CVE Database

39807+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-48280
7.6 HIGH

A SQL Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers to execute …

Oct 15, 2024
CVE-2024-48279
7.6 HIGH

A HTML Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Management System 3.2. This vulnerability allows remote attackers to …

Oct 15, 2024
CVE-2024-49387
7.5 HIGH

Cleartext transmission of sensitive information in acep-collector service. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 38690.

Oct 15, 2024
CVE-2024-45276
7.5 HIGH

An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication.

Oct 15, 2024
CVE-2024-45273
8.4 HIGH

An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used.

Oct 15, 2024
CVE-2024-45272
7.5 HIGH

An unauthenticated remote attacker can perform a brute-force attack on the credentials of the remote service portal with a high chance of success, resulting in …

Oct 15, 2024
CVE-2024-45271
8.4 HIGH

An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation.

Oct 15, 2024
CVE-2024-9983
7.5 HIGH

Enterprise Cloud Database from Ragic does not properly validate a specific page parameter, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system …

Oct 15, 2024
CVE-2024-9981
8.8 HIGH

The ee-class from FormosaSoft does not properly validate a specific page parameter, allowing remote attackers with regular privileges to upload a malicious PHP file first …

Oct 15, 2024
CVE-2024-9980
8.8 HIGH

The ee-class from FormosaSoft does not properly validate a specific page parameter, allowing remote attackers with regular privileges to inject arbitrary SQL commands to read, …

Oct 15, 2024
CVE-2024-9837
7.3 HIGH

The The AADMY – Add Auto Date Month Year Into Posts plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, …

Oct 15, 2024
CVE-2024-46898
7.5 HIGH

SHIRASAGI prior to v1.19.1 processes URLs in HTTP requests improperly, resulting in a path traversal vulnerability. If this vulnerability is exploited, arbitrary files on the …

Oct 15, 2024
CVE-2024-9971
8.8 HIGH

The specific query functionality in the FlowMaster BPM Plus from NewType does not properly restrict user input, allowing remote attackers with regular privileges to inject …

Oct 15, 2024
CVE-2024-9970
8.8 HIGH

The FlowMaster BPM Plus system from NewType has a privilege escalation vulnerability. Remote attackers with regular privileges can elevate their privileges to administrator by tampering …

Oct 15, 2024
CVE-2024-9968
8.8 HIGH

WebEIP v3.0 from NewType does not properly validate user input, allowing remote attackers with regular privilege to inject SQL commands to read, modify, and delete …

Oct 15, 2024
CVE-2024-9687
8.8 HIGH

The WP 2FA with Telegram plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 3.0. This is due to insufficient …

Oct 15, 2024
CVE-2024-9548
7.2 HIGH

The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the resource parameter in all versions up to, and including, 5.2.6 due …

Oct 15, 2024
CVE-2024-35520
8.4 HIGH

Netgear R7000 1.0.11.136 is vulnerable to Command Injection in RMT_invite.cgi via device_name2 parameter.

Oct 14, 2024
CVE-2024-35519
8.4 HIGH

Netgear EX6120 v1.0.0.68, Netgear EX6100 v1.0.2.28, and Netgear EX3700 v1.0.0.96 are vulnerable to command injection in operating_mode.cgi via the ap_mode parameter.

Oct 14, 2024
CVE-2024-35518
8.4 HIGH

Netgear EX6120 v1.0.0.68 is vulnerable to Command Injection in genie_fix2.cgi via the wan_dns1_pri parameter.

Oct 14, 2024
CVE-2024-6207
7.5 HIGH

CVE 2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html and send a specially crafted CIP message to the device. If exploited, a threat actor could help prevent access to the legitimate …

Oct 14, 2024
CVE-2024-48911
7.8 HIGH

OpenCanary, a multi-protocol network honeypot, directly executed commands taken from its config file. Prior to version 0.9.4, where the config file is stored in an …

Oct 14, 2024
CVE-2024-48824
7.5 HIGH

An issue in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a remote attacker to obtain sensitive information via the Racine & FileName parameters in the download-file.php …

Oct 14, 2024
CVE-2024-48822
8.8 HIGH

Privilege escalation in Automatic Systems Maintenance SlimLane 29565_d74ecce0c1081d50546db573a499941b10799fb7 allows a remote attacker to escalate privileges via the FtpConfig.php page.

Oct 14, 2024
CVE-2024-48792
7.5 HIGH

An issue in Hideez com.hideez 2.7.8.3 allows a remote attacker to obtain sensitive information via the firmware update process.

Oct 14, 2024
CVE-2024-48791
7.5 HIGH

An issue in Plug n Play Camera com.starvedia.mCamView.zwave 5.5.1 allows a remote attacker to obtain sensitive information via the firmware update process

Oct 14, 2024
CVE-2024-48789
7.5 HIGH

An issue in INATRONIC com.inatronic.drivedeck.home 2.6.23 allows a remote attacker to obtain sensitve information via the firmware update process.

Oct 14, 2024
CVE-2024-48799
7.5 HIGH

An issue in LOREX TECHNOLOGY INC com.lorexcorp.lorexping 1.4.22 allows a remote attacker to obtain sensitive information via the firmware update process.

Oct 14, 2024
CVE-2024-48798
7.5 HIGH

An issue in Hubble Connected (com.hubbleconnected.vervelife) 2.00.81 allows a remote attacker to obtain sensitive information via the firmware update process.

Oct 14, 2024
CVE-2024-48797
7.5 HIGH

An issue in PCS Engineering Preston Cinema (com.prestoncinema.app) 0.2.0 allows a remote attacker to obtain sensitive information via the firmware update process.

Oct 14, 2024
CVE-2024-48796
7.5 HIGH

An issue in EQUES com.eques.plug 1.0.1 allows a remote attacker to obtain sensitive information via the firmware update process.

Oct 14, 2024
CVE-2024-45733
8.8 HIGH

In Splunk Enterprise for Windows versions below 9.2.3 and 9.1.6, a low-privileged user that does not hold the "admin" or "power" Splunk roles could perform …

Oct 14, 2024
CVE-2024-45732
7.1 HIGH

In Splunk Enterprise versions below 9.3.1, and 9.2.0 versions below 9.2.3, and Splunk Cloud Platform versions below 9.2.2403.103, 9.1.2312.200, 9.1.2312.110 and 9.1.2308.208, a low-privileged user …

Oct 14, 2024
CVE-2024-45731
8.0 HIGH

In Splunk Enterprise for Windows versions below 9.3.1, 9.2.3, and 9.1.6, a low-privileged user that does not hold the "admin" or "power" Splunk roles could …

Oct 14, 2024
CVE-2023-50780
8.8 HIGH

Apache ActiveMQ Artemis allows access to diagnostic information and controls through MBeans, which are also exposed through the authenticated Jolokia endpoint. Before version 2.29.0, this …

Oct 14, 2024
CVE-2024-48259
7.3 HIGH

Cloudlog 2.6.15 allows Oqrs.php request_form SQL injection via station_id or callsign.

Oct 14, 2024
CVE-2024-48249
7.3 HIGH

Wavelog 1.8.5 allows Gridmap_model.php get_band_confirmed SQL injection via band, sat, propagation, or mode.

Oct 14, 2024
CVE-2024-7847
7.7 HIGH

VULNERABILITY DETAILS Rockwell Automation used the latest versions of the CVSS scoring system to assess the following vulnerabilities. The following vulnerabilities were reported to us …

Oct 14, 2024
CVE-2024-9139
7.2 HIGH

The affected product permits OS command injection through improperly restricted commands, potentially allowing attackers to execute arbitrary code.

Oct 14, 2024
CVE-2024-43701
7.8 HIGH

Software installed and run as a non-privileged user may conduct GPU system calls to read and write freed physical memory from the GPU.

Oct 14, 2024
CVE-2024-38863
7.5 HIGH

Exposure of CSRF tokens in query parameters on specific requests in Checkmk GmbH's Checkmk versions <2.3.0p18, <2.2.0p35 and <2.1.0p48 could lead to a leak of …

Oct 14, 2024
CVE-2024-9922
7.5 HIGH

The Team+ from TEAMPLUS TECHNOLOGY does not properly validate a specific page parameter, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system …

Oct 14, 2024
CVE-2024-8070
8.5 HIGH

CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that exposes test credentials in the firmware binary

Oct 13, 2024
CVE-2024-9916
7.3 HIGH

A vulnerability, which was classified as critical, has been found in HuangDou UTCMS V9. Affected by this issue is some unknown functionality of the file …

Oct 13, 2024
CVE-2024-9915
8.8 HIGH

A vulnerability classified as critical was found in D-Link DIR-619L B1 2.06. Affected by this vulnerability is the function formVirtualServ of the file /goform/formVirtualServ. The …

Oct 13, 2024
CVE-2024-9914
8.8 HIGH

A vulnerability classified as critical has been found in D-Link DIR-619L B1 2.06. Affected is the function formSetWizardSelectMode of the file /goform/formSetWizardSelectMode. The manipulation of …

Oct 13, 2024
CVE-2024-9913
8.8 HIGH

A vulnerability was found in D-Link DIR-619L B1 2.06. It has been rated as critical. This issue affects the function formSetRoute of the file /goform/formSetRoute. …

Oct 13, 2024
CVE-2024-9912
8.8 HIGH

A vulnerability was found in D-Link DIR-619L B1 2.06. It has been declared as critical. This vulnerability affects the function formSetQoS of the file /goform/formSetQoS. …

Oct 13, 2024
CVE-2024-9911
8.8 HIGH

A vulnerability was found in D-Link DIR-619L B1 2.06. It has been classified as critical. This affects the function formSetPortTr of the file /goform/formSetPortTr. The …

Oct 13, 2024
CVE-2024-9910
8.8 HIGH

A vulnerability was found in D-Link DIR-619L B1 2.06 and classified as critical. Affected by this issue is the function formSetPassword of the file /goform/formSetPassword. …

Oct 13, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.