CVE Database

39716+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-48288
8.0 HIGH

TP-Link TL-IPC42C V4.0_20211227_1.0.16 is vulnerable to command injection due to the lack of malicious code verification on both the frontend and backend.

Nov 21, 2024
CVE-2024-48286
8.0 HIGH

Linksys E3000 1.0.06.002_US is vulnerable to command injection via the diag_ping_start function.

Nov 21, 2024
CVE-2024-52803
7.5 HIGH

LLama Factory enables fine-tuning of large language models. A critical remote OS command injection vulnerability has been identified in the LLama Factory training process. This …

Nov 21, 2024
CVE-2024-52799
8.2 HIGH

Argo Workflows Chart is used to set up argo and its needed dependencies through one command. Prior to 0.44.0, the workflow-role has excessive privileges, the …

Nov 21, 2024
CVE-2024-53429
7.5 HIGH

Open62541 v1.4.6 is has an assertion failure in fuzz_binary_decode, which leads to a crash.

Nov 21, 2024
CVE-2024-28027
7.2 HIGH

Three OS command injection vulnerabilities exist in the web interface I/O configuration functionality of MC Technologies MC LR Router 2.10.5. A specially crafted HTTP request …

Nov 21, 2024
CVE-2024-28026
7.2 HIGH

Three OS command injection vulnerabilities exist in the web interface I/O configuration functionality of MC Technologies MC LR Router 2.10.5. A specially crafted HTTP request …

Nov 21, 2024
CVE-2024-28025
7.2 HIGH

Three OS command injection vulnerabilities exist in the web interface I/O configuration functionality of MC Technologies MC LR Router 2.10.5. A specially crafted HTTP request …

Nov 21, 2024
CVE-2024-21786
7.2 HIGH

An OS command injection vulnerability exists in the web interface configuration upload functionality of MC Technologies MC LR Router 2.10.5. A specially crafted HTTP request …

Nov 21, 2024
CVE-2024-11592
7.3 HIGH

A vulnerability has been found in 1000 Projects Beauty Parlour Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file …

Nov 21, 2024
CVE-2024-7026
7.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Teknogis Informatics Closed Circuit Vehicle Tracking Software allows SQL Injection, Blind …

Nov 21, 2024
CVE-2024-11591
7.3 HIGH

A vulnerability, which was classified as critical, was found in 1000 Projects Beauty Parlour Management System 1.0. This affects an unknown part of the file …

Nov 21, 2024
CVE-2024-11590
7.3 HIGH

A vulnerability, which was classified as critical, has been found in 1000 Projects Bookstore Management System 1.0. Affected by this issue is some unknown functionality …

Nov 21, 2024
CVE-2024-7517
7.8 HIGH

A command injection vulnerability in Brocade Fabric OS before 9.2.0c, and 9.2.1 through 9.2.1a on IP extension platforms could allow a local authenticated attacker to …

Nov 21, 2024
CVE-2024-11596
7.8 HIGH

ECMP dissector crash in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture file

Nov 21, 2024
CVE-2024-11595
7.8 HIGH

FiveCo RAP dissector infinite loop in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture file

Nov 21, 2024
CVE-2024-11409
7.2 HIGH

The Grid View Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0 via deserialization of untrusted …

Nov 21, 2024
CVE-2024-10898
8.8 HIGH

The Contact Form 7 Email Add on plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.9 via …

Nov 21, 2024
CVE-2024-10788
7.2 HIGH

The Activity Log – Monitor & Record User Changes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the event parameters in all versions …

Nov 21, 2024
CVE-2024-10403
7.5 HIGH

Brocade Fabric OS versions before 8.2.3e2, versions 9.0.0 through 9.2.0c, and 9.2.1 through 9.2.1a can capture the SFTP/FTP server password used for a firmware download …

Nov 21, 2024
CVE-2024-10400
7.5 HIGH

The Tutor LMS plugin for WordPress is vulnerable to SQL Injection via the ‘rating_filter’ parameter in all versions up to, and including, 2.7.6 due to …

Nov 21, 2024
CVE-2024-9875
7.1 HIGH

Okta Privileged Access server agent (SFTD) versions 1.82.0 to 1.84.0 are affected by a privilege escalation vulnerability when the sudo command bundles feature is enabled. …

Nov 21, 2024
CVE-2024-52581
7.5 HIGH

Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 2.13.0, the multipart form parser shipped with litestar expects the entire request body …

Nov 20, 2024
CVE-2024-48986
7.5 HIGH

An issue was discovered in MBed OS 6.16.0. Its hci parsing software dynamically determines the length of certain hci packets by reading a byte from …

Nov 20, 2024
CVE-2024-48982
7.5 HIGH

An issue was discovered in MBed OS 6.16.0. Its hci parsing software dynamically determines the length of certain hci packets by reading a byte from …

Nov 20, 2024
CVE-2024-48536
7.5 HIGH

Incorrect access control in eSoft Planner 3.24.08271-USA allow attackers to view all transactions performed by the company via supplying a crafted web request.

Nov 20, 2024
CVE-2024-48530
7.5 HIGH

An issue in the Instructor Appointment Availability module of eSoft Planner 3.24.08271-USA allows attackers to cause a Denial of Service (DoS) via a crafted POST …

Nov 20, 2024
CVE-2024-48985
7.5 HIGH

An issue was discovered in MBed OS 6.16.0. During processing of HCI packets, the software dynamically determines the length of the packet data by reading …

Nov 20, 2024
CVE-2024-48983
7.5 HIGH

An issue was discovered in MBed OS 6.16.0. During processing of HCI packets, the software dynamically determines the length of the packet data by reading …

Nov 20, 2024
CVE-2024-48981
7.5 HIGH

An issue was discovered in MBed OS 6.16.0. During processing of HCI packets, the software dynamically determines the length of the packet header by looking …

Nov 20, 2024
CVE-2024-52739
8.0 HIGH

D-LINK DI-8400 v16.07.26A1 was discovered to contain multiple remote command execution (RCE) vulnerabilities in the msp_info_htm function via the flag and cmd parameters.

Nov 20, 2024
CVE-2018-9484
7.5 HIGH

In l2cu_send_peer_config_rej of l2c_utils.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure …

Nov 20, 2024
CVE-2018-9477
7.8 HIGH

In the development options section of the Settings app, there is a possible authentication bypass due to a missing permission check. This could lead to …

Nov 20, 2024
CVE-2018-9475
8.8 HIGH

In HeadsetInterface::ClccResponse of btif_hf.cc, there is a possible out of bounds stack write due to a missing bounds check. This could lead to remote escalation …

Nov 20, 2024
CVE-2018-9474
7.8 HIGH

In writeToParcel of MediaPlayer.java, there is a possible serialization/deserialization mismatch due to improper input validation. This could lead to local escalation of privilege with no …

Nov 20, 2024
CVE-2018-9472
8.8 HIGH

In xmlMemStrdupLoc of xmlmemory.c, there is a possible out-of-bounds write due to an integer overflow. This could lead to remote code execution in an unprivileged …

Nov 20, 2024
CVE-2018-9471
7.8 HIGH

In the deserialization constructor of NanoAppFilter.java, there is a possible loss of data due to type confusion. This could lead to local escalation of privilege …

Nov 20, 2024
CVE-2018-9470
8.8 HIGH

In bff_Scanner_addOutPos of Scanner.c, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege in …

Nov 20, 2024
CVE-2024-52769
7.2 HIGH

An arbitrary file upload vulnerability in the component /admin/friendlink_edit of DedeBIZ v6.3.0 allows attackers to execute arbitrary code via uploading a crafted file.

Nov 20, 2024
CVE-2024-51163
7.5 HIGH

A Local File Inclusion vulnerability in Vegam Solutions Vegam 4i versions 6.3.47.0 and earlier allows a remote attacker to obtain sensitive information through the print …

Nov 20, 2024
CVE-2024-51162
8.8 HIGH

An issue in Audimex EE versions 15.1.20 and earlier allowing a remote attacker to escalate privileges. Analyzing the offline client code, it was identified that …

Nov 20, 2024
CVE-2018-9469
7.8 HIGH

In multiple functions of ShortcutService.java, there is a possible creation of a spoofed shortcut due to a missing permission check. This could lead to local …

Nov 20, 2024
CVE-2018-9468
7.1 HIGH

In query of DownloadManager.java, there is a possible read/write of arbitrary files due to a permissions bypass. This could lead to local information disclosure and …

Nov 20, 2024
CVE-2024-52598
7.5 HIGH

2FAuth is a web app to manage Two-Factor Authentication (2FA) accounts and generate their security codes. Two interconnected vulnerabilities exist in version 5.4.1 a SSRF …

Nov 20, 2024
CVE-2024-52473
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sandeep Verma HTML5 Lyrics Karaoke Player html5-lyrics-karaoke-player allows Reflected XSS.This issue affects HTML5 …

Nov 20, 2024
CVE-2024-52472
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Weather Atlas Weather Atlas Widget weather-atlas allows Reflected XSS.This issue affects Weather Atlas …

Nov 20, 2024
CVE-2024-52471
7.1 HIGH

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in petesheppard84 Extensions for Elementor allows Reflected XSS.This issue affects Extensions for …

Nov 20, 2024
CVE-2024-52470
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brainvireinfo Dynamic URL SEO dynamic-url-seo allows Reflected XSS.This issue affects Dynamic URL SEO: …

Nov 20, 2024
CVE-2024-51208
7.2 HIGH

File Upload vulnerability in change-image.php in Anuj Kumar's Boat Booking System version 1.0 allows local attackers to upload a malicious PHP script via the Image …

Nov 20, 2024
CVE-2024-10913
8.8 HIGH

The Clone plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.4.6 via deserialization of untrusted input in …

Nov 20, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.