CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2021-1494
5.8 MEDIUM

Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file …

Nov 15, 2024
CVE-2021-1491
6.5 MEDIUM

A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to read arbitrary files on the underlying file …

Nov 15, 2024
CVE-2021-1484
6.5 MEDIUM

A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to inject arbitrary commands on an affected system and …

Nov 15, 2024
CVE-2021-1483
6.4 MEDIUM

A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that …

Nov 15, 2024
CVE-2021-1482
6.4 MEDIUM

A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization checking and gain access to …

Nov 15, 2024
CVE-2021-1481
4.3 MEDIUM

A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct Cypher query language injection attacks on …

Nov 15, 2024
CVE-2021-1470
4.9 MEDIUM

A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected …

Nov 15, 2024
CVE-2021-1466
5.4 MEDIUM

A vulnerability in the vDaemon service of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to cause a buffer overflow on an affected system, …

Nov 15, 2024
CVE-2021-1464
5.0 MEDIUM

A vulnerability in Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization checking and gain restricted access to the configuration information of …

Nov 15, 2024
CVE-2024-52555
6.3 MEDIUM

In JetBrains WebStorm before 2024.3 code execution in Untrusted Project mode was possible via type definitions installer script

Nov 15, 2024
CVE-2024-52526
4.8 MEDIUM

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Services" tab of the Device page allows authenticated users …

Nov 15, 2024
CVE-2024-51497
4.8 MEDIUM

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Custom OID" tab of a device allows authenticated users …

Nov 15, 2024
CVE-2024-51496
4.8 MEDIUM

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Reflected Cross-Site Scripting (XSS) vulnerability in the "metric" parameter of the "/wireless" and "/health" endpoints allows …

Nov 15, 2024
CVE-2024-51495
4.8 MEDIUM

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the Device Overview page allows authenticated users to inject arbitrary …

Nov 15, 2024
CVE-2024-51494
4.8 MEDIUM

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Port Settings" page allows authenticated users to inject arbitrary …

Nov 15, 2024
CVE-2024-50652
4.3 MEDIUM

A file upload vulnerability in java_shop 1.0 allows attackers to upload arbitrary files by modifying the avatar function.

Nov 15, 2024
CVE-2024-50651
6.5 MEDIUM

java_shop 1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of users with different IDs by modifying the ID parameter.

Nov 15, 2024
CVE-2024-50355
4.8 MEDIUM

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. User with Admin role can edit the Display Name of a device, the application did not properly …

Nov 15, 2024
CVE-2024-50352
4.8 MEDIUM

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Services" section of the Device Overview page allows authenticated …

Nov 15, 2024
CVE-2024-50351
4.8 MEDIUM

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Reflected Cross-Site Scripting (XSS) vulnerability in the "section" parameter of the "logs" tab of a device …

Nov 15, 2024
CVE-2024-50350
4.8 MEDIUM

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Port Settings" page allows authenticated users to inject arbitrary …

Nov 15, 2024
CVE-2024-49764
4.8 MEDIUM

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Capture Debug Information" page allows authenticated users to inject …

Nov 15, 2024
CVE-2024-49759
4.8 MEDIUM

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Manage User Access" page allows authenticated users to inject …

Nov 15, 2024
CVE-2024-49758
4.8 MEDIUM

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. User with Admin role can add Notes to a device, the application did not properly sanitize the …

Nov 15, 2024
CVE-2024-11245
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in code-projects Farmacia 1.0. This issue affects some unknown processing of the file /editar-produto.php. The …

Nov 15, 2024
CVE-2024-11244
6.3 MEDIUM

A vulnerability classified as critical was found in code-projects Farmacia 1.0. This vulnerability affects unknown code of the file /editar-cliente.php. The manipulation of the argument …

Nov 15, 2024
CVE-2023-20094
4.3 MEDIUM

A vulnerability in Cisco TelePresence CE and RoomOS could allow an unauthenticated, adjacent attacker to view sensitive information on an affected device. This vulnerability exists …

Nov 15, 2024
CVE-2023-20093
4.4 MEDIUM

Three vulnerabilities in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to overwrite arbitrary files on the local file …

Nov 15, 2024
CVE-2023-20092
4.4 MEDIUM

Three vulnerabilities in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to overwrite arbitrary files on the local file …

Nov 15, 2024
CVE-2023-20091
5.1 MEDIUM

A vulnerability in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to overwrite arbitrary files on the local file …

Nov 15, 2024
CVE-2023-20090
6.7 MEDIUM

A vulnerability in Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability …

Nov 15, 2024
CVE-2023-20060
6.1 MEDIUM

A vulnerability in the web-based management interface of Cisco Prime Collaboration Deployment could allow an unauthenticated, remote attacker to conduct a cross-site scripting attack against …

Nov 15, 2024
CVE-2023-20039
5.5 MEDIUM

A vulnerability in Cisco IND could allow an authenticated, local attacker to read application data. This vulnerability is due to insufficient default file permissions that …

Nov 15, 2024
CVE-2023-20004
4.4 MEDIUM

Three vulnerabilities in the CLI of Cisco TelePresence CE and RoomOS could allow an authenticated, local attacker to overwrite arbitrary files on the local file …

Nov 15, 2024
CVE-2022-20948
5.4 MEDIUM

A vulnerability in the web management interface of Cisco BroadWorks Hosted Thin Receptionist could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack …

Nov 15, 2024
CVE-2022-20939
4.3 MEDIUM

A vulnerability in the web-based management interface of Cisco Smart Software Manager On-Prem could allow an authenticated, remote attacker to elevate privileges on an affected system. …

Nov 15, 2024
CVE-2022-20931
6.5 MEDIUM

A vulnerability in the version control of Cisco TelePresence CE Software for Cisco Touch 10 Devices could allow an unauthenticated, adjacent attacker to install an older version …

Nov 15, 2024
CVE-2022-20871
6.3 MEDIUM

A vulnerability in the web management interface of Cisco AsyncOS for Cisco Secure Web Appliance, formerly Cisco Web Security Appliance (WSA), could allow an authenticated, remote attacker to perform …

Nov 15, 2024
CVE-2022-20849
6.1 MEDIUM

A vulnerability in the Broadband Network Gateway PPP over Ethernet (PPPoE) feature of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause the …

Nov 15, 2024
CVE-2022-20846
4.3 MEDIUM

A vulnerability in the Cisco Discovery Protocol implementation for Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause the Cisco Discovery Protocol process to reload …

Nov 15, 2024
CVE-2022-20845
6.0 MEDIUM

A vulnerability in the TL1 function of Cisco Network Convergence System (NCS) 4000 Series could allow an authenticated, local attacker to cause a memory leak in …

Nov 15, 2024
CVE-2022-20793
6.8 MEDIUM

A vulnerability in pairing process of Cisco TelePresence CE Software and RoomOS Software for Cisco Touch 10 Devices could allow an unauthenticated, remote attacker to impersonate a …

Nov 15, 2024
CVE-2022-20766
5.3 MEDIUM

A vulnerability in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Adaptive Telephone Adapter firmware could allow an unauthenticated, remote attacker to cause a DoS …

Nov 15, 2024
CVE-2022-20663
6.1 MEDIUM

A vulnerability in the web-based management interface of Cisco Secure Network Analytics, formerly Stealthwatch Enterprise, could allow an unauthenticated, remote attacker to conduct a cross-site scripting …

Nov 15, 2024
CVE-2022-20657
6.1 MEDIUM

A vulnerability in the web-based management interface of Cisco PI and Cisco EPNM could allow an unauthenticated, remote attacker to conduct an XSS attack against a user …

Nov 15, 2024
CVE-2022-20656
6.5 MEDIUM

A vulnerability in the web-based management interface of Cisco PI and Cisco EPNM could allow an authenticated, remote attacker to conduct a path traversal attack on an …

Nov 15, 2024
CVE-2022-20654
6.1 MEDIUM

A vulnerability in the web-based interface of Cisco Webex Meetings could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user …

Nov 15, 2024
CVE-2022-20652
6.5 MEDIUM

A vulnerability in the web-based management interface and in the API subsystem of Cisco Tetration could allow an authenticated, remote attacker to inject arbitrary commands to …

Nov 15, 2024
CVE-2022-20648
5.3 MEDIUM

A vulnerability in a debug function for Cisco RCM for Cisco StarOS Software could allow an unauthenticated, remote attacker to perform debug actions that could result in …

Nov 15, 2024
CVE-2022-20634
4.7 MEDIUM

A vulnerability in the web-based management interface of Cisco ECE could allow an unauthenticated, remote attacker to redirect a user to an undesired web page. This …

Nov 15, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.