CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-37574
8.2 HIGH

The GriceMobile com.grice.call application 4.5.2 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted …

Dec 4, 2024
CVE-2024-11643
8.8 HIGH

The Accessibility by AllAccessible plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability …

Dec 4, 2024
CVE-2024-53140
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netlink: terminate outstanding dump on socket close Netlink supports iterative dumping of data. It provides …

Dec 4, 2024
CVE-2024-53139
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: sctp: fix possible UAF in sctp_v6_available() A lockdep report [1] with CONFIG_PROVE_RCU_LIST=y hints that sctp_v6_available() …

Dec 4, 2024
CVE-2024-53138
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: kTLS, Fix incorrect page refcounting The kTLS tx handling code is using a mix …

Dec 4, 2024
CVE-2024-53137
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ARM: fix cacheflush with PAN It seems that the cacheflush syscall got broken when PAN …

Dec 4, 2024
CVE-2024-53136
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm: revert "mm: shmem: fix data-race in shmem_getattr()" Revert d949d1d14fa2 ("mm: shmem: fix data-race in …

Dec 4, 2024
CVE-2024-53135
6.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Bury Intel PT virtualization (guest/host mode) behind CONFIG_BROKEN Hide KVM's pt_mode module param …

Dec 4, 2024
CVE-2024-53134
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: pmdomain: imx93-blk-ctrl: correct remove path The check condition should be 'i < bc->onecell_data.num_domains', not 'bc->onecell_data.num_domains' …

Dec 4, 2024
CVE-2024-53133
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Handle dml allocation failure to avoid crash [Why] In the case where a dml …

Dec 4, 2024
CVE-2024-53132
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/xe/oa: Fix "Missing outer runtime PM protection" warning Fix the following drm_WARN: [953.586396] xe 0000:00:02.0: …

Dec 4, 2024
CVE-2024-53131
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix null-ptr-deref in block_touch_buffer tracepoint Patch series "nilfs2: fix null-ptr-deref bugs on block tracepoints". …

Dec 4, 2024
CVE-2024-53130
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix null-ptr-deref in block_dirty_buffer tracepoint When using the "block:block_dirty_buffer" tracepoint, mark_buffer_dirty() may cause a …

Dec 4, 2024
CVE-2024-53129
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/rockchip: vop: Fix a dereferenced before check warning The 'state' can't be NULL, we should …

Dec 4, 2024
CVE-2024-53128
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sched/task_stack: fix object_is_on_stack() for KASAN tagged pointers When CONFIG_KASAN_SW_TAGS and CONFIG_KASAN_STACK are enabled, the object_is_on_stack() …

Dec 4, 2024
CVE-2024-53127
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Revert "mmc: dw_mmc: Fix IDMAC operation with pages bigger than 4K" The commit 8396c793ffdf ("mmc: …

Dec 4, 2024
CVE-2024-53126
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: vdpa: solidrun: Fix UB bug with devres In psnet_open_pf_bar() and snet_open_vf_bar() a string later passed …

Dec 4, 2024
CVE-2024-40745
5.4 MEDIUM

Reflected Cross site scripting vulnerability in Convert Forms component for Joomla in versions before 4.4.8.

Dec 4, 2024
CVE-2024-40744
9.8 CRITICAL

Unrestricted file upload via security bypass in Convert Forms component for Joomla in versions before 4.4.8.

Dec 4, 2024
CVE-2024-12056

The Client secret is not checked when using the OAuth Password grant type. By exploiting this vulnerability, an attacker could connect to a web server …

Dec 4, 2024
CVE-2024-7488
5.3 MEDIUM

Integer Overflow or Wraparound, Improper Validation of Specified Quantity in Input vulnerability in RestApp Inc. Online Ordering System allows Integer Attacks. This issue affects Online …

Dec 4, 2024
CVE-2024-53125
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: sync_linked_regs() must preserve subreg_def Range propagation must not affect subreg_def marks, otherwise the following …

Dec 4, 2024
CVE-2024-51465
8.8 HIGH

IBM App Connect Enterprise Certified Container 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, and 12.3 could allow a remote authenticated attacker to execute arbitrary commands on …

Dec 4, 2024
CVE-2024-12138
6.3 MEDIUM

A vulnerability classified as critical was found in horilla up to 1.2.1. This vulnerability affects the function request_new/get_employee_shift/create_reimbursement/key_result_current_value_update/create_meetings/create_skills. The manipulation leads to deserialization. The attack …

Dec 4, 2024
CVE-2024-11935
6.4 MEDIUM

The Email Address Obfuscation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘class’ parameter in all versions up to, and including, 1.0.1 …

Dec 4, 2024
CVE-2024-8962
6.4 MEDIUM

The WPBITS Addons For Elementor Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, …

Dec 4, 2024
CVE-2024-8894

Out-of-bounds Write vulnerability was discovered in Open Design Alliance Drawings SDK before 2025.10. Reading crafted DWF file and missing proper checks on received SectionIterator data …

Dec 4, 2024
CVE-2024-54158
3.5 LOW

In JetBrains YouTrack before 2024.3.52635 potential spoofing attack was possible via lack of Punycode encoding

Dec 4, 2024
CVE-2024-54157
4.3 MEDIUM

In JetBrains YouTrack before 2024.3.52635 potential ReDoS was possible due to vulnerable RegExp in Ruby syntax detector

Dec 4, 2024
CVE-2024-54156
4.2 MEDIUM

In JetBrains YouTrack before 2024.3.52635 multiple merge functions were vulnerable to prototype pollution attack

Dec 4, 2024
CVE-2024-54155
3.7 LOW

In JetBrains YouTrack before 2024.3.51866 improper access control allowed listing of project names during app import without authentication

Dec 4, 2024
CVE-2024-54154
8.0 HIGH

In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox

Dec 4, 2024
CVE-2024-54153
3.1 LOW

In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query parameter

Dec 4, 2024
CVE-2024-52278

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Dec 4, 2024
CVE-2024-52269
8.1 HIGH

User Interface (UI) Misrepresentation of Critical Information vulnerability in DocuSign allows Content Spoofing. The SaaS AI assistant ignores hidden content that is rendered after signing, …

Dec 4, 2024
CVE-2024-11854
6.4 MEDIUM

The Listdom – Business Directory and Classified Ads Listings WordPress Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘shortcode’ parameter in …

Dec 4, 2024
CVE-2024-10576

Infinix devices contain a pre-loaded "com.transsion.agingfunction" application, that exposes an unsecured broadcast receiver. An attacker can communicate with the receiver and force the device to …

Dec 4, 2024
CVE-2024-52277

User Interface (UI) Misrepresentation of Critical Information vulnerability in DocuSeal allows Content Spoofing.Displayed version does not show the layer flattened version, once download, If printed …

Dec 4, 2024
CVE-2024-52276
7.5 HIGH

User Interface (UI) Misrepresentation of Critical Information vulnerability in DocuSign allows Content Spoofing. 1. Displayed version does not show the layer flattened version, which is …

Dec 4, 2024
CVE-2024-52275
9.8 CRITICAL

Stack-based Buffer Overflow vulnerability in Shenzhen Tenda Technology Co Tenda AC6V2 (fromWizardHandle modules) allows Overflow Buffers.This issue affects Tenda AC6V2: through 15.03.06.50.

Dec 4, 2024
CVE-2024-52274
9.8 CRITICAL

Stack-based Buffer Overflow vulnerability in Shenzhen Tenda Technology Co Tenda AC6V2 (setDoubleL2tpConfig->guest_ip_check(overflow arg: mask) modules) allows Overflow Buffers.This issue affects Tenda AC6V2: through 15.03.06.50

Dec 4, 2024
CVE-2024-52273
9.8 CRITICAL

Stack-based Buffer Overflow vulnerability in Shenzhen Tenda Technology Co Tenda AC6V2 (setDoublePppoeConfig->guest_ip_check(overflow arg: mask) modules) allows Overflow Buffers.This issue affects Tenda AC6V2: through 15.03.06.50

Dec 4, 2024
CVE-2024-52272
9.8 CRITICAL

Stack-based Buffer Overflow vulnerability in Shenzhen Tenda Technology Co Tenda AC6V2 (fromAdvSetLanip(overflow arg:lanMask) modules) allows Overflow Buffers.This issue affects Tenda AC6V2: through 15.03.06.50

Dec 4, 2024
CVE-2024-12107
7.5 HIGH

Double-Free Vulnerability in uD3TN BPv7 Caused by Malformed Endpoint Identifier allows remote attacker to reliably cause DoS

Dec 4, 2024
CVE-2024-11814
6.1 MEDIUM

The Additional Custom Order Status for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the wfwp_wcos_delete_finished, wfwp_wcos_delete_fallback_finished, wfwp_wcos_delete_fallback_orders_updated, and wfwp_wcos_delete_fallback_status parameters in …

Dec 4, 2024
CVE-2024-5020
6.4 MEDIUM

Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions 1.3.4 to 3.5.7) in various versions due …

Dec 4, 2024
CVE-2024-11952
7.5 HIGH

The Classic Addons – WPBakery Page Builder plugin for WordPress is vulnerable to Limited Local PHP File Inclusion in all versions up to, and including, …

Dec 4, 2024
CVE-2024-11880
6.4 MEDIUM

The B Testimonial – testimonial plugin for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'b_testimonial' shortcode in all versions …

Dec 4, 2024
CVE-2024-10787
4.3 MEDIUM

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.4.4 via the 'elementor-template' …

Dec 4, 2024
CVE-2024-10567
7.5 HIGH

The TI WooCommerce Wishlist plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wizard' function in …

Dec 4, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.