CVE Database

40083+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-51794
7.8 HIGH

Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/af_stereowiden.c:120:69.

Apr 26, 2024
CVE-2023-51365
8.7 HIGH

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to read the contents …

Apr 26, 2024
CVE-2023-51364
8.7 HIGH

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to read the contents …

Apr 26, 2024
CVE-2023-50363
7.4 HIGH

An incorrect authorization vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to bypass intended …

Apr 26, 2024
CVE-2024-1789
7.2 HIGH

The WP SMTP plugin for WordPress is vulnerable to SQL Injection via the 'search' parameter in versions 1.2 to 1.2.6 due to insufficient escaping on …

Apr 26, 2024
CVE-2023-6116
8.9 HIGH

Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the camera. An attacker could inject malicious …

Apr 26, 2024
CVE-2023-6096
7.4 HIGH

Vladimir Kononovich, a Security Researcher has found a flaw that using a inappropriate encryption logic on the DVR. firmware encryption is broken and allows to …

Apr 26, 2024
CVE-2023-6095
8.9 HIGH

Vladimir Kononovich, a Security Researcher has found a flaw that allows for a remote code execution on the DVR. An attacker could inject malicious HTTP …

Apr 26, 2024
CVE-2024-4056
7.5 HIGH

Denial of service condition in M-Files Server in versions before 24.4.13592.4 and after 23.11 (excluding 24.2 LTS) allows unauthenticated user to consume computing resources.

Apr 26, 2024
CVE-2024-3075
8.1 HIGH

The MM-email2image WordPress plugin through 0.2.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the …

Apr 26, 2024
CVE-2024-3154
7.2 HIGH

A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation. Any user who can create a pod …

Apr 26, 2024
CVE-2024-32406
7.5 HIGH

Server-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1 allows a remote attacker to execute arbitrary code via a crafted payload to the Batch-Issue …

Apr 26, 2024
CVE-2024-4163
8.0 HIGH

The Skylab IGX IIoT Gateway allowed users to connect to it via a limited shell terminal (IGX). However, it was discovered that the process was …

Apr 26, 2024
CVE-2024-31755
7.6 HIGH

cJSON v1.7.17 was discovered to contain a segmentation violation, which can trigger through the second parameter of function cJSON_SetValuestring at cJSON.c.

Apr 26, 2024
CVE-2024-33673
7.8 HIGH

An issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. Improper access controls allow for DLL Hijacking in the Windows DLL Search path.

Apr 26, 2024
CVE-2024-33672
7.7 HIGH

An issue was discovered in Veritas NetBackup before 10.4. The Multi-Threaded Agent used in NetBackup can be leveraged to perform arbitrary file deletion on protected …

Apr 26, 2024
CVE-2024-33671
7.7 HIGH

An issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. The Backup Exec Deduplication Multi-threaded Streaming Agent can be leveraged to perform arbitrary …

Apr 26, 2024
CVE-2024-33666
8.6 HIGH

An issue was discovered in Zammad before 6.3.0. Users with customer access to a ticket could have accessed time accounting details of this ticket via …

Apr 26, 2024
CVE-2024-31609
7.1 HIGH

Cross Site Scripting (XSS) vulnerability in BOSSCMS v3.10 allows attackers to run arbitrary code via the header code and footer code fields in code configuration.

Apr 25, 2024
CVE-2024-32324
7.8 HIGH

Buffer Overflow vulnerability in Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 v.3.2 allows a local attacker to execute arbitrary code via the vpn_client_ip variable of the …

Apr 25, 2024
CVE-2024-3625
7.3 HIGH

A flaw was found in Quay, where Quay's database is stored in plain text in mirror-registry on Jinja's config.yaml file. This issue leaves the possibility …

Apr 25, 2024
CVE-2024-3624
7.3 HIGH

A flaw was found in how Quay's database is stored in plain-text in mirror-registry on the jinja's config.yaml file. This flaw allows a malicious actor …

Apr 25, 2024
CVE-2024-3622
8.8 HIGH

A flaw was found when using mirror-registry to install Quay. It uses a default secret, which is stored in plain-text format in one of the …

Apr 25, 2024
CVE-2024-32358
7.5 HIGH

An issue in Jpress v.5.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the custom plug-in module function, a different …

Apr 25, 2024
CVE-2024-28241
7.3 HIGH

The GLPI Agent is a generic management agent. Prior to version 1.7.2, a local user can modify GLPI-Agent code or used DLLs to modify agent …

Apr 25, 2024
CVE-2024-28240
7.3 HIGH

The GLPI Agent is a generic management agent. A vulnerability that only affects GLPI-Agent installed on windows via MSI packaging can allow a local user …

Apr 25, 2024
CVE-2024-1657
8.1 HIGH

A flaw was found in the ansible automation platform. An insecure WebSocket connection was being used in installation from the Ansible rulebook EDA server. An …

Apr 25, 2024
CVE-2024-1139
7.7 HIGH

A credentials leak vulnerability was found in the cluster monitoring operator in OCP. This issue may allow a remote attacker who has basic login credentials …

Apr 25, 2024
CVE-2023-6596
7.5 HIGH

An incomplete fix was shipped for the Rapid Reset (CVE-2023-44487/CVE-2023-39325) vulnerability for an OpenShift Containers.

Apr 25, 2024
CVE-2024-22391
7.7 HIGH

A heap-based buffer overflow vulnerability exists in the LookupTable::SetLUT functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted malformed file can lead to memory …

Apr 25, 2024
CVE-2024-22373
8.1 HIGH

An out-of-bounds write vulnerability exists in the JPEG2000Codec::DecodeByStreamsCommon functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted DICOM file can lead to a heap …

Apr 25, 2024
CVE-2024-4171
8.8 HIGH

A vulnerability classified as critical has been found in Tenda W30E 1.0/1.0.1.25. Affected is the function fromWizardHandle of the file /goform/WizardHandle. The manipulation of the …

Apr 25, 2024
CVE-2024-4024
7.3 HIGH

An issue has been discovered in GitLab CE/EE affecting all versions starting from 7.8 before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions …

Apr 25, 2024
CVE-2024-4170
8.8 HIGH

A vulnerability was found in Tenda 4G300 1.01.42. It has been rated as critical. This issue affects the function sub_429A30. The manipulation of the argument …

Apr 25, 2024
CVE-2024-4169
8.8 HIGH

A vulnerability was found in Tenda 4G300 1.01.42. It has been declared as critical. This vulnerability affects the function sub_42775C/sub_4279CC. The manipulation of the argument …

Apr 25, 2024
CVE-2024-33247
8.8 HIGH

Sourcecodester Employee Task Management System v1.0 is vulnerable to SQL Injection via admin-manage-user.php.

Apr 25, 2024
CVE-2024-4168
8.8 HIGH

A vulnerability was found in Tenda 4G300 1.01.42. It has been classified as critical. This affects the function sub_4260F0. The manipulation of the argument upfilen …

Apr 25, 2024
CVE-2024-4167
8.8 HIGH

A vulnerability was found in Tenda 4G300 1.01.42 and classified as critical. Affected by this issue is the function sub_422AA4. The manipulation of the argument …

Apr 25, 2024
CVE-2024-4166
8.8 HIGH

A vulnerability has been found in Tenda 4G300 1.01.42 and classified as critical. Affected by this vulnerability is the function sub_41E858. The manipulation of the …

Apr 25, 2024
CVE-2024-4165
8.8 HIGH

A vulnerability, which was classified as critical, was found in Tenda G3 15.11.0.17(9502). Affected is the function modifyDhcpRule of the file /goform/modifyDhcpRule. The manipulation of …

Apr 25, 2024
CVE-2024-4164
8.8 HIGH

A vulnerability, which was classified as critical, has been found in Tenda G3 15.11.0.17(9502). This issue affects the function formModifyPppAuthWhiteMac of the file /goform/ModifyPppAuthWhiteMac. The …

Apr 25, 2024
CVE-2024-2829
7.5 HIGH

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.5 before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions …

Apr 25, 2024
CVE-2024-2434
8.5 HIGH

An issue has been discovered in GitLab affecting all versions of GitLab CE/EE 16.9 prior to 16.9.6, 16.10 prior to 16.10.4, and 16.11 prior to …

Apr 25, 2024
CVE-2024-4077
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AndonDesign UDesign allows Reflected XSS.This issue affects UDesign: from n/a through 4.7.3.

Apr 25, 2024
CVE-2024-25583
7.5 HIGH

A crafted response from an upstream server the recursor has been configured to forward-recurse to can cause a Denial of Service in the Recursor. The …

Apr 25, 2024
CVE-2024-25917
8.8 HIGH

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in CodeRevolution WP Setup Wizard.This issue affects WP Setup Wizard: from n/a through 1.0.8.1.

Apr 25, 2024
CVE-2024-4173
7.6 HIGH

A vulnerability in Brocade SANnav exposes Kafka in the wan interface. The vulnerability could allow an unauthenticated attacker to perform various attacks, including DOS against …

Apr 25, 2024
CVE-2024-4161
8.6 HIGH

In Brocade SANnav, before Brocade SANnav v2.3.0, syslog traffic received clear text. This could allow an unauthenticated, remote attacker to capture sensitive information.

Apr 25, 2024
CVE-2024-29205
7.5 HIGH

An Improper Check for Unusual or Exceptional Conditions vulnerability in the web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) …

Apr 25, 2024
CVE-2024-23527
7.5 HIGH

An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthenticated remote attacker to read sensitive information …

Apr 25, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.