CVE Database
Synced from NVD, cross-referenced against CISA KEV and EPSS · ordered by last update
| CVE ID | Score | Description |
|---|---|---|
| Exploit 1mo ago | 9.1 | eLabFTW is an electronic lab notebook manager for research teams. In versions prior to 4.2.0 there is a vulnerability which allows an attacker to authenticate as an existing user, if that user was created using a single sign-on authentication option such as LDAP or SAML. It impacts instances where LDAP or SAML is used for authentication instead of the (default) local password mechanism. Users should upgrade to at least version 4.2.0. |
| Exploit 1mo ago | 9.8 | SQL Injection vulnerability exists in ThinkPHP5 5.0.x <=5.1.22 via the parseOrder function in Builder.php. |
| Exploit 1mo ago | 9.8 | bookstack is vulnerable to Improper Access Control |
| 1mo ago | 9.8 | FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 includes an account named "cmuser" that has administrative privileges and no password. Older versions of FatPipe software may also be vulnerable. The FatPipe advisory identifier for this vulnerability is FPSA002. |
| 1mo ago | 9.8 | Product: AndroidVersions: Android kernelAndroid ID: A-192641593References: N/A |
| 1mo ago | 9.8 | Product: AndroidVersions: Android kernelAndroid ID: A-199805112References: N/A |
| 1mo ago | 9.8 | Product: AndroidVersions: Android kernelAndroid ID: A-199809304References: N/A |
| 1mo ago | 9.8 | Product: AndroidVersions: Android kernelAndroid ID: A-126949257References: N/A |
| 1mo ago | 9.8 | Unauthenticated Arbitrary Options Update vulnerability leading to full website compromise discovered in Image Hover Effects Ultimate (versions <= 9.6.1) WordPress plugin. |
| Exploit 1mo ago | 9.8 | In NfcTag::discoverTechnologies (activation) of NfcTag.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additionalSystem execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12Android ID: A-189942532 |
| Exploit 1mo ago | 9.8 | In Android TV , there is a possible silent pairing due to lack of rate limiting in the pairing flow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-8.1 Android-9Android ID: A-180745296 |
| Exploit 1mo ago | 9.8 | A Broken or Risky Cryptographic Algorithm exists in AnonAddy 0.8.5 via VerificationController.php. |
| Exploit 1mo ago | 9.8 | Online Pre-owned/Used Car Showroom Management System 1.0 contains a SQL injection authentication bypass vulnerability. Admin panel authentication can be bypassed due to SQL injection vulnerability in the login form allowing attacker to get admin access on the application. |
| Exploit 1mo ago | 9.8 | Online Magazine Management System 1.0 contains a SQL injection authentication bypass vulnerability. The Admin panel authentication can be bypassed due to SQL injection vulnerability in the login form allowing attacker to gain access as admin to the application. |
| Exploit 1mo ago | 9.8 | Visual Studio Code WSL Extension Remote Code Execution Vulnerability |
| Exploit 1mo ago | 9.6 | Microsoft Office app Remote Code Execution Vulnerability |
| Exploit 1mo ago | 9.8 | Microsoft 4K Wireless Display Adapter Remote Code Execution Vulnerability |
| Exploit 1mo ago | 9 | Microsoft Defender for IoT Remote Code Execution Vulnerability |
| Exploit 1mo ago | 9.8 | iSNS Server Memory Corruption Vulnerability Can Lead to Remote Code Execution |
| Exploit 1mo ago | 10 | Microsoft Defender for IoT Remote Code Execution Vulnerability |
| Exploit 1mo ago | 10 | Microsoft Defender for IoT Remote Code Execution Vulnerability |
| Exploit 1mo ago | 9.8 | iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (aka Ghostscript) command line in GhostscriptHelper.java. |
| Exploit 1mo ago | 9.8 | A SQL Injection vulnerability exists in ZZCMS 2021 via the askbigclassid parameter in /admin/ask.php. |
| Exploit 1mo ago | 9.8 | OpenCATS through 0.9.6 allows remote attackers to execute arbitrary code by uploading an executable file via lib/FileUtility.php. |
| 1mo ago | 9.8 | Crocoblock JetEngine before 2.9.1 does not properly validate and sanitize form data. |
| Exploit 1mo ago | 9.9 | Opencast is an Open Source Lecture Capture & Video Management for Education. Opencast before version 9.10 or 10.6 allows references to local file URLs in ingested media packages, allowing attackers to include local files from Opencast's host machines and making them available via the web interface. Before Opencast 9.10 and 10.6, Opencast would open and include local files during ingests. Attackers could exploit this to include most local files the process has read access to, extracting secrets from the host machine. An attacker would need to have the privileges required to add new media to exploit this. But these are often widely given. The issue has been fixed in Opencast 10.6 and 11.0. You can mitigate this issue by narrowing down the read access Opencast has to files on the file system using UNIX permissions or mandatory access control systems like SELinux. This cannot prevent access to files Opencast needs to read though and we highly recommend updating. |
| KEV Exploit 1mo ago | 9 | It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in an information leak and remote code execution in some environments and local code execution in all environments. Log4j 2.16.0 (Java 8) and 2.12.2 (Java 7) fix this issue by removing support for message lookup patterns and disabling JNDI functionality by default. |
| Exploit 1mo ago | 9.8 | A Remote Code Execution (RCE) vulnerability exists in emlog 5.3.1 via content/plugins. |
| 1mo ago | 9.8 | An issue was discovered in UiPath Assistant 21.4.4. User-controlled data supplied to the --process-start argument of the URI handler for uipath-assistant:// is not correctly encoded, resulting in attacker-controlled content being injected into the error message displayed (when the injected content does not match an existing process). A determined attacker could leverage this to execute JavaScript in the context of the Electron application. |
| 1mo ago | 9.8 | UiPath Assistant 21.4.4 will load and execute attacker controlled data from the file path supplied to the --dev-widget argument of the URI handler for uipath-assistant://. This allows an attacker to execute code on a victim's machine or capture NTLM credentials by supplying a networked or WebDAV file path. |