CVE Database

11843+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2022-47036
9.8 CRITICAL

Siklu TG Terragraph devices before approximately 2.1.1 have a hardcoded root password that has been revealed via a brute force attack on an MD5 hash. …

Mar 18, 2024
CVE-2024-27957
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Pie Register.This issue affects Pie Register: from n/a through 3.8.3.1.

Mar 17, 2024
CVE-2024-28639
9.8 CRITICAL

Buffer Overflow vulnerability in TOTOLink X5000R V9.1.0u.6118-B20201102 and A7000R V9.1.0u.6115-B20201022, allow remote attackers to execute arbitrary code and cause a denial of service (DoS) via …

Mar 16, 2024
CVE-2024-28255
9.8 CRITICAL

OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. The `JwtFilter` handles …

Mar 15, 2024
CVE-2024-28253
9.4 CRITICAL

OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. `CompiledRule::validateExpression` is also …

Mar 15, 2024
CVE-2023-7017
9.8 CRITICAL

Sciener locks' firmware update mechanism do not authenticate or validate firmware updates if passed to the lock through the Bluetooth Low Energy service. A challenge …

Mar 15, 2024
CVE-2023-7006
9.1 CRITICAL

The unlockKey character in a lock using Sciener firmware can be brute forced through repeated challenge requests, compromising the locks integrity.

Mar 15, 2024
CVE-2024-28752
9.3 CRITICAL

A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style attacks …

Mar 15, 2024
CVE-2024-28354
10.0 CRITICAL

There is a command injection vulnerability in the TRENDnet TEW-827DRU router with firmware version 2.10B01. An attacker can inject commands into the post request parameters …

Mar 15, 2024
CVE-2024-25227
9.8 CRITICAL

SQL Injection vulnerability in ABO.CMS version 5.8, allows remote attackers to execute arbitrary code, cause a denial of service (DoS), escalate privileges, and obtain sensitive …

Mar 15, 2024
CVE-2024-1917
9.8 CRITICAL

Integer Overflow or Wraparound vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remote unauthenticated attacker to execute malicious code …

Mar 15, 2024
CVE-2024-1916
9.8 CRITICAL

Integer Overflow or Wraparound vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remote unauthenticated attacker to execute malicious code …

Mar 15, 2024
CVE-2024-1915
9.8 CRITICAL

Incorrect Pointer Scaling vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remote unauthenticated attacker to execute malicious code on …

Mar 15, 2024
CVE-2024-0803
9.8 CRITICAL

Integer Overflow or Wraparound vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remote unauthenticated attacker to execute malicious code …

Mar 15, 2024
CVE-2024-0802
9.8 CRITICAL

Incorrect Pointer Scaling vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remote unauthenticated attacker to read arbitrary information from …

Mar 15, 2024
CVE-2024-26503
9.1 CRITICAL

Unrestricted File Upload vulnerability in Greek Universities Network Open eClass v.3.15 and earlier allows attackers to run arbitrary code via upload of crafted file to …

Mar 14, 2024
CVE-2023-42286
9.8 CRITICAL

There is a PHP file inclusion vulnerability in the template configuration of eyoucms v1.6.4, allowing attackers to execute code or system commands through a carefully …

Mar 14, 2024
CVE-2024-28423
9.8 CRITICAL

Airflow-Diagrams v2.1.0 was discovered to contain an arbitrary file upload vulnerability in the unsafe_load function at cli.py. This vulnerability allows attackers to execute arbitrary code …

Mar 14, 2024
CVE-2024-25139
10.0 CRITICAL

In TP-Link Omada er605 1.0.1 through (v2.6) 2.2.3, a cloud-brd binary is susceptible to an integer overflow that leads to a heap-based buffer overflow. After …

Mar 14, 2024
CVE-2024-28383
9.8 CRITICAL

Tenda AX12 v1.0 v22.03.01.16 was discovered to contain a stack overflow via the ssid parameter in the sub_431CF0 function.

Mar 14, 2024
CVE-2024-28391
9.8 CRITICAL

SQL injection vulnerability in FME Modules quickproducttable module for PrestaShop v.1.2.1 and before, allows a remote attacker to escalate privileges and obtain information via the …

Mar 14, 2024
CVE-2024-28390
9.8 CRITICAL

An issue in Advanced Plugins ultimateimagetool module for PrestaShop before v.2.2.01, allows a remote attacker to escalate privileges and obtain sensitive information via Improper Access …

Mar 14, 2024
CVE-2024-28388
9.8 CRITICAL

SQL injection vulnerability in SunnyToo stproductcomments module for PrestaShop v.1.0.5 and before, allows a remote attacker to escalate privileges and obtain sensitive information via the …

Mar 14, 2024
CVE-2024-28175
9.0 CRITICAL

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Due to the improper URL protocols filtering of links specified in the `link.argocd.argoproj.io` annotations …

Mar 13, 2024
CVE-2024-27102
9.9 CRITICAL

Wings is the server control plane for Pterodactyl Panel. This vulnerability impacts anyone running the affected versions of Wings. The vulnerability can potentially be used …

Mar 13, 2024
CVE-2024-25250
9.8 CRITICAL

SQL Injection vulnerability in code-projects Agro-School Management System 1.0 allows attackers to run arbitrary code via the Login page.

Mar 13, 2024
CVE-2023-41505
9.8 CRITICAL

An arbitrary file upload vulnerability in the Add Student's Profile Picture function of Student Enrollment In PHP v1.0 allows attackers to execute arbitrary code via …

Mar 13, 2024
CVE-2024-28194
9.1 CRITICAL

your_spotify is an open source, self hosted Spotify tracking dashboard. YourSpotify versions < 1.8.0 use a hardcoded JSON Web Token (JWT) secret to sign authentication …

Mar 13, 2024
CVE-2024-0799
9.8 CRITICAL

An authentication bypass vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in the edge-app-base-webui.jar!com.ca.arcserve.edge.app.base.ui.server.EdgeLoginServiceImpl.doLogin() function within wizardLogin.

Mar 13, 2024
CVE-2024-2172
9.8 CRITICAL

The Malware Scanner plugin and the Web Application Firewall plugin for WordPress (both by MiniOrange) are vulnerable to privilege escalation due to a missing capability …

Mar 13, 2024
CVE-2024-1071
9.8 CRITICAL

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to SQL Injection via the …

Mar 13, 2024
CVE-2023-6825
9.9 CRITICAL

The File Manager and File Manager Pro plugins for WordPress are vulnerable to Directory Traversal in versions up to, and including version 7.2.1 (free version) …

Mar 13, 2024
CVE-2024-25153
9.8 CRITICAL

A directory traversal within the ‘ftpservlet’ of the FileCatalyst Workflow Web Portal allows files to be uploaded outside of the intended ‘uploadtemp’ directory with a …

Mar 13, 2024
CVE-2024-2413
9.8 CRITICAL

Intumit SmartRobot uses a fixed encryption key for authentication. Remote attackers can use this key to encrypt a string composed of the user's name and …

Mar 13, 2024
CVE-2024-24101
9.8 CRITICAL

Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection under Eligibility Information Update.

Mar 12, 2024
CVE-2024-24093
9.8 CRITICAL

SQL Injection vulnerability in Code-projects Scholars Tracking System 1.0 allows attackers to run arbitrary code via Personal Information Update information.

Mar 12, 2024
CVE-2024-21400
9.0 CRITICAL

Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability

Mar 12, 2024
CVE-2024-21334
9.8 CRITICAL

Open Management Infrastructure (OMI) Remote Code Execution Vulnerability

Mar 12, 2024
CVE-2024-1527
9.8 CRITICAL

Unrestricted file upload vulnerability in CMS Made Simple, affecting version 2.2.14. This vulnerability allows an authenticated user to bypass the security measures of the upload …

Mar 12, 2024
CVE-2024-1301
9.8 CRITICAL

SQL injection vulnerability in Badger Meter Monitool affecting versions 4.6.3 and earlier. A remote attacker could send a specially crafted SQL query to the server …

Mar 12, 2024
CVE-2023-48788
9.8 CRITICAL KEV

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows …

Mar 12, 2024
CVE-2023-47534
9.6 CRITICAL

A improper neutralization of formula elements in a csv file in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.10, 6.4.0 through 6.4.9, 6.2.0 through …

Mar 12, 2024
CVE-2023-42789
9.8 CRITICAL

A out-of-bounds write in Fortinet FortiOS 7.4.0 through 7.4.1, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, FortiProxy 7.4.0, 7.2.0 through …

Mar 12, 2024
CVE-2024-28553
9.8 CRITICAL

Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the entrys parameter fromAddressNat function.

Mar 12, 2024
CVE-2024-28535
9.8 CRITICAL

Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the mitInterface parameter of fromAddressNat function.

Mar 12, 2024
CVE-2024-22039
10.0 CRITICAL

A vulnerability has been identified in Cerberus PRO EN Engineering Tool (All versions < IP8), Cerberus PRO EN Fire Panel FC72x IP6 (All versions < …

Mar 12, 2024
CVE-2023-41313
9.8 CRITICAL

The authentication method in Apache Doris versions before 2.0.0 was vulnerable to timing attacks. Users are recommended to upgrade to version 2.0.0 + or 1.2.8, …

Mar 12, 2024
CVE-2022-32257
9.8 CRITICAL

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2). The affected application consists of a web service that lacks proper …

Mar 12, 2024
CVE-2024-25995
9.8 CRITICAL

An unauthenticated remote attacker can modify configurations to perform a remote code execution, gain root rights or perform an DoS due to improper input validation.

Mar 12, 2024
CVE-2024-25331
9.3 CRITICAL

DIR-822 Rev. B Firmware v2.02KRB09 and DIR-822-CA Rev. B Firmware v2.03WWb01 suffer from a LAN-Side Unauthenticated Remote Code Execution (RCE) vulnerability elevated from HNAP Stack-Based …

Mar 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.