CVE Database

39885+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-5546
8.3 HIGH

Zohocorp ManageEngine Password Manager Pro versions before 12431 and ManageEngine PAM360 versions before 7001 are affected by authenticated SQL Injection vulnerability via a global search …

Aug 28, 2024
CVE-2023-26324
8.8 HIGH

A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit …

Aug 28, 2024
CVE-2023-26323
7.6 HIGH

A code execution vulnerability exists in the Xiaomi App market product. The vulnerability is caused by unsafe configuration and can be exploited by attackers to …

Aug 28, 2024
CVE-2023-26322
8.8 HIGH

A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit …

Aug 28, 2024
CVE-2024-6311
7.2 HIGH

The Funnelforms Free plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'af2_add_font' function in all versions …

Aug 28, 2024
CVE-2024-4555
7.7 HIGH

Improper Privilege Management vulnerability in OpenText NetIQ Access Manager allows user account impersonation in specific scenario. This issue affects NetIQ Access Manager before 5.0.4.1 and …

Aug 28, 2024
CVE-2024-4554
7.3 HIGH

Improper Input Validation vulnerability in OpenText NetIQ Access Manager leads to Cross-Site Scripting (XSS) attack. This issue affects Access Manager before 5.0.4.1 and 5.1.

Aug 28, 2024
CVE-2024-45346
8.8 HIGH

The Xiaomi Security Center expresses heartfelt thanks to Ken Gannon and Ilyes Beghdadi of NCC Group working with Trend Micro Zero Day Initiative! At the …

Aug 28, 2024
CVE-2021-38121
8.3 HIGH

Insufficient or weak TLS protocol version identified in Advance authentication client server communication when specific service is accessed between devices. This issue affects NetIQ Advance …

Aug 28, 2024
CVE-2021-22530
8.2 HIGH

A vulnerability identified in NetIQ Advance Authentication that doesn't enforce account lockout when brute force attack is performed on API based login. This issue may …

Aug 28, 2024
CVE-2021-22509
8.1 HIGH

A vulnerability identified in storing and reusing information in Advance Authentication. This issue can lead to leakage of sensitive data to unauthorized user. The issue …

Aug 28, 2024
CVE-2024-39584
8.2 HIGH

Dell Client Platform BIOS contains a Use of Default Cryptographic Key Vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading …

Aug 28, 2024
CVE-2023-45896
7.1 HIGH

ntfs3 in the Linux kernel through 6.8.0 allows a physically proximate attacker to read kernel memory by mounting a filesystem (e.g., if a Linux distribution …

Aug 28, 2024
CVE-2024-8231
8.8 HIGH

A vulnerability classified as critical has been found in Tenda O6 1.0.0.7(2054). Affected is the function fromVirtualSet of the file /goform/setPortForward. The manipulation of the …

Aug 28, 2024
CVE-2024-8230
8.8 HIGH

A vulnerability was found in Tenda O6 1.0.0.7(2054). It has been rated as critical. This issue affects the function fromSafeSetMacFilter of the file /goform/setMacFilterList. The …

Aug 28, 2024
CVE-2024-8229
8.8 HIGH

A vulnerability was found in Tenda O6 1.0.0.7(2054). It has been declared as critical. This vulnerability affects the function frommacFilterModify of the file /goform/operateMacFilter. The …

Aug 28, 2024
CVE-2024-8228
8.8 HIGH

A vulnerability was found in Tenda O5 1.0.0.8(5017). It has been classified as critical. This affects the function fromSafeSetMacFilter of the file /goform/setMacFilterList. The manipulation …

Aug 28, 2024
CVE-2024-8227
8.8 HIGH

A vulnerability was found in Tenda O1 1.0.0.7(10648) and classified as critical. Affected by this issue is the function fromDhcpSetSer of the file /goform/DhcpSetSer. The …

Aug 28, 2024
CVE-2024-8226
8.8 HIGH

A vulnerability has been found in Tenda O1 1.0.0.7(10648) and classified as critical. Affected by this vulnerability is the function formSetCfm of the file /goform/setcfm. …

Aug 28, 2024
CVE-2024-8225
8.8 HIGH

A vulnerability, which was classified as critical, was found in Tenda G3 15.11.0.20. Affected is the function formSetSysTime of the file /goform/SetSysTimeCfg. The manipulation of …

Aug 27, 2024
CVE-2024-8224
8.8 HIGH

A vulnerability, which was classified as critical, has been found in Tenda G3 15.11.0.20. This issue affects the function formSetDebugCfg of the file /goform/setDebugCfg. The …

Aug 27, 2024
CVE-2024-8219
7.3 HIGH

A vulnerability was found in code-projects Responsive Hotel Site 1.0. It has been classified as critical. Affected is an unknown function of the file index.php. …

Aug 27, 2024
CVE-2024-8218
7.3 HIGH

A vulnerability was found in code-projects Online Quiz Site 1.0 and classified as critical. This issue affects some unknown processing of the file index.php. The …

Aug 27, 2024
CVE-2024-8217
7.3 HIGH

A vulnerability has been found in SourceCodester E-Commerce Website 1.0 and classified as critical. This vulnerability affects unknown code of the file /Admin/registration.php. The manipulation …

Aug 27, 2024
CVE-2024-45049
7.5 HIGH

Hydra is a Continuous Integration service for Nix based projects. It is possible to trigger evaluations in Hydra without any authentication. Depending on the size …

Aug 27, 2024
CVE-2024-45038
7.5 HIGH

Meshtastic device firmware is a firmware for meshtastic devices to run an open source, off-grid, decentralized, mesh network built to run on affordable, low-power devices. …

Aug 27, 2024
CVE-2024-5991
7.5 HIGH

In function MatchDomainName(), input param str is treated as a NULL terminated string despite being user provided and unchecked. Specifically, the function X509_check_host() takes in …

Aug 27, 2024
CVE-2022-39997
8.0 HIGH

A weak password requirement issue was discovered in Teldats Router RS123, RS123w allows a remote attacker to escalate privileges

Aug 27, 2024
CVE-2024-43783
7.5 HIGH

The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. Instances of …

Aug 27, 2024
CVE-2024-43414
7.5 HIGH

Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Each team can own their slice of the graph independently, empowering them …

Aug 27, 2024
CVE-2024-42851
7.8 HIGH

Buffer Overflow vulnerability in open source exiftags v.1.01 allows a local attacker to execute arbitrary code via the paresetag function.

Aug 27, 2024
CVE-2024-45264
8.8 HIGH

A cross-site request forgery (CSRF) vulnerability in the admin panel in SkySystem Arfa-CMS before 5.1.3124 allows remote attackers to add a new administrator, leading to …

Aug 27, 2024
CVE-2024-44340
8.8 HIGH

D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via keys smartqos_express_devices and smartqos_normal_devices in SetSmartQoSSettings.

Aug 27, 2024
CVE-2024-6632
7.2 HIGH

A vulnerability exists in FileCatalyst Workflow whereby a field accessible to the super admin can be used to perform an SQL injection attack which can …

Aug 27, 2024
CVE-2024-8182
7.5 HIGH

An Unauthenticated Denial of Service (DoS) vulnerability exists in Flowise version 1.8.2 leading to a complete crash of the instance running a vulnerable version due …

Aug 27, 2024
CVE-2024-7940
8.3 HIGH

The product exposes a service that is intended for local only to all network interfaces without any authentication.

Aug 27, 2024
CVE-2024-3982
8.2 HIGH

An attacker with local access to machine where MicroSCADA X SYS600 is installed, could enable the session logging supporting the product and try to exploit …

Aug 27, 2024
CVE-2024-41176
7.3 HIGH

The MPD package included in TwinCAT/BSD allows an authenticated, low-privileged local attacker to induce a Denial-of-Service (DoS) condition on the daemon and execute code in …

Aug 27, 2024
CVE-2024-41174
7.3 HIGH

The IPC-Diagnostics package in TwinCAT/BSD is susceptible to improper input neutralization by a low-privileged local attacker.

Aug 27, 2024
CVE-2024-41173
7.8 HIGH

The IPC-Diagnostics package included in TwinCAT/BSD is vulnerable to a local authentication bypass by a low privileged attacker.

Aug 27, 2024
CVE-2024-7125
7.8 HIGH

Authentication Bypass vulnerability in Hitachi Ops Center Common Services.This issue affects Hitachi Ops Center Common Services: from 10.9.3-00 before 11.0.2-01.

Aug 27, 2024
CVE-2024-45321
8.1 HIGH

The App::cpanminus package through 1.7047 for Perl downloads code via insecure HTTP, enabling code execution for network attackers.

Aug 27, 2024
CVE-2024-43798
8.6 HIGH

Chisel is a fast TCP/UDP tunnel, transported over HTTP, secured via SSH. The Chisel server doesn't ever read the documented `AUTH` environment variable used to …

Aug 26, 2024
CVE-2024-43301
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Fonts Plugin Fonts allows Stored XSS.This issue affects Fonts: from n/a through 3.7.7.

Aug 26, 2024
CVE-2024-43255
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in zookatron MyBookTable Bookstore mybooktable.This issue affects MyBookTable Bookstore: from n/a through <= 3.3.9.

Aug 26, 2024
CVE-2024-28077
7.5 HIGH

A denial-of-service issue was discovered on certain GL-iNet devices. Some websites can detect devices exposed to the external network through DDNS, and consequently obtain the …

Aug 26, 2024
CVE-2024-7401
7.5 HIGH

Netskope was notified about a security gap in Netskope Client enrollment process where NSClient is using a static token “Orgkey” as authentication parameter. Since this …

Aug 26, 2024
CVE-2024-8173
7.3 HIGH

A vulnerability, which was classified as critical, was found in code-projects Blood Bank System 1.0. Affected is an unknown function of the file /login.php of …

Aug 26, 2024
CVE-2024-43289
7.5 HIGH

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in gVectors Team wpForo Forum.This issue affects wpForo Forum: from n/a through 2.3.4.

Aug 26, 2024
CVE-2024-42791
8.8 HIGH

A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via /music/ajax.php?action=delete_genre.

Aug 26, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.