CVE Database

39807+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-9567
8.8 HIGH

A vulnerability, which was classified as critical, has been found in D-Link DIR-619L B1 2.06. This issue affects the function formAdvFirewall of the file /goform/formAdvFirewall. …

Oct 7, 2024
CVE-2024-9566
8.8 HIGH

A vulnerability classified as critical was found in D-Link DIR-619L B1 2.06. This vulnerability affects the function formDeviceReboot of the file /goform/formDeviceReboot. The manipulation of …

Oct 7, 2024
CVE-2024-43047
7.8 HIGH KEV

Memory corruption while maintaining memory maps of HLOS memory.

Oct 7, 2024
CVE-2024-38399
8.4 HIGH

Memory corruption while processing user packets to generate page faults.

Oct 7, 2024
CVE-2024-38397
7.5 HIGH

Transient DOS while parsing probe response and assoc response frame.

Oct 7, 2024
CVE-2024-33073
8.2 HIGH

Information disclosure while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.

Oct 7, 2024
CVE-2024-33071
7.5 HIGH

Transient DOS while parsing the MBSSID IE from the beacons when IE length is 0.

Oct 7, 2024
CVE-2024-33070
7.5 HIGH

Transient DOS while parsing ESP IE from beacon/probe response frame.

Oct 7, 2024
CVE-2024-33069
7.5 HIGH

Transient DOS when transmission of management frame sent by host is not successful and error status is received in the host.

Oct 7, 2024
CVE-2024-33065
8.4 HIGH

Memory corruption while taking snapshot when an offset variable is set by camera driver.

Oct 7, 2024
CVE-2024-33064
8.2 HIGH

Information disclosure while parsing the multiple MBSSID IEs from the beacon.

Oct 7, 2024
CVE-2024-33049
7.5 HIGH

Transient DOS while parsing noninheritance IE of Extension element when length of IE is 2 of beacon frame.

Oct 7, 2024
CVE-2024-23369
7.8 HIGH

Memory corruption when invalid length is provided from HLOS for FRS/UDS request/response buffers.

Oct 7, 2024
CVE-2024-21455
7.8 HIGH

Memory corruption when a compat IOCTL call is followed by another IOCTL call from userspace to a driver.

Oct 7, 2024
CVE-2024-47335
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bit Apps Bit Form bit-form allows SQL Injection.This issue affects Bit …

Oct 7, 2024
CVE-2024-20094
7.5 HIGH

In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service with no additional …

Oct 7, 2024
CVE-2024-20092
7.8 HIGH

In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Oct 7, 2024
CVE-2024-9565
8.8 HIGH

A vulnerability has been found in D-Link DIR-605L 2.13B01 BETA and classified as critical. Affected by this vulnerability is the function formSetPassword of the file …

Oct 7, 2024
CVE-2024-9564
8.8 HIGH

A vulnerability, which was classified as critical, was found in D-Link DIR-605L 2.13B01 BETA. Affected is the function formWlanWizardSetup of the file /goform/formWlanWizardSetup. The manipulation …

Oct 7, 2024
CVE-2024-9563
8.8 HIGH

A vulnerability, which was classified as critical, has been found in D-Link DIR-605L 2.13B01 BETA. This issue affects the function formWlanSetup_Wizard of the file /goform/formWlanSetup_Wizard. …

Oct 7, 2024
CVE-2024-9562
8.8 HIGH

A vulnerability classified as critical was found in D-Link DIR-605L 2.13B01 BETA. This vulnerability affects the function formSetWizard1/formSetWizard2. The manipulation of the argument curTime leads …

Oct 6, 2024
CVE-2024-9561
8.8 HIGH

A vulnerability classified as critical has been found in D-Link DIR-605L 2.13B01 BETA. This affects the function formSetWAN_Wizard51/formSetWAN_Wizard52. The manipulation of the argument curTime leads …

Oct 6, 2024
CVE-2024-9559
8.8 HIGH

A vulnerability was found in D-Link DIR-605L 2.13B01 BETA. It has been classified as critical. Affected is the function formWlanSetup of the file /goform/formWlanSetup. The …

Oct 6, 2024
CVE-2024-9558
8.8 HIGH

A vulnerability was found in D-Link DIR-605L 2.13B01 BETA and classified as critical. This issue affects the function formSetWanPPTP of the file /goform/formSetWanPPTP. The manipulation …

Oct 6, 2024
CVE-2024-9557
8.8 HIGH

A vulnerability has been found in D-Link DIR-605L 2.13B01 BETA and classified as critical. This vulnerability affects the function formSetWanPPPoE of the file /goform/formSetWanPPPoE. The …

Oct 6, 2024
CVE-2024-9556
8.8 HIGH

A vulnerability, which was classified as critical, was found in D-Link DIR-605L 2.13B01 BETA. This affects the function formSetEnableWizard of the file /goform/formSetEnableWizard. The manipulation …

Oct 6, 2024
CVE-2024-9555
8.8 HIGH

A vulnerability, which was classified as critical, has been found in D-Link DIR-605L 2.13B01 BETA. Affected by this issue is the function formSetEasy_Wizard of the …

Oct 6, 2024
CVE-2024-47338
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal WPExperts Square For GiveWP wpexperts-square-for-give allows SQL Injection.This issue …

Oct 6, 2024
CVE-2024-45248
7.5 HIGH

Multi-DNC – CWE-35: Path Traversal: '.../...//'

Oct 6, 2024
CVE-2024-44029
7.1 HIGH

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in David Garlitz viala allows Reflected XSS.This issue affects viala: from n/a …

Oct 6, 2024
CVE-2024-44028
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in nicejob NiceJob nicejob allows Stored XSS.This issue affects NiceJob: from n/a through < 3.6.5.

Oct 6, 2024
CVE-2024-47322
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ex-Themes WP Timeline – Vertical and Horizontal timeline plugin wp-timelines allows Reflected XSS.This …

Oct 6, 2024
CVE-2024-47320
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mark Westguard WS Form LITE ws-form allows Stored XSS.This issue affects WS Form …

Oct 6, 2024
CVE-2024-47306
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Secure Copy Content Protection and Content Locking secure-copy-content-protection-subscribe-to-view allows Stored XSS.This …

Oct 6, 2024
CVE-2024-47301
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bit Apps Bit Form bit-form allows Stored XSS.This issue affects Bit Form: from …

Oct 6, 2024
CVE-2024-47300
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Imran Tauqeer CubeWP Forms cubewp-forms allows Stored XSS.This issue affects CubeWP Forms: from …

Oct 6, 2024
CVE-2024-47297
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codepeople CP Polls cp-polls allows Reflected XSS.This issue affects CP Polls: from n/a …

Oct 6, 2024
CVE-2024-45454
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Reflected …

Oct 6, 2024
CVE-2024-45246
7.3 HIGH

Diebold Nixdorf – CWE-427: Uncontrolled Search Path Element

Oct 6, 2024
CVE-2024-9553
8.8 HIGH

A vulnerability classified as critical has been found in D-Link DIR-605L 2.13B01 BETA. This affects the function formdumpeasysetup of the file /goform/formdumpeasysetup. The manipulation of …

Oct 6, 2024
CVE-2024-47352
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xylus Themes WP Bulk Delete wp-bulk-delete allows Stored XSS.This issue affects WP Bulk …

Oct 6, 2024
CVE-2024-47349
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Amauri WPMobile.App wpappninja.This issue affects WPMobile.App: from n/a through <= 11.50.

Oct 6, 2024
CVE-2024-47348
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YellowPencil YellowPencil Visual CSS Style Editor yellow-pencil-visual-theme-customizer allows Reflected XSS.This issue affects YellowPencil …

Oct 6, 2024
CVE-2024-47347
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Chartify chart-builder allows Reflected XSS.This issue affects Chartify: from n/a through …

Oct 6, 2024
CVE-2024-47346
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tribulant Software Newsletters newsletters-lite allows Reflected XSS.This issue affects Newsletters: from n/a through …

Oct 6, 2024
CVE-2024-47341
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lester Chan WP-DownloadManager wp-downloadmanager allows Reflected XSS.This issue affects WP-DownloadManager: from n/a through …

Oct 6, 2024
CVE-2024-47339
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in JWardee WP Mail Catcher wp-mail-catcher allows Reflected XSS.This issue affects WP Mail Catcher: …

Oct 6, 2024
CVE-2024-47333
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tangible Loops & Logic tangible-loops-and-logic allows Reflected XSS.This issue affects Loops & Logic: …

Oct 6, 2024
CVE-2024-47327
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eyal Fitoussi GEO my WordPress geo-my-wp allows Reflected XSS.This issue affects GEO my …

Oct 6, 2024
CVE-2024-47326
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ILLID Share This Image share-this-image allows Reflected XSS.This issue affects Share This Image: …

Oct 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.