CVE Database

122268+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-4508
4.7 MEDIUM

A vulnerability was found in Ruijie RG-UAC up to 20240428. It has been classified as critical. Affected is an unknown function of the file /view/IPV6/ipv6StaticRoute/static_route_edit_ipv6.php. …

May 6, 2024
CVE-2024-4507
4.7 MEDIUM

A vulnerability was found in Ruijie RG-UAC up to 20240428 and classified as critical. This issue affects some unknown processing of the file /view/IPV6/ipv6StaticRoute/static_route_add_ipv6.php. The …

May 6, 2024
CVE-2024-34529
4.8 MEDIUM

Nebari through 2024.4.1 prints the temporary Keycloak root password.

May 6, 2024
CVE-2024-34528
7.7 HIGH

WordOps through 3.20.0 has a wo/cli/plugins/stack_pref.py TOCTOU race condition because the conf_path os.open does not use a mode parameter during file creation.

May 6, 2024
CVE-2024-34527
7.5 HIGH

spaces_plugin/app.py in SolidUI 0.4.0 has an unnecessary print statement for an OpenAI key. The printed string might be logged.

May 6, 2024
CVE-2024-34525
5.3 MEDIUM

FileCodeBox 2.0 stores a OneDrive password and AWS key in a cleartext env file.

May 6, 2024
CVE-2024-34524
9.1 CRITICAL

In XLANG OpenAgents through fe73ac4, the allowed_file protection mechanism can be bypassed by using an incorrect file extension for the nature of the file content.

May 6, 2024
CVE-2024-4506
4.7 MEDIUM

A vulnerability has been found in Ruijie RG-UAC up to 20240428 and classified as critical. This vulnerability affects unknown code of the file /view/IPV6/ipv6Addr/ip_addr_edit_commit.php. The …

May 5, 2024
CVE-2024-4505
4.7 MEDIUM

A vulnerability, which was classified as critical, was found in Ruijie RG-UAC up to 20240428. This affects an unknown part of the file /view/IPV6/ipv6Addr/ip_addr_add_commit.php. The …

May 5, 2024
CVE-2024-4504
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in Ruijie RG-UAC up to 20240428. Affected by this issue is some unknown functionality of …

May 5, 2024
CVE-2024-4503
4.7 MEDIUM

A vulnerability classified as critical was found in Ruijie RG-UAC up to 20240428. Affected by this vulnerability is an unknown functionality of the file /view/dhcp/dhcpConfig/dhcp_relay_commit.php. …

May 5, 2024
CVE-2024-4502
4.7 MEDIUM

A vulnerability classified as critical has been found in Ruijie RG-UAC up to 20240428. Affected is an unknown function of the file /view/dhcp/dhcpClient/dhcp_client_commit.php. The manipulation …

May 5, 2024
CVE-2024-34519
6.8 MEDIUM

Avantra Server 24.x before 24.0.7 and 24.1.x before 24.1.1 mishandles the security of dashboards, aka XAN-5367. If a user can create a dashboard with an …

May 5, 2024
CVE-2024-34515
8.8 HIGH

image-optimizer before 1.7.3 allows PHAR deserialization, e.g., the phar:// protocol in arguments to file_exists().

May 5, 2024
CVE-2024-4501
4.7 MEDIUM

A vulnerability was found in Ruijie RG-UAC up to 20240428. It has been rated as critical. This issue affects some unknown processing of the file …

May 5, 2024
CVE-2024-34511

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-1561. Reason: This candidate is a duplicate of CVE-2024-1561. Notes: All CVE users should reference CVE-2024-1561 …

May 5, 2024
CVE-2024-34510
7.5 HIGH

Gradio before 4.20 allows credential leakage on Windows.

May 5, 2024
CVE-2024-34509
5.3 MEDIUM

dcmdata in DCMTK before 3.6.9 has a segmentation fault via an invalid DIMSE message.

May 5, 2024
CVE-2024-34508
4.3 MEDIUM

dcmnet in DCMTK before 3.6.9 has a segmentation fault via an invalid DIMSE message.

May 5, 2024
CVE-2024-34507
7.4 HIGH

An issue was discovered in includes/CommentFormatter/CommentParser.php in MediaWiki before 1.39.7, 1.40.x before 1.40.3, and 1.41.x before 1.41.1. XSS can occur because of mishandling of the …

May 5, 2024
CVE-2024-34506
7.5 HIGH

An issue was discovered in includes/specials/SpecialMovePage.php in MediaWiki before 1.39.7, 1.40.x before 1.40.3, and 1.41.x before 1.41.1. If a user with the necessary rights to …

May 5, 2024
CVE-2024-34502
9.8 CRITICAL

An issue was discovered in WikibaseLexeme in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. Loading Special:MergeLexemes will (attempt to) make an edit …

May 5, 2024
CVE-2024-34500
6.1 MEDIUM

An issue was discovered in the UnlinkedWikibase extension in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. XSS can occur through an interface …

May 5, 2024
CVE-2024-4500
6.3 MEDIUM

A vulnerability was found in SourceCodester Prison Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /Employee/edit-photo.php. …

May 5, 2024
CVE-2024-34474
7.8 HIGH

Clario through 2024-04-11 for Desktop has weak permissions for %PROGRAMDATA%\Clario and tries to load DLLs from there as SYSTEM.

May 5, 2024
CVE-2024-4497
8.8 HIGH

A vulnerability was found in Tenda i21 1.0.0.14(4656). It has been declared as critical. This vulnerability affects the function formexeCommand. The manipulation of the argument …

May 5, 2024
CVE-2024-4496
8.8 HIGH

A vulnerability was found in Tenda i21 1.0.0.14(4656). It has been classified as critical. This affects the function formWifiMacFilterSet. The manipulation of the argument ssidIndex …

May 5, 2024
CVE-2024-4495
8.8 HIGH

A vulnerability was found in Tenda i21 1.0.0.14(4656) and classified as critical. Affected by this issue is the function formWifiMacFilterGet. The manipulation of the argument …

May 5, 2024
CVE-2024-4494
8.8 HIGH

A vulnerability has been found in Tenda i21 1.0.0.14(4656) and classified as critical. Affected by this vulnerability is the function formSetUplinkInfo of the file /goform/setUplinkInfo. …

May 5, 2024
CVE-2024-4493
8.8 HIGH

A vulnerability, which was classified as critical, was found in Tenda i21 1.0.0.14(4656). Affected is the function formSetAutoPing. The manipulation of the argument ping1/ping2 leads …

May 5, 2024
CVE-2024-34490
5.1 MEDIUM

In Maxima through 5.47.0 before 51704c, the plotting facilities make use of predictable names under /tmp. Thus, the contents may be controlled by a local …

May 5, 2024
CVE-2024-34489
7.5 HIGH

OFPHello in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via length=0.

May 5, 2024
CVE-2024-34488
7.5 HIGH

OFPMultipartReply in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via b.length=0.

May 5, 2024
CVE-2024-34487
7.5 HIGH

OFPFlowStats in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via inst.length=0.

May 5, 2024
CVE-2024-34486
7.5 HIGH

OFPPacketQueue in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via OFPQueueProp.len=0.

May 5, 2024
CVE-2024-34484
5.3 MEDIUM

OFPBucket in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via action.len=0.

May 5, 2024
CVE-2024-34483
7.5 HIGH

OFPGroupDescStats in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via OFPBucket.len=0.

May 5, 2024
CVE-2024-4492
8.8 HIGH

A vulnerability, which was classified as critical, has been found in Tenda i21 1.0.0.14(4656). This issue affects the function formOfflineSet of the file /goform/setStaOffline. The …

May 5, 2024
CVE-2024-34478
7.5 HIGH

btcd before 0.24.0 does not correctly implement the consensus rules outlined in BIP 68 and BIP 112, making it susceptible to consensus failures. Specifically, it …

May 5, 2024
CVE-2024-4491
8.8 HIGH

A vulnerability classified as critical was found in Tenda i21 1.0.0.14(4656). This vulnerability affects the function formGetDiagnoseInfo. The manipulation of the argument cmdinput leads to …

May 5, 2024
CVE-2024-34476
5.3 MEDIUM

Open5GS before 2.7.1 is vulnerable to a reachable assertion that can cause an AMF crash via NAS messages from a UE: ogs_nas_encrypt in lib/nas/common/security.c for …

May 5, 2024
CVE-2024-34475
7.5 HIGH

Open5GS before 2.7.1 is vulnerable to a reachable assertion that can cause an AMF crash via NAS messages from a UE: gmm_state_authentication in amf/gmm-sm.c for …

May 5, 2024
CVE-2024-34473
5.3 MEDIUM

An issue was discovered in appmgr in O-RAN Near-RT RIC I-Release. An attacker could register an unintended RMR message type during xApp registration to disrupt …

May 4, 2024
CVE-2023-52729
7.5 HIGH

TCPServer.cpp in SimpleNetwork through 29bc615 has an off-by-one error that causes a buffer overflow when trying to add '\0' to the end of long msg …

May 4, 2024
CVE-2024-34469
7.1 HIGH

Rukovoditel before 3.5.3 allows XSS via user_photo to index.php?module=users/registration&action=save.

May 4, 2024
CVE-2024-34468
6.1 MEDIUM

Rukovoditel before 3.5.3 allows XSS via user_photo to My Page.

May 4, 2024
CVE-2024-34467
6.1 MEDIUM

ThinkPHP 8.0.3 allows remote attackers to exploit XSS due to inadequate filtering of function argument values in think_exception.tpl.

May 4, 2024
CVE-2024-34462
6.1 MEDIUM

Alinto SOGo through 5.10.0 allows XSS during attachment preview.

May 4, 2024
CVE-2023-27283
5.3 MEDIUM

IBM Aspera Orchestrator 4.0.1 could allow a remote attacker to enumerate usernames due to observable response discrepancies. IBM X-Force ID: 248545.

May 4, 2024
CVE-2024-1050
4.3 MEDIUM

The Import and export users and customers plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …

May 4, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.