CVE Database

40083+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-30202
7.8 HIGH

In Emacs before 29.3, arbitrary Lisp code is evaluated as part of turning on Org mode. This affects Org Mode before 9.6.23.

Mar 25, 2024
CVE-2024-28434
7.6 HIGH

The CRM platform Twenty is vulnerable to stored cross site scripting via file upload in version 0.3.0. A crafted svg file can trigger the execution …

Mar 25, 2024
CVE-2024-28387
7.5 HIGH

An issue in axonaut v.3.1.23 and before allows a remote attacker to obtain sensitive information via the log.txt component.

Mar 25, 2024
CVE-2024-25002
8.8 HIGH

Command Injection in the diagnostics interface of the Bosch Network Synchronizer allows unauthorized users full access to the device.

Mar 25, 2024
CVE-2024-2864
7.3 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KaineLabs Youzify - Buddypress Moderation.This issue affects Youzify - Buddypress Moderation: from n/a …

Mar 25, 2024
CVE-2021-47175
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: net/sched: fq_pie: fix OOB access in the traffic path the following script: # tc qdisc …

Mar 25, 2024
CVE-2021-47160
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: dsa: mt7530: fix VLAN traffic leaks PCR_MATRIX field was set to all 1's when …

Mar 25, 2024
CVE-2021-47153
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: i2c: i801: Don't generate an interrupt on bus reset Now that the i2c-i801 driver supports …

Mar 25, 2024
CVE-2021-47148
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: fix a buffer overflow in otx2_set_rxfh_context() This function is called from ethtool_set_rxfh() and "*rss_context" …

Mar 25, 2024
CVE-2021-47138
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: cxgb4: avoid accessing registers when clearing filters Hardware register having the server TID base can …

Mar 25, 2024
CVE-2021-47137
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: lantiq: fix memory corruption in RX ring In a situation where memory allocation or …

Mar 25, 2024
CVE-2024-24899
7.2 HIGH

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in openEuler aops-zeus on Linux allows Command Injection. This vulnerability is …

Mar 25, 2024
CVE-2024-24897
8.1 HIGH

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in openEuler A-Tune-Collector on Linux allows Command Injection. This vulnerability is associated with …

Mar 25, 2024
CVE-2024-24892
8.1 HIGH

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Improper Privilege Management vulnerability in openEuler migration-tools on Linux allows Command Injection, …

Mar 25, 2024
CVE-2024-24890
7.8 HIGH

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in openEuler gala-gopher on Linux allows Command Injection. This vulnerability is …

Mar 25, 2024
CVE-2021-33632
7.0 HIGH

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in openEuler iSulad on Linux allows Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions. This vulnerability is associated with program …

Mar 25, 2024
CVE-2024-21505
7.5 HIGH

Versions of the package web3-utils before 4.2.1 are vulnerable to Prototype Pollution via the utility functions format and mergeDeep, due to insecure recursive merge. An …

Mar 25, 2024
CVE-2024-1962
8.8 HIGH

The CM Download Manager WordPress plugin before 2.9.1 does not have CSRF checks in some places, which could allow attackers to make logged in admins …

Mar 25, 2024
CVE-2024-29071
8.8 HIGH

HGW BL1500HM Ver 002.001.013 and earlier contains a use of week credentials issue. A network-adjacent unauthenticated attacker may change the system settings.

Mar 25, 2024
CVE-2024-28041
8.8 HIGH

HGW BL1500HM Ver 002.001.013 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary command.

Mar 25, 2024
CVE-2024-29188
7.9 HIGH

WiX toolset lets developers create installers for Windows Installer, the Windows installation engine. The custom action behind WiX's `RemoveFolderEx` functionality could allow a standard user …

Mar 24, 2024
CVE-2024-29187
7.3 HIGH

WiX toolset lets developers create installers for Windows Installer, the Windows installation engine. When a bundle runs as SYSTEM user, Burn uses GetTempPathW which points …

Mar 24, 2024
CVE-2024-29194
8.3 HIGH

OneUptime is a solution for monitoring and managing online services. The vulnerability lies in the improper validation of client-side stored data within the web application. …

Mar 24, 2024
CVE-2024-2856
8.8 HIGH

A vulnerability, which was classified as critical, has been found in Tenda AC10 16.03.10.13/16.03.10.20. Affected by this issue is the function fromSetSysTime of the file …

Mar 24, 2024
CVE-2024-2855
8.8 HIGH

A vulnerability classified as critical was found in Tenda AC15 15.03.05.18/15.03.05.19/15.03.20. Affected by this vulnerability is the function fromSetSysTime of the file /goform/SetSysTimeCfg. The manipulation …

Mar 24, 2024
CVE-2024-2852
8.8 HIGH

A vulnerability was found in Tenda AC15 15.03.20_multi. It has been declared as critical. This vulnerability affects the function saveParentControlInfo of the file /goform/saveParentControlInfo. The …

Mar 24, 2024
CVE-2024-2850
8.8 HIGH

A vulnerability was found in Tenda AC15 15.03.05.18 and classified as critical. Affected by this issue is the function saveParentControlInfo of the file /goform/saveParentControlInfo. The …

Mar 24, 2024
CVE-2024-30156
7.5 HIGH

Varnish Cache before 7.3.2 and 7.4.x before 7.4.3 (and before 6.0.13 LTS), and Varnish Enterprise 6 before 6.0.12r6, allows credits exhaustion for an HTTP/2 connection …

Mar 24, 2024
CVE-2024-24725
8.8 HIGH

Gibbon through 26.0.00 allows remote authenticated users to conduct PHP deserialization attacks via columnOrder in a POST request to the modules/System%20Admin/import_run.php&type=externalAssessment&step=4 URI.

Mar 23, 2024
CVE-2024-23755
8.8 HIGH

ClickUp Desktop before 3.3.77 on macOS and Windows allows code injection because of specific Electron Fuses. There is inadequate protection against code injection through settings …

Mar 23, 2024
CVE-2024-1603
7.5 HIGH

paddlepaddle/paddle 2.6.0 allows arbitrary file read via paddle.vision.ops.read_file.

Mar 23, 2024
CVE-2024-24832
8.2 HIGH

Missing Authorization vulnerability in Metagauss EventPrime.This issue affects EventPrime: from n/a through 3.3.9.

Mar 23, 2024
CVE-2021-33633
7.3 HIGH

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in openEuler aops-ceres on Linux allows Command Injection. This vulnerability is …

Mar 23, 2024
CVE-2024-2025
8.8 HIGH

The "BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages" plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and …

Mar 23, 2024
CVE-2024-29059
7.5 HIGH KEV

.NET Framework Information Disclosure Vulnerability

Mar 23, 2024
CVE-2024-29190
7.5 HIGH

Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. In version 3.9.5 Beta and …

Mar 22, 2024
CVE-2023-5685
7.5 HIGH

A flaw was found in XNIO. The XNIO NotifierState that can cause a Stack Overflow Exception when the chain of notifier states becomes problematically large …

Mar 22, 2024
CVE-2024-29499
7.4 HIGH

Anchor CMS v0.12.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via /anchor/admin/users/delete/2.

Mar 22, 2024
CVE-2024-29366
8.8 HIGH

A command injection vulnerability exists in the cgibin binary in DIR-845L router firmware <= v1.01KRb03.

Mar 22, 2024
CVE-2024-29184
8.0 HIGH

FreeScout is a self-hosted help desk and shared mailbox. A Stored Cross-Site Scripting (XSS) vulnerability has been identified within the Signature Input Field of the …

Mar 22, 2024
CVE-2024-2228
7.1 HIGH

This vulnerability allows an authenticated user to perform a Lifecycle Manager flow or other QuickLink for a target user outside of the defined QuickLink Population.

Mar 22, 2024
CVE-2023-41099
7.8 HIGH

In the Windows installer in Atos Eviden CardOS API before 5.5.5.2811, Local Privilege Escalation can occur.(from a regular user to SYSTEM).

Mar 22, 2024
CVE-2024-2725
7.5 HIGH

Information exposure vulnerability in the CIGESv2 system. A remote attacker might be able to access /vendor/composer/installed.json and retrieve all installed packages used by the application.

Mar 22, 2024
CVE-2024-2449
7.5 HIGH

A cross-site request forgery vulnerability has been identified in LoadMaster. It is possible for a malicious actor, who has prior knowledge of the IP or …

Mar 22, 2024
CVE-2024-2448
8.4 HIGH

An OS command injection vulnerability has been identified in LoadMaster. An authenticated UI user with any permission settings may be able to inject commands into …

Mar 22, 2024
CVE-2024-29944
8.4 HIGH

An attacker was able to inject an event handler into a privileged object that would allow arbitrary JavaScript execution in the parent process. Note: This …

Mar 22, 2024
CVE-2024-28559
8.8 HIGH

SQL injection vulnerability in Niushop B2B2C v.5.3.3 and before allows an attacker to escalate privileges via the setPrice() function of the Goodsbatchset.php component.

Mar 22, 2024
CVE-2024-28824
8.8 HIGH

Least privilege violation and reliance on untrusted inputs in the mk_informix Checkmk agent plugin before Checkmk 2.3.0b4 (beta), 2.2.0p24, 2.1.0p41 and 2.0.0 (EOL) allows local …

Mar 22, 2024
CVE-2024-1848
7.8 HIGH

Heap-based Buffer Overflow, Memory Corruption, Out-Of-Bounds Read, Out-Of-Bounds Write, Stack-based Buffer Overflow, Type Confusion, Uninitialized Variable, Use-After-Free vulnerabilities exist in the file reading procedure in …

Mar 22, 2024
CVE-2024-0638
8.2 HIGH

Least privilege violation in the Checkmk agent plugins mk_oracle, mk_oracle.ps1, and mk_oracle_crs before Checkmk 2.3.0b4 (beta), 2.2.0p24, 2.1.0p41 and 2.0.0 (EOL) allows local users to …

Mar 22, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.