CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-52949
5.5 MEDIUM

Missing authentication for critical function vulnerability in proxy settings functionality in Synology Active Backup for Business Agent before 2.7.0-3221 allows local users to obtain user …

Sep 26, 2024
CVE-2023-52948
5.0 MEDIUM

Missing encryption of sensitive data vulnerability in settings functionality in Synology Active Backup for Business Agent before 2.7.0-3221 allows local users to obtain user credential …

Sep 26, 2024
CVE-2023-52947
4.0 MEDIUM

Missing authentication for critical function vulnerability in logout functionality in Synology Active Backup for Business Agent before 2.6.3-3101 allows local users to logout the client …

Sep 26, 2024
CVE-2023-52946
8.2 HIGH

Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in vss service component in Synology Drive Client before 3.5.0-16084 allows remote attackers to …

Sep 26, 2024
CVE-2022-49041
4.4 MEDIUM

Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in backup task management functionality in Synology Drive Client before 3.4.0-15721 allows local users …

Sep 26, 2024
CVE-2022-49040
4.4 MEDIUM

Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in connection management functionality in Synology Drive Client before 3.4.0-15721 allows local users with …

Sep 26, 2024
CVE-2022-49039
6.7 MEDIUM

Out-of-bounds write vulnerability in backup task management functionality in Synology Drive Client before 3.4.0-15721 allows local users with administrator privileges to execute arbitrary commands via …

Sep 26, 2024
CVE-2022-49038
7.8 HIGH

Inclusion of functionality from untrusted control sphere vulnerability in OpenSSL DLL component in Synology Drive Client before 3.3.0-15082 allows local users to execute arbitrary code …

Sep 26, 2024
CVE-2022-49037
6.5 MEDIUM

Insertion of sensitive information into log file vulnerability in proxy settings component in Synology Drive Client before 3.3.0-15082 allows remote authenticated users to obtain sensitive …

Sep 26, 2024
CVE-2024-8803
6.1 MEDIUM

The Bulk NoIndex & NoFollow Toolkit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on …

Sep 26, 2024
CVE-2024-8723
6.4 MEDIUM

The 012 Ps Multi Languages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via translated titles in all versions up to, and including, 1.6 …

Sep 26, 2024
CVE-2024-8552
4.3 MEDIUM

The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the enable_shop() function in all …

Sep 26, 2024
CVE-2024-47330
4.3 MEDIUM

Missing Authorization vulnerability in Supsystic Slider by Supsystic, Supsystic Social Share Buttons by Supsystic.This issue affects Slider by Supsystic: from n/a through 1.8.6; Social Share …

Sep 26, 2024
CVE-2024-8405
6.1 MEDIUM

An arbitrary file creation vulnerability exists in PaperCut NG/MF that only affects Windows servers with Web Print enabled. This specific flaw exists within the web-print.exe …

Sep 26, 2024
CVE-2024-8404
7.8 HIGH

An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print enabled. To exploit this vulnerability, an attacker must first …

Sep 26, 2024
CVE-2024-47083
7.5 HIGH

Power Platform Terraform Provider allows managing environments and other resources within Power Platform. Versions prior to 3.0.0 have an issue in the Power Platform Terraform …

Sep 25, 2024
CVE-2023-51157
5.4 MEDIUM

Cross Site Scripting vulnerability in ZKTeco WDMS v.5.1.3 Pro allows a remote attacker to execute arbitrary code and obtain sensitive information via a crafted script …

Sep 25, 2024
CVE-2024-47315
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in StellarWP GiveWP give.This issue affects GiveWP: from n/a through <= 3.15.1.

Sep 25, 2024
CVE-2024-47305
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Dnesscarkey Use Any Font use-any-font allows Cross Site Request Forgery.This issue affects Use Any Font: from n/a through <= …

Sep 25, 2024
CVE-2024-47082
4.6 MEDIUM

Strawberry GraphQL is a library for creating GraphQL APIs. Prior to version 0.243.0, multipart file upload support as defined in the GraphQL multipart request specification …

Sep 25, 2024
CVE-2024-46655
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in Ellevo 6.2.0.38160 allows attackers to execute arbitrary code in the context of a user's browser via a crafted …

Sep 25, 2024
CVE-2024-46489
8.8 HIGH

A remote command execution (RCE) vulnerability in promptr v6.0.7 allows attackers to execute arbitrary commands via a crafted URL.

Sep 25, 2024
CVE-2024-46488
5.5 MEDIUM

sqlite-vec v0.1.1 was discovered to contain a heap buffer overflow via the npy_token_next function. This vulnerability allows attackers to cause a Denial of Service (DoS) …

Sep 25, 2024
CVE-2024-45750
7.3 HIGH

An issue in TheGreenBow Windows Standard VPN Client 6.87.108 (and older), Windows Enterprise VPN Client 6.87.109 (and older), Windows Enterprise VPN Client 7.5.007 (and older), …

Sep 25, 2024
CVE-2024-8996
7.3 HIGH

Unquoted Search Path or Element vulnerability in Grafana Agent (Flow mode) on Windows allows Privilege Escalation from Local User to SYSTEM This issue affects Agent …

Sep 25, 2024
CVE-2024-8975
7.3 HIGH

Unquoted Search Path or Element vulnerability in Grafana Alloy on Windows allows Privilege Escalation from Local User to SYSTEM This issue affects Alloy: before 1.3.3, …

Sep 25, 2024
CVE-2024-44678
8.0 HIGH

Gigastone TR1 Travel Router R101 v1.0.2 is vulnerable to Command Injection. This allows an authenticated attacker to execute arbitrary commands on the device by sending …

Sep 25, 2024
CVE-2024-41708
7.5 HIGH

An issue was discovered in AdaCore ada_web_services 20.0 allows an attacker to escalate privileges and steal sessions via the Random_String() function in the src/core/aws-utils.adb module.

Sep 25, 2024
CVE-2024-41445
6.5 MEDIUM

Library MDF (mdflib) v2.1 is vulnerable to a heap-based buffer overread via a crafted mdf4 file is parsed using the ReadData function

Sep 25, 2024
CVE-2024-20510
4.7 MEDIUM

A vulnerability in the Central Web Authentication (CWA) feature of Cisco IOS XE Software for Wireless Controllers could allow an unauthenticated, adjacent attacker to bypass …

Sep 25, 2024
CVE-2024-20508
5.8 MEDIUM

A vulnerability in Cisco Unified Threat Defense (UTD) Snort Intrusion Prevention System (IPS) Engine for Cisco IOS XE Software could allow an unauthenticated, remote attacker …

Sep 25, 2024
CVE-2024-20496
6.1 MEDIUM

A vulnerability in the UDP packet validation code of Cisco SD-WAN vEdge Software could allow an unauthenticated, adjacent attacker to cause a denial of service …

Sep 25, 2024
CVE-2024-20480
8.6 HIGH

A vulnerability in the DHCP Snooping feature of Cisco IOS XE Software on Software-Defined Access (SD-Access) fabric edge nodes could allow an unauthenticated, remote attacker …

Sep 25, 2024
CVE-2024-20475
6.4 MEDIUM

A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, remote attacker to conduct a …

Sep 25, 2024
CVE-2024-20467
8.6 HIGH

A vulnerability in the implementation of the IPv4 fragmentation reassembly code in Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a …

Sep 25, 2024
CVE-2024-20465
5.8 MEDIUM

A vulnerability in the access control list (ACL) programming of Cisco IOS Software running on Cisco Industrial Ethernet 4000, 4010, and 5000 Series Switches could …

Sep 25, 2024
CVE-2024-20464
8.6 HIGH

A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of …

Sep 25, 2024
CVE-2024-20455
8.6 HIGH

A vulnerability in the process that classifies traffic that is going to the Unified Threat Defense (UTD) component of Cisco IOS XE Software in controller …

Sep 25, 2024
CVE-2024-20437
8.1 HIGH

A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform a cross-site request forgery (CSRF) …

Sep 25, 2024
CVE-2024-20436
8.6 HIGH

A vulnerability in the HTTP Server feature of Cisco IOS XE Software when the Telephony Service feature is enabled could allow an unauthenticated, remote attacker …

Sep 25, 2024
CVE-2024-20434
4.3 MEDIUM

A vulnerability in Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the control plane …

Sep 25, 2024
CVE-2024-20433
8.6 HIGH

A vulnerability in the Resource Reservation Protocol (RSVP) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to …

Sep 25, 2024
CVE-2024-20414
6.5 MEDIUM

A vulnerability in the web UI feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a …

Sep 25, 2024
CVE-2024-20350
7.5 HIGH

A vulnerability in the SSH server of Cisco Catalyst Center, formerly Cisco DNA Center, could allow an unauthenticated, remote attacker to impersonate a Cisco Catalyst …

Sep 25, 2024
CVE-2024-7421
5.5 MEDIUM

An information exposure in Devolutions Remote Desktop Manager 2024.2.20.0 and earlier on Windows allows local attackers with access to system logs to obtain session credentials …

Sep 25, 2024
CVE-2024-47078
8.1 HIGH

Meshtastic is an open source, off-grid, decentralized, mesh network. Meshtastic uses MQTT to communicate over an internet connection to a shared or private MQTT Server. …

Sep 25, 2024
CVE-2024-46600
4.7 MEDIUM

dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/doAdminAction.php?act=delCate&id=31

Sep 25, 2024
CVE-2024-46485
6.3 MEDIUM

dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/doAdminAction.php?act=addCate

Sep 25, 2024
CVE-2024-44825
7.5 HIGH

Directory Traversal vulnerability in Centro de Tecnologia da Informaco Renato Archer InVesalius3 v3.1.99995 allows attackers to write arbitrary files unto the system via a crafted …

Sep 25, 2024
CVE-2023-25189
3.3 LOW

BTS is affected by information disclosure vulnerability where mobile network operator personnel connected over BTS Web Element Manager, regardless of the access privileges, having a …

Sep 25, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.