CVE Database

122268+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-28060
7.3 HIGH

An issue was discovered in Apiris Kafeo 6.4.4. It permits DLL hijacking, allowing a user to trigger the execution of arbitrary code every time the …

May 28, 2024
CVE-2023-46694
8.1 HIGH

Vtenext 21.02 allows an authenticated attacker to upload arbitrary files, potentially enabling them to execute remote commands. This flaw exists due to the application's failure …

May 28, 2024
CVE-2023-30313
7.5 HIGH

An issue discovered in Wavlink QUANTUM D2G routers allows attackers to hijack TCP sessions which could lead to a denial of service.

May 28, 2024
CVE-2023-30310
7.5 HIGH

An issue discovered in Comfast Comfast CF-616AC routers allows attackers to hijack TCP sessions which could lead to a denial of service.

May 28, 2024
CVE-2023-30309
5.7 MEDIUM

An issue discovered in D-Link DI-7003GV2 routers allows attackers to hijack TCP sessions which could lead to a denial of service.

May 28, 2024
CVE-2023-30308
6.5 MEDIUM

An issue discovered in Ruijie EG210G-P, Ruijie EG105G-V2, Ruijie NBR, and Ruijie EG105G routers allows attackers to hijack TCP sessions which could lead to a …

May 28, 2024
CVE-2023-30307
5.3 MEDIUM

An issue discovered in TP-LINK TL-R473GP-AC, TP-LINK XDR6020, TP-LINK TL-R479GP-AC, TP-LINK TL-R4239G, TP-LINK TL-WAR1200L, and TP-LINK TL-R476G routers allows attackers to hijack TCP sessions which …

May 28, 2024
CVE-2023-30306
4.3 MEDIUM

An issue discovered in Mercury x30g, Mercury YR1800XG routers allows attackers to hijack TCP sessions which could lead to a denial of service.

May 28, 2024
CVE-2022-45171
8.8 HIGH

An issue was discovered in LIVEBOX Collaboration vDesk through v018. An Unrestricted Upload of a File with a Dangerous Type can occur under the vShare …

May 28, 2024
CVE-2024-5434

The Campbell Scientific CSI Web Server stores web authentication credentials in a file with a specific file name. Passwords within that file are stored in …

May 28, 2024
CVE-2024-5433

The Campbell Scientific CSI Web Server supports a command that will return the most recent file that matches a given expression. A specially crafted expression …

May 28, 2024
CVE-2024-36110
8.2 HIGH

ansibleguy-webui is an open source WebUI for using Ansible. Multiple forms in versions < 0.0.21 allowed injection of HTML elements. These are returned to the …

May 28, 2024
CVE-2024-36109
7.6 HIGH

CoCalc is web-based software that enables collaboration in research, teaching, and scientific publishing. In affected versions the markdown parser allows `<script>` tags to be included …

May 28, 2024
CVE-2024-36107
5.3 MEDIUM

MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. `If-Modified-Since` and `If-Unmodified-Since` headers when used with anonymous requests by …

May 28, 2024
CVE-2024-33450
7.5 HIGH

SQL Injection in Finereport v.8.0 allows a remote attacker to obtain sensitive information

May 28, 2024
CVE-2024-24919
8.6 HIGH KEV

Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or …

May 28, 2024
CVE-2023-43850
6.5 MEDIUM

Improper input validation in the user management function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows remote authenticated users to cause a partial …

May 28, 2024
CVE-2023-43849
6.5 MEDIUM

Incorrect access control in firmware upgrade function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows remote authenticated users to submit a firmware image …

May 28, 2024
CVE-2023-43848
8.0 HIGH

Incorrect access control in the firewall management function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows remote authenticated users to alter local firewall …

May 28, 2024
CVE-2023-43847
5.3 MEDIUM

Incorrect access control in the outlet control function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows remote authenticated users to control all the …

May 28, 2024
CVE-2023-43846
5.3 MEDIUM

Incorrect access control in logs management function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows remote attackers to get the device logs via …

May 28, 2024
CVE-2023-43845
9.8 CRITICAL

Aten PE6208 2.3.228 and 2.4.232 have default credentials for the privileged telnet account. The user is not asked to change the credentials after first login. …

May 28, 2024
CVE-2023-43844
8.0 HIGH

Aten PE6208 2.3.228 and 2.4.232 have default credentials for the privileged web interface account. The user is not asked to change the credentials after first …

May 28, 2024
CVE-2023-43843
7.3 HIGH

Incorrect access control in the account management function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows remote authenticated users to read user and …

May 28, 2024
CVE-2023-43842
7.3 HIGH

Incorrect access control in the account management function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows remote authenticated users to alter user and …

May 28, 2024
CVE-2023-30311
7.5 HIGH

An issue discovered in H3C Magic R365 and H3C Magic R100 routers allows attackers to hijack TCP sessions which could lead to a denial of …

May 28, 2024
CVE-2023-30305
7.5 HIGH

An issue discovered in Linksys E5600 routers allows attackers to hijack TCP sessions which could lead to a denial of service.

May 28, 2024
CVE-2024-33402
8.1 HIGH

A SQL injection vulnerability in /model/approve_petty_cash.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the id parameter.

May 28, 2024
CVE-2024-35563
9.8 CRITICAL

CDG-Server-V5.6.2.126.139 and earlier was discovered to contain a SQL injection vulnerability via the permissionId parameter in CDGTempPermissions.

May 28, 2024
CVE-2024-35403
2.7 LOW

TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a stack overflow via the desc parameter in the function setIpPortFilterRules

May 28, 2024
CVE-2024-35401
5.9 MEDIUM

TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFile function.

May 28, 2024
CVE-2024-35344
9.9 CRITICAL

Certain Anpviz products contain a hardcoded cryptographic key stored in the firmware of the device. This affects IPC-D250, IPC-D260, IPC-B850, IPC-D850, IPC-D350, IPC-D3150, IPC-D4250, IPC-D380, …

May 28, 2024
CVE-2024-35343
9.8 CRITICAL

Certain Anpviz products allow unauthenticated users to download arbitrary files from the device's filesystem via a HTTP GET request to the /playback/ URI. This affects …

May 28, 2024
CVE-2024-35342
4.6 MEDIUM

Certain Anpviz products allow unauthenticated users to modify or disable camera related settings such as microphone volume, speaker volume, LED lighting, NTP, motion detection, etc. …

May 28, 2024
CVE-2024-35341
7.5 HIGH

Certain Anpviz products allow unauthenticated users to download the running configuration of the device via a HTTP GET request to /ConfigFile.ini or /config.xml URIs. This …

May 28, 2024
CVE-2024-34854
9.8 CRITICAL

F-logic DataCube3 v1.0 is vulnerable to File Upload via `/admin/transceiver_schedule.php.`

May 28, 2024
CVE-2024-34852
6.3 MEDIUM

F-logic DataCube3 v1.0 is affected by command injection due to improper string filtering at the command execution point in the ./admin/transceiver_schedule.php file. An unauthenticated remote …

May 28, 2024
CVE-2024-30165
7.1 HIGH

Amazon AWS Client VPN before 3.9.1 on macOS has a buffer overflow that could potentially allow a local actor to execute arbitrary commands with elevated …

May 28, 2024
CVE-2024-30164
6.7 MEDIUM

Amazon AWS Client VPN has a buffer overflow that could potentially allow a local actor to execute arbitrary commands with elevated permissions. This is resolved …

May 28, 2024
CVE-2024-26024
8.4 HIGH

SUBNET Solutions Inc. has identified vulnerabilities in third-party components used in Substation Server.

May 28, 2024
CVE-2024-36472
6.5 MEDIUM

In GNOME Shell through 45.7, a portal helper can be launched automatically (without user confirmation) based on network responses provided by an adversary (e.g., an …

May 28, 2024
CVE-2024-35621
4.8 MEDIUM

A cross-site scripting (XSS) vulnerability in the Edit function of Formwork before 1.13.0 allows attackers to execute arbitrary web scripts or HTML via a crafted …

May 28, 2024
CVE-2024-35324
9.8 CRITICAL

Douchat 4.0.5 suffers from an arbitrary file upload vulnerability via Public/Plugins/webuploader/server/preview.php.

May 28, 2024
CVE-2024-33849
6.5 MEDIUM

ci solution CI-Out-of-Office Manager through 6.0.0.77 uses a Hard-coded Cryptographic Key.

May 28, 2024
CVE-2024-33808
9.8 CRITICAL

A SQL injection vulnerability in /model/get_timetable.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id …

May 28, 2024
CVE-2024-33807
5.4 MEDIUM

A SQL injection vulnerability in /model/get_teacher_timetable.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the grade …

May 28, 2024
CVE-2024-33806
9.8 CRITICAL

A SQL injection vulnerability in /model/get_grade.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id …

May 28, 2024
CVE-2024-33805
9.8 CRITICAL

A SQL injection vulnerability in /model/get_student.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id …

May 28, 2024
CVE-2024-33804
6.3 MEDIUM

A SQL injection vulnerability in /model/get_subject.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id …

May 28, 2024
CVE-2024-33803
5.4 MEDIUM

A SQL injection vulnerability in /model/get_exam.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id …

May 28, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.