CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-37643
8.8 HIGH

TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a stack overflow vulnerability via the submit-url parameter at /formPasswordAuth .

Jun 14, 2024
CVE-2024-37642
9.1 CRITICAL

TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a command injection vulnerability via the ipv4_ping, ipv6_ping parameter at /formSystemCheck .

Jun 14, 2024
CVE-2024-37641
8.8 HIGH

TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a stack overflow via the submit-url parameter at /formNewSchedule

Jun 14, 2024
CVE-2024-37317
4.6 MEDIUM

The Nextcloud Notes app is a distraction free notes taking app for Nextcloud. If an attacker managed to share a folder called `Notes/` with a …

Jun 14, 2024
CVE-2024-37316
4.6 MEDIUM

Nextcloud Calendar is a calendar app for Nextcloud. Authenticated users could create an event with manipulated attachment data leading to a bad redirect for participants …

Jun 14, 2024
CVE-2024-37315
3.5 LOW

Nextcloud Server is a self hosted personal cloud system. An attacker with read-only access to a file is able to restore older versions of a …

Jun 14, 2024
CVE-2024-33373
6.3 MEDIUM

An issue in the LB-LINK BL-W1210M v2.0 router allows attackers to bypass password complexity requirements and set single digit passwords for authentication. This vulnerability can …

Jun 14, 2024
CVE-2024-37644
8.8 HIGH

TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in as root.

Jun 14, 2024
CVE-2024-37368
7.5 HIGH

A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE. The vulnerability allows a user from a remote system with FTView to send …

Jun 14, 2024
CVE-2024-37367
7.5 HIGH

A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE v12. The vulnerability allows a user from a remote system with FTView to …

Jun 14, 2024
CVE-2024-37314
3.5 LOW

Nextcloud Photos is a photo management app. Users can remove photos from the album of registered users. It is recommended that the Nextcloud Server is …

Jun 14, 2024
CVE-2024-37313
7.3 HIGH

Nextcloud server is a self hosted personal cloud system. Under some circumstance it was possible to bypass the second factor of 2FA after successfully providing …

Jun 14, 2024
CVE-2024-37312
6.3 MEDIUM

user_oidc app is an OpenID Connect user backend for Nextcloud. Missing access control on the ID4me endpoint allows an attacker to register an account eventually …

Jun 14, 2024
CVE-2024-36656
6.1 MEDIUM

In MintHCM 4.0.3, a registered user can execute arbitrary JavaScript code and achieve a reflected Cross-site Scripting (XSS) attack.

Jun 14, 2024
CVE-2024-34694
8.1 HIGH

LNbits is a Lightning wallet and accounts system. Paying invoices in Eclair that do not get settled within the internal timeout (about 30s) lead to …

Jun 14, 2024
CVE-2024-34539
9.4 CRITICAL

Hardcoded credentials in TerraMaster TOS firmware through 5.1 allow a remote attacker to successfully login to the mail or webmail server. These credentials can also …

Jun 14, 2024
CVE-2024-33377
8.1 HIGH

LB-LINK BL-W1210M v2.0 was discovered to contain a clickjacking vulnerability via the Administrator login page. Attackers can cause victim users to perform arbitrary operations via …

Jun 14, 2024
CVE-2024-33375
9.8 CRITICAL

LB-LINK BL-W1210M v2.0 was discovered to store user credentials in plaintext within the router's firmware.

Jun 14, 2024
CVE-2024-33374
9.8 CRITICAL

Incorrect access control in the UART/Serial interface on the LB-LINK BL-W1210M v2.0 router allows attackers to access the root terminal without authentication.

Jun 14, 2024
CVE-2024-23442
6.1 MEDIUM

An open redirect issue was discovered in Kibana that could lead to a user being redirected to an arbitrary website if they use a maliciously …

Jun 14, 2024
CVE-2024-5731
6.8 MEDIUM

A vulnerability in the IPS Manager, Central Manager, and Local Manager communication workflow allows an attacker to control the destination of a request by manipulating …

Jun 14, 2024
CVE-2024-5671
9.8 CRITICAL

Insecure Deserialization in some workflows of the IPS Manager allows unauthenticated remote attackers to perform arbitrary code execution and access to the vulnerable Trellix IPS …

Jun 14, 2024
CVE-2024-37640
8.8 HIGH

TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid5g in the function setWiFiEasyGuestCfg.

Jun 14, 2024
CVE-2024-37639
8.8 HIGH

TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via eport in the function setIpPortFilterRules.

Jun 14, 2024
CVE-2024-37637
9.8 CRITICAL

TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid5g in the function setWizardCfg.

Jun 14, 2024
CVE-2024-2024
8.8 HIGH

The Folders Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'handle_folders_file_upload' function in all versions …

Jun 14, 2024
CVE-2024-2023
4.3 MEDIUM

The Folders and Folders Pro plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.0 in Folders and 3.0.2 …

Jun 14, 2024
CVE-2024-36459

A CRLF cross-site scripting vulnerability has been identified in certain configurations of the SiteMinder Web Agent for IIS Web Server and SiteMinder Web Agent for …

Jun 14, 2024
CVE-2023-51376
4.3 MEDIUM

Missing Authorization vulnerability in Brainstorm Force ProjectHuddle Client Site.This issue affects ProjectHuddle Client Site: from n/a through 1.0.34.

Jun 14, 2024
CVE-2024-5685
7.6 HIGH

Users with "User:edit" and "Self:api" permissions can promote or demote themselves or other users by performing changes to the group's memberships via API call.This issue …

Jun 14, 2024
CVE-2024-3912
9.8 CRITICAL

Certain models of ASUS routers have an arbitrary firmware upload vulnerability. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands on …

Jun 14, 2024
CVE-2024-34012
4.4 MEDIUM

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cloud Manager (Windows) before build 6.2.24135.272.

Jun 14, 2024
CVE-2024-2472
9.1 CRITICAL

The LatePoint Plugin plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the …

Jun 14, 2024
CVE-2024-5996

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 14, 2024
CVE-2024-4863
6.4 MEDIUM

The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘titleFont’ parameter …

Jun 14, 2024
CVE-2024-37182
4.7 MEDIUM

Mattermost Desktop App versions <=5.7.0 fail to correctly prompt for permission when opening external URLs which allows a remote attacker to force a victim over …

Jun 14, 2024
CVE-2024-36287
3.8 LOW

Mattermost Desktop App versions <=5.7.0 fail to disable certain Electron debug flags which allows for bypassing TCC restrictions on macOS.

Jun 14, 2024
CVE-2024-25142
5.5 MEDIUM

Use of Web Browser Cache Containing Sensitive Information vulnerability in Apache Airflow. Airflow did not return "Cache-Control" header for dynamic content, which in case of …

Jun 14, 2024
CVE-2024-5995
8.8 HIGH

The notification emails sent by Soar Cloud HR Portal contain a link with a embedded session. The expiration of the session is not properly configured, …

Jun 14, 2024
CVE-2024-5961

Improper neutralization of input during web page generation vulnerability in 2ClickPortal software allows reflected cross-site scripting (XSS). An attacker might trick somebody into using a …

Jun 14, 2024
CVE-2024-5577
9.8 CRITICAL

The Where I Was, Where I Will Be plugin for WordPress is vulnerable to Remote File Inclusion in version <= 1.1.1 via the WIW_HEADER parameter …

Jun 14, 2024
CVE-2024-5465
5.9 MEDIUM

Function vulnerabilities in the Calendar module Impact: Successful exploitation of this vulnerability will affect availability.

Jun 14, 2024
CVE-2024-5464
4.0 MEDIUM

Vulnerability of insufficient permission verification in the NearLink module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jun 14, 2024
CVE-2024-36503
7.3 HIGH

Memory management vulnerability in the Gralloc module Impact: Successful exploitation of this vulnerability will affect availability.

Jun 14, 2024
CVE-2024-36502
7.9 HIGH

Out-of-bounds read vulnerability in the audio module Impact: Successful exploitation of this vulnerability will affect availability.

Jun 14, 2024
CVE-2024-36501
5.6 MEDIUM

Memory management vulnerability in the boottime module Impact: Successful exploitation of this vulnerability can affect integrity.

Jun 14, 2024
CVE-2024-36500
7.8 HIGH

Privilege escalation vulnerability in the AMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jun 14, 2024
CVE-2024-36499
6.8 MEDIUM

Vulnerability of unauthorized screenshot capturing in the WMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jun 14, 2024
CVE-2024-5994
6.4 MEDIUM

The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom JS option in versions up to, …

Jun 14, 2024
CVE-2024-31163
7.2 HIGH

ASUS Download Master has a buffer overflow vulnerability. An unauthenticated remote attacker with administrative privileges can exploit this vulnerability to execute arbitrary system commands on …

Jun 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.