CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-40479
8.1 HIGH

A SQL injection vulnerability in "/admin/quizquestion.php" in Kashipara Online Exam System v1.0 allows remote attackers to execute arbitrary SQL commands via the "eid" parameter.

Aug 12, 2024
CVE-2024-40478
5.4 MEDIUM

A Stored Cross Site Scripting (XSS) vulnerability was found in "/admin/afeedback.php" in Kashipara Online Exam System v1.0, which allows remote attackers to execute arbitrary code …

Aug 12, 2024
CVE-2024-40477
9.8 CRITICAL

A SQL injection vulnerability in "/oahms/admin/forgot-password.php" in PHPGurukul Old Age Home Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "email" …

Aug 12, 2024
CVE-2024-40476
8.0 HIGH

A Cross-Site Request Forgery (CSRF) vulnerability was found in SourceCodester Best House Rental Management System v1.0. This could lead to an attacker tricking the administrator …

Aug 12, 2024
CVE-2024-40475
8.8 HIGH

SourceCodester Best House Rental Management System v1.0 is vulnerable to Incorrect Access Control via /rental/payment_report.php, /rental/balance_report.php, /rental/invoices.php, /rental/tenants.php, and /rental/users.php.

Aug 12, 2024
CVE-2024-40474
5.4 MEDIUM

A Reflected Cross Site Scripting (XSS) vulnerability was found in "edit-cate.php" in SourceCodester House Rental Management System v1.0.

Aug 12, 2024
CVE-2024-40473
5.4 MEDIUM

A Stored Cross Site Scripting (XSS) vulnerability was found in "manage_houses.php" in SourceCodester Best House Rental Management System v1.0. It allows remote attackers to execute …

Aug 12, 2024
CVE-2024-40472
9.8 CRITICAL

Sourcecodester Daily Calories Monitoring Tool v1.0 is vulnerable to SQL Injection via "delete-calorie.php."

Aug 12, 2024
CVE-2024-3279
9.1 CRITICAL

An improper access control vulnerability exists in the mintplex-labs/anything-llm application, specifically within the import endpoint. This vulnerability allows an anonymous attacker, without an account in …

Aug 12, 2024
CVE-2024-39815
9.1 CRITICAL

Improper check or handling of exceptional conditions vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9 and prior, enable an …

Aug 12, 2024
CVE-2024-39791
10.0 CRITICAL

Stack-based buffer overflow vulnerabilities affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9 and prior, enable an unauthenticated remote attacker to …

Aug 12, 2024
CVE-2024-39338
7.5 HIGH

axios 1.7.2 allows SSRF via unexpected behavior where requests for path relative URLs get processed as protocol relative URLs.

Aug 12, 2024
CVE-2024-38989
9.8 CRITICAL

izatop bunt v0.29.19 was discovered to contain a prototype pollution via the component /esm/qs.js. This vulnerability allows attackers to execute arbitrary code or cause a …

Aug 12, 2024
CVE-2024-38219
6.5 MEDIUM

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Aug 12, 2024
CVE-2024-38218
8.4 HIGH

Microsoft Edge (HTML-based) Memory Corruption Vulnerability

Aug 12, 2024
CVE-2024-38200
6.5 MEDIUM

Microsoft Office Spoofing Vulnerability

Aug 12, 2024
CVE-2024-37826
7.5 HIGH

A NULL pointer dereference in vercot Serva v4.6.0 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

Aug 12, 2024
CVE-2024-37283
6.5 MEDIUM

An issue was discovered whereby Elastic Agent will leak secrets from the agent policy elastic-agent.yml only when the log level is configured to debug. By …

Aug 12, 2024
CVE-2024-37023
9.1 CRITICAL

Multiple OS command injection vulnerabilities affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9 and prior, enable an authenticated remote attacker …

Aug 12, 2024
CVE-2024-36518
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in attack surface analyzer's dashboard.

Aug 12, 2024
CVE-2024-36462
7.5 HIGH

Uncontrolled resource consumption refers to a software vulnerability where a attacker or system uses excessive resources, such as CPU, memory, or network bandwidth, without proper …

Aug 12, 2024
CVE-2024-36461
9.1 CRITICAL

Within Zabbix, users have the ability to directly modify memory pointers in the JavaScript engine.

Aug 12, 2024
CVE-2024-36460
8.1 HIGH

The front-end audit log allows viewing of unprotected plaintext passwords, where the passwords are displayed in plain text.

Aug 12, 2024
CVE-2024-36035
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection in user session recording.

Aug 12, 2024
CVE-2024-36034
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection in aggregate reports' search option.

Aug 12, 2024
CVE-2024-32765
4.2 MEDIUM

A vulnerability has been reported to affect Network & Virtual Switch. If exploited, the vulnerability could allow local authenticated administrators to gain access to and …

Aug 12, 2024
CVE-2024-30188
8.1 HIGH

File read and write vulnerability in Apache DolphinScheduler , authenticated users can illegally access additional resource files. This issue affects Apache DolphinScheduler: from 3.1.0 before …

Aug 12, 2024
CVE-2024-29831
8.8 HIGH

Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server. If you are using …

Aug 12, 2024
CVE-2024-29082
8.6 HIGH

Improper access control vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9 and prior, enables an unauthenticated remote attacker to …

Aug 12, 2024
CVE-2024-22123
2.7 LOW

Setting SMS media allows to set GSM modem file. Later this file is used as Linux device. But due everything is a file for Linux, …

Aug 12, 2024
CVE-2024-22122
3.0 LOW

Zabbix allows to configure SMS notifications. AT command injection occurs on "Zabbix Server" because there is no validation of "Number" field on Web nor on …

Aug 12, 2024
CVE-2024-22121
6.1 MEDIUM

A non-admin user can change or remove important features within the Zabbix Agent application, thus impacting the integrity and availability of the application.

Aug 12, 2024
CVE-2024-22116
9.9 CRITICAL

An administrator with restricted permissions can exploit the script execution functionality within the Monitoring Hosts section. The lack of default escaping for script parameters enabled …

Aug 12, 2024
CVE-2024-22114
4.3 MEDIUM

User with no permission to any of the Hosts can access and view host count & other statistics through System Information Widget in Global View …

Aug 12, 2024
CVE-2024-21881

Inadequate Encryption Strength vulnerability allow an authenticated attacker to execute arbitrary OS Commands via encrypted package upload.This issue affects Envoy: 4.x and 5.x

Aug 12, 2024
CVE-2024-21880
7.2 HIGH

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability via the url parameter of an authenticated enpoint in Enphase IQ Gateway (formerly …

Aug 12, 2024
CVE-2024-21879
8.8 HIGH

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability through an url parameter of an authenticated enpoint in Enphase IQ Gateway (formerly …

Aug 12, 2024
CVE-2024-21878
9.8 CRITICAL

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Enphase IQ Gateway (formerly known as Envoy) allows OS Command Injection. This …

Aug 12, 2024
CVE-2024-21877
6.5 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability through a url parameter in Enphase IQ Gateway (formerly known as Envoy) allows …

Aug 12, 2024
CVE-2024-21876
9.1 CRITICAL

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability via a URL parameter in Enphase IQ Gateway (formerly known as Envoy) allows …

Aug 12, 2024
CVE-2024-0115
6.1 MEDIUM

NVIDIA CV-CUDA for Ubuntu 20.04, Ubuntu 22.04, and Jetpack contains a vulnerability in Python APIs where a user may cause an uncontrolled resource consumption issue …

Aug 12, 2024
CVE-2024-0113
7.5 HIGH

NVIDIA Mellanox OS, ONYX, Skyway, and MetroX-3 XCC contain a vulnerability in the web support, where an attacker can cause a CGI path traversal by …

Aug 12, 2024
CVE-2023-50810
6.0 MEDIUM

In certain Sonos products before Sonos S1 Release 11.12 and S2 release 15.9, a vulnerability exists in the U-Boot component of the firmware that allow …

Aug 12, 2024
CVE-2023-50809
7.8 HIGH

In certain Sonos products before S1 Release 11.12 and S2 release 15.9, the mt_7615.ko wireless driver does not properly validate an information element during negotiation …

Aug 12, 2024
CVE-2023-38018
6.3 MEDIUM

IBM Aspera Shares 1.10.0 PL2 does not invalidate session after a password change which could allow an authenticated user to impersonate another user on the …

Aug 12, 2024
CVE-2023-31315
7.5 HIGH

Improper validation in a model specific register (MSR) could allow a malicious program with ring0 access to modify SMM configuration while SMI lock is enabled, …

Aug 12, 2024
CVE-2022-38322

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 12, 2024
CVE-2024-42493
5.3 MEDIUM

Dorsett Controls InfoScan is vulnerable due to a leak of possible sensitive information through the response headers and the rendered JavaScript prior to user login.

Aug 8, 2024
CVE-2024-42408
5.3 MEDIUM

The InfoScan client download page can be intercepted with a proxy, to expose filenames located on the system, which could lead to additional information exposure.

Aug 8, 2024
CVE-2024-41161
7.5 HIGH

Use of hard-coded credentials vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9 and prior, enables an unauthenticated remote attacker …

Aug 8, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.