CVE Database

122268+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-33429
7.1 HIGH

Buffer-Overflow vulnerability at pcm_convert.h:513 of phiola v2.0-rc22 allows a remote attacker to execute arbitrary code via a crafted .wav file.

May 1, 2024
CVE-2024-33428
8.8 HIGH

Buffer-Overflow vulnerability at conv.c:68 of stsaz phiola v2.0-rc22 allows a remote attacker to execute arbitrary code via the a crafted .wav file.

May 1, 2024
CVE-2024-33424
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary web scripts or HTML via a crafted payload …

May 1, 2024
CVE-2024-33393
6.2 MEDIUM

An issue in spidernet-io spiderpool v.0.9.3 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component.

May 1, 2024
CVE-2024-33304
6.1 MEDIUM

SourceCodester Product Show Room 1.0 is vulnerable to Cross Site Scripting (XSS) via "Last Name" under Add Users.

May 1, 2024
CVE-2024-33300
7.3 HIGH

Typora v1.0.0 through v1.7 version (below) Markdown editor has a cross-site scripting (XSS) vulnerability, which allows attackers to execute arbitrary code by uploading Markdown files.

May 1, 2024
CVE-2024-33292
8.2 HIGH

SQL Injection vulnerability in Realisation MGSD v.1.0 allows a remote attacker to obtain sensitive information via the id parameter.

May 1, 2024
CVE-2024-29011
7.5 HIGH

Use of hard-coded password in the GMS ECM endpoint leading to authentication bypass vulnerability. This issue affects GMS: 9.3.4 and earlier versions.

May 1, 2024
CVE-2024-26504
8.8 HIGH

An issue in Wifire Hotspot v.4.5.3 allows a local attacker to execute arbitrary code via a crafted payload to the dst parameter.

May 1, 2024
CVE-2024-25458
7.5 HIGH

An issue in CYCZCAM, SHIX ZHAO, SHIXCAM A9 Camera (circuit board identifier A9-48B-V1.0) firmware v.CYCAM_48B_BC01_v87_0903 allows a remote attacker to obtain sensitive information via a …

May 1, 2024
CVE-2024-25355
7.5 HIGH

s3-url-parser 1.0.3 is vulnerable to Denial of service via the regexes component.

May 1, 2024
CVE-2024-24313
7.5 HIGH

An issue in Vaales Technologies V_QRS v.2024-01-17 allows a remote attacker to obtain sensitive information via the Models/FormModel.php and QRModel.php component.

May 1, 2024
CVE-2024-24312
7.5 HIGH

SQL injection vulnerability in Vaales Technologies V_QRS v.2024-01-17 allows a remote attacker to obtain sensitive information via the Models/UserModel.php component.

May 1, 2024
CVE-2024-22830
5.3 MEDIUM

Anti-Cheat Expert's Windows kernel module "ACE-BASE.sys" version 1.0.2202.6217 does not perform proper access control when handling system resources. This allows a local attacker to escalate …

May 1, 2024
CVE-2023-26793
9.8 CRITICAL

libmodbus v3.1.10 has a heap-based buffer overflow vulnerability in read_io_status function in src/modbus.c.

May 1, 2024
CVE-2023-23022
6.1 MEDIUM

Cross site scripting (XSS) vulnerability in sourcecodester oretnom23 employee's payroll management system 1.0, allows attackers to execute arbitrary code via the code, title, from_date and …

May 1, 2024
CVE-2023-23021
6.1 MEDIUM

Cross Site Scripting (XSS) vulnerability in sourcecodester oretnom23 pos point sale system 1.0, allows attackers to execute arbitrary code via the code, name, and description …

May 1, 2024
CVE-2023-23019
5.4 MEDIUM

Cross site scripting (XSS) vulnerability in file main.php in sourcecodester oretnom23 Blog Site 1.0 via the name and email parameters to function user_add.\

May 1, 2024
CVE-2024-33442
4.3 MEDIUM

An issue in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the add_post.php component.

May 1, 2024
CVE-2024-33078
9.8 CRITICAL

Tencent Libpag v4.3 is vulnerable to Buffer Overflow. A user can send a crafted image to trigger a overflow leading to remote code execution.

May 1, 2024
CVE-2024-32213
5.3 MEDIUM

The LoMag WareHouse Management application version 1.0.20.120 and older were found to allow weak passwords. By default, hard-coded passwords of 10 characters with little or …

May 1, 2024
CVE-2024-32212
8.1 HIGH

SQL Injection vulnerability in LOGINT LoMag Inventory Management v1.0.20.120 and before allows an attacker to execute arbitrary code via the ArticleGetGroups, DocAddDocument, ClassClickShop and frmSettings …

May 1, 2024
CVE-2024-32211
5.5 MEDIUM

An issue in LOGINT LoMag Inventory Management v1.0.20.120 and before allows a local attacker to obtain sensitive information via the UserClass.cs and Settings.cs components.

May 1, 2024
CVE-2024-32210
5.3 MEDIUM

The LoMag WareHouse Management application version 1.0.20.120 and older were to utilize hard-coded passwords by default for forms and SQL connections.

May 1, 2024
CVE-2024-30176
5.3 MEDIUM

In Logpoint before 7.4.0, an attacker can enumerate a valid list of usernames by using publicly exposed URLs of shared widgets.

May 1, 2024
CVE-2024-29010
7.1 HIGH

The XML document processed in the GMS ECM URL endpoint is vulnerable to XML external entity (XXE) injection, potentially resulting in the disclosure of sensitive …

May 1, 2024
CVE-2024-33518
5.3 MEDIUM

An unauthenticated Denial-of-Service (DoS) vulnerability exists in the Radio Frequency Manager service accessed via the PAPI protocol. Successful exploitation of this vulnerability results in the …

May 1, 2024
CVE-2024-33517
5.3 MEDIUM

An unauthenticated Denial-of-Service (DoS) vulnerability exists in the Radio Frequency Manager service accessed via the PAPI protocol. Successful exploitation of this vulnerability results in the …

May 1, 2024
CVE-2024-33516
5.3 MEDIUM

An unauthenticated Denial of Service (DoS) vulnerability exists in the Auth service accessed via the PAPI protocol provided by ArubaOS. Successful exploitation of this vulnerability …

May 1, 2024
CVE-2024-33515
5.3 MEDIUM

Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Management service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to …

May 1, 2024
CVE-2024-33514
5.3 MEDIUM

Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Management service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to …

May 1, 2024
CVE-2024-33513
5.9 MEDIUM

Unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Management service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to …

May 1, 2024
CVE-2024-28764
6.5 MEDIUM

IBM WebSphere Automation 1.7.0 could allow an attacker with privileged access to the network to conduct a CSV injection. An attacker could execute arbitrary commands …

May 1, 2024
CVE-2024-25015
7.5 HIGH

IBM MQ 9.2 LTS, 9.3 LTS, and 9.3 CD Internet Pass-Thru could allow a remote user to cause a denial of service by sending HTTP …

May 1, 2024
CVE-2024-23480
7.5 HIGH

A fallback mechanism in code sign checking on macOS may allow arbitrary code execution. This issue affects Zscaler Client Connector on MacOS prior to 4.2.

May 1, 2024
CVE-2024-23457
7.8 HIGH

The anti-tampering functionality of the Zscaler Client Connector can be disabled under certain conditions when an uninstall password is enforced. This affects Zscaler Client Connector …

May 1, 2024
CVE-2024-20378
7.5 HIGH

A vulnerability in the web-based management interface of Cisco IP Phone firmware could allow an unauthenticated, remote attacker to retrieve sensitive information from an affected …

May 1, 2024
CVE-2024-20376
7.5 HIGH

A vulnerability in the web-based management interface of Cisco IP Phone firmware could allow an unauthenticated, remote attacker to cause an affected device to reload, …

May 1, 2024
CVE-2024-20357
5.9 MEDIUM

A vulnerability in the XML service of Cisco IP Phone firmware could allow an unauthenticated, remote attacker to initiate phone calls on an affected device. …

May 1, 2024
CVE-2023-7241
7.9 HIGH

Privilege Escalation in WRSA.EXE in Webroot Antivirus 8.0.1X- 9.0.35.12 on Windows64 bit and 32 bit allows malicious software to abuse WRSA.EXE to delete arbitrary and …

May 1, 2024
CVE-2024-33820
7.5 HIGH

Totolink AC1200 Wireless Dual Band Gigabit Router A3002R_V4 Firmware V4.0.0-B20230531.1404 is vulnerable to Buffer Overflow via the formWlEncrypt function of the boa server. Specifically, they …

May 1, 2024
CVE-2024-28893
7.7 HIGH

Certain HP software packages (SoftPaqs) are potentially vulnerable to arbitrary code execution when the SoftPaq configuration file has been modified after extraction. HP has released …

May 1, 2024
CVE-2023-49606
9.8 CRITICAL

A use-after-free vulnerability exists in the HTTP Connection Headers parsing in Tinyproxy 1.11.1 and Tinyproxy 1.10.0. A specially crafted HTTP header can trigger reuse of …

May 1, 2024
CVE-2023-47212
9.8 CRITICAL

A heap-based buffer overflow vulnerability exists in the comment functionality of stb _vorbis.c v1.22. A specially crafted .ogg file can lead to an out-of-bounds write. …

May 1, 2024
CVE-2023-47166
8.8 HIGH

A firmware update vulnerability exists in the luci2-io file-import functionality of Milesight UR32L v32.3.0.7-r2. A specially crafted network request can lead to arbitrary firmware update. …

May 1, 2024
CVE-2023-40533

Rejected reason: This CVE ID is a duplicate of CVE-2022-40468

May 1, 2024
CVE-2024-33512
9.8 CRITICAL

There is a buffer overflow vulnerability in the underlying Local User Authentication Database service that could lead to unauthenticated remote code execution by sending specially …

May 1, 2024
CVE-2024-33511
9.8 CRITICAL

There is a buffer overflow vulnerability in the underlying Automatic Reporting service that could lead to unauthenticated remote code execution by sending specially crafted packets …

May 1, 2024
CVE-2024-26305
9.8 CRITICAL

There is a buffer overflow vulnerability in the underlying Utility daemon that could lead to unauthenticated remote code execution by sending specially crafted packets destined …

May 1, 2024
CVE-2024-26304
9.8 CRITICAL

There is a buffer overflow vulnerability in the underlying L2/L3 Management service that could lead to unauthenticated remote code execution by sending specially crafted packets …

May 1, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.