CVE Database

122268+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-3052
7.5 HIGH

Malformed S2 Nonce Get command classes can be sent to crash the gateway. A hard reset is required to recover the gateway.

Apr 26, 2024
CVE-2024-3051
7.5 HIGH

Malformed Device Reset Locally command classes can be sent to temporarily deny service to an end device. Any frames sent by the end device will …

Apr 26, 2024
CVE-2024-31828
6.1 MEDIUM

Cross Site Scripting vulnerability in Lavalite CMS v.10.1.0 allows attackers to execute arbitrary code and obtain sensitive information via a crafted payload to the URL.

Apr 26, 2024
CVE-2024-31741
6.1 MEDIUM

Cross Site Scripting vulnerability in MiniCMS v.1.11 allows a remote attacker to run arbitrary code via crafted string in the URL after login.

Apr 26, 2024
CVE-2024-31551
7.5 HIGH

Directory Traversal vulnerability in lib/admin/image.admin.php in cmseasy v7.7.7.9 20240105 allows attackers to delete arbitrary files via crafted GET request.

Apr 26, 2024
CVE-2024-30804
9.8 CRITICAL

An issue discovered in the DeviceIoControl component in ASUS Fan_Xpert before v.10013 allows an attacker to execute arbitrary code via crafted IOCTL requests.

Apr 26, 2024
CVE-2024-28322
9.8 CRITICAL

SQL Injection vulnerability in /event-management-master/backend/register.php in PuneethReddyHC Event Management 1.0 allows attackers to run arbitrary SQL commands via the event_id parameter in a crafted POST …

Apr 26, 2024
CVE-2024-4242
8.8 HIGH

A vulnerability was found in Tenda W9 1.0.0.7(4456). It has been rated as critical. This issue affects the function formwrlSSIDget of the file /goform/wifiSSIDget. The …

Apr 26, 2024
CVE-2024-4241
8.8 HIGH

A vulnerability was found in Tenda W9 1.0.0.7(4456). It has been declared as critical. This vulnerability affects the function formQosManageDouble_auto. The manipulation of the argument …

Apr 26, 2024
CVE-2024-4240
8.8 HIGH

A vulnerability was found in Tenda W9 1.0.0.7(4456). It has been classified as critical. This affects the function formQosManageDouble_user. The manipulation of the argument ssidIndex …

Apr 26, 2024
CVE-2024-4239
8.8 HIGH

A vulnerability was found in Tenda AX1806 1.0.0.1 and classified as critical. Affected by this issue is the function formSetRebootTimer of the file /goform/SetRebootTimer. The …

Apr 26, 2024
CVE-2024-32887
5.5 MEDIUM

Sidekiq is simple, efficient background processing for Ruby. Sidekiq is reflected XSS vulnerability. The value of substr parameter is reflected in the response without any …

Apr 26, 2024
CVE-2024-32883
7.7 HIGH

MCUboot is a secure bootloader for 32-bits microcontrollers. MCUboot uses a TLV (tag-length-value) structure to represent the meta data associated with an image. The TLVs …

Apr 26, 2024
CVE-2024-32881
9.8 CRITICAL

Danswer is the AI Assistant connected to company's docs, apps, and people. Danswer is vulnerable to unauthorized access to GET/SET of Slack Bot Tokens. Anyone …

Apr 26, 2024
CVE-2024-32878
7.1 HIGH

Llama.cpp is LLM inference in C/C++. There is a use of uninitialized heap variable vulnerability in gguf_init_from_file, the code will free this uninitialized variable later. …

Apr 26, 2024
CVE-2024-31601
9.8 CRITICAL

An issue in Beijing Panabit Network Software Co., Ltd Panalog big data analysis platform v. 20240323 and before allows attackers to execute arbitrary code via …

Apr 26, 2024
CVE-2024-31502
8.1 HIGH

An issue in Insurance Management System v.1.0.0 and before allows a remote attacker to escalate privileges via a crafted POST request to /admin/core/new_staff.

Apr 26, 2024
CVE-2024-4238
8.8 HIGH

A vulnerability has been found in Tenda AX1806 1.0.0.1 and classified as critical. Affected by this vulnerability is the function formSetDeviceName of the file /goform/SetOnlineDevName. …

Apr 26, 2024
CVE-2024-28326
6.8 MEDIUM

Incorrect Access Control in ASUS RT-N12+ B1 and RT-N12 D1 routers allows local attackers to obtain root terminal access via the the UART interface.

Apr 26, 2024
CVE-2024-25343
9.1 CRITICAL

Tenda N300 F3 router vulnerability allows users to bypass intended security policy and create weak passwords.

Apr 26, 2024
CVE-2023-26603
5.9 MEDIUM

JumpCloud Agent before 1.178.0 Creates a Temporary File in a Directory with Insecure Permissions. This allows privilege escalation to SYSTEM via a repair action in …

Apr 26, 2024
CVE-2022-48611
7.8 HIGH

A logic issue was addressed with improved checks. This issue is fixed in iTunes 12.12.4 for Windows. A local attacker may be able to elevate …

Apr 26, 2024
CVE-2024-4237
8.8 HIGH

A vulnerability, which was classified as critical, was found in Tenda AX1806 1.0.0.1. Affected is the function R7WebsSecurityHandler of the file /goform/execCommand. The manipulation of …

Apr 26, 2024
CVE-2024-28327
8.4 HIGH

Asus RT-N12+ B1 router stores user passwords in plaintext, which could allow local attackers to obtain unauthorized access and modify router settings.

Apr 26, 2024
CVE-2024-28325
6.1 MEDIUM

Asus RT-N12+ B1 router stores credentials in cleartext, which could allow local attackers to obtain unauthorized access and modify router settings.

Apr 26, 2024
CVE-2024-4236
8.8 HIGH

A vulnerability, which was classified as critical, has been found in Tenda AX1803 1.0.0.1. This issue affects the function formSetSysToolDDNS of the file /goform/SetDDNSCfg. The …

Apr 26, 2024
CVE-2024-4235
2.7 LOW

A vulnerability classified as problematic was found in Netgear DG834Gv5 1.6.01.34. This vulnerability affects unknown code of the component Web Management Interface. The manipulation leads …

Apr 26, 2024
CVE-2024-33344
9.8 CRITICAL

D-Link DIR-822+ V1.0.5 was found to contain a command injection in ftext function of upload_firmware.cgi, which allows remote attackers to execute arbitrary commands via shell.

Apr 26, 2024
CVE-2024-33343
8.8 HIGH

D-Link DIR-822+ V1.0.5 was found to contain a command injection in ChgSambaUserSettings function of prog.cgi, which allows remote attackers to execute arbitrary commands via shell.

Apr 26, 2024
CVE-2024-33342
7.5 HIGH

D-Link DIR-822+ V1.0.5 was found to contain a command injection in SetPlcNetworkpwd function of prog.cgi, which allows remote attackers to execute arbitrary commands via shell.

Apr 26, 2024
CVE-2024-32884
6.4 MEDIUM

gitoxide is a pure Rust implementation of Git. `gix-transport` does not check the username part of a URL for text that the external `ssh` program …

Apr 26, 2024
CVE-2024-32880
9.1 CRITICAL

pyload is an open-source Download Manager written in pure Python. An authenticated user can change the download folder and upload a crafted template to the …

Apr 26, 2024
CVE-2024-33260
5.1 MEDIUM

Jerryscript commit cefd391 was discovered to contain a segmentation violation via the component parser_parse_class at jerry-core/parser/js/js-parser-expr.c

Apr 26, 2024
CVE-2024-33259
5.5 MEDIUM

Jerryscript commit cefd391 was discovered to contain a segmentation violation via the component scanner_seek at jerry-core/parser/js/js-scanner-util.c.

Apr 26, 2024
CVE-2024-33258
7.1 HIGH

Jerryscript commit ff9ff8f was discovered to contain a segmentation violation via the component vm_loop at jerry-core/vm/vm.c.

Apr 26, 2024
CVE-2024-33255
6.2 MEDIUM

Jerryscript commit cefd391 was discovered to contain an Assertion Failure via ECMA_STRING_IS_REF_EQUALS_TO_ONE (string_p) in ecma_free_string_list.

Apr 26, 2024
CVE-2024-32766
10.0 CRITICAL

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands …

Apr 26, 2024
CVE-2024-32764
9.9 CRITICAL

A missing authentication for critical function vulnerability has been reported to affect myQNAPcloud Link. If exploited, the vulnerability could allow users with the privilege level …

Apr 26, 2024
CVE-2024-28328
5.4 MEDIUM

CSV Injection vulnerability in the Asus RT-N12+ router allows administrator users to inject arbitrary commands or formulas in the client name parameter which can be …

Apr 26, 2024
CVE-2024-27124
7.5 HIGH

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands …

Apr 26, 2024
CVE-2024-21905
6.5 MEDIUM

An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to compromise …

Apr 26, 2024
CVE-2023-51794
7.8 HIGH

Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/af_stereowiden.c:120:69.

Apr 26, 2024
CVE-2023-51365
8.7 HIGH

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to read the contents …

Apr 26, 2024
CVE-2023-51364
8.7 HIGH

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to read the contents …

Apr 26, 2024
CVE-2023-50364
6.4 MEDIUM

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow …

Apr 26, 2024
CVE-2023-50363
7.4 HIGH

An incorrect authorization vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to bypass intended …

Apr 26, 2024
CVE-2023-50362
5.0 MEDIUM

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow …

Apr 26, 2024
CVE-2023-50361
5.0 MEDIUM

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow …

Apr 26, 2024
CVE-2023-47222
9.6 CRITICAL

An exposure of sensitive information vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow users to compromise the security …

Apr 26, 2024
CVE-2023-41291
5.5 MEDIUM

A path traversal vulnerability has been reported to affect QuFirewall. If exploited, the vulnerability could allow authenticated administrators to read the contents of unexpected files …

Apr 26, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.