CVE Database

11833+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-38812
9.8 CRITICAL KEV

The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger …

Sep 17, 2024
CVE-2024-8767
9.9 CRITICAL

Sensitive data disclosure and manipulation due to unnecessary privileges assignment. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build …

Sep 17, 2024
CVE-2024-7387
9.1 CRITICAL

A flaw was found in openshift/builder. This vulnerability allows command injection via path traversal, where a malicious user can execute arbitrary commands on the OpenShift …

Sep 17, 2024
CVE-2024-45496
9.9 CRITICAL

A flaw was found in OpenShift. This issue occurs due to the misuse of elevated privileges in the OpenShift Container Platform's build process. During the …

Sep 17, 2024
CVE-2024-44148
10.0 CRITICAL

This issue was addressed with improved validation of file attributes. This issue is fixed in macOS Sequoia 15. An app may be able to break …

Sep 17, 2024
CVE-2024-44146
10.0 CRITICAL

A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15. An app may be able to break out …

Sep 17, 2024
CVE-2024-45415
9.8 CRITICAL

The HTTPD binary in multiple ZTE routers has a stack-based buffer overflow vulnerability in check_data_integrity function. This function is responsible for validating the checksum of …

Sep 16, 2024
CVE-2024-45414
9.8 CRITICAL

The HTTPD binary in multiple ZTE routers has a stack-based buffer overflow vulnerability in webPrivateDecrypt function. This function is responsible for decrypting RSA encrypted ciphertext, …

Sep 16, 2024
CVE-2024-44623
9.8 CRITICAL

An issue in TuomoKu SPx-GC v.1.3.0 and before allows a remote attacker to execute arbitrary code via the child_process.js function.

Sep 16, 2024
CVE-2024-7104
9.8 CRITICAL

Improper Control of Generation of Code ('Code Injection') vulnerability in SFS Consulting ww.Winsure allows Code Injection.This issue affects ww.Winsure: before 4.6.2.

Sep 16, 2024
CVE-2024-7098
9.8 CRITICAL

Improper Restriction of XML External Entity Reference vulnerability in SFS Consulting ww.Winsure allows XML Injection.This issue affects ww.Winsure: before 4.6.2.

Sep 16, 2024
CVE-2024-6401
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SFS Consulting InsureE GL allows SQL Injection.This issue affects InsureE GL: …

Sep 16, 2024
CVE-2024-46419
9.8 CRITICAL

TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the setWizardCfg function via the ssid5g parameter.

Sep 16, 2024
CVE-2024-46451
9.8 CRITICAL

TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the setWiFiAclRules function via the desc parameter.

Sep 16, 2024
CVE-2024-22399
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in Apache Seata. When developers disable authentication on the Seata-Server and do not use the Seata client SDK dependencies, they …

Sep 16, 2024
CVE-2024-45698
9.8 CRITICAL

Certain models of D-Link wireless routers do not properly validate user input in the telnet service, allowing unauthenticated remote attackers to use hard-coded credentials to …

Sep 16, 2024
CVE-2024-45697
9.8 CRITICAL

Certain models of D-Link wireless routers have a hidden functionality where the telnet service is enabled when the WAN port is plugged in. Unauthorized remote …

Sep 16, 2024
CVE-2024-45695
9.8 CRITICAL

The web service of certain models of D-Link wireless routers contains a Stack-based Buffer Overflow vulnerability, which allows unauthenticated remote attackers to exploit this vulnerability …

Sep 16, 2024
CVE-2024-45694
9.8 CRITICAL

The web service of certain models of D-Link wireless routers contains a Stack-based Buffer Overflow vulnerability, which allows unauthenticated remote attackers to exploit this vulnerability …

Sep 16, 2024
CVE-2024-46958
9.1 CRITICAL

In Nextcloud Desktop Client 3.13.1 through 3.13.3 on Linux, synchronized files (between the server and client) may become world writable or world readable. This is …

Sep 16, 2024
CVE-2024-8669
9.1 CRITICAL

The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to SQL Injection via the 'options' parameter passed to the backuply_wp_clone_sql() function …

Sep 14, 2024
CVE-2024-8039
9.8 CRITICAL

Improper permission configurationDomain configuration vulnerability of the mobile application (com.afmobi.boomplayer) can lead to account takeover risks.

Sep 14, 2024
CVE-2024-44430
9.8 CRITICAL

SQL Injection vulnerability in Best Free Law Office Management Software-v1.0 allows an attacker to execute arbitrary code and obtain sensitive information via a crafted payload …

Sep 13, 2024
CVE-2024-46049
9.8 CRITICAL

Tenda O6 V3.0 firmware V1.0.0.7(2054) contains a stack overflow vulnerability in the formexeCommand function.

Sep 13, 2024
CVE-2024-46048
9.8 CRITICAL

Tenda FH451 v1.0.0.9 has a command injection vulnerability in the formexeCommand function i

Sep 13, 2024
CVE-2024-46046
9.8 CRITICAL

Tenda FH451 v1.0.0.9 has a stack overflow vulnerability located in the RouteStatic function.

Sep 13, 2024
CVE-2024-46045
9.8 CRITICAL

Tenda CH22 V1.0.0.6(468) has a stack overflow vulnerability located in the frmL7PlotForm function.

Sep 13, 2024
CVE-2024-46044
9.8 CRITICAL

CH22 V1.0.0.6(468) has a stack overflow vulnerability located in the fromqossetting function.

Sep 13, 2024
CVE-2024-41874
9.8 CRITICAL

ColdFusion versions 2023.9, 2021.15 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context …

Sep 13, 2024
CVE-2024-6656
9.8 CRITICAL

Use of Hard-coded Credentials vulnerability in TNB Mobile Solutions Cockpit Software allows Read Sensitive Strings Within an Executable.This issue affects Cockpit Software: before v2.13.

Sep 13, 2024
CVE-2024-7961
9.8 CRITICAL

A path traversal vulnerability exists in the Rockwell Automation affected product. If exploited, the threat actor could upload arbitrary files to the server that could …

Sep 12, 2024
CVE-2024-7960
9.1 CRITICAL

The Rockwell Automation affected product contains a vulnerability that allows a threat actor to view sensitive information and change settings. The vulnerability exists due to …

Sep 12, 2024
CVE-2024-6678
9.9 CRITICAL

An issue was discovered in GitLab CE/EE affecting all versions starting from 8.14 prior to 17.1.7, starting from 17.2 prior to 17.2.5, and starting from …

Sep 12, 2024
CVE-2024-8696
9.8 CRITICAL

A remote code execution (RCE) vulnerability via crafted extension publisher-url/additional-urls could be abused by a malicious extension in Docker Desktop before 4.34.2.

Sep 12, 2024
CVE-2024-8695
9.8 CRITICAL

A remote code execution (RCE) vulnerability via crafted extension description/changelog could be abused by a malicious extension in Docker Desktop before 4.34.2.

Sep 12, 2024
CVE-2024-45824
9.8 CRITICAL

CVE-2024-45824 IMPACT A remote code vulnerability exists in the affected products. The vulnerability occurs when chained with Path Traversal, Command Injection, and XSS Vulnerabilities and …

Sep 12, 2024
CVE-2024-40457
9.1 CRITICAL

No-IP Dynamic Update Client (DUC) v3.x uses cleartext credentials that may occur on a command line or in a file. NOTE: the vendor's position is …

Sep 12, 2024
CVE-2024-28991
9.0 CRITICAL

SolarWinds Access Rights Manager (ARM) was found to be susceptible to a remote code execution vulnerability. If exploited, this vulnerability would allow an authenticated user …

Sep 12, 2024
CVE-2024-45856
9.0 CRITICAL

A cross-site scripting (XSS) vulnerability exists in all versions of the MindsDB platform, enabling the execution of a JavaScript payload whenever a user enumerates an …

Sep 12, 2024
CVE-2024-8529
10.0 CRITICAL

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_fields' parameter of the /wp-json/lp/v1/courses/archive-course REST API endpoint in …

Sep 12, 2024
CVE-2024-8522
10.0 CRITICAL

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to SQL Injection via the 'c_only_fields' parameter of the /wp-json/learnpress/v1/courses REST API endpoint in …

Sep 12, 2024
CVE-2024-29847
9.8 CRITICAL

Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to …

Sep 12, 2024
CVE-2024-44541
9.8 CRITICAL

evilnapsis Inventio Lite Versions v4 and before is vulnerable to SQL Injection via the "username" parameter in "/?action=processlogin."

Sep 11, 2024
CVE-2024-44466
9.8 CRITICAL

COMFAST CF-XR11 V2.7.2 has a command injection vulnerability in function sub_424CB4. Attackers can send POST request messages to /usr/bin/webmgnt and inject commands into parameter iface.

Sep 11, 2024
CVE-2024-27115
9.8 CRITICAL

A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. With this vulnerability, an attacker can upload executable files …

Sep 11, 2024
CVE-2024-27114
9.8 CRITICAL

A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. If the public view setting is enabled, a attacker …

Sep 11, 2024
CVE-2024-27113
9.8 CRITICAL

An unauthenticated Insecure Direct Object Reference (IDOR) to the database has been found in the SO Planning tool that occurs when the public view setting …

Sep 11, 2024
CVE-2024-27112
9.8 CRITICAL

A unauthenticated SQL Injection has been found in the SO Planning tool that occurs when the public view setting is enabled. An attacker could use …

Sep 11, 2024
CVE-2024-6091
9.8 CRITICAL

A vulnerability in significant-gravitas/autogpt version 0.5.1 allows an attacker to bypass the shell commands denylist settings. The issue arises when the denylist is configured to …

Sep 11, 2024
CVE-2024-45790
9.8 CRITICAL

This vulnerability exists in Reedos aiM-Star version 2.0.1 due to missing restrictions for excessive failed authentication attempts on its API based login. A remote attacker …

Sep 11, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.