CVE Database

39885+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-42747
8.8 HIGH

In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setWanIeCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.

Aug 12, 2024
CVE-2024-42745
8.8 HIGH

In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setUPnPCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.

Aug 12, 2024
CVE-2024-42744
8.8 HIGH

In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setModifyVpnUser. Authenticated Attackers can send malicious packet to execute arbitrary commands.

Aug 12, 2024
CVE-2024-42743
8.8 HIGH

In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setSyslogCfg . Authenticated Attackers can send malicious packet to execute arbitrary …

Aug 12, 2024
CVE-2024-42742
8.8 HIGH

In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setUrlFilterRules. Authenticated Attackers can send malicious packet to execute arbitrary commands.

Aug 12, 2024
CVE-2024-42741
8.8 HIGH

In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setL2tpServerCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.

Aug 12, 2024
CVE-2023-48171
8.8 HIGH

An issue in OWASP DefectDojo before v.1.5.3.1 allows a remote attacker to escalate privileges via the user permissions component.

Aug 12, 2024
CVE-2023-41884
7.1 HIGH

ZoneMinder is a free, open source Closed-circuit television software application. In WWW/AJAX/watch.php, Line: 51 takes a few parameter in sql query without sanitizing it which …

Aug 12, 2024
CVE-2024-41710
7.2 HIGH KEV

A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an …

Aug 12, 2024
CVE-2024-40892
7.1 HIGH

A weak credential vulnerability exists in Firewalla Box Software versions before 1.979. This vulnerability allows a physically close attacker to use the license UUID for …

Aug 12, 2024
CVE-2024-42627
8.8 HIGH

FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/snippet/delete/3.

Aug 12, 2024
CVE-2024-42626
8.8 HIGH

FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/snippet/add.

Aug 12, 2024
CVE-2024-42625
8.8 HIGH

FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/layout/add

Aug 12, 2024
CVE-2024-42624
8.8 HIGH

FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/page/delete/10.

Aug 12, 2024
CVE-2024-42623
8.8 HIGH

FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/layout/delete/1

Aug 12, 2024
CVE-2024-41651
8.1 HIGH

An issue in Prestashop v.8.1.7 and before allows a remote attacker to execute arbitrary code via the module upgrade functionality. NOTE: this is disputed by …

Aug 12, 2024
CVE-2024-41475
8.8 HIGH

Gnuboard g6 6.0.7 is vulnerable to Session hijacking due to a CORS misconfiguration.

Aug 12, 2024
CVE-2024-40500
8.6 HIGH

Cross Site Scripting vulnerability in Martin Kucej i-librarian v.5.11.0 and before allows a local attacker to execute arbitrary code via the search function in the …

Aug 12, 2024
CVE-2024-42632
8.8 HIGH

FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/page/add.

Aug 12, 2024
CVE-2024-42631
8.8 HIGH

FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/layout/edit/1.

Aug 12, 2024
CVE-2024-42630
8.8 HIGH

FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/create_file.

Aug 12, 2024
CVE-2024-42629
8.8 HIGH

FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/page/edit/10.

Aug 12, 2024
CVE-2024-42628
8.8 HIGH

FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/snippet/edit/3.

Aug 12, 2024
CVE-2024-42485
7.5 HIGH

Filament Excel enables excel export for Filament admin resources. The export download route `/filament-excel/{path}` allowed downloading any file without login when the webserver allows `../` …

Aug 12, 2024
CVE-2024-42481
7.5 HIGH

Skyport Daemon (skyportd) is the daemon for the Skyport Panel. By making thousands of folders & files (easy due to skyport's lack of rate limiting …

Aug 12, 2024
CVE-2024-42480
8.1 HIGH

Kamaji is the Hosted Control Plane Manager for Kubernetes. In versions 1.0.0 and earlier, Kamaji uses an "open at the top" range definition in RBAC …

Aug 12, 2024
CVE-2024-39091
8.8 HIGH

An OS command injection vulnerability in the ccm_debug component of MIPC Camera firmware prior to v5.4.1.240424171021 allows attackers within the same network to execute arbitrary …

Aug 12, 2024
CVE-2024-36877
8.2 HIGH

Micro-Star International Z-series motherboards (Z590, Z490, and Z790) and B-series motherboards (B760, B560, B660, and B460) with firmware 7D25v14, 7D25v17 to 7D25v19, and 7D25v1A to …

Aug 12, 2024
CVE-2024-33535
7.5 HIGH

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. The vulnerability involves unauthenticated local file inclusion (LFI) in a web application, specifically impacting …

Aug 12, 2024
CVE-2024-27442
7.8 HIGH

An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. The zmmailboxdmgr binary, a component of ZCS, is intended to be executed by the …

Aug 12, 2024
CVE-2024-7697
7.5 HIGH

Logical vulnerability in the mobile application (com.transsion.carlcare) may lead to user information leakage risks.

Aug 12, 2024
CVE-2024-7694
7.2 HIGH KEV

ThreatSonar Anti-Ransomware from TeamT5 does not properly validate the content of uploaded files. Remote attackers with administrator privileges on the product platform can upload malicious …

Aug 12, 2024
CVE-2024-7693
7.5 HIGH

Raiden MAILD Remote Management System from Team Johnlong Software has a Relative Path Traversal vulnerability, allowing unauthenticated remote attackers to read arbitrary file on the …

Aug 12, 2024
CVE-2024-7682
7.3 HIGH

A vulnerability was found in code-projects Job Portal 1.0. It has been rated as critical. This issue affects some unknown processing of the file rw_i_nat.php. …

Aug 12, 2024
CVE-2024-7681
7.3 HIGH

A vulnerability was found in code-projects College Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file login.php …

Aug 12, 2024
CVE-2024-7637
7.3 HIGH

A vulnerability was found in code-projects Online Polling 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the …

Aug 12, 2024
CVE-2024-7636
7.3 HIGH

A vulnerability was found in code-projects Simple Ticket Booking 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Aug 12, 2024
CVE-2024-7635
7.3 HIGH

A vulnerability was found in code-projects Simple Ticket Booking 1.0. It has been classified as critical. Affected is an unknown function of the file register_insert.php …

Aug 12, 2024
CVE-2024-7615
8.8 HIGH

A vulnerability was found in Tenda FH1206 1.2.0.8. It has been declared as critical. Affected by this vulnerability is the function fromSafeClientFilter/fromSafeMacFilter/fromSafeUrlFilter. The manipulation leads …

Aug 12, 2024
CVE-2024-7614
8.8 HIGH

A vulnerability was found in Tenda FH1206 1.2.0.8(8155). It has been classified as critical. Affected is the function fromqossetting of the file /goform/qossetting. The manipulation …

Aug 12, 2024
CVE-2024-7613
8.8 HIGH

A vulnerability was found in Tenda FH1206 1.2.0.8(8155) and classified as critical. This issue affects the function fromGstDhcpSetSer of the file /goform/GstDhcpSetSer. The manipulation of …

Aug 12, 2024
CVE-2024-7589
8.1 HIGH

A signal handler in sshd(8) may call a logging function that is not async-signal-safe. The signal handler is invoked when a client does not authenticate …

Aug 12, 2024
CVE-2024-7557
8.8 HIGH

A vulnerability was found in OpenShift AI that allows for authentication bypass and privilege escalation across models within the same namespace. When deploying AI models, …

Aug 12, 2024
CVE-2024-7399
8.8 HIGH KEV

Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as …

Aug 12, 2024
CVE-2024-7006
7.5 HIGH

A null pointer dereference flaw was found in Libtiff via `tif_dirinfo.c`. This issue may allow an attacker to trigger memory allocation failures through certain means, …

Aug 12, 2024
CVE-2024-6760
7.5 HIGH

A logic bug in the code which disables kernel tracing for setuid programs meant that tracing was not disabled when it should have, allowing unprivileged …

Aug 12, 2024
CVE-2024-5800
7.5 HIGH

Diffie-Hellman groups with insufficient strength are used in the SSL/TLS stack of B&R Automation Runtime versions before 6.0.2, allowing a network attacker to decrypt the …

Aug 12, 2024
CVE-2024-5651
8.8 HIGH

A flaw was found in the Fence Agents Remediation operator. This vulnerability can allow a Remote Code Execution (RCE) primitive by supplying an arbitrary command …

Aug 12, 2024
CVE-2024-5527
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in file auditing configuration.

Aug 12, 2024
CVE-2024-5487
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8110 are vulnerable to authenticated SQL Injection in attack surface analyzer's export option.

Aug 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.