CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-51114
8.8 HIGH

An issue in Beijing Digital China Yunke Information Technology Co.Ltd v.7.2.6.120 allows a remote attacker to execute arbitrary code via the code/function/dpi/web_auth/customizable.php file

Dec 3, 2024
CVE-2024-53921
2.8 LOW

An issue was discovered in the installer in Samsung Magician 8.1.0 on Windows. An attacker can create arbitrary folders in the system permission directory via …

Dec 3, 2024
CVE-2024-50948
7.5 HIGH

mochiMQTT v2.6.3 is vulnerable to Denial of Service (DoS) due to improper resource management. An attacker can exhaust system memory and crash the broker by …

Dec 3, 2024
CVE-2024-48080
7.5 HIGH

An issue in aedes v0.51.2 allows attackers to cause a Denial of Service(DoS) via a crafted request. NOTE: the Supplier indicates that exploitation cannot occur …

Dec 3, 2024
CVE-2024-12053
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 131.0.6778.108 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium …

Dec 3, 2024
CVE-2024-52548
6.7 MEDIUM

An attacker who can execute arbitrary Operating Systems commands, can bypass code signing enforcements in the kernel, and execute arbitrary native code. This vulnerability has …

Dec 3, 2024
CVE-2024-52547
7.2 HIGH

An authenticated attacker can trigger a stack based buffer overflow in the DHIP Service (TCP port 80). This vulnerability has been resolved in firmware version …

Dec 3, 2024
CVE-2024-52546
5.3 MEDIUM

An unauthenticated attacker can perform a null pointer dereference in the DHIP Service (UDP port 37810). This vulnerability has been resolved in firmware version 2.800.0000000.8.R.20241111.

Dec 3, 2024
CVE-2024-52545
6.5 MEDIUM

An unauthenticated attacker can perform an out of bounds heap read in the IQ Service (TCP port 9876). This vulnerability has been resolved in firmware …

Dec 3, 2024
CVE-2024-52544
9.8 CRITICAL

An unauthenticated attacker can trigger a stack based buffer overflow in the DP Service (TCP port 3500). This vulnerability has been resolved in firmware version …

Dec 3, 2024
CVE-2024-45676
4.3 MEDIUM

IBM Cognos Controller 11.0.0 and 11.0.1 could allow an authenticated user to upload insecure files, due to insufficient file type distinction.

Dec 3, 2024
CVE-2024-41777
7.5 HIGH

IBM Cognos Controller 11.0.0 and 11.0.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound …

Dec 3, 2024
CVE-2024-41776
6.5 MEDIUM

IBM Cognos Controller 11.0.0 and 11.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from …

Dec 3, 2024
CVE-2024-41775
5.9 MEDIUM

IBM Cognos Controller 11.0.0 and 11.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

Dec 3, 2024
CVE-2024-25020
5.5 MEDIUM

IBM Cognos Controller 11.0.0 and 11.0.1 is vulnerable to malicious file upload by allowing unrestricted filetype attachments in the Journal entry page. Attackers can make …

Dec 3, 2024
CVE-2023-7255

Rejected reason: Assigned as duplicate and no longer used.

Dec 3, 2024
CVE-2024-53867
4.3 MEDIUM

Synapse is an open-source Matrix homeserver. The Sliding Sync feature on Synapse versions between 1.113.0rc1 and 1.120.0 can leak partial room state changes to users …

Dec 3, 2024
CVE-2024-53863
9.1 CRITICAL

Synapse is an open-source Matrix homeserver. In Synapse versions before 1.120.1, enabling the dynamic_thumbnails option or processing a specially crafted request could trigger the decoding …

Dec 3, 2024
CVE-2024-52815
5.3 MEDIUM

Synapse is an open-source Matrix homeserver. Synapse versions before 1.120.1 fail to properly validate invites received over federation. This vulnerability allows a malicious server to …

Dec 3, 2024
CVE-2024-52805
7.5 HIGH

Synapse is an open-source Matrix homeserver. In Synapse before 1.120.1, multipart/form-data requests can in certain configurations transiently increase memory consumption beyond expected levels while processing …

Dec 3, 2024
CVE-2024-40691
8.0 HIGH

IBM Cognos Controller 11.0.0 and 11.0.1 could be vulnerable to malicious file upload by not validating the content of the file uploaded to the web …

Dec 3, 2024
CVE-2024-37303
5.3 MEDIUM

Synapse is an open-source Matrix homeserver. Synapse before version 1.106 allows, by design, unauthenticated remote participants to trigger a download and caching of remote media …

Dec 3, 2024
CVE-2024-37302
7.5 HIGH

Synapse is an open-source Matrix homeserver. Synapse versions before 1.106 are vulnerable to a disk fill attack, where an unauthenticated adversary can induce Synapse to …

Dec 3, 2024
CVE-2024-29404
7.8 HIGH

An issue in Razer Synapse 3 v.3.9.131.20813 and Synapse 3 App v.20240213 allows a local attacker to execute arbitrary code via the export parameter of …

Dec 3, 2024
CVE-2024-25036
4.3 MEDIUM

IBM Cognos Controller 11.0.0 and 11.0.1 could allow an authenticated user with local access to bypass security allowing users to circumvent restrictions imposed on input …

Dec 3, 2024
CVE-2024-25035
5.3 MEDIUM

IBM Cognos Controller 11.0.0 and 11.0.1 exposes server details that could allow an attacker to obtain information of the application environment to conduct further attacks.

Dec 3, 2024
CVE-2024-25019
5.5 MEDIUM

IBM Cognos Controller 11.0.0 and 11.0.1 could be vulnerable to malicious file upload by not validating the type of file uploaded to Journal entry attachments. …

Dec 3, 2024
CVE-2021-29892
5.9 MEDIUM

IBM Cognos Controller 11.0.0 and 11.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport …

Dec 3, 2024
CVE-2024-54000
7.5 HIGH

Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. In versions prior to 3.9.7, …

Dec 3, 2024
CVE-2024-53999
8.1 HIGH

Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. The application allows users to …

Dec 3, 2024
CVE-2024-53257
4.9 MEDIUM

Vitess is a database clustering system for horizontal scaling of MySQL. The /debug/querylogz and /debug/env pages for vtgate and vttablet do not properly escape user …

Dec 3, 2024
CVE-2024-11391
7.5 HIGH

The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the 'class_fma_connector.php' file in all …

Dec 3, 2024
CVE-2024-11200
6.1 MEDIUM

The Goodlayers Core plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘font-family’ parameter in all versions up to, and including, 2.0.7 due …

Dec 3, 2024
CVE-2024-9978
5.5 MEDIUM

in OpenHarmony v4.1.1 and prior versions allow a local attacker cause information leak through out-of-bounds Read.

Dec 3, 2024
CVE-2024-42422
8.3 HIGH

Dell NetWorker, version(s) 19.10, contain(s) an Authorization Bypass Through User-Controlled Key vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to …

Dec 3, 2024
CVE-2024-12082
5.5 MEDIUM

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.

Dec 3, 2024
CVE-2024-10074
8.8 HIGH

in OpenHarmony v4.1.1 and prior versions allow a local attacker cause the common permission is upgraded to root through use after free.

Dec 3, 2024
CVE-2024-11326
6.1 MEDIUM

The Campaign Monitor Forms by Optin Cat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping …

Dec 3, 2024
CVE-2024-47476
7.8 HIGH

Dell NetWorker Management Console, version(s) 19.11, contain(s) an Improper Verification of Cryptographic Signature vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, …

Dec 3, 2024
CVE-2024-45106
8.1 HIGH

Improper authentication of an HTTP endpoint in the S3 Gateway of Apache Ozone 1.4.0 allows any authenticated Kerberos user to revoke and regenerate the S3 …

Dec 3, 2024
CVE-2024-12062
4.3 MEDIUM

The Charity Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.3.3 via the 'nacharity_elementor_template' shortcode …

Dec 3, 2024
CVE-2024-11782
6.4 MEDIUM

The WP Mailster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mst_subscribe' shortcode in all versions up to, and including, 1.8.17.0 …

Dec 3, 2024
CVE-2024-11325
5.2 MEDIUM

The AWeber Forms by Optin Cat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on …

Dec 3, 2024
CVE-2024-11866
6.4 MEDIUM

The BMLT Tabbed Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bmlt_tabbed_map' shortcode in all versions up to, and including, …

Dec 3, 2024
CVE-2024-11844
4.3 MEDIUM

The IdeaPush plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the idea_push_taxonomy_save_routine function in all versions …

Dec 3, 2024
CVE-2024-11898
6.4 MEDIUM

The Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more plugin for WordPress is vulnerable to Stored Cross-Site …

Dec 3, 2024
CVE-2024-11853
6.4 MEDIUM

The jAlbum Bridge plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ar’ parameter in all versions up to, and including, 2.0.16 due …

Dec 3, 2024
CVE-2024-11805
6.1 MEDIUM

The Quick License Manager – WooCommerce Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'submit_qlm_products' parameter in all versions up to, …

Dec 3, 2024
CVE-2024-11732
6.5 MEDIUM

The BP Profile Shortcodes Extra plugin for WordPress is vulnerable to time-based SQL Injection via the ‘tab’ parameter in all versions up to, and including, …

Dec 3, 2024
CVE-2024-11707
6.1 MEDIUM

The My auctions allegro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 3.6.17 …

Dec 3, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.