CVE Database

10843+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-49147
9.3 CRITICAL

Deserialization of untrusted data in Microsoft Update Catalog allows an unauthorized attacker to elevate privileges on the website’s webserver.

Dec 12, 2024
CVE-2024-55662
9.9 CRITICAL

XWiki Platform is a generic wiki platform. Starting in version 3.3-milestone-1 and prior to versions 15.10.9 and 16.3.0, on instances where `Extension Repository Application` is …

Dec 12, 2024
CVE-2024-54810
9.8 CRITICAL

A SQL Injection vulnerability was found in /preschool/admin/password-recovery.php in PHPGurukul Pre-School Enrollment System Project v1.0, which allows remote attackers to execute arbitrary code via the …

Dec 12, 2024
CVE-2024-55099
9.8 CRITICAL

A SQL Injection vulnerability was found in /admin/index.php in phpgurukul Online Nurse Hiring System v1.0, which allows remote attackers to execute arbitrary SQL commands to …

Dec 12, 2024
CVE-2024-54842
9.8 CRITICAL

A SQL injection vulnerability was found in phpgurukul Online Nurse Hiring System v1.0 in /admin/password-recovery.php via the mobileno parameter.

Dec 12, 2024
CVE-2024-21574
10.0 CRITICAL

The issue stems from a missing validation of the pip field in a POST request sent to the /customnode/install endpoint used to install custom nodes …

Dec 12, 2024
CVE-2024-10124
9.8 CRITICAL

The Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation and activation due to a …

Dec 12, 2024
CVE-2024-11015
9.8 CRITICAL

The Sign In With Google plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.8.0. This is due to …

Dec 12, 2024
CVE-2024-55660
9.8 CRITICAL

SiYuan is a personal knowledge management system. Prior to version 3.1.16, SiYuan's `/api/template/renderSprig` endpoint is vulnerable to Server-Side Template Injection (SSTI) through the Sprig template …

Dec 12, 2024
CVE-2024-54534
9.8 CRITICAL

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.6, macOS Sequoia 15.2, …

Dec 12, 2024
CVE-2024-54506
9.8 CRITICAL

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.2. An attacker may be able to cause …

Dec 12, 2024
CVE-2024-54465
9.8 CRITICAL

A logic issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.2. An app may be able to elevate privileges.

Dec 12, 2024
CVE-2024-44299
9.8 CRITICAL

The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1. An attacker may be …

Dec 12, 2024
CVE-2024-44242
9.8 CRITICAL

The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1. An attacker may be …

Dec 12, 2024
CVE-2024-44241
9.8 CRITICAL

The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1. An attacker may be …

Dec 12, 2024
CVE-2024-55884
9.0 CRITICAL

In the Mullvad VPN client 2024.6 (Desktop), 2024.8 (iOS), and 2024.8-beta1 (Android), the exception-handling alternate stack can be exhausted, leading to heap-based out-of-bounds writes in …

Dec 12, 2024
CVE-2024-49112
9.8 CRITICAL

Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

Dec 12, 2024
CVE-2024-47834
9.1 CRITICAL

GStreamer is a library for constructing graphs of media-handling components. An Use-After-Free read vulnerability has been discovered affecting the processing of CodecPrivate elements in Matroska …

Dec 12, 2024
CVE-2024-47777
9.1 CRITICAL

GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been identified in the gst_wavparse_smpl_chunk function within gstwavparse.c. This function attempts …

Dec 12, 2024
CVE-2024-47776
9.1 CRITICAL

GStreamer is a library for constructing graphs of media-handling components. An OOB-read has been discovered in gst_wavparse_cue_chunk within gstwavparse.c. The vulnerability happens due to a …

Dec 12, 2024
CVE-2024-47775
9.1 CRITICAL

GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been found in the parse_ds64 function within gstwavparse.c. The parse_ds64 function …

Dec 12, 2024
CVE-2024-47774
9.1 CRITICAL

GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been identified in the gst_avi_subtitle_parse_gab2_chunk function within gstavisubtitle.c. The function reads …

Dec 12, 2024
CVE-2024-47615
9.8 CRITICAL

GStreamer is a library for constructing graphs of media-handling components. An OOB-Write has been detected in the function gst_parse_vorbis_setup_packet within vorbis_parse.c. The integer size is …

Dec 12, 2024
CVE-2024-47613
9.8 CRITICAL

GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been identified in `gst_gdk_pixbuf_dec_flush` within `gstgdkpixbufdec.c`. This function invokes …

Dec 12, 2024
CVE-2024-47607
9.8 CRITICAL

GStreamer is a library for constructing graphs of media-handling components. stack-buffer overflow has been detected in the gst_opus_dec_parse_header function within `gstopusdec.c'. The pos array is …

Dec 12, 2024
CVE-2024-47606
9.8 CRITICAL

GStreamer is a library for constructing graphs of media-handling components. An integer underflow has been detected in the function qtdemux_parse_theora_extension within qtdemux.c. The vulnerability occurs …

Dec 12, 2024
CVE-2024-47600
9.1 CRITICAL

GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been detected in the format_channel_mask function in gst-discoverer.c. The vulnerability affects …

Dec 12, 2024
CVE-2024-47598
9.1 CRITICAL

GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been discovered in the qtdemux_merge_sample_table function within qtdemux.c. The problem is …

Dec 12, 2024
CVE-2024-47597
9.1 CRITICAL

GStreamer is a library for constructing graphs of media-handling components. An OOB-read has been detected in the function qtdemux_parse_samples within qtdemux.c. This issue arises when …

Dec 12, 2024
CVE-2024-47540
9.8 CRITICAL

GStreamer is a library for constructing graphs of media-handling components. An uninitialized stack variable vulnerability has been identified in the gst_matroska_demux_add_wvpk_header function within matroska-demux.c. When …

Dec 12, 2024
CVE-2024-47539
9.8 CRITICAL

GStreamer is a library for constructing graphs of media-handling components. An out-of-bounds write vulnerability was identified in the convert_to_s334_1a function in isomp4/qtdemux.c. The vulnerability arises …

Dec 12, 2024
CVE-2024-47538
9.8 CRITICAL

GStreamer is a library for constructing graphs of media-handling components. A stack-buffer overflow has been detected in the `vorbis_handle_identification_packet` function within `gstvorbisdec.c`. The position array …

Dec 12, 2024
CVE-2024-47537
9.8 CRITICAL

GStreamer is a library for constructing graphs of media-handling components. The program attempts to reallocate the memory pointed to by stream->samples to accommodate stream->n_samples + …

Dec 12, 2024
CVE-2024-45337
9.1 CRITICAL

Applications and libraries which misuse connection.serverAuthenticate (via callback field ServerConfig.PublicKeyCallback) may be susceptible to an authorization bypass. The documentation for ServerConfig.PublicKeyCallback says that "A call …

Dec 12, 2024
CVE-2024-42448
9.9 CRITICAL

From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is possible to perform Remote Code Execution …

Dec 12, 2024
CVE-2024-11948
9.8 CRITICAL

GFI Archiver Telerik Web UI Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GFI Archiver. Authentication …

Dec 12, 2024
CVE-2024-53677
9.8 CRITICAL

File upload logic in Apache Struts is flawed. An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can …

Dec 11, 2024
CVE-2024-11737
9.8 CRITICAL

CWE-20: Improper Input Validation vulnerability exists that could lead to a denial of service and a loss of confidentiality, integrity of the controller when an …

Dec 11, 2024
CVE-2024-54036
9.3 CRITICAL

Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject …

Dec 10, 2024
CVE-2024-54034
9.3 CRITICAL

Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim …

Dec 10, 2024
CVE-2024-54032
9.3 CRITICAL

Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject …

Dec 10, 2024
CVE-2024-53480
9.8 CRITICAL

Phpgurukul's Beauty Parlour Management System v1.1 is vulnerable to SQL Injection in `login.php` via the `emailcont` parameter.

Dec 10, 2024
CVE-2024-46340
9.8 CRITICAL

TL-WR845N(UN)_V4_201214, TP-Link TL-WR845N(UN)_V4_200909, and TL-WR845N(UN)_V4_190219 was discovered to transmit user credentials in plaintext after executing a factory reset.

Dec 10, 2024
CVE-2024-46442
9.8 CRITICAL

An issue in the BYD Dilink Headunit System v3.0 to v4.0 allows attackers to bypass authentication via a bruteforce attack.

Dec 10, 2024
CVE-2024-11773
9.1 CRITICAL

SQL injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to run arbitrary SQL …

Dec 10, 2024
CVE-2024-11772
9.1 CRITICAL

Command injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to achieve remote code …

Dec 10, 2024
CVE-2024-11639
10.0 CRITICAL

An authentication bypass in the admin web console of Ivanti CSA before 5.0.3 allows a remote unauthenticated attacker to gain administrative access

Dec 10, 2024
CVE-2024-11634
9.1 CRITICAL

Command injection in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to …

Dec 10, 2024
CVE-2024-11633
9.1 CRITICAL

Argument injection in Ivanti Connect Secure before version 22.7R2.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution

Dec 10, 2024
CVE-2024-53866
9.8 CRITICAL

The package manager pnpm prior to version 9.15.0 seems to mishandle overrides and global cache: Overrides from one workspace leak into npm metadata saved in …

Dec 10, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.