CVE Database

46795+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-8194
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 128.0.6613.113 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Aug 28, 2024
CVE-2024-8193
8.8 HIGH

Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.113 allowed a remote attacker who had compromised the renderer process to potentially exploit heap …

Aug 28, 2024
CVE-2024-45059
8.8 HIGH

i-Educar is free, fully online school management software that can be used by school secretaries, teachers, coordinators, and area managers. A SQL Injection vulnerability was …

Aug 28, 2024
CVE-2024-45058
8.1 HIGH

i-Educar is free, fully online school management software that can be used by school secretaries, teachers, coordinators, and area managers. Prior to the 2.9 branch, …

Aug 28, 2024
CVE-2024-45048
8.8 HIGH

PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Affected versions are subject to a bypassing of a filter which allows for …

Aug 28, 2024
CVE-2024-44760
7.5 HIGH

Incorrect access control in the component /servlet/SnoopServlet of Shenzhou News Union Enterprise Management System v5.0 through v18.8 allows attackers to access sensitive information regarding the …

Aug 28, 2024
CVE-2024-43805
7.6 HIGH

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. This vulnerability depends on user interaction by opening a …

Aug 28, 2024
CVE-2024-42793
8.0 HIGH

A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via a crafted request to the /music/ajax.php?action=save_user page.

Aug 28, 2024
CVE-2024-41236
7.2 HIGH

A SQL injection vulnerability in /smsa/admin_login.php in Kashipara Responsive School Management System v3.2.0 allows an attacker to execute arbitrary SQL commands via the "username" parameter …

Aug 28, 2024
CVE-2024-20446
8.6 HIGH

A vulnerability in the DHCPv6 relay agent of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition …

Aug 28, 2024
CVE-2024-5546
8.3 HIGH

Zohocorp ManageEngine Password Manager Pro versions before 12431 and ManageEngine PAM360 versions before 7001 are affected by authenticated SQL Injection vulnerability via a global search …

Aug 28, 2024
CVE-2023-26324
8.8 HIGH

A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit …

Aug 28, 2024
CVE-2023-26323
7.6 HIGH

A code execution vulnerability exists in the Xiaomi App market product. The vulnerability is caused by unsafe configuration and can be exploited by attackers to …

Aug 28, 2024
CVE-2023-26322
8.8 HIGH

A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit …

Aug 28, 2024
CVE-2024-6311
7.2 HIGH

The Funnelforms Free plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'af2_add_font' function in all versions …

Aug 28, 2024
CVE-2024-4555
7.7 HIGH

Improper Privilege Management vulnerability in OpenText NetIQ Access Manager allows user account impersonation in specific scenario. This issue affects NetIQ Access Manager before 5.0.4.1 and …

Aug 28, 2024
CVE-2024-4554
7.3 HIGH

Improper Input Validation vulnerability in OpenText NetIQ Access Manager leads to Cross-Site Scripting (XSS) attack. This issue affects Access Manager before 5.0.4.1 and 5.1.

Aug 28, 2024
CVE-2024-45346
8.8 HIGH

The Xiaomi Security Center expresses heartfelt thanks to Ken Gannon and Ilyes Beghdadi of NCC Group working with Trend Micro Zero Day Initiative! At the …

Aug 28, 2024
CVE-2021-38121
8.3 HIGH

Insufficient or weak TLS protocol version identified in Advance authentication client server communication when specific service is accessed between devices. This issue affects NetIQ Advance …

Aug 28, 2024
CVE-2021-22530
8.2 HIGH

A vulnerability identified in NetIQ Advance Authentication that doesn't enforce account lockout when brute force attack is performed on API based login. This issue may …

Aug 28, 2024
CVE-2021-22509
8.1 HIGH

A vulnerability identified in storing and reusing information in Advance Authentication. This issue can lead to leakage of sensitive data to unauthorized user. The issue …

Aug 28, 2024
CVE-2024-39584
8.2 HIGH

Dell Client Platform BIOS contains a Use of Default Cryptographic Key Vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading …

Aug 28, 2024
CVE-2023-45896
7.1 HIGH

ntfs3 in the Linux kernel through 6.8.0 allows a physically proximate attacker to read kernel memory by mounting a filesystem (e.g., if a Linux distribution …

Aug 28, 2024
CVE-2024-8231
8.8 HIGH

A vulnerability classified as critical has been found in Tenda O6 1.0.0.7(2054). Affected is the function fromVirtualSet of the file /goform/setPortForward. The manipulation of the …

Aug 28, 2024
CVE-2024-8230
8.8 HIGH

A vulnerability was found in Tenda O6 1.0.0.7(2054). It has been rated as critical. This issue affects the function fromSafeSetMacFilter of the file /goform/setMacFilterList. The …

Aug 28, 2024
CVE-2024-8229
8.8 HIGH

A vulnerability was found in Tenda O6 1.0.0.7(2054). It has been declared as critical. This vulnerability affects the function frommacFilterModify of the file /goform/operateMacFilter. The …

Aug 28, 2024
CVE-2024-8228
8.8 HIGH

A vulnerability was found in Tenda O5 1.0.0.8(5017). It has been classified as critical. This affects the function fromSafeSetMacFilter of the file /goform/setMacFilterList. The manipulation …

Aug 28, 2024
CVE-2024-8227
8.8 HIGH

A vulnerability was found in Tenda O1 1.0.0.7(10648) and classified as critical. Affected by this issue is the function fromDhcpSetSer of the file /goform/DhcpSetSer. The …

Aug 28, 2024
CVE-2024-8226
8.8 HIGH

A vulnerability has been found in Tenda O1 1.0.0.7(10648) and classified as critical. Affected by this vulnerability is the function formSetCfm of the file /goform/setcfm. …

Aug 28, 2024
CVE-2024-8225
8.8 HIGH

A vulnerability, which was classified as critical, was found in Tenda G3 15.11.0.20. Affected is the function formSetSysTime of the file /goform/SetSysTimeCfg. The manipulation of …

Aug 27, 2024
CVE-2024-8224
8.8 HIGH

A vulnerability, which was classified as critical, has been found in Tenda G3 15.11.0.20. This issue affects the function formSetDebugCfg of the file /goform/setDebugCfg. The …

Aug 27, 2024
CVE-2024-8219
7.3 HIGH

A vulnerability was found in code-projects Responsive Hotel Site 1.0. It has been classified as critical. Affected is an unknown function of the file index.php. …

Aug 27, 2024
CVE-2024-8218
7.3 HIGH

A vulnerability was found in code-projects Online Quiz Site 1.0 and classified as critical. This issue affects some unknown processing of the file index.php. The …

Aug 27, 2024
CVE-2024-8217
7.3 HIGH

A vulnerability has been found in SourceCodester E-Commerce Website 1.0 and classified as critical. This vulnerability affects unknown code of the file /Admin/registration.php. The manipulation …

Aug 27, 2024
CVE-2024-45049
7.5 HIGH

Hydra is a Continuous Integration service for Nix based projects. It is possible to trigger evaluations in Hydra without any authentication. Depending on the size …

Aug 27, 2024
CVE-2024-45038
7.5 HIGH

Meshtastic device firmware is a firmware for meshtastic devices to run an open source, off-grid, decentralized, mesh network built to run on affordable, low-power devices. …

Aug 27, 2024
CVE-2024-5991
7.5 HIGH

In function MatchDomainName(), input param str is treated as a NULL terminated string despite being user provided and unchecked. Specifically, the function X509_check_host() takes in …

Aug 27, 2024
CVE-2022-39997
8.0 HIGH

A weak password requirement issue was discovered in Teldats Router RS123, RS123w allows a remote attacker to escalate privileges

Aug 27, 2024
CVE-2024-43783
7.5 HIGH

The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. Instances of …

Aug 27, 2024
CVE-2024-43414
7.5 HIGH

Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Each team can own their slice of the graph independently, empowering them …

Aug 27, 2024
CVE-2024-42851
7.8 HIGH

Buffer Overflow vulnerability in open source exiftags v.1.01 allows a local attacker to execute arbitrary code via the paresetag function.

Aug 27, 2024
CVE-2024-45264
8.8 HIGH

A cross-site request forgery (CSRF) vulnerability in the admin panel in SkySystem Arfa-CMS before 5.1.3124 allows remote attackers to add a new administrator, leading to …

Aug 27, 2024
CVE-2024-44340
8.8 HIGH

D-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via keys smartqos_express_devices and smartqos_normal_devices in SetSmartQoSSettings.

Aug 27, 2024
CVE-2024-6632
7.2 HIGH

A vulnerability exists in FileCatalyst Workflow whereby a field accessible to the super admin can be used to perform an SQL injection attack which can …

Aug 27, 2024
CVE-2024-8182
7.5 HIGH

An Unauthenticated Denial of Service (DoS) vulnerability exists in Flowise version 1.8.2 leading to a complete crash of the instance running a vulnerable version due …

Aug 27, 2024
CVE-2024-7940
8.3 HIGH

The product exposes a service that is intended for local only to all network interfaces without any authentication.

Aug 27, 2024
CVE-2024-3982
8.2 HIGH

An attacker with local access to machine where MicroSCADA X SYS600 is installed, could enable the session logging supporting the product and try to exploit …

Aug 27, 2024
CVE-2024-41176
7.3 HIGH

The MPD package included in TwinCAT/BSD allows an authenticated, low-privileged local attacker to induce a Denial-of-Service (DoS) condition on the daemon and execute code in …

Aug 27, 2024
CVE-2024-41174
7.3 HIGH

The IPC-Diagnostics package in TwinCAT/BSD is susceptible to improper input neutralization by a low-privileged local attacker.

Aug 27, 2024
CVE-2024-41173
7.8 HIGH

The IPC-Diagnostics package included in TwinCAT/BSD is vulnerable to a local authentication bypass by a low privileged attacker.

Aug 27, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.