CVE Database

122268+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-34201
7.3 HIGH

TOTOLINK CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the getSaveConfig function.

May 14, 2024
CVE-2024-34200
8.8 HIGH

TOTOLINK CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a stack buffer overflow vulnerability in the setIpQosRules function.

May 14, 2024
CVE-2024-34199
8.6 HIGH

TinyWeb 1.94 and below allows unauthenticated remote attackers to cause a denial of service (Buffer Overflow) when sending excessively large elements in the request line.

May 14, 2024
CVE-2024-34196
8.8 HIGH

Totolink AC1200 Wireless Dual Band Gigabit Router A3002RU_V3 Firmware V3.0.0-B20230809.1615 is vulnerable to Buffer Overflow. The "boa" program allows attackers to modify the value of …

May 14, 2024
CVE-2024-34081
6.6 MEDIUM

MantisBT (Mantis Bug Tracker) is an open source issue tracker. Improper escaping of a custom field's name allows an attacker to inject HTML and, if …

May 14, 2024
CVE-2024-34080
5.3 MEDIUM

MantisBT (Mantis Bug Tracker) is an open source issue tracker. If an issue references a note that belongs to another issue that the user doesn't …

May 14, 2024
CVE-2024-34079
3.7 LOW

octo-sts is a GitHub App that acts like a Security Token Service (STS) for the Github API. This vulnerability can spike the resource utilization of …

May 14, 2024
CVE-2024-34077
7.3 HIGH

MantisBT (Mantis Bug Tracker) is an open source issue tracker. Insufficient access control in the registration and password reset process allows an attacker to reset …

May 14, 2024
CVE-2024-34074
6.1 MEDIUM

Frappe is a full-stack web application framework. Prior to 15.26.0 and 14.74.0, the login page accepts redirect argument and it allowed redirect to untrusted external …

May 14, 2024
CVE-2024-34070
9.6 CRITICAL

Froxlor is open source server administration software. Prior to 2.1.9, a Stored Blind Cross-Site Scripting (XSS) vulnerability was identified in the Failed Login Attempts Logging …

May 14, 2024
CVE-2024-33956
4.3 MEDIUM

Missing Authorization vulnerability in ThemeLocation Custom WooCommerce Checkout Fields Editor.This issue affects Custom WooCommerce Checkout Fields Editor: from n/a through 1.3.0.

May 14, 2024
CVE-2024-33955
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Theme Freesia Freesia Empire allows Stored XSS.This issue affects Freesia Empire: from n/a …

May 14, 2024
CVE-2024-33954
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Atanas Yonkov Pliska allows Stored XSS.This issue affects Pliska: from n/a through 0.3.5.

May 14, 2024
CVE-2024-33953
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matt van Andel Adventure Journal allows Stored XSS.This issue affects Adventure Journal: from …

May 14, 2024
CVE-2024-33952
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Tadlock Unique allows Stored XSS.This issue affects Unique: from n/a through 0.3.0.

May 14, 2024
CVE-2024-33951
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Adam DeHaven Perfect Pullquotes allows Stored XSS.This issue affects Perfect Pullquotes: from n/a …

May 14, 2024
CVE-2024-33950
5.9 MEDIUM

Administrator Cross Site Scripting (XSS) in Archives Calendar Widget <= 1.0.15 versions.

May 14, 2024
CVE-2024-33942
4.3 MEDIUM

Missing Authorization vulnerability in Eric Alli Google Typography.This issue affects Google Typography: from n/a through 1.1.2.

May 14, 2024
CVE-2024-33938
6.5 MEDIUM

Missing Authorization vulnerability in codename065 Sliding Widgets allows Cross-Site Scripting (XSS).This issue affects Sliding Widgets: from n/a through 1.5.0.

May 14, 2024
CVE-2024-33878

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not …

May 14, 2024
CVE-2024-33877
8.8 HIGH

HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5T__conv_struct_opt in H5Tconv.c.

May 14, 2024
CVE-2024-33876
5.7 MEDIUM

HDF5 Library through 1.14.3 has a heap buffer overflow in H5S__point_deserialize in H5Spoint.c.

May 14, 2024
CVE-2024-33875
5.7 MEDIUM

HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5O__layout_encode in H5Olayout.c, resulting in the corruption of the instruction pointer.

May 14, 2024
CVE-2024-33874
9.8 CRITICAL

HDF5 Library through 1.14.3 has a heap buffer overflow in H5O__mtime_new_encode in H5Omtime.c.

May 14, 2024
CVE-2024-33873
8.8 HIGH

HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5D__scatter_mem in H5Dscatgath.c.

May 14, 2024
CVE-2024-33819
4.6 MEDIUM

Globitel KSA SpeechLog v8.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Save Query function.

May 14, 2024
CVE-2024-33818
7.5 HIGH

Globitel KSA SpeechLog v8.1 was discovered to contain an Insecure Direct Object Reference (IDOR) via the userID parameter.

May 14, 2024
CVE-2024-33774
6.5 MEDIUM

A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via formWlanSetup_Wizard allows remote authenticated users to trigger a denial of service (DoS) through …

May 14, 2024
CVE-2024-33773
6.5 MEDIUM

A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via formWlanGuestSetup allows remote authenticated users to trigger a denial of service (DoS) through …

May 14, 2024
CVE-2024-33772
5.7 MEDIUM

A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via formTcpipSetup allows remote authenticated users to trigger a denial of service (DoS) through …

May 14, 2024
CVE-2024-33771
6.5 MEDIUM

A buffer overflow vulnerability in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 via goform/formWPS, allows remote authenticated users to trigger a denial of service (DoS) through …

May 14, 2024
CVE-2024-33454
6.5 MEDIUM

Buffer Overflow vulnerability in esp-idf v.5.1 allows a remote attacker to execute arbitrary code via a crafted script to the Bluetooth stack component.

May 14, 2024
CVE-2024-33433
4.8 MEDIUM

Cross Site Scripting vulnerability in TOTOLINK X2000R before v1.0.0-B20231213.1013 allows a remote attacker to execute arbitrary code via the Guest Access Control parameter in the …

May 14, 2024
CVE-2024-33386

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not …

May 14, 2024
CVE-2024-33263
4.0 MEDIUM

QuickJS commit 3b45d15 was discovered to contain an Assertion Failure via JS_FreeRuntime(JSRuntime *) at quickjs.c.

May 14, 2024
CVE-2024-33250
7.2 HIGH

An issue in Open-Source Technology Committee SRS real-time video server RS/4.0.268(Leo) and SRS/4.0.195(Leo) allows a remote attacker to execute arbitrary code via a crafted request.

May 14, 2024
CVE-2024-32999
6.8 MEDIUM

Cracking vulnerability in the OS security module Impact: Successful exploitation of this vulnerability will affect availability.

May 14, 2024
CVE-2024-32998
5.9 MEDIUM

NULL pointer access vulnerability in the clock module Impact: Successful exploitation of this vulnerability will affect availability.

May 14, 2024
CVE-2024-32997
8.4 HIGH

Race condition vulnerability in the binder driver module Impact: Successful exploitation of this vulnerability will affect availability.

May 14, 2024
CVE-2024-32996
6.2 MEDIUM

Privilege escalation vulnerability in the account module Impact: Successful exploitation of this vulnerability will affect availability.

May 14, 2024
CVE-2024-32995
6.2 MEDIUM

Denial of service (DoS) vulnerability in the AMS module Impact: Successful exploitation of this vulnerability will affect availability.

May 14, 2024
CVE-2024-32993
5.6 MEDIUM

Out-of-bounds access vulnerability in the memory module Impact: Successful exploitation of this vulnerability will affect availability.

May 14, 2024
CVE-2024-32992
7.5 HIGH

Insufficient verification vulnerability in the baseband module Impact: Successful exploitation of this vulnerability will affect availability.

May 14, 2024
CVE-2024-32991
7.5 HIGH

Permission verification vulnerability in the wpa_supplicant module Impact: Successful exploitation of this vulnerability will affect availability.

May 14, 2024
CVE-2024-32990
6.1 MEDIUM

Permission verification vulnerability in the system sharing pop-up module Impact: Successful exploitation of this vulnerability will affect availability.

May 14, 2024
CVE-2024-32989
3.3 LOW

Insufficient verification vulnerability in the system sharing pop-up module Impact: Successful exploitation of this vulnerability will affect availability.

May 14, 2024
CVE-2024-32985
5.9 MEDIUM

Stellar-core is a reference implementation for the peer-to-peer agent that manages the Stellar network. Prior to 20.4.0, core nodes could be randomly crashed due to …

May 14, 2024
CVE-2024-32964
9.0 CRITICAL

Lobe Chat is a chatbot framework that supports speech synthesis, multimodal, and extensible Function Call plugin system. Prior to 0.150.6, lobe-chat had an unauthorized Server-Side …

May 14, 2024
CVE-2024-32874
6.8 MEDIUM

Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Below 0.13.2 Release, when uploading a file or retrieving the …

May 14, 2024
CVE-2024-32776
6.5 MEDIUM

Missing Authorization vulnerability in AppPresser Team AppPresser.This issue affects AppPresser: from n/a through 4.3.0.

May 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.