CVE Database

39807+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-45891
8.0 HIGH

DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `delete_wlan_profile.`

Nov 4, 2024
CVE-2024-45890
8.0 HIGH

DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `download_ovpn.`

Nov 4, 2024
CVE-2024-45889
8.0 HIGH

DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `commandTable.`

Nov 4, 2024
CVE-2024-45888
8.0 HIGH

DrayTek Vigor3900 1.5.1.3 contains a command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `set_ap_map_config.'

Nov 4, 2024
CVE-2024-45887
8.0 HIGH

DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `doOpenVPN.`

Nov 4, 2024
CVE-2024-45885
8.0 HIGH

DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `autodiscovery_clear.`

Nov 4, 2024
CVE-2024-45884
8.0 HIGH

DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `setSWMGroup.`

Nov 4, 2024
CVE-2024-45882
8.0 HIGH

DrayTek Vigor3900 1.5.1.3 contains a command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `delete_map_profile.`

Nov 4, 2024
CVE-2024-51672
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPDeveloper BetterLinks betterlinks allows SQL Injection.This issue affects BetterLinks: from n/a …

Nov 4, 2024
CVE-2024-51582
7.5 HIGH

Path Traversal: '.../...//' vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows PHP Local File Inclusion.This issue affects WP Hotel Booking: from n/a through <= 2.2.9.

Nov 4, 2024
CVE-2024-51408
8.5 HIGH

AppSmith Community 1.8.3 before 1.46 allows SSRF via New DataSource for application/json requests to 169.254.169.254 to retrieve AWS metadata credentials.

Nov 4, 2024
CVE-2024-51253
8.0 HIGH

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doL2TP function.

Nov 4, 2024
CVE-2024-51251
8.0 HIGH

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the backup function.

Nov 4, 2024
CVE-2024-51249
8.0 HIGH

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the reboot function.

Nov 4, 2024
CVE-2024-51246
8.0 HIGH

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPTP function.

Nov 4, 2024
CVE-2024-50528
7.5 HIGH

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Retrieve Embedded Sensitive Data.This issue affects …

Nov 4, 2024
CVE-2024-45164
7.1 HIGH

Akamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the latest 19.2.0 patch and Apps Portal before 19.2.0.3 or 19.2.0.20240814, …

Nov 4, 2024
CVE-2024-51561
7.5 HIGH

This vulnerability exists in Aero due to improper implementation of OTP validation mechanism in certain API endpoints. An authenticated remote attacker could exploit this vulnerability …

Nov 4, 2024
CVE-2024-36485
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to SQL Injection in Technician reports option.

Nov 4, 2024
CVE-2024-48878
8.3 HIGH

Zohocorp ManageEngine ADManager Plus versions 7241 and prior are vulnerable to SQL Injection in Archived Audit Report.

Nov 4, 2024
CVE-2024-10389
7.5 HIGH

There exists a Path Traversal vulnerability in Safearchive on Platforms with Case-Insensitive Filesystems (e.g., NTFS). This allows Attackers to Write Arbitrary Files via Archive Extraction …

Nov 4, 2024
CVE-2024-38424
7.8 HIGH

Memory corruption during GNSS HAL process initialization.

Nov 4, 2024
CVE-2024-38423
7.8 HIGH

Memory corruption while processing GPU page table switch.

Nov 4, 2024
CVE-2024-38422
7.8 HIGH

Memory corruption while processing voice packet with arbitrary data received from ADSP.

Nov 4, 2024
CVE-2024-38421
7.8 HIGH

Memory corruption while processing GPU commands.

Nov 4, 2024
CVE-2024-38419
7.8 HIGH

Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node.

Nov 4, 2024
CVE-2024-38415
7.8 HIGH

Memory corruption while handling session errors from firmware.

Nov 4, 2024
CVE-2024-38410
7.8 HIGH

Memory corruption while IOCLT is called when device is in invalid state and the WMI command buffer may be freed twice.

Nov 4, 2024
CVE-2024-38409
7.8 HIGH

Memory corruption while station LL statistic handling.

Nov 4, 2024
CVE-2024-38408
8.2 HIGH

Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.

Nov 4, 2024
CVE-2024-38407
7.8 HIGH

Memory corruption while processing input parameters for any IOCTL call in the JPEG Encoder driver.

Nov 4, 2024
CVE-2024-38406
7.8 HIGH

Memory corruption while handling IOCTL calls in JPEG Encoder driver.

Nov 4, 2024
CVE-2024-38405
7.5 HIGH

Transient DOS while processing the CU information from RNR IE.

Nov 4, 2024
CVE-2024-38403
7.5 HIGH

Transient DOS while parsing BTM ML IE when per STA profile is not included.

Nov 4, 2024
CVE-2024-33068
7.5 HIGH

Transient DOS while parsing fragments of MBSSID IE from beacon frame.

Nov 4, 2024
CVE-2024-23385
7.5 HIGH

Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.

Nov 4, 2024
CVE-2024-10758
7.3 HIGH

A vulnerability, which was classified as critical, was found in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. This affects an unknown part of the file …

Nov 4, 2024
CVE-2024-20104
8.4 HIGH

In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Nov 4, 2024
CVE-2024-10752
7.3 HIGH

A vulnerability was found in Codezips Pet Shop Management System 1.0. It has been classified as critical. This affects an unknown part of the file …

Nov 4, 2024
CVE-2024-10741
7.3 HIGH

A vulnerability has been found in code-projects E-Health Care System 1.0 and classified as critical. This vulnerability affects unknown code of the file /Users/registration.php. The …

Nov 3, 2024
CVE-2024-10739
7.3 HIGH

A vulnerability, which was classified as critical, has been found in code-projects E-Health Care System 1.0. Affected by this issue is some unknown functionality of …

Nov 3, 2024
CVE-2024-10737
7.3 HIGH

A vulnerability classified as critical has been found in Codezips Free Exam Hall Seating Management System 1.0. Affected is an unknown function of the file …

Nov 3, 2024
CVE-2024-10736
7.3 HIGH

A vulnerability was found in Codezips Free Exam Hall Seating Management System 1.0. It has been rated as critical. This issue affects some unknown processing …

Nov 3, 2024
CVE-2024-10733
7.3 HIGH

A vulnerability was found in code-projects Restaurant Order System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Nov 3, 2024
CVE-2024-10702
7.3 HIGH

A vulnerability classified as critical has been found in code-projects Simple Car Rental System 1.0. Affected is an unknown function of the file /signup.php. The …

Nov 2, 2024
CVE-2024-10699
7.3 HIGH

A vulnerability was found in code-projects Wazifa System 1.0. It has been classified as critical. This affects an unknown part of the file /controllers/logincontrol.php. The …

Nov 2, 2024
CVE-2024-10698
8.8 HIGH

A vulnerability was found in Tenda AC6 15.03.05.19 and classified as critical. Affected by this issue is the function formSetDeviceName of the file /goform/SetOnlineDevName. The …

Nov 2, 2024
CVE-2024-51774
8.1 HIGH

qBittorrent before 5.0.1 proceeds with use of https URLs even after certificate validation errors.

Nov 2, 2024
CVE-2024-9191
7.1 HIGH

The Okta Device Access features, provided by the Okta Verify agent for Windows, provides access to the OktaDeviceAccessPipe, which enables attackers in a compromised device …

Nov 1, 2024
CVE-2024-48353
7.5 HIGH

Yealink Meeting Server before V26.0.0.67 allows attackers to obtain static key information from a front-end JS file and decrypt the plaintext passwords based on the …

Nov 1, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.