CVE Database

47326+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-2915
8.8 HIGH

Improper access control in PAM JIT elevation in Devolutions Server 2024.1.6 and earlier allows an attacker with access to the PAM JIT elevation feature to …

Mar 26, 2024
CVE-2024-2892
8.8 HIGH

A vulnerability has been found in Tenda AC7 15.03.06.44 and classified as critical. Affected by this vulnerability is the function formSetCfm of the file /goform/setcfm. …

Mar 26, 2024
CVE-2024-2452
7.0 HIGH

In Eclipse ThreadX NetX Duo before 6.4.0, if an attacker can control parameters of __portable_aligned_alloc() could cause an integer wrap-around and an allocation smaller than …

Mar 26, 2024
CVE-2024-2214
7.0 HIGH

In Eclipse ThreadX before version 6.4.0, the _Mtxinit() function in the Xtensa port was missing an array size check causing a memory overwrite. The affected …

Mar 26, 2024
CVE-2024-2212
7.3 HIGH

In Eclipse ThreadX before 6.4.0, xQueueCreate() and xQueueCreateSet() functions from the FreeRTOS compatibility API (utility/rtos_compatibility_layers/FreeRTOS/tx_freertos.c) were missing parameter checks. This could lead to integer wraparound, …

Mar 26, 2024
CVE-2024-21919
7.8 HIGH

An uninitialized pointer in Rockwell Automation Arena Simulation software could potentially allow a malicious user to insert unauthorized code to the software by leveraging the …

Mar 26, 2024
CVE-2024-21918
7.8 HIGH

A memory buffer vulnerability in Rockwell Automation Arena Simulation software could potentially allow a malicious user to insert unauthorized code to the software by corrupting …

Mar 26, 2024
CVE-2024-21913
7.8 HIGH

A heap-based memory buffer overflow vulnerability in Rockwell Automation Arena Simulation software could potentially allow a malicious user to insert unauthorized code into the software …

Mar 26, 2024
CVE-2024-21912
7.8 HIGH

An arbitrary code execution vulnerability in Rockwell Automation Arena Simulation could let a malicious user insert unauthorized code into the software. This is done by …

Mar 26, 2024
CVE-2024-23722
7.5 HIGH

In Fluent Bit 2.1.8 through 2.2.1, a NULL pointer dereference can be caused via an invalid HTTP payload with the content type of x-www-form-urlencoded. It …

Mar 26, 2024
CVE-2024-23482
7.0 HIGH

The ZScaler service is susceptible to a local privilege escalation vulnerability found in the ZScalerService process. Fixed Version: Mac ZApp 4.2.0.241 and later.

Mar 26, 2024
CVE-2023-50895
7.2 HIGH

In Janitza GridVis through 9.0.66, exposed dangerous methods in the de.janitza.pasw.project.server.ServerDatabaseProject project load functionality allow remote authenticated administrative users to execute arbitrary Groovy code.

Mar 26, 2024
CVE-2023-50894
8.8 HIGH

In Janitza GridVis through 9.0.66, use of hard-coded credentials in the de.janitza.pasw.feature.impl.activators.PasswordEncryption password encryption function allows remote authenticated administrative users to discover cleartext database credentials …

Mar 26, 2024
CVE-2023-41973
7.3 HIGH

ZSATray passes the previousInstallerName as a config parameter to TrayManager, and TrayManager constructs the path and appends previousInstallerName to get the full path of the …

Mar 26, 2024
CVE-2023-41972
7.3 HIGH

In some rare cases, there is a password type validation missing in Revert Password check and for some features it could be disabled. Fixed Version: …

Mar 26, 2024
CVE-2023-41969
7.3 HIGH

An arbitrary file deletion in ZSATrayManager where it protects the temporary encrypted ZApp issue reporting file from the unprivileged end user access and modification. Fixed …

Mar 26, 2024
CVE-2024-2891
8.8 HIGH

A vulnerability, which was classified as critical, was found in Tenda AC7 15.03.06.44. Affected is the function formQuickIndex of the file /goform/QuickIndex. The manipulation of …

Mar 26, 2024
CVE-2023-47150
7.5 HIGH

IBM Common Cryptographic Architecture (CCA) 7.0.0 through 7.5.36 could allow a remote user to cause a denial of service due to incorrect data handling for …

Mar 26, 2024
CVE-2024-1933
7.1 HIGH

Insecure UNIX Symbolic Link (Symlink) Following in TeamViewer Remote Client prior Version 15.52 for macOS allows an attacker with unprivileged access, to potentially elevate privileges …

Mar 26, 2024
CVE-2024-28093
8.8 HIGH

The TELNET service of AdTran NetVanta 3120 18.01.01.00.E devices is enabled by default, and has default credentials for a root-level account.

Mar 26, 2024
CVE-2024-28131
7.8 HIGH

EasyRange Ver 1.41 contains an issue with the executable file search path when displaying an extracted file on Explorer, which may lead to loading an …

Mar 26, 2024
CVE-2024-28033
7.3 HIGH

OS command injection vulnerability exists in WebProxy 1.7.8 and 1.7.9, which may allow a remote unauthenticated attacker to execute an arbitrary OS command with the …

Mar 26, 2024
CVE-2023-45771
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Contact Form With Captcha allows Reflected XSS.This issue affects Contact Form With Captcha: …

Mar 26, 2024
CVE-2023-33322
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Etoile Web Design Front End Users allows Reflected XSS.This issue affects Front End …

Mar 26, 2024
CVE-2023-23991
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPdevelop / Oplugins Booking Calendar allows SQL Injection.This issue affects Booking …

Mar 26, 2024
CVE-2023-6175
7.8 HIGH

NetScreen file parser crash in Wireshark 4.0.0 to 4.0.10 and 3.6.0 to 3.6.18 allows denial of service via crafted capture file

Mar 26, 2024
CVE-2023-49839
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KlbTheme Cosmetsy theme (core plugin), KlbTheme Partdo theme (core plugin), KlbTheme Bacola theme …

Mar 26, 2024
CVE-2024-29189
7.4 HIGH

PyAnsys Geometry is a Python client library for the Ansys Geometry service and other CAD Ansys products. On file src/ansys/geometry/core/connection/product_instance.py, upon calling this method _start_program …

Mar 26, 2024
CVE-2024-0866
8.1 HIGH

The Check & Log Email plugin for WordPress is vulnerable to Unauthenticated Hook Injection in all versions up to, and including, 1.0.9 via the check_nonce …

Mar 26, 2024
CVE-2024-29302
7.5 HIGH

SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection via update-employee.php.

Mar 26, 2024
CVE-2024-29301
7.5 HIGH

SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection via update-admin.php?admin_id=

Mar 26, 2024
CVE-2024-0901
7.5 HIGH

Remotely executed SEGV and out of bounds read allows malicious packet sender to crash or cause an out of bounds read via sending a malformed …

Mar 25, 2024
CVE-2024-1973
8.5 HIGH

By leveraging the vulnerability, lower-privileged users of Content Manager can manipulate Content Manager clients to elevate privileges and perform unauthorized operations.

Mar 25, 2024
CVE-2023-47430
7.5 HIGH

Stack-buffer-overflow vulnerability in ReadyMedia (MiniDLNA) v1.3.3 allows attackers to cause a denial of service via via the SendContainer() function at tivo_commands.c.

Mar 25, 2024
CVE-2024-2427
7.5 HIGH

A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper traffic throttling in the device. If multiple data packets are sent to …

Mar 25, 2024
CVE-2024-2426
7.5 HIGH

A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper input validation in the device. If exploited, a disruption in the CIP …

Mar 25, 2024
CVE-2024-2425
7.5 HIGH

A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper input validation in the device. If exploited, the web server will crash …

Mar 25, 2024
CVE-2024-29515
8.8 HIGH

File Upload vulnerability in lepton v.7.1.0 allows a remote authenticated attackers to execute arbitrary code via uploading a crafted PHP file to the save.php and …

Mar 25, 2024
CVE-2024-28850
8.1 HIGH

WP Crontrol controls the cron events on WordPress websites. WP Crontrol includes a feature that allows administrative users to create events in the WP-Cron system …

Mar 25, 2024
CVE-2024-28107
8.8 HIGH

phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. A SQL injection vulnerability has been discovered in …

Mar 25, 2024
CVE-2024-28105
7.2 HIGH

phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. The category image upload function in phpmyfaq is …

Mar 25, 2024
CVE-2024-27299
8.8 HIGH

phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. A SQL injection vulnerability has been discovered in …

Mar 25, 2024
CVE-2024-30205
7.1 HIGH

In Emacs before 29.3, Org mode considers contents of remote files to be trusted. This affects Org Mode before 9.6.23.

Mar 25, 2024
CVE-2024-30202
7.8 HIGH

In Emacs before 29.3, arbitrary Lisp code is evaluated as part of turning on Org mode. This affects Org Mode before 9.6.23.

Mar 25, 2024
CVE-2024-28434
7.6 HIGH

The CRM platform Twenty is vulnerable to stored cross site scripting via file upload in version 0.3.0. A crafted svg file can trigger the execution …

Mar 25, 2024
CVE-2024-28387
7.5 HIGH

An issue in axonaut v.3.1.23 and before allows a remote attacker to obtain sensitive information via the log.txt component.

Mar 25, 2024
CVE-2024-25002
8.8 HIGH

Command Injection in the diagnostics interface of the Bosch Network Synchronizer allows unauthorized users full access to the device.

Mar 25, 2024
CVE-2024-2864
7.3 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KaineLabs Youzify - Buddypress Moderation.This issue affects Youzify - Buddypress Moderation: from n/a …

Mar 25, 2024
CVE-2021-47175
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: net/sched: fq_pie: fix OOB access in the traffic path the following script: # tc qdisc …

Mar 25, 2024
CVE-2021-47160
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: dsa: mt7530: fix VLAN traffic leaks PCR_MATRIX field was set to all 1's when …

Mar 25, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.