CVE Database

46624+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-10097
8.1 HIGH

The Loginizer Security and Loginizer plugins for WordPress are vulnerable to authentication bypass in all versions up to, and including, 1.9.2. This is due to …

Nov 5, 2024
CVE-2024-9459
8.3 HIGH

Zohocorp ManageEngine Exchange Reporter Plus versions 5718 and prior are vulnerable to authenticated SQL Injection in reports module.

Nov 5, 2024
CVE-2024-31998
8.8 HIGH

Combodo iTop is a simple, web based IT Service Management tool. A CSRF can be performed on CSV import simulation. This issue has been fixed …

Nov 5, 2024
CVE-2024-31448
8.8 HIGH

Combodo iTop is a simple, web based IT Service Management tool. By filling malicious code in a CSV content, an Cross-site Scripting (XSS) attack can …

Nov 5, 2024
CVE-2023-34445
8.8 HIGH

Combodo iTop is a simple, web based IT Service Management tool. When displaying pages/ajax.render.php XSS are possible for scripts outside of script tags. This issue …

Nov 5, 2024
CVE-2023-34444
8.8 HIGH

Combodo iTop is a simple, web based IT Service Management tool. When displaying pages/ajax.searchform.php XSS are possible for scripts outside of script tags. This issue …

Nov 5, 2024
CVE-2023-34443
8.8 HIGH

Combodo iTop is a simple, web based IT Service Management tool. When displaying page Run queries Cross-site Scripting (XSS) are possible for scripts outside of …

Nov 5, 2024
CVE-2024-10791
7.3 HIGH

A vulnerability, which was classified as critical, has been found in Codezips Hospital Appointment System 1.0. This issue affects some unknown processing of the file …

Nov 4, 2024
CVE-2024-30619
7.5 HIGH

Chamilo LMS Version 1.11.26 is vulnerable to Incorrect Access Control. A non-authenticated attacker can request the number of messages and the number of online users …

Nov 4, 2024
CVE-2024-30616
8.8 HIGH

Chamilo LMS 1.11.26 is vulnerable to Incorrect Access Control via main/auth/profile. Non-admin users can manipulate sensitive profiles information, posing a significant risk to data integrity.

Nov 4, 2024
CVE-2024-51329
8.8 HIGH

A Host header injection vulnerability in Agile-Board 1.0 allows attackers to obtain the password reset token via user interaction with a crafted password reset link.

Nov 4, 2024
CVE-2024-51326
7.5 HIGH

SQL Injection vulnerability in projectworlds Travel management System v.1.0 allows a remote attacker to execute arbitrary code via the 't2' parameter in deletesubcategory.php.

Nov 4, 2024
CVE-2024-51127
7.1 HIGH

An issue in the createTempFile method of hornetq v2.4.9 allows attackers to arbitrarily overwrite files or access sensitive information.

Nov 4, 2024
CVE-2024-48336
8.4 HIGH

The install() function of ProviderInstaller.java in Magisk App before canary version 27007 does not verify the GMS app before loading it, which allows a local …

Nov 4, 2024
CVE-2024-48809
7.5 HIGH

An issue in Open Networking Foundations sdran-in-a-box v.1.4.3 and onos-a1t v.0.2.3 allows a remote attacker to cause a denial of service via the onos-a1t component …

Nov 4, 2024
CVE-2024-51626
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in chenyenming Woocommerce Quote Calculator woo-quote-calculator-order allows Blind SQL Injection.This issue affects …

Nov 4, 2024
CVE-2024-45893
8.0 HIGH

DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `setSWMOption.`

Nov 4, 2024
CVE-2024-45891
8.0 HIGH

DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `delete_wlan_profile.`

Nov 4, 2024
CVE-2024-45890
8.0 HIGH

DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `download_ovpn.`

Nov 4, 2024
CVE-2024-45889
8.0 HIGH

DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `commandTable.`

Nov 4, 2024
CVE-2024-45888
8.0 HIGH

DrayTek Vigor3900 1.5.1.3 contains a command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `set_ap_map_config.'

Nov 4, 2024
CVE-2024-45887
8.0 HIGH

DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `doOpenVPN.`

Nov 4, 2024
CVE-2024-45885
8.0 HIGH

DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `autodiscovery_clear.`

Nov 4, 2024
CVE-2024-45884
8.0 HIGH

DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `setSWMGroup.`

Nov 4, 2024
CVE-2024-45882
8.0 HIGH

DrayTek Vigor3900 1.5.1.3 contains a command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `delete_map_profile.`

Nov 4, 2024
CVE-2024-51672
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPDeveloper BetterLinks betterlinks allows SQL Injection.This issue affects BetterLinks: from n/a …

Nov 4, 2024
CVE-2024-51582
7.5 HIGH

Path Traversal: '.../...//' vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows PHP Local File Inclusion.This issue affects WP Hotel Booking: from n/a through <= 2.2.9.

Nov 4, 2024
CVE-2024-51408
8.5 HIGH

AppSmith Community 1.8.3 before 1.46 allows SSRF via New DataSource for application/json requests to 169.254.169.254 to retrieve AWS metadata credentials.

Nov 4, 2024
CVE-2024-51253
8.0 HIGH

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doL2TP function.

Nov 4, 2024
CVE-2024-51251
8.0 HIGH

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the backup function.

Nov 4, 2024
CVE-2024-51249
8.0 HIGH

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the reboot function.

Nov 4, 2024
CVE-2024-51246
8.0 HIGH

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPTP function.

Nov 4, 2024
CVE-2024-50528
7.5 HIGH

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Retrieve Embedded Sensitive Data.This issue affects …

Nov 4, 2024
CVE-2024-45164
7.1 HIGH

Akamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the latest 19.2.0 patch and Apps Portal before 19.2.0.3 or 19.2.0.20240814, …

Nov 4, 2024
CVE-2024-51561
7.5 HIGH

This vulnerability exists in Aero due to improper implementation of OTP validation mechanism in certain API endpoints. An authenticated remote attacker could exploit this vulnerability …

Nov 4, 2024
CVE-2024-36485
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to SQL Injection in Technician reports option.

Nov 4, 2024
CVE-2024-48878
8.3 HIGH

Zohocorp ManageEngine ADManager Plus versions 7241 and prior are vulnerable to SQL Injection in Archived Audit Report.

Nov 4, 2024
CVE-2024-10389
7.5 HIGH

There exists a Path Traversal vulnerability in Safearchive on Platforms with Case-Insensitive Filesystems (e.g., NTFS). This allows Attackers to Write Arbitrary Files via Archive Extraction …

Nov 4, 2024
CVE-2024-38424
7.8 HIGH

Memory corruption during GNSS HAL process initialization.

Nov 4, 2024
CVE-2024-38423
7.8 HIGH

Memory corruption while processing GPU page table switch.

Nov 4, 2024
CVE-2024-38422
7.8 HIGH

Memory corruption while processing voice packet with arbitrary data received from ADSP.

Nov 4, 2024
CVE-2024-38421
7.8 HIGH

Memory corruption while processing GPU commands.

Nov 4, 2024
CVE-2024-38419
7.8 HIGH

Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node.

Nov 4, 2024
CVE-2024-38415
7.8 HIGH

Memory corruption while handling session errors from firmware.

Nov 4, 2024
CVE-2024-38410
7.8 HIGH

Memory corruption while IOCLT is called when device is in invalid state and the WMI command buffer may be freed twice.

Nov 4, 2024
CVE-2024-38409
7.8 HIGH

Memory corruption while station LL statistic handling.

Nov 4, 2024
CVE-2024-38408
8.2 HIGH

Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.

Nov 4, 2024
CVE-2024-38407
7.8 HIGH

Memory corruption while processing input parameters for any IOCTL call in the JPEG Encoder driver.

Nov 4, 2024
CVE-2024-38406
7.8 HIGH

Memory corruption while handling IOCTL calls in JPEG Encoder driver.

Nov 4, 2024
CVE-2024-38405
7.5 HIGH

Transient DOS while processing the CU information from RNR IE.

Nov 4, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.