CVE Database

40083+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-35434
7.5 HIGH

Irontec Sngrep v1.8.1 was discovered to contain a heap buffer overflow via the function rtp_check_packet at /sngrep/src/rtp.c. This vulnerability allows attackers to cause a Denial …

May 29, 2024
CVE-2024-36427
8.1 HIGH

The file-serving function in TARGIT Decision Suite before 24.06.19002 (TARGIT Decision Suite 2024 – June) allows authenticated attackers to read or write to server files …

May 29, 2024
CVE-2024-35333
8.4 HIGH

A stack-buffer-overflow vulnerability exists in the read_charset_decl function of html2xhtml 1.3. This vulnerability occurs due to improper bounds checking when copying data into a fixed-size …

May 29, 2024
CVE-2024-28974
7.6 HIGH

Dell Data Protection Advisor, version(s) 19.9, contain(s) an Inadequate Encryption Strength vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading …

May 29, 2024
CVE-2024-36470
8.1 HIGH

In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5 authentication bypass was possible in specific edge cases

May 29, 2024
CVE-2024-5185
7.3 HIGH

The EmbedAI application is susceptible to security issues that enable Data Poisoning attacks. This weakness could result in the application becoming compromised, leading to unauthorized …

May 29, 2024
CVE-2024-25977
7.3 HIGH

The application does not change the session token when using the login or logout functionality. An attacker can set a session token in the victim's …

May 29, 2024
CVE-2023-42005
7.4 HIGH

IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data 3.5, 4.0, 4.5, 4.6, 4.7, and 4.8 could allow a …

May 29, 2024
CVE-2024-28826
8.8 HIGH

Improper restriction of local upload and download paths in check_sftp in Checkmk before 2.3.0p4, 2.2.0p27, 2.1.0p44, and in Checkmk 2.0.0 (EOL) allows attackers with sufficient …

May 29, 2024
CVE-2024-36015
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ppdev: Add an error check in register_device In register_device, the return value of ida_simple_get is …

May 29, 2024
CVE-2024-4611
8.1 HIGH

The AppPresser plugin for WordPress is vulnerable to improper missing encryption exception handling on the 'decrypt_value' and on the 'doCookieAuth' functions in all versions up …

May 29, 2024
CVE-2024-21512
8.2 HIGH

Versions of the package mysql2 before 3.9.8 are vulnerable to Prototype Pollution due to improper user input sanitization passed to fields and tables when using …

May 29, 2024
CVE-2023-6743
8.8 HIGH

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, …

May 29, 2024
CVE-2024-5204
8.8 HIGH

The Swiss Toolkit For WP plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.0.7. This is due to the …

May 29, 2024
CVE-2023-30312
7.3 HIGH

An issue discovered in OpenWrt 18.06, 19.07, 21.02, 22.03, and beyond allows off-path attackers to hijack TCP sessions, which could lead to a denial of …

May 28, 2024
CVE-2024-35226
7.3 HIGH

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. In affected versions template authors could inject php code …

May 28, 2024
CVE-2024-22641
7.5 HIGH

TCPDF version 6.6.5 and before is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted SVG file.

May 28, 2024
CVE-2024-28060
7.3 HIGH

An issue was discovered in Apiris Kafeo 6.4.4. It permits DLL hijacking, allowing a user to trigger the execution of arbitrary code every time the …

May 28, 2024
CVE-2023-46694
8.1 HIGH

Vtenext 21.02 allows an authenticated attacker to upload arbitrary files, potentially enabling them to execute remote commands. This flaw exists due to the application's failure …

May 28, 2024
CVE-2023-30313
7.5 HIGH

An issue discovered in Wavlink QUANTUM D2G routers allows attackers to hijack TCP sessions which could lead to a denial of service.

May 28, 2024
CVE-2023-30310
7.5 HIGH

An issue discovered in Comfast Comfast CF-616AC routers allows attackers to hijack TCP sessions which could lead to a denial of service.

May 28, 2024
CVE-2022-45171
8.8 HIGH

An issue was discovered in LIVEBOX Collaboration vDesk through v018. An Unrestricted Upload of a File with a Dangerous Type can occur under the vShare …

May 28, 2024
CVE-2024-36110
8.2 HIGH

ansibleguy-webui is an open source WebUI for using Ansible. Multiple forms in versions < 0.0.21 allowed injection of HTML elements. These are returned to the …

May 28, 2024
CVE-2024-36109
7.6 HIGH

CoCalc is web-based software that enables collaboration in research, teaching, and scientific publishing. In affected versions the markdown parser allows `<script>` tags to be included …

May 28, 2024
CVE-2024-33450
7.5 HIGH

SQL Injection in Finereport v.8.0 allows a remote attacker to obtain sensitive information

May 28, 2024
CVE-2024-24919
8.6 HIGH KEV

Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or …

May 28, 2024
CVE-2023-43848
8.0 HIGH

Incorrect access control in the firewall management function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows remote authenticated users to alter local firewall …

May 28, 2024
CVE-2023-43844
8.0 HIGH

Aten PE6208 2.3.228 and 2.4.232 have default credentials for the privileged web interface account. The user is not asked to change the credentials after first …

May 28, 2024
CVE-2023-43843
7.3 HIGH

Incorrect access control in the account management function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows remote authenticated users to read user and …

May 28, 2024
CVE-2023-43842
7.3 HIGH

Incorrect access control in the account management function of web interface in Aten PE6208 2.3.228 and 2.4.232 allows remote authenticated users to alter user and …

May 28, 2024
CVE-2023-30311
7.5 HIGH

An issue discovered in H3C Magic R365 and H3C Magic R100 routers allows attackers to hijack TCP sessions which could lead to a denial of …

May 28, 2024
CVE-2023-30305
7.5 HIGH

An issue discovered in Linksys E5600 routers allows attackers to hijack TCP sessions which could lead to a denial of service.

May 28, 2024
CVE-2024-33402
8.1 HIGH

A SQL injection vulnerability in /model/approve_petty_cash.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the id parameter.

May 28, 2024
CVE-2024-35341
7.5 HIGH

Certain Anpviz products allow unauthenticated users to download the running configuration of the device via a HTTP GET request to /ConfigFile.ini or /config.xml URIs. This …

May 28, 2024
CVE-2024-30165
7.1 HIGH

Amazon AWS Client VPN before 3.9.1 on macOS has a buffer overflow that could potentially allow a local actor to execute arbitrary commands with elevated …

May 28, 2024
CVE-2024-26024
8.4 HIGH

SUBNET Solutions Inc. has identified vulnerabilities in third-party components used in Substation Server.

May 28, 2024
CVE-2024-24959
8.2 HIGH

Several out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of AutomationDirect P3-550E 1.2.10.9. Specially crafted network packets can lead to heap-based …

May 28, 2024
CVE-2024-24958
8.2 HIGH

Several out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of AutomationDirect P3-550E 1.2.10.9. Specially crafted network packets can lead to heap-based …

May 28, 2024
CVE-2024-24957
8.2 HIGH

Several out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of AutomationDirect P3-550E 1.2.10.9. Specially crafted network packets can lead to heap-based …

May 28, 2024
CVE-2024-24956
8.2 HIGH

Several out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of AutomationDirect P3-550E 1.2.10.9. Specially crafted network packets can lead to heap-based …

May 28, 2024
CVE-2024-24955
8.2 HIGH

Several out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of AutomationDirect P3-550E 1.2.10.9. Specially crafted network packets can lead to heap-based …

May 28, 2024
CVE-2024-24954
8.2 HIGH

Several out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of AutomationDirect P3-550E 1.2.10.9. Specially crafted network packets can lead to heap-based …

May 28, 2024
CVE-2024-24947
8.2 HIGH

A heap-based buffer overflow vulnerability exists in the Programming Software Connection CurrDir functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted network packet can lead to …

May 28, 2024
CVE-2024-24946
8.2 HIGH

A heap-based buffer overflow vulnerability exists in the Programming Software Connection CurrDir functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted network packet can lead to …

May 28, 2024
CVE-2024-24851
7.5 HIGH

A heap-based buffer overflow vulnerability exists in the Programming Software Connection FiBurn functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted network packet can lead to …

May 28, 2024
CVE-2024-23315
7.5 HIGH

A read-what-where vulnerability exists in the Programming Software Connection IMM 01A1 Memory Read functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted network packet can lead …

May 28, 2024
CVE-2024-3969
7.8 HIGH

XML External Entity injection vulnerability found in OpenText™ iManager 3.2.6.0200. This could lead to remote code execution by parsing untrusted XML payload

May 28, 2024
CVE-2024-35399
8.8 HIGH

TOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a stack overflow via the password parameter in the function loginAuth

May 28, 2024
CVE-2024-35397
8.8 HIGH

TOTOLINK CP900L v4.1.5cu.798_B20221228 weas discovered to contain a command injection vulnerability in the NTPSyncWithHost function via the hostTime parameter. This vulnerability allows attackers to execute …

May 28, 2024
CVE-2024-29072
8.2 HIGH

A privilege escalation vulnerability exists in the Foxit Reader 2024.2.0.25138. The vulnerability occurs due to improper certification validation of the updater executable before executing it. …

May 28, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.