CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-56456
6.8 MEDIUM

Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.

Jan 8, 2025
CVE-2024-56455
5.5 MEDIUM

Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.

Jan 8, 2025
CVE-2024-56454
5.5 MEDIUM

Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.

Jan 8, 2025
CVE-2024-56453
6.8 MEDIUM

Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.

Jan 8, 2025
CVE-2024-56452
5.5 MEDIUM

Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.

Jan 8, 2025
CVE-2024-56451
7.3 HIGH

Integer overflow vulnerability during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.

Jan 8, 2025
CVE-2024-56450
6.3 MEDIUM

Buffer overflow vulnerability in the component driver module Impact: Successful exploitation of this vulnerability may affect availability.

Jan 8, 2025
CVE-2024-56449
6.6 MEDIUM

Privilege escalation vulnerability in the Account module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jan 8, 2025
CVE-2024-56448
6.7 MEDIUM

Vulnerability of improper access control in the home screen widget module Impact: Successful exploitation of this vulnerability may affect availability.

Jan 8, 2025
CVE-2024-54121
6.2 MEDIUM

Startup control vulnerability in the ability module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.

Jan 8, 2025
CVE-2024-12713
5.3 MEDIUM

The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, …

Jan 8, 2025
CVE-2024-12521
6.4 MEDIUM

The Slotti Ajanvaraus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'slotti-embed-ga' shortcode in all versions up to, and including, 1.3.1 …

Jan 8, 2025
CVE-2024-12112
6.4 MEDIUM

The Easy Form Builder – WordPress plugin form builder: contact form, survey form, payment form, and custom form builder plugin for WordPress is vulnerable to …

Jan 8, 2025
CVE-2024-11916
7.4 HIGH

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification and retrieval of data due to a missing capability …

Jan 8, 2025
CVE-2024-11816
8.8 HIGH

The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Remote Code Execution in version 3.0.11. This is due to a missing …

Jan 8, 2025
CVE-2024-56447
7.8 HIGH

Vulnerability of improper permission control in the window management module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jan 8, 2025
CVE-2024-56446
4.0 MEDIUM

Vulnerability of variables not being initialized in the notification module Impact: Successful exploitation of this vulnerability may affect availability.

Jan 8, 2025
CVE-2024-56445
4.3 MEDIUM

Instruction authentication bypass vulnerability in the Findnetwork module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.

Jan 8, 2025
CVE-2024-56444
7.5 HIGH

Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jan 8, 2025
CVE-2024-56443
6.2 MEDIUM

Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jan 8, 2025
CVE-2024-56442
5.5 MEDIUM

Vulnerability of native APIs not being implemented in the NFC service module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.

Jan 8, 2025
CVE-2024-56441
4.1 MEDIUM

Race condition vulnerability in the Bastet module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jan 8, 2025
CVE-2024-56440
6.2 MEDIUM

Permission control vulnerability in the Connectivity module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.

Jan 8, 2025
CVE-2024-56439
7.5 HIGH

Access control vulnerability in the identity authentication module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jan 8, 2025
CVE-2024-56438
6.0 MEDIUM

Vulnerability of improper memory address protection in the HUKS module Impact: Successful exploitation of this vulnerability may affect availability.

Jan 8, 2025
CVE-2024-56437
5.7 MEDIUM

Vulnerability of input parameters not being verified in the widget framework module Impact: Successful exploitation of this vulnerability may affect availability.

Jan 8, 2025
CVE-2024-54120
4.1 MEDIUM

Race condition vulnerability in the distributed notification module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.

Jan 8, 2025
CVE-2024-47934
5.3 MEDIUM

Improper Input Validation vulnerability in Management Program in TXOne Networks Portable Inspector and Portable Inspector Pro Edition allows remote attacker to crash management service. The …

Jan 8, 2025
CVE-2024-47239
6.5 MEDIUM

Dell PowerScale OneFS versions 8.2.2.x through 9.9.0.0 contain an uncontrolled resource consumption vulnerability. A remote low privileged attacker could potentially exploit this vulnerability, leading to …

Jan 8, 2025
CVE-2023-52955
6.5 MEDIUM

Vulnerability of improper authentication in the ANS system service module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.

Jan 8, 2025
CVE-2023-52954
4.4 MEDIUM

Vulnerability of improper permission control in the Gallery module Impact: Successful exploitation of this vulnerability may affect availability.

Jan 8, 2025
CVE-2023-52953
6.2 MEDIUM

Path traversal vulnerability in the Medialibrary module Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.

Jan 8, 2025
CVE-2024-56436
5.5 MEDIUM

Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jan 8, 2025
CVE-2024-56435
6.2 MEDIUM

Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jan 8, 2025
CVE-2024-56434
4.4 MEDIUM

UAF vulnerability in the device node access module Impact: Successful exploitation of this vulnerability may cause service exceptions of the device.

Jan 8, 2025
CVE-2024-55356

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not …

Jan 8, 2025
CVE-2024-55355

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not …

Jan 8, 2025
CVE-2024-50603
10.0 CRITICAL KEV

An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutralization of special elements used in an OS …

Jan 8, 2025
CVE-2024-40679
5.5 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to an information disclosure vulnerability as sensitive information may be included …

Jan 8, 2025
CVE-2018-4301
9.8 CRITICAL

This issue is fixed in SCSSU-201801. A potential stack based buffer overflow existed in GemaltoKeyHandle.cpp.

Jan 8, 2025
CVE-2025-22133
9.9 CRITICAL

WeGIA is a web manager for charitable institutions. Prior to 3.2.8, a critical vulnerability was identified in the /WeGIA/html/socio/sistema/controller/controla_xlsx.php endpoint. The endpoint accepts file uploads …

Jan 7, 2025
CVE-2025-22132
8.3 HIGH

WeGIA is a web manager for charitable institutions. A Cross-Site Scripting (XSS) vulnerability was identified in the file upload functionality of the WeGIA/html/socio/sistema/controller/controla_xlsx.php endpoint. By …

Jan 7, 2025
CVE-2025-0218
5.5 MEDIUM

When batch jobs are executed by pgAgent, a script is created in a temporary directory and then executed. In versions of pgAgent prior to 4.2.3, …

Jan 7, 2025
CVE-2024-55218
6.1 MEDIUM

IceWarp Server 10.2.1 is vulnerable to Cross Site Scripting (XSS) via the meta parameter.

Jan 7, 2025
CVE-2024-54819
9.1 CRITICAL

I, Librarian before and including 5.11.1 is vulnerable to Server-Side Request Forgery (SSRF) due to improper input validation in classes/security/validation.php

Jan 7, 2025
CVE-2024-53522
7.5 HIGH

Bangkok Medical Software HOSxP XE v4.64.11.3 was discovered to contain a hardcoded IDEA Key-IV pair in the HOSxPXE4.exe and HOS-WIN32.INI components. This allows attackers to …

Jan 7, 2025
CVE-2024-35532
9.1 CRITICAL

An XML External Entity (XXE) injection vulnerability in Intersec Geosafe-ea 2022.12, 2022.13, and 2022.14 allows attackers to perform arbitrary file reading under the privileges of …

Jan 7, 2025
CVE-2022-45186
8.1 HIGH

An issue was discovered in SuiteCRM 7.12.7. Authenticated users can recover an arbitrary field of a database.

Jan 7, 2025
CVE-2022-45185
8.8 HIGH

An issue was discovered in SuiteCRM 7.12.7. Authenticated users can use CRM functions to upload malicious files. Then, deserialization can be used to achieve code …

Jan 7, 2025
CVE-2022-41573
9.8 CRITICAL

An issue was discovered in Ovidentia 8.3. The file upload feature does not prevent the uploading of executable files. A user can upload a .png …

Jan 7, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.