CVE Database

Comprehensive vulnerability intelligence with advanced analytics

6.5

A vulnerability was found in TP-Link VN020 F3v(T) TT_V6.2.1021. It has been rated as critical. This issue affects some unknown processing of the file /control/WANIPConnection of the component Incomplete SOAP Request Handler. The manipulation leads to denial of service. The attack can only be initiated within the local network. The…

Published: Dec 08, 2024
EPSS: 1.42%
View Details
7.5

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'visit_type[service_id]' parameter of the tax_calculated_data AJAX action in all versions up to, and including, 3.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…

Published: Dec 06, 2024
Modified: Feb 05, 2025
Product: iqonic kivicare
EPSS: 61.87%
View Details
9.9

A non-admin user account on the Zabbix frontend with the default User role, or with any other role that gives API access can exploit this vulnerability. An SQLi exists in the CUser class in the addRelatedObjects function, this function is being called from the CUser.get function which is available for…

Published: Nov 27, 2024
Modified: Oct 08, 2025
Product: zabbix zabbix
EPSS: 90.30%
View Details
8.8

Hugging Face Transformers MobileViTV2 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.…

Published: Nov 22, 2024
Modified: Feb 10, 2025
Product: huggingface transformers
EPSS: 30.77%
View Details
9.1

InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows authorized users with read access to the authorization resource of the default organization to retrieve the operator token. InfluxDB OSS 1.x, Enterprise, Cloud, Cloud Dedicated and Clustered are not affected. NOTE: The researcher states…

Published: Nov 21, 2024
Modified: Dec 19, 2025
EPSS: 21.15%
View Details
7.5

A vulnerability, which was classified as critical, has been found in TP-Link VN020 F3v(T) TT_V6.2.1021. Affected by this issue is some unknown functionality of the component DHCP DISCOVER Packet Parser. The manipulation of the argument hostname leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has…

Published: Nov 15, 2024
Modified: Nov 19, 2024
Product: tp-link vn020-f3v\(t\)_firmware
EPSS: 2.29%
View Details
9.8

The Really Simple Security (Free, Pro, and Pro Multisite) plugins for WordPress are vulnerable to authentication bypass in versions 9.0.0 to 9.1.1.1. This is due to improper user check error handling in the two-factor REST API actions with the 'check_login_and_get_user' function. This makes it possible for unauthenticated attackers to log…

Published: Nov 15, 2024
Modified: Nov 20, 2024
EPSS: 93.80%
View Details
8.8

Zohocorp ManageEngine ADManager Plus versions 7203 and prior are vulnerable to Privilege Escalation in the Modify Computers option.

Published: Nov 08, 2024
Modified: Nov 13, 2024
Product: zohocorp manageengine_admanager_plus
EPSS: 2.72%
View Details
8.1

A flaw was found in Moodle. Additional restrictions are required to avoid a remote code execution risk in calculated question types. Note: This requires the capability to add/update questions.

Published: Nov 07, 2024
Modified: May 01, 2025
Product: moodle moodle
EPSS: 89.36%
View Details
7.3

A vulnerability, which was classified as critical, was found in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. This affects an unknown part of the file /index.php. The manipulation of the argument user_name leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to…

Published: Nov 04, 2024
Modified: Nov 05, 2024
Product: code-projects content_management_system
EPSS: 0.10%
View Details
9.8

Insufficiently Protected Credentials vulnerability in LiteSpeed Technologies LiteSpeed Cache allows Authentication Bypass.This issue affects LiteSpeed Cache: from n/a before 6.5.0.1.

Published: Oct 20, 2024
Modified: Oct 23, 2024
Product: litespeedtech litespeed_cache
EPSS: 92.78%
View Details
5.3

A discrepancy in error messages for invalid login attempts in Webmin Usermin v2.100 allows attackers to enumerate valid user accounts.

Published: Oct 16, 2024
Modified: Oct 15, 2025
Product: webmin usermin
EPSS: 11.58%
View Details
4.3

An Insecure Direct Object Reference (IDOR) vulnerability in KubeSphere 4.x before 4.1.3 and 3.x through 3.4.1 and KubeSphere Enterprise 4.x before 4.1.3 and 3.x through 3.5.0 allows low-privileged authenticated attackers to access sensitive resources without proper authorization checks.

Published: Oct 14, 2024
Modified: Aug 28, 2025
EPSS: 1.08%
View Details
9.8

angular-base64-upload prior to v0.1.21 is vulnerable to unauthenticated remote code execution via demo/server.php. Exploiting this vulnerability allows an attacker to upload arbitrary content to the server, which can subsequently be accessed through demo/uploads. This leads to the execution of previously uploaded content and enables the attacker to achieve code execution…

Published: Oct 11, 2024
Modified: Oct 15, 2024
EPSS: 86.15%
View Details
6.1

A reflected cross-site scripting (XSS) vulnerability in Elaine's Realtime CRM Automation v6.18.17 allows attackers to execute arbitrary JavaScript code in the web browser of a user via injecting a crafted payload into the dialog parameter at wrapper_dialog.php.

Published: Oct 07, 2024
Modified: Nov 21, 2024
EPSS: 1.49%
View Details
8.4

Teedy 1.11 is vulnerable to Cross Site Scripting (XSS) via the management console.

Published: Oct 07, 2024
Modified: Jun 04, 2025
Product: sismics teedy
EPSS: 0.76%
View Details
6.1

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimeProvider 4100 (banner config modules) allows Cross-Site Scripting (XSS).This issue affects TimeProvider 4100: from 1.0 before 2.4.7.

Published: Oct 04, 2024
Modified: Oct 16, 2024
Product: microchip timeprovider_4100_firmware
EPSS: 0.89%
View Details
8.8

OS4ED openSIS-Classic v9.1 was discovered to contain a SQL injection vulnerability via a crafted payload.

Published: Oct 02, 2024
Modified: Jul 17, 2025
Product: os4ed opensis
EPSS: 0.14%
View Details
9.0

NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a specifically crafted container image may gain access to the host file system. This does not impact use cases where CDI is used. A successful exploit of this vulnerability may lead to…

Published: Sep 26, 2024
Modified: Oct 02, 2024
Product: nvidia nvidia_container_toolkit
EPSS: 2.92%
View Details
6.8

Sony XAV-AX5500 Insufficient Firmware Update Validation Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Sony XAV-AX5500 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of software updates. The issue results from the…

Published: Sep 23, 2024
Modified: Sep 30, 2024
Product: sony xav-ax5500_firmware
EPSS: 0.72%
View Details
9.8

evilnapsis Inventio Lite Versions v4 and before is vulnerable to SQL Injection via the "username" parameter in "/?action=processlogin."

Published: Sep 11, 2024
Modified: Sep 12, 2024
EPSS: 2.16%
View Details
7.2

An arbitrary file upload vulnerability in the component /admin/index.php of moziloCMS v3.0 allows attackers to execute arbitrary code via uploading a crafted file.

Published: Sep 10, 2024
Modified: Sep 13, 2024
Product: mozilo mozilocms
EPSS: 11.98%
View Details
7.3

actions/artifact is the GitHub ToolKit for developing GitHub Actions. Versions of `actions/artifact` on the 2.x branch before 2.1.2 are vulnerable to arbitrary file write when using `downloadArtifactInternal`, `downloadArtifactPublic`, or `streamExtractExternal` for extracting a specifically crafted artifact that contains path traversal filenames. Users are advised to upgrade to version 2.1.2 or…

Published: Sep 02, 2024
Modified: Aug 27, 2025
Product: github actions\/artifact
EPSS: 5.83%
View Details
6.1

phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\import-export\import-load-data.php.

Published: Aug 29, 2024
Modified: Apr 16, 2025
Product: phpipam phpipam
EPSS: 1.85%
View Details