CVE Database

122268+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-30985
9.8 CRITICAL

SQL Injection vulnerability in "B/W Dates Reports" page in phpgurukul Client Management System using PHP & MySQL 1.1 allows attacker to execute arbitrary SQL commands …

Apr 17, 2024
CVE-2024-30982
9.8 CRITICAL

SQL Injection vulnerability in phpgurukul Cyber Cafe Management System Using PHP & MySQL 1.0 allows attackers to run arbitrary SQL commands via the upid parameter …

Apr 17, 2024
CVE-2024-30951
6.1 MEDIUM

FUDforum v3.1.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the chpos parameter at /adm/admsmiley.php.

Apr 17, 2024
CVE-2024-2961
7.3 HIGH

The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes …

Apr 17, 2024
CVE-2024-30983
7.3 HIGH

SQL Injection vulnerability in phpgurukul Cyber Cafe Management System Using PHP & MySQL 1.0 allows attackers to run arbitrary SQL commands via the compname parameter …

Apr 17, 2024
CVE-2024-30981
9.8 CRITICAL

SQL Injection vulnerability in /edit-computer-detail.php in phpgurukul Cyber Cafe Management System Using PHP & MySQL v1.0 allows attackers to run arbitrary SQL commands via editid …

Apr 17, 2024
CVE-2024-30980
9.8 CRITICAL

SQL Injection vulnerability in phpgurukul Cyber Cafe Management System Using PHP & MySQL 1.0 allows attackers to run arbitrary SQL commands via the Computer Location …

Apr 17, 2024
CVE-2024-28073
8.4 HIGH

SolarWinds Serv-U was found to be susceptible to a Directory Traversal Remote Code Vulnerability. This vulnerability requires a highly privileged account to be exploited.

Apr 17, 2024
CVE-2023-5407
5.9 MEDIUM

Controller denial of service due to improper handling of a specially crafted message received by the controller. See Honeywell Security Notification for recommendations on upgrading …

Apr 17, 2024
CVE-2023-5406
5.9 MEDIUM

Server communication with a controller can lead to remote code execution using a specially crafted message from the controller. See Honeywell Security Notification for recommendations …

Apr 17, 2024
CVE-2023-5405
5.9 MEDIUM

Server information leak for the CDA Server process memory can occur when an error is generated in response to a specially crafted message. See Honeywell …

Apr 17, 2024
CVE-2023-5404
8.1 HIGH

Server receiving a malformed message can cause a pointer to be overwritten which can result in a remote code execution or failure. See Honeywell Security …

Apr 17, 2024
CVE-2023-5403
8.1 HIGH

Server hostname translation to IP address manipulation which could lead to an attacker performing remote code execution or causing a failure. See Honeywell Security Notification …

Apr 17, 2024
CVE-2023-5401
8.1 HIGH

Server receiving a malformed message based on a using the specified key values can cause a stack overflow vulnerability which could lead to an attacker …

Apr 17, 2024
CVE-2023-5400
8.1 HIGH

Server receiving a malformed message based on a using the specified key values can cause a heap overflow vulnerability which could lead to an attacker …

Apr 17, 2024
CVE-2023-5398
5.9 MEDIUM

Server receiving a malformed message based on a list of IPs resulting in heap corruption causing a denial of service. See Honeywell Security Notification for …

Apr 17, 2024
CVE-2023-5397
8.1 HIGH

Server receiving a malformed message to create a new connection could lead to an attacker performing remote code execution or causing a failure. See Honeywell …

Apr 17, 2024
CVE-2023-5396
7.4 HIGH

Server receiving a malformed message creates connection for a hostname that may cause a stack overflow resulting in possible remote code execution. See Honeywell Security …

Apr 17, 2024
CVE-2023-5395
8.1 HIGH

Server receiving a malformed message that uses the hostname in an internal table may cause a stack overflow resulting in possible remote code execution. See …

Apr 17, 2024
CVE-2024-32463
7.1 HIGH

phlex is an open source framework for building object-oriented views in Ruby. There is a potential cross-site scripting (XSS) vulnerability that can be exploited via …

Apr 17, 2024
CVE-2024-32320
5.9 MEDIUM

Tenda AC500 V2.0.1.9(1307) firmware has a stack overflow vulnerability via the timeZone parameter in the formSetTimeZone function.

Apr 17, 2024
CVE-2024-32318
9.8 CRITICAL

Tenda AC500 V2.0.1.9(1307) firmware has a stack overflow vulnerability via the vlan parameter in the formSetVlanInfo function.

Apr 17, 2024
CVE-2024-32317
7.5 HIGH

Tenda AC10 v4.0 V16.03.10.13 and V16.03.10.20 firmware has a stack overflow vulnerability via the adslPwd parameter in the formWanParameterSetting function.

Apr 17, 2024
CVE-2024-32316
6.5 MEDIUM

Tenda AC500 V2.0.1.9(1307) firmware has a stack overflow vulnerability in the fromDhcpListClient function.

Apr 17, 2024
CVE-2024-32314
3.8 LOW

Tenda AC500 V2.0.1.9(1307) firmware contains a command injection vulnerablility in the formexeCommand function via the cmdinput parameter.

Apr 17, 2024
CVE-2024-32305
8.8 HIGH

Tenda A18 v15.03.05.05 firmware has a stack overflow vulnerability located via the PPW parameter in the fromWizardHandle function.

Apr 17, 2024
CVE-2024-32303
8.0 HIGH

Tenda AC15 v15.03.20_multi, v15.03.05.19, and v15.03.05.18 firmware has a stack overflow vulnerability located via the PPW parameter in the fromWizardHandle function.

Apr 17, 2024
CVE-2024-31463
4.7 MEDIUM

Ironic-image is an OpenStack Ironic deployment packaged and configured by Metal3. When the reverse proxy mode is enabled by the `IRONIC_REVERSE_PROXY_SETUP` variable set to `true`, …

Apr 17, 2024
CVE-2024-30979
5.9 MEDIUM

Cross Site Scripting vulnerability in Cyber Cafe Management System 1.0 allows a remote attacker to execute arbitrary code via the compname parameter in edit-computer-details.php.

Apr 17, 2024
CVE-2024-26920
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tracing/trigger: Fix to return error if failed to alloc snapshot Fix register_snapshot_trigger() to return error …

Apr 17, 2024
CVE-2024-26919
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: ulpi: Fix debugfs directory leak The ULPI per-device debugfs root is named after the …

Apr 17, 2024
CVE-2024-26918
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: PCI: Fix active state requirement in PME polling The commit noted in fixes added a …

Apr 17, 2024
CVE-2024-26917
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: Revert "scsi: fcoe: Fix potential deadlock on &fip->ctlr_lock" This reverts commit 1a1975551943f681772720f639ff42fbaa746212. This commit …

Apr 17, 2024
CVE-2024-26916
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Revert "drm/amd: flush any delayed gfxoff on suspend entry" commit ab4750332dbe ("drm/amdgpu/sdma5.2: add begin/end_use ring …

Apr 17, 2024
CVE-2024-26915
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Reset IH OVERFLOW_CLEAR bit Allows us to detect subsequent IH ring buffer overflows as …

Apr 17, 2024
CVE-2024-26914
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: fix incorrect mpc_combine array size [why] MAX_SURFACES is per stream, while MAX_PLANES is per …

Apr 17, 2024
CVE-2024-26913
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix dcn35 8k30 Underflow/Corruption Issue [why] odm calculation is missing for pipe split policy …

Apr 17, 2024
CVE-2024-26912
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: fix several DMA buffer leaks Nouveau manages GSP-RM DMA buffers with nvkm_gsp_mem objects. Several …

Apr 17, 2024
CVE-2024-26911
3.3 LOW

In the Linux kernel, the following vulnerability has been resolved: drm/buddy: Fix alloc_range() error handling code Few users have observed display corruption when they boot …

Apr 17, 2024
CVE-2024-26910
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: fix performance regression in swap operation The patch "netfilter: ipset: fix race condition …

Apr 17, 2024
CVE-2023-52645
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: pmdomain: mediatek: fix race conditions with genpd If the power domains are registered first with …

Apr 17, 2024
CVE-2023-46060
7.5 HIGH

A Buffer Overflow vulnerability in Tenda AC500 v.2.0.1.9 allows a remote attacker to cause a denial of service via the port parameter at the goform/setVlanInfo …

Apr 17, 2024
CVE-2024-3825
4.3 MEDIUM

Versions of the BlazeMeter Jenkins plugin prior to 4.22 contain a flaw which results in credential enumeration

Apr 17, 2024
CVE-2024-30253
7.5 HIGH

@solana/web3.js is the Solana JavaScript SDK. Using particular inputs with `@solana/web3.js` will result in memory exhaustion (OOM). If you have a server, client, mobile, or …

Apr 17, 2024
CVE-2024-29035
4.1 MEDIUM

Umbraco is an ASP.NET CMS. Failing webhooks logs are available when solution is not in debug mode. Those logs can contain information that is critical. …

Apr 17, 2024
CVE-2024-32315
4.7 MEDIUM

Tenda FH1202 v1.2.0.14(408) firmware has a stack overflow vulnerability via the adslPwd parameter in the formWanParameterSetting function.

Apr 17, 2024
CVE-2024-32311
6.5 MEDIUM

Tenda FH1203 v2.0.1.6 firmware has a stack overflow vulnerability via the adslPwd parameter in the formWanParameterSetting function.

Apr 17, 2024
CVE-2024-32306
5.7 MEDIUM

Tenda AC10U v1.0 Firmware v15.03.06.49 has a stack overflow vulnerability located via the PPW parameter in the fromWizardHandle function.

Apr 17, 2024
CVE-2024-32302
6.3 MEDIUM

Tenda FH1202 v1.2.0.14(408) firmware has a stack overflow vulnerability via the PPW parameter in the fromWizardHandle function.

Apr 17, 2024
CVE-2024-32299
8.8 HIGH

Tenda FH1203 v2.0.1.6 firmware has a stack overflow vulnerability via the PPW parameter in the fromWizardHandle function.

Apr 17, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.