CVE Database

40083+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-4599
7.5 HIGH

Remote denial of service vulnerability in LAN Messenger affecting version 3.4.0. This vulnerability allows an attacker to crash the LAN Messenger service by sending a …

May 7, 2024
CVE-2024-4582
7.3 HIGH

A vulnerability classified as critical has been found in Faraday GM8181 and GM828x up to 20240429. Affected is an unknown function of the component NTP …

May 7, 2024
CVE-2024-22472
8.1 HIGH

A buffer Overflow vulnerability in Silicon Labs 500 Series Z-Wave devices may allow Denial of Service, and potential Remote Code execution This issue affects all …

May 7, 2024
CVE-2024-29941
8.0 HIGH

Insecure storage of the ICT MIFARE and DESFire encryption keys in the firmware binary allows malicious actors to create credentials for any site code and …

May 6, 2024
CVE-2024-30973
8.8 HIGH

An issue in V-SOL G/EPON ONU HG323AC-B with firmware version V2.0.08-210715 allows an attacker to execute arbtirary code and obtain sensitive information via crafted POST …

May 6, 2024
CVE-2024-34534
7.3 HIGH

A SQL injection vulnerability in Cybrosys Techno Solutions Text Commander module (aka text_commander) 16.0 through 16.0.1 allows a remote attacker to gain privileges via the …

May 6, 2024
CVE-2024-34533
7.3 HIGH

A SQL injection vulnerability in ZI PT Solusi Usaha Mudah Analytic Data Query module (aka izi_data) 11.0 through 17.x before 17.0.3 allows a remote attacker …

May 6, 2024
CVE-2024-28725
7.1 HIGH

Cross Site Scripting (XSS) vulnerability in YzmCMS 7.0 allows attackers to run arbitrary code via Ads Management, Carousel Management, and System Settings.

May 6, 2024
CVE-2024-33602
7.4 HIGH

nscd: netgroup cache assumes NSS callback uses in-buffer strings The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory when the NSS callback does …

May 6, 2024
CVE-2024-33601
7.3 HIGH

nscd: netgroup cache may terminate daemon on memory allocation failure The Name Service Cache Daemon's (nscd) netgroup cache uses xmalloc or xrealloc and these functions …

May 6, 2024
CVE-2024-33599
8.1 HIGH

nscd: Stack-based buffer overflow in netgroup cache If the Name Service Cache Daemon's (nscd) fixed size cache is exhausted by client requests then a subsequent …

May 6, 2024
CVE-2024-33118
7.5 HIGH

LuckyFrameWeb v3.5.2 was discovered to contain an arbitrary read vulnerability via the fileDownload method in class com.luckyframe.project.common.CommonController.

May 6, 2024
CVE-2024-3661
7.6 HIGH

DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect …

May 6, 2024
CVE-2024-34412
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Parcel Panel ParcelPanel.This issue affects ParcelPanel: from n/a through 3.8.1.

May 6, 2024
CVE-2024-34386
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Lucian Apostol Auto Affiliate Links.This issue affects Auto Affiliate Links: from …

May 6, 2024
CVE-2024-34378
8.6 HIGH

Missing Authorization vulnerability in LeadConnector.This issue affects LeadConnector: from n/a through 1.7.

May 6, 2024
CVE-2024-34369
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webpushr Web Push Notifications Webpushr allows Reflected XSS.This issue affects Webpushr: from n/a …

May 6, 2024
CVE-2024-34367
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Popup Box Team Popup box allows Cross-Site Scripting (XSS).This issue affects Popup box: from n/a through 4.1.2.

May 6, 2024
CVE-2024-33912
7.1 HIGH

Missing Authorization vulnerability in Academy LMS.This issue affects Academy LMS: from n/a through 1.9.16.

May 6, 2024
CVE-2024-34388
7.5 HIGH

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Scribit GDPR Compliance.This issue affects GDPR Compliance: from n/a through 1.2.5.

May 6, 2024
CVE-2024-33410
8.1 HIGH

SQL injection vulnerability in /model/delete_range_grade.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the id parameter.

May 6, 2024
CVE-2024-33406
7.3 HIGH

SQL injection vulnerability in /model/delete_student_grade_subject.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the index parameter.

May 6, 2024
CVE-2024-33405
8.6 HIGH

SQL injection vulnerability in add_friends.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the friend_index parameter.

May 6, 2024
CVE-2024-33404
8.3 HIGH

A SQL injection vulnerability in /model/add_student_first_payment.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the index parameter.

May 6, 2024
CVE-2024-32807
8.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brevo Sendinblue for WooCommerce allows Relative Path Traversal, Manipulating Web Input to …

May 6, 2024
CVE-2024-34251
7.5 HIGH

An out-of-bound memory read vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to cause a denial of service via the …

May 6, 2024
CVE-2024-34246
7.5 HIGH

wasm3 v0.5.0 was discovered to contain an out-of-bound memory read which leads to segmentation fault via the function "main" in wasm3/platforms/app/main.c.

May 6, 2024
CVE-2024-34092
8.8 HIGH

An issue was discovered in Archer Platform 6 before 2024.04. Authentication was mishandled because lock did not terminate an existing session. 6.14 P3 (6.14.0.3) is …

May 6, 2024
CVE-2024-34091
7.3 HIGH

An issue was discovered in Archer Platform 6 before 2024.04. There is a stored cross-site scripting (XSS) vulnerability. A remote authenticated malicious Archer user could …

May 6, 2024
CVE-2024-34090
7.3 HIGH

An issue was discovered in Archer Platform 6 before 2024.04. There is a stored cross-site scripting (XSS) vulnerability. The login banner in the Archer Control …

May 6, 2024
CVE-2024-34089
7.3 HIGH

An issue was discovered in Archer Platform 6 before 2024.04. There is a stored cross-site scripting (XSS) vulnerability. A remote authenticated malicious Archer user could …

May 6, 2024
CVE-2024-34470
8.6 HIGH

An issue was discovered in HSC Mailinspector 5.2.17-3 through v.5.2.18. An Unauthenticated Path Traversal vulnerability exists in the /public/loader.php file. The path parameter does not …

May 6, 2024
CVE-2024-34252
7.5 HIGH

wasm3 v0.5.0 was discovered to contain a global buffer overflow which leads to segmentation fault via the function "PreserveRegisterIfOccupied" in wasm3/source/m3_compile.c.

May 6, 2024
CVE-2024-34069
7.5 HIGH

Werkzeug is a comprehensive WSGI web application library. The debugger in affected versions of Werkzeug can allow an attacker to execute code on a developer's …

May 6, 2024
CVE-2024-33112
7.5 HIGH

D-Link DIR-845L router v1.01KRb03 and before is vulnerable to Command injection via the hnap_main()func.

May 6, 2024
CVE-2024-32982
8.2 HIGH

Litestar and Starlite is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.8.3, 2.7.2, and 2.6.4, a Local File Inclusion (LFI) vulnerability has been …

May 6, 2024
CVE-2024-32972
7.5 HIGH

go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to 1.13.15, a vulnerable node can be made to consume very large …

May 6, 2024
CVE-2024-23354
8.4 HIGH

Memory corruption when the IOCTL call is interrupted by a signal.

May 6, 2024
CVE-2024-23351
8.4 HIGH

Memory corruption as GPU registers beyond the last protected range can be accessed through LPAC submissions.

May 6, 2024
CVE-2024-21480
7.3 HIGH

Memory corruption while playing audio file having large-sized input buffer.

May 6, 2024
CVE-2024-21477
7.5 HIGH

Transient DOS while parsing a protected 802.11az Fine Time Measurement (FTM) frame.

May 6, 2024
CVE-2024-21476
7.8 HIGH

Memory corruption when the channel ID passed by user is not validated and further used.

May 6, 2024
CVE-2024-21475
7.8 HIGH

Memory corruption when the payload received from firmware is not as per the expected protocol size.

May 6, 2024
CVE-2024-21474
8.4 HIGH

Memory corruption when size of buffer from previous call is used without validation or re-initialization.

May 6, 2024
CVE-2024-21471
8.4 HIGH

Memory corruption when IOMMU unmap of a GPU buffer fails in Linux.

May 6, 2024
CVE-2023-43531
8.4 HIGH

Memory corruption while verifying the serialized header when the key pairs are generated.

May 6, 2024
CVE-2023-43529
7.5 HIGH

Transient DOS while processing IKEv2 Informational request messages, when a malformed fragment packet is received.

May 6, 2024
CVE-2023-33119
8.4 HIGH

Memory corruption while loading a VM from a signed VM image that is not coherent in the processor cache.

May 6, 2024
CVE-2024-4549
7.5 HIGH

A denial of service vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior. When processing an 'ICS Restart!' message, CEBC.exe restarts the system.

May 6, 2024
CVE-2024-33830
8.1 HIGH

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/readDeal.php?mudi=clearWebCache.

May 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.