CVE Database

122268+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-33155
9.8 CRITICAL

J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the getDeptList() function.

May 7, 2024
CVE-2024-33153
9.8 CRITICAL

J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the commentList() function.

May 7, 2024
CVE-2024-33149
8.1 HIGH

J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the myProcessList function.

May 7, 2024
CVE-2024-33148
7.3 HIGH

J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the list function.

May 7, 2024
CVE-2024-33147
8.8 HIGH

J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the authRoleList function.

May 7, 2024
CVE-2024-29210
2.8 LOW

A local privilege escalation (LPE) vulnerability has been identified in Phish Alert Button for Outlook (PAB), specifically within its configuration management functionalities. This vulnerability allows …

May 7, 2024
CVE-2024-29209
6.0 MEDIUM

A medium severity vulnerability has been identified in the update mechanism of the Phish Alert Button for Outlook, which could allow an attacker to remotely …

May 7, 2024
CVE-2024-29208
2.2 LOW

An Unverified Password Change could allow a malicious actor with API access to the device to change the system password without knowing the previous password. …

May 7, 2024
CVE-2024-29207
7.5 HIGH

An Improper Certificate Validation could allow a malicious actor with access to an adjacent network to take control of the system. Affected Products: UniFi Connect …

May 7, 2024
CVE-2024-29206
2.2 LOW

An Improper Access Control could allow a malicious actor authenticated in the API to enable Android Debug Bridge (ADB) and make unsupported changes to the …

May 7, 2024
CVE-2024-29150
8.8 HIGH

An issue was discovered in Alcatel-Lucent ALE NOE deskphones through 86x8_NOE-R300.1.40.12.4180 and SIP deskphones through 86x8_SIP-R200.1.01.10.728. Because of improper privilege management, an authenticated attacker is …

May 7, 2024
CVE-2024-29149
7.4 HIGH

An issue was discovered in Alcatel-Lucent ALE NOE deskphones through 86x8_NOE-R300.1.40.12.4180 and SIP deskphones through 86x8_SIP-R200.1.01.10.728. Because of a time-of-check time-of-use vulnerability, an authenticated attacker …

May 7, 2024
CVE-2024-27982
6.5 MEDIUM

The team has identified a critical vulnerability in the http server of the most recent version of Node, where malformed headers can lead to HTTP …

May 7, 2024
CVE-2022-37249

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not …

May 7, 2024
CVE-2024-4596
3.7 LOW

A vulnerability was found in Kimai up to 2.15.0 and classified as problematic. Affected by this issue is some unknown functionality of the component Session …

May 7, 2024
CVE-2024-34341
5.4 MEDIUM

Trix is a rich text editor. The Trix editor, versions prior to 2.1.1, is vulnerable to arbitrary code execution when copying and pasting content from …

May 7, 2024
CVE-2024-33858
5.3 MEDIUM

An issue was discovered in Logpoint before 7.4.0. A path injection vulnerability is seen while adding a CSV enrichment source. The source_name parameter could be …

May 7, 2024
CVE-2024-33857
9.6 CRITICAL

An issue was discovered in Logpoint before 7.4.0. Due to a lack of input validation on URLs in threat intelligence, an attacker with low-level access …

May 7, 2024
CVE-2024-33856
5.3 MEDIUM

An issue was discovered in Logpoint before 7.4.0. An attacker can enumerate a valid list of usernames by observing the response time at the Forgot …

May 7, 2024
CVE-2024-33748
4.1 MEDIUM

Cross-site scripting (XSS) vulnerability in the search function in Maven net.mingsoft MS Basic 2.1.13.4 and earlier.

May 7, 2024
CVE-2024-33146
9.1 CRITICAL

J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the export function.

May 7, 2024
CVE-2024-33144
8.8 HIGH

J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the findApplyedTasksPage function in BpmTaskMapper.xml.

May 7, 2024
CVE-2024-33139
7.5 HIGH

J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the findpage function.

May 7, 2024
CVE-2024-4595
6.3 MEDIUM

A vulnerability has been found in SEMCMS up to 4.8 and classified as critical. Affected by this vulnerability is the function locate of the file …

May 7, 2024
CVE-2024-4594
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in DedeCMS 5.7. Affected is an unknown function of the file /src/dede/sys_safe.php. The manipulation leads to …

May 7, 2024
CVE-2024-34523
7.5 HIGH

AChecker 1.5 allows remote attackers to read the contents of arbitrary files via the download.php path parameter by using Unauthenticated Path Traversal. This occurs through …

May 7, 2024
CVE-2024-34342
7.1 HIGH

react-pdf displays PDFs in React apps. If PDF.js is used to load a malicious PDF, and PDF.js is configured with `isEvalSupported` set to `true` (which …

May 7, 2024
CVE-2024-34084
7.5 HIGH

Minder's `HandleGithubWebhook` is susceptible to a denial of service attack from an untrusted HTTP request. The vulnerability exists before the request has been validated, and …

May 7, 2024
CVE-2024-33124
9.8 CRITICAL

Roothub v2.6 was discovered to contain a SQL injection vulnerability via the nodeTitle parameter in the parentNode() function..

May 7, 2024
CVE-2024-33122
6.3 MEDIUM

Roothub v2.6 was discovered to contain a SQL injection vulnerability via the topic parameter in the list() function.

May 7, 2024
CVE-2024-33120
9.8 CRITICAL

Roothub v2.5 was discovered to contain an arbitrary file upload vulnerability via the customPath parameter in the upload() function. This vulnerability allows attackers to execute …

May 7, 2024
CVE-2024-32867
5.3 MEDIUM

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.5 and 6.0.19, various problems in handling of …

May 7, 2024
CVE-2024-32664
5.3 MEDIUM

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.5 and 6.0.19, specially crafted traffic or datasets …

May 7, 2024
CVE-2024-32663
7.5 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.5 and 6.0.19, a small amount of HTTP/2 …

May 7, 2024
CVE-2024-32371
7.5 HIGH

An issue in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a regular user account to escalate their privileges and gain administrative access by changing …

May 7, 2024
CVE-2024-32370
9.8 CRITICAL

An issue in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a remote attacker to obtain sensitive information via a crafted payload to the id …

May 7, 2024
CVE-2024-32369
4.3 MEDIUM

SQL Injection vulnerability in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a remote attacker to obtain sensitive information via a crafted payload to the …

May 7, 2024
CVE-2024-4593
4.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in DedeCMS 5.7. This issue affects some unknown processing of the file /src/dede/sys_multiserv.php. The manipulation …

May 7, 2024
CVE-2024-4592
4.3 MEDIUM

A vulnerability classified as problematic was found in DedeCMS 5.7. This vulnerability affects unknown code of the file /src/dede/sys_group_edit.php. The manipulation leads to cross-site request …

May 7, 2024
CVE-2024-4591
4.3 MEDIUM

A vulnerability classified as problematic has been found in DedeCMS 5.7. This affects an unknown part of the file /src/dede/sys_group_add.php. The manipulation leads to cross-site …

May 7, 2024
CVE-2024-4590
4.3 MEDIUM

A vulnerability was found in DedeCMS 5.7. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /src/dede/sys_info.php. …

May 7, 2024
CVE-2024-33783
6.5 MEDIUM

MP-SPDZ v0.3.8 was discovered to contain a segmentation violation via the function osuCrypto::SilentMultiPprfReceiver::expand in /Tools/SilentPprf.cpp. This vulnerability allows attackers to cause a Denial of Service …

May 7, 2024
CVE-2024-33782
7.5 HIGH

MP-SPDZ v0.3.8 was discovered to contain a stack overflow via the function OTExtensionWithMatrix::extend in /OT/OTExtensionWithMatrix.cpp. This vulnerability allows attackers to cause a Denial of Service …

May 7, 2024
CVE-2024-33781
7.5 HIGH

MP-SPDZ v0.3.8 was discovered to contain a stack overflow via the function octetStream::get_bytes in /Tools/octetStream.cpp. This vulnerability allows attackers to cause a Denial of Service …

May 7, 2024
CVE-2024-33780
6.5 MEDIUM

MP-SPDZ v0.3.8 was discovered to contain a segmentation violation via the function osuCrypto::copyOut at /Tools/SilentPprf.cpp. This vulnerability allows attackers to cause a Denial of Service …

May 7, 2024
CVE-2024-33434
9.8 CRITICAL

An issue in tiagorlampert CHAOS v5.0.1 before 1b451cf62582295b7225caf5a7b506f0bad56f6b and 24c9e109b5be34df7b2bce8368eae669c481ed5e allows a remote attacker to execute arbitrary code via the unsafe concatenation of the `filename` …

May 7, 2024
CVE-2024-31456
7.7 HIGH

GLPI is a Free Asset and IT Management Software package. Prior to 10.0.15, an authenticated user can exploit a SQL injection vulnerability from map search. …

May 7, 2024
CVE-2024-29889
7.1 HIGH

GLPI is a Free Asset and IT Management Software package. Prior to 10.0.15, an authenticated user can exploit a SQL injection vulnerability in the saved …

May 7, 2024
CVE-2024-28148
4.3 MEDIUM

An authenticated user could potentially access metadata for a datasource they are not authorized to view by submitting a targeted REST API request.This issue affects …

May 7, 2024
CVE-2023-46012
9.8 CRITICAL

Buffer Overflow vulnerability LINKSYS EA7500 3.0.1.207964 allows a remote attacker to execute arbitrary code via an HTTP request to the IGD UPnP.

May 7, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.