CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-9845
7.8 HIGH

Under specific circumstances, insecure permissions in Ivanti Automation before version 2024.4.0.1 allows a local authenticated attacker to achieve local privilege escalation.

Dec 11, 2024
CVE-2024-8496
7.8 HIGH

Under specific circumstances, insecure permissions in Ivanti Workspace Control before version 10.18.40.0 allows a local authenticated attacker to achieve local privilege escalation.

Dec 11, 2024
CVE-2024-48912
8.1 HIGH

GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.17, an authenticated user can use an …

Dec 11, 2024
CVE-2024-47761
7.2 HIGH

GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.17, an administrator with access to the …

Dec 11, 2024
CVE-2024-47760
8.8 HIGH

GLPI is a free asset and IT management software package. Starting in version 9.1.0 and prior to version 10.0.17, a technician with an access to …

Dec 11, 2024
CVE-2024-11598
7.8 HIGH

Under specific circumstances, insecure permissions in Ivanti Application Control before version 2024.3 HF1, 2024.1 HF2, or 2023.3 HF3 allows a local authenticated attacker to achieve …

Dec 11, 2024
CVE-2024-11597
7.8 HIGH

Under specific circumstances, insecure permissions in Ivanti Performance Manager before version 2024.3 HF1, 2024.1 HF1, or 2023.3 HF1 allows a local authenticated attacker to achieve …

Dec 11, 2024
CVE-2024-10251
7.8 HIGH

Under specific circumstances, insecure permissions in Ivanti Security Controls before version 2024.4.1 allows a local authenticated attacker to achieve local privilege escalation.

Dec 11, 2024
CVE-2024-53677
9.8 CRITICAL

File upload logic in Apache Struts is flawed. An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can …

Dec 11, 2024
CVE-2024-47758
8.8 HIGH

GLPI is a free asset and IT management software package. Starting in version 9.3.0 and prior to version 10.0.17, an authenticated user can use the …

Dec 11, 2024
CVE-2024-28141
6.3 MEDIUM

The web application is not protected against cross-site request forgery attacks. Therefore, an attacker can trick users into performing actions on the application when they …

Dec 11, 2024
CVE-2024-28140
6.1 MEDIUM

The scanner device boots into a kiosk mode by default and opens the Scan2Net interface in a browser window. This browser is run with the …

Dec 11, 2024
CVE-2024-28139
8.8 HIGH

The www-data user can elevate its privileges because sudo is configured to allow the execution of the mount command as root without a password. Therefore, …

Dec 11, 2024
CVE-2024-50585
4.7 MEDIUM

Users who click on a malicious link or visit a website under the control of an attacker can be infected with arbitrary JavaScript which is …

Dec 11, 2024
CVE-2024-51460
4.3 MEDIUM

IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information when a detailed technical error message is returned in a stack …

Dec 11, 2024
CVE-2024-11351
5.3 MEDIUM

The Restrict – membership, site, content and user access restrictions for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up …

Dec 11, 2024
CVE-2023-23472
3.1 LOW

IBM InfoSphere DataStage Flow Designer (InfoSphere Information Server 11.7) could allow an authenticated user to obtain sensitive information that could aid in further attacks against …

Dec 11, 2024
CVE-2024-12325
6.1 MEDIUM

The Waymark plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘content’ parameter in all versions up to, and including, 1.4.1 due to …

Dec 11, 2024
CVE-2024-12294
5.3 MEDIUM

The Last Viewed Posts by WPBeginner plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.1 via the …

Dec 11, 2024
CVE-2024-11840
7.1 HIGH

The RapidLoad – Optimize Web Vitals Automatically plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing …

Dec 11, 2024
CVE-2024-11008
5.3 MEDIUM

The Members – Membership & User Role Editor Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, …

Dec 11, 2024
CVE-2024-54269
4.3 MEDIUM

Missing Authorization vulnerability in Ninja Team Notibar notibar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Notibar: from n/a through <= 2.1.4.

Dec 11, 2024
CVE-2024-12363
7.1 HIGH

Insufficient permissions in the TeamViewer Patch & Asset Management component prior to version 24.12 on Windows allows a local authenticated user to delete arbitrary files. …

Dec 11, 2024
CVE-2024-11737
9.8 CRITICAL

CWE-20: Improper Input Validation vulnerability exists that could lead to a denial of service and a loss of confidentiality, integrity of the controller when an …

Dec 11, 2024
CVE-2024-11401

Rapid7 Insight Platform versions prior to November 13th 2024, suffer from a privilege escalation vulnerability whereby, due to a lack of authorization checks, an attacker …

Dec 11, 2024
CVE-2024-12283
6.1 MEDIUM

The WP Pipes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘x1’ parameter in all versions up to, and including, 1.4.1 due …

Dec 11, 2024
CVE-2024-12004
6.1 MEDIUM

The WPC Order Notes for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.2. This is …

Dec 11, 2024
CVE-2024-10511
5.3 MEDIUM

CWE-287: Improper Authentication vulnerability exists that could cause Denial of access to the web interface when someone on the local network repeatedly requests the /accessdenied …

Dec 11, 2024
CVE-2024-53292
7.2 HIGH

Dell VxVerify, versions prior to x.40.405, contain a Plain-text Password Storage Vulnerability in the shell wrapper. A local high privileged attacker could potentially exploit this …

Dec 11, 2024
CVE-2024-53290
8.4 HIGH

Dell ThinOS version 2408 contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with local access could …

Dec 11, 2024
CVE-2024-53289
7.8 HIGH

Dell ThinOS version 2408 contains a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading …

Dec 11, 2024
CVE-2024-52537
6.3 MEDIUM

Dell Client Platform Firmware Update Utility contains an Improper Link Resolution vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading …

Dec 11, 2024
CVE-2024-11053
3.4 LOW

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host …

Dec 11, 2024
CVE-2023-37395
2.5 LOW

IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information due to improper encryption of certain data.

Dec 11, 2024
CVE-2024-35117
4.4 MEDIUM

IBM OpenPages with Watson 9.0 may write sensitive information, under specific configurations, in clear text to the system tracing log files that could be obtained …

Dec 11, 2024
CVE-2024-55655

sigstore-python is a Python tool for generating and verifying Sigstore signatures. Versions of sigstore-python newer than 2.0.0 but prior to 3.6.0 perform insufficient validation of …

Dec 10, 2024
CVE-2024-55653
6.5 MEDIUM

PwnDoc is a penetration test report generator. In versions up to and including 0.5.3, an authenticated user is able to crash the backend by raising …

Dec 10, 2024
CVE-2024-54133

Action Pack is a framework for handling and responding to web requests. There is a possible Cross Site Scripting (XSS) vulnerability in the `content_security_policy` helper …

Dec 10, 2024
CVE-2024-53960
5.4 MEDIUM

Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject …

Dec 10, 2024
CVE-2024-53959
7.8 HIGH

Adobe Framemaker versions 2020.7, 2022.5 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Dec 10, 2024
CVE-2024-53958
7.8 HIGH

Substance3D - Painter versions 10.1.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Dec 10, 2024
CVE-2024-53957
7.8 HIGH

Substance3D - Painter versions 10.1.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Dec 10, 2024
CVE-2024-53956
7.8 HIGH

Premiere Pro versions 25.0, 24.6.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Dec 10, 2024
CVE-2024-53955
7.8 HIGH

Bridge versions 14.1.3, 15.0 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the …

Dec 10, 2024
CVE-2024-53006
5.5 MEDIUM

Substance3D - Modeler versions 1.14.1 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could …

Dec 10, 2024
CVE-2024-53005
5.5 MEDIUM

Substance3D - Modeler versions 1.14.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Dec 10, 2024
CVE-2024-53004
5.5 MEDIUM

Substance3D - Modeler versions 1.14.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Dec 10, 2024
CVE-2024-53003
7.8 HIGH

Substance3D - Modeler versions 1.14.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Dec 10, 2024
CVE-2024-53002
7.8 HIGH

Substance3D - Modeler versions 1.14.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Dec 10, 2024
CVE-2024-53001
7.8 HIGH

Substance3D - Modeler versions 1.14.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Dec 10, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.