CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-44231
4.6 MEDIUM

This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.1. A person with physical access to a Mac may …

Dec 20, 2024
CVE-2024-44223
4.6 MEDIUM

This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.1. An attacker with physical access to a Mac may …

Dec 20, 2024
CVE-2024-44211
5.5 MEDIUM

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.1. An app may be able to access user-sensitive …

Dec 20, 2024
CVE-2024-44195
7.5 HIGH

A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.1. An app may be able to read arbitrary files.

Dec 20, 2024
CVE-2023-42867
7.8 HIGH

This issue was addressed with improved validation of the process entitlement and Team ID. This issue is fixed in GarageBand 10.4.9. An app may be …

Dec 20, 2024
CVE-2024-11776
6.4 MEDIUM

The PCRecruiter Extensions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'PCRecruiter' shortcode in all versions up to, and including, 1.4.22 …

Dec 20, 2024
CVE-2022-34159
7.5 HIGH

Huawei printers have an input verification vulnerability. Successful exploitation of this vulnerability may cause device service exceptions. (Vulnerability ID: HWPSIRT-2022-80078) This vulnerability has been assigned …

Dec 20, 2024
CVE-2022-32204
7.5 HIGH

There is an improper input verification vulnerability in Huawei printer product. Successful exploitation of this vulnerability may cause service abnormal. (Vulnerability ID: HWPSIRT-2022-87185) This vulnerability …

Dec 20, 2024
CVE-2022-32203
9.8 CRITICAL

There is a command injection vulnerability in Huawei terminal printer product. Successful exploitation could result in the highest privileges of the printer. (Vulnerability ID: HWPSIRT-2022-51773) …

Dec 20, 2024
CVE-2024-12678
6.5 MEDIUM

Nomad Community and Nomad Enterprise ("Nomad") allocations are vulnerable to privilege escalation within a namespace through unredacted workload identity tokens. This vulnerability, identified as CVE-2024-12678, …

Dec 20, 2024
CVE-2022-32144
8.6 HIGH

There is an insufficient input verification vulnerability in Huawei product. Successful exploitation of this vulnerability may lead to service abnormal. (Vulnerability ID: HWPSIRT-2022-76192) This vulnerability …

Dec 20, 2024
CVE-2020-9250
3.3 LOW

There is an insufficient authentication vulnerability in some Huawei smart phone. An unauthenticated, local attacker can crafts software package to exploit this vulnerability. Due to …

Dec 20, 2024
CVE-2024-54538
7.5 HIGH

A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS …

Dec 20, 2024
CVE-2024-12832
6.3 MEDIUM

Arista NG Firewall ReportEntry SQL Injection Arbitrary File Read and Write Vulnerability. This vulnerability allows remote attackers to create arbitrary files and disclose sensitive information …

Dec 20, 2024
CVE-2024-12831
7.8 HIGH

Arista NG Firewall uvm_login Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Arista NG Firewall. An …

Dec 20, 2024
CVE-2024-12830
7.3 HIGH

Arista NG Firewall custom_handler Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Arista NG …

Dec 20, 2024
CVE-2024-12829
8.8 HIGH

Arista NG Firewall ExecManagerImpl Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Arista NG …

Dec 20, 2024
CVE-2024-56327
9.8 CRITICAL

pyrage is a set of Python bindings for the rage file encryption library (age in Rust). `pyrage` uses the Rust `age` crate for its underlying …

Dec 19, 2024
CVE-2024-54663
7.5 HIGH

An issue was discovered in the Webmail Classic UI in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A Local File Inclusion (LFI) vulnerability exists …

Dec 19, 2024
CVE-2024-54009
4.0 MEDIUM

Remote authentication bypass vulnerability in HPE Alletra Storage MP B10000 in versions prior to version 10.4.5 could be remotely exploited to allow disclosure of information.

Dec 19, 2024
CVE-2024-12700
8.8 HIGH

There is an unrestricted file upload vulnerability where it is possible for an authenticated user (low privileged) to upload an jsp shell and execute code …

Dec 19, 2024
CVE-2024-54984
9.8 CRITICAL

An issue in Quectel BG96 BG96MAR02A08M1G allows attackers to bypass authentication via a crafted NAS message. NOTE: this is disputed by the supplier.

Dec 19, 2024
CVE-2024-54983
9.8 CRITICAL

An issue in Quectel BC95-CNV V100R001C00SPC051 allows attackers to bypass authentication via a crafted NAS message.

Dec 19, 2024
CVE-2024-54982

An issue in Quectel BC25 with firmware version BC25PAR01A06 allows attackers to bypass authentication via a crafted NAS message. NOTE: Quectel disputes this because the …

Dec 19, 2024
CVE-2024-2201
4.7 MEDIUM

A cross-privilege Spectre v2 vulnerability allows attackers to bypass all deployed mitigations, including the recent Fine(IBT), and to leak arbitrary Linux kernel memory on Intel …

Dec 19, 2024
CVE-2024-12729
8.8 HIGH

A post-auth code injection vulnerability in the User Portal allows authenticated users to execute code remotely in Sophos Firewall older than version 21.0 MR1 (21.0.1).

Dec 19, 2024
CVE-2024-12728
9.8 CRITICAL

A weak credentials vulnerability potentially allows privileged system access via SSH to Sophos Firewall older than version 20.0 MR3 (20.0.3).

Dec 19, 2024
CVE-2024-12727
9.8 CRITICAL

A pre-auth SQL injection vulnerability in the email protection feature of Sophos Firewall versions older than 21.0 MR1 (21.0.1) allows access to the reporting database …

Dec 19, 2024
CVE-2024-12672
7.3 HIGH

A third-party vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the boundaries of allocated memory in a …

Dec 19, 2024
CVE-2024-12175
7.8 HIGH

Another “use after free” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and …

Dec 19, 2024
CVE-2024-11364
7.3 HIGH

Another “uninitialized variable” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force …

Dec 19, 2024
CVE-2024-11157
7.3 HIGH

A third-party vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the boundaries of allocated memory in a …

Dec 19, 2024
CVE-2024-7139
6.5 MEDIUM

Due to an unchecked buffer length, a specially crafted L2CAP packet can cause a buffer overflow. This buffer overflow triggers an assert, which results in …

Dec 19, 2024
CVE-2024-7138
6.5 MEDIUM

An assert may be triggered, causing a temporary denial of service when a peer device sends a specially crafted malformed L2CAP packet. If a watchdog …

Dec 19, 2024
CVE-2024-7137
6.5 MEDIUM

The L2CAP receive data buffer for L2CAP packets is restricted to packet sizes smaller than the maximum supported packet size. Receiving a packet that exceeds …

Dec 19, 2024
CVE-2024-53991
7.5 HIGH

Discourse is an open source platform for community discussion. This vulnerability only impacts Discourse instances configured to use `FileStore::LocalStore` which means uploads and backups are …

Dec 19, 2024
CVE-2024-52794
6.8 MEDIUM

Discourse is an open source platform for community discussion. Users clicking on the lightbox thumbnails could be affected. This problem is patched in the latest …

Dec 19, 2024
CVE-2024-52589
2.2 LOW

Discourse is an open source platform for community discussion. Moderators can see the Screened emails list in the admin dashboard, and through that can learn …

Dec 19, 2024
CVE-2024-49765
5.3 MEDIUM

Discourse is an open source platform for community discussion. Sites that are using discourse connect but still have local logins enabled could allow attackers to …

Dec 19, 2024
CVE-2024-12111
8.0 HIGH

In a specific scenario a LDAP user can abuse the authentication process using injection attack in OpenText Privileged Access Manager that allows authentication bypass. This …

Dec 19, 2024
CVE-2024-56200
8.6 HIGH

Altair is a fork of Misskey v12. Affected versions lack of request validation and lack of authentication in the image proxy for compressing and resizing …

Dec 19, 2024
CVE-2024-56159
5.3 MEDIUM

Astro is a web framework for content-driven websites. A bug in the build process allows any unauthenticated user to read parts of the server source …

Dec 19, 2024
CVE-2024-55196
7.5 HIGH

Insufficiently Protected Credentials in the Mail Server Configuration in GoPhish v0.12.1 allows an attacker to access cleartext passwords for the configured IMAP and SMTP servers.

Dec 19, 2024
CVE-2024-54150
9.1 CRITICAL

cjwt is a C JSON Web Token (JWT) Implementation. Algorithm confusion occurs when a system improperly verifies the type of signature used, allowing attackers to …

Dec 19, 2024
CVE-2020-6923
5.7 MEDIUM

The HP Linux Imaging and Printing (HPLIP) software may potentially be affected by memory buffer overflow.

Dec 19, 2024
CVE-2024-52897
6.2 MEDIUM

IBM MQ 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a remote attacker to obtain sensitive information when …

Dec 19, 2024
CVE-2024-51471
5.3 MEDIUM

IBM MQ Appliance 9.3 LTS, 9.3 CD, and 9.4 LTS web console could allow an authenticated user to cause a denial-of-service when trace is enabled …

Dec 19, 2024
CVE-2024-49336
6.5 MEDIUM

IBM Security Guardium 11.5 and 12.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the …

Dec 19, 2024
CVE-2024-38819
7.5 HIGH

Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests …

Dec 19, 2024
CVE-2024-12794
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Codezips E-Commerce Site 1.0. This affects an unknown part of the file /admin/editorder.php. The manipulation …

Dec 19, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.