CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-47776
9.1 CRITICAL

GStreamer is a library for constructing graphs of media-handling components. An OOB-read has been discovered in gst_wavparse_cue_chunk within gstwavparse.c. The vulnerability happens due to a …

Dec 12, 2024
CVE-2024-47775
9.1 CRITICAL

GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been found in the parse_ds64 function within gstwavparse.c. The parse_ds64 function …

Dec 12, 2024
CVE-2024-47774
9.1 CRITICAL

GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been identified in the gst_avi_subtitle_parse_gab2_chunk function within gstavisubtitle.c. The function reads …

Dec 12, 2024
CVE-2024-47615
9.8 CRITICAL

GStreamer is a library for constructing graphs of media-handling components. An OOB-Write has been detected in the function gst_parse_vorbis_setup_packet within vorbis_parse.c. The integer size is …

Dec 12, 2024
CVE-2024-47613
9.8 CRITICAL

GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been identified in `gst_gdk_pixbuf_dec_flush` within `gstgdkpixbufdec.c`. This function invokes …

Dec 12, 2024
CVE-2024-47607
9.8 CRITICAL

GStreamer is a library for constructing graphs of media-handling components. stack-buffer overflow has been detected in the gst_opus_dec_parse_header function within `gstopusdec.c'. The pos array is …

Dec 12, 2024
CVE-2024-47606
9.8 CRITICAL

GStreamer is a library for constructing graphs of media-handling components. An integer underflow has been detected in the function qtdemux_parse_theora_extension within qtdemux.c. The vulnerability occurs …

Dec 12, 2024
CVE-2024-47603
7.5 HIGH

GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been discovered in the gst_matroska_demux_update_tracks function within matroska-demux.c. The …

Dec 12, 2024
CVE-2024-47602
7.5 HIGH

GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been discovered in the gst_matroska_demux_add_wvpk_header function within matroska-demux.c. This …

Dec 12, 2024
CVE-2024-47601
7.5 HIGH

GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been discovered in the gst_matroska_demux_parse_blockgroup_or_simpleblock function within matroska-demux.c. This …

Dec 12, 2024
CVE-2024-47600
9.1 CRITICAL

GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been detected in the format_channel_mask function in gst-discoverer.c. The vulnerability affects …

Dec 12, 2024
CVE-2024-47599
7.5 HIGH

GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference vulnerability has been discovered in the gst_jpeg_dec_negotiate function in gstjpegdec.c. This …

Dec 12, 2024
CVE-2024-47598
9.1 CRITICAL

GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been discovered in the qtdemux_merge_sample_table function within qtdemux.c. The problem is …

Dec 12, 2024
CVE-2024-47597
9.1 CRITICAL

GStreamer is a library for constructing graphs of media-handling components. An OOB-read has been detected in the function qtdemux_parse_samples within qtdemux.c. This issue arises when …

Dec 12, 2024
CVE-2024-47596
7.5 HIGH

GStreamer is a library for constructing graphs of media-handling components. An OOB-read has been discovered in the qtdemux_parse_svq3_stsd_data function within qtdemux.c. In the FOURCC_SMI_ case, …

Dec 12, 2024
CVE-2024-47546
7.5 HIGH

GStreamer is a library for constructing graphs of media-handling components. An integer underflow has been detected in extract_cc_from_data function within qtdemux.c. In the FOURCC_c708 case, …

Dec 12, 2024
CVE-2024-47545
7.5 HIGH

GStreamer is a library for constructing graphs of media-handling components. An integer underflow has been detected in qtdemux_parse_trak function within qtdemux.c. During the strf parsing …

Dec 12, 2024
CVE-2024-47544
7.5 HIGH

GStreamer is a library for constructing graphs of media-handling components. The function qtdemux_parse_sbgp in qtdemux.c is affected by a null dereference vulnerability. This vulnerability is …

Dec 12, 2024
CVE-2024-47543
7.5 HIGH

GStreamer is a library for constructing graphs of media-handling components. An OOB-read vulnerability has been discovered in qtdemux_parse_container function within qtdemux.c. In the parent function …

Dec 12, 2024
CVE-2024-47542
7.5 HIGH

GStreamer is a library for constructing graphs of media-handling components. A null pointer dereference has been discovered in the id3v2_read_synch_uint function, located in id3v2.c. If …

Dec 12, 2024
CVE-2024-47541
7.5 HIGH

GStreamer is a library for constructing graphs of media-handling components. An OOB-write vulnerability has been identified in the gst_ssa_parse_remove_override_codes function of the gstssaparse.c file. This …

Dec 12, 2024
CVE-2024-47540
9.8 CRITICAL

GStreamer is a library for constructing graphs of media-handling components. An uninitialized stack variable vulnerability has been identified in the gst_matroska_demux_add_wvpk_header function within matroska-demux.c. When …

Dec 12, 2024
CVE-2024-47539
9.8 CRITICAL

GStreamer is a library for constructing graphs of media-handling components. An out-of-bounds write vulnerability was identified in the convert_to_s334_1a function in isomp4/qtdemux.c. The vulnerability arises …

Dec 12, 2024
CVE-2024-47538
9.8 CRITICAL

GStreamer is a library for constructing graphs of media-handling components. A stack-buffer overflow has been detected in the `vorbis_handle_identification_packet` function within `gstvorbisdec.c`. The position array …

Dec 12, 2024
CVE-2024-47537
9.8 CRITICAL

GStreamer is a library for constructing graphs of media-handling components. The program attempts to reallocate the memory pointed to by stream->samples to accommodate stream->n_samples + …

Dec 12, 2024
CVE-2024-45404
8.1 HIGH

OpenCTI is an open-source cyber threat intelligence platform. In versions below 6.2.18, because the function to limit the rate of OTP does not exist, an …

Dec 12, 2024
CVE-2024-45337
9.1 CRITICAL

Applications and libraries which misuse connection.serverAuthenticate (via callback field ServerConfig.PublicKeyCallback) may be susceptible to an authorization bypass. The documentation for ServerConfig.PublicKeyCallback says that "A call …

Dec 12, 2024
CVE-2024-43600
7.8 HIGH

Microsoft Office Elevation of Privilege Vulnerability

Dec 12, 2024
CVE-2024-43594
7.3 HIGH

Microsoft System Center Elevation of Privilege Vulnerability

Dec 12, 2024
CVE-2024-42448
9.9 CRITICAL

From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is possible to perform Remote Code Execution …

Dec 12, 2024
CVE-2024-37401
7.5 HIGH

An out-of-bounds read in IPsec of Ivanti Connect Secure before version 22.7R2.1 allows a remote unauthenticated attacker to cause a denial of service.

Dec 12, 2024
CVE-2024-37377
7.5 HIGH

A heap-based buffer overflow in IPsec of Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to cause a denial of service.

Dec 12, 2024
CVE-2024-12489
6.3 MEDIUM

A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0. It has been classified as critical. This affects an unknown part of …

Dec 12, 2024
CVE-2024-12488
6.3 MEDIUM

A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0 and classified as critical. Affected by this issue is some unknown functionality …

Dec 12, 2024
CVE-2024-12487
6.3 MEDIUM

A vulnerability has been found in code-projects Online Class and Exam Scheduling System 1.0 and classified as critical. Affected by this vulnerability is an unknown …

Dec 12, 2024
CVE-2024-12486
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in code-projects Online Class and Exam Scheduling System 1.0. Affected is an unknown function of the …

Dec 12, 2024
CVE-2024-12485
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in code-projects Online Class and Exam Scheduling System 1.0. This issue affects some unknown processing …

Dec 12, 2024
CVE-2024-12484
7.3 HIGH

A vulnerability classified as critical was found in Codezips Technical Discussion Forum 1.0. This vulnerability affects unknown code of the file /signuppost.php. The manipulation of …

Dec 12, 2024
CVE-2024-12483
3.7 LOW

A vulnerability classified as problematic has been found in Dromara UJCMS up to 9.6.3. This affects an unknown part of the file /users/id of the …

Dec 12, 2024
CVE-2024-12482
4.3 MEDIUM

A vulnerability was found in cjbi wetech-cms 1.0/1.1/1.2. It has been rated as problematic. Affected by this issue is the function backup of the file …

Dec 12, 2024
CVE-2024-12481
6.3 MEDIUM

A vulnerability was found in cjbi wetech-cms 1.0/1.1/1.2. It has been declared as critical. Affected by this vulnerability is the function findUser of the file …

Dec 12, 2024
CVE-2024-12480
6.3 MEDIUM

A vulnerability was found in cjbi wetech-cms 1.0/1.1/1.2. It has been classified as critical. Affected is the function searchTopic of the file wetech-cms-master\wetech-core\src\main\java\tech\wetech\cms\dao\TopicDao.java. The manipulation …

Dec 12, 2024
CVE-2024-12479
6.3 MEDIUM

A vulnerability was found in cjbi wetech-cms 1.0/1.1/1.2 and classified as critical. This issue affects the function searchTopicByKeyword of the file wetech-cms-master\wetech-core\src\main\java\tech\wetech\cms\dao\TopicDao.java. The manipulation of …

Dec 12, 2024
CVE-2024-12382
8.8 HIGH

Use after free in Translate in Google Chrome prior to 131.0.6778.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Dec 12, 2024
CVE-2024-12381
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 131.0.6778.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Dec 12, 2024
CVE-2024-11950
8.8 HIGH

XnSoft XnView Classic RWZ File Parsing Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Dec 12, 2024
CVE-2024-11949
8.8 HIGH

GFI Archiver Store Service Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Dec 12, 2024
CVE-2024-11948
9.8 CRITICAL

GFI Archiver Telerik Web UI Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GFI Archiver. Authentication …

Dec 12, 2024
CVE-2024-11947
8.8 HIGH

GFI Archiver Core Service Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Dec 12, 2024
CVE-2024-11872
7.8 HIGH

Epic Games Launcher Incorrect Default Permissions Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Epic Games Launcher. …

Dec 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.