CVE Database

47326+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-27292
7.5 HIGH

Docassemble is an expert system for guided interviews and document assembly. The vulnerability allows attackers to gain unauthorized access to information on the system through …

Mar 21, 2024
CVE-2024-27105
8.1 HIGH

Frappe is a full-stack web application framework. Prior to versions 14.66.3 and 15.16.0, file permission can be bypassed using certain endpoints, granting less privileged users …

Mar 21, 2024
CVE-2024-24813
7.5 HIGH

Frappe is a full-stack web application framework. Prior to versions 14.64.0 and 15.0.0, SQL injection from a particular whitelisted method can result in access to …

Mar 21, 2024
CVE-2024-24520
7.8 HIGH

An issue in Lepton CMS v.7.0.0 allows a local attacker to execute arbitrary code via the upgrade.php file in the languages place.

Mar 21, 2024
CVE-2023-49982
8.8 HIGH

Broken access control in the component /admin/management/users of School Fees Management System v1.0 allows attackers to escalate privileges and perform Administrative actions, including adding and …

Mar 21, 2024
CVE-2023-49981
7.5 HIGH

A directory listing vulnerability in School Fees Management System v1.0 allows attackers to list directories and sensitive files within the application without requiring authorization.

Mar 21, 2024
CVE-2023-49980
7.5 HIGH

A directory listing vulnerability in Best Student Result Management System v1.0 allows attackers to list directories and sensitive files within the application without requiring authorization.

Mar 21, 2024
CVE-2023-49979
7.5 HIGH

A directory listing vulnerability in Customer Support System v1 allows attackers to list directories and sensitive files within the application without requiring authorization.

Mar 21, 2024
CVE-2023-49978
8.8 HIGH

Incorrect access control in Customer Support System v1 allows non-administrator users to access administrative pages and execute actions reserved for administrators.

Mar 21, 2024
CVE-2023-35899
7.0 HIGH

IBM Cloud Pak for Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 is potentially vulnerable to CSV …

Mar 21, 2024
CVE-2024-28916
8.8 HIGH

Xbox Gaming Services Elevation of Privilege Vulnerability

Mar 21, 2024
CVE-2024-2469
8.0 HIGH

An attacker with an Administrator role in GitHub Enterprise Server could gain SSH root access via remote code execution. This vulnerability affected GitHub Enterprise Server …

Mar 20, 2024
CVE-2024-29026
8.2 HIGH

Owncast is an open source, self-hosted, decentralized, single user live video streaming and chat server. In versions 0.1.2 and prior, a lenient CORS policy allows …

Mar 20, 2024
CVE-2024-29033
7.5 HIGH

OAuthenticator provides plugins for JupyterHub to use common OAuth providers, as well as base classes for writing one's own Authenticators with any OAuth 2.0 provider. …

Mar 20, 2024
CVE-2024-23721
7.5 HIGH

A Directory Traversal issue was discovered in process_post on Draytek Vigor3910 4.3.2.5 devices. When sending a certain POST request, it calls the function and exports …

Mar 20, 2024
CVE-2024-2711
8.8 HIGH

A vulnerability was found in Tenda AC10U 15.03.06.48. It has been rated as critical. Affected by this issue is the function addWifiMacFilter of the file …

Mar 20, 2024
CVE-2024-2710
8.8 HIGH

A vulnerability was found in Tenda AC10U 15.03.06.49. It has been declared as critical. Affected by this vulnerability is the function setSchedWifi of the file …

Mar 20, 2024
CVE-2024-2709
8.8 HIGH

A vulnerability was found in Tenda AC10U 15.03.06.49. It has been classified as critical. Affected is the function fromSetRouteStatic of the file /goform/SetStaticRouteCfg. The manipulation …

Mar 20, 2024
CVE-2024-2708
8.8 HIGH

A vulnerability was found in Tenda AC10U 15.03.06.49 and classified as critical. This issue affects the function formexeCommand of the file /goform/execCommand. The manipulation of …

Mar 20, 2024
CVE-2024-2706
8.8 HIGH

A vulnerability, which was classified as critical, was found in Tenda AC10U 15.03.06.49. This affects the function formWifiWpsStart of the file /goform/WifiWpsStart. The manipulation of …

Mar 20, 2024
CVE-2024-2705
8.8 HIGH

A vulnerability, which was classified as critical, has been found in Tenda AC10U 1.0/15.03.06.49. Affected by this issue is the function formSetQosBand of the file …

Mar 20, 2024
CVE-2024-2627
8.8 HIGH

Use after free in Canvas in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Mar 20, 2024
CVE-2024-2625
8.8 HIGH

Object lifecycle issue in V8 in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. …

Mar 20, 2024
CVE-2024-2704
8.8 HIGH

A vulnerability classified as critical was found in Tenda AC10U 15.03.06.49. Affected by this vulnerability is the function formSetFirewallCfg of the file /goform/SetFirewallCfg. The manipulation …

Mar 20, 2024
CVE-2024-2703
8.8 HIGH

A vulnerability classified as critical has been found in Tenda AC10U 15.03.06.49. Affected is the function formSetDeviceName of the file /goform/SetOnlineDevName. The manipulation of the …

Mar 20, 2024
CVE-2023-50967
7.5 HIGH

latchset jose through version 11 allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.

Mar 20, 2024
CVE-2024-28735
8.1 HIGH

Unit4 Financials by Coda versions prior to 2023Q4 suffer from an incorrect access control authorization bypass vulnerability which allows an authenticated user to modify the …

Mar 20, 2024
CVE-2023-51444
7.2 HIGH

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. An arbitrary file upload vulnerability exists …

Mar 20, 2024
CVE-2023-41877
7.2 HIGH

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. A path traversal vulnerability in versions …

Mar 20, 2024
CVE-2023-41038
7.5 HIGH

Firebird is a relational database. Versions 4.0.0 through 4.0.3 and version 5.0 beta1 are vulnerable to a server crash when a user uses a specific …

Mar 20, 2024
CVE-2024-28396
7.5 HIGH

An issue in MyPrestaModules ordersexport v.6.0.2 and before allows a remote attacker to execute arbitrary code via the download.php component.

Mar 20, 2024
CVE-2024-1856
8.5 HIGH

In Progress® Telerik® Reporting versions prior to 2024 Q1 (18.0.24.130), a code execution attack is possible by a remote threat actor through an insecure deserialization …

Mar 20, 2024
CVE-2024-1801
7.7 HIGH

In Progress® Telerik® Reporting versions prior to 2024 Q1 (18.0.24.130), a code execution attack is possible by a local threat actor through an insecure deserialization …

Mar 20, 2024
CVE-2024-2721
8.2 HIGH

Deserialization of Untrusted Data vulnerability in Social Media Share Buttons By Sygnoos Social Media Share Buttons.This issue affects Social Media Share Buttons: from n/a through …

Mar 20, 2024
CVE-2024-2702
8.2 HIGH

Missing Authorization vulnerability in Olive Themes Olive One Click Demo Import allows importing settings and data, ultimately leading to XSS.This issue affects Olive One Click …

Mar 20, 2024
CVE-2024-2459
7.4 HIGH

The UX Flat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'button' shortcode in all versions up to, and including, 4.4 …

Mar 20, 2024
CVE-2024-1205
8.8 HIGH

The Management App for WooCommerce – Order notifications, Order management, Lead management, Uptime Monitoring plugin for WordPress is vulnerable to arbitrary file uploads due to …

Mar 20, 2024
CVE-2024-28583
7.8 HIGH

Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the readLine() function when reading images in …

Mar 20, 2024
CVE-2024-28582
8.4 HIGH

Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the rgbe_RGBEToFloat() function when reading images in …

Mar 20, 2024
CVE-2024-28581
8.4 HIGH

Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the _assignPixel<>() function when reading images in …

Mar 20, 2024
CVE-2024-28580
8.4 HIGH

Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the ReadData() function when reading images in …

Mar 20, 2024
CVE-2024-28578
8.4 HIGH

Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the Load() function when reading images in …

Mar 20, 2024
CVE-2024-28569
7.8 HIGH

Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the Imf_2_2::Xdr::read() function when reading images in …

Mar 20, 2024
CVE-2024-28566
8.4 HIGH

Buffer Overflow vulnerability in open source FreeImage v.3.19.0 [r1909] allows a local attacker to execute arbitrary code via the AssignPixel() function when reading images in …

Mar 20, 2024
CVE-2024-22084
7.5 HIGH

An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Cleartext passwords and hashes are exposed through log files.

Mar 20, 2024
CVE-2024-22082
7.5 HIGH

An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Unauthenticated directory listing can occur: the web interface cay be abused …

Mar 20, 2024
CVE-2024-22079
7.5 HIGH

An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Directory traversal can occur via the system logs download mechanism.

Mar 20, 2024
CVE-2024-22078
8.8 HIGH

An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Privilege escalation can occur via world writable files. The network configuration …

Mar 20, 2024
CVE-2024-1983
7.1 HIGH

The Simple Ajax Chat WordPress plugin before 20240223 does not prevent visitors from using malicious Names when using the chat, which will be reflected unsanitized …

Mar 20, 2024
CVE-2024-0856
8.8 HIGH

The Appointment Booking Calendar WordPress plugin before 1.3.83 does not have CSRF checks in some places, which could allow attackers to make logged in users …

Mar 20, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.