CVE Database

11843+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-24543
9.8 CRITICAL

Buffer Overflow vulnerability in the function setSchedWifi in Tenda AC9 v.3.0, firmware version v.15.03.06.42_multi allows a remote attacker to cause a denial of service or …

Feb 5, 2024
CVE-2023-51951
9.8 CRITICAL

SQL Injection vulnerability in Stock Management System 1.0 allows a remote attacker to execute arbitrary code via the id parameter in the manage_bo.php file.

Feb 5, 2024
CVE-2024-23054
9.8 CRITICAL

An issue in Plone Docker Official Image 5.2.13 (5221) open-source software that could allow for remote code execution due to a package listed in ++plone++static/components …

Feb 5, 2024
CVE-2024-0323
9.8 CRITICAL

The FTP server used on the B&R Automation Runtime supports unsecure encryption mechanisms, such as SSLv3, TLSv1.0 and TLS1.1. An network-based attacker can exploit the …

Feb 5, 2024
CVE-2024-23109
10.0 CRITICAL

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands …

Feb 5, 2024
CVE-2024-23108
10.0 CRITICAL

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands …

Feb 5, 2024
CVE-2021-4436
9.8 CRITICAL

The 3DPrint Lite WordPress plugin before 1.9.1.5 does not have any authorisation and does not check the uploaded file in its p3dlite_handle_upload AJAX action , …

Feb 5, 2024
CVE-2023-7077
9.8 CRITICAL

Sharp NEC Displays (P403, P463, P553, P703, P801, X554UN, X464UN, X554UNS, X464UNV, X474HB, X464UNS, X554UNV, X555UNS, X555UNV, X754HB, X554HB, E705, E805, E905, UN551S, UN551VS, X551UHD, …

Feb 5, 2024
CVE-2024-20011
9.8 CRITICAL

In alac decoder, there is a possible information disclosure due to an incorrect bounds check. This could lead to remote code execution with no additional …

Feb 5, 2024
CVE-2024-25089
9.8 CRITICAL

Malwarebytes Binisoft Windows Firewall Control before 6.9.9.2 allows remote attackers to execute arbitrary code via gRPC named pipes.

Feb 4, 2024
CVE-2020-36773
9.8 CRITICAL

Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) because a single character code in a PDF document can map …

Feb 4, 2024
CVE-2024-24029
9.8 CRITICAL

JFinalCMS 5.0.0 is vulnerable to SQL injection via /admin/content/data.

Feb 2, 2024
CVE-2024-22108
9.8 CRITICAL

An issue was discovered in GTB Central Console 15.17.1-30814.NG. The method setTermsHashAction at /opt/webapp/lib/PureApi/CCApi.class.php is vulnerable to an unauthenticated SQL injection via /ccapi.php that an …

Feb 2, 2024
CVE-2023-45025
9.0 CRITICAL

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands …

Feb 2, 2024
CVE-2022-34381
9.1 CRITICAL

Dell BSAFE SSL-J version 7.0 and all versions prior to 6.5, and Dell BSAFE Crypto-J versions prior to 6.2.6.1 contain an unmaintained third-party component vulnerability. …

Feb 2, 2024
CVE-2023-6675
9.8 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in National Keep Cyber Security Services CyberMath allows Upload a Web Shell to a Web Server.This issue …

Feb 2, 2024
CVE-2023-47143
10.0 CRITICAL

IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. …

Feb 2, 2024
CVE-2023-50488
9.8 CRITICAL

An issue in Blurams Lumi Security Camera (A31C) v23.0406.435.4120 allows attackers to execute arbitrary code.

Feb 2, 2024
CVE-2024-23978
9.8 CRITICAL

Heap-based buffer overflow vulnerability exists in HOME SPOT CUBE2 V102 and earlier. By processing invalid values, arbitrary code may be executed. Note that the affected …

Feb 2, 2024
CVE-2024-1143
9.3 CRITICAL

Central Dogma versions prior to 0.64.1 is vulnerable to Cross-Site Scripting (XSS), which could allow for the leakage of user sessions and subsequent authentication bypass.

Feb 2, 2024
CVE-2024-24482
9.8 CRITICAL

Aprktool before 2.9.3 on Windows allows ../ and /.. directory traversal.

Feb 2, 2024
CVE-2024-22533
9.8 CRITICAL

Before Beetl v3.15.12, the rendering template has a server-side template injection (SSTI) vulnerability. When the incoming template is controllable, it will be filtered by the …

Feb 2, 2024
CVE-2024-22320
9.8 CRITICAL

IBM Operational Decision Manager 8.10.3 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unsafe deserialization. By sending …

Feb 2, 2024
CVE-2024-23746
9.8 CRITICAL

Miro Desktop 0.8.18 on macOS allows local Electron code injection via a complex series of steps that might be usable in some environments (bypass a …

Feb 2, 2024
CVE-2024-22902
9.8 CRITICAL

Vinchin Backup & Recovery v7.2 was discovered to be configured with default root credentials.

Feb 2, 2024
CVE-2024-22901
9.8 CRITICAL

Vinchin Backup & Recovery v7.2 was discovered to use default MYSQL credentials.

Feb 2, 2024
CVE-2023-48793
9.8 CRITICAL

Zoho ManageEngine ADAudit Plus through 7250 allows SQL Injection in the aggregate report feature.

Feb 2, 2024
CVE-2023-48792
9.8 CRITICAL

Zoho ManageEngine ADAudit Plus through 7250 is vulnerable to SQL Injection in the report export option.

Feb 2, 2024
CVE-2024-21764
9.8 CRITICAL

In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the product uses hard-coded credentials, which may allow an attacker to connect to a …

Feb 2, 2024
CVE-2023-49617
10.0 CRITICAL

The MachineSense application programmable interface (API) is improperly protected and can be accessed without authentication. A remote attacker could retrieve and modify sensitive information without …

Feb 1, 2024
CVE-2023-46706
9.1 CRITICAL

Multiple MachineSense devices have credentials unable to be changed by the user or administrator.

Feb 1, 2024
CVE-2024-1039
9.8 CRITICAL

Gessler GmbH WEB-MASTER has a restoration account that uses weak hard coded credentials and if exploited could allow an attacker control over the web management …

Feb 1, 2024
CVE-2023-4472
9.8 CRITICAL

Objectplanet Opinio version 7.22 and prior uses a cryptographically weak pseudo-random number generator (PRNG) coupled to a predictable seed, which could lead to an unauthenticated …

Feb 1, 2024
CVE-2023-5841
9.1 CRITICAL

Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing …

Feb 1, 2024
CVE-2024-24561
9.8 CRITICAL

Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. In versions 0.3.10 and earlier, the bounds check for slices does not account …

Feb 1, 2024
CVE-2024-23832
9.4 CRITICAL

Mastodon is a free, open-source social network server based on ActivityPub Mastodon allows configuration of LDAP for authentication. Due to insufficient origin validation in all …

Feb 1, 2024
CVE-2024-23653
9.8 CRITICAL

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. In addition to running containers as build …

Jan 31, 2024
CVE-2024-23652
10.0 CRITICAL

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A malicious BuildKit frontend or Dockerfile using …

Jan 31, 2024
CVE-2022-47072
9.8 CRITICAL

SQL injection vulnerability in Enterprise Architect 16.0.1605 32-bit allows attackers to run arbitrary SQL commands via the Find parameter in the Select Classifier dialog box..

Jan 31, 2024
CVE-2024-21917
9.8 CRITICAL

A vulnerability exists in Rockwell Automation FactoryTalk® Service Platform that allows a malicious user to obtain the service token and use it for authentication on …

Jan 31, 2024
CVE-2024-23745
9.8 CRITICAL

In Notion Web Clipper 1.0.3(7), a .nib file is susceptible to the Dirty NIB attack. NIB files can be manipulated to execute arbitrary commands. Additionally, …

Jan 31, 2024
CVE-2023-5389
9.1 CRITICAL

An attacker could potentially exploit this vulnerability, leading to the ability to modify files on Honeywell Experion ControlEdge VirtualUOC and ControlEdge UOC . This exploit …

Jan 30, 2024
CVE-2024-24333
9.8 CRITICAL

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the desc parameter in the setWiFiAclRules function.

Jan 30, 2024
CVE-2024-24332
9.8 CRITICAL

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the url parameter in the setUrlFilterRules function.

Jan 30, 2024
CVE-2024-24331
9.8 CRITICAL

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setWiFiScheduleCfg function.

Jan 30, 2024
CVE-2024-24330
9.8 CRITICAL

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the port or enable parameter in the setRemoteCfg function.

Jan 30, 2024
CVE-2024-24329
9.8 CRITICAL

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setPortForwardRules function.

Jan 30, 2024
CVE-2024-24328
9.8 CRITICAL

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the enable parameter in the setMacFilterRules function.

Jan 30, 2024
CVE-2024-24327
9.8 CRITICAL

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the pppoePass parameter in the setIpv6Cfg function.

Jan 30, 2024
CVE-2024-24326
9.8 CRITICAL

TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the arpEnable parameter in the setStaticDhcpRules function.

Jan 30, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.