CVE Database

122268+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-23115
7.2 HIGH

Centreon updateGroups SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required …

Apr 1, 2024
CVE-2024-1863
9.8 CRITICAL

Sante PACS Server Token Endpoint SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante …

Apr 1, 2024
CVE-2024-1179
8.8 HIGH

TP-Link Omada ER605 DHCPv6 Client Options Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations …

Apr 1, 2024
CVE-2024-0637
8.8 HIGH

Centreon updateDirectory SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required …

Apr 1, 2024
CVE-2023-51573
9.8 CRITICAL

Voltronic Power ViewPower Pro updateManagerPassword Exposed Dangerous Function Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Voltronic Power …

Apr 1, 2024
CVE-2023-51572
9.8 CRITICAL

Voltronic Power ViewPower Pro getMacAddressByIp Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Voltronic …

Apr 1, 2024
CVE-2023-51571
7.5 HIGH

Voltronic Power ViewPower Pro SocketService Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Voltronic Power …

Apr 1, 2024
CVE-2023-51570
9.8 CRITICAL

Voltronic Power ViewPower Pro Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Apr 1, 2024
CVE-2024-29435
4.1 MEDIUM

An issue discovered in Alldata v0.4.6 allows attacker to run arbitrary commands via the processId parameter.

Apr 1, 2024
CVE-2024-29433
9.8 CRITICAL

A deserialization vulnerability in the FASTJSON component of Alldata v0.4.6 allows attackers to execute arbitrary commands via supplying crafted data.

Apr 1, 2024
CVE-2023-48906
4.3 MEDIUM

Stack Overflow vulnerability in Btstack 1.6 and earlier allows attackers to cause a denial of service via crafted input to the char_for_nibble function.

Apr 1, 2024
CVE-2024-3135
6.5 MEDIUM

A Cross-Site Request Forgery (CSRF) vulnerability exists in the mudler/localai application, allowing attackers to craft malicious webpages that, when visited by a victim, perform unauthorized …

Apr 1, 2024
CVE-2024-3131
6.3 MEDIUM

A vulnerability was found in SourceCodester Computer Laboratory Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file …

Apr 1, 2024
CVE-2024-28232
6.2 MEDIUM

Go package IceWhaleTech/CasaOS-UserService provides user management functionalities to CasaOS. The Casa OS Login page has disclosed the username enumeration vulnerability in the login page which …

Apr 1, 2024
CVE-2024-3129
6.3 MEDIUM

A vulnerability was found in SourceCodester Image Accordion Gallery App 1.0. It has been classified as critical. This affects an unknown part of the file …

Apr 1, 2024
CVE-2024-30867
9.8 CRITICAL

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/edit_virtual_site_info.php.

Apr 1, 2024
CVE-2024-30863
6.3 MEDIUM

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /WebPages/history.php.

Apr 1, 2024
CVE-2024-30862
8.8 HIGH

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /3g/index.php.

Apr 1, 2024
CVE-2024-30861
5.3 MEDIUM

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/configguide/ipsec_guide_1.php.

Apr 1, 2024
CVE-2024-30860
8.8 HIGH

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/export_excel_user.php.

Apr 1, 2024
CVE-2024-30859
8.8 HIGH

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/config_ISCGroupSSLCert.php.

Apr 1, 2024
CVE-2024-30858
9.8 CRITICAL

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/edit_fire_wall.php.

Apr 1, 2024
CVE-2024-25574
8.8 HIGH

SQL injection vulnerability exists in GetDIAE_usListParameters.

Apr 1, 2024
CVE-2024-3128
2.4 LOW

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as problematic, has been found in Replify-Messenger 1.0 on Android. This issue affects some unknown …

Apr 1, 2024
CVE-2024-30866
5.4 MEDIUM

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /3g/menu.php.

Apr 1, 2024
CVE-2024-30865
9.8 CRITICAL

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/edit_user_login.php.

Apr 1, 2024
CVE-2024-30864
6.3 MEDIUM

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/config_ISCGroupTimePolicy.php.

Apr 1, 2024
CVE-2024-26655
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Fix memory leak in posix_clock_open() If the clk ops.open() function returns an error, we don't …

Apr 1, 2024
CVE-2024-21473
9.8 CRITICAL

Memory corruption while redirecting log file to any file location with any file name.

Apr 1, 2024
CVE-2024-21472
8.4 HIGH

Memory corruption in Kernel while handling GPU operations.

Apr 1, 2024
CVE-2024-21470
8.4 HIGH

Memory corruption while allocating memory for graphics.

Apr 1, 2024
CVE-2024-21468
8.4 HIGH

Memory corruption when there is failed unmap operation in GPU.

Apr 1, 2024
CVE-2024-21463
7.3 HIGH

Memory corruption while processing Codec2 during v13k decoder pitch synthesis.

Apr 1, 2024
CVE-2024-21454
7.5 HIGH

Transient DOS while decoding the ToBeSignedMessage in Automotive Telematics.

Apr 1, 2024
CVE-2024-21453
7.5 HIGH

Transient DOS while decoding message of size that exceeds the available system memory.

Apr 1, 2024
CVE-2024-21452
7.3 HIGH

Transient DOS while decoding an ASN.1 OER message containing a SEQUENCE of unknown extensions.

Apr 1, 2024
CVE-2023-43515
6.6 MEDIUM

Memory corruption in HLOS while running kernel address sanitizers (syzkaller) on tmecom with DEBUG_FS enabled.

Apr 1, 2024
CVE-2023-33115
7.8 HIGH

Memory corruption while processing buffer initialization, when trusted report for certain report types are generated.

Apr 1, 2024
CVE-2023-33111
5.5 MEDIUM

Information disclosure when VI calibration state set by ADSP is greater than MAX_FBSP_STATE in the response payload to AFE calibration command.

Apr 1, 2024
CVE-2023-33101
7.5 HIGH

Transient DOS while processing DL NAS TRANSPORT message with payload length 0.

Apr 1, 2024
CVE-2023-33100
7.5 HIGH

Transient DOS while processing DL NAS Transport message when message ID is not defined in the 3GPP specification.

Apr 1, 2024
CVE-2023-33099
7.5 HIGH

Transient DOS while processing SMS container of non-standard size received in DL NAS transport in NR.

Apr 1, 2024
CVE-2023-33023
8.4 HIGH

Memory corruption while processing finish_sign command to pass a rsp buffer.

Apr 1, 2024
CVE-2023-28547
8.4 HIGH

Memory corruption in SPS Application while requesting for public key in sorter TA.

Apr 1, 2024
CVE-2024-3125
2.4 LOW

A vulnerability classified as problematic was found in Zebra ZTC GK420d 1.0. This vulnerability affects unknown code of the file /settings of the component Alert …

Apr 1, 2024
CVE-2024-31099
6.4 MEDIUM

Missing Authorization vulnerability in Averta Shortcodes and extra features for Phlox theme auxin-elements.This issue affects Shortcodes and extra features for Phlox theme: from n/a through …

Apr 1, 2024
CVE-2024-3124
2.4 LOW

A vulnerability classified as problematic has been found in fridgecow smartalarm 1.8.1 on Android. This affects an unknown part of the file androidmanifest.xml of the …

Apr 1, 2024
CVE-2024-30872
5.1 MEDIUM

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /include/authrp.php.

Apr 1, 2024
CVE-2024-30871
8.8 HIGH

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /WebPages/applyhardware.php.

Apr 1, 2024
CVE-2024-30870
8.8 HIGH

netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/address_interpret.php.

Apr 1, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.