CVE Database

40083+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-2815
8.8 HIGH

A vulnerability classified as critical has been found in Tenda AC15 15.03.20_multi. Affected is the function R7WebsSecurityHandler of the file /goform/execCommand of the component Cookie …

Mar 22, 2024
CVE-2024-2814
8.8 HIGH

A vulnerability was found in Tenda AC15 15.03.20_multi. It has been rated as critical. This issue affects the function fromDhcpListClient of the file /goform/DhcpListClient. The …

Mar 22, 2024
CVE-2024-2813
8.8 HIGH

A vulnerability was found in Tenda AC15 15.03.20_multi. It has been declared as critical. This vulnerability affects the function form_fast_setting_wifi_set of the file /goform/fast_setting_wifi_set. The …

Mar 22, 2024
CVE-2024-2811
8.8 HIGH

A vulnerability was found in Tenda AC15 15.03.20_multi and classified as critical. Affected by this issue is the function formWifiWpsStart of the file /goform/WifiWpsStart. The …

Mar 22, 2024
CVE-2024-2810
8.8 HIGH

A vulnerability has been found in Tenda AC15 15.03.05.18/15.03.20_multi and classified as critical. Affected by this vulnerability is the function formWifiWpsOOB of the file /goform/WifiWpsOOB. …

Mar 22, 2024
CVE-2024-2809
8.8 HIGH

A vulnerability, which was classified as critical, was found in Tenda AC15 15.03.05.18/15.03.20_multi. Affected is the function formSetFirewallCfg of the file /goform/SetFirewallCfg. The manipulation of …

Mar 22, 2024
CVE-2024-2808
8.8 HIGH

A vulnerability, which was classified as critical, has been found in Tenda AC15 15.03.05.18/15.03.20_multi. This issue affects the function formQuickIndex of the file /goform/QuickIndex. The …

Mar 22, 2024
CVE-2024-2807
8.8 HIGH

A vulnerability classified as critical was found in Tenda AC15 15.03.05.18/15.03.20_multi. This vulnerability affects the function formExpandDlnaFile of the file /goform/expandDlnaFile. The manipulation of the …

Mar 22, 2024
CVE-2024-2806
8.8 HIGH

A vulnerability classified as critical has been found in Tenda AC15 15.03.05.18/15.03.20_multi. This affects the function addWifiMacFilter of the file /goform/addWifiMacFilter. The manipulation of the …

Mar 22, 2024
CVE-2024-25808
8.3 HIGH

Cross-site Request Forgery (CSRF) vulnerability in Lychee version 3.1.6, allows remote attackers to execute arbitrary code via the create new album function.

Mar 22, 2024
CVE-2024-2805
8.8 HIGH

A vulnerability was found in Tenda AC15 15.03.05.18/15.03.20_multi. It has been rated as critical. Affected by this issue is the function formSetSpeedWan of the file …

Mar 22, 2024
CVE-2024-29031
7.5 HIGH

Meshery is an open source, cloud native manager that enables the design and management of Kubernetes-based infrastructure and applications. A SQL injection vulnerability in Meshery …

Mar 21, 2024
CVE-2024-28171
8.1 HIGH

It is possible to perform a path traversal attack and write outside of the intended directory. If a file name is specified that already exists …

Mar 21, 2024
CVE-2024-28040
8.8 HIGH

SQL injection vulnerability exists in GetDIAE_astListParameters.

Mar 21, 2024
CVE-2024-25567
8.1 HIGH

Path traversal attack is possible and write outside of the intended directory and may access sensitive information. If a file name is specified that already …

Mar 21, 2024
CVE-2024-23975
8.8 HIGH

SQL injection vulnerability exists in GetDIAE_slogListParameters.

Mar 21, 2024
CVE-2024-23494
8.8 HIGH

SQL injection vulnerability exists in GetDIAE_unListParameters.

Mar 21, 2024
CVE-2024-28891
8.8 HIGH

SQL injection vulnerability exists in the script Handler_CFG.ashx.

Mar 21, 2024
CVE-2024-28521
7.8 HIGH

SQL Injection vulnerability in Netcome NS-ASG Application Security Gateway v.6.3.1 allows a local attacker to execute arbitrary code and obtain sensitive information via a crafted …

Mar 21, 2024
CVE-2024-28119
8.8 HIGH

Grav is an open-source, flat-file content management system. Prior to version 1.7.45, due to the unrestricted access to twig extension class from grav context, an …

Mar 21, 2024
CVE-2024-28118
8.8 HIGH

Grav is an open-source, flat-file content management system. Prior to version 1.7.45, due to the unrestricted access to twig extension class from Grav context, an …

Mar 21, 2024
CVE-2024-28117
8.8 HIGH

Grav is an open-source, flat-file content management system. Prior to version 1.7.45, Grav validates accessible functions through the Utils::isDangerousFunction function, but does not impose restrictions …

Mar 21, 2024
CVE-2024-28116
8.8 HIGH

Grav is an open-source, flat-file content management system. Grav CMS prior to version 1.7.45 is vulnerable to a Server-Side Template Injection (SSTI), which allows any …

Mar 21, 2024
CVE-2024-28029
8.8 HIGH

Privileges are not fully verified server-side, which can be abused by a user with limited privileges to bypass authorization and access privileged functionality.

Mar 21, 2024
CVE-2024-27921
8.8 HIGH

Grav is an open-source, flat-file content management system. A file upload path traversal vulnerability has been identified in the application prior to version 1.7.45, enabling …

Mar 21, 2024
CVE-2024-25937
8.8 HIGH

SQL injection vulnerability exists in the script DIAE_tagHandler.ashx.

Mar 21, 2024
CVE-2024-24272
7.1 HIGH

An issue in iTop DualSafe Password Manager & Digital Vault before 1.4.24 allows a local attacker to obtain sensitive information via leaked credentials as plaintext …

Mar 21, 2024
CVE-2024-2764
8.8 HIGH

A vulnerability, which was classified as critical, was found in Tenda AC10U 15.03.06.48. This affects the function formSetPPTPServer of the file /goform/SetPptpServerCfg. The manipulation of …

Mar 21, 2024
CVE-2024-2763
8.8 HIGH

A vulnerability, which was classified as critical, has been found in Tenda AC10U 15.03.06.48. Affected by this issue is the function formSetCfm of the file …

Mar 21, 2024
CVE-2024-29180
7.4 HIGH

Prior to versions 7.1.0, 6.1.2, and 5.3.4, the webpack-dev-middleware development middleware for devpack does not validate the supplied URL address sufficiently before returning the local …

Mar 21, 2024
CVE-2024-27968
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Optimole Super Page Cache for Cloudflare allows Stored XSS.This issue affects Super Page Cache for Cloudflare: from n/a through …

Mar 21, 2024
CVE-2024-27964
8.8 HIGH

Unrestricted Upload of File with Dangerous Type vulnerability in Gesundheit Bewegt GmbH Zippy.This issue affects Zippy: from n/a through 1.6.9.

Mar 21, 2024
CVE-2024-27962
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Florian 'fkrauthan' Krauthan allows Reflected XSS.This issue affects wp-mpdf: from n/a through 3.7.1.

Mar 21, 2024
CVE-2024-2465
7.1 HIGH

Open redirection vulnerability in CDeX application allows to redirect users to arbitrary websites via a specially crafted URL.This issue affects CDeX application versions through 5.7.1.

Mar 21, 2024
CVE-2024-2463
8.0 HIGH

Weak password recovery mechanism in CDeX application allows to retrieve password reset token.This issue affects CDeX application versions through 5.7.1.

Mar 21, 2024
CVE-2024-27994
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in YITHEMES YITH WooCommerce Product Add-Ons yith-woocommerce-product-add-ons.This issue affects YITH WooCommerce Product Add-Ons: from …

Mar 21, 2024
CVE-2024-27993
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in typps Calendarista Basic Edition calendarista-basic-edition.This issue affects Calendarista Basic Edition: from n/a through …

Mar 21, 2024
CVE-2024-29879
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/index/getdepartments/format/html, 'business_id' parameter. The exploitation of this vulnerability could allow a remote user to send a specially …

Mar 21, 2024
CVE-2024-29878
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/sitepreference/add, 'description' parameter. The exploitation of this vulnerability could allow a remote user to send a specially …

Mar 21, 2024
CVE-2024-29877
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in Sentrifugo 3.2, through /sentrifugo/index.php/expenses/expensecategories/edit, 'expense_category_name' parameter. The exploitation of this vulnerability could allow a remote user to send a specially …

Mar 21, 2024
CVE-2024-1394
7.5 HIGH

A memory leak flaw was found in Golang in the RSA encrypting/decrypting code, which might lead to a resource exhaustion vulnerability using attacker-controlled inputs​. The …

Mar 21, 2024
CVE-2024-29131
7.3 HIGH

Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are recommended to upgrade to version 2.10.1, which …

Mar 21, 2024
CVE-2024-2162
8.8 HIGH

An OS Command Injection vulnerability in Kiloview NDI allows a low-privileged user to execute arbitrary code remotely on the device with high privileges. This issue …

Mar 21, 2024
CVE-2024-29862
7.5 HIGH

The Kerlink firewall in ChirpStack chirpstack-mqtt-forwarder before 4.2.1 and chirpstack-gateway-bridge before 4.0.11 wrongly accepts certain TCP packets when a connection is not in the ESTABLISHED …

Mar 21, 2024
CVE-2024-1538
8.8 HIGH

The File Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.2.4. This is due to missing …

Mar 21, 2024
CVE-2024-2053
7.5 HIGH

The Artica Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subsequently enable code execution as the "www-data" user. This …

Mar 21, 2024
CVE-2024-2014
7.3 HIGH

A vulnerability classified as critical was found in Panabit Panalog 202103080942. This vulnerability affects unknown code of the file /Maintain/sprog_upstatus.php. The manipulation of the argument …

Mar 21, 2024
CVE-2024-28286
7.5 HIGH

In mz-automation libiec61850 v1.4.0, a NULL Pointer Dereference was detected in the mmsServer_handleFileCloseRequest.c function of src/mms/iso_mms/server/mms_file_service.c. The vulnerability manifests as SEGV and causes the application …

Mar 21, 2024
CVE-2024-28123
7.3 HIGH

Wasmi is an efficient and lightweight WebAssembly interpreter with a focus on constrained and embedded systems. In the WASMI Interpreter, an Out-of-bounds Buffer Write will …

Mar 21, 2024
CVE-2024-28101
7.5 HIGH

The Apollo Router is a graph router written in Rust to run a federated supergraph that uses Apollo Federation. Versions 0.9.5 until 1.40.2 are subject …

Mar 21, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.