CVE Database

9974+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-22203
9.1 CRITICAL

Whoogle Search is a self-hosted metasearch engine. In versions prior to 0.8.4, the `element` method in `app/routes.py` does not validate the user-controlled `src_type` and `element_url` …

Jan 23, 2024
CVE-2024-22663
9.8 CRITICAL

TOTOLINK_A3700R_V9.1.2u.6165_20211012has a command Injection vulnerability via setOpModeCfg

Jan 23, 2024
CVE-2024-22662
9.8 CRITICAL

TOTOLINK A3700R_V9.1.2u.6165_20211012 has a stack overflow vulnerability via setParentalRules

Jan 23, 2024
CVE-2024-22660
9.8 CRITICAL

TOTOLINK_A3700R_V9.1.2u.6165_20211012has a stack overflow vulnerability via setLanguageCfg

Jan 23, 2024
CVE-2023-49657
9.6 CRITICAL

A stored cross-site scripting (XSS) vulnerability exists in Apache Superset before 3.0.3. An authenticated attacker with create/update permissions on charts or dashboards could store a …

Jan 23, 2024
CVE-2024-22076
9.8 CRITICAL

MyQ Print Server before 8.2 patch 43 allows remote authenticated administrators to execute arbitrary code via PHP scripts that are reached through the administrative interface.

Jan 23, 2024
CVE-2021-42141
9.8 CRITICAL

An issue was discovered in Contiki-NG tinyDTLS through 2018-08-30. One incorrect handshake could complete with different epoch numbers in the packets Client_Hello, Client_key_exchange, and Change_cipher_spec, …

Jan 22, 2024
CVE-2023-48118
9.8 CRITICAL

SQL Injection vulnerability in Quest Analytics LLC IQCRM v.2023.9.5 allows a remote attacker to execute arbitrary code via a crafted request to the Common.svc WSDL …

Jan 22, 2024
CVE-2024-0204
9.8 CRITICAL

Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the administration portal.

Jan 22, 2024
CVE-2017-20189
9.8 CRITICAL

In Clojure before 1.9.0, classes can be used to construct a serialized object that executes arbitrary code upon deserialization. This is relevant if a server …

Jan 22, 2024
CVE-2024-23771
9.8 CRITICAL

darkhttpd before 1.15 uses strcmp (which is not constant time) to verify authentication, which makes it easier for remote attackers to bypass authentication via a …

Jan 22, 2024
CVE-2024-23752
9.8 CRITICAL

GenerateSDFPipeline in synthetic_dataframe in PandasAI (aka pandas-ai) through 1.5.17 allows attackers to trigger the generation of arbitrary Python code that is executed by SDFCodeExecutor. An …

Jan 22, 2024
CVE-2024-23751
9.8 CRITICAL

LlamaIndex (aka llama_index) through 0.9.34 allows SQL injection via the Text-to-SQL feature in NLSQLTableQueryEngine, SQLTableRetrieverQueryEngine, NLSQLRetriever, RetrieverQueryEngine, and PGVectorSQLQueryEngine. For example, an attacker might be …

Jan 22, 2024
CVE-2024-23731
9.8 CRITICAL

The OpenAPI loader in Embedchain before 0.1.57 allows attackers to execute arbitrary code, related to the openapi.py yaml.load function argument.

Jan 21, 2024
CVE-2024-23730
9.8 CRITICAL

The OpenAPI and ChatGPT plugin loaders in LlamaHub (aka llama-hub) before 0.0.67 allow attackers to execute arbitrary code because safe_load is not used for YAML.

Jan 21, 2024
CVE-2023-51925
9.8 CRITICAL

An arbitrary file upload vulnerability in the nccloud.web.arcp.taskmonitor.action.ArcpUploadAction.doAction() method of YonBIP v3_23.05 allows attackers to execute arbitrary code via uploading a crafted file.

Jan 20, 2024
CVE-2023-51924
9.8 CRITICAL

An arbitrary file upload vulnerability in the uap.framework.rc.itf.IResourceManager interface of YonBIP v3_23.05 allows attackers to execute arbitrary code via uploading a crafted file.

Jan 20, 2024
CVE-2023-51906
9.8 CRITICAL

An issue in yonyou YonBIP v3_23.05 allows a remote attacker to execute arbitrary code via a crafted script to the ServiceDispatcherServlet uap.framework.rc.itf.IResourceManager component.

Jan 20, 2024
CVE-2023-51928
9.8 CRITICAL

An arbitrary file upload vulnerability in the nccloud.web.arcp.taskmonitor.action.ArcpUploadAction.doAction() method of YonBIP v3_23.05 allows attackers to execute arbitrary code via uploading a crafted file.

Jan 20, 2024
CVE-2023-51927
9.8 CRITICAL

YonBIP v3_23.05 was discovered to contain a SQL injection vulnerability via the com.yonyou.hrcloud.attend.web.AttendScriptController.runScript() method.

Jan 20, 2024
CVE-2023-51892
9.8 CRITICAL

An issue in weaver e-cology v.10.0.2310.01 allows a remote attacker to execute arbitrary code via a crafted script to the FrameworkShellController component.

Jan 20, 2024
CVE-2021-31314
9.8 CRITICAL

File upload vulnerability in ejinshan v8+ terminal security system allows attackers to upload arbitrary files to arbitrary locations on the server.

Jan 20, 2024
CVE-2024-23687
9.1 CRITICAL

Hard-coded credentials in FOLIO mod-data-export-spring versions before 1.5.4 and from 2.0.0 to 2.0.2 allows unauthenticated users to access critical APIs, modify user data, modify configurations …

Jan 19, 2024
CVE-2024-23679
9.8 CRITICAL

Enonic XP versions less than 7.7.4 are vulnerable to a session fixation issue. An remote and unauthenticated attacker can use prior sessions due to the …

Jan 19, 2024
CVE-2023-50694
9.8 CRITICAL

An issue in dom96 HTTPbeast v.0.4.1 and before allows a remote attacker to send a malicious crafted request due to insufficient parsing in the parser.nim …

Jan 19, 2024
CVE-2023-50693
9.8 CRITICAL

An issue in Jester v.0.6.0 and before allows a remote attacker to send a malicious crafted request.

Jan 19, 2024
CVE-2023-51947
9.1 CRITICAL

Improper access control on nasSvr.php in actidata actiNAS SL 2U-8 RDX 3.2.03-SP1 allows remote attackers to read and modify different types of data without authentication.

Jan 19, 2024
CVE-2023-50030
9.8 CRITICAL

In the module "Jms Setting" (jmssetting) from Joommasters for PrestaShop, a guest can perform SQL injection in versions <= 1.1.0. The method `JmsSetting::getSecondImgs()` has a …

Jan 19, 2024
CVE-2023-50028
9.8 CRITICAL

In the module "Sliding cart block" (blockslidingcart) up to version 2.3.8 from PrestashopModules.eu for PrestaShop, a guest can perform SQL injection.

Jan 19, 2024
CVE-2023-46351
9.8 CRITICAL

In the module mib < 1.6.1 from MyPresta.eu for PrestaShop, a guest can perform SQL injection. The methods `mib::getManufacturersByCategory()` has sensitive SQL calls that can …

Jan 19, 2024
CVE-2023-43985
9.8 CRITICAL

SunnyToo stblogsearch up to v1.0.0 was discovered to contain a SQL injection vulnerability via the StBlogSearchClass::prepareSearch component.

Jan 19, 2024
CVE-2023-27168
9.8 CRITICAL

An arbitrary file upload vulnerability in Xpand IT Write-back Manager v2.3.1 allows attackers to execute arbitrary code via a crafted jsp file.

Jan 19, 2024
CVE-2024-0705
9.8 CRITICAL

The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, …

Jan 19, 2024
CVE-2023-5716
9.8 CRITICAL

ASUS Armoury Crate has a vulnerability in arbitrary file write and allows remote attackers to access or modify arbitrary files by sending specific HTTP requests …

Jan 19, 2024
CVE-2024-22212
9.6 CRITICAL

Nextcloud Global Site Selector is a tool which allows you to run multiple small Nextcloud instances and redirect users to the right server. A problem …

Jan 18, 2024
CVE-2023-40051
9.1 CRITICAL

This issue affects Progress Application Server (PAS) for OpenEdge in versions 11.7 prior to 11.7.18, 12.2 prior to 12.2.13, and innovation releases prior to 12.8.0. …

Jan 18, 2024
CVE-2024-22317
9.1 CRITICAL

IBM App Connect Enterprise 11.0.0.1 through 11.0.0.24 and 12.0.1.0 through 12.0.11.0 could allow a remote attacker to obtain sensitive information or cause a denial of …

Jan 18, 2024
CVE-2023-5806
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mergen Software Quality Management System allows SQL Injection.This issue affects Quality …

Jan 18, 2024
CVE-2023-6816
9.8 CRITICAL

A flaw was found in X.Org server. Both DeviceFocusEvent and the XIQueryPointer reply contain a bit for each logical button currently down. Buttons can be …

Jan 18, 2024
CVE-2024-22416
9.6 CRITICAL

pyLoad is a free and open-source Download Manager written in pure Python. The `pyload` API allows any API call to be made using GET requests. …

Jan 18, 2024
CVE-2023-44077
9.8 CRITICAL

Studio Network Solutions ShareBrowser before 7.0 on macOS mishandles signature verification, aka PMP-2636.

Jan 17, 2024
CVE-2024-0643
10.0 CRITICAL

Unrestricted upload of dangerous file types in the C21 Live Encoder and Live Mosaic product, version 5.3. This vulnerability allows a remote attacker to upload …

Jan 17, 2024
CVE-2024-0642
9.8 CRITICAL

Inadequate access control in the C21 Live Encoder and Live Mosaic product, version 5.3. This vulnerability allows a remote attacker to access the application as …

Jan 17, 2024
CVE-2021-4434
10.0 CRITICAL

The Social Warfare plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.5.2 via the 'swp_url' parameter. This allows …

Jan 17, 2024
CVE-2024-22406
9.3 CRITICAL

Shopware is an open headless commerce platform. The Shopware application API contains a search functionality which enables users to search through information stored within their …

Jan 16, 2024
CVE-2024-22916
9.8 CRITICAL

In D-LINK Go-RT-AC750 v101b03, the sprintf function in the sub_40E700 function within the cgibin is susceptible to stack overflow.

Jan 16, 2024
CVE-2023-52042
9.8 CRITICAL

An issue discovered in sub_4117F8 function in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the 'lang' parameter.

Jan 16, 2024
CVE-2023-39691
9.8 CRITICAL

An issue discovered in kodbox through 1.43 allows attackers to arbitrarily add Administrator accounts via crafted GET request.

Jan 16, 2024
CVE-2023-52041
9.8 CRITICAL

An issue discovered in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary code via the sub_410118 function of the shttpd program.

Jan 16, 2024
CVE-2023-49351
9.8 CRITICAL

A stack-based buffer overflow vulnerability in /bin/webs binary in Edimax BR6478AC V2 firmware veraion v1.23 allows attackers to overwrite other values located on the stack …

Jan 16, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.