CVE Database

39885+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-41463
7.5 HIGH

Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the entrys parameter at ip/goform/addressNat.

Jul 24, 2024
CVE-2024-41462
7.5 HIGH

Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the page parameter at ip/goform/DhcpListClient.

Jul 24, 2024
CVE-2024-41550
7.2 HIGH

CampCodes Supplier Management System v1.0 is vulnerable to SQL injection via Supply_Management_System/admin/view_invoice_items.php?id= .

Jul 24, 2024
CVE-2024-41135
7.2 HIGH

A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remote authenticated users to run arbitrary commands on the …

Jul 24, 2024
CVE-2024-41134
7.2 HIGH

A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remote authenticated users to run arbitrary commands on the …

Jul 24, 2024
CVE-2024-41133
7.2 HIGH

A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remote authenticated users to run arbitrary commands on the …

Jul 24, 2024
CVE-2024-36534
8.4 HIGH

Insecure permissions in hwameistor v0.14.3 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.

Jul 24, 2024
CVE-2024-33519
7.2 HIGH

A vulnerability in the web-based management interface of HPE Aruba Networking EdgeConnect SD-WAN gateway could allow an authenticated remote attacker to conduct a server-side prototype …

Jul 24, 2024
CVE-2024-40495
8.0 HIGH

A vulnerability was discovered in Linksys Router E2500 with firmware 2.0.00, allows authenticated attackers to execute arbitrary code via the hnd_parentalctrl_unblock function.

Jul 24, 2024
CVE-2024-36538
8.8 HIGH

Insecure permissions in chaos-mesh v2.6.3 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.

Jul 24, 2024
CVE-2024-36537
7.2 HIGH

Insecure permissions in cert-manager v1.14.4 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.

Jul 24, 2024
CVE-2024-41672
7.5 HIGH

DuckDB is a SQL database management system. In versions 1.0.0 and prior, content in filesystem is accessible for reading using `sniff_csv`, even with `enable_external_access=false`. This …

Jul 24, 2024
CVE-2024-41667
8.8 HIGH

OpenAM is an open access management solution. In versions 15.0.3 and prior, the `getCustomLoginUrlTemplate` method in RealmOAuth2ProviderSettings.java is vulnerable to template injection due to its …

Jul 24, 2024
CVE-2024-41662
8.6 HIGH

VNote is a note-taking platform. A Cross-Site Scripting (XSS) vulnerability has been identified in the Markdown rendering functionality of versions 3.18.1 and prior of the …

Jul 24, 2024
CVE-2024-36541
8.8 HIGH

Insecure permissions in logging-operator v4.6.0 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.

Jul 24, 2024
CVE-2024-31970
8.8 HIGH

AdTran SRG 834-5 HDC17600021F1 devices (with SmartOS 11.1.1.1 and fixed in Version 12.1.3.1) have SSH enabled by default, accessible both over the LAN and the …

Jul 24, 2024
CVE-2024-41914
8.1 HIGH

A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack …

Jul 24, 2024
CVE-2024-39345
7.2 HIGH

AdTran 834-5 HDC17600021F1 (SmartOS 11.1.1.1) devices enable the SSH service by default and have a hidden, undocumented, hard-coded support account whose password is based on …

Jul 24, 2024
CVE-2024-31977
8.8 HIGH

Adtran 834-5 11.1.0.101-202106231430, and fixed as of SmartOS Version 12.6.3.1, devices allow OS Command Injection via shell metacharacters to the Ping or Traceroute utility.

Jul 24, 2024
CVE-2024-22443
7.2 HIGH

A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a server-side prototype pollution attack. Successful …

Jul 24, 2024
CVE-2024-6096
8.8 HIGH

In Progress® Telerik® Reporting versions prior to 18.1.24.709, a code execution attack is possible through object injection via an insecure type resolution vulnerability.

Jul 24, 2024
CVE-2024-7066
7.3 HIGH

A vulnerability was found in F-logic DataCube3 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file …

Jul 24, 2024
CVE-2024-6197
7.5 HIGH

libcurl's ASN1 parser has this utf8asn1str() function used for parsing an ASN.1 UTF-8 string. Itcan detect an invalid field and return error. Unfortunately, when doing …

Jul 24, 2024
CVE-2024-39676
7.5 HIGH

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Pinot. This issue affects Apache Pinot: from 0.1 before 1.0.0. Users are recommended to …

Jul 24, 2024
CVE-2023-48362
8.8 HIGH

XXE in the XML Format Plugin in Apache Drill version 1.19.0 and greater allows a user to read any file on a remote file system …

Jul 24, 2024
CVE-2024-7027
7.3 HIGH

The WooCommerce - PDF Vouchers plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 4.9.3. This is due to insufficient …

Jul 24, 2024
CVE-2024-6756
8.8 HIGH

The Social Auto Poster plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpw_auto_poster_get_image_path' function in all …

Jul 24, 2024
CVE-2024-6753
7.2 HIGH

The Social Auto Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mapTypes’ parameter in the 'wpw_auto_poster_map_wordpress_post_type' AJAX function in all versions …

Jul 24, 2024
CVE-2024-6750
7.3 HIGH

The Social Auto Poster plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple …

Jul 24, 2024
CVE-2024-41656
7.1 HIGH

Sentry is an error tracking and performance monitoring platform. Starting in version 10.0.0 and prior to version 24.7.1, an unsanitized payload sent by an Integration …

Jul 23, 2024
CVE-2024-38176
8.1 HIGH

An improper restriction of excessive authentication attempts in GroupMe allows a unauthenticated attacker to elevate privileges over a network.

Jul 23, 2024
CVE-2024-0981
7.1 HIGH

Okta Browser Plugin versions 6.5.0 through 6.31.0 (Chrome/Edge/Firefox/Safari) are vulnerable to cross-site scripting. This issue occurs when the plugin prompts the user to save these …

Jul 23, 2024
CVE-2024-41668
8.3 HIGH

The cBioPortal for Cancer Genomics provides visualization, analysis, and download of large-scale cancer genomics data sets. When running a publicly exposed proxy endpoint without authentication, …

Jul 23, 2024
CVE-2020-11640
8.8 HIGH

AdvaBuild uses a command queue to launch certain operations. An attacker who gains access to the command queue can use it to launch an attack …

Jul 23, 2024
CVE-2020-11639
7.8 HIGH

An attacker could exploit the vulnerability by injecting garbage data or specially crafted data. Depending on the data injected each process might be affected differently. …

Jul 23, 2024
CVE-2024-41178
7.5 HIGH

Exposure of temporary credentials in logs in Apache Arrow Rust Object Store (`object_store` crate), version 0.10.1 and earlier on all platforms using AWS WebIdentityTokens. On …

Jul 23, 2024
CVE-2024-6714
8.8 HIGH

An issue was discovered in provd before version 0.1.5 with a setuid binary, which allows a local attacker to escalate their privilege.

Jul 23, 2024
CVE-2024-4076
7.5 HIGH

Client queries that trigger serving stale data and that also require lookups in local authoritative zone data may result in an assertion failure. This issue …

Jul 23, 2024
CVE-2024-41655
7.5 HIGH

TF2 Item Format helps users format TF2 items to the community standards. Versions of `tf2-item-format` since at least `4.2.6` and prior to `5.9.14` are vulnerable …

Jul 23, 2024
CVE-2024-40060
7.5 HIGH

go-chart v2.1.1 was discovered to contain an infinite loop via the drawCanvas() function.

Jul 23, 2024
CVE-2024-1975
7.5 HIGH

If a server hosts a zone containing a "KEY" Resource Record, or a resolver DNSSEC-validates a "KEY" Resource Record from a DNSSEC-signed domain in cache, …

Jul 23, 2024
CVE-2024-1737
7.5 HIGH

Resolver caches and authoritative zone databases that hold significant numbers of RRs for the same hostname (of any RTYPE) can suffer from degraded performance as …

Jul 23, 2024
CVE-2024-0760
7.5 HIGH

A malicious client can send many DNS messages over TCP, potentially causing the server to become unstable while the attack is in progress. The server …

Jul 23, 2024
CVE-2024-5602
7.8 HIGH

A stack-based buffer overflow vulnerability due to a missing bounds check in the NI I/O Trace Tool may result in arbitrary code execution. Successful exploitation …

Jul 23, 2024
CVE-2024-4081
7.8 HIGH

A memory corruption issue due to an improper length check in NI LabVIEW may disclose information or result in arbitrary code execution. Successful exploitation requires …

Jul 23, 2024
CVE-2024-4080
7.8 HIGH

A memory corruption issue due to an improper length check in LabVIEW tdcore.dll may disclose information or result in arbitrary code execution. Successful exploitation requires …

Jul 23, 2024
CVE-2024-4079
7.8 HIGH

An out of bounds read due to a missing bounds check in LabVIEW may disclose information or result in arbitrary code execution. Successful exploitation requires …

Jul 23, 2024
CVE-2024-7014
8.1 HIGH

EvilVideo vulnerability allows sending malicious apps disguised as videos in Telegram for Android application affecting versions 10.14.4 and older.

Jul 23, 2024
CVE-2024-6420
8.6 HIGH

The Hide My WP Ghost WordPress plugin before 5.2.02 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated …

Jul 23, 2024
CVE-2024-6885
8.1 HIGH

The MaxiBlocks: 2200+ Patterns, 190 Pages, 14.2K Icons & 100 Styles plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path …

Jul 23, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.