CVE Database

46624+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-47939
7.7 HIGH

Stack-based buffer overflow vulnerability exists in multiple laser printers and MFPs which implement Ricoh Web Image Monitor. If this vulnerability is exploited, receiving a specially …

Nov 1, 2024
CVE-2024-10608
7.3 HIGH

A vulnerability was found in code-projects Courier Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file …

Nov 1, 2024
CVE-2024-10607
7.3 HIGH

A vulnerability was found in code-projects Courier Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /track-result.php. …

Nov 1, 2024
CVE-2024-10600
7.3 HIGH

A vulnerability, which was classified as critical, was found in Tongda OA 2017 up to 11.6. Affected is an unknown function of the file pda/appcenter/submenu.php. …

Oct 31, 2024
CVE-2024-48360
7.5 HIGH

Qualitor v8.24 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /request/viewValidacao.php.

Oct 31, 2024
CVE-2024-39722
7.5 HIGH

An issue was discovered in Ollama before 0.1.46. It exposes which files exist on the server on which it is deployed via path traversal in …

Oct 31, 2024
CVE-2024-39721
7.5 HIGH

An issue was discovered in Ollama before 0.1.34. The CreateModelHandler function uses os.Open to read a file until completion. The req.Path parameter is user-controlled and …

Oct 31, 2024
CVE-2024-39720
8.2 HIGH

An issue was discovered in Ollama before 0.1.46. An attacker can use two HTTP requests to upload a malformed GGUF file containing just 4 bytes …

Oct 31, 2024
CVE-2024-39719
7.5 HIGH

An issue was discovered in Ollama through 0.3.14. File existence disclosure can occur via api/create. When calling the CreateModel route with a path parameter that …

Oct 31, 2024
CVE-2024-51066
7.5 HIGH

An Insecure Direct Object Reference (IDOR) vulnerability in appointment-detail.php in Phpgurukul's Beauty Parlour Management System v1.1 allows unauthorized access to the Personally Identifiable Information (PII) …

Oct 31, 2024
CVE-2024-48200
8.4 HIGH

An issue in MobaXterm v24.2 allows a local attacker to escalate privileges and execute arbitrary code via the remove function of the MobaXterm MSI is …

Oct 31, 2024
CVE-2024-8185
7.5 HIGH

Vault Community and Vault Enterprise (“Vault”) clusters using Vault’s Integrated Storage backend are vulnerable to a denial-of-service (DoS) attack through memory exhaustion through a Raft …

Oct 31, 2024
CVE-2024-51254
8.8 HIGH

DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the sign_cacertificate function.

Oct 31, 2024
CVE-2024-43383
8.0 HIGH

Deserialization of Untrusted Data vulnerability in Apache Lucene.Net.Replicator. This issue affects Apache Lucene.NET's Replicator library: from 4.8.0-beta00005 through 4.8.0-beta00016. An attacker that can intercept traffic …

Oct 31, 2024
CVE-2024-21537
8.8 HIGH

Versions of the package lilconfig from 3.1.0 and before 3.1.1 are vulnerable to Arbitrary Code Execution due to the insecure usage of eval in the …

Oct 31, 2024
CVE-2024-48311
8.8 HIGH

Piwigo v14.5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Edit album function.

Oct 31, 2024
CVE-2024-10561
7.3 HIGH

A vulnerability was found in Codezips Pet Shop Management System 1.0. It has been classified as critical. This affects an unknown part of the file …

Oct 31, 2024
CVE-2024-10556
7.3 HIGH

A vulnerability, which was classified as critical, was found in Codezips Pet Shop Management System 1.0. Affected is an unknown function of the file birdsadd.php. …

Oct 31, 2024
CVE-2024-10006
8.3 HIGH

A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using Headers in L7 traffic intentions could bypass HTTP header based access rules.

Oct 30, 2024
CVE-2024-10005
8.1 HIGH

A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using URL paths in L7 traffic intentions could bypass HTTP request path-based access …

Oct 30, 2024
CVE-2024-51426
8.8 HIGH

An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an unspecified impact via the …

Oct 30, 2024
CVE-2024-51425
8.8 HIGH

An issue in the WaterToken smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an unspecified impact. NOTE: this …

Oct 30, 2024
CVE-2024-51243
7.2 HIGH

The eladmin v2.7 and before contains a remote code execution (RCE) vulnerability that can control all application deployment servers of this management system via DeployController.java.

Oct 30, 2024
CVE-2024-48735
7.7 HIGH

Directory Traversal in /SASStudio/sasexec/sessions/{sessionID}/workspace/{InternalPath} in SAS Studio 9.4 allows remote attacker to access internal files by manipulating default path during file download. NOTE: this is …

Oct 30, 2024
CVE-2024-48734
8.8 HIGH

Unrestricted file upload in /SASStudio/SASStudio/sasexec/{sessionID}/{InternalPath} in SAS Studio 9.4 allows remote attacker to upload malicious files. NOTE: this is disputed by the vendor because file …

Oct 30, 2024
CVE-2024-48733
8.8 HIGH

SQL injection vulnerability in /SASStudio/sasexec/sessions/{sessionID}/sql in SAS Studio 9.4 allows remote attacker to execute arbitrary SQL commands via the POST body request. NOTE: this is …

Oct 30, 2024
CVE-2024-48093
8.0 HIGH

Unrestricted File Upload in the Discussions tab in Operately v.0.1.0 allows a privileged user to achieve Remote Code Execution via uploading and executing malicious files …

Oct 30, 2024
CVE-2023-52066
7.2 HIGH

http.zig commit 76cf5 was discovered to contain a CRLF injection vulnerability via the url parameter.

Oct 30, 2024
CVE-2024-48271
8.8 HIGH

D-Link DSL6740C v6.TR069.20211230 was discovered to use insecure default credentials for Administrator access, possibly allowing attackers to bypass authentication and escalate privileges on the device …

Oct 30, 2024
CVE-2024-9419
7.8 HIGH

Client / Server PCs with the HP Smart Universal Printing Driver installed are potentially vulnerable to Remote Code Execution and/or Elevation of Privilege. A client …

Oct 30, 2024
CVE-2024-48647
7.2 HIGH

A file disclosure vulnerability exists in Sage 1000 v7.0.0. This vulnerability allows remote attackers to retrieve arbitrary files from the server's file system by manipulating …

Oct 30, 2024
CVE-2024-48646
8.1 HIGH

An Unrestricted File Upload vulnerability exists in Sage 1000 v7.0.0, which allows authorized users to upload files without proper validation. An attacker could exploit this …

Oct 30, 2024
CVE-2024-48214
8.4 HIGH

KERUI HD 3MP 1080P Tuya Camera 1.0.4 has a command injection vulnerability in the module that connects to the local network via a QR code. …

Oct 30, 2024
CVE-2024-42041
8.1 HIGH

The com.videodownload.browser.videodownloader (aka AppTool-Browser-Video All Video Downloader) application 20-30.05.24 for Android allows an attacker to execute arbitrary JavaScript code via the acr.browser.lightning.DefaultBrowserActivity component.

Oct 30, 2024
CVE-2024-37573
8.4 HIGH

The Talkatone com.talkatone.android application 8.4.6 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted …

Oct 30, 2024
CVE-2024-36060
8.8 HIGH

EnGenius EnStation5-AC A8J-ENS500AC 1.0.0 devices allow blind OS command injection via shell metacharacters in the Ping and Speed Test parameters.

Oct 30, 2024
CVE-2024-51258
8.8 HIGH

DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doSSLTunnel function.

Oct 30, 2024
CVE-2024-51301
8.8 HIGH

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the packet_monitor function.

Oct 30, 2024
CVE-2024-51300
8.8 HIGH

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the get_rrd function.

Oct 30, 2024
CVE-2024-51299
8.8 HIGH

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the dumpSyslog function.

Oct 30, 2024
CVE-2024-51296
8.8 HIGH

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the pingtrace function.

Oct 30, 2024
CVE-2024-51257
8.8 HIGH

DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doCertificate function.

Oct 30, 2024
CVE-2024-33700
7.5 HIGH

The LevelOne WBR-6012 router firmware R0.40e6 suffers from an input validation vulnerability within its FTP functionality, enabling attackers to cause a denial of service through …

Oct 30, 2024
CVE-2024-31151
8.1 HIGH

A security flaw involving hard-coded credentials in LevelOne WBR-6012's web services allows attackers to gain unauthorized access during the first 30 seconds post-boot. Other vulnerabilities …

Oct 30, 2024
CVE-2024-28875
8.1 HIGH

A security flaw involving hard-coded credentials in LevelOne WBR-6012's web services allows attackers to gain unauthorized access during the first 30 seconds post-boot. Other vulnerabilities …

Oct 30, 2024
CVE-2024-24777
8.8 HIGH

A cross-site request forgery (CSRF) vulnerability exists in the Web Application functionality of the LevelOne WBR-6012 R0.40e6. A specially crafted HTTP request can lead to …

Oct 30, 2024
CVE-2024-51304
8.8 HIGH

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the ldap_search_dn function.

Oct 30, 2024
CVE-2024-9632
7.8 HIGH

A flaw was found in the X.org server. Due to improperly tracked allocation size in _XkbSetCompatMap, a local attacker may be able to trigger a …

Oct 30, 2024
CVE-2024-50509
8.6 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Chetan Khandla Woocommerce Product Design woo-product-design allows Path Traversal.This issue affects Woocommerce …

Oct 30, 2024
CVE-2024-50508
7.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Chetan Khandla Woocommerce Product Design woo-product-design allows Path Traversal.This issue affects Woocommerce …

Oct 30, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.