CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-54115
4.3 MEDIUM

Out-of-bounds read vulnerability in the DASH module Impact: Successful exploitation of this vulnerability will affect availability.

Dec 12, 2024
CVE-2024-54114
4.4 MEDIUM

Out-of-bounds access vulnerability in playback in the DASH module Impact: Successful exploitation of this vulnerability will affect availability.

Dec 12, 2024
CVE-2024-54113
6.5 MEDIUM

Process residence vulnerability in abnormal scenarios in the print module Impact: Successful exploitation of this vulnerability may affect power consumption.

Dec 12, 2024
CVE-2024-54112
5.5 MEDIUM

Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Dec 12, 2024
CVE-2024-54111
5.7 MEDIUM

Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.

Dec 12, 2024
CVE-2024-54110
6.2 MEDIUM

Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Dec 12, 2024
CVE-2024-54109
6.5 MEDIUM

Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.

Dec 12, 2024
CVE-2024-54108
6.5 MEDIUM

Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.

Dec 12, 2024
CVE-2024-54107
7.1 HIGH

Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.

Dec 12, 2024
CVE-2024-54106
7.1 HIGH

Null pointer dereference vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.

Dec 12, 2024
CVE-2024-54105
5.1 MEDIUM

Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.

Dec 12, 2024
CVE-2024-54104
6.2 MEDIUM

Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Dec 12, 2024
CVE-2024-54103
6.1 MEDIUM

Vulnerability of improper access control in the album module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Dec 12, 2024
CVE-2024-54102
6.1 MEDIUM

Race condition vulnerability in the DDR module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Dec 12, 2024
CVE-2024-54101
6.2 MEDIUM

Denial of service (DoS) vulnerability in the installation module Impact: Successful exploitation of this vulnerability will affect availability.

Dec 12, 2024
CVE-2024-54100
6.2 MEDIUM

Vulnerability of improper access control in the secure input module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.

Dec 12, 2024
CVE-2024-54099
6.7 MEDIUM

File replacement vulnerability on some devices Impact: Successful exploitation of this vulnerability will affect integrity and confidentiality.

Dec 12, 2024
CVE-2024-54098
8.5 HIGH

Service logic error vulnerability in the system service module Impact: Successful exploitation of this vulnerability may affect service integrity.

Dec 12, 2024
CVE-2024-54097
7.3 HIGH

Security vulnerability in the HiView module Impact: Successful exploitation of this vulnerability may affect feature implementation and integrity.

Dec 12, 2024
CVE-2024-54096
5.3 MEDIUM

Vulnerability of improper access control in the MTP module Impact: Successful exploitation of this vulnerability may affect integrity and accuracy.

Dec 12, 2024
CVE-2024-12570
6.7 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 prior to 17.4.6, from 17.5 prior to 17.5.4, and from 17.6 …

Dec 12, 2024
CVE-2024-12292
4.0 MEDIUM

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.0 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from …

Dec 12, 2024
CVE-2024-11274
8.7 HIGH

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from …

Dec 12, 2024
CVE-2024-10043
3.1 LOW

An issue has been discovered in GitLab EE affecting all versions starting from 14.3 before 17.4.6, all versions starting from 17.5 before 17.5.4 all versions …

Dec 12, 2024
CVE-2024-4109

Rejected reason: Red Hat Product Security has determined that this CVE is not a security vulnerability.

Dec 12, 2024
CVE-2024-21574
10.0 CRITICAL

The issue stems from a missing validation of the pip field in a POST request sent to the /customnode/install endpoint used to install custom nodes …

Dec 12, 2024
CVE-2024-12401
4.4 MEDIUM

A flaw was found in the cert-manager package. This flaw allows an attacker who can modify PEM data that the cert-manager reads, for example, in …

Dec 12, 2024
CVE-2024-12397
7.4 HIGH

A flaw was found in Quarkus-HTTP, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct …

Dec 12, 2024
CVE-2024-12333
6.5 MEDIUM

The Woodmart theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.0.3. This is due to the software …

Dec 12, 2024
CVE-2024-12160
6.1 MEDIUM

The Seraphinite Bulk Discounts for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on …

Dec 12, 2024
CVE-2024-11760
6.4 MEDIUM

The Currency Converter Widget ⚡ PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'currency-converter-widget-pro' shortcode in all versions up to, …

Dec 12, 2024
CVE-2024-12564

Exposure of Sensitive Information to an Unauthorized Actor vulnerability was discovered in Open Design Alliance CDE inWEB SDK before 2025.3. Installing CDE Server with default …

Dec 12, 2024
CVE-2024-12329
4.3 MEDIUM

The Essential Real Estate plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on several pages/post types in …

Dec 12, 2024
CVE-2024-12312
8.1 HIGH

The Print Science Designer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.152 via deserialization of untrusted …

Dec 12, 2024
CVE-2024-12201
4.3 MEDIUM

The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check when creating …

Dec 12, 2024
CVE-2024-11727
4.4 MEDIUM

The NotificationX – Live Sales Notification, WooCommerce Sales Popup, FOMO, Social Proof, Announcement Banner & Floating Notification Top Bar plugin for WordPress is vulnerable to …

Dec 12, 2024
CVE-2024-11724
4.3 MEDIUM

The Cookie Consent for WP – Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) plugin for WordPress is vulnerable to …

Dec 12, 2024
CVE-2024-11181
4.3 MEDIUM

The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 9.9.9.3 via …

Dec 12, 2024
CVE-2024-10784
6.4 MEDIUM

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Tile Gallery' widget in all …

Dec 12, 2024
CVE-2024-10583
5.4 MEDIUM

The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Dec 12, 2024
CVE-2024-9881
4.8 MEDIUM

The LearnPress WordPress plugin before 4.2.7.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Dec 12, 2024
CVE-2024-9641
4.8 MEDIUM

The LuckyWP Table of Contents WordPress plugin before 2.1.7 does not sanitise and escape some of its settings, which could allow high privilege users such …

Dec 12, 2024
CVE-2024-9428
4.8 MEDIUM

The Popup Builder WordPress plugin before 4.3.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Dec 12, 2024
CVE-2024-12265
5.3 MEDIUM

The Web3 Crypto Payments by DePay for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on …

Dec 12, 2024
CVE-2024-12263
4.3 MEDIUM

The Child Theme Creator by Orbisius plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the cloud_delete() …

Dec 12, 2024
CVE-2024-12255
5.3 MEDIUM

The Accept Stripe Payments Using Contact Form 7 plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.5 via …

Dec 12, 2024
CVE-2024-12172
7.5 HIGH

The WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses plugin for WordPress is vulnerable to unauthorized access due to a …

Dec 12, 2024
CVE-2024-12072
6.1 MEDIUM

The Analytics Cat – Google Analytics Made Easy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate …

Dec 12, 2024
CVE-2024-12059
4.3 MEDIUM

The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.1 via the eli_option_value …

Dec 12, 2024
CVE-2024-12040
8.8 HIGH

The Product Carousel Slider & Grid Ultimate for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, …

Dec 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.