CVE Database

9973+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-28179
9.0 CRITICAL

Jupyter Server Proxy allows users to run arbitrary external processes alongside their Jupyter notebook servers and provides authenticated web access. Prior to versions 3.2.3 and …

Mar 20, 2024
CVE-2024-28395
9.8 CRITICAL

SQL injection vulnerability in Best-Kit bestkit_popup v.1.7.2 and before allows a remote attacker to escalate privileges via the bestkit_popup.php component.

Mar 20, 2024
CVE-2024-28392
9.8 CRITICAL

SQL injection vulnerability in pscartabandonmentpro v.2.0.11 and before allows a remote attacker to escalate privileges via the pscartabandonmentproFrontCAPUnsubscribeJobModuleFrontController::setEmailVisualized() method.

Mar 20, 2024
CVE-2024-1811
9.8 CRITICAL

A potential vulnerability has been identified in OpenText ArcSight Platform. The vulnerability could be remotely exploited.

Mar 20, 2024
CVE-2024-1800
9.9 CRITICAL

In Progress® Telerik® Report Server versions prior to 2024 Q1 (10.0.24.130), a remote code execution attack is possible through an insecure deserialization vulnerability.

Mar 20, 2024
CVE-2024-1711
9.8 CRITICAL

The Create by Mediavine plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 1.9.4 due …

Mar 20, 2024
CVE-2024-22081
9.8 CRITICAL

An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Unauthenticated memory corruption can occur in the HTTP header parsing mechanism.

Mar 20, 2024
CVE-2024-22080
9.8 CRITICAL

An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Unauthenticated memory corruption can occur during XML body parsing.

Mar 20, 2024
CVE-2024-28389
9.8 CRITICAL

SQL injection vulnerability in KnowBand spinwheel v.3.0.3 and before allows a remote attacker to gain escalated privileges and obtain sensitive information via the SpinWheelFrameSpinWheelModuleFrontController::sendEmail() method.

Mar 19, 2024
CVE-2024-28595
9.8 CRITICAL

SQL Injection vulnerability in Employee Management System v1.0 allows attackers to run arbitrary SQL commands via the admin_id parameter in update-admin.php.

Mar 19, 2024
CVE-2024-28394
9.8 CRITICAL

An issue in Advanced Plugins reportsstatistics v1.3.20 and before allows a remote attacker to execute arbitrary code via the Sales Reports, Statistics, Custom Fields & …

Mar 19, 2024
CVE-2024-29027
9.0 CRITICAL

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 6.5.5 and 7.0.0-alpha.29, calling …

Mar 19, 2024
CVE-2024-28303
9.8 CRITICAL

Open Source Medicine Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the date parameter at /admin/reports/index.php.

Mar 19, 2024
CVE-2024-29135
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Themefic Tourfic tourfic.This issue affects Tourfic: from n/a through <= 2.11.15.

Mar 19, 2024
CVE-2024-2636
9.0 CRITICAL

An Unrestricted Upload of File vulnerability has been found on Cegid Meta4 HR, that allows an attacker to upload malicios files to the server via …

Mar 19, 2024
CVE-2024-2615
9.8 CRITICAL

Memory safety bugs present in Firefox 123. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of …

Mar 19, 2024
CVE-2023-40276
9.1 CRITICAL

An issue was discovered in OpenClinic GA 5.247.01. An Unauthenticated File Download vulnerability has been discovered in pharmacy/exportFile.jsp.

Mar 19, 2024
CVE-2023-40275
9.1 CRITICAL

An issue was discovered in OpenClinic GA 5.247.01. It allows retrieval of patient lists via queries such as findFirstname= to _common/search/searchByAjax/patientslistShow.jsp.

Mar 19, 2024
CVE-2024-24578
10.0 CRITICAL

RaspberryMatic is an open-source operating system for HomeMatic internet-of-things devices. RaspberryMatic / OCCU prior to version 3.75.6.20240316 contains a unauthenticated remote code execution (RCE) vulnerability, …

Mar 18, 2024
CVE-2024-21652
9.8 CRITICAL

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.8.13, 2.9.9, and 2.10.4, an attacker can exploit a chain of …

Mar 18, 2024
CVE-2024-2051
9.8 CRITICAL

CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could cause account takeover and unauthorized access to the system when an attacker conducts brute-force …

Mar 18, 2024
CVE-2024-2599
9.9 CRITICAL

File upload restriction evasion vulnerability in AMSS++ version 4.31. This vulnerability could allow an authenticated user to potentially obtain RCE through webshell, compromising the entire …

Mar 18, 2024
CVE-2024-28537
9.8 CRITICAL

Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the page parameter of fromNatStaticSetting function.

Mar 18, 2024
CVE-2024-27768
9.8 CRITICAL

Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-22: 'Path Traversal' may allow RCE

Mar 18, 2024
CVE-2024-27767
10.0 CRITICAL

CWE-287: Improper Authentication may allow Authentication Bypass

Mar 18, 2024
CVE-2024-28125
9.8 CRITICAL

FitNesse all releases allows a remote authenticated attacker to execute arbitrary OS commands. Note: A contributor of FitNesse has claimed that this is not a …

Mar 18, 2024
CVE-2024-29151
9.1 CRITICAL

Rocket.Chat.Audit through 5ad78e8 depends on filecachetools, which does not exist in PyPI.

Mar 18, 2024
CVE-2021-47157
9.8 CRITICAL

The Kossy module before 0.60 for Perl allows JSON hijacking because of X-Requested-With mishandling.

Mar 18, 2024
CVE-2021-47155
9.1 CRITICAL

The Net::IPV4Addr module 0.10 for Perl does not properly consider extraneous zero characters in an IP address string, which (in some situations) allows attackers to …

Mar 18, 2024
CVE-2018-25099
9.8 CRITICAL

In the CryptX module before 0.062 for Perl, gcm_decrypt_verify() and chacha20poly1305_decrypt_verify() do not verify the tag.

Mar 18, 2024
CVE-2022-47036
9.8 CRITICAL

Siklu TG Terragraph devices before approximately 2.1.1 have a hardcoded root password that has been revealed via a brute force attack on an MD5 hash. …

Mar 18, 2024
CVE-2024-27957
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Pie Register.This issue affects Pie Register: from n/a through 3.8.3.1.

Mar 17, 2024
CVE-2024-28639
9.8 CRITICAL

Buffer Overflow vulnerability in TOTOLink X5000R V9.1.0u.6118-B20201102 and A7000R V9.1.0u.6115-B20201022, allow remote attackers to execute arbitrary code and cause a denial of service (DoS) via …

Mar 16, 2024
CVE-2024-28255
9.8 CRITICAL

OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. The `JwtFilter` handles …

Mar 15, 2024
CVE-2024-28253
9.4 CRITICAL

OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. `CompiledRule::validateExpression` is also …

Mar 15, 2024
CVE-2023-7017
9.8 CRITICAL

Sciener locks' firmware update mechanism do not authenticate or validate firmware updates if passed to the lock through the Bluetooth Low Energy service. A challenge …

Mar 15, 2024
CVE-2023-7006
9.1 CRITICAL

The unlockKey character in a lock using Sciener firmware can be brute forced through repeated challenge requests, compromising the locks integrity.

Mar 15, 2024
CVE-2024-28752
9.3 CRITICAL

A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style attacks …

Mar 15, 2024
CVE-2024-28354
10.0 CRITICAL

There is a command injection vulnerability in the TRENDnet TEW-827DRU router with firmware version 2.10B01. An attacker can inject commands into the post request parameters …

Mar 15, 2024
CVE-2024-25227
9.8 CRITICAL

SQL Injection vulnerability in ABO.CMS version 5.8, allows remote attackers to execute arbitrary code, cause a denial of service (DoS), escalate privileges, and obtain sensitive …

Mar 15, 2024
CVE-2024-1917
9.8 CRITICAL

Integer Overflow or Wraparound vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remote unauthenticated attacker to execute malicious code …

Mar 15, 2024
CVE-2024-1916
9.8 CRITICAL

Integer Overflow or Wraparound vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remote unauthenticated attacker to execute malicious code …

Mar 15, 2024
CVE-2024-1915
9.8 CRITICAL

Incorrect Pointer Scaling vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remote unauthenticated attacker to execute malicious code on …

Mar 15, 2024
CVE-2024-0803
9.8 CRITICAL

Integer Overflow or Wraparound vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remote unauthenticated attacker to execute malicious code …

Mar 15, 2024
CVE-2024-0802
9.8 CRITICAL

Incorrect Pointer Scaling vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remote unauthenticated attacker to read arbitrary information from …

Mar 15, 2024
CVE-2024-26503
9.1 CRITICAL

Unrestricted File Upload vulnerability in Greek Universities Network Open eClass v.3.15 and earlier allows attackers to run arbitrary code via upload of crafted file to …

Mar 14, 2024
CVE-2023-42286
9.8 CRITICAL

There is a PHP file inclusion vulnerability in the template configuration of eyoucms v1.6.4, allowing attackers to execute code or system commands through a carefully …

Mar 14, 2024
CVE-2024-28423
9.8 CRITICAL

Airflow-Diagrams v2.1.0 was discovered to contain an arbitrary file upload vulnerability in the unsafe_load function at cli.py. This vulnerability allows attackers to execute arbitrary code …

Mar 14, 2024
CVE-2024-25139
10.0 CRITICAL

In TP-Link Omada er605 1.0.1 through (v2.6) 2.2.3, a cloud-brd binary is susceptible to an integer overflow that leads to a heap-based buffer overflow. After …

Mar 14, 2024
CVE-2024-28383
9.8 CRITICAL

Tenda AX12 v1.0 v22.03.01.16 was discovered to contain a stack overflow via the ssid parameter in the sub_431CF0 function.

Mar 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.