CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-38640
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability has been reported to affect Download Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via …

Sep 6, 2024
CVE-2024-32771
2.6 LOW

An improper restriction of excessive authentication attempts vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow local …

Sep 6, 2024
CVE-2024-32763
8.8 HIGH

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow …

Sep 6, 2024
CVE-2024-32762
8.2 HIGH

A cross-site scripting (XSS) vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow users to inject malicious code via a …

Sep 6, 2024
CVE-2024-27126
6.3 MEDIUM

A cross-site scripting (XSS) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow authenticated users to inject malicious code …

Sep 6, 2024
CVE-2024-27125
3.5 LOW

A cross-site scripting (XSS) vulnerability has been reported to affect Helpdesk. If exploited, the vulnerability could allow authenticated administrators to inject malicious code via a …

Sep 6, 2024
CVE-2024-27122
6.3 MEDIUM

A cross-site scripting (XSS) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow authenticated users to inject malicious code …

Sep 6, 2024
CVE-2024-21906
4.7 MEDIUM

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute …

Sep 6, 2024
CVE-2024-21904
5.9 MEDIUM

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to read the contents …

Sep 6, 2024
CVE-2024-21903
6.6 MEDIUM

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute …

Sep 6, 2024
CVE-2024-21898
8.8 HIGH

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute …

Sep 6, 2024
CVE-2024-21897
8.9 HIGH

A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to inject …

Sep 6, 2024
CVE-2023-51368
5.4 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to launch a …

Sep 6, 2024
CVE-2023-51367
5.4 MEDIUM

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow …

Sep 6, 2024
CVE-2023-51366
8.7 HIGH

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to read the contents …

Sep 6, 2024
CVE-2023-50366
4.3 MEDIUM

A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to inject …

Sep 6, 2024
CVE-2023-50360
8.8 HIGH

A SQL injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a …

Sep 6, 2024
CVE-2023-47563
7.4 HIGH

An OS command injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow authenticated users to execute commands via a …

Sep 6, 2024
CVE-2023-45038
4.3 MEDIUM

An improper authentication vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow users to compromise the security of the system …

Sep 6, 2024
CVE-2023-39300
7.2 HIGH

An OS command injection vulnerability has been reported to affect legacy QTS. If exploited, the vulnerability could allow authenticated administrators to execute commands via a …

Sep 6, 2024
CVE-2023-39298
7.8 HIGH

A missing authorization vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow local authenticated users to access …

Sep 6, 2024
CVE-2023-34979
6.6 MEDIUM

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute …

Sep 6, 2024
CVE-2023-34974
8.8 HIGH

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands …

Sep 6, 2024
CVE-2022-27592
6.7 MEDIUM

An unquoted search path or element vulnerability has been reported to affect QVR Smart Client. If exploited, the vulnerability could allow local authenticated administrators to …

Sep 6, 2024
CVE-2024-8517
9.8 CRITICAL

SPIP before 4.3.2, 4.2.16, and 4.1.18 is vulnerable to a command injection issue. A remote and unauthenticated attacker can execute arbitrary operating system commands by …

Sep 6, 2024
CVE-2024-8509
7.5 HIGH

A vulnerability was found in Forklift Controller. There is no verification against the authorization header except to ensure it uses bearer authentication. Without an Authorization …

Sep 6, 2024
CVE-2024-45758
9.1 CRITICAL

H2O.ai H2O through 3.46.0.4 allows attackers to arbitrarily set the JDBC URL, leading to deserialization attacks, file reads, and command execution. Exploitation can occur when …

Sep 6, 2024
CVE-2024-45294
8.6 HIGH

The HL7 FHIR Core Artifacts repository provides the java core object handling code, with utilities (including validator), for the Fast Healthcare Interoperability Resources (FHIR) specification. …

Sep 6, 2024
CVE-2024-44408
7.5 HIGH

D-Link DIR-823G v1.0.2B05_20181207 is vulnerable to Information Disclosure. The device allows unauthorized configuration file downloads, and the downloaded configuration files contain plaintext user passwords.

Sep 6, 2024
CVE-2024-44402
9.8 CRITICAL

D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via msp_info.htm.

Sep 6, 2024
CVE-2024-44401
9.8 CRITICAL

D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via sub47A60C function in the upgrade_filter.asp file

Sep 6, 2024
CVE-2024-25584
5.3 MEDIUM

Dovecot accepts dot LF DOT LF symbol as end of DATA command. RFC requires that it should always be CR LF DOT CR LF. This …

Sep 6, 2024
CVE-2024-8428
8.8 HIGH

The ForumWP – Forum & Discussion Board Plugin plugin for WordPress is vulnerable to Privilege Escalation via Insecure Direct Object Reference in all versions up …

Sep 6, 2024
CVE-2024-7622
4.3 MEDIUM

The Revision Manager TMC plugin for WordPress is vulnerable to unauthorized arbitrary email sending due to a missing capability check on the _a_ajaxQuickEmailTestCallback() function in …

Sep 6, 2024
CVE-2024-7611
6.4 MEDIUM

The Enter Addons – Ultimate Template Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' attribute of the Events …

Sep 6, 2024
CVE-2024-7599
6.4 MEDIUM

The Advanced Sermons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘sermon_video_embed’ parameter in all versions up to, and including, 3.3 due …

Sep 6, 2024
CVE-2024-7493
9.8 CRITICAL

The WPCOM Member plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.5.2.1. This is due to the plugin …

Sep 6, 2024
CVE-2024-6445
7.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in DataFlowX Technology DataDiodeX allows Path Traversal.This issue affects DataDiodeX: from v3.0.0 before …

Sep 6, 2024
CVE-2024-44837
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability in the component \bean\Manager.java of Drug v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload …

Sep 6, 2024
CVE-2024-45405
6.0 MEDIUM

`gix-path` is a crate of the `gitoxide` project (an implementation of `git` written in Rust) dealing paths and their conversions. Prior to version 0.10.11, `gix-path` …

Sep 6, 2024
CVE-2024-45300
7.5 HIGH

alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5, a race condition allows the user …

Sep 6, 2024
CVE-2024-45299
6.5 MEDIUM

alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5, the preloaded data as json is …

Sep 6, 2024
CVE-2024-45040
5.9 MEDIUM

gnark is a fast zk-SNARK library that offers a high-level API to design circuits. Prior to version 0.11.0, commitments to private witnesses in Groth16 as …

Sep 6, 2024
CVE-2024-45039
6.2 MEDIUM

gnark is a fast zk-SNARK library that offers a high-level API to design circuits. Versions prior to 0.11.0 have a soundness issue - in case …

Sep 6, 2024
CVE-2024-44739
8.8 HIGH

Sourcecodester Simple Forum Website v1.0 has a SQL injection vulnerability in /php-sqlite-forum/?page=manage_user&id=.

Sep 6, 2024
CVE-2024-1744
7.5 HIGH

Authorization Bypass Through User-Controlled Key, Missing Authorization vulnerability in Ariva Computer Accord ORS allows Retrieve Embedded Sensitive Data.This issue affects Accord ORS: before 7.3.2.1.

Sep 6, 2024
CVE-2023-52916
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: media: aspeed: Fix memory overwrite if timing is 1600x900 When capturing 1600x900, system could crash …

Sep 6, 2024
CVE-2023-52915
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: dvb-usb-v2: af9035: Fix null-ptr-deref in af9035_i2c_master_xfer In af9035_i2c_master_xfer, msg is controlled by user. When …

Sep 6, 2024
CVE-2024-8427
4.3 MEDIUM

The Frontend Post Submission Manager Lite – Frontend Posting WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing …

Sep 6, 2024
CVE-2024-8317
6.4 MEDIUM

The WP AdCenter – Ad Manager & Adsense Ads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ad_alignment’ attribute in all versions …

Sep 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.