CVE Database

40083+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-3778
7.2 HIGH

The file upload functionality of Ai3 QbiBot does not properly restrict types of uploaded files, allowing remote attackers with administrator privilege to upload files with …

Apr 15, 2024
CVE-2024-3769
7.3 HIGH

A vulnerability, which was classified as critical, was found in PHPGurukul Student Record System 3.20. Affected is an unknown function of the file /login.php. The …

Apr 15, 2024
CVE-2024-1655
8.8 HIGH

Certain ASUS WiFi routers models has an OS Command Injection vulnerability, allowing an authenticated remote attacker to execute arbitrary system commands by sending a specially …

Apr 15, 2024
CVE-2024-29843
7.5 HIGH

The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on MOBILE_GET_USERS_LIST, allowing for an unauthenticated attacker to enumerate all …

Apr 15, 2024
CVE-2024-29842
7.5 HIGH

The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_ABACARD_FIELDS, allowing for an unauthenticated attacker to return the …

Apr 15, 2024
CVE-2024-29841
7.5 HIGH

The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_KEYS_FIELDS, allowing for an unauthenticated attacker to return the …

Apr 15, 2024
CVE-2024-29840
7.5 HIGH

The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_PIN_FIELDS, allowing for an unauthenticated attacker to return the …

Apr 15, 2024
CVE-2024-29839
7.5 HIGH

The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control on DESKTOP_EDIT_USER_GET_CARD, allowing for an unauthenticated attacker to return the …

Apr 15, 2024
CVE-2024-29838
7.5 HIGH

The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below does not proper sanitize user input, allowing for an unauthenticated attacker to crash the controller …

Apr 15, 2024
CVE-2024-29837
8.8 HIGH

The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below uses poor session management, allowing for an unauthenticated attacker to access administrator functionality if any …

Apr 15, 2024
CVE-2024-3738
7.3 HIGH

A vulnerability classified as critical has been found in cym1102 nginxWebUI up to 3.9.9. This affects the function handlePath of the file /adminPage/conf/saveCmd. The manipulation …

Apr 13, 2024
CVE-2024-32487
8.6 HIGH

less through 653 allows OS command execution via a newline character in the name of a file, because quoting is mishandled in filename.c. Exploitation typically …

Apr 13, 2024
CVE-2024-28869
7.5 HIGH

Traefik is an HTTP reverse proxy and load balancer. In affected versions sending a GET request to any Traefik endpoint with the "Content-length" request header …

Apr 12, 2024
CVE-2024-32019
8.8 HIGH

Netdata is an open source observability tool. In affected versions the `ndsudo` tool shipped with affected versions of the Netdata Agent allows an attacker to …

Apr 12, 2024
CVE-2024-32005
8.2 HIGH

NiceGUI is an easy-to-use, Python-based UI framework. A local file inclusion is present in the NiceUI leaflet component when requesting resource files under the `/_nicegui/{__version__}/resources/{key}/{path:path}` …

Apr 12, 2024
CVE-2024-32003
8.8 HIGH

wn-dusk-plugin (Dusk plugin) is a plugin which integrates Laravel Dusk browser testing into Winter CMS. The Dusk plugin provides some special routes as part of …

Apr 12, 2024
CVE-2024-29023
7.2 HIGH

Xibo is an Open Source Digital Signage platform with a web content management system and Windows display player software. Session tokens are exposed in the …

Apr 12, 2024
CVE-2024-29022
8.8 HIGH

Xibo is an Open Source Digital Signage platform with a web content management system and Windows display player software. In affected versions some request headers …

Apr 12, 2024
CVE-2024-3691
7.3 HIGH

A vulnerability, which was classified as critical, has been found in PHPGurukul Small CRM 3.0. Affected by this issue is some unknown functionality of the …

Apr 12, 2024
CVE-2024-31069
7.4 HIGH

IO-1020 Micro ELD web server uses a default password for authentication.

Apr 12, 2024
CVE-2024-30398
7.5 HIGH

An Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows …

Apr 12, 2024
CVE-2024-30397
7.5 HIGH

An Improper Check for Unusual or Exceptional Conditions vulnerability in the the Public Key Infrastructure daemon (pkid) of Juniper Networks Junos OS allows an unauthenticated …

Apr 12, 2024
CVE-2024-30392
7.5 HIGH

A Stack-based Buffer Overflow vulnerability in Flow Processing Daemon (flowd) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause Denial of Service …

Apr 12, 2024
CVE-2024-30382
7.5 HIGH

An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based, …

Apr 12, 2024
CVE-2024-30210
7.4 HIGH

IO-1020 Micro ELD uses a default WIFI password that could allow an adjacent attacker to connect to the device.

Apr 12, 2024
CVE-2024-30407
8.1 HIGH

The Use of a Hard-coded Cryptographic Key vulnerability in Juniper Networks Juniper Cloud Native Router (JCNR) and containerized routing Protocol Deamon (cRPD) products allows an …

Apr 12, 2024
CVE-2024-30405
7.5 HIGH

An Incorrect Calculation of Buffer Size vulnerability in Juniper Networks Junos OS SRX 5000 Series devices using SPC2 line cards while ALGs are enabled allows …

Apr 12, 2024
CVE-2024-30395
7.5 HIGH

An Improper Validation of Specified Type of Input vulnerability in Routing Protocol Daemon (RPD) of Junos OS and Junos OS Evolved allows an unauthenticated, network-based …

Apr 12, 2024
CVE-2024-30394
7.5 HIGH

A Stack-based Buffer Overflow vulnerability in the Routing Protocol Daemon (RPD) component of Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to …

Apr 12, 2024
CVE-2024-30381
8.4 HIGH

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Juniper Networks Paragon Active Assurance Control Center allows a network-adjacent attacker with root access …

Apr 12, 2024
CVE-2024-21598
7.5 HIGH

An Improper Validation of Syntactic Correctness of Input vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows …

Apr 12, 2024
CVE-2023-51515
8.8 HIGH

Missing Authorization vulnerability in Undsgn Uncode Core allows Privilege Escalation.This issue affects Uncode Core: from n/a through 2.8.8.

Apr 12, 2024
CVE-2024-3705
8.8 HIGH

Unrestricted file upload vulnerability in OpenGnsys affecting version 1.1.1d (Espeto). This vulnerability allows an attacker to send a POST request to the endpoint '/opengnsys/images/M_Icons.php' modifying …

Apr 12, 2024
CVE-2024-25545
7.8 HIGH

An issue in Weave Weave Desktop v.7.78.10 allows a local attacker to execute arbitrary code via a crafted script to the nwjs framework component.

Apr 12, 2024
CVE-2020-8006
8.8 HIGH

The server in Circontrol Raption through 5.11.2 has a pre-authentication stack-based buffer overflow that can be exploited to gain run-time control of the device as …

Apr 12, 2024
CVE-2024-3211
8.8 HIGH

The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to SQL Injection via the 'productid' attribute of the ec_addtocart shortcode in all versions …

Apr 12, 2024
CVE-2024-3054
7.2 HIGH

WPvivid Backup & Migration Plugin for WordPress is vulnerable to PHAR Deserialization in all versions up to, and including, 0.9.99 via deserialization of untrusted input …

Apr 12, 2024
CVE-2024-29400
7.5 HIGH

An issue was discovered in RuoYi v4.5.1, allows attackers to obtain sensitive information via the status parameter.

Apr 12, 2024
CVE-2024-27309
7.4 HIGH

While an Apache Kafka cluster is being migrated from ZooKeeper mode to KRaft mode, in some cases ACLs will not be correctly enforced. Two preconditions …

Apr 12, 2024
CVE-2023-49528
8.0 HIGH

Buffer Overflow vulnerability in FFmpeg version n6.1-3-g466799d4f5, allows a local attacker to execute arbitrary code and cause a denial of service (DoS) via the af_dialoguenhance.c:261:5 …

Apr 12, 2024
CVE-2023-44857
8.1 HIGH

An issue in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a crafted script to the sub_21D24 function in …

Apr 12, 2024
CVE-2023-44852
8.2 HIGH

Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a crafted script to the …

Apr 12, 2024
CVE-2024-3092
8.7 HIGH

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 before 16.9.4, all versions starting from 16.10 before 16.10.2. A payload …

Apr 12, 2024
CVE-2024-2279
8.7 HIGH

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.7 to 16.8.6 all versions starting from 16.9 before 16.9.4, all versions …

Apr 12, 2024
CVE-2024-28458
7.5 HIGH

Null Pointer Dereference vulnerability in swfdump in swftools 0.9.2 allows attackers to crash the appliation via the function compileSWFActionCode in action/actioncompiler.c.

Apr 11, 2024
CVE-2024-25852
8.8 HIGH

Linksys RE7000 v2.0.9, v2.0.11, and v2.0.15 have a command execution vulnerability in the "AccessControlList" parameter of the access control function point. An attacker can use …

Apr 11, 2024
CVE-2024-25376
7.8 HIGH

An issue discovered in Thesycon Software Solutions Gmbh & Co. KG TUSBAudio MSI-based installers before 5.68.0 allows a local attacker to execute arbitrary code via …

Apr 11, 2024
CVE-2024-22722
7.2 HIGH

Server Side Template Injection (SSTI) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary commands via the Group Name field under the add forms …

Apr 11, 2024
CVE-2024-22719
8.1 HIGH

SQL Injection vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary SQL commands via the 'keyword' when searching for a client.

Apr 11, 2024
CVE-2023-5394
7.4 HIGH

Server receiving a malformed message that where the GCL message hostname may be too large which may cause a stack overflow; resulting in possible remote …

Apr 11, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.