CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-55638
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 7.0 before 7.102, from 8.0.0 before 10.2.11, from 10.3.0 …

Dec 10, 2024
CVE-2024-55637
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 …

Dec 10, 2024
CVE-2024-55636
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in Drupal Core allows Object Injection.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 …

Dec 10, 2024
CVE-2024-55635
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Core allows Cross-Site Scripting (XSS).This issue affects Drupal Core: from …

Dec 10, 2024
CVE-2024-55634
8.1 HIGH

A vulnerability in Drupal Core allows Privilege Escalation.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8.

Dec 10, 2024
CVE-2024-12393
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Drupal Core allows Cross-Site Scripting (XSS).This issue affects Drupal Core: from …

Dec 10, 2024
CVE-2024-55601

Hugo is a static site generator. Starting in version 0.123.0 and prior to version 0.139.4, some HTML attributes in Markdown in the internal templates listed …

Dec 9, 2024
CVE-2024-50628
8.8 HIGH

An issue was discovered in the web services of Digi ConnectPort LTS before 1.4.12. It allows an attacker on the local area network to achieve …

Dec 9, 2024
CVE-2024-50627
8.8 HIGH

An issue was discovered in Digi ConnectPort LTS before 1.4.12. A Privilege Escalation vulnerability exists in the file upload feature. It allows an attacker on …

Dec 9, 2024
CVE-2024-50626
8.8 HIGH

An issue was discovered in Digi ConnectPort LTS before 1.4.12. A Directory Traversal vulnerability exists in WebFS. This allows an attacker on the local area …

Dec 9, 2024
CVE-2024-50625
8.0 HIGH

An issue was discovered in Digi ConnectPort LTS before 1.4.12. A vulnerability in the file upload handling of a web application allows manipulation of file …

Dec 9, 2024
CVE-2024-12174
2.7 LOW

An Improper Certificate Validation vulnerability exists in Tenable Security Center where an authenticated, privileged attacker could intercept email messages sent from Security Center via a …

Dec 9, 2024
CVE-2024-54151
7.5 HIGH

Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 11.0.0 and prior to version 11.3.0, when setting `WEBSOCKETS_GRAPHQL_AUTH` …

Dec 9, 2024
CVE-2024-54149
8.4 HIGH

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Winter CMS prior to versions 1.2.7, 1.1.11, and 1.0.476 allow …

Dec 9, 2024
CVE-2024-46455
9.8 CRITICAL

unstructured v.0.14.2 and before is vulnerable to XML External Entity (XXE) via the XMLParser.

Dec 9, 2024
CVE-2024-12369
4.2 MEDIUM

A vulnerability was found in OIDC-Client. When using the RH SSO OIDC adapter with EAP 7.x or when using the elytron-oidc-client subsystem with EAP 8.x, …

Dec 9, 2024
CVE-2024-53441
9.1 CRITICAL

An issue in the index.js decryptCookie function of cookie-encrypter v1.0.1 allows attackers to execute a bit flipping attack.

Dec 9, 2024
CVE-2024-54938
7.5 HIGH

A Directory Listing issue was found in Kashipara E-Learning Management System v1.0, which allows remote attackers to access sensitive files and directories via /admin/uploads.

Dec 9, 2024
CVE-2024-54934
9.8 CRITICAL

Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_class.php.

Dec 9, 2024
CVE-2024-54932
9.8 CRITICAL

Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_department.php.

Dec 9, 2024
CVE-2024-54931
9.8 CRITICAL

A SQL Injection was found in /admin/delete_event.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized …

Dec 9, 2024
CVE-2024-54928
7.2 HIGH

kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_teacher.php,

Dec 9, 2024
CVE-2024-54927
7.2 HIGH

Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_users.php.

Dec 9, 2024
CVE-2024-54925
9.8 CRITICAL

A SQL Injection was found in /remove_sent_message.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized …

Dec 9, 2024
CVE-2024-54924
9.8 CRITICAL

A SQL Injection was found in /admin/edit_content.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized …

Dec 9, 2024
CVE-2024-54923
9.8 CRITICAL

A SQL Injection vulnerability was found in /admin/edit_teacher.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get …

Dec 9, 2024
CVE-2024-54921
9.8 CRITICAL

A SQL Injection was found in /student_signup.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized …

Dec 9, 2024
CVE-2024-54918
9.8 CRITICAL

Kashipara E-learning Management System v1.0 is vulnerable to Remote Code Execution via File Upload in /teacher_avatar.php.

Dec 9, 2024
CVE-2024-54147
6.8 MEDIUM

Altair is a GraphQL client for all platforms. Prior to version 8.0.5, Altair GraphQL Client's desktop app does not validate HTTPS certificates allowing a man-in-the-middle …

Dec 9, 2024
CVE-2024-53847

The Trix rich text editor, prior to versions 2.1.9 and 1.3.3, is vulnerable to cross-site scripting (XSS) + mutation XSS attacks when pasting malicious code. …

Dec 9, 2024
CVE-2024-52599
5.4 MEDIUM

Tuleap is an open source suite to improve management of software developments and collaboration. In Tuleap Community Edition prior to version 16.1.99.50 and Tuleap Enterprise …

Dec 9, 2024
CVE-2024-52586
5.4 MEDIUM

eLabFTW is an open source electronic lab notebook for research labs. A vulnerability has been found starting in version 4.6.0 and prior to version 5.1.0 …

Dec 9, 2024
CVE-2024-48956
9.8 CRITICAL

Serviceware Processes 6.0 through 7.3 before 7.4 allows attackers without valid authentication to send a specially crafted HTTP request to a service endpoint resulting in …

Dec 9, 2024
CVE-2024-46547
7.5 HIGH

A vulnerability was found in Romain Bourdon Wampserver all versions (discovered in v3.2.3 and v3.2.6) where unauthorized users could access sensitive information due to improper …

Dec 9, 2024
CVE-2024-12057

User credentials (login & password) are inserted into log files when a user tries to authenticate using a version of a Web client that is …

Dec 9, 2024
CVE-2022-29974
4.3 MEDIUM

AMI (aka American Megatrends) NTFS driver 1.0.0 (fixed in late 2021 or early 2022) has a buffer overflow. This driver is, for example, used in …

Dec 9, 2024
CVE-2024-54935
5.4 MEDIUM

A Stored Cross-Site Scripting (XSS) vulnerability was found in /send_message_teacher_to_student.php of kashipara E-learning Management System v1.0. This vulnerability allows remote attackers to execute arbitrary scripts …

Dec 9, 2024
CVE-2024-54933
7.2 HIGH

Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_content.php.

Dec 9, 2024
CVE-2024-54930
7.2 HIGH

Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_student.php.

Dec 9, 2024
CVE-2024-54922
7.2 HIGH

A SQL Injection was found in /admin/edit_user.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized …

Dec 9, 2024
CVE-2024-11608
7.8 HIGH

A maliciously crafted SKP file, when linked or imported into Autodesk Revit, can be used to cause a Heap-based Overflow. A malicious actor can leverage …

Dec 9, 2024
CVE-2024-11454
7.8 HIGH

A maliciously crafted DLL file, when placed in the same directory as an RVT file could be loaded by Autodesk Revit, and execute arbitrary code …

Dec 9, 2024
CVE-2024-11268
5.5 MEDIUM

A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read. A malicious actor can leverage this vulnerability to cause a …

Dec 9, 2024
CVE-2024-54926
8.8 HIGH

A SQL Injection vulnerability was found in /search_class.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get …

Dec 9, 2024
CVE-2024-53450
7.5 HIGH

RAGFlow 0.13.0 suffers from improper access control in document-hooks.ts, allowing unauthorized access to user documents.

Dec 9, 2024
CVE-2024-45761
5.4 MEDIUM

Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper input validation vulnerability. A remote low-privileged malicious user could potentially exploit this vulnerability to …

Dec 9, 2024
CVE-2024-45760
4.3 MEDIUM

Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper access control vulnerability. A remote low privileged user could potentially exploit this vulnerability via …

Dec 9, 2024
CVE-2023-43962
4.8 MEDIUM

Cross Site Scripting vulnerability in Xunrui CMS Public Edition v.4.6.1 allows a remote attacker to execute arbitrary code via the project name function in the …

Dec 9, 2024
CVE-2022-38946
9.8 CRITICAL

Arbitrary File Upload vulnerability in Doctor-Appointment version 1.0 in /Frontend/signup_com.php, allows attackers to execute arbitrary code.

Dec 9, 2024
CVE-2024-40583
9.1 CRITICAL

Pentaminds CuroVMS v2.0.1 was discovered to contain exposed credentials.

Dec 9, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.