CVE Database

11833+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-39671
9.3 CRITICAL

Access control vulnerability in the security verification module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jul 25, 2024
CVE-2024-37084
9.8 CRITICAL

In Spring Cloud Data Flow versions prior to 2.11.4, a malicious user who has access to the Skipper server api can use a crafted upload …

Jul 25, 2024
CVE-2024-41461
9.8 CRITICAL

Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the list1 parameter at ip/goform/DhcpListClient.

Jul 24, 2024
CVE-2024-41460
9.8 CRITICAL

Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the entrys parameter at ip/goform/RouteStatic.

Jul 24, 2024
CVE-2024-41459
9.8 CRITICAL

Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the PPPOEPassword parameter at ip/goform/QuickIndex.

Jul 24, 2024
CVE-2024-41551
9.8 CRITICAL

CampCodes Supplier Management System v1.0 is vulnerable to SQL injection via Supply_Management_System/admin/view_order_items.php?id= .

Jul 24, 2024
CVE-2024-36535
9.8 CRITICAL

Insecure permissions in meshery v0.7.51 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.

Jul 24, 2024
CVE-2024-36533
9.8 CRITICAL

Insecure permissions in volcano v1.8.2 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.

Jul 24, 2024
CVE-2024-36536
9.8 CRITICAL

Insecure permissions in fabedge v0.8.1 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.

Jul 24, 2024
CVE-2024-41110
9.9 CRITICAL

Moby is an open-source project created by Docker for software containerization. A security vulnerability has been detected in certain versions of Docker Engine, which could …

Jul 24, 2024
CVE-2024-36540
9.8 CRITICAL

Insecure permissions in external-secrets v0.9.16 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.

Jul 24, 2024
CVE-2024-36539
9.8 CRITICAL

Insecure permissions in contour v1.28.3 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.

Jul 24, 2024
CVE-2024-40422
9.1 CRITICAL

The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path traversal attack. An attacker can manipulate the snapshot_path parameter …

Jul 24, 2024
CVE-2024-6327
9.9 CRITICAL

In Progress® Telerik® Report Server versions prior to 2024 Q2 (10.1.24.709), a remote code execution attack is possible through an insecure deserialization vulnerability.

Jul 24, 2024
CVE-2023-45249
9.8 CRITICAL KEV

Remote command execution due to use of default passwords. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.0.1-61, Acronis Cyber Infrastructure (ACI) …

Jul 24, 2024
CVE-2024-38164
9.6 CRITICAL

An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network by convincing a user to click on …

Jul 23, 2024
CVE-2024-41319
9.8 CRITICAL

TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the cmd parameter in the webcmd function.

Jul 23, 2024
CVE-2024-29070
9.1 CRITICAL

On versions before 2.1.4, session is not invalidated after logout. When the user logged in successfully, the Backend service returns "Authorization" as the front-end authentication …

Jul 23, 2024
CVE-2024-6912
9.8 CRITICAL

Use of hard-coded MSSQL credentials in PerkinElmer ProcessPlus on Windows allows an attacker to login remove on all prone installations.This issue affects ProcessPlus: through 1.11.6507.0.

Jul 22, 2024
CVE-2024-6806
9.8 CRITICAL

The NI VeriStand Gateway is missing authorization checks when an actor attempts to access Project resources. These missing checks may result in remote code execution. …

Jul 22, 2024
CVE-2024-6794
9.8 CRITICAL

A deserialization of untrusted data vulnerability exists in NI VeriStand Waveform Streaming Server that may result in remote code execution. Successful exploitation requires an attacker …

Jul 22, 2024
CVE-2024-6793
9.8 CRITICAL

A deserialization of untrusted data vulnerability exists in NI VeriStand DataLogging Server that may result in remote code execution. Successful exploitation requires an attacker to …

Jul 22, 2024
CVE-2024-40502
9.8 CRITICAL

SQL injection vulnerability in Hospital Management System Project in ASP.Net MVC 1 allows aremote attacker to execute arbitrary code via the btn_login_b_Click function of the …

Jul 22, 2024
CVE-2024-39250
9.8 CRITICAL

EfroTech Timetrax v8.3 was discovered to contain an unauthenticated SQL injection vulnerability via the q parameter in the search web interface.

Jul 22, 2024
CVE-2024-38944
9.8 CRITICAL

An issue in Intelight X-1L Traffic controller Maxtime v.1.9.6 allows a remote attacker to execute arbitrary code via the /cgi-bin/generateForm.cgi?formID=142 component.

Jul 22, 2024
CVE-2024-28698
9.8 CRITICAL

Directory Traversal vulnerability in Marimer LLC CSLA .Net before 8.0 allows a remote attacker to execute arbitrary code via a crafted script to the MobileFormatter …

Jul 22, 2024
CVE-2024-39686
9.8 CRITICAL

Bert-VITS2 is the VITS2 Backbone with multilingual bert. User input supplied to the data_dir variable is used directly in a command executed with subprocess.run(cmd, shell=True) …

Jul 22, 2024
CVE-2024-39685
9.8 CRITICAL

Bert-VITS2 is the VITS2 Backbone with multilingual bert. User input supplied to the data_dir variable is used directly in a command executed with subprocess.run(cmd, shell=True) …

Jul 22, 2024
CVE-2024-26020
9.6 CRITICAL

An arbitrary script execution vulnerability exists in the MPV functionality of Ankitects Anki 24.04. A specially crafted flashcard can lead to a arbitrary code execution. …

Jul 22, 2024
CVE-2024-21552
9.8 CRITICAL

All versions of `SuperAGI` are vulnerable to Arbitrary Code Execution due to unsafe use of the ‘eval’ function. An attacker could induce the LLM output …

Jul 22, 2024
CVE-2024-41318
9.8 CRITICAL

TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_wps_gen_pincode function.

Jul 22, 2024
CVE-2024-41316
9.8 CRITICAL

TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_cancel_wps function.

Jul 22, 2024
CVE-2024-37998
9.8 CRITICAL

A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V5.40), SICORE Base system (All versions < V1.4.0). The password of administrative accounts …

Jul 22, 2024
CVE-2024-38773
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Adrian Tobey FormLift for Infusionsoft Web Forms allows Blind SQL Injection.This …

Jul 22, 2024
CVE-2024-41704
9.8 CRITICAL

LibreChat through 0.7.4-rc1 does not validate the normalized pathnames of images.

Jul 22, 2024
CVE-2024-41703
9.8 CRITICAL

LibreChat through 0.7.4-rc1 has incorrect access control for message updates.

Jul 22, 2024
CVE-2024-38438
9.8 CRITICAL

D-Link - CWE-294: Authentication Bypass by Capture-replay

Jul 21, 2024
CVE-2024-38437
9.8 CRITICAL

D-Link - CWE-288:Authentication Bypass Using an Alternate Path or Channel

Jul 21, 2024
CVE-2024-6636
9.8 CRITICAL

The WooCommerce - Social Login plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'woo_slg_login_email' function …

Jul 20, 2024
CVE-2024-41603
9.6 CRITICAL

Spina CMS v2.18.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the URI /admin/layout.

Jul 19, 2024
CVE-2024-39962
9.8 CRITICAL

D-Link DIR-823X AX3000 Dual-Band Gigabit Wireless Router v21_D240126 was discovered to contain a remote code execution (RCE) vulnerability in the ntp_zone_val parameter at /goform/set_ntp. This …

Jul 19, 2024
CVE-2024-29736
9.1 CRITICAL

A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform SSRF style attacks …

Jul 19, 2024
CVE-2024-6205
9.8 CRITICAL

The PayPlus Payment Gateway WordPress plugin before 6.6.9 does not properly sanitise and escape a parameter before using it in a SQL statement via a …

Jul 19, 2024
CVE-2024-35198
9.8 CRITICAL

TorchServe is a flexible and easy-to-use tool for serving and scaling PyTorch models in production. TorchServe 's check on allowed_urls configuration can be by-passed if …

Jul 19, 2024
CVE-2024-39173
9.8 CRITICAL

calculator-boilerplate v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the eval function at /routes/calculator.js. This vulnerability allows attackers to execute arbitrary …

Jul 18, 2024
CVE-2024-0857
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Universal Software Inc. FlexWater Corporate Water Management allows SQL Injection.This issue …

Jul 18, 2024
CVE-2024-5619
9.6 CRITICAL

Authorization Bypass Through User-Controlled Key vulnerability in PruvaSoft Informatics Apinizer Management Console allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Apinizer Management Console: …

Jul 18, 2024
CVE-2024-5618
9.9 CRITICAL

Incorrect Permission Assignment for Critical Resource vulnerability in PruvaSoft Informatics Apinizer Management Console allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Apinizer Management …

Jul 18, 2024
CVE-2024-40629
10.0 CRITICAL

JumpServer is an open-source Privileged Access Management (PAM) tool that provides DevOps and IT teams with on-demand and secure access to SSH, RDP, Kubernetes, Database …

Jul 18, 2024
CVE-2024-40628
10.0 CRITICAL

JumpServer is an open-source Privileged Access Management (PAM) tool that provides DevOps and IT teams with on-demand and secure access to SSH, RDP, Kubernetes, Database …

Jul 18, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.