CVE Database

122268+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-25575
8.8 HIGH

A type confusion vulnerability vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a Lock object. A specially crafted Javascript code inside a malicious PDF …

Apr 30, 2024
CVE-2023-45385
7.5 HIGH

ProQuality pqprintshippinglabels before v.4.15.0 is vulnerable to Directory Traversal via the pqprintshippinglabels module.

Apr 30, 2024
CVE-2023-38002
5.0 MEDIUM

IBM Storage Scale 5.1.0.0 through 5.1.9.2 could allow an authenticated user to steal or manipulate an active session to gain access to the system. IBM …

Apr 30, 2024
CVE-2024-23774
7.8 HIGH

An issue was discovered in Quest KACE Agent for Windows 12.0.38 and 13.1.23.0. An unquoted Windows search path vulnerability exists in the KSchedulerSvc.exe and AMPTools.exe …

Apr 30, 2024
CVE-2024-23773
7.8 HIGH

An issue was discovered in Quest KACE Agent for Windows 12.0.38 and 13.1.23.0. An Arbitrary file delete vulnerability exists in the KSchedulerSvc.exe component. Local attackers …

Apr 30, 2024
CVE-2024-23772
6.6 MEDIUM

An issue was discovered in Quest KACE Agent for Windows 12.0.38 and 13.1.23.0. An Arbitrary file create vulnerability exists in the KSchedulerSvc.exe, KUserAlert.exe, and Runkbot.exe …

Apr 30, 2024
CVE-2023-50915
6.5 MEDIUM

An issue exists in GalaxyClientService.exe in GOG Galaxy (Beta) 2.0.67.2 through 2.0.71.2 that could allow authenticated users to overwrite and corrupt critical system files via …

Apr 30, 2024
CVE-2023-50914
6.7 MEDIUM

A Privilege Escalation issue in the inter-process communication procedure from GOG Galaxy (Beta) 2.0.67.2 through v2.0.71.2 allows authentictaed users to change the DACL of arbitrary …

Apr 30, 2024
CVE-2024-2617
7.2 HIGH

A vulnerability exists in the RTU500 that allows for authenticated and authorized users to bypass secure update, if secure update feature was not enabled on …

Apr 30, 2024
CVE-2024-2378
8.0 HIGH

A vulnerability exists in the web-authentication component of the SDM600. If exploited an attacker could escalate privileges on af-fected installations.

Apr 30, 2024
CVE-2024-2377
7.6 HIGH

A vulnerability exists in the too permissive HTTP response header web server settings of the SDM600. An attacker can take advantage of this and possibly …

Apr 30, 2024
CVE-2023-46304
8.1 HIGH

modules/Users/models/Module.php in Vtiger CRM 7.5.0 allows a remote authenticated attacker to run arbitrary PHP code because an unprotected endpoint allows them to write this code …

Apr 30, 2024
CVE-2024-4337
7.6 HIGH

Adive Framework 2.0.8, does not sufficiently encode user-controlled inputs, resulting in a persistent Cross-Site Scripting (XSS) vulnerability via the /adive/admin/nav/add, in multiple parameters. This vulnerability …

Apr 30, 2024
CVE-2024-4336
7.6 HIGH

Adive Framework 2.0.8, does not sufficiently encode user-controlled inputs, resulting in a persistent Cross-Site Scripting (XSS) vulnerability via the /adive/admin/tables/add, in multiple parameters. An attacker …

Apr 30, 2024
CVE-2024-22405
5.5 MEDIUM

XADMaster is an objective-C library for archive and file unarchiving and extraction. When extracting a specially crafted zip archive XADMaster may not apply quarantine attribute …

Apr 30, 2024
CVE-2024-4185
8.1 HIGH

The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Email Verification and Authentication Bypass in all versions up to, and including, 2.7.4 …

Apr 30, 2024
CVE-2024-3072
4.3 MEDIUM

The ACF Front End Editor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_texts() function …

Apr 30, 2024
CVE-2024-2663
8.3 HIGH

The ZD YouTube FLV Player plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.2.6 via the $_GET['image'] …

Apr 30, 2024
CVE-2024-1895
7.5 HIGH

The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and …

Apr 30, 2024
CVE-2024-4225
7.6 HIGH

Multiple security vulnerabilities has been discovered in web interface of NetGuardian DIN Remote Telemetry Unit (RTU), by DPS Telecom. Attackers can exploit those security vulnerabilities …

Apr 30, 2024
CVE-2024-31837
8.4 HIGH

DMitry (Deepmagic Information Gathering Tool) 1.3a has a format-string vulnerability, with a threat model similar to CVE-2017-7938.

Apr 30, 2024
CVE-2024-1371
6.5 MEDIUM

The LeadConnector plugin for WordPress is vulnerable to unauthorized modification & loss of data due to a missing capability check on the lc_public_api_proxy() function in …

Apr 30, 2024
CVE-2024-4226
3.5 LOW

It was identified that in certain versions of Octopus Server, that a user created with no permissions could view all users, user roles and permissions. …

Apr 30, 2024
CVE-2024-0216
6.4 MEDIUM

The Google Doc Embedder plugin for WordPress is vulnerable to Server Side Request Forgery via the 'gview' shortcode in versions up to, and including, 2.6.4. …

Apr 30, 2024
CVE-2024-4327
3.5 LOW

A vulnerability was found in Apryse WebViewer up to 10.8.0. It has been classified as problematic. This affects an unknown part of the component PDF …

Apr 30, 2024
CVE-2024-34050
7.5 HIGH

Open Networking Foundation SD-RAN Rimedo rimedo-ts 0.1.1 has a slice bounds out-of-range panic in "return uint64(b[2])<<16 | uint64(b[1])<<8 | uint64(b[0])" in reader.go.

Apr 30, 2024
CVE-2024-34049
7.5 HIGH

Open Networking Foundation SD-RAN Rimedo rimedo-ts 0.1.1 has a slice bounds out-of-range panic in "return plmnIdString[0:3], plmnIdString[3:]" in reader.go.

Apr 30, 2024
CVE-2024-34048
9.8 CRITICAL

O-RAN RIC I-Release e2mgr lacks array size checks in E2nodeConfigUpdateNotificationHandler.

Apr 30, 2024
CVE-2024-34047
4.3 MEDIUM

O-RAN RIC I-Release e2mgr lacks array size checks in RicServiceUpdateHandler.

Apr 30, 2024
CVE-2024-34046
7.5 HIGH

The O-RAN E2T I-Release Prometheus metric Increment function can crash in sctpThread.cpp for message.peerInfo->sctpParams->e2tCounters[IN_SUCC][MSG_COUNTER][ProcedureCode_id_RICsubscription]->Increment().

Apr 30, 2024
CVE-2024-34045
7.5 HIGH

The O-RAN E2T I-Release Prometheus metric Increment function can crash in sctpThread.cpp for message.peerInfo->counters[IN_INITI][MSG_COUNTER][ProcedureCode_id_E2setup]->Increment().

Apr 30, 2024
CVE-2024-34044
5.3 MEDIUM

The O-RAN E2T I-Release buildPrometheusList function can have a NULL pointer dereference because peerInfo can be NULL.

Apr 30, 2024
CVE-2024-34043
5.3 MEDIUM

O-RAN RICAPP kpimon-go I-Release has a segmentation violation via a certain E2AP-PDU message.

Apr 30, 2024
CVE-2023-52728
5.5 MEDIUM

Open Networking Foundation SD-RAN ONOS onos-lib-go 0.10.25 allows an index out-of-range condition in putBitString.

Apr 30, 2024
CVE-2023-52727
8.1 HIGH

Open Networking Foundation SD-RAN ONOS onos-lib-go 0.10.25 allows an index out-of-range condition in parseAlignBits.

Apr 30, 2024
CVE-2023-52726
6.5 MEDIUM

Open Networking Foundation SD-RAN ONOS onos-ric-sdk-go 0.8.12 allows infinite repetition of the processing of an error (in the Subscribe function implementation for the subscribed indication …

Apr 30, 2024
CVE-2023-52725
6.5 MEDIUM

Open Networking Foundation SD-RAN ONOS onos-kpimon 0.4.7 allows blocking of the errCh channel within the Start function of the monitoring package.

Apr 30, 2024
CVE-2023-52724
8.1 HIGH

Open Networking Foundation SD-RAN onos-kpimon 0.4.7 allows out-of-bounds array access in the processIndicationFormat1 function.

Apr 30, 2024
CVE-2024-33522
6.7 MEDIUM

In vulnerable versions of Calico (v3.27.2 and below), Calico Enterprise (v3.19.0-1, v3.18.1, v3.17.3 and below), and Calico Cloud (v19.2.0 and below), an attacker who has …

Apr 29, 2024
CVE-2024-33401
4.4 MEDIUM

Cross Site Scripting vulnerability in DedeCMS v.5.7.113 allows a remote attacker to run arbitrary code via the mnum parameter.

Apr 29, 2024
CVE-2023-50434
9.8 CRITICAL

emdns_resolve_raw in emdns.c in emdns through fbd1eef calls strlen with an input that may not be '\0' terminated, leading to a stack-based buffer over-read. This …

Apr 29, 2024
CVE-2023-50433
6.5 MEDIUM

marshall in dhcp_packet.c in simple-dhcp-server through ec976d2 allows remote attackers to cause a denial of service by sending a malicious DHCP packet. The crash is …

Apr 29, 2024
CVE-2023-50432
5.3 MEDIUM

simple-dhcp-server through ec976d2 allows remote attackers to cause a denial of service (daemon crash) by sending a DHCP packet without any option fields, which causes …

Apr 29, 2024
CVE-2024-33350
9.8 CRITICAL

Directory Traversal vulnerability in TaoCMS v.3.0.2 allows a remote attacker to execute arbitrary code and obtain sensitive information via the include/model/file.php component.

Apr 29, 2024
CVE-2024-28294
6.5 MEDIUM

Limbas up to v5.2.14 was discovered to contain a SQL injection vulnerability via the ftid parameter.

Apr 29, 2024
CVE-2024-27518
7.8 HIGH

An issue in SUPERAntiSyware Professional X 10.0.1262 and 10.0.1264 allows unprivileged attackers to escalate privileges via a restore of a crafted DLL file into the …

Apr 29, 2024
CVE-2023-46960
8.6 HIGH

Buffer Overflow vulnerability in PyPXE v.1.8.4 allows a remote attacker to cause a denial of service via the handle function in the tftp module.

Apr 29, 2024
CVE-2023-46566
7.5 HIGH

Buffer Overflow vulnerability in msoulier tftpy commit 467017b844bf6e31745138a30e2509145b0c529c allows a remote attacker to cause a denial of service via the parse function in the TftpPacketFactory …

Apr 29, 2024
CVE-2023-31889
5.5 MEDIUM

An issue discovered in httpd in ASUS RT-AC51U with firmware version up to and including 3.0.0.4.380.8591 allows local attackers to cause a denial of service …

Apr 29, 2024
CVE-2024-33435
9.8 CRITICAL

Insecure Permissions vulnerability in Guangzhou Yingshi Electronic Technology Co. Ncast Yingshi high-definition intelligent recording and playback system 2007-2017 allows a remote attacker to execute arbitrary …

Apr 29, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.