CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-51112
6.1 MEDIUM

Open Redirect vulnerability in Pnetlab 5.3.11 allows an attacker to manipulate URLs to redirect users to arbitrary external websites via a crafted script

Jan 6, 2025
CVE-2024-51111
4.1 MEDIUM

Cross-Site Scripting (XSS) vulnerability in Pnetlab 5.3.11 allows an attacker to inject malicious scripts into a web page, which are executed in the context of …

Jan 6, 2025
CVE-2024-31914
6.4 MEDIUM

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed …

Jan 6, 2025
CVE-2024-31913
5.5 MEDIUM

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed …

Jan 6, 2025
CVE-2024-8474
7.5 HIGH

OpenVPN Connect before version 3.5.0 can contain the configuration profile's clear-text private key which is logged in the application log, which an unauthorized actor can …

Jan 6, 2025
CVE-2024-5594
9.1 CRITICAL

OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which an attacker controlling the server can use to inject unexpected arbitrary data ending up in …

Jan 6, 2025
CVE-2024-12970
3.9 LOW

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TUBITAK BILGEM Pardus OS My Computer allows OS Command Injection.This …

Jan 6, 2025
CVE-2024-45559
5.5 MEDIUM

Transient DOS can occur when GVM sends a specific message type to the Vdev-FastRPC backend.

Jan 6, 2025
CVE-2024-45558
7.5 HIGH

Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE …

Jan 6, 2025
CVE-2024-45555
8.4 HIGH

Memory corruption can occur if an already verified IFS2 image is overwritten, bypassing boot verification. This allows unauthorized programs to be injected into security-sensitive images, …

Jan 6, 2025
CVE-2024-45553
7.8 HIGH

Memory corruption can occur when process-specific maps are added to the global list. If a map is removed from the global list while another thread …

Jan 6, 2025
CVE-2024-45550
7.8 HIGH

Memory corruption occurs when invoking any IOCTL-calling application that executes all MCDM driver IOCTL calls.

Jan 6, 2025
CVE-2024-45548
7.8 HIGH

Memory corruption while processing FIPS encryption or decryption validation functionality IOCTL call.

Jan 6, 2025
CVE-2024-45547
7.8 HIGH

Memory corruption while processing IOCTL call invoked from user-space to verify non extension FIPS encryption and decryption functionality.

Jan 6, 2025
CVE-2024-45546
7.8 HIGH

Memory corruption while processing FIPS encryption or decryption IOCTL call invoked from user-space.

Jan 6, 2025
CVE-2024-45542
7.8 HIGH

Memory corruption when IOCTL call is invoked from user-space to write board data to WLAN driver.

Jan 6, 2025
CVE-2024-45541
7.8 HIGH

Memory corruption when IOCTL call is invoked from user-space to read board data.

Jan 6, 2025
CVE-2024-43064
7.5 HIGH

Uncontrolled resource consumption when a driver, an application or a SMMU client tries to access the global registers through SMMU.

Jan 6, 2025
CVE-2024-43063
6.1 MEDIUM

information disclosure while invoking the mailbox read API.

Jan 6, 2025
CVE-2024-33067
6.1 MEDIUM

Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver.

Jan 6, 2025
CVE-2024-33061
6.8 MEDIUM

Information disclosure while processing IOCTL call made for releasing a trusted VM process release or opening a channel without initializing the process.

Jan 6, 2025
CVE-2024-33059
6.7 MEDIUM

Memory corruption while processing frame command IOCTL calls.

Jan 6, 2025
CVE-2024-33055
6.7 MEDIUM

Memory corruption while invoking IOCTL calls to unmap the DMA buffers.

Jan 6, 2025
CVE-2024-33041
6.7 MEDIUM

Memory corruption when input parameter validation for number of fences is missing for fence frame IOCTL calls,

Jan 6, 2025
CVE-2024-23366
6.6 MEDIUM

Information Disclosure while invoking the mailbox write API when message received from user is larger than mailbox size.

Jan 6, 2025
CVE-2024-21464
8.4 HIGH

Memory corruption while processing IPA statistics, when there are no active clients registered.

Jan 6, 2025
CVE-2024-12311
6.5 MEDIUM

The Email Subscribers by Icegram Express WordPress plugin before 5.7.44 does not sanitize and escape a parameter before using it in a SQL statement, allowing …

Jan 6, 2025
CVE-2024-12302
6.1 MEDIUM

The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its Campaign settings, which could allow authors and above to perform …

Jan 6, 2025
CVE-2024-11849
6.1 MEDIUM

The Pods WordPress plugin before 3.2.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Jan 6, 2025
CVE-2024-11356
6.1 MEDIUM

The tourmaster WordPress plugin before 5.3.4 does not sanitise and escape some parameters when outputting them in the page, which could allow unauthenticated users to …

Jan 6, 2025
CVE-2024-20154
8.8 HIGH

In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution, if a …

Jan 6, 2025
CVE-2024-20153
7.5 HIGH

In wlan STA, there is a possible way to trick a client to connect to an AP with spoofed SSID. This could lead to remote …

Jan 6, 2025
CVE-2024-20152
4.4 MEDIUM

In wlan STA driver, there is a possible reachable assertion due to improper exception handling. This could lead to local denial of service if a …

Jan 6, 2025
CVE-2024-20151
6.7 MEDIUM

In Modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if …

Jan 6, 2025
CVE-2024-20150
7.5 HIGH

In Modem, there is a possible system crash due to a logic error. This could lead to remote denial of service with no additional execution …

Jan 6, 2025
CVE-2024-20149
7.5 HIGH

In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution …

Jan 6, 2025
CVE-2024-20148
9.8 CRITICAL

In wlan STA FW, there is a possible out of bounds write due to improper input validation. This could lead to remote (proximal/adjacent) code execution …

Jan 6, 2025
CVE-2024-20146
8.1 HIGH

In wlan STA driver, there is a possible out of bounds write due to improper input validation. This could lead to remote (proximal/adjacent) code execution …

Jan 6, 2025
CVE-2024-20145
6.6 MEDIUM

In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, …

Jan 6, 2025
CVE-2024-20144
6.6 MEDIUM

In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, …

Jan 6, 2025
CVE-2024-20143
6.6 MEDIUM

In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, …

Jan 6, 2025
CVE-2024-20140
6.7 MEDIUM

In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if …

Jan 6, 2025
CVE-2024-20105
6.7 MEDIUM

In m4u, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if …

Jan 6, 2025
CVE-2024-13145
6.3 MEDIUM

A vulnerability classified as critical was found in zhenfeng13 My-Blog 1.0. Affected by this vulnerability is the function upload of the file src/main/java/com/site/blog/my/core/controller/admin/uploadController. java. The …

Jan 6, 2025
CVE-2024-13144
6.3 MEDIUM

A vulnerability classified as critical has been found in zhenfeng13 My-Blog 1.0. Affected is the function uploadFileByEditomd of the file src/main/java/com/site/blog/my/core/controller/admin/BlogController.java. The manipulation of the …

Jan 6, 2025
CVE-2024-13143
2.4 LOW

A vulnerability was found in ZeroWdd studentmanager 1.0. It has been rated as problematic. This issue affects the function submitAddPermission of the file src/main/java/com/zero/system/controller/PermissionController. java. …

Jan 6, 2025
CVE-2025-0233
7.3 HIGH

A vulnerability was found in Codezips Project Management System 1.0. It has been classified as critical. This affects an unknown part of the file /pages/forms/course.php. …

Jan 5, 2025
CVE-2024-13142
2.4 LOW

A vulnerability was found in ZeroWdd studentmanager 1.0. It has been declared as problematic. This vulnerability affects the function submitAddRole of the file src/main/java/com/zero/system/controller/RoleController. java. …

Jan 5, 2025
CVE-2025-0232
6.3 MEDIUM

A vulnerability was found in Codezips Blood Bank Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Jan 5, 2025
CVE-2025-0231
6.3 MEDIUM

A vulnerability has been found in Codezips Gym Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Jan 5, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.