CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-41729
4.3 MEDIUM

Due to missing authorization checks, SAP BEx Analyzer allows an authenticated attacker to access information over the network which is otherwise restricted. On successful exploitation …

Sep 10, 2024
CVE-2024-6342
9.8 CRITICAL

**UNSUPPORTED WHEN ASSIGNED** A command injection vulnerability in the export-cgi program of Zyxel NAS326 firmware versions through V5.21(AAZF.18)C0 and NAS542 firmware versions through V5.21(ABAG.15)C0 could …

Sep 10, 2024
CVE-2024-38270
5.3 MEDIUM

An insufficient entropy vulnerability caused by the improper use of a randomness function with low entropy for web authentication tokens generation exists in the Zyxel …

Sep 10, 2024
CVE-2024-8611
6.3 MEDIUM

A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0. Affected by this vulnerability is an unknown functionality of the file ssms.php. …

Sep 9, 2024
CVE-2024-8610
3.5 LOW

A vulnerability classified as problematic has been found in SourceCodester Best House Rental Management System 1.0. Affected is an unknown function of the file /index.php?page=tenants …

Sep 9, 2024
CVE-2024-44411
9.8 CRITICAL

D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the msp_info_htm function.

Sep 9, 2024
CVE-2024-44410
9.8 CRITICAL

D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the upgrade_filter_asp function.

Sep 9, 2024
CVE-2024-27365
4.4 MEDIUM

An issue was discovered in Samsung Mobile Processor Exynos Exynos 980, Exynos 850, Exynos 1080, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 1480, Exynos W920, …

Sep 9, 2024
CVE-2024-6796
8.2 HIGH

In Baxter Connex health portal released before 8/30/2024, an improper access control vulnerability has been found that could allow an unauthenticated attacker to gain unauthorized …

Sep 9, 2024
CVE-2024-6795
10.0 CRITICAL

In Connex health portal released before8/30/2024, SQL injection vulnerabilities were found that could have allowed an unauthenticated attacker to gain unauthorized access to Connex portal's …

Sep 9, 2024
CVE-2024-44902
9.8 CRITICAL

A deserialization vulnerability in Thinkphp v6.1.3 to v8.0.4 allows attackers to execute arbitrary code.

Sep 9, 2024
CVE-2024-44725
7.2 HIGH

AutoCMS v5.4 was discovered to contain a SQL injection vulnerability via the sidebar parameter at /admin/robot.php.

Sep 9, 2024
CVE-2024-44724
7.2 HIGH

AutoCMS v5.4 was discovered to contain a PHP code injection vulnerability via the txtsite_url parameter at /admin/site_add.php. This vulnerability allows attackers to execute arbitrary PHP …

Sep 9, 2024
CVE-2024-44085
6.1 MEDIUM

ONLYOFFICE Docs before 8.1.0 allows XSS via a GeneratorFunction Object attack against a macro. This is related to use of an immediately-invoked function expression (IIFE) …

Sep 9, 2024
CVE-2024-42500
9.3 CRITICAL

HPE has identified a denial of service vulnerability in HPE HP-UX System's Network File System (NFSv4) services.

Sep 9, 2024
CVE-2024-27387
6.7 MEDIUM

An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_rx_range_done_ind(), there is …

Sep 9, 2024
CVE-2024-27383
6.7 MEDIUM

An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_get_scan_extra_ies(), there is …

Sep 9, 2024
CVE-2024-27368
4.4 MEDIUM

An issue was discovered in Samsung Mobile Processor Exynos Mobile Processor, Wearable Processor Exynos 980, Exynos 850, Exynos 1080, Exynos 1280, Exynos 1380, Exynos 1330, …

Sep 9, 2024
CVE-2024-27367
4.4 MEDIUM

An issue was discovered in Samsung Mobile Processor Exynos Wearable Processor Exynos 980, Exynos 850, Exynos 1080, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 1480, …

Sep 9, 2024
CVE-2024-27366
4.4 MEDIUM

An issue was discovered in Samsung Mobile Processor, Wearable Processor Exynos Exynos 980, Exynos 850, Exynos 1080, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 1480, …

Sep 9, 2024
CVE-2024-27364
4.4 MEDIUM

An issue was discovered in Mobile Processor, Wearable Processor Exynos 980, Exynos 850, Exynos 1080, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 1480, Exynos W920, …

Sep 9, 2024
CVE-2023-50883
6.1 MEDIUM

ONLYOFFICE Docs before 8.0.1 allows XSS because a macro is an immediately-invoked function expression (IIFE), and therefore a sandbox escape is possible by directly calling …

Sep 9, 2024
CVE-2024-7341
7.1 HIGH

A session fixation issue was discovered in the SAML adapters provided by Keycloak. The session ID and JSESSIONID cookie are not changed at login time, …

Sep 9, 2024
CVE-2024-7318
4.8 MEDIUM

A vulnerability was found in Keycloak. Expired OTP codes are still usable when using FreeOTP when the OTP token period is set to 30 seconds …

Sep 9, 2024
CVE-2024-7260
6.1 MEDIUM

An open redirect vulnerability was found in Keycloak. A specially crafted URL can be constructed where the referrer and referrer_uri parameters are made to trick …

Sep 9, 2024
CVE-2024-45411
8.5 HIGH

Twig is a template language for PHP. Under some circumstances, the sandbox security checks are not run which allows user-contributed templates to bypass the sandbox …

Sep 9, 2024
CVE-2024-45296
7.5 HIGH

path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. …

Sep 9, 2024
CVE-2024-42759
6.3 MEDIUM

An issue in Ellevo v.6.2.0.38160 allows a remote attacker to escalate privileges via the /api/usuario/cadastrodesuplente endpoint.

Sep 9, 2024
CVE-2024-24510
6.1 MEDIUM

Cross Site Scripting vulnerability in Alinto SOGo before 5.10.0 allows a remote attacker to execute arbitrary code via the import function to the mail component.

Sep 9, 2024
CVE-2024-44849
9.8 CRITICAL

Qualitor up to 8.24 is vulnerable to Remote Code Execution (RCE) via Arbitrary File Upload in checkAcesso.php.

Sep 9, 2024
CVE-2024-44335
8.8 HIGH

D-Link DI-7003G v19.12.24A1, DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution (RCE) via version_upgrade.asp.

Sep 9, 2024
CVE-2024-44334
8.8 HIGH

D-Link DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution due to insufficient parameter filtering …

Sep 9, 2024
CVE-2024-45406
5.5 MEDIUM

Craft is a content management system (CMS). Craft CMS 5 stored XSS can be triggered by the breadcrumb list and title fields with user input.

Sep 9, 2024
CVE-2024-44333
8.8 HIGH

D-Link DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution. An attacker can achieve arbitrary …

Sep 9, 2024
CVE-2024-8605
4.3 MEDIUM

A vulnerability classified as problematic was found in code-projects Inventory Management 1.0. This vulnerability affects unknown code of the file /view/registration.php of the component Registration …

Sep 9, 2024
CVE-2024-8604
4.3 MEDIUM

A vulnerability classified as problematic has been found in SourceCodester Online Food Ordering System 2.0. This affects an unknown part of the file index.php of …

Sep 9, 2024
CVE-2024-44721
9.8 CRITICAL

SeaCMS v13.1 was discovered to a Server-Side Request Forgery (SSRF) via the url parameter at /admin_reslib.php.

Sep 9, 2024
CVE-2024-44720
7.5 HIGH

SeaCMS v13.1 was discovered to an arbitrary file read vulnerability via the component admin_safe.php.

Sep 9, 2024
CVE-2024-8373
4.8 MEDIUM

Improper sanitization of the value of the [srcset] attribute in <source> HTML elements in AngularJS allows attackers to bypass common image source restrictions, which can …

Sep 9, 2024
CVE-2024-8372
4.8 MEDIUM

Improper sanitization of the value of the 'srcset' attribute in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a …

Sep 9, 2024
CVE-2024-8042
2.4 LOW

Rapid7 Insight Platform versions between November 2019 and August 14, 2024 suffer from missing authorization issues whereby an attacker can intercept local requests to set …

Sep 9, 2024
CVE-2024-45041
8.3 HIGH

External Secrets Operator is a Kubernetes operator that integrates external secret management systems. The external-secrets has a deployment called default-external-secrets-cert-controller, which is bound with a …

Sep 9, 2024
CVE-2024-40643
9.6 CRITICAL

Joplin is a free, open source note taking and to-do application. Joplin fails to take into account that "<" followed by a non letter character …

Sep 9, 2024
CVE-2024-7015
9.8 CRITICAL

Missing Authentication for Critical Function vulnerability in Profelis Informatics and Consulting PassBox allows Authentication Abuse.This issue affects PassBox: before v1.2.

Sep 9, 2024
CVE-2024-44375
7.5 HIGH

D-Link DI-8100 v16.07.26A1 has a stack overflow vulnerability in the dbsrv_asp function.

Sep 9, 2024
CVE-2024-8601
6.5 MEDIUM

This vulnerability exists in TechExcel Back Office Software versions prior to 1.0.0 due to improper access controls on certain API endpoints. An authenticated remote attacker …

Sep 9, 2024
CVE-2024-6572
7.4 HIGH

Improper host key checking in active check 'Check SFTP Service' and special agent 'VNX quotas and filesystem' in Checkmk before Checkmk 2.3.0p15, 2.2.0p33, 2.1.0p48 and …

Sep 9, 2024
CVE-2024-37288
9.9 CRITICAL

A deserialization issue in Kibana can lead to arbitrary code execution when Kibana attempts to parse a YAML document containing a crafted payload. This issue …

Sep 9, 2024
CVE-2024-45203
4.3 MEDIUM

Improper authorization in handler for custom URL scheme issue in "@cosme" App for Android versions prior 5.69.0 and "@cosme" App for iOS versions prior to …

Sep 9, 2024
CVE-2024-7918
4.8 MEDIUM

The Pocket Widget WordPress plugin through 0.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Sep 9, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.