CVE Database

122268+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-33407
5.9 MEDIUM

SQL injection vulnerability in /model/delete_record.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the id parameter.

May 6, 2024
CVE-2024-33406
7.3 HIGH

SQL injection vulnerability in /model/delete_student_grade_subject.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the index parameter.

May 6, 2024
CVE-2024-33405
8.6 HIGH

SQL injection vulnerability in add_friends.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the friend_index parameter.

May 6, 2024
CVE-2024-33404
8.3 HIGH

A SQL injection vulnerability in /model/add_student_first_payment.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the index parameter.

May 6, 2024
CVE-2024-33403
9.8 CRITICAL

A SQL injection vulnerability in /model/get_events.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the event_id parameter.

May 6, 2024
CVE-2024-32807
8.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brevo Sendinblue for WooCommerce allows Relative Path Traversal, Manipulating Web Input to …

May 6, 2024
CVE-2024-34471
5.4 MEDIUM

An issue was discovered in HSC Mailinspector 5.2.17-3. A Path Traversal vulnerability (resulting in file deletion) exists in the mliRealtimeEmails.php file. The filename parameter in …

May 6, 2024
CVE-2024-34251
7.5 HIGH

An out-of-bound memory read vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to cause a denial of service via the …

May 6, 2024
CVE-2024-34250
6.2 MEDIUM

A heap buffer overflow vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to cause at least a denial of service …

May 6, 2024
CVE-2024-34246
7.5 HIGH

wasm3 v0.5.0 was discovered to contain an out-of-bound memory read which leads to segmentation fault via the function "main" in wasm3/platforms/app/main.c.

May 6, 2024
CVE-2024-34093
5.3 MEDIUM

An issue was discovered in Archer Platform 6 before 2024.03. There is an X-Forwarded-For Header Bypass vulnerability. An unauthenticated attacker could potentially bypass intended whitelisting …

May 6, 2024
CVE-2024-34092
8.8 HIGH

An issue was discovered in Archer Platform 6 before 2024.04. Authentication was mishandled because lock did not terminate an existing session. 6.14 P3 (6.14.0.3) is …

May 6, 2024
CVE-2024-34091
7.3 HIGH

An issue was discovered in Archer Platform 6 before 2024.04. There is a stored cross-site scripting (XSS) vulnerability. A remote authenticated malicious Archer user could …

May 6, 2024
CVE-2024-34090
7.3 HIGH

An issue was discovered in Archer Platform 6 before 2024.04. There is a stored cross-site scripting (XSS) vulnerability. The login banner in the Archer Control …

May 6, 2024
CVE-2024-34089
7.3 HIGH

An issue was discovered in Archer Platform 6 before 2024.04. There is a stored cross-site scripting (XSS) vulnerability. A remote authenticated malicious Archer user could …

May 6, 2024
CVE-2024-26312
4.3 MEDIUM

Archer Platform 6 before 2024.03 contains a sensitive information disclosure vulnerability. An authenticated attacker could potentially obtain access to sensitive information via a popup warning …

May 6, 2024
CVE-2024-34472
5.5 MEDIUM

An issue was discovered in HSC Mailinspector 5.2.17-3 through v.5.2.18. An authenticated blind SQL injection vulnerability exists in the mliRealtimeEmails.php file. The ordemGrid parameter in …

May 6, 2024
CVE-2024-34470
8.6 HIGH

An issue was discovered in HSC Mailinspector 5.2.17-3 through v.5.2.18. An Unauthenticated Path Traversal vulnerability exists in the /public/loader.php file. The path parameter does not …

May 6, 2024
CVE-2024-34466

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-34467. Reason: This candidate is a reservation duplicate of CVE-2024-34467. Notes: All CVE users should reference …

May 6, 2024
CVE-2024-34252
7.5 HIGH

wasm3 v0.5.0 was discovered to contain a global buffer overflow which leads to segmentation fault via the function "PreserveRegisterIfOccupied" in wasm3/source/m3_compile.c.

May 6, 2024
CVE-2024-34249
9.8 CRITICAL

wasm3 v0.5.0 was discovered to contain a heap buffer overflow which leads to segmentation fault via the function "DeallocateSlot" in wasm3/source/m3_compile.c.

May 6, 2024
CVE-2024-34078
6.1 MEDIUM

html-sanitizer is an allowlist-based HTML cleaner. If using `keep_typographic_whitespace=False` (which is the default), the sanitizer normalizes unicode to the NFKC form at the end. Some …

May 6, 2024
CVE-2024-34069
7.5 HIGH

Werkzeug is a comprehensive WSGI web application library. The debugger in affected versions of Werkzeug can allow an attacker to execute code on a developer's …

May 6, 2024
CVE-2024-34064
5.4 MEDIUM

Jinja is an extensible templating engine. The `xmlattr` filter in affected versions of Jinja accepts keys containing non-attribute characters. XML/HTML attributes cannot contain spaces, `/`, …

May 6, 2024
CVE-2024-33294
9.1 CRITICAL

An issue in Library System using PHP/MySQli with Source Code V1.0 allows a remote attacker to execute arbitrary code via the _FAILE variable in the …

May 6, 2024
CVE-2024-33113
5.3 MEDIUM

D-LINK DIR-845L <=v1.01KRb03 is vulnerable to Information disclosurey via bsc_sms_inbox.php.

May 6, 2024
CVE-2024-33112
7.5 HIGH

D-Link DIR-845L router v1.01KRb03 and before is vulnerable to Command injection via the hnap_main()func.

May 6, 2024
CVE-2024-33111
5.4 MEDIUM

D-Link DIR-845L router <=v1.01KRb03 is vulnerable to Cross Site Scripting (XSS) via /htdocs/webinc/js/bsc_sms_inbox.php.

May 6, 2024
CVE-2024-33110
9.1 CRITICAL

D-Link DIR-845L router v1.01KRb03 and before is vulnerable to Permission Bypass via the getcfg.php component.

May 6, 2024
CVE-2024-32982
8.2 HIGH

Litestar and Starlite is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.8.3, 2.7.2, and 2.6.4, a Local File Inclusion (LFI) vulnerability has been …

May 6, 2024
CVE-2024-32972
7.5 HIGH

go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to 1.13.15, a vulnerable node can be made to consume very large …

May 6, 2024
CVE-2024-23354
8.4 HIGH

Memory corruption when the IOCTL call is interrupted by a signal.

May 6, 2024
CVE-2024-23351
8.4 HIGH

Memory corruption as GPU registers beyond the last protected range can be accessed through LPAC submissions.

May 6, 2024
CVE-2024-21480
7.3 HIGH

Memory corruption while playing audio file having large-sized input buffer.

May 6, 2024
CVE-2024-21477
7.5 HIGH

Transient DOS while parsing a protected 802.11az Fine Time Measurement (FTM) frame.

May 6, 2024
CVE-2024-21476
7.8 HIGH

Memory corruption when the channel ID passed by user is not validated and further used.

May 6, 2024
CVE-2024-21475
7.8 HIGH

Memory corruption when the payload received from firmware is not as per the expected protocol size.

May 6, 2024
CVE-2024-21474
8.4 HIGH

Memory corruption when size of buffer from previous call is used without validation or re-initialization.

May 6, 2024
CVE-2024-21471
8.4 HIGH

Memory corruption when IOMMU unmap of a GPU buffer fails in Linux.

May 6, 2024
CVE-2023-43531
8.4 HIGH

Memory corruption while verifying the serialized header when the key pairs are generated.

May 6, 2024
CVE-2023-43530
5.9 MEDIUM

Memory corruption in HLOS while checking for the storage type.

May 6, 2024
CVE-2023-43529
7.5 HIGH

Transient DOS while processing IKEv2 Informational request messages, when a malformed fragment packet is received.

May 6, 2024
CVE-2023-43528
6.1 MEDIUM

Information disclosure when the ADSP payload size received in HLOS in response to Audio Stream Manager matrix session is less than this expected size.

May 6, 2024
CVE-2023-43527
6.8 MEDIUM

Information disclosure while parsing dts header atom in Video.

May 6, 2024
CVE-2023-43526
6.7 MEDIUM

Memory corruption while querying module parameters from Listen Sound model client in kernel from user space.

May 6, 2024
CVE-2023-43525
6.7 MEDIUM

Memory corruption while copying the sound model data from user to kernel buffer during sound model register.

May 6, 2024
CVE-2023-43524
6.7 MEDIUM

Memory corruption when the bandpass filter order received from AHAL is not within the expected range.

May 6, 2024
CVE-2023-43521
6.7 MEDIUM

Memory corruption when multiple listeners are being registered with the same file descriptor.

May 6, 2024
CVE-2023-33119
8.4 HIGH

Memory corruption while loading a VM from a signed VM image that is not coherent in the processor cache.

May 6, 2024
CVE-2024-4549
7.5 HIGH

A denial of service vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior. When processing an 'ICS Restart!' message, CEBC.exe restarts the system.

May 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.