CVE Database

11843+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-29866
9.1 CRITICAL

Datalust Seq before 2023.4.11151 and 2024 before 2024.1.11146 has Incorrect Access Control because a Project Owner or Organization Owner can escalate to System privileges.

Mar 21, 2024
CVE-2024-29732
9.8 CRITICAL

A SQL Injection has been found on SCAN_VISIO eDocument Suite Web Viewer of Abast. This vulnerability allows an unauthenticated user to retrieve, update and delete …

Mar 21, 2024
CVE-2024-27438
9.8 CRITICAL

Download of Code Without Integrity Check vulnerability in Apache Doris. The jdbc driver files used for JDBC catalog is not checked and may resulting in …

Mar 21, 2024
CVE-2024-1148
9.8 CRITICAL

Weak access control in OpenText PVCS Version Manager allows potential bypassing of authentication and uploading of files.

Mar 21, 2024
CVE-2024-1147
9.8 CRITICAL

Weak access control in OpenText PVCS Version Manager allows potential bypassing of authentication and download of files.

Mar 21, 2024
CVE-2024-2161
9.8 CRITICAL

Use of Hard-coded Credentials in Kiloview NDI allows un-authenticated users to bypass authenticationThis issue affects Kiloview NDI N3, N3-s, N4, N20, N30, N40 and was …

Mar 21, 2024
CVE-2024-29864
9.8 CRITICAL

Distrobox before 1.7.0.1 allows attackers to execute arbitrary code via command injection into exported executables.

Mar 21, 2024
CVE-2024-29859
9.8 CRITICAL

In MISP before 2.4.187, add_misp_export in app/Controller/EventsController.php does not properly check for a valid file upload.

Mar 21, 2024
CVE-2024-29858
9.8 CRITICAL

In MISP before 2.4.187, __uploadLogo in app/Controller/OrganisationsController.php does not properly check for a valid logo upload.

Mar 21, 2024
CVE-2023-48902
9.8 CRITICAL

An issue was discovered in tramyardg autoexpress version 1.3.0, allows unauthenticated remote attackers to escalate privileges, update car data, delete vehicles, and upload car images …

Mar 21, 2024
CVE-2023-48901
9.8 CRITICAL

A SQL injection vulnerability in tramyardg Autoexpress version 1.3.0, allows remote unauthenticated attackers to execute arbitrary SQL commands via the parameter "id" within the getPhotosByCarId …

Mar 21, 2024
CVE-2024-2054
9.8 CRITICAL

The Artica-Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subsequently enable code execution as the "www-data" user.

Mar 21, 2024
CVE-2024-27922
9.8 CRITICAL

TOMP Bare Server implements the TompHTTP bare server. A vulnerability in versions prior to 2.0.2 relates to insecure handling of HTTP requests by the @tomphttp/bare-server-node …

Mar 21, 2024
CVE-2024-25239
9.8 CRITICAL

SQL Injection vulnerability in Sourcecodester Employee Management System v1.0 allows attackers to run arbitrary SQL commands via crafted POST request to /emloyee_akpoly/Account/login.php.

Mar 21, 2024
CVE-2024-1202
9.8 CRITICAL

Authentication Bypass by Primary Weakness vulnerability in XPodas Octopod allows Authentication Bypass.This issue affects Octopod: before v1. NOTE: The vendor was contacted and it was …

Mar 21, 2024
CVE-2020-26942
9.1 CRITICAL

An issue discovered in Axigen Mail Server 10.3.x before 10.3.1.27 and 10.3.2.x before 10.3.3.1 allows unauthenticated attackers to submit a setAdminPassword operation request, subsequently setting …

Mar 21, 2024
CVE-2024-2443
9.1 CRITICAL

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin …

Mar 20, 2024
CVE-2024-29037
9.1 CRITICAL

datahub-helm provides the Kubernetes Helm charts for deploying Datahub and its dependencies on a Kubernetes cluster. Starting in version 0.1.143 and prior to version 0.2.182, …

Mar 20, 2024
CVE-2024-25294
9.1 CRITICAL

An SSRF issue in REBUILD v.3.5 allows a remote attacker to obtain sensitive information and execute arbitrary code via the FileDownloader.java, proxyDownload,URL parameters.

Mar 20, 2024
CVE-2024-28231
9.6 CRITICAL

eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.14.0, 2.13.4, 2.12.3, 2.10.4, …

Mar 20, 2024
CVE-2024-28179
9.0 CRITICAL

Jupyter Server Proxy allows users to run arbitrary external processes alongside their Jupyter notebook servers and provides authenticated web access. Prior to versions 3.2.3 and …

Mar 20, 2024
CVE-2024-28395
9.8 CRITICAL

SQL injection vulnerability in Best-Kit bestkit_popup v.1.7.2 and before allows a remote attacker to escalate privileges via the bestkit_popup.php component.

Mar 20, 2024
CVE-2024-28392
9.8 CRITICAL

SQL injection vulnerability in pscartabandonmentpro v.2.0.11 and before allows a remote attacker to escalate privileges via the pscartabandonmentproFrontCAPUnsubscribeJobModuleFrontController::setEmailVisualized() method.

Mar 20, 2024
CVE-2024-1811
9.8 CRITICAL

A potential vulnerability has been identified in OpenText ArcSight Platform. The vulnerability could be remotely exploited.

Mar 20, 2024
CVE-2024-1800
9.9 CRITICAL

In Progress® Telerik® Report Server versions prior to 2024 Q1 (10.0.24.130), a remote code execution attack is possible through an insecure deserialization vulnerability.

Mar 20, 2024
CVE-2024-1711
9.8 CRITICAL

The Create by Mediavine plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 1.9.4 due …

Mar 20, 2024
CVE-2024-22081
9.8 CRITICAL

An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Unauthenticated memory corruption can occur in the HTTP header parsing mechanism.

Mar 20, 2024
CVE-2024-22080
9.8 CRITICAL

An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Unauthenticated memory corruption can occur during XML body parsing.

Mar 20, 2024
CVE-2024-28389
9.8 CRITICAL

SQL injection vulnerability in KnowBand spinwheel v.3.0.3 and before allows a remote attacker to gain escalated privileges and obtain sensitive information via the SpinWheelFrameSpinWheelModuleFrontController::sendEmail() method.

Mar 19, 2024
CVE-2024-28595
9.8 CRITICAL

SQL Injection vulnerability in Employee Management System v1.0 allows attackers to run arbitrary SQL commands via the admin_id parameter in update-admin.php.

Mar 19, 2024
CVE-2024-28394
9.8 CRITICAL

An issue in Advanced Plugins reportsstatistics v1.3.20 and before allows a remote attacker to execute arbitrary code via the Sales Reports, Statistics, Custom Fields & …

Mar 19, 2024
CVE-2024-29027
9.0 CRITICAL

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 6.5.5 and 7.0.0-alpha.29, calling …

Mar 19, 2024
CVE-2024-28303
9.8 CRITICAL

Open Source Medicine Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the date parameter at /admin/reports/index.php.

Mar 19, 2024
CVE-2024-29135
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Themefic Tourfic tourfic.This issue affects Tourfic: from n/a through <= 2.11.15.

Mar 19, 2024
CVE-2024-2636
9.0 CRITICAL

An Unrestricted Upload of File vulnerability has been found on Cegid Meta4 HR, that allows an attacker to upload malicios files to the server via …

Mar 19, 2024
CVE-2024-2615
9.8 CRITICAL

Memory safety bugs present in Firefox 123. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of …

Mar 19, 2024
CVE-2023-40276
9.1 CRITICAL

An issue was discovered in OpenClinic GA 5.247.01. An Unauthenticated File Download vulnerability has been discovered in pharmacy/exportFile.jsp.

Mar 19, 2024
CVE-2023-40275
9.1 CRITICAL

An issue was discovered in OpenClinic GA 5.247.01. It allows retrieval of patient lists via queries such as findFirstname= to _common/search/searchByAjax/patientslistShow.jsp.

Mar 19, 2024
CVE-2024-24578
10.0 CRITICAL

RaspberryMatic is an open-source operating system for HomeMatic internet-of-things devices. RaspberryMatic / OCCU prior to version 3.75.6.20240316 contains a unauthenticated remote code execution (RCE) vulnerability, …

Mar 18, 2024
CVE-2024-21652
9.8 CRITICAL

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to versions 2.8.13, 2.9.9, and 2.10.4, an attacker can exploit a chain of …

Mar 18, 2024
CVE-2024-2051
9.8 CRITICAL

CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could cause account takeover and unauthorized access to the system when an attacker conducts brute-force …

Mar 18, 2024
CVE-2024-2599
9.9 CRITICAL

File upload restriction evasion vulnerability in AMSS++ version 4.31. This vulnerability could allow an authenticated user to potentially obtain RCE through webshell, compromising the entire …

Mar 18, 2024
CVE-2024-28537
9.8 CRITICAL

Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the page parameter of fromNatStaticSetting function.

Mar 18, 2024
CVE-2024-27768
9.8 CRITICAL

Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-22: 'Path Traversal' may allow RCE

Mar 18, 2024
CVE-2024-27767
10.0 CRITICAL

CWE-287: Improper Authentication may allow Authentication Bypass

Mar 18, 2024
CVE-2024-28125
9.8 CRITICAL

FitNesse all releases allows a remote authenticated attacker to execute arbitrary OS commands. Note: A contributor of FitNesse has claimed that this is not a …

Mar 18, 2024
CVE-2024-29151
9.1 CRITICAL

Rocket.Chat.Audit through 5ad78e8 depends on filecachetools, which does not exist in PyPI.

Mar 18, 2024
CVE-2021-47157
9.8 CRITICAL

The Kossy module before 0.60 for Perl allows JSON hijacking because of X-Requested-With mishandling.

Mar 18, 2024
CVE-2021-47155
9.1 CRITICAL

The Net::IPV4Addr module 0.10 for Perl does not properly consider extraneous zero characters in an IP address string, which (in some situations) allows attackers to …

Mar 18, 2024
CVE-2018-25099
9.8 CRITICAL

In the CryptX module before 0.062 for Perl, gcm_decrypt_verify() and chacha20poly1305_decrypt_verify() do not verify the tag.

Mar 18, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.