CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-40456
9.8 CRITICAL

ThinkSAAS v3.7.0 was discovered to contain a SQL injection vulnerability via the name parameter at \system\action\update.php.

Jul 16, 2024
CVE-2024-40455
2.7 LOW

An arbitrary file deletion vulnerability in ThinkSAAS v3.7 allows attackers to delete arbitrary files via a crafted request.

Jul 16, 2024
CVE-2024-21686
8.7 HIGH

This High severity Stored XSS vulnerability was introduced in versions 7.13 of Confluence Data Center and Server. This Stored XSS vulnerability, with a CVSS Score …

Jul 16, 2024
CVE-2024-6492
7.4 HIGH

Exposure of Sensitive Information in edge browser session proxy feature in Devolutions Remote Desktop Manager 2024.2.14.0 and earlier on Windows allows an attacker to intercept …

Jul 16, 2024
CVE-2024-40516
8.8 HIGH

An issue in H3C Technologies Co., Limited H3C Magic RC3000 RC3000V100R009 allows a remote attacker to execute arbitrary code via the Routing functionality.

Jul 16, 2024
CVE-2024-40503
6.5 MEDIUM

An issue in Tenda AX12 v.16.03.49.18_cn+ allows a remote attacker to cause a denial of service via the Routing functionality and ICMP packet handling.

Jul 16, 2024
CVE-2024-40394
9.8 CRITICAL

Simple Library Management System Project Using PHP/MySQL v1.0 was discovered to contain an arbitrary file upload vulnerability via the component ajax.php.

Jul 16, 2024
CVE-2024-40393
9.8 CRITICAL

Online Clinic Management System In PHP With Free Source code v1.0 was discovered to contain a SQL injection vulnerability via the user parameter at login.php.

Jul 16, 2024
CVE-2024-40392
9.8 CRITICAL

SourceCodester Pharmacy/Medical Store Point of Sale System Using PHP/MySQL and Bootstrap Framework with Source Code 1.0 was discovered to contain a SQL injection vulnerability via …

Jul 16, 2024
CVE-2024-40130
9.8 CRITICAL

open5gs v2.6.4 is vulnerable to Buffer Overflow. via /lib/core/abts.c.

Jul 16, 2024
CVE-2024-40129
9.8 CRITICAL

Open5GS v2.6.4 is vulnerable to Buffer Overflow. via /lib/pfcp/context.c.

Jul 16, 2024
CVE-2024-39036
6.5 MEDIUM

SeaCMS v12.9 is vulnerable to Arbitrary File Read via admin_safe.php.

Jul 16, 2024
CVE-2024-40425
9.8 CRITICAL

File Upload vulnerability in Nanjin Xingyuantu Technology Co Sparkshop (Spark Mall B2C Mall v.1.1.6 and before allows a remote attacker to execute arbitrary code via …

Jul 16, 2024
CVE-2024-39908
4.3 MEDIUM

REXML is an XML toolkit for Ruby. The REXML gem before 3.3.1 has some DoS vulnerabilities when it parses an XML that has many specific …

Jul 16, 2024
CVE-2024-39700
9.9 CRITICAL

JupyterLab extension template is a `copier` template for JupyterLab extensions. Repositories created using this template with `test` option include `update-integration-tests.yml` workflow which has an RCE …

Jul 16, 2024
CVE-2024-33181
8.8 HIGH

Tenda AC18 V15.03.3.10_EN was discovered to contain a stack-based buffer overflow vulnerability via the deviceMac parameter at ip/goform/addWifiMacFilter.

Jul 16, 2024
CVE-2023-31456
5.4 MEDIUM

There is an SSRF vulnerability in the Fluid Topics platform that affects versions prior to 4.3, where the server can be forced to make arbitrary …

Jul 16, 2024
CVE-2024-6326
5.5 MEDIUM

An exposure of sensitive information vulnerability exists in the Rockwell Automation FactoryTalk® System Service. A malicious user could exploit this vulnerability by starting a back-up …

Jul 16, 2024
CVE-2024-6325
6.5 MEDIUM

The v6.40 release of Rockwell Automation FactoryTalk® Policy Manager CVE-2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html and CVE-2022-1161 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1585.html by implementing CIP security and did not update to the versions …

Jul 16, 2024
CVE-2024-6089
7.5 HIGH

An input validation vulnerability exists in the Rockwell Automation 5015 - AENFTXT when a manipulated PTP packet is sent, causing the secondary adapter to result …

Jul 16, 2024
CVE-2024-40626
7.3 HIGH

Outline is an open source, collaborative document editor. A type confusion issue was found in ProseMirror’s rendering process that leads to a Stored Cross-Site Scripting …

Jul 16, 2024
CVE-2024-3232
7.6 HIGH

A formula injection vulnerability exists in Tenable Identity Exposure where an authenticated remote attacker with administrative privileges could manipulate application form fields in order to …

Jul 16, 2024
CVE-2019-16641
8.4 HIGH

An issue was found on the Ruijie EG-2000 series gateway. There is a buffer overflow in client.so. Consequently, an attacker can use login.php to login …

Jul 16, 2024
CVE-2019-16640
7.5 HIGH

An issue was found in upload.php on the Ruijie EG-2000 series gateway. A parameter passed to the class UploadFile is mishandled (%00 and /var/./html are …

Jul 16, 2024
CVE-2019-16639
9.8 CRITICAL

An issue was found on the Ruijie EG-2000 series gateway. There is a newcli.php API interface without access control, which can allow an attacker (who …

Jul 16, 2024
CVE-2019-16638
7.5 HIGH

An issue was found on the Ruijie EG-2000 series gateway. An attacker can easily dump cleartext stored passwords in /data/config.text with simple XORs. This affects …

Jul 16, 2024
CVE-2024-40322
8.8 HIGH

An issue was discovered in JFinalCMS v.5.0.0. There is a SQL injection vulnerablity via /admin/div_data/data

Jul 16, 2024
CVE-2024-35338
9.8 CRITICAL

Tenda i29V1.0 V1.0.0.5 was discovered to contain a hardcoded password for root.

Jul 16, 2024
CVE-2024-33182
9.8 CRITICAL

Tenda AC18 V15.03.3.10_EN was discovered to contain a stack-based buffer overflow vulnerability via the deviceId parameter at ip/goform/addWifiMacFilter.

Jul 16, 2024
CVE-2024-33180
9.8 CRITICAL

Tenda AC18 V15.03.3.10_EN was discovered to contain a stack-based buffer overflow vulnerability via the deviceId parameter at ip/goform/saveParentControlInfo.

Jul 16, 2024
CVE-2024-22442
9.8 CRITICAL

The vulnerability could be remotely exploited to bypass authentication.

Jul 16, 2024
CVE-2024-6655
7.0 HIGH

A flaw was found in the GTK library. Under certain conditions, it is possible for a library to be injected into a GTK application from …

Jul 16, 2024
CVE-2024-32861
7.8 HIGH

Under certain circumstances the impacted Software House C•CURE 9000 installer will utilize unnecessarily wide permissions.

Jul 16, 2024
CVE-2022-45449
6.5 MEDIUM

Sensitive information disclosure due to excessive privileges assigned to Acronis Agent. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 30984.

Jul 16, 2024
CVE-2024-6435
8.8 HIGH

A privilege escalation vulnerability exists in the affected products which could allow a malicious user with basic privileges to access functions which should only be …

Jul 16, 2024
CVE-2022-48866
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: HID: hid-thrustmaster: fix OOB read in thrustmaster_interrupts Syzbot reported an slab-out-of-bounds Read in thrustmaster_probe() bug. …

Jul 16, 2024
CVE-2022-48865
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tipc: fix kernel panic when enabling bearer When enabling a bearer on a node, a …

Jul 16, 2024
CVE-2022-48864
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: vdpa/mlx5: add validation for VIRTIO_NET_CTRL_MQ_VQ_PAIRS_SET command When control vq receives a VIRTIO_NET_CTRL_MQ_VQ_PAIRS_SET command request from …

Jul 16, 2024
CVE-2022-48863
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mISDN: Fix memory leak in dsp_pipeline_build() dsp_pipeline_build() allocates dup pointer by kstrdup(cfg), but then it …

Jul 16, 2024
CVE-2022-48862
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: vhost: fix hung thread due to erroneous iotlb entries In vhost_iotlb_add_range_ctx(), range size can overflow …

Jul 16, 2024
CVE-2022-48861
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: vdpa: fix use-after-free on vp_vdpa_remove When vp_vdpa driver is unbind, vp_vdpa is freed in vdpa_unregister_device …

Jul 16, 2024
CVE-2022-48860
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ethernet: Fix error handling in xemaclite_of_probe This node pointer is returned by of_parse_phandle() with refcount …

Jul 16, 2024
CVE-2022-48859
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: marvell: prestera: Add missing of_node_put() in prestera_switch_set_base_mac_addr This node pointer is returned by of_find_compatible_node() …

Jul 16, 2024
CVE-2022-48858
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix a race on command flush flow Fix a refcount use after free warning …

Jul 16, 2024
CVE-2022-48857
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: NFC: port100: fix use-after-free in port100_send_complete Syzbot reported UAF in port100_send_complete(). The root case is …

Jul 16, 2024
CVE-2022-48856
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: gianfar: ethtool: Fix refcount leak in gfar_get_ts_info The of_find_compatible_node() function returns a node pointer with …

Jul 16, 2024
CVE-2022-48855
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: sctp: fix kernel-infoleak for SCTP sockets syzbot reported a kernel infoleak [1] of 4 bytes. …

Jul 16, 2024
CVE-2022-48854
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: arc_emac: Fix use after free in arc_mdio_probe() If bus->state is equal to MDIOBUS_ALLOCATED, mdiobus_free(bus) …

Jul 16, 2024
CVE-2022-48853
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: swiotlb: fix info leak with DMA_FROM_DEVICE The problem I'm addressing was discovered by the LTP …

Jul 16, 2024
CVE-2022-48852
3.3 LOW

In the Linux kernel, the following vulnerability has been resolved: drm/vc4: hdmi: Unregister codec device on unbind On bind we will register the HDMI codec …

Jul 16, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.