CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-37861
9.8 CRITICAL

Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow via the nav2_amcl process. This vulnerability is …

Dec 5, 2024
CVE-2024-37860
7.3 HIGH

Buffer Overflow vulnerability in Open Robotic Operating System 2 ROS2 navigation2- ROS2-humble&& navigation2-humble allows a local attacker to execute arbitrary code via a crafted .yaml …

Dec 5, 2024
CVE-2024-30964
7.8 HIGH

Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble allows a local attacker to execute arbitrary code via …

Dec 5, 2024
CVE-2024-30963
7.8 HIGH

Buffer Overflow vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble allows a local attacker to execute arbitrary code via …

Dec 5, 2024
CVE-2024-30962
7.8 HIGH

Buffer Overflow vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble allows a local attacker to execute arbitrary code via …

Dec 5, 2024
CVE-2024-30961
7.8 HIGH

Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble allows a local attacker to execute arbitrary code via …

Dec 5, 2024
CVE-2018-9391
6.7 MEDIUM

In update_gps_sv and output_vzw_debug of vendor/mediatek/proprietary/hardware/connectivity/gps/gps_hal/src/gpshal_wor ker.c, there is a possible out of bounds write due to a missing bounds check. This could lead to …

Dec 5, 2024
CVE-2018-9390
6.7 MEDIUM

In procfile_write of gl_proc.c, there is a possible out of bounds read of a function pointer due to an incorrect bounds check. This could lead …

Dec 5, 2024
CVE-2018-9388
9.8 CRITICAL

In store_upgrade and store_cmd of drivers/input/touchscreen/stm/ftm4_pdc.c, there are out of bound writes due to missing bounds checks or integer underflows. These could lead to escalation …

Dec 5, 2024
CVE-2018-9386
6.7 MEDIUM

In reboot_block_command of htc reboot_block driver, there is a possible stack buffer overflow due to a missing bounds check. This could lead to local escalation …

Dec 5, 2024
CVE-2024-54140

sigstore-java is a sigstore java client for interacting with sigstore infrastructure. sigstore-java has insufficient verification for a situation where a bundle provides a invalid signature …

Dec 5, 2024
CVE-2024-53457
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the Device Settings section of LibreNMS v24.9.0 to v24.10.0 allows attackers to execute arbitrary web scripts or HTML …

Dec 5, 2024
CVE-2021-0937

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Dec 5, 2024
CVE-2017-13308
6.7 MEDIUM

In tscpu_write_GPIO_out and mtkts_Abts_write of mtk_ts_Abts.c, there is a possible buffer overflow in an sscanf due to improper input validation. This could lead to a …

Dec 5, 2024
CVE-2024-53523
7.5 HIGH

JSFinder commit d70ab9bc5221e016c08cffaf0d9ac79646c90645 is vulnerable to Directory Traversal in the find_by_file function.

Dec 5, 2024
CVE-2024-53589
8.4 HIGH

GNU objdump 2.43 is vulnerable to Buffer Overflow in the BFD (Binary File Descriptor) library's handling of tekhex format files.

Dec 5, 2024
CVE-2024-53442
9.8 CRITICAL

whapa v1.59 is vulnerable to Command Injection via a crafted filename to the HTML reports component.

Dec 5, 2024
CVE-2024-41579
9.8 CRITICAL

DTStack Taier 1.4.0 allows remote attackers to specify the jobName parameter in the console listNames function to cause a SQL injection vulnerability

Dec 5, 2024
CVE-2024-11148
7.5 HIGH

In OpenBSD 7.4 before errata 006 and OpenBSD 7.3 before errata 020, httpd(8) is vulnerable to a NULL dereference when handling a malformed fastcgi request.

Dec 5, 2024
CVE-2024-10933
5.0 MEDIUM

In OpenBSD 7.5 before errata 009 and OpenBSD 7.4 before errata 022, exclude any '/' in readdir name validation to avoid unexpected directory traversal on …

Dec 5, 2024
CVE-2023-50913
9.1 CRITICAL

Oxide control plane software before 5 allows SSRF.

Dec 5, 2024
CVE-2023-48010
9.8 CRITICAL

STMicroelectronics SPC58 is vulnerable to Missing Protection Mechanism for Alternate Hardware Interface. Code running as Supervisor on the SPC58 PowerPC microcontrollers may disable the System …

Dec 5, 2024
CVE-2024-12235
6.3 MEDIUM

A vulnerability was found in Shenzhen Dashi Tongzhou Information Technology AgileBPM up to 1.0.0. It has been declared as critical. Affected by this vulnerability is …

Dec 5, 2024
CVE-2024-12130
7.8 HIGH

An “out of bounds read” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file …

Dec 5, 2024
CVE-2024-11158
6.7 MEDIUM

An “uninitialized variable” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force …

Dec 5, 2024
CVE-2024-11156
7.8 HIGH

An “out of bounds write” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the boundaries …

Dec 5, 2024
CVE-2024-11155
7.8 HIGH

A “use after free” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and …

Dec 5, 2024
CVE-2024-54128
5.7 MEDIUM

Directus is a real-time API and App dashboard for managing SQL database content. The Comment feature has implemented a filter to prevent users from adding …

Dec 5, 2024
CVE-2024-53846
5.5 MEDIUM

OTP is a set of Erlang libraries, which consists of the Erlang runtime system, a number of ready-to-use components mainly written in Erlang, and a …

Dec 5, 2024
CVE-2024-53490
7.5 HIGH

Favorites-web 1.3.0 favorites-web has a directory traversal vulnerability in SecurityFilter.java.

Dec 5, 2024
CVE-2024-12234
7.3 HIGH

A vulnerability was found in 1000 Projects Beauty Parlour Management System 1.0. It has been classified as critical. Affected is an unknown function of the …

Dec 5, 2024
CVE-2024-12233
7.3 HIGH

A vulnerability was found in code-projects Online Notice Board up to 1.0 and classified as critical. This issue affects some unknown processing of the file …

Dec 5, 2024
CVE-2024-54130

The NASA’s Interplanetary Overlay Network (ION) is an implementation of Delay/Disruption Tolerant Networking (DTN). A segmentation fault occurs with ION-DTN BPv7 software version 4.1.3 when …

Dec 5, 2024
CVE-2024-54129

The NASA’s Interplanetary Overlay Network (ION) is an implementation of Delay/Disruption Tolerant Networking (DTN). A vulnerability exists in the version ION-DTN BPv7 implementation version 4.1.3 …

Dec 5, 2024
CVE-2024-54001
5.5 MEDIUM

Kanboard is project management software that focuses on the Kanban methodology. HTML can be injected and stored into the application settings section. The fields application_language, …

Dec 5, 2024
CVE-2024-53857
7.5 HIGH

rPGP is a pure Rust implementation of OpenPGP. Prior to 0.14.1, rPGP allows attackers to trigger resource exhaustion vulnerabilities in rpgp by providing crafted messages. …

Dec 5, 2024
CVE-2024-53856
7.5 HIGH

rPGP is a pure Rust implementation of OpenPGP. Prior to 0.14.1, rPGP allows an attacker to trigger rpgp crashes by providing crafted data. This vulnerability …

Dec 5, 2024
CVE-2024-53472
8.8 HIGH

WeGIA v3.2.0 was discovered to contain a Cross-Site Request Forgery (CSRF).

Dec 5, 2024
CVE-2024-53471
6.1 MEDIUM

Multiple stored cross-site scripting (XSS) vulnerabilities in the component /configuracao/meio_pagamento.php of WeGIA v3.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted …

Dec 5, 2024
CVE-2024-53470
6.1 MEDIUM

Multiple stored cross-site scripting (XSS) vulnerabilities in the component /configuracao/gateway_pagamento.php of WeGIA v3.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted …

Dec 5, 2024
CVE-2024-12247
4.6 MEDIUM

Mattermost versions 9.7.x <= 9.7.5, 9.8.x <= 9.8.2 and 9.9.x <= 9.9.2 fail to properly propagate permission scheme updates across cluster nodes which allows a …

Dec 5, 2024
CVE-2024-12232
3.5 LOW

A vulnerability has been found in code-projects Simple CRUD Functionality 1.0 and classified as problematic. This vulnerability affects unknown code of the file /index.php. The …

Dec 5, 2024
CVE-2024-12231
7.3 HIGH

A vulnerability, which was classified as critical, was found in CodeZips Project Management System 1.0. This affects an unknown part of the file /index.php. The …

Dec 5, 2024
CVE-2024-10716
5.9 MEDIUM

Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an XSS issue with search.

Dec 5, 2024
CVE-2024-12230
7.3 HIGH

A vulnerability, which was classified as critical, has been found in PHPGurukul Complaint Management System 1.0. Affected by this issue is some unknown functionality of …

Dec 5, 2024
CVE-2024-12229
7.3 HIGH

A vulnerability classified as critical was found in PHPGurukul Complaint Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/complaint-search.php. …

Dec 5, 2024
CVE-2024-11942
5.9 MEDIUM

A vulnerability in Drupal Core allows File Manipulation.This issue affects Drupal Core: from 10.0.0 before 10.2.10.

Dec 5, 2024
CVE-2024-11941
7.5 HIGH

A vulnerability in Drupal Core allows Excessive Allocation.This issue affects Drupal Core: from 10.2.0 before 10.2.2, from 10.1.0 before 10.1.8.

Dec 5, 2024
CVE-2024-54679
4.3 MEDIUM

CyberPanel (aka Cyber Panel) before 6778ad1 does not require the FilemanagerAdmin capability for restartMySQL actions.

Dec 5, 2024
CVE-2024-53703
8.1 HIGH

A vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions mod_httprp library loaded by the Apache web server allows remote attackers to cause …

Dec 5, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.