CVE Database

11843+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-40057
9.0 CRITICAL

The SolarWinds Access Rights Manager was found to be susceptible to a Remote Code Execution Vulnerability. If exploited, this vulnerability allows an authenticated user to …

Feb 15, 2024
CVE-2024-25502
9.8 CRITICAL

Directory Traversal vulnerability in flusity CMS v.2.4 allows a remote attacker to execute arbitrary code and obtain sensitive information via the download_backup.php component.

Feb 15, 2024
CVE-2023-7081
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in POSTAHSİL Online Payment System allows SQL Injection.This issue affects Online Payment …

Feb 15, 2024
CVE-2023-5155
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Utarit Information Technologies SoliPay Mobile App allows SQL Injection.This issue affects …

Feb 15, 2024
CVE-2024-23113
9.8 CRITICAL KEV

A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 …

Feb 15, 2024
CVE-2024-20720
9.1 CRITICAL

Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') …

Feb 15, 2024
CVE-2024-20719
9.1 CRITICAL

Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin attacker …

Feb 15, 2024
CVE-2024-20738
9.8 CRITICAL

Adobe FrameMaker Publishing Server versions 2022.1 and earlier are affected by an Improper Authentication vulnerability that could result in a Security feature bypass. An attacker …

Feb 15, 2024
CVE-2023-39245
9.8 CRITICAL

DELL ESI (Enterprise Storage Integrator) for SAP LAMA, version 10.0, contains an information disclosure vulnerability in EHAC component. An remote unauthenticated attacker could potentially exploit …

Feb 15, 2024
CVE-2023-32484
9.8 CRITICAL

Dell Networking Switches running Enterprise SONiC versions 4.1.0, 4.0.5, 3.5.4 and below contains an improper input validation vulnerability. A remote unauthenticated malicious user may exploit …

Feb 15, 2024
CVE-2023-32462
9.8 CRITICAL

Dell OS10 Networking Switches running 10.5.2.x and above contain an OS command injection vulnerability when using remote user authentication. A remote unauthenticated attacker could potentially …

Feb 15, 2024
CVE-2023-28078
9.1 CRITICAL

Dell OS10 Networking Switches running 10.5.2.x and above contain a vulnerability with zeroMQ when VLT is configured. A remote unauthenticated attacker could potentially exploit this …

Feb 15, 2024
CVE-2024-0390
9.8 CRITICAL

INPRAX "iZZi connect" application on Android contains hard-coded MQTT queue credentials. The same MQTT queue is used by corresponding physical recuperation devices. Exploiting this vulnerability …

Feb 15, 2024
CVE-2022-23088
9.8 CRITICAL

The 802.11 beacon handling routine failed to validate the length of an IEEE 802.11s Mesh ID before copying it to a heap-allocated buffer. While a …

Feb 15, 2024
CVE-2024-26264
9.8 CRITICAL

EBM Technologies RISWEB's specific query function parameter does not properly restrict user input, and this feature page is accessible without login. This allows remote attackers …

Feb 15, 2024
CVE-2024-26261
9.8 CRITICAL

The functionality for file download in HGiga OAKlouds' certain modules contains an Arbitrary File Read and Delete vulnerability. Attackers can put file path in specific …

Feb 15, 2024
CVE-2024-26260
9.8 CRITICAL

The functionality for synchronization in HGiga OAKlouds' certain moudules has an OS Command Injection vulnerability, allowing remote attackers to inject system commands within specific request …

Feb 15, 2024
CVE-2024-24300
9.8 CRITICAL

4ipnet EAP-767 v3.42.00 is vulnerable to Incorrect Access Control. The device uses the same set of credentials, regardless of how many times a user logs …

Feb 14, 2024
CVE-2024-25223
9.8 CRITICAL

Simple Admin Panel App v1.0 was discovered to contain a SQL injection vulnerability via the orderID parameter at /adminView/viewEachOrder.php.

Feb 14, 2024
CVE-2024-25222
9.8 CRITICAL

Task Manager App v1.0 was discovered to contain a SQL injection vulnerability via the projectID parameter at /TaskManager/EditProject.php.

Feb 14, 2024
CVE-2024-25220
9.8 CRITICAL

Task Manager App v1.0 was discovered to contain a SQL injection vulnerability via the taskID parameter at /TaskManager/EditTask.php.

Feb 14, 2024
CVE-2024-25217
9.8 CRITICAL

Online Medicine Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /omos/?p=products/view_product.

Feb 14, 2024
CVE-2024-25216
9.8 CRITICAL

Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the mailud parameter at /aprocess.php.

Feb 14, 2024
CVE-2024-25215
9.8 CRITICAL

Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the pwd parameter at /aprocess.php.

Feb 14, 2024
CVE-2024-25214
9.8 CRITICAL

An issue in Employee Managment System v1.0 allows attackers to bypass authentication via injecting a crafted payload into the E-mail and Password parameters at /alogin.html.

Feb 14, 2024
CVE-2024-25211
9.8 CRITICAL

Simple Expense Tracker v1.0 was discovered to contain a SQL injection vulnerability via the category parameter at /endpoint/delete_category.php.

Feb 14, 2024
CVE-2024-25210
9.8 CRITICAL

Simple Expense Tracker v1.0 was discovered to contain a SQL injection vulnerability via the expense parameter at /endpoint/delete_expense.php.

Feb 14, 2024
CVE-2024-25209
9.8 CRITICAL

Barangay Population Monitoring System 1.0 was discovered to contain a SQL injection vulnerability via the resident parameter at /endpoint/delete-resident.php.

Feb 14, 2024
CVE-2023-6441
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in UNI-PA University Marketing & Computer Internet Trade Inc. University Information System …

Feb 14, 2024
CVE-2024-23786
9.3 CRITICAL

Cross-site scripting vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary script …

Feb 14, 2024
CVE-2024-24691
9.6 CRITICAL

Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user …

Feb 14, 2024
CVE-2024-24142
9.8 CRITICAL

Sourcecodester School Task Manager 1.0 allows SQL Injection via the 'subject' parameter.

Feb 13, 2024
CVE-2024-1378
9.1 CRITICAL

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin …

Feb 13, 2024
CVE-2024-1374
9.1 CRITICAL

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin …

Feb 13, 2024
CVE-2024-1372
9.1 CRITICAL

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin …

Feb 13, 2024
CVE-2024-1369
9.1 CRITICAL

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin …

Feb 13, 2024
CVE-2024-1359
9.1 CRITICAL

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin …

Feb 13, 2024
CVE-2024-1355
9.1 CRITICAL

A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin …

Feb 13, 2024
CVE-2024-21413
9.8 CRITICAL KEV

Microsoft Outlook Remote Code Execution Vulnerability

Feb 13, 2024
CVE-2024-21410
9.8 CRITICAL KEV

Microsoft Exchange Server Elevation of Privilege Vulnerability

Feb 13, 2024
CVE-2024-21403
9.0 CRITICAL

Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability

Feb 13, 2024
CVE-2024-21401
9.8 CRITICAL

Microsoft Entra Jira Single-Sign-On Plugin Elevation of Privilege Vulnerability

Feb 13, 2024
CVE-2024-21376
9.0 CRITICAL

Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability

Feb 13, 2024
CVE-2024-21364
9.3 CRITICAL

Microsoft Azure Site Recovery Elevation of Privilege Vulnerability

Feb 13, 2024
CVE-2024-22923
9.8 CRITICAL

SQL injection vulnerability in adv radius v.2.2.5 allows a local attacker to execute arbitrary code via a crafted script.

Feb 13, 2024
CVE-2024-23816
9.8 CRITICAL

A vulnerability has been identified in Location Intelligence Perpetual Large (9DE5110-8CA13-1AX0) (All versions < V4.3), Location Intelligence Perpetual Medium (9DE5110-8CA12-1AX0) (All versions < V4.3), Location …

Feb 13, 2024
CVE-2022-48623
9.1 CRITICAL

The Cpanel::JSON::XS package before 4.33 for Perl performs out-of-bounds accesses in a way that allows attackers to obtain sensitive information or cause a denial of …

Feb 13, 2024
CVE-2024-22131
9.1 CRITICAL

In SAP ABA (Application Basis) - versions 700, 701, 702, 731, 740, 750, 751, 752, 75C, 75I, an attacker authenticated as a user with a …

Feb 13, 2024
CVE-2023-42374
9.8 CRITICAL

An issue in mystenlabs Sui Blockchain before v.1.6.3 allow a remote attacker to execute arbitrary code and cause a denial of service via a crafted …

Feb 13, 2024
CVE-2024-23763
9.8 CRITICAL

SQL Injection vulnerability in Gambio through 4.9.2.0 allows attackers to run arbitrary SQL commands via crafted GET request using modifiers[attribute][] parameter.

Feb 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.