CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-12121
5.4 MEDIUM

The Broken Link Checker | Finder plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 2.5.0 via …

Dec 19, 2024
CVE-2024-10548
6.5 MEDIUM

The WP Project Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.15 via the Project Task …

Dec 19, 2024
CVE-2023-30443
5.3 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted …

Dec 19, 2024
CVE-2023-23357
4.8 MEDIUM

A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have …

Dec 19, 2024
CVE-2023-23356
5.5 MEDIUM

A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained …

Dec 19, 2024
CVE-2023-23354
7.3 HIGH

A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have …

Dec 19, 2024
CVE-2022-27600
6.8 MEDIUM

An uncontrolled resource consumption vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to launch …

Dec 19, 2024
CVE-2022-27595
7.8 HIGH

An insecure library loading vulnerability has been reported to affect QVPN Device Client. If exploited, the vulnerability could allow local attackers who have gained user …

Dec 19, 2024
CVE-2022-33954
4.6 MEDIUM

IBM Robotic Process Automation 21.0.1, 21.0.2, and 21.0.3 could allow a user with psychical access to the system to obtain sensitive information due to insufficiently …

Dec 19, 2024
CVE-2021-39081
5.9 MEDIUM

IBM Cognos Analytics Mobile for Android 1.1.14 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

Dec 19, 2024
CVE-2024-55603
6.5 MEDIUM

Kanboard is project management software that focuses on the Kanban methodology. In affected versions sessions are still usable even though their lifetime has exceeded. Kanboard …

Dec 19, 2024
CVE-2023-21586
5.5 MEDIUM

Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a NULL Pointer Dereference vulnerability. An unauthenticated attacker …

Dec 19, 2024
CVE-2022-44520
7.8 HIGH

Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary …

Dec 19, 2024
CVE-2022-44519
5.5 MEDIUM

Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability that could lead to disclosure …

Dec 19, 2024
CVE-2022-44518
7.8 HIGH

Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary …

Dec 19, 2024
CVE-2022-44517
5.5 MEDIUM

Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted …

Dec 19, 2024
CVE-2022-44516
5.5 MEDIUM

Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted …

Dec 19, 2024
CVE-2022-44515
5.5 MEDIUM

Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted …

Dec 19, 2024
CVE-2022-44514
7.8 HIGH

Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary …

Dec 19, 2024
CVE-2022-44513
7.8 HIGH

Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by an out-of-bounds write vulnerability that could result in …

Dec 19, 2024
CVE-2022-44512
7.8 HIGH

Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by an out-of-bounds write vulnerability that could result in …

Dec 19, 2024
CVE-2021-29827
5.2 MEDIUM

IBM InfoSphere Information Server 11.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a …

Dec 19, 2024
CVE-2021-20553
5.4 MEDIUM

IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the …

Dec 19, 2024
CVE-2024-56319
7.5 HIGH

In Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0 before e3277eb, unlimited user label appends in a userlabel cluster can lead to a denial of …

Dec 18, 2024
CVE-2024-56318
7.5 HIGH

In raw\TCP.cpp in Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0 before 27ca6ec, there is a NULL pointer dereference in TCPBase::ProcessSingleMessage via TCP packets with …

Dec 18, 2024
CVE-2024-56317
7.5 HIGH

In Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0, the WriteAcl function deletes all existing ACL entries first, and then attempts to recreate them based …

Dec 18, 2024
CVE-2024-56116
8.8 HIGH

A Cross-Site Request Forgery vulnerability in Amiro.CMS before 7.8.4 allows remote attackers to create an administrator account.

Dec 18, 2024
CVE-2024-56115
6.1 MEDIUM

A vulnerability in Amiro.CMS before 7.8.4 exists due to the failure to take measures to neutralize special elements. It allows remote attackers to conduct a …

Dec 18, 2024
CVE-2024-55506
8.8 HIGH

An IDOR vulnerability in CodeAstro's Complaint Management System v1.0 (version with 0 updates) enables an attacker to execute arbitrary code and obtain sensitive information via …

Dec 18, 2024
CVE-2024-55461
9.8 CRITICAL

SeaCMS <=13.0 is vulnerable to command execution in phome.php via the function Ebak_RepPathFiletext().

Dec 18, 2024
CVE-2024-55239
5.4 MEDIUM

A reflected Cross-Site Scripting vulnerability in the standard documentation upload functionality in Portabilis i-Educar 2.9 allows attacker to craft malicious urls with arbitrary javascript in …

Dec 18, 2024
CVE-2024-53580
7.5 HIGH

iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function.

Dec 18, 2024
CVE-2024-43106
7.1 HIGH

A library injection vulnerability exists in Microsoft Excel 16.83 for macOS. A specially crafted library can leverage Excel's access privileges, leading to a permission bypass. …

Dec 18, 2024
CVE-2024-42220
7.1 HIGH

A library injection vulnerability exists in Microsoft Outlook 16.83.3 for macOS. A specially crafted library can leverage Outlook's access privileges, leading to a permission bypass. …

Dec 18, 2024
CVE-2024-42004
7.1 HIGH

A library injection vulnerability exists in Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to …

Dec 18, 2024
CVE-2024-41165
7.1 HIGH

A library injection vulnerability exists in Microsoft Word 16.83 for macOS. A specially crafted library can leverage Word's access privileges, leading to a permission bypass. …

Dec 18, 2024
CVE-2024-41159
7.1 HIGH

A library injection vulnerability exists in Microsoft OneNote 16.83 for macOS. A specially crafted library can leverage OneNote's access privileges, leading to a permission bypass. …

Dec 18, 2024
CVE-2024-41145
7.1 HIGH

A library injection vulnerability exists in the WebView.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage …

Dec 18, 2024
CVE-2024-41138
7.1 HIGH

A library injection vulnerability exists in the com.microsoft.teams2.modulehost.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage …

Dec 18, 2024
CVE-2024-39804
7.1 HIGH

A library injection vulnerability exists in Microsoft PowerPoint 16.83 for macOS. A specially crafted library can leverage PowerPoint's access privileges, leading to a permission bypass. …

Dec 18, 2024
CVE-2024-37649
4.6 MEDIUM

Insecure Permissions vulnerability in SecureSTATION v.2.5.5.3116-S50-SMA-B20160811A and before allows a physically proximate attacker to obtain sensitive information via the modification of user credentials.

Dec 18, 2024
CVE-2022-40733
5.0 MEDIUM

An access violation vulnerability exists in the DirectComposition functionality win32kbase.sys driver version 10.0.22000.593 as part of Windows 11 version 22000.593 and version 10.0.20348.643 as part …

Dec 18, 2024
CVE-2022-40732
5.0 MEDIUM

An access violation vulnerability exists in the DirectComposition functionality win32kbase.sys driver version 10.0.22000.593 as part of Windows 11 version 22000.593 and version 10.0.20348.643 as part …

Dec 18, 2024
CVE-2024-55505
8.8 HIGH

An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the mess-view.php component.

Dec 18, 2024
CVE-2024-55232
5.4 MEDIUM

An IDOR vulnerability in the manage-notes.php module in PHPGurukul Online Notes Sharing Management System v1.0 allows unauthorized users to delete notes belonging to other accounts …

Dec 18, 2024
CVE-2024-55231
4.3 MEDIUM

An IDOR vulnerability in the edit-notes.php module of PHPGurukul Online Notes Sharing Management System v1.0 allows unauthorized users to modify notes belonging to other accounts …

Dec 18, 2024
CVE-2024-12695
8.8 HIGH

Out of bounds write in V8 in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to execute arbitrary code inside a sandbox via a …

Dec 18, 2024
CVE-2024-12694
8.8 HIGH

Use after free in Compositing in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Dec 18, 2024
CVE-2024-12693
8.8 HIGH

Out of bounds memory access in V8 in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to execute arbitrary code inside a sandbox via …

Dec 18, 2024
CVE-2024-12692
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Dec 18, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.