CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-51741
4.4 MEDIUM

Redis is an open source, in-memory database that persists on disk. An authenticated with sufficient privileges may create a malformed ACL selector which, when accessed, …

Jan 6, 2025
CVE-2024-48457
7.5 HIGH

An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi 11AC Router NC63 3.0.0.3327 and …

Jan 6, 2025
CVE-2024-48456
7.5 HIGH

An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi 11AC Router NC63 3.0.0.3327 and …

Jan 6, 2025
CVE-2024-48455
2.7 LOW

An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi 11AC Router NC63 3.0.0.3327 and …

Jan 6, 2025
CVE-2024-46981
7.0 HIGH

Redis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua script to manipulate the garbage …

Jan 6, 2025
CVE-2021-27285
8.4 HIGH

An issue was discovered in Inspur ClusterEngine v4.0 that allows attackers to gain escalated Local privileges and execute arbitrary commands via /opt/tsce4/torque6/bin/getJobsByShell.

Jan 6, 2025
CVE-2024-55076
8.1 HIGH

Grocy through 4.3.0 has no CSRF protection, as demonstrated by changing the Administrator's password.

Jan 6, 2025
CVE-2024-55075
4.3 MEDIUM

Grocy through 4.3.0 allows remote attackers to obtain sensitive information via direct requests to pages that are not shown in the UI, such as calendar …

Jan 6, 2025
CVE-2025-21617

Guzzle OAuth Subscriber signs Guzzle requests using OAuth 1.0. Prior to 0.8.1, Nonce generation does not use sufficient entropy nor a cryptographically secure pseudorandom source. …

Jan 6, 2025
CVE-2024-55074
8.8 HIGH

The edit profile function of Grocy through 4.3.0 allows stored XSS and resultant privilege escalation by uploading a crafted HTML or SVG file, a different …

Jan 6, 2025
CVE-2024-55408
5.3 MEDIUM

An improper access control vulnerability in the AsusSAIO.sys driver may lead to the misuse of software functionality utilizing the driver when crafted IOCTL requests are …

Jan 6, 2025
CVE-2024-55407
7.8 HIGH

An issue in the DeviceloControl function of ITE Tech. Inc ITE IO Access v1.0.0.0 allows attackers to perform arbitrary port read and write actions via …

Jan 6, 2025
CVE-2024-46209
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the component /media/test.html of REDAXO CMS v5.17.1 allows attackers to execute arbitrary web scripts or HTML via injecting …

Jan 6, 2025
CVE-2024-35498
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in Grav v1.7.45 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

Jan 6, 2025
CVE-2024-56828
9.8 CRITICAL

File Upload vulnerability in ChestnutCMS through 1.5.0. Based on the code analysis, it was determined that the /api/member/avatar API endpoint receives a base64 string as …

Jan 6, 2025
CVE-2024-55629
7.5 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.8, TCP streams with TCP urgent data (out …

Jan 6, 2025
CVE-2024-55628
7.5 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.8, DNS resource name compression can lead …

Jan 6, 2025
CVE-2024-55627
5.9 MEDIUM

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.8, a specially crafted TCP stream can lead …

Jan 6, 2025
CVE-2024-55626
3.3 LOW

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.8, a large BPF filter file provided to …

Jan 6, 2025
CVE-2024-55529
9.8 CRITICAL

Z-BlogPHP 1.7.3 is vulnerable to arbitrary code execution via \zb_users\theme\shell\template.

Jan 6, 2025
CVE-2024-54880
9.1 CRITICAL

SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to register accounts in …

Jan 6, 2025
CVE-2024-54879
9.1 CRITICAL

SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to recharge members indefinitely.

Jan 6, 2025
CVE-2024-46622
9.8 CRITICAL

An Escalation of Privilege security vulnerability was found in SecureAge Security Suite software 7.0.x before 7.0.38, 7.1.x before 7.1.11, 8.0.x before 8.0.18, and 8.1.x before …

Jan 6, 2025
CVE-2024-46073
6.1 MEDIUM

A reflected Cross-Site Scripting (XSS) vulnerability exists in the login page of IceHRM v32.4.0.OS. The vulnerability is due to improper sanitization of the "next" parameter, …

Jan 6, 2025
CVE-2025-21618
7.5 HIGH

NiceGUI is an easy-to-use, Python-based UI framework. Prior to 2.9.1, authenticating with NiceGUI logged in the user for all browsers, including browsers in incognito mode. …

Jan 6, 2025
CVE-2025-21615
5.5 MEDIUM

AAT (Another Activity Tracker) is a GPS-tracking application for tracking sportive activities, with emphasis on cycling. Versions lower than v1.26 of AAT are vulnerable to …

Jan 6, 2025
CVE-2025-21614
7.5 HIGH

go-git is a highly extensible git implementation library written in pure Go. A denial of service (DoS) vulnerability was discovered in go-git versions prior to …

Jan 6, 2025
CVE-2025-21613
9.8 CRITICAL

go-git is a highly extensible git implementation library written in pure Go. An argument injection vulnerability was discovered in go-git versions prior to v5.13. Successful …

Jan 6, 2025
CVE-2024-56769
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: dvb-frontends: dib3000mb: fix uninit-value in dib3000_write_reg Syzbot reports [1] an uninitialized value issue found …

Jan 6, 2025
CVE-2024-56768
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix bpf_get_smp_processor_id() on !CONFIG_SMP On x86-64 calling bpf_get_smp_processor_id() in a kernel with CONFIG_SMP disabled …

Jan 6, 2025
CVE-2024-56767
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: dmaengine: at_xdmac: avoid null_prt_deref in at_xdmac_prep_dma_memset The at_xdmac_memset_create_desc may return NULL, which will lead to …

Jan 6, 2025
CVE-2024-56766
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: mtd: rawnand: fix double free in atmel_pmecc_create_user() The "user" pointer was converted from being allocated …

Jan 6, 2025
CVE-2024-56765
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: powerpc/pseries/vas: Add close() callback in vas_vm_ops struct The mapping VMA address is saved in VAS …

Jan 6, 2025
CVE-2024-56764
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ublk: detach gendisk from ublk device if add_disk() fails Inside ublk_abort_requests(), gendisk is grabbed for …

Jan 6, 2025
CVE-2024-56763
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tracing: Prevent bad count for tracing_cpumask_write If a large count is provided, it will trigger …

Jan 6, 2025
CVE-2024-56762

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jan 6, 2025
CVE-2024-56761
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: x86/fred: Clear WFE in missing-ENDBRANCH #CPs An indirect branch instruction sets the CPU indirect branch …

Jan 6, 2025
CVE-2024-56760
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: PCI/MSI: Handle lack of irqdomain gracefully Alexandre observed a warning emitted from pci_msi_setup_msi_irqs() on a …

Jan 6, 2025
CVE-2024-56759
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix use-after-free when COWing tree bock and tracing is enabled When a COWing a …

Jan 6, 2025
CVE-2024-56758
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: check folio mapping after unlock in relocate_one_folio() When we call btrfs_read_folio() to bring a …

Jan 6, 2025
CVE-2024-56757
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: mediatek: add intf release flow when usb disconnect MediaTek claim an special usb …

Jan 6, 2025
CVE-2024-55605
7.5 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.8, a large input buffer to the to_lowercase, …

Jan 6, 2025
CVE-2024-51472
3.1 LOW

IBM UrbanCode Deploy (UCD) 7.2 through 7.2.3.13, 7.3 through 7.3.2.8, and IBM DevOps Deploy 8.0 through 8.0.1.3 are vulnerable to HTML injection. This vulnerability may …

Jan 6, 2025
CVE-2024-47475
5.0 MEDIUM

Dell PowerScale OneFS 8.2.2.x through 9.8.0.x contains an incorrect permission assignment for critical resource vulnerability. A locally authenticated attacker could potentially exploit this vulnerability, leading …

Jan 6, 2025
CVE-2023-6605
7.2 HIGH

A flaw was found in FFmpeg's DASH playlist support. This vulnerability allows arbitrary HTTP GET requests to be made on behalf of the machine running …

Jan 6, 2025
CVE-2023-6604
5.3 MEDIUM

A flaw was found in FFmpeg. This vulnerability allows unexpected additional CPU load and storage consumption, potentially leading to degraded performance or denial of service …

Jan 6, 2025
CVE-2023-6601
4.7 MEDIUM

A flaw was found in FFmpeg's HLS demuxer. This vulnerability allows bypassing unsafe file extension checks and triggering arbitrary demuxers via base64-encoded data URIs appended …

Jan 6, 2025
CVE-2025-21612
8.6 HIGH

TabberNeue is a MediaWiki extension that allows the wiki to create tabs. Prior to 2.7.2, TabberTransclude.php doesn't escape the user-supplied page name when outputting, so …

Jan 6, 2025
CVE-2025-21611
8.8 HIGH

tgstation-server is a production scale tool for BYOND server management. Prior to 6.12.3, roles used to authorize API methods were incorrectly OR'd instead of AND'ed …

Jan 6, 2025
CVE-2025-21604

LangChain4j-AIDeepin is a Retrieval enhancement generation (RAG) project. Prior to 3.5.0, LangChain4j-AIDeepin uses MD5 to hash files, which may cause file upload conflicts. This issue …

Jan 6, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.