CVE Database

39716+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-5579
7.2 HIGH

Allegra renderFieldMatch Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Authentication …

Nov 22, 2024
CVE-2024-5513
7.8 HIGH

Kofax Power PDF JP2 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Nov 22, 2024
CVE-2024-5511
7.8 HIGH

Kofax Power PDF JP2 File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Nov 22, 2024
CVE-2024-5510
7.8 HIGH

Kofax Power PDF JP2 File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Nov 22, 2024
CVE-2024-30377
7.8 HIGH

G DATA Total Security Scan Server Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of G …

Nov 22, 2024
CVE-2024-30376
7.3 HIGH

Famatech Advanced IP Scanner Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Famatech …

Nov 22, 2024
CVE-2024-1868
7.8 HIGH

G DATA Total Security Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of G DATA Total …

Nov 22, 2024
CVE-2024-1867
7.8 HIGH

G DATA Total Security Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of G DATA Total …

Nov 22, 2024
CVE-2023-52335
7.5 HIGH

Advantech iView ConfigurationServlet SQL Injection Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Advantech iView. Authentication is …

Nov 22, 2024
CVE-2023-52333
7.3 HIGH

Allegra saveFile Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Although authentication is …

Nov 22, 2024
CVE-2023-52332
7.5 HIGH

Allegra serveMathJaxLibraries Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Allegra. Authentication is not required …

Nov 22, 2024
CVE-2023-51644
7.3 HIGH

Allegra SiteConfigAction Improper Access Control Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Authentication is …

Nov 22, 2024
CVE-2023-51635
8.8 HIGH

NETGEAR RAX30 fing_dil Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 …

Nov 22, 2024
CVE-2023-51634
7.5 HIGH

NETGEAR RAX30 Improper Certificate Validation Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of …

Nov 22, 2024
CVE-2023-39470
7.2 HIGH

PaperCut NG print.script.sandboxed Exposed Dangerous Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PaperCut NG. …

Nov 22, 2024
CVE-2024-52726
7.5 HIGH

CRMEB v5.4.0 is vulnerable to Arbitrary file read in the save_basics function which allows an attacker to obtain sensitive information

Nov 22, 2024
CVE-2024-11618
7.3 HIGH

A vulnerability classified as critical was found in IPC Unigy Management System 04.03.00.08.0027. Affected by this vulnerability is an unknown functionality of the component HTTP …

Nov 22, 2024
CVE-2024-44786
7.5 HIGH

Incorrect access control in Meabilis CMS 1.0 allows attackers to access other users' address books via unspecified vectors.

Nov 22, 2024
CVE-2024-10220
8.1 HIGH

The Kubernetes kubelet component allows arbitrary command execution via specially crafted gitRepo volumes.This issue affects kubelet: through 1.28.11, from 1.29.0 through 1.29.6, from 1.30.0 through …

Nov 22, 2024
CVE-2024-52804
7.5 HIGH

Tornado is a Python web framework and asynchronous networking library. The algorithm used for parsing HTTP cookies in Tornado versions prior to 6.4.2 sometimes has …

Nov 22, 2024
CVE-2024-52802
7.5 HIGH

RIOT is an operating system for internet of things (IoT) devices. In version 2024.04 and prior, the function `_parse_advertise`, located in `/sys/net/application_layer/dhcpv6/client.c`, has no minimum …

Nov 22, 2024
CVE-2024-50401
7.2 HIGH

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers …

Nov 22, 2024
CVE-2024-50400
7.2 HIGH

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers …

Nov 22, 2024
CVE-2024-50399
7.2 HIGH

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers …

Nov 22, 2024
CVE-2024-50398
7.2 HIGH

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers …

Nov 22, 2024
CVE-2024-50397
8.8 HIGH

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers …

Nov 22, 2024
CVE-2024-50396
8.8 HIGH

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers …

Nov 22, 2024
CVE-2024-50395
8.8 HIGH

An authorization bypass through user-controlled key vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow local network attackers to …

Nov 22, 2024
CVE-2024-48861
7.8 HIGH

An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow local network attackers to execute commands. …

Nov 22, 2024
CVE-2024-38647
7.5 HIGH

An exposure of sensitive information vulnerability has been reported to affect QNAP AI Core. If exploited, the vulnerability could allow remote attackers to compromise the …

Nov 22, 2024
CVE-2024-38644
8.8 HIGH

An OS command injection vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote authenticated attackers to execute commands. …

Nov 22, 2024
CVE-2024-37044
7.2 HIGH

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow …

Nov 22, 2024
CVE-2024-37041
7.2 HIGH

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow …

Nov 22, 2024
CVE-2023-24467
8.8 HIGH

Possible Command Injection in iManager GET parameter has been discovered in OpenText™ iManager 3.2.6.0000.

Nov 22, 2024
CVE-2023-24466
7.5 HIGH

Possible XML External Entity Injection in iManager GET parameter has been discovered in OpenText™ iManager 3.2.6.0200.

Nov 22, 2024
CVE-2022-26324
7.6 HIGH

Possible XSS in iManager URL for access Component has been discovered in OpenText™ iManager 3.2.6.0000.

Nov 22, 2024
CVE-2021-38135
8.6 HIGH

Possible External Service Interaction attack in iManager has been discovered in OpenText™ iManager 3.2.6.0000.

Nov 22, 2024
CVE-2021-38117
8.8 HIGH

Possible Command injection Vulnerability in iManager has been discovered in OpenText™ iManager 3.2.4.0000.

Nov 22, 2024
CVE-2021-38116
8.8 HIGH

Possible Elevation of Privilege Vulnerability in iManager has been discovered in OpenText™ iManager. This impacts all versions before 3.2.5

Nov 22, 2024
CVE-2024-7837
8.2 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Firmanet Software ERP allows SQL Injection.This issue affects ERP: through 22.11.2024. …

Nov 22, 2024
CVE-2024-11601
8.1 HIGH

The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart, Blog, Video Gallery) plugin for WordPress is …

Nov 22, 2024
CVE-2024-11104
8.1 HIGH

The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart, Blogs) plugin for WordPress is vulnerable to …

Nov 22, 2024
CVE-2024-31408
8.0 HIGH

OS command injection vulnerability exists in AIPHONE IX SYSTEM and IXG SYSTEM. A network-adjacent authenticated attacker may execute an arbitrary OS command with root privileges …

Nov 22, 2024
CVE-2024-52052
7.2 HIGH

Wowza Streaming Engine below 4.9.1 permits an authenticated Streaming Engine Manager administrator to define a custom application property and poison a stream target for high-privilege …

Nov 21, 2024
CVE-2024-51364
8.8 HIGH

An arbitrary file upload vulnerability in ModbusMechanic v3.0 allows attackers to execute arbitrary code via uploading a crafted .xml file.

Nov 21, 2024
CVE-2024-53095
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: smb: client: Fix use-after-free of network namespace. Recently, we got a customer report that CIFS …

Nov 21, 2024
CVE-2024-53432
7.5 HIGH

While parsing certain malformed PLY files, PCL version 1.14.1 crashes due to an uncaught std::out_of_range exception in PCLPointCloud2::at. This issue could potentially be exploited to …

Nov 21, 2024
CVE-2024-53335
7.8 HIGH

TOTOLINK A810R V4.1.2cu.5182_B20201026 is vulnerable to Buffer Overflow in downloadFlile.cgi.

Nov 21, 2024
CVE-2024-53334
8.8 HIGH

TOTOLINK A810R V4.1.2cu.5182_B20201026 is vulnerable to Buffer Overflow in infostat.cgi.

Nov 21, 2024
CVE-2024-52287
7.2 HIGH

authentik is an open-source identity provider. When using the client_credentials or device_code OAuth grants, it was possible for an attacker to get a token from …

Nov 21, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.