CVE Database

39885+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-37335
8.8 HIGH

Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability

Sep 10, 2024
CVE-2024-30073
7.8 HIGH

Windows Security Zone Mapping Security Feature Bypass Vulnerability

Sep 10, 2024
CVE-2024-26191
8.8 HIGH

Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability

Sep 10, 2024
CVE-2024-26186
8.8 HIGH

Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability

Sep 10, 2024
CVE-2024-21416
8.1 HIGH

Windows TCP/IP Remote Code Execution Vulnerability

Sep 10, 2024
CVE-2023-6841
7.5 HIGH

A denial of service vulnerability was found in keycloak where the amount of attributes per object is not limited,an attacker by sending repeated HTTP requests …

Sep 10, 2024
CVE-2024-45592
8.2 HIGH

auditor-bundle, formerly known as DoctrineAuditBundle, integrates auditor library into any Symfony 3.4+ application. Prior to version 5.2.6, there is an unescaped entity property enabling Javascript …

Sep 10, 2024
CVE-2024-45590
7.5 HIGH

body-parser is Node.js body parsing middleware. body-parser <1.20.3 is vulnerable to denial of service when url encoding is enabled. A malicious actor using a specially …

Sep 10, 2024
CVE-2024-31960
7.8 HIGH

An issue was discovered in Samsung Mobile Processor Exynos 1480, Exynos 2400. The xclipse amdgpu driver has a reference count bug. This can lead to …

Sep 10, 2024
CVE-2023-37233
8.8 HIGH

Loftware Spectrum before 4.6 HF14 allows authenticated XXE attacks.

Sep 10, 2024
CVE-2023-37232
7.5 HIGH

Loftware Spectrum through 4.6 exposes Sensitive Information (Logs) to an Unauthorized Actor.

Sep 10, 2024
CVE-2024-45044
8.8 HIGH

Bareos is open source software for backup, archiving, and recovery of data for operating systems. When a command ACL is in place and a user …

Sep 10, 2024
CVE-2024-33508
7.3 HIGH

An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in Fortinet FortiClientEMS 7.2.0 through 7.2.4, 7.0.0 through 7.0.12 may allow …

Sep 10, 2024
CVE-2024-23185
7.5 HIGH

Very large headers can cause resource exhaustion when parsing message. The message-parser normally reads reasonably sized chunks of the message. However, when it feeds them …

Sep 10, 2024
CVE-2024-44867
7.5 HIGH

phpok v3.0 was discovered to contain an arbitrary file read vulnerability via the component /autoload/file.php.

Sep 10, 2024
CVE-2024-37728
7.5 HIGH

Arbitrary File Read vulnerability in Xi'an Daxi Information Technology Co., Ltd OfficeWeb365 v.7.18.23.0 and v8.6.1.0 allows a remote attacker to obtain sensitive information via the …

Sep 10, 2024
CVE-2023-37230
8.8 HIGH

Loftware Spectrum (testDeviceConnection) before 5.1 allows SSRF.

Sep 10, 2024
CVE-2023-37229
8.8 HIGH

Loftware Spectrum before 5.1 allows SSRF.

Sep 10, 2024
CVE-2024-7770
8.8 HIGH

The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to arbitrary file …

Sep 10, 2024
CVE-2024-44087
8.6 HIGH

A vulnerability has been identified in Automation License Manager V5 (All versions), Automation License Manager V6.0 (All versions < V6.0 SP12 Upd3), Automation License Manager …

Sep 10, 2024
CVE-2024-43647
7.5 HIGH

A vulnerability has been identified in SIMATIC S7-200 SMART CPU CR40 (6ES7288-1CR40-0AA0) (All versions), SIMATIC S7-200 SMART CPU CR60 (6ES7288-1CR60-0AA0) (All versions), SIMATIC S7-200 SMART …

Sep 10, 2024
CVE-2024-41171
8.8 HIGH

A vulnerability has been identified in SINUMERIK 828D V4 (All versions), SINUMERIK 828D V5 (All versions < V5.24), SINUMERIK 840D sl V4 (All versions), SINUMERIK …

Sep 10, 2024
CVE-2024-41170
7.8 HIGH

A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0015), Tecnomatix Plant Simulation V2404 (All versions < V2404.0004). The affected applications …

Sep 10, 2024
CVE-2024-8258
7.8 HIGH

Improper Control of Generation of Code ('Code Injection') in Electron Fuses in Logitech Options Plus version 1.60.496306 on macOS allows attackers to execute arbitrary code …

Sep 10, 2024
CVE-2024-7699
8.8 HIGH

An low privileged remote attacker can execute OS commands with root privileges due to improper neutralization of special elements in user data.

Sep 10, 2024
CVE-2024-43393
8.1 HIGH

A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the …

Sep 10, 2024
CVE-2024-43392
8.1 HIGH

A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the …

Sep 10, 2024
CVE-2024-43391
8.1 HIGH

A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the …

Sep 10, 2024
CVE-2024-43390
8.1 HIGH

A low privileged remote attacker can perform configuration changes of the firewall services, including packet forwarding or NAT through the FW_NAT.IN_IP environment variable which can …

Sep 10, 2024
CVE-2024-43389
8.1 HIGH

A low privileged remote attacker can perform configuration changes of the ospf service through OSPF_INTERFACE.SIMPLE_KEY, OSPF_INTERFACE.DIGEST_KEY environment variables which can lead to a DoS.

Sep 10, 2024
CVE-2024-43388
8.8 HIGH

A low privileged remote attacker with write permissions can reconfigure the SNMP service due to improper input validation.

Sep 10, 2024
CVE-2024-43387
8.8 HIGH

A low privileged remote attacker can read and write files as root due to improper neutralization of special elements in the variable EMAIL_RELAY_PASSWORD in mGuard …

Sep 10, 2024
CVE-2024-43386
8.8 HIGH

A low privileged remote attacker can trigger the execution of arbitrary OS commands as root due to improper neutralization of special elements in the variable …

Sep 10, 2024
CVE-2024-43385
8.8 HIGH

A low privileged remote attacker can trigger the execution of arbitrary OS commands as root due to improper neutralization of special elements in the variable …

Sep 10, 2024
CVE-2024-39583
8.1 HIGH

Dell PowerScale InsightIQ, versions 5.0 through 5.1, contains a Use of a Broken or Risky Cryptographic Algorithm vulnerability. An unauthenticated attacker with remote access could …

Sep 10, 2024
CVE-2024-39581
7.3 HIGH

Dell PowerScale InsightIQ, versions 5.0 through 5.1, contains a File or Directories Accessible to External Parties vulnerability. An unauthenticated attacker with remote access could potentially …

Sep 10, 2024
CVE-2024-42427
7.6 HIGH

Dell ThinOS versions 2402 and 2405, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with physical …

Sep 10, 2024
CVE-2024-8478
7.3 HIGH

The The Affiliate Super Assistent plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.5.3. This is due …

Sep 10, 2024
CVE-2024-8268
8.8 HIGH

The Frontend Dashboard plugin for WordPress is vulnerable to unauthorized code execution due to insufficient filtering on callable methods/functions via the ajax_request() function in all …

Sep 10, 2024
CVE-2024-6796
8.2 HIGH

In Baxter Connex health portal released before 8/30/2024, an improper access control vulnerability has been found that could allow an unauthenticated attacker to gain unauthorized …

Sep 9, 2024
CVE-2024-44725
7.2 HIGH

AutoCMS v5.4 was discovered to contain a SQL injection vulnerability via the sidebar parameter at /admin/robot.php.

Sep 9, 2024
CVE-2024-44724
7.2 HIGH

AutoCMS v5.4 was discovered to contain a PHP code injection vulnerability via the txtsite_url parameter at /admin/site_add.php. This vulnerability allows attackers to execute arbitrary PHP …

Sep 9, 2024
CVE-2024-7341
7.1 HIGH

A session fixation issue was discovered in the SAML adapters provided by Keycloak. The session ID and JSESSIONID cookie are not changed at login time, …

Sep 9, 2024
CVE-2024-45411
8.5 HIGH

Twig is a template language for PHP. Under some circumstances, the sandbox security checks are not run which allows user-contributed templates to bypass the sandbox …

Sep 9, 2024
CVE-2024-45296
7.5 HIGH

path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. …

Sep 9, 2024
CVE-2024-44335
8.8 HIGH

D-Link DI-7003G v19.12.24A1, DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution (RCE) via version_upgrade.asp.

Sep 9, 2024
CVE-2024-44334
8.8 HIGH

D-Link DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution due to insufficient parameter filtering …

Sep 9, 2024
CVE-2024-44333
8.8 HIGH

D-Link DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution. An attacker can achieve arbitrary …

Sep 9, 2024
CVE-2024-44720
7.5 HIGH

SeaCMS v13.1 was discovered to an arbitrary file read vulnerability via the component admin_safe.php.

Sep 9, 2024
CVE-2024-45041
8.3 HIGH

External Secrets Operator is a Kubernetes operator that integrates external secret management systems. The external-secrets has a deployment called default-external-secrets-cert-controller, which is bound with a …

Sep 9, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.