CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-7202
9.8 CRITICAL

The query functionality of WinMatrix3 Web package from Simopro Technology lacks proper validation of user input, allowing unauthenticated remote attackers to inject SQL commands to …

Jul 29, 2024
CVE-2024-7182
8.8 HIGH

A vulnerability, which was classified as critical, has been found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. This issue affects the function setUpgradeFW of the file /cgi-bin/cstecgi.cgi. The …

Jul 29, 2024
CVE-2024-7181
6.3 MEDIUM

A vulnerability classified as critical was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. This vulnerability affects the function setTelnetCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the …

Jul 29, 2024
CVE-2024-7201
9.8 CRITICAL

The login functionality of WinMatrix3 Web package from Simopro Technology lacks proper validation of user input, allowing unauthenticated remote attackers to inject SQL commands to …

Jul 29, 2024
CVE-2024-7180
8.8 HIGH

A vulnerability classified as critical has been found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. This affects the function setPortForwardRules of the file /cgi-bin/cstecgi.cgi. The manipulation of the …

Jul 29, 2024
CVE-2024-7179
8.8 HIGH

A vulnerability was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. It has been rated as critical. Affected by this issue is the function setParentalRules of the file …

Jul 29, 2024
CVE-2024-7178
8.8 HIGH

A vulnerability was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. It has been declared as critical. Affected by this vulnerability is the function setMacQos of the file …

Jul 29, 2024
CVE-2024-5670
9.8 CRITICAL

The web services of Softnext's products, Mail SQR Expert and Mail Archiving Expert do not properly validate user input, allowing unauthenticated remote attackers to inject …

Jul 29, 2024
CVE-2024-32671
9.8 CRITICAL

Heap-based Buffer Overflow vulnerability in Samsung Open Source Escargot JavaScript engine allows Overflow Buffers.This issue affects Escargot: 4.0.0.

Jul 29, 2024
CVE-2024-7177
8.8 HIGH

A vulnerability was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. It has been classified as critical. Affected is the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi. The manipulation …

Jul 29, 2024
CVE-2024-7176
8.8 HIGH

A vulnerability was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102 and classified as critical. This issue affects the function setIpQosRules of the file /cgi-bin/cstecgi.cgi. The manipulation of …

Jul 29, 2024
CVE-2024-7175
6.3 MEDIUM

A vulnerability has been found in TOTOLINK A3600R 4.1.2cu.5182_B20201102 and classified as critical. This vulnerability affects the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi. The manipulation …

Jul 29, 2024
CVE-2024-7174
8.8 HIGH

A vulnerability, which was classified as critical, was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. This affects the function setdeviceName of the file /cgi-bin/cstecgi.cgi. The manipulation of …

Jul 29, 2024
CVE-2024-7173
8.8 HIGH

A vulnerability, which was classified as critical, has been found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. Affected by this issue is the function loginauth of the file …

Jul 29, 2024
CVE-2024-7172
8.8 HIGH

A vulnerability classified as critical was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. Affected by this vulnerability is the function getSaveConfig of the file /cgi-bin/cstecgi.cgi?action=save&setting. The manipulation …

Jul 28, 2024
CVE-2024-7171
6.3 MEDIUM

A vulnerability classified as critical has been found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. Affected is the function NTPSyncWithHost of the file /cgi-bin/cstecgi.cgi. The manipulation of the …

Jul 28, 2024
CVE-2024-7170
3.5 LOW

A vulnerability was found in TOTOLINK A3000RU 5.9c.5185. It has been rated as problematic. This issue affects some unknown processing of the file /web_cste/cgi-bin/product.ini. The …

Jul 28, 2024
CVE-2024-7169
4.3 MEDIUM

A vulnerability classified as problematic has been found in SourceCodester School Fees Payment System 1.0. This affects an unknown part of the file /ajax.php. The …

Jul 28, 2024
CVE-2024-7168
6.3 MEDIUM

A vulnerability was found in SourceCodester School Fees Payment System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

Jul 28, 2024
CVE-2024-7167
6.3 MEDIUM

A vulnerability was found in SourceCodester School Fees Payment System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Jul 28, 2024
CVE-2024-7166
6.3 MEDIUM

A vulnerability was found in SourceCodester School Fees Payment System 1.0. It has been classified as critical. Affected is an unknown function of the file …

Jul 28, 2024
CVE-2024-7165
6.3 MEDIUM

A vulnerability was found in SourceCodester School Fees Payment System 1.0 and classified as critical. This issue affects some unknown processing of the file /view_payment.php. …

Jul 28, 2024
CVE-2024-7164
7.3 HIGH

A vulnerability has been found in SourceCodester School Fees Payment System 1.0 and classified as critical. This vulnerability affects unknown code of the file /ajax.php?action=login. …

Jul 28, 2024
CVE-2024-7163
3.5 LOW

A vulnerability, which was classified as problematic, was found in SeaCMS 12.9. This affects an unknown part of the file /js/player/dmplayer/player/index.php. The manipulation of the …

Jul 28, 2024
CVE-2024-7162
3.5 LOW

A vulnerability, which was classified as problematic, has been found in SeaCMS 12.9/13.0. Affected by this issue is some unknown functionality of the file js/player/dmplayer/admin/post.php?act=setting. …

Jul 28, 2024
CVE-2024-7161
4.3 MEDIUM

A vulnerability classified as problematic was found in SeaCMS 13.0. Affected by this vulnerability is an unknown functionality of the file /member.php?action=chgpwdsubmit of the component …

Jul 28, 2024
CVE-2024-7160
6.3 MEDIUM

A vulnerability classified as critical has been found in TOTOLINK A3700R 9.1.2u.5822_B20200513. Affected is the function setWanCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the …

Jul 28, 2024
CVE-2024-7159
5.5 MEDIUM

A vulnerability was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. It has been rated as critical. This issue affects some unknown processing of the file /web_cste/cgi-bin/product.ini of …

Jul 28, 2024
CVE-2024-7158
6.3 MEDIUM

A vulnerability was found in TOTOLINK A3100R 4.1.2cu.5050_B20200504. It has been declared as critical. This vulnerability affects the function setTelnetCfg of the file /cgi-bin/cstecgi.cgi of …

Jul 28, 2024
CVE-2024-7157
8.8 HIGH

A vulnerability was found in TOTOLINK A3100R 4.1.2cu.5050_B20200504. It has been classified as critical. This affects the function getSaveConfig of the file /cgi-bin/cstecgi.cgi?action=save&setting. The manipulation …

Jul 28, 2024
CVE-2024-7156
5.3 MEDIUM

A vulnerability was found in TOTOLINK A3700R 9.1.2u.5822_B20200513 and classified as problematic. Affected by this issue is some unknown functionality of the file /cgi-bin/ExportSettings.sh of …

Jul 28, 2024
CVE-2024-7155
2.5 LOW

A vulnerability has been found in TOTOLINK A3300R 17.0.0cu.557_B20221024 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /etc/shadow.sample. …

Jul 28, 2024
CVE-2024-7154
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in TOTOLINK A3700R 9.1.2u.5822_B20200513. Affected is an unknown function of the file /wizard.html of the component …

Jul 28, 2024
CVE-2024-42055
5.4 MEDIUM

Cervantes through 0.5-alpha allows stored XSS.

Jul 28, 2024
CVE-2024-42054
5.4 MEDIUM

Cervantes through 0.5-alpha accepts insecure file uploads.

Jul 28, 2024
CVE-2024-42053
7.8 HIGH

The MSI installer for Splashtop Streamer for Windows before 3.6.0.0 uses a temporary folder with weak permissions during installation. A local user can exploit this …

Jul 28, 2024
CVE-2024-42052
7.8 HIGH

The MSI installer for Splashtop Streamer for Windows before 3.5.8.0 uses a temporary folder with weak permissions during installation. A local user can exploit this …

Jul 28, 2024
CVE-2024-42051
7.8 HIGH

The MSI installer for Splashtop Streamer for Windows before 3.6.2.0 uses a temporary folder with weak permissions during installation. A local user can exploit this …

Jul 28, 2024
CVE-2024-42050
7.0 HIGH

The MSI installer for Splashtop Streamer for Windows before 3.7.0.0 uses a temporary folder with weak permissions during installation. A local user can exploit this …

Jul 28, 2024
CVE-2024-42049
9.1 CRITICAL

TightVNC (Server for Windows) before 2.8.84 allows attackers to connect to the control pipe via a network connection.

Jul 28, 2024
CVE-2024-7153
5.3 MEDIUM

A vulnerability classified as problematic has been found in Netgear WN604 up to 20240719. Affected is an unknown function of the file siteSurvey.php. The manipulation …

Jul 27, 2024
CVE-2024-7152
8.8 HIGH

A vulnerability was found in Tenda O3 1.0.0.10(2478). It has been rated as critical. This issue affects the function fromSafeSetMacFilter of the file /goform/setMacFilterList. The …

Jul 27, 2024
CVE-2024-7151
8.8 HIGH

A vulnerability was found in Tenda O3 1.0.0.10(2478). It has been declared as critical. This vulnerability affects the function fromMacFilterSet of the file /goform/setMacFilter. The …

Jul 27, 2024
CVE-2024-6703
4.9 MEDIUM

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site …

Jul 27, 2024
CVE-2024-6897
6.4 MEDIUM

The aThemes Starter Sites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.53 …

Jul 27, 2024
CVE-2024-6627
6.4 MEDIUM

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's PDF View widget in all versions up to, …

Jul 27, 2024
CVE-2024-6521
4.4 MEDIUM

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site …

Jul 27, 2024
CVE-2024-6520
4.4 MEDIUM

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site …

Jul 27, 2024
CVE-2024-6518
4.4 MEDIUM

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site …

Jul 27, 2024
CVE-2024-5614
5.3 MEDIUM

The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.29 via the 'pafe_posts_list' …

Jul 27, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.