CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-12192
7.8 HIGH

A maliciously crafted DWF file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause …

Dec 17, 2024
CVE-2024-12191
7.8 HIGH

A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause …

Dec 17, 2024
CVE-2024-12179
7.8 HIGH

A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can be used to cause a Heap-based Overflow vulnerability. A malicious actor can leverage this …

Dec 17, 2024
CVE-2024-12178
7.8 HIGH

A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute …

Dec 17, 2024
CVE-2024-11422
7.8 HIGH

A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to cause …

Dec 17, 2024
CVE-2024-10476
8.0 HIGH

Default credentials are used in the above listed BD Diagnostic Solutions products. If exploited, threat actors may be able to access, modify or delete data, …

Dec 17, 2024
CVE-2024-37607
6.5 MEDIUM

A Buffer overflow vulnerability in D-Link DAP-2555 REVA_FIRMWARE_1.20 allows remote attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

Dec 17, 2024
CVE-2024-37606
6.5 MEDIUM

A Stack overflow vulnerability in D-Link DCS-932L REVB_FIRMWARE_2.18.01 allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

Dec 17, 2024
CVE-2024-37605
6.5 MEDIUM

A NULL pointer dereference in D-Link DIR-860L REVB_FIRMWARE_2.04.B04_ic5b allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

Dec 17, 2024
CVE-2024-36832
7.5 HIGH

A NULL pointer dereference in D-Link DAP-1513 REVA_FIRMWARE_1.01 allows attackers to cause a Denial of Service (DoS) via a crafted web request without authentication. The …

Dec 17, 2024
CVE-2024-36831
5.3 MEDIUM

A NULL pointer dereference in the plugins_call_handle_uri_clean function of D-Link DAP-1520 REVA_FIRMWARE_1.10B04_BETA02_HOTFIX allows attackers to cause a Denial of Service (DoS) via a crafted HTTP …

Dec 17, 2024
CVE-2024-8972
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mobil365 Informatics Saha365 App allows SQL Injection.This issue affects Saha365 App: …

Dec 17, 2024
CVE-2024-9819
6.5 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in NextGeography NG Analyser allows Functionality Misuse.This issue affects NG Analyser: before 2.2.711.

Dec 17, 2024
CVE-2024-54677
5.3 MEDIUM

Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service. This issue affects Apache Tomcat: from 11.0.0-M1 …

Dec 17, 2024
CVE-2024-50379
9.8 CRITICAL

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is …

Dec 17, 2024
CVE-2024-10356
4.3 MEDIUM

The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.4.8 in inc/Widgets/accordion/output/content.php. This …

Dec 17, 2024
CVE-2024-9654
3.7 LOW

The Easy Digital Downloads plugin for WordPress is vulnerable to Improper Authorization in versions 3.1 through 3.3.4. This is due to a lack of sufficient …

Dec 17, 2024
CVE-2024-8475
6.5 MEDIUM

Authentication Bypass by Assumed-Immutable Data vulnerability in Digital Operation Services WiFiBurada allows Manipulating User-Controlled Variables.This issue affects WiFiBurada: before 1.0.5.

Dec 17, 2024
CVE-2024-8429
4.3 MEDIUM

Improper Restriction of Excessive Authentication Attempts vulnerability in Digital Operation Services WiFiBurada allows Use of Known Domain Credentials.This issue affects WiFiBurada: before 1.0.5.

Dec 17, 2024
CVE-2024-52542
4.4 MEDIUM

Dell AppSync, version 4.6.0.x, contain a Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to …

Dec 17, 2024
CVE-2024-12601
5.3 MEDIUM

The Calculated Fields Form plugin for WordPress is vulnerable to Denial of Service in all versions up to, and including, 5.2.63. This is due to …

Dec 17, 2024
CVE-2024-12395
6.1 MEDIUM

The WooCommerce Additional Fees On Checkout (Free) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘number’ parameter in all versions up to, …

Dec 17, 2024
CVE-2024-11280
5.3 MEDIUM

The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.9.5 via the …

Dec 17, 2024
CVE-2024-8326
8.8 HIGH

The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Sensitive Information Exposure …

Dec 17, 2024
CVE-2024-12469
6.1 MEDIUM

The WP BASE Booking of Appointments, Services and Events plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘status’ parameter in all versions …

Dec 17, 2024
CVE-2024-12127
6.1 MEDIUM

The Learning Management System, eLearning, Course Builder, WordPress LMS Plugin – Sikshya LMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ …

Dec 17, 2024
CVE-2024-12024
7.2 HIGH

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the em_ticket_category_data and em_ticket_individual_data parameters in all …

Dec 17, 2024
CVE-2024-12293
8.8 HIGH

The User Role Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.64.3. This is due to …

Dec 17, 2024
CVE-2024-11294
5.3 MEDIUM

The Memberful plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.73.9 via the WordPress core search feature. …

Dec 17, 2024
CVE-2024-12220
6.1 MEDIUM

The SMS for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.1. This is due to …

Dec 17, 2024
CVE-2024-12219
6.1 MEDIUM

The Stop Registration Spam plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.23. This is due to …

Dec 17, 2024
CVE-2024-11999
8.8 HIGH

CWE-1104: Use of Unmaintained Third-Party Components vulnerability exists that could cause complete control of the device when an authenticated user installs malicious code into HMI …

Dec 17, 2024
CVE-2021-26281
5.5 MEDIUM

Some parameters of the alarm clock module are improperly stored, leaking some sensitive information.

Dec 17, 2024
CVE-2021-26280
7.9 HIGH

Locally installed application can bypass the permission check and perform system operations that require permission.

Dec 17, 2024
CVE-2024-9624
7.6 HIGH

The WP All Import Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.9.3 due to missing …

Dec 17, 2024
CVE-2024-54125
3.3 LOW

Improper authorization in handler for custom URL scheme issue in "Shonen Jump+" App for Android versions prior to 4.0.0 allows an attacker to lead a …

Dec 17, 2024
CVE-2024-38499
8.8 HIGH

CA Client Automation (ITCM) allows non-admin/non-root users to encrypt a string using CAF CLI and SD_ACMD CLI. This would allow the non admin user to …

Dec 17, 2024
CVE-2024-55864
4.8 MEDIUM

Cross-site scripting vulnerability exists in My WP Customize Admin/Frontend versions prior to ver 1.24.1. If a malicious administrative user customizes the administrative page with some …

Dec 17, 2024
CVE-2024-12356
9.8 CRITICAL KEV

A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands …

Dec 17, 2024
CVE-2021-26279
5.9 MEDIUM

Some parameters of the weather module are improperly stored, leaking some sensitive information.

Dec 17, 2024
CVE-2024-12239
6.1 MEDIUM

The PowerPack Lite for Beaver Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the navigate parameter in all versions up to, and …

Dec 17, 2024
CVE-2021-26278
6.3 MEDIUM

The wifi module exposes the interface and has improper permission control, leaking sensitive information about the device.

Dec 17, 2024
CVE-2020-12487
7.0 HIGH

Due to the flaws in the verification of input parameters, the attacker can input carefully constructed commands to make the ABE service execute some commands …

Dec 17, 2024
CVE-2020-12484
6.4 MEDIUM

When using special mode to connect to enterprise wifi, certain options are not properly configured and attackers can pretend to be enterprise wifi through a …

Dec 17, 2024
CVE-2024-10205
9.4 CRITICAL

Authentication Bypass vulnerability in Hitachi Ops Center Analyzer on Linux, 64 bit (Hitachi Ops Center Analyzer detail view component), Hitachi Infrastructure Analytics Advisor on Linux, …

Dec 17, 2024
CVE-2024-11906
6.4 MEDIUM

The TPG Get Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tpg_get_posts' shortcode in all versions up to, and including, …

Dec 17, 2024
CVE-2024-11905
6.4 MEDIUM

The Animated Counters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'animatedcounte' shortcode in all versions up to, and including, 2.0 …

Dec 17, 2024
CVE-2024-11902
6.4 MEDIUM

The Slope Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'slope-reservations' shortcode in all versions up to, and including, 4.2.12 …

Dec 17, 2024
CVE-2024-11900
6.4 MEDIUM

The Portfolio – Filterable Masonry Portfolio Gallery for Professionals plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'portfolio-pro' shortcode in all …

Dec 17, 2024
CVE-2024-56017
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Tom Royal Stop Registration Spam allows Stored XSS.This issue affects Stop Registration Spam: from n/a through 1.23.

Dec 16, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.