CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-49533
5.5 MEDIUM

Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. …

Dec 10, 2024
CVE-2024-49532
5.5 MEDIUM

Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. …

Dec 10, 2024
CVE-2024-49531
5.5 MEDIUM

Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. …

Dec 10, 2024
CVE-2024-49530
7.8 HIGH

Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution …

Dec 10, 2024
CVE-2024-46341
8.0 HIGH

TP-Link TL-WR845N(UN)_V4_190219 was discovered to transmit credentials in base64 encoded form, which can be easily decoded by an attacker executing a man-in-the-middle attack.

Dec 10, 2024
CVE-2024-46340
9.8 CRITICAL

TL-WR845N(UN)_V4_201214, TP-Link TL-WR845N(UN)_V4_200909, and TL-WR845N(UN)_V4_190219 was discovered to transmit user credentials in plaintext after executing a factory reset.

Dec 10, 2024
CVE-2024-9844
7.1 HIGH

Insufficient server-side controls in Secure Application Manager of Ivanti Connect Secure before version 22.7R2.4 allows a remote authenticated attacker to bypass restrictions.

Dec 10, 2024
CVE-2024-8540
8.8 HIGH

Insecure permissions in Ivanti Sentry before versions 9.20.2 and 10.0.2 or 10.1.0 allow a local authenticated attacker to modify sensitive application components.

Dec 10, 2024
CVE-2024-7572
7.1 HIGH

Insufficient permissions in Ivanti DSM before version 2024.3.5740 allows a local authenticated attacker to delete arbitrary files.

Dec 10, 2024
CVE-2024-55550
2.7 LOW KEV

Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A …

Dec 10, 2024
CVE-2024-55500
8.8 HIGH

Cross-Site Request Forgery (CSRF) in Avenwu Whistle v.2.9.90 and before allows attackers to perform malicious API calls, resulting in the execution of arbitrary code on …

Dec 10, 2024
CVE-2024-54008
7.2 HIGH

An authenticated Remote Code Execution (RCE) vulnerability exists in the AirWave CLI. Successful exploitation of this vulnerability could allow a remote authenticated threat actor to …

Dec 10, 2024
CVE-2024-50931
4.6 MEDIUM

Silicon Labs Z-Wave Series 500 v6.84.0 was discovered to contain insecure permissions.

Dec 10, 2024
CVE-2024-50930
8.8 HIGH

An issue in Silicon Labs Z-Wave Series 500 v6.84.0 allows attackers to execute arbitrary code.

Dec 10, 2024
CVE-2024-50929
6.2 MEDIUM

Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to arbitrarily change the device type in the controller's memory, leading …

Dec 10, 2024
CVE-2024-50928
6.5 MEDIUM

Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to change the wakeup interval of end devices in controller memory, …

Dec 10, 2024
CVE-2024-50924
6.5 MEDIUM

Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to cause disrupt communications between the controller and the device itself …

Dec 10, 2024
CVE-2024-50921
6.5 MEDIUM

Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to cause a Denial of Service (DoS) via repeatedly sending crafted …

Dec 10, 2024
CVE-2024-50920
8.8 HIGH

Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to create a fake node via supplying crafted packets.

Dec 10, 2024
CVE-2024-50699
8.0 HIGH

TP-Link TL-WR845N(UN)_V4_201214, TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 were discovered to contain weak default credentials for the Administrator account.

Dec 10, 2024
CVE-2024-46442
9.8 CRITICAL

An issue in the BYD Dilink Headunit System v3.0 to v4.0 allows attackers to bypass authentication via a bruteforce attack.

Dec 10, 2024
CVE-2024-11773
9.1 CRITICAL

SQL injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to run arbitrary SQL …

Dec 10, 2024
CVE-2024-11772
9.1 CRITICAL

Command injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to achieve remote code …

Dec 10, 2024
CVE-2024-11639
10.0 CRITICAL

An authentication bypass in the admin web console of Ivanti CSA before 5.0.3 allows a remote unauthenticated attacker to gain administrative access

Dec 10, 2024
CVE-2024-11634
9.1 CRITICAL

Command injection in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to …

Dec 10, 2024
CVE-2024-11633
9.1 CRITICAL

Argument injection in Ivanti Connect Secure before version 22.7R2.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution

Dec 10, 2024
CVE-2024-10256
7.1 HIGH

Insufficient permissions in Ivanti Patch SDK before version 9.7.703 allows a local authenticated attacker to delete arbitrary files.

Dec 10, 2024
CVE-2024-53866
9.8 CRITICAL

The package manager pnpm prior to version 9.15.0 seems to mishandle overrides and global cache: Overrides from one workspace leak into npm metadata saved in …

Dec 10, 2024
CVE-2024-53247
8.8 HIGH

In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7, and versions below 3.4.261 and 3.7.13 of the Splunk Secure Gateway app on Splunk Cloud Platform, …

Dec 10, 2024
CVE-2024-53246
5.3 MEDIUM

In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7 and Splunk Cloud Platform versions below 9.3.2408.101, 9.2.2406.106, 9.2.2403.111, and 9.1.2312.206, an SPL command can potentially …

Dec 10, 2024
CVE-2024-53245
3.1 LOW

In Splunk Enterprise versions below 9.3.0, 9.2.4, and 9.1.7 and Splunk Cloud Platform versions below 9.1.2312.206, a low-privileged user that does not hold the “admin“ …

Dec 10, 2024
CVE-2024-53244
5.7 MEDIUM

In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7 and Splunk Cloud Platform versions below 9.2.2406.107, 9.2.2403.109, and 9.1.2312.206, a low-privileged user that does not …

Dec 10, 2024
CVE-2024-53243
4.3 MEDIUM

In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7 and versions below 3.2.462, 3.7.18, and 3.8.5 of the Splunk Secure Gateway app on Splunk Cloud …

Dec 10, 2024
CVE-2024-12286
9.8 CRITICAL

MOBATIME Network Master Clock - DTS 4801 allows attackers to use SSH to gain initial access using default credentials.

Dec 10, 2024
CVE-2024-55602
7.6 HIGH

PwnDoc is a penetration test report generator. Prior to commit 1d4219c596f4f518798492e48386a20c6e9a2fe6, an authenticated user who is able to update and download templates can inject path …

Dec 10, 2024
CVE-2024-55548
7.5 HIGH

Improper check of password character lenght in ORing IAP-420 allows a forced deadlock. This issue affects IAP-420: through 2.01e.

Dec 10, 2024
CVE-2024-55547
9.8 CRITICAL

SNMP objects in NET-SNMP used in ORing IAP-420 allows Command Injection. This issue affects IAP-420: through 2.01e.

Dec 10, 2024
CVE-2024-55546
5.4 MEDIUM

Missing input validation in the ORing IAP-420 web-interface allows stored Cross-Site Scripting (XSS).This issue affects IAP-420 version 2.01e and below.

Dec 10, 2024
CVE-2024-55545
6.1 MEDIUM

Missing input validation in the ORing IAP-420 web-interface allows Cross-Site Scripting (XSS).This issue affects IAP-420 version 2.01e and below.

Dec 10, 2024
CVE-2024-46657
5.5 MEDIUM

Artifex Software mupdf v1.24.9 was discovered to contain a segmentation fault via the component /tools/pdfextract.c. This vulnerability allows attackers to cause a Denial of Service …

Dec 10, 2024
CVE-2024-45494
9.8 CRITICAL

An issue was discovered in MSA FieldServer Gateway 5.0.0 through 6.5.2 (Fixed in 7.0.0). The FieldServer Gateway has an internally used shared administrative user account …

Dec 10, 2024
CVE-2024-45493
9.8 CRITICAL

An issue was discovered in MSA FieldServer Gateway 5.0.0 through 6.5.2 (Fixed in 7.0.0). The FieldServer Gateway has internal users, whose access is supposed to …

Dec 10, 2024
CVE-2024-55544
8.8 HIGH

Missing input validation in the ORing IAP-420 web-interface allows authenticated Command Injections on OS level.This issue affects IAP-420 version 2.01e and below.

Dec 10, 2024
CVE-2024-54152

Angular Expressions provides expressions for the Angular.JS web framework as a standalone module. Prior to version 1.4.3, an attacker can write a malicious expression that …

Dec 10, 2024
CVE-2024-10496
7.8 HIGH

An out of bounds read due to improper input validation in BuildFontMap in fontmgr.cpp in NI LabVIEW may disclose information or result in arbitrary code …

Dec 10, 2024
CVE-2024-10495
7.8 HIGH

An out of bounds read due to improper input validation when loading the font table in fontmgr.cpp in NI LabVIEW may disclose information or result …

Dec 10, 2024
CVE-2024-10494
7.8 HIGH

An out of bounds read due to improper input validation in HeapObjMapImpl.cpp in NI LabVIEW may disclose information or result in arbitrary code execution. Successful …

Dec 10, 2024
CVE-2024-54751
9.8 CRITICAL

COMFAST CF-WR630AX v2.7.0.2 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.

Dec 10, 2024
CVE-2024-12323
6.1 MEDIUM

The turboSMTP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in all versions up to, and including, 4.6 due to …

Dec 10, 2024
CVE-2024-12236
5.5 MEDIUM

A security issue exists in Vertex Gemini API for customers using VPC-SC. By utilizing a custom crafted file URI for image input, data exfiltration is …

Dec 10, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.