CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-53272
6.1 MEDIUM

Habitica is an open-source habit-building program. Versions prior to 5.28.5 are vulnerable to reflected cross-site scripting. The `login` and `social media` function in `RegisterLoginReset.vue` contains …

Dec 12, 2024
CVE-2024-44300
5.5 MEDIUM

A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An app …

Dec 12, 2024
CVE-2024-44299
9.8 CRITICAL

The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1. An attacker may be …

Dec 12, 2024
CVE-2024-44291
7.8 HIGH

A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. A malicious …

Dec 12, 2024
CVE-2024-44290
3.3 LOW

This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, watchOS 11.1. …

Dec 12, 2024
CVE-2024-44248
6.5 MEDIUM

This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. A user with …

Dec 12, 2024
CVE-2024-44246
5.3 MEDIUM

The issue was addressed with improved routing of Safari-originated requests. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS …

Dec 12, 2024
CVE-2024-44245
7.1 HIGH

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, macOS Sonoma …

Dec 12, 2024
CVE-2024-44243
5.5 MEDIUM

A configuration issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.3. An app may be able to …

Dec 12, 2024
CVE-2024-44242
9.8 CRITICAL

The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1. An attacker may be …

Dec 12, 2024
CVE-2024-44241
9.8 CRITICAL

The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1. An attacker may be …

Dec 12, 2024
CVE-2024-44225
7.8 HIGH

A logic issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, macOS Sonoma …

Dec 12, 2024
CVE-2024-44224
7.8 HIGH

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. A malicious app …

Dec 12, 2024
CVE-2024-44220
5.5 MEDIUM

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2. Parsing a maliciously crafted video file …

Dec 12, 2024
CVE-2024-44212
5.3 MEDIUM

A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, …

Dec 12, 2024
CVE-2024-44201
5.5 MEDIUM

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.1 and iPadOS 18.1, iPadOS 17.7.3, macOS Sequoia 15.1, macOS Sonoma …

Dec 12, 2024
CVE-2024-44200
3.3 LOW

This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1. An app …

Dec 12, 2024
CVE-2024-42407
8.5 HIGH

Insertion of Sensitive Information into Log File (CWE-532) in the Gallagher Command Centre Alarm Transmitter feature could allow an authenticated Operator to view some security …

Dec 12, 2024
CVE-2024-41146
4.6 MEDIUM

Use of Multiple Resources with Duplicate Identifier (CWE-694) in the Controller 6000 and Controller 7000 Platforms could allow an attacker with physical access to HBUS …

Dec 12, 2024
CVE-2024-12536
3.5 LOW

A vulnerability, which was classified as problematic, has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0. Affected by this issue is some …

Dec 12, 2024
CVE-2024-12503
2.4 LOW

A vulnerability classified as problematic was found in ClassCMS 4.8. Affected by this vulnerability is an unknown functionality of the file /index.php/admin of the component …

Dec 12, 2024
CVE-2024-12497
7.3 HIGH

A vulnerability classified as critical has been found in 1000 Projects Attendance Tracking Management System 1.0. Affected is an unknown function of the file /admin/check_admin_login.php. …

Dec 12, 2024
CVE-2024-12492
6.3 MEDIUM

A vulnerability was found in code-projects Farmacia 1.0. It has been rated as critical. This issue affects some unknown processing of the file /visualizar-usuario.php. The …

Dec 12, 2024
CVE-2024-12490
6.3 MEDIUM

A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0. It has been declared as critical. This vulnerability affects unknown code of …

Dec 12, 2024
CVE-2024-55884
9.0 CRITICAL

In the Mullvad VPN client 2024.6 (Desktop), 2024.8 (iOS), and 2024.8-beta1 (Android), the exception-handling alternate stack can be exhausted, leading to heap-based out-of-bounds writes in …

Dec 12, 2024
CVE-2024-55587
8.8 HIGH

python-libarchive through 4.2.1 allows directory traversal (to create files) in extract in zip.py for ZipFile.extractall and ZipFile.extract.

Dec 12, 2024
CVE-2024-50339
5.3 MEDIUM

GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.17, an unauthenticated user can retrieve all …

Dec 12, 2024
CVE-2024-49142
7.8 HIGH

Microsoft Access Remote Code Execution Vulnerability

Dec 12, 2024
CVE-2024-49138
7.8 HIGH KEV

Windows Common Log File System Driver Elevation of Privilege Vulnerability

Dec 12, 2024
CVE-2024-49132
8.1 HIGH

Windows Remote Desktop Services Remote Code Execution Vulnerability

Dec 12, 2024
CVE-2024-49129
7.5 HIGH

Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability

Dec 12, 2024
CVE-2024-49128
8.1 HIGH

Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.

Dec 12, 2024
CVE-2024-49127
8.1 HIGH

Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

Dec 12, 2024
CVE-2024-49126
8.1 HIGH

Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability

Dec 12, 2024
CVE-2024-49125
8.8 HIGH

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

Dec 12, 2024
CVE-2024-49124
8.1 HIGH

Lightweight Directory Access Protocol (LDAP) Client Remote Code Execution Vulnerability

Dec 12, 2024
CVE-2024-49123
8.1 HIGH

Windows Remote Desktop Services Remote Code Execution Vulnerability

Dec 12, 2024
CVE-2024-49122
8.1 HIGH

Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

Dec 12, 2024
CVE-2024-49121
7.5 HIGH

Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability

Dec 12, 2024
CVE-2024-49120
8.1 HIGH

Windows Remote Desktop Services Remote Code Execution Vulnerability

Dec 12, 2024
CVE-2024-49119
8.1 HIGH

Windows Remote Desktop Services Remote Code Execution Vulnerability

Dec 12, 2024
CVE-2024-49118
8.1 HIGH

Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

Dec 12, 2024
CVE-2024-49117
8.8 HIGH

Windows Hyper-V Remote Code Execution Vulnerability

Dec 12, 2024
CVE-2024-49116
8.1 HIGH

Windows Remote Desktop Services Remote Code Execution Vulnerability

Dec 12, 2024
CVE-2024-49115
8.1 HIGH

Windows Remote Desktop Services Remote Code Execution Vulnerability

Dec 12, 2024
CVE-2024-49114
7.8 HIGH

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

Dec 12, 2024
CVE-2024-49113
7.5 HIGH

Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability

Dec 12, 2024
CVE-2024-49112
9.8 CRITICAL

Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

Dec 12, 2024
CVE-2024-49111
6.6 MEDIUM

Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability

Dec 12, 2024
CVE-2024-49110
6.8 MEDIUM

Windows Mobile Broadband Driver Elevation of Privilege Vulnerability

Dec 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.