NVD Vulnerability Information Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
In descending order of publication date
In descending order of update date
Number of items displayed

You can search the list of vulnerabilities managed by the NVD (National Vulnerability Database).
Since vulnerability information is often updated before JVN (Japan Vulnerability Note), vulnerabilities that are not listed in JVN may be updated.

If there is a vulnerability related to JVN (Japan Vulnerability Note), the information will be displayed on the detail page.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW

Update Date:May 11, 2026, 4:09 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
313001 6.1 MEDIUM
Network
rems qr_code_attendance_system A vulnerability, which was classified as problematic, has been found in SourceCodester QR Code Attendance System 1.0. This issue affects some unknown processing of the file /endpoint/delete-student.p… CWE-79
Cross-site Scripting
CVE-2024-8172 2024-08-28 01:01 2024-08-27 Show GitHub Exploit DB Packet Storm
313002 4.3 MEDIUM
Network
getbrave brave Cross-Site Request Forgery (CSRF) vulnerability in Brave Brave Popup Builder.This issue affects Brave Popup Builder: from n/a through 0.7.0. CWE-352
 Origin Validation Error
CVE-2024-43337 2024-08-28 00:59 2024-08-27 Show GitHub Exploit DB Packet Storm
313003 6.1 MEDIUM
Network
webinarpress webinarpress Cross-Site Request Forgery (CSRF) vulnerability in WebinarPress allows Cross-Site Scripting (XSS).This issue affects WebinarPress: from n/a through 1.33.20. CWE-352
 Origin Validation Error
CVE-2024-43339 2024-08-28 00:58 2024-08-27 Show GitHub Exploit DB Packet Storm
313004 4.3 MEDIUM
Network
advancedformintegration advanced_form_integration Cross-Site Request Forgery (CSRF) vulnerability in Nasirahmed Advanced Form Integration.This issue affects Advanced Form Integration: from n/a through 1.89.4. CWE-352
 Origin Validation Error
CVE-2024-43340 2024-08-28 00:56 2024-08-27 Show GitHub Exploit DB Packet Storm
313005 4.3 MEDIUM
Network
bobbingwide oik Cross-Site Request Forgery (CSRF) vulnerability in bobbingwide.This issue affects oik: from n/a through 4.12.0. CWE-352
 Origin Validation Error
CVE-2024-43356 2024-08-28 00:54 2024-08-27 Show GitHub Exploit DB Packet Storm
313006 9.8 CRITICAL
Network
pharmacy_management_system_project pharmacy_management_system A vulnerability, which was classified as critical, was found in code-projects Pharmacy Management System 1.0. Affected is the function editManager of the file /index.php?action=editManager of the com… CWE-89
SQL Injection
CVE-2024-8138 2024-08-28 00:51 2024-08-25 Show GitHub Exploit DB Packet Storm
313007 6.1 MEDIUM
Network
jkev record_management_system A vulnerability has been found in SourceCodester Record Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file search_user.php. The manipulation of t… CWE-79
Cross-site Scripting
CVE-2024-8137 2024-08-28 00:50 2024-08-25 Show GitHub Exploit DB Packet Storm
313008 7.5 HIGH
Network
nicmx fort-validator An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) an ROA or a Manifest containing a null eContent fie… CWE-476
 NULL Pointer Dereference
CVE-2024-45239 2024-08-28 00:49 2024-08-25 Show GitHub Exploit DB Packet Storm
313009 9.8 CRITICAL
Network
nicmx fort-validator An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a resource certificate containing a Key Usage exten… CWE-120
Classic Buffer Overflow
CVE-2024-45237 2024-08-28 00:48 2024-08-25 Show GitHub Exploit DB Packet Storm
313010 7.5 HIGH
Network
nicmx fort-validator An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a signed object containing an empty signedAttribute… NVD-CWE-noinfo
CVE-2024-45236 2024-08-28 00:48 2024-08-25 Show GitHub Exploit DB Packet Storm
313011 7.5 HIGH
Network
nicmx fort-validator An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) an ROA or a Manifest containing a signedAttrs encod… NVD-CWE-noinfo
CVE-2024-45234 2024-08-28 00:45 2024-08-25 Show GitHub Exploit DB Packet Storm
313012 6.1 MEDIUM
Network
jkev record_management_system A vulnerability, which was classified as problematic, was found in SourceCodester Record Management System 1.0. This affects an unknown part of the file sort1_user.php. The manipulation of the argume… CWE-79
Cross-site Scripting
CVE-2024-8136 2024-08-28 00:43 2024-08-25 Show GitHub Exploit DB Packet Storm
313013 9.8 CRITICAL
Network
gotribe gotribe A vulnerability classified as critical has been found in Go-Tribe gotribe up to cd3ccd32cd77852c9ea73f986eaf8c301cfb6310. Affected is the function Sign of the file pkg/token/token.go. The manipulatio… CWE-798
 Use of Hard-coded Credentials
CVE-2024-8135 2024-08-28 00:41 2024-08-25 Show GitHub Exploit DB Packet Storm
313014 6.5 MEDIUM
Local
catonetworks cato_client A vulnerability in Cato Networks SDP Client on Windows allows the insertion of sensitive information into the log file, which can lead to an account takeover. However, the attack requires bypassing p… CWE-532
 Inclusion of Sensitive Information in Log Files
CVE-2024-6977 2024-08-28 00:41 2024-08-1 Show GitHub Exploit DB Packet Storm
313015 8.8 HIGH
Local
catonetworks cato_client Cato Networks Windows SDP Client Local Privilege Escalation via openssl configuration file. This issue affects SDP Client before 5.10.34. CWE-426
 Untrusted Search Path
CVE-2024-6975 2024-08-28 00:40 2024-08-1 Show GitHub Exploit DB Packet Storm
313016 9.8 CRITICAL
Network
dlink dns-1550-04_firmware
dns-1200-05_firmware
dns-1100-4_firmware
dns-726-4_firmware
dns-345_firmware
dns-343_firmware
dns-340l_firmware
dnr-326_firmware
dns-327l_firmware
dns-…
A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, … CWE-78
OS Command 
CVE-2024-8134 2024-08-28 00:39 2024-08-25 Show GitHub Exploit DB Packet Storm
313017 7.8 HIGH
Local
catonetworks cato_client Cato Networks Windows SDP Client Local Privilege Escalation via self-upgradeThis issue affects SDP Client: before 5.10.34. CWE-426
CWE-276
 Untrusted Search Path
Incorrect Default Permissions 
CVE-2024-6974 2024-08-28 00:36 2024-08-1 Show GitHub Exploit DB Packet Storm
313018 9.8 CRITICAL
Network
dlink dns-1550-04_firmware
dns-1200-05_firmware
dns-1100-4_firmware
dns-726-4_firmware
dns-345_firmware
dns-343_firmware
dns-340l_firmware
dnr-326_firmware
dns-327l_firmware
dns-…
A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, … CWE-78
OS Command 
CVE-2024-8133 2024-08-28 00:35 2024-08-25 Show GitHub Exploit DB Packet Storm
313019 9.8 CRITICAL
Network
dlink dns-1550-04_firmware
dns-1200-05_firmware
dns-1100-4_firmware
dns-726-4_firmware
dns-345_firmware
dns-343_firmware
dns-340l_firmware
dnr-326_firmware
dns-327l_firmware
dns-…
A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, … CWE-78
OS Command 
CVE-2024-8132 2024-08-28 00:35 2024-08-25 Show GitHub Exploit DB Packet Storm
313020 - -
- - A SQL Injection vulnerability exists in the updateServiceHost functionality in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23. - CVE-2024-32501 2024-08-28 00:35 2024-08-24 Show GitHub Exploit DB Packet Storm
313021 - -
- - An issue in Netgear DGN1000WW v.1.1.00.45 allows a remote attacker to execute arbitrary code via the Diagnostics page - CVE-2024-42756 2024-08-28 00:35 2024-08-24 Show GitHub Exploit DB Packet Storm
313022 9.8 CRITICAL
Network
dlink dns-1550-04_firmware
dns-1200-05_firmware
dns-1100-4_firmware
dns-726-4_firmware
dns-345_firmware
dns-343_firmware
dns-340l_firmware
dnr-326_firmware
dns-327l_firmware
dns-…
A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, … CWE-78
OS Command 
CVE-2024-8131 2024-08-28 00:34 2024-08-25 Show GitHub Exploit DB Packet Storm
313023 9.8 CRITICAL
Network
dlink dns-1550-04_firmware
dns-1200-05_firmware
dns-1100-4_firmware
dns-726-4_firmware
dns-345_firmware
dns-343_firmware
dns-340l_firmware
dnr-326_firmware
dns-327l_firmware
dns-…
A vulnerability has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-72… CWE-78
OS Command 
CVE-2024-8130 2024-08-28 00:34 2024-08-25 Show GitHub Exploit DB Packet Storm
313024 8.8 HIGH
Network
catonetworks cato_client Remote Code Execution in Cato Windows SDP client via crafted URLs. This issue affects Windows SDP Client before 5.10.34. NVD-CWE-noinfo
CVE-2024-6973 2024-08-28 00:34 2024-08-1 Show GitHub Exploit DB Packet Storm
313025 9.8 CRITICAL
Network
dlink dns-1550-04_firmware
dns-1200-05_firmware
dns-1100-4_firmware
dns-726-4_firmware
dns-345_firmware
dns-343_firmware
dns-340l_firmware
dnr-326_firmware
dns-327l_firmware
dns-…
A vulnerability, which was classified as critical, was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-… CWE-78
OS Command 
CVE-2024-8129 2024-08-28 00:33 2024-08-25 Show GitHub Exploit DB Packet Storm
313026 9.8 CRITICAL
Network
dlink dns-1550-04_firmware
dns-1200-05_firmware
dns-1100-4_firmware
dns-726-4_firmware
dns-345_firmware
dns-343_firmware
dns-340l_firmware
dnr-326_firmware
dns-327l_firmware
dns-…
A vulnerability, which was classified as critical, has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326,… CWE-78
OS Command 
CVE-2024-8128 2024-08-28 00:32 2024-08-24 Show GitHub Exploit DB Packet Storm
313027 7.8 HIGH
Local
dell peripheral_manager Dell Peripheral Manager, versions prior to 1.7.6, contain an uncontrolled search path element vulnerability. An attacker could potentially exploit this vulnerability through preloading malicious DLL … CWE-427
 Uncontrolled Search Path Element
CVE-2024-37127 2024-08-28 00:23 2024-07-31 Show GitHub Exploit DB Packet Storm
313028 8.8 HIGH
Network
netgear prosafe_network_management_system NETGEAR ProSAFE Network Management System getFilterString SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installat… CWE-89
SQL Injection
CVE-2024-6814 2024-08-28 00:03 2024-08-22 Show GitHub Exploit DB Packet Storm
313029 8.8 HIGH
Network
netgear prosafe_network_management_system NETGEAR ProSAFE Network Management System getSortString SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installatio… CWE-89
SQL Injection
CVE-2024-6813 2024-08-28 00:01 2024-08-22 Show GitHub Exploit DB Packet Storm
313030 9.8 CRITICAL
Network
servision ivg_webmax Servision - CWE-287: Improper Authentication CWE-287
Improper Authentication
CVE-2024-42336 2024-08-27 23:59 2024-08-20 Show GitHub Exploit DB Packet Storm
313031 9.8 CRITICAL
Network
dlink dns-1550-04_firmware
dns-1200-05_firmware
dns-1100-4_firmware
dns-726-4_firmware
dns-345_firmware
dns-343_firmware
dns-340l_firmware
dnr-326_firmware
dns-327l_firmware
dns-…
A vulnerability classified as critical was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-34… CWE-78
OS Command 
CVE-2024-8127 2024-08-27 23:53 2024-08-24 Show GitHub Exploit DB Packet Storm
313032 8.8 HIGH
Adjacent
tencacn fh1206_firmware Tenda FH1206 V1.2.0.8(8155)_EN contains a Buffer Overflow vulnerability via the function formWrlsafeset. CWE-787
 Out-of-bounds Write
CVE-2024-44390 2024-08-27 23:48 2024-08-24 Show GitHub Exploit DB Packet Storm
313033 6.5 MEDIUM
Adjacent
tencacn fh1206_firmware Tenda FH1206 V1.2.0.8(8155)_EN contains a Buffer Overflow vulnerability via the functino formWrlExtraGet. CWE-787
 Out-of-bounds Write
CVE-2024-44387 2024-08-27 23:48 2024-08-24 Show GitHub Exploit DB Packet Storm
313034 5.4 MEDIUM
Network
adonesevangelista online_accreditation_management_system itsourcecode Online Accreditation Management System contains a Cross Site Scripting vulnerability, which allows an attacker to execute arbitrary code via a crafted payload to the SCHOOLNAME, EMAILADD… CWE-79
Cross-site Scripting
CVE-2024-42918 2024-08-27 23:47 2024-08-24 Show GitHub Exploit DB Packet Storm
313035 5.4 MEDIUM
Network
adobe experience_manager Adobe Experience Manager versions 6.5.19 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. This vulnerability could allow an attacker to inject and execute arbitrary J… CWE-79
Cross-site Scripting
CVE-2024-41878 2024-08-27 23:46 2024-08-24 Show GitHub Exploit DB Packet Storm
313036 5.4 MEDIUM
Network
adobe experience_manager Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable … CWE-79
Cross-site Scripting
CVE-2024-41877 2024-08-27 23:46 2024-08-24 Show GitHub Exploit DB Packet Storm
313037 5.4 MEDIUM
Network
adobe experience_manager Adobe Experience Manager versions 6.5.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vul… CWE-79
Cross-site Scripting
CVE-2024-41876 2024-08-27 23:45 2024-08-24 Show GitHub Exploit DB Packet Storm
313038 5.4 MEDIUM
Network
adobe experience_manager Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable … CWE-79
Cross-site Scripting
CVE-2024-41875 2024-08-27 23:45 2024-08-24 Show GitHub Exploit DB Packet Storm
313039 5.5 MEDIUM
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Add null checker before passing variables Checks null pointer before passing variables to functions. This fixes… CWE-476
 NULL Pointer Dereference
CVE-2024-43902 2024-08-27 23:38 2024-08-26 Show GitHub Exploit DB Packet Storm
313040 5.5 MEDIUM
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix NULL pointer dereference for DTN log in DCN401 When users run the command: cat /sys/kernel/debug/dri/0/amdg… CWE-476
 NULL Pointer Dereference
CVE-2024-43901 2024-08-27 23:38 2024-08-26 Show GitHub Exploit DB Packet Storm
313041 5.5 MEDIUM
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix null pointer deref in dcn20_resource.c Fixes a hang thats triggered when MPV is run on a DCN401 dGPU: mpv -… CWE-476
 NULL Pointer Dereference
CVE-2024-43899 2024-08-27 23:38 2024-08-26 Show GitHub Exploit DB Packet Storm
313042 7.8 HIGH
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: media: xc2028: avoid use-after-free in load_firmware_cb() syzkaller reported use-after-free in load_firmware_cb() [1]. The reason… CWE-416
 Use After Free
CVE-2024-43900 2024-08-27 23:38 2024-08-26 Show GitHub Exploit DB Packet Storm
313043 5.5 MEDIUM
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: padata: Fix possible divide-by-0 panic in padata_mt_helper() We are hit with a not easily reproducible divide-by-0 panic in padat… CWE-369
 Divide By Zero
CVE-2024-43889 2024-08-27 23:38 2024-08-26 Show GitHub Exploit DB Packet Storm
313044 7.8 HIGH
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mm: list_lru: fix UAF for memory cgroup The mem_cgroup_from_slab_obj() is supposed to be called under rcu lock or cgroup_mutex or… CWE-416
 Use After Free
CVE-2024-43888 2024-08-27 23:37 2024-08-26 Show GitHub Exploit DB Packet Storm
313045 5.5 MEDIUM
Local
linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Add null check in resource_log_pipe_topology_update [WHY] When switching from "Extend" to "Second Display Only" … CWE-476
 NULL Pointer Dereference
CVE-2024-43886 2024-08-27 23:37 2024-08-26 Show GitHub Exploit DB Packet Storm
313046 8.8 HIGH
Network
zohocorp manageengine_adaudit_plus Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injection in extranet lockouts report option. CWE-89
SQL Injection
CVE-2024-5586 2024-08-27 23:37 2024-08-23 Show GitHub Exploit DB Packet Storm
313047 8.8 HIGH
Network
zohocorp manageengine_adaudit_plus Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in reports module. CWE-89
SQL Injection
CVE-2024-5556 2024-08-27 23:36 2024-08-23 Show GitHub Exploit DB Packet Storm
313048 8.8 HIGH
Network
zohocorp manageengine_adaudit_plus Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in aggregate reports option. CWE-89
SQL Injection
CVE-2024-5490 2024-08-27 23:36 2024-08-23 Show GitHub Exploit DB Packet Storm
313049 - -
- - A cross-site scripting (XSS) vulnerability in the Create Product function of fastapi-admin pro v0.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the… - CVE-2024-42816 2024-08-27 23:35 2024-08-27 Show GitHub Exploit DB Packet Storm
313050 6.1 MEDIUM
Network
zohocorp manageengine_servicedesk_plus_msp
manageengine_servicedesk_plus
manageengine_supportcenter_plus
An Stored Cross-site Scripting vulnerability in request module affects Zohocorp ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP and SupportCenter Plus.This issue affects ServiceDesk Plus versions… CWE-79
Cross-site Scripting
CVE-2024-41150 2024-08-27 23:35 2024-08-24 Show GitHub Exploit DB Packet Storm