CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-12752
7.8 HIGH

Foxit PDF Reader AcroForm Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF …

Dec 30, 2024
CVE-2024-12751
7.8 HIGH

Foxit PDF Reader AcroForm Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF …

Dec 30, 2024
CVE-2024-11946
6.5 MEDIUM

iXsystems TrueNAS CORE fetch_plugin_packagesites tar Cleartext Transmission of Sensitive Information Vulnerability. This vulnerability allows network-adjacent attackers to tamper with firmware update files on affected installations …

Dec 30, 2024
CVE-2024-11944
8.8 HIGH

iXsystems TrueNAS CORE tarfile.extractall Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of iXsystems TrueNAS …

Dec 30, 2024
CVE-2024-56801
9.8 CRITICAL

Tasklists provides plugin tasklists for GLPI. Versions prior to 2.0.4 have a blind SQL injection vulnerability. Version 2.0.4 contains a patch for the vulnerability.

Dec 30, 2024
CVE-2024-56800
7.4 HIGH

Firecrawl is a web scraper that allows users to extract the content of a webpage for a large language model. Versions prior to 1.1.1 contain …

Dec 30, 2024
CVE-2024-56799
10.0 CRITICAL

Simofa is a tool to help automate static website building and deployment. Prior to version 0.2.7, due to a design mistake in the RouteLoader class, …

Dec 30, 2024
CVE-2024-46542
6.5 MEDIUM

Veritas / Arctera Data Insight before 7.1.1 allows Application Administrators to conduct SQL injection attacks.

Dec 30, 2024
CVE-2024-56734
6.1 MEDIUM

Better Auth is an authentication library for TypeScript. An open redirect vulnerability has been identified in the verify email endpoint of all versions of Better …

Dec 30, 2024
CVE-2024-56733
5.7 MEDIUM

Password Pusher is an open source application to communicate sensitive information over the web. A vulnerability has been reported in versions 1.50.3 and prior where …

Dec 30, 2024
CVE-2024-56517

LGSL (Live Game Server List) provides online status lists for online video games. Versions up to and including 6.2.1 contain a reflected cross-site scripting vulnerability …

Dec 30, 2024
CVE-2024-56516

free-one-api allows users to access large language model reverse engineering libraries through the standard OpenAI API format. In versions up to and including 1.0.1, MD5 …

Dec 30, 2024
CVE-2024-52294
4.3 MEDIUM

Khoj is a self-hostable artificial intelligence app. Prior to version 1.29.10, an Insecure Direct Object Reference (IDOR) vulnerability in the update_subscription endpoint allows any authenticated …

Dec 30, 2024
CVE-2024-12836
7.8 HIGH

Delta Electronics DRASimuCAD STP File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Dec 30, 2024
CVE-2024-12835
7.8 HIGH

Delta Electronics DRASimuCAD ICS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Dec 30, 2024
CVE-2024-12834
7.8 HIGH

Delta Electronics DRASimuCAD STP File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Dec 30, 2024
CVE-2024-12828
8.8 HIGH

Webmin CGI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Webmin. Authentication is required …

Dec 30, 2024
CVE-2024-12754
5.5 MEDIUM

AnyDesk Link Following Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of AnyDesk. An attacker must first obtain …

Dec 30, 2024
CVE-2024-50703
5.4 MEDIUM

TeamPass before 3.1.3.1 does not properly prevent a user from acting with the privileges of a different user_id.

Dec 30, 2024
CVE-2024-50702
5.4 MEDIUM

TeamPass before 3.1.3.1 does not properly check whether a mail_me (aka action_mail) operation is on behalf of an administrator or manager.

Dec 30, 2024
CVE-2024-50701
4.3 MEDIUM

TeamPass before 3.1.3.1, when retrieving information about access rights for a folder, does not properly check whether a folder is in a user's allowed folders …

Dec 30, 2024
CVE-2024-54181
7.2 HIGH

IBM WebSphere Automation 1.7.5 could allow a remote privileged user, who has authorized access to the swagger UI, to execute arbitrary code. Using specially crafted …

Dec 30, 2024
CVE-2024-10044
9.3 CRITICAL

A Server-Side Request Forgery (SSRF) vulnerability exists in the POST /worker_generate_stream API endpoint of the Controller API Server in lm-sys/fastchat, as of commit e208d5677c6837d590b81cb03847c0b9de100765. This …

Dec 30, 2024
CVE-2024-12993

Infinix devices contain a pre-loaded "com.rlk.weathers" application, that exposes an unsecured content provider. An attacker can communicate with the provider and reveal the user’s location …

Dec 30, 2024
CVE-2024-47926
9.8 CRITICAL

Tecnick TCExam – CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Dec 30, 2024
CVE-2024-47925
7.5 HIGH

Tecnick TCExam – Multiple CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Dec 30, 2024
CVE-2024-47924
7.5 HIGH

Boa web server – CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Dec 30, 2024
CVE-2024-47923
5.3 MEDIUM

Mashov – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Dec 30, 2024
CVE-2024-47922
7.5 HIGH

Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Dec 30, 2024
CVE-2024-47921
8.4 HIGH

Smadar SPS – CWE-327: Use of a Broken or Risky Cryptographic Algorithm

Dec 30, 2024
CVE-2024-47920
7.5 HIGH

Tiki Wiki CMS – CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Dec 30, 2024
CVE-2024-47919
9.8 CRITICAL

Tiki Wiki CMS – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Dec 30, 2024
CVE-2024-47918
6.1 MEDIUM

Tiki Wiki CMS – CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

Dec 30, 2024
CVE-2024-47917
7.5 HIGH

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Dec 30, 2024
CVE-2024-22063
7.6 HIGH

The ZENIC ONE R58 products by ZTE Corporation have a command injection vulnerability. An authenticated attacker can exploit this vulnerability to tamper with messages, inject …

Dec 30, 2024
CVE-2024-13039
6.3 MEDIUM

A vulnerability was found in code-projects Simple Chat System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Dec 30, 2024
CVE-2024-13038
7.3 HIGH

A vulnerability was found in CodeAstro Simple Loan Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Dec 30, 2024
CVE-2024-13037
6.3 MEDIUM

A vulnerability was found in 1000 Projects Attendance Tracking Management System 1.0. It has been classified as critical. Affected is the function attendance_report of the …

Dec 30, 2024
CVE-2024-13036
6.3 MEDIUM

A vulnerability was found in code-projects Chat System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/update_room.php. The manipulation …

Dec 30, 2024
CVE-2024-13035
6.3 MEDIUM

A vulnerability has been found in code-projects Chat System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/update_user.php. The manipulation …

Dec 30, 2024
CVE-2024-13034
3.5 LOW

A vulnerability, which was classified as problematic, was found in code-projects Chat System 1.0. This affects an unknown part of the file /admin/update_user.php. The manipulation …

Dec 30, 2024
CVE-2024-13033
3.5 LOW

A vulnerability, which was classified as problematic, has been found in code-projects Chat System 1.0. Affected by this issue is some unknown functionality of the …

Dec 30, 2024
CVE-2024-13032
2.7 LOW

A vulnerability classified as problematic was found in Antabot White-Jotter up to 0.2.2. Affected by this vulnerability is an unknown functionality of the file /admin/content/editor …

Dec 30, 2024
CVE-2024-13031
2.4 LOW

A vulnerability classified as problematic has been found in Antabot White-Jotter up to 0.2.2. Affected is an unknown function of the file /admin/content/editor of the …

Dec 30, 2024
CVE-2024-13030
7.3 HIGH

A vulnerability was found in D-Link DIR-823G 1.0.2B05_20181207. It has been rated as critical. This issue affects the function SetAutoRebootSettings/SetClientInfo/SetDMZSettings/SetFirewallSettings/SetParentsControlInfo/SetQoSSettings/SetVirtualServerSettings of the file /HNAP1/ of …

Dec 30, 2024
CVE-2024-13029
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in Antabot White-Jotter up to 0.2.2. Affected is an unknown function of the file /admin/content/book of …

Dec 30, 2024
CVE-2024-13028
3.7 LOW

A vulnerability, which was classified as problematic, has been found in Antabot White-Jotter up to 0.2.2. This issue affects some unknown processing of the file …

Dec 29, 2024
CVE-2024-13025
6.3 MEDIUM

A vulnerability was found in Codezips College Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /Front-end/faculty.php. …

Dec 29, 2024
CVE-2024-13024
6.3 MEDIUM

A vulnerability was found in Codezips Blood Bank Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /campaign.php. …

Dec 29, 2024
CVE-2024-13023
2.4 LOW

A vulnerability has been found in PHPGurukul Maid Hiring Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /admin/search-maid.php …

Dec 29, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.