CVE Database

46795+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-47856
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the boa set_RadvdPrefixParam functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can …

Jul 8, 2024
CVE-2023-47677
8.8 HIGH

A cross-site request forgery (csrf) vulnerability exists in the boa CSRF protection functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted network request can …

Jul 8, 2024
CVE-2023-45742
7.2 HIGH

An integer overflow vulnerability exists in the boa updateConfigIntoFlash functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead …

Jul 8, 2024
CVE-2023-45215
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the boa setRepeaterSsid functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of network requests can …

Jul 8, 2024
CVE-2023-41251
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the boa formRoute functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can …

Jul 8, 2024
CVE-2023-34435
7.2 HIGH

A firmware update vulnerability exists in the boa formUpload functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted network packets can lead to arbitrary …

Jul 8, 2024
CVE-2024-39742
8.1 HIGH

IBM MQ Operator 3.2.2 and IBM MQ Operator 2.0.24 could allow a user to bypass authentication under certain configurations due to a partial string comparison …

Jul 8, 2024
CVE-2024-37999
7.8 HIGH

A vulnerability has been identified in Medicalis Workflow Orchestrator (All versions). The affected application executes as a trusted account with high privileges and network access. …

Jul 8, 2024
CVE-2024-27459
7.8 HIGH

The interactive service in OpenVPN 2.6.9 and earlier allows an attacker to send data causing a stack overflow which can be used to execute arbitrary …

Jul 8, 2024
CVE-2024-24974
7.5 HIGH

The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service pipe to be accessed remotely, which allows a remote attacker to interact with …

Jul 8, 2024
CVE-2024-38330
7.0 HIGH

IBM System Management for i 7.2, 7.3, and 7.4 could allow a local user to gain elevated privileges due to an unqualified library program call. …

Jul 8, 2024
CVE-2024-3651
7.5 HIGH

A vulnerability was identified in the kjd/idna library, specifically within the `idna.encode()` function, affecting version 3.6. The issue arises from the function's handling of crafted …

Jul 7, 2024
CVE-2024-40597
7.5 HIGH

An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. It can expose suppressed information for log events. (The log_deleted attribute is not …

Jul 7, 2024
CVE-2024-39486
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/drm_file: Fix pid refcounting race <[email protected]>, Maxime Ripard <[email protected]>, Thomas Zimmermann <[email protected]> filp->pid is supposed …

Jul 6, 2024
CVE-2024-37260
7.2 HIGH

Server-Side Request Forgery (SSRF) vulnerability in Theme-Ruby Foxiz.This issue affects Foxiz: from n/a through 2.3.5.

Jul 6, 2024
CVE-2024-39182
7.5 HIGH

An information disclosure vulnerability in ISPmanager v6.98.0 allows attackers to access sensitive details of the root user's session via an arbitrary command (ISP6-1779).

Jul 5, 2024
CVE-2024-33862
7.5 HIGH

A buffer-management vulnerability in OPC Foundation OPCFoundation.NetStandard.Opc.Ua.Core before 1.05.374.54 could allow remote attackers to exhaust memory resources. It is triggered when the system receives an …

Jul 5, 2024
CVE-2024-5753
7.5 HIGH

vanna-ai/vanna version v0.3.4 is vulnerable to SQL injection in some file-critical functions such as `pg_read_file()`. This vulnerability allows unauthenticated remote users to read arbitrary local …

Jul 5, 2024
CVE-2024-39696
8.8 HIGH

Evmos is a decentralized Ethereum Virtual Machine chain on the Cosmos Network. Prior to version 19.0.0, a user can create a vesting account with a …

Jul 5, 2024
CVE-2024-39689
7.5 HIGH

Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi starting in …

Jul 5, 2024
CVE-2024-39023
8.8 HIGH

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via admin/info_deal.php?mudi=add&nohrefStr=close

Jul 5, 2024
CVE-2024-39022
8.8 HIGH

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/infoSys_deal.php?mudi=deal

Jul 5, 2024
CVE-2024-34361
8.5 HIGH

Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. A vulnerability in versions prior to 5.18.3 allows an …

Jul 5, 2024
CVE-2024-39687
7.2 HIGH

Fedify is a TypeScript library for building federated server apps powered by ActivityPub and other standards. At present, when Fedify needs to retrieve an object …

Jul 5, 2024
CVE-2024-39321
7.5 HIGH

Traefik is an HTTP reverse proxy and load balancer. Versions prior to 2.11.6, 3.0.4, and 3.1.0-rc3 have a vulnerability that allows bypassing IP allow-lists via …

Jul 5, 2024
CVE-2024-37903
8.2 HIGH

Mastodon is a self-hosted, federated microblogging platform. Starting in version 2.6.0 and prior to versions 4.1.18 and 4.2.10, by crafting specific activities, an attacker can …

Jul 5, 2024
CVE-2024-37767
7.5 HIGH

Insecure permissions in the component /api/admin/user of 14Finger v1.1 allows attackers to access all user information via a crafted GET request.

Jul 5, 2024
CVE-2024-27715
8.2 HIGH

An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via a crafted request to the …

Jul 5, 2024
CVE-2024-27713
8.8 HIGH

An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via the HTTP Response Header Settings …

Jul 5, 2024
CVE-2024-27711
8.8 HIGH

An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via the Sin-up process function in …

Jul 5, 2024
CVE-2024-39210
7.5 HIGH

Best House Rental Management System v1.0 was discovered to contain an arbitrary file read vulnerability via the Page parameter at index.php. This vulnerability allows attackers …

Jul 5, 2024
CVE-2024-37769
8.8 HIGH

Insecure permissions in 14Finger v1.1 allow attackers to escalate privileges from normal user to Administrator via a crafted POST request.

Jul 5, 2024
CVE-2024-39027
7.5 HIGH

SeaCMS v12.9 has an unauthorized SQL injection vulnerability. The vulnerability is caused by the SQL injection through the cid parameter at /js/player/dmplayer/dmku/index.php?ac=edit, which can cause …

Jul 5, 2024
CVE-2024-39480
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: kdb: Fix buffer overflow during tab-complete Currently, when the user attempts symbol completion with the …

Jul 5, 2024
CVE-2024-39479
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/i915/hwmon: Get rid of devm When both hwmon and hwmon drvdata (on which hwmon depends) …

Jul 5, 2024
CVE-2024-36041
7.8 HIGH

KSmserver in KDE Plasma Workspace (aka plasma-workspace) before 5.27.11.1 and 6.x before 6.0.5.1 allows connections via ICE based purely on the host, i.e., all local …

Jul 5, 2024
CVE-2023-52340
7.5 HIGH

The IPv6 implementation in the Linux kernel before 6.3 has a net/ipv6/route.c max_size threshold that can be consumed easily, e.g., leading to a denial of …

Jul 5, 2024
CVE-2024-39937
8.6 HIGH

supOS 5.0 allows api/image/download?fileName=../ directory traversal for reading files.

Jul 4, 2024
CVE-2024-39936
8.6 HIGH

An issue was discovered in HTTP2 in Qt before 5.15.18, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.7, and 6.6.x through 6.7.x before 6.7.3. Code …

Jul 4, 2024
CVE-2024-39935
8.8 HIGH

jc21 NGINX Proxy Manager before 2.11.3 allows backend/internal/certificate.js OS command injection by an authenticated user (with certificate management privileges) via untrusted input to the DNS …

Jul 4, 2024
CVE-2024-39934
7.8 HIGH

Robotmk before 2.0.1 allows a local user to escalate privileges (e.g., to SYSTEM) if automated Python environment setup is enabled, because the "shared holotree usage" …

Jul 4, 2024
CVE-2024-37472
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WofficeIO Woffice woffice.This issue affects Woffice: from n/a through <= 5.4.8.

Jul 4, 2024
CVE-2024-37471
7.1 HIGH

Cross Site Scripting (XSS) vulnerability in WofficeIO Woffice Core allows Reflected XSS.This issue affects Woffice Core: from n/a through 5.4.8.

Jul 4, 2024
CVE-2024-39933
7.7 HIGH

Gogs through 0.13.0 allows argument injection during the tagging of a new release.

Jul 4, 2024
CVE-2024-6506
8.2 HIGH

Information exposure vulnerability in the MRW plugin, in its 5.4.3 version, affecting the "mrw_log" functionality. This vulnerability could allow a remote attacker to obtain other …

Jul 4, 2024
CVE-2024-6507
8.1 HIGH

Command injection when ingesting a remote Kaggle dataset due to a lack of input sanitization in the ingest_kaggle() API

Jul 4, 2024
CVE-2024-5943
8.8 HIGH

The Nested Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.7. This is due to missing …

Jul 4, 2024
CVE-2024-6319
8.8 HIGH

The IMGspider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload' function in all versions up …

Jul 4, 2024
CVE-2024-6318
8.8 HIGH

The IMGspider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload_img_file' function in all versions up …

Jul 4, 2024
CVE-2024-3904
8.8 HIGH

Incorrect Default Permissions vulnerability in Smart Device Communication Gateway preinstalled on MELIPC Series MI5122-VW firmware versions "05" to "07" allows a local attacker to execute …

Jul 4, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.