CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-44761
9.8 CRITICAL

An issue in EQ Enterprise Management System before v2.0.0 allows attackers to execute a directory traversal via crafted requests.

Aug 28, 2024
CVE-2024-44915
5.5 MEDIUM

An issue in the component EXR!ReadEXR+0x4eef0 of Irfanview v4.67.1.0 allows attackers to cause an access violation via a crafted EXR file. This vulnerability can lead …

Aug 28, 2024
CVE-2024-44914
5.5 MEDIUM

An issue in the component EXR!ReadEXR+0x3df50 of Irfanview v4.67.1.0 allows attackers to cause an access violation via a crafted EXR file. This vulnerability can lead …

Aug 28, 2024
CVE-2024-44913
5.5 MEDIUM

An issue in the component EXR!ReadEXR+0x40ef1 of Irfanview v4.67.1.0 allows attackers to cause an access violation via a crafted EXR file. This vulnerability can lead …

Aug 28, 2024
CVE-2024-42905
9.8 CRITICAL

Beijing Digital China Cloud Technology Co., Ltd. DCME-320 v.7.4.12.60 has a command execution vulnerability, which can be exploited to obtain device administrator privileges via the …

Aug 28, 2024
CVE-2024-41236
7.2 HIGH

A SQL injection vulnerability in /smsa/admin_login.php in Kashipara Responsive School Management System v3.2.0 allows an attacker to execute arbitrary SQL commands via the "username" parameter …

Aug 28, 2024
CVE-2024-7745
6.5 MEDIUM

In WS_FTP Server versions before 8.8.8 (2022.0.8), a Missing Critical Step in Multi-Factor Authentication of the Web Transfer Module allows users to skip the second-factor …

Aug 28, 2024
CVE-2024-7744
6.5 MEDIUM

In WS_FTP Server versions before 8.8.8 (2022.0.8), an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the Web Transfer Module …

Aug 28, 2024
CVE-2024-6053
4.3 MEDIUM

Improper access control in the clipboard synchronization feature in TeamViewer Full Client prior version 15.57 and TeamViewer Meeting prior version 15.55.3 can lead to unintentional …

Aug 28, 2024
CVE-2024-41565
4.3 MEDIUM

JustEnoughItems (JEI) 19.5.0.33 and before contains an Improper Validation of Specified Index, Position, or Offset in Input vulnerability. The specific issue is a failure to …

Aug 28, 2024
CVE-2024-41564
4.3 MEDIUM

EMI v.1.1.10 and before, fixed in v.1.1.11, contains an Improper Validation of Specified Index, Position, or Offset in Input vulnerability. The specific issue is a …

Aug 28, 2024
CVE-2024-20478
6.5 MEDIUM

A vulnerability in the software upgrade component of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Network Controller, formerly Cisco Cloud APIC, could allow an …

Aug 28, 2024
CVE-2024-20446
8.6 HIGH

A vulnerability in the DHCPv6 relay agent of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition …

Aug 28, 2024
CVE-2024-20413
6.7 MEDIUM

A vulnerability in Cisco NX-OS Software could allow an authenticated, local attacker with privileges to access the Bash shell to elevate privileges to network-admin on …

Aug 28, 2024
CVE-2024-20411
6.7 MEDIUM

A vulnerability in Cisco NX-OS Software could allow an authenticated, local attacker with privileges to access the Bash shell to execute arbitrary code as root on …

Aug 28, 2024
CVE-2024-20289
4.4 MEDIUM

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, low-privileged, local attacker to execute arbitrary commands on the underlying operating system …

Aug 28, 2024
CVE-2024-20286
5.3 MEDIUM

A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local attacker to escape the Python sandbox and gain unauthorized …

Aug 28, 2024
CVE-2024-20285
5.3 MEDIUM

A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local attacker to escape the Python sandbox and gain unauthorized …

Aug 28, 2024
CVE-2024-20284
5.3 MEDIUM

A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local attacker to escape the Python sandbox and gain unauthorized …

Aug 28, 2024
CVE-2024-20279
4.3 MEDIUM

A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to modify the behavior …

Aug 28, 2024
CVE-2024-42900
6.1 MEDIUM

Ruoyi v4.7.9 and before was discovered to contain a cross-site scripting (XSS) vulnerability via the sql parameter of the createTable() function at /tool/gen/create.

Aug 28, 2024
CVE-2024-42698
4.3 MEDIUM

Roughly Enough Items (REI) v.16.0.729 and before contains an Improper Validation of Specified Index, Position, or Offset in Input vulnerability. The specific issue is a …

Aug 28, 2024
CVE-2024-34198
9.8 CRITICAL

TOTOLINK AC1200 Wireless Router A3002RU V2.1.1-B20230720.1011 is vulnerable to Buffer Overflow. The formWlEncrypt CGI handler in the boa program fails to limit the length of …

Aug 28, 2024
CVE-2024-8195
5.3 MEDIUM

The Permalink Manager Lite plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'debug_data', 'debug_query', and …

Aug 28, 2024
CVE-2024-7447
5.3 MEDIUM

The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification …

Aug 28, 2024
CVE-2024-6450
6.1 MEDIUM

HyperView Geoportal Toolkit in versions lower than 8.5.0 is vulnerable to Reflected Cross-Site Scripting (XSS). An unauthenticated attacker might trick somebody into using a crafted …

Aug 28, 2024
CVE-2024-6449
6.5 MEDIUM

HyperView Geoportal Toolkit in versions lower than 8.5.0 does not restrict cross-domain requests when fetching remote content pointed by one of GET request parameters. An …

Aug 28, 2024
CVE-2024-7269
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation vulnerability in "Update of Personal Details" form in ConnX ESP HR Management allows Stored XSS attack. An …

Aug 28, 2024
CVE-2024-5546
8.3 HIGH

Zohocorp ManageEngine Password Manager Pro versions before 12431 and ManageEngine PAM360 versions before 7001 are affected by authenticated SQL Injection vulnerability via a global search …

Aug 28, 2024
CVE-2024-44943
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm: gup: stop abusing try_grab_folio A kernel warning was reported when pinning folio in CMA …

Aug 28, 2024
CVE-2023-26324
8.8 HIGH

A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit …

Aug 28, 2024
CVE-2023-26323
7.6 HIGH

A code execution vulnerability exists in the Xiaomi App market product. The vulnerability is caused by unsafe configuration and can be exploited by attackers to …

Aug 28, 2024
CVE-2023-26322
8.8 HIGH

A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit …

Aug 28, 2024
CVE-2023-26321
6.3 MEDIUM

A path traversal vulnerability exists in the Xiaomi File Manager application product(international version). The vulnerability is caused by unfiltered special characters and can be exploited …

Aug 28, 2024
CVE-2024-6312
6.5 MEDIUM

The Funnelforms Free plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 3.7.3.2 via the 'af2DeleteFontFile' function. This …

Aug 28, 2024
CVE-2024-6311
7.2 HIGH

The Funnelforms Free plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'af2_add_font' function in all versions …

Aug 28, 2024
CVE-2024-4556
5.7 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText NetIQ Access Manager allows access the sensitive information. This issue affects …

Aug 28, 2024
CVE-2024-4555
7.7 HIGH

Improper Privilege Management vulnerability in OpenText NetIQ Access Manager allows user account impersonation in specific scenario. This issue affects NetIQ Access Manager before 5.0.4.1 and …

Aug 28, 2024
CVE-2024-4554
7.3 HIGH

Improper Input Validation vulnerability in OpenText NetIQ Access Manager leads to Cross-Site Scripting (XSS) attack. This issue affects Access Manager before 5.0.4.1 and 5.1.

Aug 28, 2024
CVE-2024-45346
8.8 HIGH

The Xiaomi Security Center expresses heartfelt thanks to Ken Gannon and Ilyes Beghdadi of NCC Group working with Trend Micro Zero Day Initiative! At the …

Aug 28, 2024
CVE-2021-38122
6.2 MEDIUM

A Cross-Site Scripting vulnerable identified in NetIQ Advance Authentication that impacts the server functionality and disclose sensitive information. This issue affects NetIQ Advance Authentication before …

Aug 28, 2024
CVE-2021-38121
8.3 HIGH

Insufficient or weak TLS protocol version identified in Advance authentication client server communication when specific service is accessed between devices. This issue affects NetIQ Advance …

Aug 28, 2024
CVE-2021-38120
5.1 MEDIUM

A vulnerability identified in Advance Authentication that allows bash command Injection in administrative controlled functionality of backup due to improper handling in provided command parameters. …

Aug 28, 2024
CVE-2021-22530
8.2 HIGH

A vulnerability identified in NetIQ Advance Authentication that doesn't enforce account lockout when brute force attack is performed on API based login. This issue may …

Aug 28, 2024
CVE-2021-22529
6.3 MEDIUM

A vulnerability identified in NetIQ Advance Authentication that leaks sensitive server information. This issue affects NetIQ Advance Authentication version before 6.3.5.1

Aug 28, 2024
CVE-2021-22509
8.1 HIGH

A vulnerability identified in storing and reusing information in Advance Authentication. This issue can lead to leakage of sensitive data to unauthorized user. The issue …

Aug 28, 2024
CVE-2024-39771
6.8 MEDIUM

QBiC CLOUD CC-2L v1.1.30 and earlier and Safie One v1.8.2 and earlier do not properly validate certificates, which may allow a network-adjacent unauthenticated attacker to …

Aug 28, 2024
CVE-2024-39584
8.2 HIGH

Dell Client Platform BIOS contains a Use of Default Cryptographic Key Vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading …

Aug 28, 2024
CVE-2023-43078
6.7 MEDIUM

Dell Dock Firmware and Dell Client Platform contain an Improper Link Resolution vulnerability during installation resulting in arbitrary folder deletion, which could lead to Privilege …

Aug 28, 2024
CVE-2023-45896
7.1 HIGH

ntfs3 in the Linux kernel through 6.8.0 allows a physically proximate attacker to read kernel memory by mounting a filesystem (e.g., if a Linux distribution …

Aug 28, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.