CVE Database

122268+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-4548
9.8 CRITICAL

An SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateHDMWYC' message, which is split into 4 fields using the …

May 6, 2024
CVE-2024-4547
9.8 CRITICAL

A SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe processes a 'RecalculateScript' message, which is splitted into 4 fields using the …

May 6, 2024
CVE-2024-33752
6.3 MEDIUM

An arbitrary file upload vulnerability exists in emlog pro 2.3.0 and pro 2.3.2 at admin/views/plugin.php that could be exploited by a remote attacker to submit …

May 6, 2024
CVE-2024-2041

Rejected reason: ***DUPLICATE** Please use CVE-2024-3241 instead.

May 6, 2024
CVE-2024-33830
8.1 HIGH

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/readDeal.php?mudi=clearWebCache.

May 6, 2024
CVE-2024-33829
5.4 MEDIUM

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/readDeal.php?mudi=updateWebCache.

May 6, 2024
CVE-2024-33788
8.0 HIGH

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the PinCode parameter at /API/info form endpoint.

May 6, 2024
CVE-2024-33749
9.1 CRITICAL

DedeCMS V5.7.114 is vulnerable to deletion of any file via mail_file_manage.php.

May 6, 2024
CVE-2024-3576
8.3 HIGH

The NPort 5100A Series firmware version v1.6 and prior versions are affected by web server XSS vulnerability. The vulnerability is caused by not correctly neutralizing …

May 6, 2024
CVE-2024-33753
8.2 HIGH

Section Camera V2.5.5.3116-S50-SMA-B20160811 and earlier versions allow the accounts and passwords of administrators and users to be changed without authorization.

May 6, 2024
CVE-2023-49676
5.5 MEDIUM

An unauthenticated local attacker may trick a user to open corrupted project files to crash the system due to use after free vulnerability.

May 6, 2024
CVE-2023-49675
7.8 HIGH

An unauthenticated local attacker may trick a user to open corrupted project files to execute arbitrary code or crash the system due to an out-of-bounds …

May 6, 2024
CVE-2023-6854
6.4 MEDIUM

The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's custom postmeta output in all versions up to, and including, 1.7.0 …

May 6, 2024
CVE-2024-4528
2.4 LOW

A vulnerability was found in SourceCodester Prison Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of …

May 6, 2024
CVE-2024-23193
5.3 MEDIUM

E-Mails exported as PDF were stored in a cache that did not consider specific session information for the related user account. Users of the same …

May 6, 2024
CVE-2024-23188
6.5 MEDIUM

Maliciously crafted E-Mail attachment names could be used to temporarily execute script code in the context of the users browser session. Common user interaction is …

May 6, 2024
CVE-2024-23187
6.5 MEDIUM

Content-ID based embedding of resources in E-Mails could be abused to trigger client-side script code when using the "show more" option. Attackers could perform malicious …

May 6, 2024
CVE-2024-23186
6.5 MEDIUM

E-Mail containing malicious display-name information could trigger client-side script execution when using specific mobile devices. Attackers could perform malicious API requests or extract information from …

May 6, 2024
CVE-2024-4527
3.5 LOW

A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been classified as problematic. Affected is an unknown function of the …

May 6, 2024
CVE-2024-4526
3.5 LOW

A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file …

May 6, 2024
CVE-2024-4525
3.5 LOW

A vulnerability has been found in Campcodes Complete Web-Based School Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file …

May 6, 2024
CVE-2024-4524
3.5 LOW

A vulnerability, which was classified as problematic, was found in Campcodes Complete Web-Based School Management System 1.0. This affects an unknown part of the file …

May 6, 2024
CVE-2024-3756
7.5 HIGH

The MF Gig Calendar WordPress plugin through 1.2.1 does not have CSRF checks in some places, which could allow attackers to make logged in Contributors …

May 6, 2024
CVE-2024-3755
5.4 MEDIUM

The MF Gig Calendar WordPress plugin through 1.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 6, 2024
CVE-2024-3752
5.4 MEDIUM

The Crelly Slider WordPress plugin through 1.4.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

May 6, 2024
CVE-2024-0904
5.9 MEDIUM

The Fancy Product Designer WordPress plugin before 6.1.81 does not sanitise and escape some of its settings, which could allow high privilege users such as …

May 6, 2024
CVE-2024-4523
3.5 LOW

A vulnerability, which was classified as problematic, has been found in Campcodes Complete Web-Based School Management System 1.0. Affected by this issue is some unknown …

May 6, 2024
CVE-2024-4522
3.5 LOW

A vulnerability classified as problematic was found in Campcodes Complete Web-Based School Management System 1.0. Affected by this vulnerability is an unknown functionality of the …

May 6, 2024
CVE-2024-4521
3.5 LOW

A vulnerability classified as problematic has been found in Campcodes Complete Web-Based School Management System 1.0. Affected is an unknown function of the file /view/teacher_salary_details2.php. …

May 6, 2024
CVE-2024-4519
3.5 LOW

A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of …

May 6, 2024
CVE-2024-4518
3.5 LOW

A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the …

May 6, 2024
CVE-2024-4517
3.5 LOW

A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been classified as problematic. This affects an unknown part of the …

May 6, 2024
CVE-2024-4516
3.5 LOW

A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of …

May 6, 2024
CVE-2024-34538
7.5 HIGH

Mateso PasswordSafe through 8.13.9.26689 has Weak Cryptography.

May 6, 2024
CVE-2024-20064
7.8 HIGH

In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with …

May 6, 2024
CVE-2024-20060
5.9 MEDIUM

In da, there is a possible escalation of privilege due to an incorrect status check. This could lead to local escalation of privilege with System …

May 6, 2024
CVE-2024-20059
6.7 MEDIUM

In da, there is a possible escalation of privilege due to an incorrect status check. This could lead to local escalation of privilege with System …

May 6, 2024
CVE-2024-20058
4.4 MEDIUM

In keyInstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System …

May 6, 2024
CVE-2024-20057
7.2 HIGH

In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

May 6, 2024
CVE-2024-20056
6.7 MEDIUM

In preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilege with System …

May 6, 2024
CVE-2024-20021
6.7 MEDIUM

In atf spm, there is a possible way to remap physical memory to virtual memory due to a logic error. This could lead to local …

May 6, 2024
CVE-2023-32873
6.7 MEDIUM

In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

May 6, 2024
CVE-2023-32871
5.3 MEDIUM

In DA, there is a possible permission bypass due to an incorrect status check. This could lead to local escalation of privilege with no additional …

May 6, 2024
CVE-2024-4515
3.5 LOW

A vulnerability has been found in Campcodes Complete Web-Based School Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality …

May 6, 2024
CVE-2024-4514
3.5 LOW

A vulnerability, which was classified as problematic, was found in Campcodes Complete Web-Based School Management System 1.0. Affected is an unknown function of the file …

May 6, 2024
CVE-2024-4513
3.5 LOW

A vulnerability, which was classified as problematic, has been found in Campcodes Complete Web-Based School Management System 1.0. This issue affects some unknown processing of …

May 6, 2024
CVE-2024-4512
3.5 LOW

A vulnerability classified as problematic was found in SourceCodester Prison Management System 1.0. This vulnerability affects unknown code of the file /Employee/edit-profile.php. The manipulation of …

May 6, 2024
CVE-2024-4511
6.3 MEDIUM

A vulnerability classified as critical has been found in Shanghai Sunfull Automation BACnet Server HMI1002-ARM 2.0.4. This affects an unknown part of the component Message …

May 6, 2024
CVE-2024-4510
4.7 MEDIUM

A vulnerability was found in Ruijie RG-UAC up to 20240428. It has been rated as critical. Affected by this issue is some unknown functionality of …

May 6, 2024
CVE-2024-4509
4.7 MEDIUM

A vulnerability was found in Ruijie RG-UAC up to 20240428. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

May 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.