is facilitated through the use of the 'getcommand' query within …

Sep 26, 2024
CVE-2024-46627
9.1 CRITICAL

Incorrect access control in BECN DATAGERRY v2.2 allows attackers to execute arbitrary commands via crafted web requests.

Sep 26, 2024
CVE-2024-45982
8.8 HIGH

A host header injection vulnerability in scheduleR v0.0.18 allows attackers to obtain the password reset token via user interaction with a crafted password reset link. …

Sep 26, 2024
CVE-2024-45981
8.8 HIGH

A host header injection vulnerability in BookReviewLibrary 1.0 allows attackers to obtain the password reset token via user interaction with a crafted password reset link.

Sep 26, 2024
CVE-2024-45980
8.8 HIGH

A host header injection vulnerability in MEANStore 1.0 allows attackers to obtain the password reset token via user interaction with a crafted password reset link. …

Sep 26, 2024
CVE-2024-45979
8.8 HIGH

A host header injection vulnerability in Lines Police CAD 1.0 allows attackers to obtain the password reset token via user interaction with a crafted password …

Sep 26, 2024
CVE-2024-44860
7.5 HIGH

An information disclosure vulnerability in the /Letter/PrintQr/ endpoint of Solvait v24.4.2 allows attackers to access sensitive data via a crafted request.

Sep 26, 2024
CVE-2024-37125
7.5 HIGH

Dell SmartFabric OS10 Software, versions 10.5.6.x, 10.5.5.x, 10.5.4.x,10.5.3.x, contains an Uncontrolled Resource Consumption vulnerability. A remote unauthenticated host could potentially exploit this vulnerability leading to …

Sep 26, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.