CVE Database

40083+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-28848
8.8 HIGH

OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. The `‎CompiledRule::validateExpression` method …

Mar 15, 2024
CVE-2024-28847
8.8 HIGH

OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. Similarly to the …

Mar 15, 2024
CVE-2024-28254
8.8 HIGH

OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. The `‎AlertUtil::validateExpression` method …

Mar 15, 2024
CVE-2024-27920
7.4 HIGH

projectdiscovery/nuclei is a fast and customisable vulnerability scanner based on simple YAML based DSL. A significant security oversight was identified in Nuclei v3, involving the …

Mar 15, 2024
CVE-2024-28854
7.5 HIGH

tls-listener is a rust lang wrapper around a connection listener to support TLS. With the default configuration of tls-listener, a malicious user can open 6.4 …

Mar 15, 2024
CVE-2024-28252
7.5 HIGH

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. If you have a NetFraming based CoreWCF service, extra …

Mar 15, 2024
CVE-2023-7060
8.6 HIGH

Zephyr OS IP packet handling does not properly drop IP packets arriving on an external interface with a source address equal to 127.0.01 or the …

Mar 15, 2024
CVE-2024-28404
8.0 HIGH

TOTOLINK X2000R before V1.0.0-B20231213.1013 contains a Stored Cross-site scripting (XSS) vulnerability in MAC Filtering under the Firewall Page.

Mar 15, 2024
CVE-2023-7009
8.2 HIGH

Some Sciener-based locks support plaintext message processing over Bluetooth Low Energy, allowing unencrypted malicious commands to be passed to the lock. These malicious commands, less …

Mar 15, 2024
CVE-2023-7007
8.2 HIGH

Sciener server does not validate connection requests from the GatewayG2, allowing an impersonation attack that provides the attacker the unlockKey field.

Mar 15, 2024
CVE-2023-6960
7.5 HIGH

TTLock App virtual keys and settings are only deleted client side, and if preserved, can access the lock after intended deletion.

Mar 15, 2024
CVE-2024-28318
7.1 HIGH

gpac 2.3-DEV-rev921-g422b78ecf-master was discovered to contain a out of boundary write vulnerability via swf_get_string at scene_manager/swf_parse.c:325

Mar 15, 2024
CVE-2024-25597
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Etoile Web Design Ultimate Reviews allows Stored XSS.This issue affects Ultimate Reviews: from …

Mar 15, 2024
CVE-2024-27196
7.1 HIGH

Cross Site Scripting (XSS) vulnerability in Joel Starnes postMash – custom post order allows Reflected XSS.This issue affects postMash – custom post order: from n/a …

Mar 15, 2024
CVE-2024-27193
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PayU India PayU India payu-india allows DOM-Based XSS.This issue affects PayU India: from …

Mar 15, 2024
CVE-2024-27192
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scott Reilly Configure SMTP allows Reflected XSS.This issue affects Configure SMTP: from n/a …

Mar 15, 2024
CVE-2024-25921
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Concerted Action Action Network allows Reflected XSS.This issue affects Action Network: from n/a …

Mar 15, 2024
CVE-2024-27987
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StellarWP GiveWP give.This issue affects GiveWP: from n/a through <= 3.3.1.

Mar 15, 2024
CVE-2024-2490
8.8 HIGH

A vulnerability classified as critical was found in Tenda AC18 15.03.05.05. Affected by this vulnerability is the function setSchedWifi of the file /goform/openSchedWifi. The manipulation …

Mar 15, 2024
CVE-2024-2450
8.8 HIGH

Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to correctly verify account ownership when switching from email …

Mar 15, 2024
CVE-2024-2489
8.8 HIGH

A vulnerability classified as critical has been found in Tenda AC18 15.03.05.05. Affected is the function formSetQosBand of the file /goform/SetNetControlList. The manipulation of the …

Mar 15, 2024
CVE-2024-2488
8.8 HIGH

A vulnerability was found in Tenda AC18 15.03.05.05. It has been rated as critical. This issue affects the function formSetPPTPServer of the file /goform/SetPptpServerCfg. The …

Mar 15, 2024
CVE-2024-2487
8.8 HIGH

A vulnerability was found in Tenda AC18 15.03.05.05. It has been declared as critical. This vulnerability affects the function formSetDeviceName of the file /goform/SetOnlineDevName. The …

Mar 15, 2024
CVE-2024-2486
8.8 HIGH

A vulnerability was found in Tenda AC18 15.03.05.05. It has been classified as critical. This affects the function formQuickIndex of the file /goform/QuickIndex. The manipulation …

Mar 15, 2024
CVE-2024-28353
8.8 HIGH

There is a command injection vulnerability in the TRENDnet TEW-827DRU router with firmware version 2.10B01. An attacker can inject commands into the post request parameters …

Mar 15, 2024
CVE-2024-2485
8.8 HIGH

A vulnerability was found in Tenda AC18 15.03.05.05 and classified as critical. Affected by this issue is the function formSetSpeedWan of the file /goform/SetSpeedWan. The …

Mar 15, 2024
CVE-2024-27756
8.8 HIGH

GLPI through 10.0.12 allows CSV injection by an attacker who is able to create an asset with a crafted title.

Mar 15, 2024
CVE-2024-1795
8.8 HIGH

The HUSKY – Products Filter for WooCommerce Professional plugin for WordPress is vulnerable to SQL Injection via the 'name' parameter in the woof shortcode in …

Mar 15, 2024
CVE-2024-26540
7.8 HIGH

A heap-based buffer overflow in Clmg before 3.3.3 can occur via a crafted file to cimg_library::CImg<unsigned char>::_load_analyze.

Mar 15, 2024
CVE-2023-50677
8.8 HIGH

An issue in NETGEAR-DGND4000 v.1.1.00.15_1.00.15 allows a remote attacker to escalate privileges via the next_file parameter to the /setup.cgi component.

Mar 14, 2024
CVE-2024-1713
7.2 HIGH

A user who can create objects in a database with plv8 3.2.1 installed is able to cause deferred triggers to execute as the Superuser during …

Mar 14, 2024
CVE-2024-0860
8.0 HIGH

The affected product is vulnerable to a cleartext transmission of sensitive information vulnerability, which may allow an attacker to capture packets to craft their own …

Mar 14, 2024
CVE-2024-28425
7.5 HIGH

greykite v1.0.0 was discovered to contain an arbitrary file upload vulnerability in the load_obj function at /templates/pickle_utils.py. This vulnerability allows attackers to execute arbitrary code …

Mar 14, 2024
CVE-2024-28424
8.8 HIGH

zenml v0.55.4 was discovered to contain an arbitrary file upload vulnerability in the load function at /materializers/cloudpickle_materializer.py. This vulnerability allows attackers to execute arbitrary code …

Mar 14, 2024
CVE-2024-27301
7.3 HIGH

Support App is an opensource application specialized in managing Apple devices. It's possible to abuse a vulnerability inside the postinstall installer script to make the …

Mar 14, 2024
CVE-2024-27266
8.2 HIGH

IBM Maximo Application Suite 7.6.1.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this …

Mar 14, 2024
CVE-2024-22346
8.4 HIGH

Db2 for IBM i 7.2, 7.3, 7.4, and 7.5 infrastructure could allow a local user to gain elevated privileges due to an unqualified library call. …

Mar 14, 2024
CVE-2023-42938
7.8 HIGH

A logic issue was addressed with improved checks. This issue is fixed in iTunes 12.13.1 for Windows. A local attacker may be able to elevate …

Mar 14, 2024
CVE-2024-28181
8.1 HIGH

turbo_boost-commands is a set of commands to help you build robust reactive applications with Rails & Hotwire. TurboBoost Commands has existing protections in place to …

Mar 14, 2024
CVE-2023-32666
7.2 HIGH

On-chip debug and test interface with improper access control in some 4th Generation Intel(R) Xeon(R) Processors when using Intel(R) SGX or Intel(R) TDX may allow …

Mar 14, 2024
CVE-2023-32282
7.2 HIGH

Race condition in BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

Mar 14, 2024
CVE-2023-50168
7.7 HIGH

Pega Platform from 6.x to 8.8.4 is affected by an XXE issue with PDF Generation.

Mar 14, 2024
CVE-2024-1623
7.7 HIGH

Insufficient session timeout vulnerability in the FAST3686 V2 Vodafone router from Sagemcom. This vulnerability could allow a local attacker to access the administration panel without …

Mar 14, 2024
CVE-2024-28746
8.1 HIGH

Apache Airflow, versions 2.8.0 through 2.8.2, has a vulnerability that allows an authenticated user with limited permissions to access resources such as variables, connections, etc …

Mar 14, 2024
CVE-2024-22397
8.3 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in the SonicOS SSLVPN portal allows a remote authenticated attacker as a firewall 'admin' user …

Mar 14, 2024
CVE-2024-1882
7.2 HIGH

This vulnerability allows an already authenticated admin user to create a malicious payload that could be leveraged for remote code execution on the server hosting …

Mar 14, 2024
CVE-2024-25652
7.6 HIGH

In Delinea PAM Secret Server 11.4, it is possible for a user assigned "Administer Reports" permission and/or with access to Report functionality via UNLIMITED ADMIN …

Mar 14, 2024
CVE-2024-1654
7.2 HIGH

This vulnerability potentially allows unauthorized write operations which may lead to remote code execution. An attacker must already have authenticated admin access and knowledge of …

Mar 14, 2024
CVE-2024-1222
8.6 HIGH

This allows attackers to use a maliciously formed API request to gain access to an API authorization level with elevated privileges. This applies to a …

Mar 14, 2024
CVE-2024-25228
8.8 HIGH

Vinchin Backup and Recovery 7.2 and Earlier is vulnerable to Authenticated Remote Code Execution (RCE) via the getVerifydiyResult function in ManoeuvreHandler.class.php.

Mar 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.