CVE Database

9973+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-25220
9.8 CRITICAL

Task Manager App v1.0 was discovered to contain a SQL injection vulnerability via the taskID parameter at /TaskManager/EditTask.php.

Feb 14, 2024
CVE-2024-25217
9.8 CRITICAL

Online Medicine Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /omos/?p=products/view_product.

Feb 14, 2024
CVE-2024-25216
9.8 CRITICAL

Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the mailud parameter at /aprocess.php.

Feb 14, 2024
CVE-2024-25215
9.8 CRITICAL

Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the pwd parameter at /aprocess.php.

Feb 14, 2024
CVE-2024-25214
9.8 CRITICAL

An issue in Employee Managment System v1.0 allows attackers to bypass authentication via injecting a crafted payload into the E-mail and Password parameters at /alogin.html.

Feb 14, 2024
CVE-2024-25211
9.8 CRITICAL

Simple Expense Tracker v1.0 was discovered to contain a SQL injection vulnerability via the category parameter at /endpoint/delete_category.php.

Feb 14, 2024
CVE-2024-25210
9.8 CRITICAL

Simple Expense Tracker v1.0 was discovered to contain a SQL injection vulnerability via the expense parameter at /endpoint/delete_expense.php.

Feb 14, 2024
CVE-2024-25209
9.8 CRITICAL

Barangay Population Monitoring System 1.0 was discovered to contain a SQL injection vulnerability via the resident parameter at /endpoint/delete-resident.php.

Feb 14, 2024
CVE-2023-6441
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in UNI-PA University Marketing & Computer Internet Trade Inc. University Information System …

Feb 14, 2024
CVE-2024-23786
9.3 CRITICAL

Cross-site scripting vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary script …

Feb 14, 2024
CVE-2024-24691
9.6 CRITICAL

Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user …

Feb 14, 2024
CVE-2024-24142
9.8 CRITICAL

Sourcecodester School Task Manager 1.0 allows SQL Injection via the 'subject' parameter.

Feb 13, 2024
CVE-2024-1378
9.1 CRITICAL

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin …

Feb 13, 2024
CVE-2024-1374
9.1 CRITICAL

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin …

Feb 13, 2024
CVE-2024-1372
9.1 CRITICAL

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin …

Feb 13, 2024
CVE-2024-1369
9.1 CRITICAL

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin …

Feb 13, 2024
CVE-2024-1359
9.1 CRITICAL

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin …

Feb 13, 2024
CVE-2024-1355
9.1 CRITICAL

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin …

Feb 13, 2024
CVE-2024-21413
9.8 CRITICAL KEV

Microsoft Outlook Remote Code Execution Vulnerability

Feb 13, 2024
CVE-2024-21410
9.8 CRITICAL KEV

Microsoft Exchange Server Elevation of Privilege Vulnerability

Feb 13, 2024
CVE-2024-21403
9.0 CRITICAL

Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability

Feb 13, 2024
CVE-2024-21401
9.8 CRITICAL

Microsoft Entra Jira Single-Sign-On Plugin Elevation of Privilege Vulnerability

Feb 13, 2024
CVE-2024-21376
9.0 CRITICAL

Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability

Feb 13, 2024
CVE-2024-21364
9.3 CRITICAL

Microsoft Azure Site Recovery Elevation of Privilege Vulnerability

Feb 13, 2024
CVE-2024-22923
9.8 CRITICAL

SQL injection vulnerability in adv radius v.2.2.5 allows a local attacker to execute arbitrary code via a crafted script.

Feb 13, 2024
CVE-2024-23816
9.8 CRITICAL

A vulnerability has been identified in Location Intelligence Perpetual Large (9DE5110-8CA13-1AX0) (All versions < V4.3), Location Intelligence Perpetual Medium (9DE5110-8CA12-1AX0) (All versions < V4.3), Location …

Feb 13, 2024
CVE-2022-48623
9.1 CRITICAL

The Cpanel::JSON::XS package before 4.33 for Perl performs out-of-bounds accesses in a way that allows attackers to obtain sensitive information or cause a denial of …

Feb 13, 2024
CVE-2024-22131
9.1 CRITICAL

In SAP ABA (Application Basis) - versions 700, 701, 702, 731, 740, 750, 751, 752, 75C, 75I, an attacker authenticated as a user with a …

Feb 13, 2024
CVE-2023-42374
9.8 CRITICAL

An issue in mystenlabs Sui Blockchain before v.1.6.3 allow a remote attacker to execute arbitrary code and cause a denial of service via a crafted …

Feb 13, 2024
CVE-2024-23763
9.8 CRITICAL

SQL Injection vulnerability in Gambio through 4.9.2.0 allows attackers to run arbitrary SQL commands via crafted GET request using modifiers[attribute][] parameter.

Feb 12, 2024
CVE-2024-23761
9.8 CRITICAL

Server Side Template Injection in Gambio 4.9.2.0 allows attackers to run arbitrary code via crafted smarty email template.

Feb 12, 2024
CVE-2024-23759
9.8 CRITICAL

Deserialization of Untrusted Data in Gambio through 4.9.2.0 allows attackers to run arbitrary code via "search" parameter of the Parcelshopfinder/AddAddressBookEntry" function.

Feb 12, 2024
CVE-2024-25110
9.8 CRITICAL

The UAMQP is a general purpose C library for AMQP 1.0. During a call to open_get_offered_capabilities, a memory allocation may fail causing a use-after-free issue …

Feb 12, 2024
CVE-2024-25108
9.9 CRITICAL

Pixelfed is an open source photo sharing platform. When processing requests authorization was improperly and insufficiently checked, allowing attackers to access far more functionality than …

Feb 12, 2024
CVE-2023-6036
9.8 CRITICAL

The Web3 WordPress plugin before 3.0.0 is vulnerable to an authentication bypass due to incorrect authentication checking in the login flow in functions 'handle_auth_request' and …

Feb 12, 2024
CVE-2024-24797
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in G5Theme ERE Recently Viewed – Essential Real Estate Add-On.This issue affects ERE Recently Viewed – Essential Real Estate Add-On: …

Feb 12, 2024
CVE-2024-25100
10.0 CRITICAL

Deserialization of Untrusted Data vulnerability in WP Swings Coupon Referral Program allows Object Injection.This issue affects Coupon Referral Program: from n/a before 1.8.4.

Feb 12, 2024
CVE-2024-25722
9.8 CRITICAL

qanything_kernel/connector/database/mysql/mysql_client.py in qanything.ai QAnything before 1.2.0 allows SQL Injection.

Feb 11, 2024
CVE-2024-25718
9.8 CRITICAL

In the Samly package before 1.4.0 for Elixir, Samly.State.Store.get_assertion/3 can return an expired session, which interferes with access control because Samly.AuthHandler uses a cached session …

Feb 11, 2024
CVE-2024-25714
9.8 CRITICAL

In Rhonabwy through 1.1.13, HMAC signature verification uses a strcmp function that is vulnerable to side-channel attacks, because it stops the comparison when the first …

Feb 11, 2024
CVE-2024-23724
9.0 CRITICAL

Ghost through 5.76.0 allows stored XSS, and resultant privilege escalation in which a contributor can take over any account, via an SVG profile picture that …

Feb 11, 2024
CVE-2024-25316
9.8 CRITICAL

Code-projects Hotel Managment System 1.0 allows SQL Injection via the 'eid' parameter in Hotel/admin/usersettingdel.php?eid=2.

Feb 9, 2024
CVE-2024-25315
9.8 CRITICAL

Code-projects Hotel Managment System 1.0, allows SQL Injection via the 'rid' parameter in Hotel/admin/roombook.php?rid=2.

Feb 9, 2024
CVE-2024-25314
9.8 CRITICAL

Code-projects Hotel Managment System 1.0, allows SQL Injection via the 'sid' parameter in Hotel/admin/show.php?sid=2.

Feb 9, 2024
CVE-2024-25307
9.8 CRITICAL

Code-projects Cinema Seat Reservation System 1.0 allows SQL Injection via the 'id' parameter at "/Cinema-Reservation/booking.php?id=1."

Feb 9, 2024
CVE-2024-25302
9.8 CRITICAL

Sourcecodester Event Student Attendance System 1.0, allows SQL Injection via the 'student' parameter.

Feb 9, 2024
CVE-2023-6677
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Oduyo Financial Technology Online Collection allows SQL Injection.This issue affects Online …

Feb 9, 2024
CVE-2024-25678
9.8 CRITICAL

In LiteSpeed QUIC (LSQUIC) Library before 4.0.4, DCID validation is mishandled.

Feb 9, 2024
CVE-2024-25675
9.8 CRITICAL

An issue was discovered in MISP before 2.4.184. A client does not need to use POST to start an export generation process. This is related …

Feb 9, 2024
CVE-2024-25674
9.8 CRITICAL

An issue was discovered in MISP before 2.4.184. Organisation logo upload is insecure because of a lack of checks for the file extension and MIME …

Feb 9, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.