CVE Database

11833+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-39911
10.0 CRITICAL

1Panel is a web-based linux server management control panel. 1Panel contains an unspecified sql injection via User-Agent handling. This issue has been addressed in version …

Jul 18, 2024
CVE-2024-39907
9.8 CRITICAL

1Panel is a web-based linux server management control panel. There are many sql injections in the project, and some of them are not well filtered, …

Jul 18, 2024
CVE-2024-6164
9.8 CRITICAL

The Filter & Grids WordPress plugin before 2.8.33 is vulnerable to Local File Inclusion via the post_layout parameter. This makes it possible for an unauthenticated …

Jul 18, 2024
CVE-2024-41184
9.8 CRITICAL

In the vrrp_ipsets_handler handler (fglobal_parser.c) of keepalived through 2.3.1, an integer overflow can occur. NOTE: this CVE Record might not be worthwhile because an empty …

Jul 18, 2024
CVE-2024-20419
10.0 CRITICAL

A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to change the password of …

Jul 17, 2024
CVE-2024-20401
9.8 CRITICAL

A vulnerability in the content scanning and message filtering features of Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to overwrite arbitrary files …

Jul 17, 2024
CVE-2024-6834
9.0 CRITICAL

A vulnerability in APIML Spring Cloud Gateway which leverages user privileges by unexpected signing proxied request by Zowe's client certificate. This allows access to a …

Jul 17, 2024
CVE-2024-28074
9.6 CRITICAL

It was discovered that a previous vulnerability was not completely fixed with SolarWinds Access Rights Manager. While some controls were implemented the researcher was able …

Jul 17, 2024
CVE-2024-23475
9.6 CRITICAL

The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an unauthenticated user to perform arbitrary file …

Jul 17, 2024
CVE-2024-23472
9.6 CRITICAL

SolarWinds Access Rights Manager (ARM) is susceptible to Directory Traversal vulnerability. This vulnerability allows an authenticated user to arbitrary read and delete files in ARM.

Jul 17, 2024
CVE-2024-23471
9.6 CRITICAL

The SolarWinds Access Rights Manager was found to be susceptible to a Remote Code Execution Vulnerability. If exploited, this vulnerability allows an authenticated user to …

Jul 17, 2024
CVE-2024-23470
9.6 CRITICAL

The SolarWinds Access Rights Manager was found to be susceptible to a pre-authentication remote code execution vulnerability. If exploited, this vulnerability allows an unauthenticated user …

Jul 17, 2024
CVE-2024-23469
9.6 CRITICAL

SolarWinds Access Rights Manager (ARM) is susceptible to a Remote Code Execution vulnerability. If exploited, this vulnerability allows an unauthenticated user to perform the actions …

Jul 17, 2024
CVE-2024-23467
9.6 CRITICAL

The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an unauthenticated user to perform remote code …

Jul 17, 2024
CVE-2024-23466
9.6 CRITICAL

SolarWinds Access Rights Manager (ARM) is susceptible to a Directory Traversal Remote Code Execution vulnerability. If exploited, this vulnerability allows an unauthenticated user to perform …

Jul 17, 2024
CVE-2024-36491
9.8 CRITICAL

FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. allow an administrative user to execute an arbitrary OS command, obtain …

Jul 17, 2024
CVE-2024-31070
9.1 CRITICAL

Initialization of a resource with an insecure default vulnerability in FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. allows …

Jul 17, 2024
CVE-2024-6220
9.8 CRITICAL

The 简数采集器 (Keydatas) plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the keydatas_downloadImages function in all versions …

Jul 17, 2024
CVE-2024-21181
9.8 CRITICAL

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability …

Jul 16, 2024
CVE-2023-7012
9.6 CRITICAL

Insufficient data validation in Permission Prompts in Google Chrome prior to 117.0.5938.62 allowed an attacker who convinced a user to install a malicious app to …

Jul 16, 2024
CVE-2023-4860
9.6 CRITICAL

Inappropriate implementation in Skia in Google Chrome prior to 115.0.5790.98 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox …

Jul 16, 2024
CVE-2019-25154
9.6 CRITICAL

Inappropriate implementation in iframe in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. …

Jul 16, 2024
CVE-2024-6779
9.6 CRITICAL

Out of bounds memory access in V8 in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to potentially perform a sandbox escape via a …

Jul 16, 2024
CVE-2024-40535
9.8 CRITICAL

Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 v3.2 was discovered to contain a stack overflow via the apn_name_3g parameter in the config_3g_para function.

Jul 16, 2024
CVE-2024-40515
9.8 CRITICAL

An issue in SHENZHEN TENDA TECHNOLOGY CO.,LTD Tenda AX2pro V16.03.29.48_cn allows a remote attacker to execute arbitrary code via the Routing functionality.

Jul 16, 2024
CVE-2024-40505
9.3 CRITICAL

Directory Traversal vulnerability in D-Link DAP-1650 Firmware v.1.03 allows a local attacker to escalate privileges via the hedwig.cgi component.

Jul 16, 2024
CVE-2024-40456
9.8 CRITICAL

ThinkSAAS v3.7.0 was discovered to contain a SQL injection vulnerability via the name parameter at \system\action\update.php.

Jul 16, 2024
CVE-2024-40394
9.8 CRITICAL

Simple Library Management System Project Using PHP/MySQL v1.0 was discovered to contain an arbitrary file upload vulnerability via the component ajax.php.

Jul 16, 2024
CVE-2024-40393
9.8 CRITICAL

Online Clinic Management System In PHP With Free Source code v1.0 was discovered to contain a SQL injection vulnerability via the user parameter at login.php.

Jul 16, 2024
CVE-2024-40392
9.8 CRITICAL

SourceCodester Pharmacy/Medical Store Point of Sale System Using PHP/MySQL and Bootstrap Framework with Source Code 1.0 was discovered to contain a SQL injection vulnerability via …

Jul 16, 2024
CVE-2024-40130
9.8 CRITICAL

open5gs v2.6.4 is vulnerable to Buffer Overflow. via /lib/core/abts.c.

Jul 16, 2024
CVE-2024-40129
9.8 CRITICAL

Open5GS v2.6.4 is vulnerable to Buffer Overflow. via /lib/pfcp/context.c.

Jul 16, 2024
CVE-2024-40425
9.8 CRITICAL

File Upload vulnerability in Nanjin Xingyuantu Technology Co Sparkshop (Spark Mall B2C Mall v.1.1.6 and before allows a remote attacker to execute arbitrary code via …

Jul 16, 2024
CVE-2024-39700
9.9 CRITICAL

JupyterLab extension template is a `copier` template for JupyterLab extensions. Repositories created using this template with `test` option include `update-integration-tests.yml` workflow which has an RCE …

Jul 16, 2024
CVE-2019-16639
9.8 CRITICAL

An issue was found on the Ruijie EG-2000 series gateway. There is a newcli.php API interface without access control, which can allow an attacker (who …

Jul 16, 2024
CVE-2024-35338
9.8 CRITICAL

Tenda i29V1.0 V1.0.0.5 was discovered to contain a hardcoded password for root.

Jul 16, 2024
CVE-2024-33182
9.8 CRITICAL

Tenda AC18 V15.03.3.10_EN was discovered to contain a stack-based buffer overflow vulnerability via the deviceId parameter at ip/goform/addWifiMacFilter.

Jul 16, 2024
CVE-2024-33180
9.8 CRITICAL

Tenda AC18 V15.03.3.10_EN was discovered to contain a stack-based buffer overflow vulnerability via the deviceId parameter at ip/goform/saveParentControlInfo.

Jul 16, 2024
CVE-2024-22442
9.8 CRITICAL

The vulnerability could be remotely exploited to bypass authentication.

Jul 16, 2024
CVE-2024-6457
9.8 CRITICAL

The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the ‘woof_author’ parameter in all versions up …

Jul 16, 2024
CVE-2024-40524
9.8 CRITICAL

Directory Traversal vulnerability in xmind2testcase v.1.5 allows a remote attacker to execute arbitrary code via the webtool\application.py component.

Jul 15, 2024
CVE-2024-4143
9.8 CRITICAL

A potential security vulnerability has been identified in certain HP PC products using AMI BIOS, which might allow arbitrary code execution. AMI has released firmware …

Jul 15, 2024
CVE-2024-40624
9.8 CRITICAL

TorrentPier is an open source BitTorrent Public/Private tracker engine, written in php. In `torrentpier/library/includes/functions.php`, `get_tracks()` uses the unsafe native PHP serialization format to deserialize user-controlled …

Jul 15, 2024
CVE-2024-39915
9.9 CRITICAL

Thruk is a multibackend monitoring webinterface for Naemon, Nagios, Icinga and Shinken using the Livestatus API. This authenticated RCE in Thruk allows authorized users with …

Jul 15, 2024
CVE-2024-40416
9.8 CRITICAL

A vulnerability in /goform/SetVirtualServerCfg in the sub_6320C function in Tenda AX1806 1.0.0.1 firmware leads to stack-based buffer overflow.

Jul 15, 2024
CVE-2024-40415
9.8 CRITICAL

A vulnerability in /goform/SetStaticRouteCfg in the sub_519F4 function in Tenda AX1806 1.0.0.1 firmware leads to stack-based buffer overflow.

Jul 15, 2024
CVE-2024-40414
9.8 CRITICAL

A vulnerability in /goform/SetNetControlList in the sub_656BC function in Tenda AX1806 1.0.0.1 firmware leads to stack-based buffer overflow.

Jul 15, 2024
CVE-2024-6744
9.8 CRITICAL

The SMTP Listener of Secure Email Gateway from Cellopoint does not properly validate user input, leading to a Buffer Overflow vulnerability. An unauthenticated remote attacker …

Jul 15, 2024
CVE-2024-6743
9.8 CRITICAL

AguardNet's Space Management System does not properly validate user input, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database …

Jul 15, 2024
CVE-2024-5450
9.1 CRITICAL

The Bug Library WordPress plugin before 2.1.1 does not check the file type on user-submitted bug reports, allowing an unauthenticated user to upload PHP files

Jul 13, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.