CVE Database

122268+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-32293
8.0 HIGH

Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability via the page parameter in the fromDhcpListClient function.

Apr 17, 2024
CVE-2024-32292
8.8 HIGH

Tenda W30E v1.0 V1.0.1.25(633) firmware contains a command injection vulnerablility in the formexeCommand function via the cmdinput parameter.

Apr 17, 2024
CVE-2024-32291
7.5 HIGH

Tenda W30E v1.0 firmware v1.0.1.25(633) has a stack overflow vulnerability via the page parameter in the fromNatlimit function.

Apr 17, 2024
CVE-2024-32290
6.7 MEDIUM

Tenda W30E v1.0 v1.0.1.25(633) firmware has a stack overflow vulnerability via the page parameter in the fromAddressNat function.

Apr 17, 2024
CVE-2024-32288
6.3 MEDIUM

Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability located via the page parameter in the fromwebExcptypemanFilter function.

Apr 17, 2024
CVE-2024-32287
6.5 MEDIUM

Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability via the qos parameter in the fromqossetting function.

Apr 17, 2024
CVE-2024-32286
9.8 CRITICAL

Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability located via the page parameter in the fromVirtualSer function.

Apr 17, 2024
CVE-2024-32285
8.0 HIGH

Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability via the password parameter in the formaddUserName function.

Apr 17, 2024
CVE-2024-32283
7.3 HIGH

Tenda FH1203 V2.0.1.6 firmware has a command injection vulnerablility in formexeCommand function via the cmdinput parameter.

Apr 17, 2024
CVE-2024-32282
6.3 MEDIUM

Tenda FH1202 v1.2.0.14(408) firmware contains a command injection vulnerablility in the formexeCommand function via the cmdinput parameter.

Apr 17, 2024
CVE-2024-31578
7.5 HIGH

FFmpeg version n6.1.1 was discovered to contain a heap use-after-free via the av_hwframe_ctx_init function.

Apr 17, 2024
CVE-2024-2419
7.1 HIGH

A flaw was found in Keycloak's redirect_uri validation logic. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful attack may lead …

Apr 17, 2024
CVE-2024-1249
7.4 HIGH

A flaw was found in Keycloak's OIDC component in the "checkLoginIframe," which allows unvalidated cross-origin messages. This flaw allows attackers to coordinate and send millions …

Apr 17, 2024
CVE-2024-1132
8.1 HIGH

A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct …

Apr 17, 2024
CVE-2024-32313
6.5 MEDIUM

Tenda FH1205 V2.0.0.7(775) firmware has a stack overflow vulnerability located via the adslPwd parameter of the formWanParameterSetting function.

Apr 17, 2024
CVE-2024-32312
5.7 MEDIUM

Tenda F1203 V2.0.1.6 firmware has a stack overflow vulnerability located in the adslPwd parameter of the formWanParameterSetting function.

Apr 17, 2024
CVE-2024-32310
8.0 HIGH

Tenda F1203 V2.0.1.6 firmware has a stack overflow vulnerability located in the PPW parameter of the fromWizardHandle function.

Apr 17, 2024
CVE-2024-32307
7.4 HIGH

Tenda FH1205 V2.0.0.7(775) firmware has a stack overflow vulnerability located via the PPW parameter in the fromWizardHandle function.

Apr 17, 2024
CVE-2024-32301
9.8 CRITICAL

Tenda AC7V1.0 v15.03.06.44 firmware has a stack overflow vulnerability via the PPW parameter in the fromWizardHandle function.

Apr 17, 2024
CVE-2024-32281
8.8 HIGH

Tenda AC7V1.0 v15.03.06.44 firmware contains a command injection vulnerablility in formexeCommand function via the cmdinput parameter.

Apr 17, 2024
CVE-2024-30952
6.1 MEDIUM

A stored cross-site scripting (XSS) vulnerability in PESCMS-TEAM v2.3.6 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the …

Apr 17, 2024
CVE-2023-6805
6.4 MEDIUM

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Blind Server-Side Request …

Apr 17, 2024
CVE-2023-45744
8.3 HIGH

A data integrity vulnerability exists in the web interface /cgi-bin/upload_config.cgi functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted HTTP request can lead …

Apr 17, 2024
CVE-2023-45209
5.3 MEDIUM

An information disclosure vulnerability exists in the web interface /cgi-bin/download_config.cgi functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted HTTP request can lead …

Apr 17, 2024
CVE-2023-43491
5.3 MEDIUM

An information disclosure vulnerability exists in the web interface /cgi-bin/debug_dump.cgi functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted HTTP request can lead …

Apr 17, 2024
CVE-2023-40146
6.8 MEDIUM

A privilege escalation vulnerability exists in the /bin/login functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted command line argument can lead to …

Apr 17, 2024
CVE-2023-39367
9.1 CRITICAL

An OS command injection vulnerability exists in the web interface mac2name functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted HTTP request can …

Apr 17, 2024
CVE-2024-3910
8.8 HIGH

A vulnerability, which was classified as critical, has been found in Tenda AC500 2.0.1.9(1307). Affected by this issue is the function fromDhcpListClient of the file …

Apr 17, 2024
CVE-2024-3909
8.8 HIGH

A vulnerability classified as critical was found in Tenda AC500 2.0.1.9(1307). Affected by this vulnerability is the function formexeCommand of the file /goform/execCommand. The manipulation …

Apr 17, 2024
CVE-2024-3908
6.3 MEDIUM

A vulnerability classified as critical has been found in Tenda AC500 2.0.1.9(1307). Affected is the function formWriteFacMac of the file /goform/WriteFacMac. The manipulation of the …

Apr 17, 2024
CVE-2024-3333
6.4 MEDIUM

The Essential Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL attributes of widgets in all versions up to, …

Apr 17, 2024
CVE-2024-3907
8.8 HIGH

A vulnerability was found in Tenda AC500 2.0.1.9(1307). It has been rated as critical. This issue affects the function formSetCfm of the file /goform/setcfm. The …

Apr 17, 2024
CVE-2024-3906
8.8 HIGH

A vulnerability was found in Tenda AC500 2.0.1.9(1307). It has been declared as critical. This vulnerability affects the function formQuickIndex of the file /goform/QuickIndex. The …

Apr 17, 2024
CVE-2024-3905
8.8 HIGH

A vulnerability was found in Tenda AC500 2.0.1.9(1307). It has been classified as critical. This affects the function R7WebsSecurityHandler of the file /goform/execCommand. The manipulation …

Apr 17, 2024
CVE-2024-26909
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: soc: qcom: pmic_glink_altmode: fix drm bridge use-after-free A recent DRM series purporting to simplify support …

Apr 17, 2024
CVE-2024-26908

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Apr 17, 2024
CVE-2024-26907
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix fortify source warning while accessing Eth segment ------------[ cut here ]------------ memcpy: detected …

Apr 17, 2024
CVE-2024-26906
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: x86/mm: Disallow vsyscall page read for copy_from_kernel_nofault() When trying to use copy_from_kernel_nofault() to read vsyscall …

Apr 17, 2024
CVE-2024-26905

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Apr 17, 2024
CVE-2024-26904

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Apr 17, 2024
CVE-2024-26903
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: rfcomm: Fix null-ptr-deref in rfcomm_check_security During our fuzz testing of the connection and disconnection …

Apr 17, 2024
CVE-2024-26902
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: perf: RISCV: Fix panic on pmu overflow handler (1 << idx) of int is not …

Apr 17, 2024
CVE-2024-26901
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: do_sys_name_to_handle(): use kzalloc() to fix kernel-infoleak syzbot identified a kernel information leak vulnerability in do_sys_name_to_handle() …

Apr 17, 2024
CVE-2024-26900
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: md: fix kmemleak of rdev->serial If kobject_add() is fail in bind_rdev_to_array(), 'rdev->serial' will be alloc …

Apr 17, 2024
CVE-2024-26899
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: block: fix deadlock between bd_link_disk_holder and partition scan 'open_mutex' of gendisk is used to protect …

Apr 17, 2024
CVE-2024-26898
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: aoe: fix the potential use-after-free problem in aoecmd_cfg_pkts This patch is against CVE-2023-6270. The description …

Apr 17, 2024
CVE-2024-26897
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: delay all of ath9k_wmi_event_tasklet() until init is complete The ath9k_wmi_event_tasklet() used in ath9k_htc …

Apr 17, 2024
CVE-2024-26896
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: wfx: fix memory leak when starting AP Kmemleak reported this error: unreferenced object 0xd73d1180 …

Apr 17, 2024
CVE-2024-26895
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: wilc1000: prevent use-after-free on vif when cleaning up all interfaces wilc_netdev_cleanup currently triggers a …

Apr 17, 2024
CVE-2024-26894
6.0 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ACPI: processor_idle: Fix memory leak in acpi_processor_power_exit() After unregistering the CPU idle device, the memory …

Apr 17, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.