CVE Database

46795+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-38641
7.8 HIGH

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow local network users to …

Sep 6, 2024
CVE-2024-32763
8.8 HIGH

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow …

Sep 6, 2024
CVE-2024-32762
8.2 HIGH

A cross-site scripting (XSS) vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow users to inject malicious code via a …

Sep 6, 2024
CVE-2024-21898
8.8 HIGH

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute …

Sep 6, 2024
CVE-2024-21897
8.9 HIGH

A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to inject …

Sep 6, 2024
CVE-2023-51366
8.7 HIGH

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to read the contents …

Sep 6, 2024
CVE-2023-50360
8.8 HIGH

A SQL injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a …

Sep 6, 2024
CVE-2023-47563
7.4 HIGH

An OS command injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could allow authenticated users to execute commands via a …

Sep 6, 2024
CVE-2023-39300
7.2 HIGH

An OS command injection vulnerability has been reported to affect legacy QTS. If exploited, the vulnerability could allow authenticated administrators to execute commands via a …

Sep 6, 2024
CVE-2023-39298
7.8 HIGH

A missing authorization vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow local authenticated users to access …

Sep 6, 2024
CVE-2023-34974
8.8 HIGH

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands …

Sep 6, 2024
CVE-2024-8509
7.5 HIGH

A vulnerability was found in Forklift Controller. There is no verification against the authorization header except to ensure it uses bearer authentication. Without an Authorization …

Sep 6, 2024
CVE-2024-45294
8.6 HIGH

The HL7 FHIR Core Artifacts repository provides the java core object handling code, with utilities (including validator), for the Fast Healthcare Interoperability Resources (FHIR) specification. …

Sep 6, 2024
CVE-2024-44408
7.5 HIGH

D-Link DIR-823G v1.0.2B05_20181207 is vulnerable to Information Disclosure. The device allows unauthorized configuration file downloads, and the downloaded configuration files contain plaintext user passwords.

Sep 6, 2024
CVE-2024-8428
8.8 HIGH

The ForumWP – Forum & Discussion Board Plugin plugin for WordPress is vulnerable to Privilege Escalation via Insecure Direct Object Reference in all versions up …

Sep 6, 2024
CVE-2024-6445
7.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in DataFlowX Technology DataDiodeX allows Path Traversal.This issue affects DataDiodeX: from v3.0.0 before …

Sep 6, 2024
CVE-2024-45300
7.5 HIGH

alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5, a race condition allows the user …

Sep 6, 2024
CVE-2024-44739
8.8 HIGH

Sourcecodester Simple Forum Website v1.0 has a SQL injection vulnerability in /php-sqlite-forum/?page=manage_user&id=.

Sep 6, 2024
CVE-2024-1744
7.5 HIGH

Authorization Bypass Through User-Controlled Key, Missing Authorization vulnerability in Ariva Computer Accord ORS allows Retrieve Embedded Sensitive Data.This issue affects Accord ORS: before 7.3.2.1.

Sep 6, 2024
CVE-2023-52916
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: media: aspeed: Fix memory overwrite if timing is 1600x900 When capturing 1600x900, system could crash …

Sep 6, 2024
CVE-2024-7349
7.2 HIGH

The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to blind SQL Injection via the 'order' parameter in …

Sep 6, 2024
CVE-2024-39585
7.9 HIGH

Dell SmartFabric OS10 Software, version(s) 10.5.5.4 through 10.5.5.10 and 10.5.6.x, contain(s) an Use of Hard-coded Password vulnerability. A low privileged attacker with remote access could …

Sep 6, 2024
CVE-2024-38486
7.5 HIGH

Dell SmartFabric OS10 Software, version(s) 10.5.5.4 through 10.5.5.10 and 10.5.6.x , contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. …

Sep 6, 2024
CVE-2024-8480
8.8 HIGH

The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

Sep 6, 2024
CVE-2024-8247
8.8 HIGH

The Newsletters plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.9.9.2. This is due to the plugin not …

Sep 6, 2024
CVE-2024-45401
7.5 HIGH

stripe-cli is a command-line tool for the payment processor Stripe. A vulnerability exists in stripe-cli starting in version 1.11.1 and prior to version 1.21.3 where …

Sep 5, 2024
CVE-2024-45392
7.7 HIGH

SuiteCRM is an open-source customer relationship management (CRM) system. Prior to version 7.14.5 and 8.6.2, insufficient access control checks allow a threat actor to delete …

Sep 5, 2024
CVE-2024-45175
8.8 HIGH

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Sensitive information is stored in cleartext. It was found out that sensitive information, for example …

Sep 5, 2024
CVE-2024-45171
8.8 HIGH

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper user input validation, it is possible to upload dangerous files, for instance …

Sep 5, 2024
CVE-2024-45178
7.1 HIGH

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper user input validation, it is possible to download arbitrary files from the …

Sep 5, 2024
CVE-2024-45173
8.8 HIGH

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper privilege management concerning sudo privileges, C-MOR is vulnerable to a privilege escalation …

Sep 5, 2024
CVE-2024-44587
8.8 HIGH

itsourcecode Alton Management System 1.0 is vulnerable to SQL Injection in /noncombo_save.php via the "menu" parameter.

Sep 5, 2024
CVE-2024-7884
7.5 HIGH

When a canister method is called via ic_cdk::call* , a new Future CallFuture is created and can be awaited by the caller to get the …

Sep 5, 2024
CVE-2024-8178
8.8 HIGH

The ctl_write_buffer and ctl_read_buffer functions allocated memory to be returned to userspace, without initializing it. Malicious software running in a guest VM that exposes virtio_scsi …

Sep 5, 2024
CVE-2024-45063
8.8 HIGH

The function ctl_write_buffer incorrectly set a flag which resulted in a kernel Use-After-Free when a command finished processing. Malicious software running in a guest VM …

Sep 5, 2024
CVE-2024-43110
8.8 HIGH

The ctl_request_sense function could expose up to three bytes of the kernel heap to userspace. Malicious software running in a guest VM that exposes virtio_scsi …

Sep 5, 2024
CVE-2024-42416
8.8 HIGH

The ctl_report_supported_opcodes function did not sufficiently validate a field provided by userspace, allowing an arbitrary write to a limited amount of kernel help memory. Malicious …

Sep 5, 2024
CVE-2024-32668
8.2 HIGH

An insufficient boundary validation in the USB code could lead to an out-of-bounds write on the heap, with data controlled by the caller. A malicious, …

Sep 5, 2024
CVE-2024-45288
8.4 HIGH

A missing null-termination character in the last element of an nvlist array string can lead to writing outside the allocated buffer.

Sep 5, 2024
CVE-2024-45287
7.5 HIGH

A malicious value of size in a structure of packed libnv can cause an integer overflow, leading to the allocation of a smaller buffer than …

Sep 5, 2024
CVE-2024-41928
8.4 HIGH

Malicious software running in a guest VM can exploit the buffer overflow to achieve code execution on the host in the bhyve userspace process, which …

Sep 5, 2024
CVE-2024-7627
8.1 HIGH

The Bit File Manager plugin for WordPress is vulnerable to Remote Code Execution in versions 6.0 to 6.5.5 via the 'checkSyntax' function. This is due …

Sep 5, 2024
CVE-2024-45692
7.5 HIGH

Webmin before 2.202 and Virtualmin before 7.20.2 allow a network traffic loop via spoofed UDP packets on port 10000.

Sep 4, 2024
CVE-2024-2166
8.8 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Email Security (Real Time Monitor modules) allows Reflected XSS.This issue affects Email …

Sep 4, 2024
CVE-2024-44999
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: gtp: pull network headers in gtp_dev_xmit() syzbot/KMSAN reported use of uninit-value in get_dev_xmit() [1] We …

Sep 4, 2024
CVE-2024-44998
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: atm: idt77252: prevent use after free in dequeue_rx() We can't dereference "skb" after calling vcc->push() …

Sep 4, 2024
CVE-2024-44997
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk_wed: fix use-after-free panic in mtk_wed_setup_tc_block_cb() When there are multiple ap interfaces on …

Sep 4, 2024
CVE-2024-44993
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Fix out-of-bounds read in `v3d_csd_job_run()` When enabling UBSAN on Raspberry Pi 5, we get …

Sep 4, 2024
CVE-2024-44987
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ipv6: prevent UAF in ip6_send_skb() syzbot reported an UAF in ip6_send_skb() [1] After ip6_local_out() has …

Sep 4, 2024
CVE-2024-44986
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ipv6: fix possible UAF in ip6_finish_output2() If skb_expand_head() returns NULL, skb has been freed and …

Sep 4, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.