CVE Database

10843+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-11925
9.8 CRITICAL

The JobSearch WP Job Board plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.6.7. This is due to …

Nov 28, 2024
CVE-2024-9369
9.6 CRITICAL

Insufficient data validation in Mojo in Google Chrome prior to 129.0.6668.89 allowed a remote attacker who had compromised the renderer process to perform an out …

Nov 27, 2024
CVE-2024-46054
9.8 CRITICAL

OpenVidReview 1.0 is vulnerable to Incorrect Access Control. The /upload route is accessible without authentication, allowing any user to upload files.

Nov 27, 2024
CVE-2024-53604
9.8 CRITICAL

A SQL Injection vulnerability was found in /covid-tms/check_availability.php in PHPGurukul COVID 19 Testing Management System v1.0, which allows remote attackers to execute arbitrary code via …

Nov 27, 2024
CVE-2024-42330
9.1 CRITICAL

The HttpRequest object allows to get the HTTP headers from the server's response after sending the request. The problem is that the returned strings are …

Nov 27, 2024
CVE-2024-42327
9.9 CRITICAL

A non-admin user account on the Zabbix frontend with the default User role, or with any other role that gives API access can exploit this …

Nov 27, 2024
CVE-2024-53676
9.8 CRITICAL

A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution.

Nov 27, 2024
CVE-2024-50942
9.8 CRITICAL

qiwen-file v1.4.0 was discovered to contain a SQL injection vulnerability via the component /mapper/NoticeMapper.xml.

Nov 26, 2024
CVE-2024-49038
9.3 CRITICAL

Improper neutralization of input during web page generation ('Cross-site Scripting') in Copilot Studio by an unauthorized attacker leads to elevation of privilege over a network.

Nov 26, 2024
CVE-2024-11145
9.8 CRITICAL

Valor Apps Easy Folder Listing Pro has a deserialization vulnerability that allows an unauthenticated, remote attacker to execute arbitrary code with the privileges of the …

Nov 26, 2024
CVE-2024-11705
9.1 CRITICAL

`NSC_DeriveKey` inadvertently assumed that the `phKey` parameter is always non-NULL. When it was passed as NULL, a segmentation fault (SEGV) occurred, leading to crashes. This …

Nov 26, 2024
CVE-2024-11704
9.8 CRITICAL

A double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` when handling an error path. Under specific conditions, the same symmetric key could have been freed twice, …

Nov 26, 2024
CVE-2024-11698
9.8 CRITICAL

A flaw in handling fullscreen transitions may have inadvertently caused the application to become stuck in fullscreen mode when a modal dialog was opened during …

Nov 26, 2024
CVE-2024-11693
9.8 CRITICAL

The executable file warning was not presented when downloading .library-ms files. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.* This …

Nov 26, 2024
CVE-2024-50375
9.8 CRITICAL

A CWE-306 "Missing Authentication for Critical Function" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= …

Nov 26, 2024
CVE-2024-50374
9.8 CRITICAL

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G …

Nov 26, 2024
CVE-2024-50373
9.8 CRITICAL

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G …

Nov 26, 2024
CVE-2024-50372
9.8 CRITICAL

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G …

Nov 26, 2024
CVE-2024-50371
9.8 CRITICAL

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G …

Nov 26, 2024
CVE-2024-50370
9.8 CRITICAL

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G …

Nov 26, 2024
CVE-2024-11024
9.8 CRITICAL

The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.4.6. …

Nov 26, 2024
CVE-2024-11680
9.8 CRITICAL KEV

ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to …

Nov 26, 2024
CVE-2018-11922
9.8 CRITICAL

Wrong configuration in Touch Pal application can collect user behavior data without awareness by the user.

Nov 26, 2024
CVE-2017-17772
9.8 CRITICAL

In multiple functions that process 802.11 frames, out-of-bounds reads can occur due to insufficient validation.

Nov 26, 2024
CVE-2017-11076
9.8 CRITICAL

On some hardware revisions where VP9 decoding is hardware-accelerated, the frame size is not programmed correctly into the decoder hardware which can lead to an …

Nov 26, 2024
CVE-2024-36248
9.1 CRITICAL

API keys for some cloud services are hardcoded in the "main" binary. As for the details of affected product names, model numbers, and versions, refer …

Nov 26, 2024
CVE-2024-35244
9.1 CRITICAL

There are several hidden accounts. Some of them are intended for maintenance engineers, and with the knowledge of their passwords (e.g., by examining the coredump), …

Nov 26, 2024
CVE-2024-33610
9.1 CRITICAL

"sessionlist.html" and "sys_trayentryreboot.html" are accessible with no authentication. "sessionlist.html" provides logged-in users' session information including session cookies, and "sys_trayentryreboot.html" allows to reboot the device. As …

Nov 26, 2024
CVE-2024-28038
9.0 CRITICAL

The web interface of the affected devices processes a cookie value improperly, leading to a stack buffer overflow. More precisely, giving too long character string …

Nov 26, 2024
CVE-2024-10542
9.8 CRITICAL

The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse DNS …

Nov 26, 2024
CVE-2024-50672
9.8 CRITICAL

A NoSQL injection vulnerability in Adapt Learning Adapt Authoring Tool <= 0.11.3 allows unauthenticated attackers to reset user and administrator account passwords via the "Reset …

Nov 25, 2024
CVE-2024-52787
9.1 CRITICAL

An issue in the upload_documents method of libre-chat v0.0.6 allows attackers to execute a path traversal via supplying a crafted filename in an uploaded file.

Nov 25, 2024
CVE-2024-11403
9.8 CRITICAL

There exists an out of bounds read/write in LibJXL versions prior to commit 9cc451b91b74ba470fd72bd48c121e9f33d24c99. The JPEG decoder used by the JPEG XL encoder when doing …

Nov 25, 2024
CVE-2024-11666
9.0 CRITICAL

Affected devices beacon to eCharge cloud infrastructure asking if there are any command they should run. This communication is established over an insecure channel since …

Nov 24, 2024
CVE-2024-53915
9.8 CRITICAL

An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24405. It allows remote attackers to execute arbitrary code because untrusted data, …

Nov 24, 2024
CVE-2024-53914
9.8 CRITICAL

An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24344. It allows remote attackers to execute arbitrary code because untrusted data, …

Nov 24, 2024
CVE-2024-53913
9.8 CRITICAL

An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24343. It allows remote attackers to execute arbitrary code because untrusted data, …

Nov 24, 2024
CVE-2024-53912
9.8 CRITICAL

An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24341. It allows remote attackers to execute arbitrary code because untrusted data, …

Nov 24, 2024
CVE-2024-53911
9.8 CRITICAL

An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24339. It allows remote attackers to execute arbitrary code because untrusted data, …

Nov 24, 2024
CVE-2024-53910
9.8 CRITICAL

An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24336. It allows remote attackers to execute arbitrary code because untrusted data, …

Nov 24, 2024
CVE-2024-53909
9.8 CRITICAL

An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24334. It allows remote attackers to execute arbitrary code because untrusted data, …

Nov 24, 2024
CVE-2024-11236
9.8 CRITICAL

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an …

Nov 24, 2024
CVE-2024-9942
9.8 CRITICAL

The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the MJ_gmgt_user_avatar_image_upload() …

Nov 23, 2024
CVE-2024-9659
9.8 CRITICAL

The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the mj_smgt_user_avatar_image_upload() function …

Nov 23, 2024
CVE-2024-9511
9.8 CRITICAL

The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider plugin for WordPress is vulnerable to PHP Object …

Nov 23, 2024
CVE-2024-10961
9.8 CRITICAL

The Social Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.9.0. This is due to insufficient verification …

Nov 23, 2024
CVE-2024-0138
9.8 CRITICAL

NVIDIA Base Command Manager contains a missing authentication vulnerability in the CMDaemon component. A successful exploit of this vulnerability might lead to code execution, denial …

Nov 23, 2024
CVE-2024-52034
10.0 CRITICAL

An OS Command Injection vulnerability exists within myPRO Manager. A parameter within a command can be exploited by an unauthenticated remote attacker to inject arbitrary …

Nov 22, 2024
CVE-2024-47407
10.0 CRITICAL

A parameter within a command does not properly validate input within myPRO Manager which could be exploited by an unauthenticated remote attacker to inject arbitrary …

Nov 22, 2024
CVE-2024-47138
9.8 CRITICAL

The administrative interface listens by default on all interfaces on a TCP port and does not require authentication when being accessed.

Nov 22, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.