CVE Database

122268+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-3777
9.8 CRITICAL

The password reset feature of Ai3 QbiBot lacks proper access control, allowing unauthenticated remote attackers to reset any user's password.

Apr 15, 2024
CVE-2024-3776
6.1 MEDIUM

The parameter used in the login page of Netvision airPASS is not properly filtered for user input. An unauthenticated remote attacker can insert JavaScript code …

Apr 15, 2024
CVE-2024-3775
5.3 MEDIUM

aEnrich Technology a+HRD's functionality for downloading files using youtube-dl.exe does not properly restrict user input. This allows attackers to pass arbitrary arguments to youtube-dl.exe, leading …

Apr 15, 2024
CVE-2024-3769
7.3 HIGH

A vulnerability, which was classified as critical, was found in PHPGurukul Student Record System 3.20. Affected is an unknown function of the file /login.php. The …

Apr 15, 2024
CVE-2024-3768
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in PHPGurukul/itsourcecode News Portal 4.1. This issue affects some unknown processing of the file search.php. …

Apr 15, 2024
CVE-2024-3767
6.3 MEDIUM

A vulnerability classified as critical was found in PHPGurukul News Portal 4.1. This vulnerability affects unknown code of the file /admin/edit-post.php. The manipulation of the …

Apr 15, 2024
CVE-2024-1655
8.8 HIGH

Certain ASUS WiFi routers models has an OS Command Injection vulnerability, allowing an authenticated remote attacker to execute arbitrary system commands by sending a specially …

Apr 15, 2024
CVE-2024-3774
5.3 MEDIUM

aEnrich Technology a+HRD's functionality for front-end retrieval of system configuration values lacks proper restrictions on a specific parameter, allowing attackers to modify this parameter to …

Apr 15, 2024
CVE-2024-3772
5.9 MEDIUM

Regular expression denial of service in Pydanic < 2.4.0, < 1.10.13 allows remote attackers to cause denial of service via a crafted email string.

Apr 15, 2024
CVE-2024-3766
2.4 LOW

A vulnerability, which was classified as problematic, has been found in slowlyo OwlAdmin up to 3.5.7. Affected by this issue is some unknown functionality of …

Apr 15, 2024
CVE-2024-29844
9.8 CRITICAL

Default credentials on the Web Interface of Evolution Controller 2.x allows anyone to log in to the server directly to perform administrative functions. Upon installation …

Apr 15, 2024
CVE-2024-29843
7.5 HIGH

The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on MOBILE_GET_USERS_LIST, allowing for an unauthenticated attacker to enumerate all …

Apr 15, 2024
CVE-2024-29842
7.5 HIGH

The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_ABACARD_FIELDS, allowing for an unauthenticated attacker to return the …

Apr 15, 2024
CVE-2024-29841
7.5 HIGH

The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_KEYS_FIELDS, allowing for an unauthenticated attacker to return the …

Apr 15, 2024
CVE-2024-29840
7.5 HIGH

The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_PIN_FIELDS, allowing for an unauthenticated attacker to return the …

Apr 15, 2024
CVE-2024-29839
7.5 HIGH

The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_CARD, allowing for an unauthenticated attacker to return the …

Apr 15, 2024
CVE-2024-29838
7.5 HIGH

The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below does not proper sanitize user input, allowing for an unauthenticated attacker to crash the controller …

Apr 15, 2024
CVE-2024-29837
8.8 HIGH

The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below uses poor session management, allowing for an unauthenticated attacker to access administrator functionality if any …

Apr 15, 2024
CVE-2024-29836
9.8 CRITICAL

The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control, allowing for an unauthenticated attacker to update and add user …

Apr 15, 2024
CVE-2024-3765
9.8 CRITICAL

A vulnerability classified as critical was found in Xiongmai AHB7804R-MH-V2, AHB8004T-GL, AHB8008T-GL, AHB7004T-GS-V3, AHB7004T-MHV2, AHB8032F-LME and XM530_R80X30-PQ_8M. Affected by this vulnerability is an unknown functionality …

Apr 14, 2024
CVE-2024-3764
2.7 LOW

** DISPUTED ** A vulnerability classified as problematic has been found in Tuya SDK up to 5.0.x. Affected is an unknown function of the component …

Apr 14, 2024
CVE-2024-3763
2.4 LOW

A vulnerability was found in Emlog Pro 2.2.10. It has been rated as problematic. This issue affects some unknown processing of the file /admin/tag.php of …

Apr 14, 2024
CVE-2024-27462

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not …

Apr 14, 2024
CVE-2024-3762
2.4 LOW

A vulnerability was found in Emlog Pro 2.2.10. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/twitter.php of the …

Apr 14, 2024
CVE-2024-24863

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. CVE-2024-24863 has been replaced by CVE-2024-36014.

Apr 14, 2024
CVE-2024-24862

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Apr 14, 2024
CVE-2024-3740
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in cym1102 nginxWebUI up to 3.9.9. This issue affects the function exec of the file …

Apr 13, 2024
CVE-2024-3739
6.3 MEDIUM

A vulnerability classified as critical was found in cym1102 nginxWebUI up to 3.9.9. This vulnerability affects unknown code of the file /adminPage/main/upload. The manipulation of …

Apr 13, 2024
CVE-2024-3738
7.3 HIGH

A vulnerability classified as critical has been found in cym1102 nginxWebUI up to 3.9.9. This affects the function handlePath of the file /adminPage/conf/saveCmd. The manipulation …

Apr 13, 2024
CVE-2024-3737
6.3 MEDIUM

A vulnerability was found in cym1102 nginxWebUI up to 3.9.9. It has been rated as critical. Affected by this issue is the function findCountByQuery of …

Apr 13, 2024
CVE-2024-32487
8.6 HIGH

less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically …

Apr 13, 2024
CVE-2024-3736
4.3 MEDIUM

A vulnerability was found in cym1102 nginxWebUI up to 3.9.9. It has been declared as problematic. Affected by this vulnerability is the function upload of …

Apr 13, 2024
CVE-2024-3735
3.7 LOW

A vulnerability was found in Smart Office up to 20240405. It has been classified as problematic. Affected is an unknown function of the file Main.aspx. …

Apr 13, 2024
CVE-2024-3721
6.3 MEDIUM

A vulnerability was found in TBK DVR-4104 and DVR-4216 up to 20240412 and classified as critical. This issue affects some unknown processing of the file …

Apr 13, 2024
CVE-2024-3720
6.3 MEDIUM

A vulnerability has been found in Tianwell Fire Intelligent Command Platform 1.1.1.1 and classified as critical. This vulnerability affects unknown code of the file /mfsNotice/page …

Apr 13, 2024
CVE-2024-26817
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: amdkfd: use calloc instead of kzalloc to avoid integer overflow This uses calloc instead of …

Apr 13, 2024
CVE-2024-3719
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Campcodes House Rental Management System 1.0. This affects an unknown part of the file ajax.php. …

Apr 13, 2024
CVE-2024-3662
4.3 MEDIUM

The WPZOOM Social Feed Widget & Block plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpzoom_instagram_clear_data() function …

Apr 13, 2024
CVE-2023-6494
4.4 MEDIUM

The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and …

Apr 13, 2024
CVE-2024-2583
5.4 MEDIUM

The WP Shortcodes Plugin — Shortcodes Ultimate WordPress plugin before 7.0.5 does not properly escape some of its shortcodes attributes before they are echoed back …

Apr 13, 2024
CVE-2024-3027
6.4 MEDIUM

The Smart Slider 3 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the upload function in …

Apr 13, 2024
CVE-2024-1957
6.4 MEDIUM

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'give_form' shortcode in all versions …

Apr 13, 2024
CVE-2024-32028
4.1 MEDIUM

OpenTelemetry dotnet is a dotnet telemetry framework. In affected versions of `OpenTelemetry.Instrumentation.Http` and `OpenTelemetry.Instrumentation.AspNetCore` the `url.full` writes attribute/tag on spans (`Activity`) when tracing is enabled …

Apr 12, 2024
CVE-2024-31462
6.3 MEDIUM

stable-diffusion-webui is a web interface for Stable Diffusion, implemented using Gradio library. Stable-diffusion-webui 1.7.0 is vulnerable to a limited file write affecting Windows systems. The …

Apr 12, 2024
CVE-2024-28869
7.5 HIGH

Traefik is an HTTP reverse proxy and load balancer. In affected versions sending a GET request to any Traefik endpoint with the "Content-length" request header …

Apr 12, 2024
CVE-2024-32019
8.8 HIGH

Netdata is an open source observability tool. In affected versions the `ndsudo` tool shipped with affected versions of the Netdata Agent allows an attacker to …

Apr 12, 2024
CVE-2024-32005
8.2 HIGH

NiceGUI is an easy-to-use, Python-based UI framework. A local file inclusion is present in the NiceUI leaflet component when requesting resource files under the `/_nicegui/{__version__}/resources/{key}/{path:path}` …

Apr 12, 2024
CVE-2024-32003
8.8 HIGH

wn-dusk-plugin (Dusk plugin) is a plugin which integrates Laravel Dusk browser testing into Winter CMS. The Dusk plugin provides some special routes as part of …

Apr 12, 2024
CVE-2024-29023
7.2 HIGH

Xibo is an Open Source Digital Signage platform with a web content management system and Windows display player software. Session tokens are exposed in the …

Apr 12, 2024
CVE-2024-29022
8.8 HIGH

Xibo is an Open Source Digital Signage platform with a web content management system and Windows display player software. In affected versions some request headers …

Apr 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.