CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-12002
4.3 MEDIUM

A vulnerability classified as problematic was found in Tenda FH451, FH1201, FH1202 and FH1206 up to 20241129. Affected by this vulnerability is the function websReadEvent …

Nov 30, 2024
CVE-2024-12001
3.5 LOW

A vulnerability classified as problematic has been found in code-projects Wazifa System 1.0. Affected is an unknown function of the file /controllers/updatesettings.php of the component …

Nov 30, 2024
CVE-2024-12000
3.5 LOW

A vulnerability was found in code-projects Blood Bank System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file …

Nov 30, 2024
CVE-2024-11998
6.3 MEDIUM

A vulnerability was found in code-projects Farmacia 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /visualizer-forneccedor.chp. The manipulation …

Nov 30, 2024
CVE-2024-11997
3.5 LOW

A vulnerability was found in code-projects Farmacia 1.0. It has been classified as problematic. This affects an unknown part of the file /vendas.php. The manipulation …

Nov 30, 2024
CVE-2024-11996
3.5 LOW

A vulnerability was found in code-projects Farmacia 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /editar-fornecedor.php. The …

Nov 30, 2024
CVE-2024-11252
6.1 MEDIUM

The Social Sharing Plugin – Sassy Social Share plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the heateor_mastodon_share parameter in all versions up …

Nov 30, 2024
CVE-2024-43703
8.1 HIGH

Software installed and run as a non-privileged user may conduct improper GPU system calls to achieve unauthorised reads and writes of physical memory from the …

Nov 30, 2024
CVE-2024-43702
8.1 HIGH

Software installed and run as a non-privileged user may conduct improper GPU system calls to allow unprivileged access to arbitrary physical memory page.

Nov 30, 2024
CVE-2024-53623
7.5 HIGH

Incorrect access control in the component l_0_0.xml of TP-Link ARCHER-C7 v5 allows attackers to access sensitive information.

Nov 29, 2024
CVE-2024-54159
4.1 MEDIUM

stalld through 1.19.7 allows local users to cause a denial of service (file overwrite) via a /tmp/rtthrottle symlink attack.

Nov 29, 2024
CVE-2024-11995
3.5 LOW

A vulnerability has been found in code-projects Farmacia 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /pagamento.php. …

Nov 29, 2024
CVE-2024-53507
9.8 CRITICAL

A SQL injection vulnerability was discovered in Siyuan 3.1.11 in /getHistoryItems.

Nov 29, 2024
CVE-2024-53506
9.8 CRITICAL

A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the ids array parameter in /batchGetBlockAttrs.

Nov 29, 2024
CVE-2024-53505
9.8 CRITICAL

A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the id parameter at /getAssetContent.

Nov 29, 2024
CVE-2024-53504
9.8 CRITICAL

A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the notebook parameter in /searchHistory.

Nov 29, 2024
CVE-2024-36612
7.5 HIGH

Zulip from 8.0 to 8.3 contains a memory leak vulnerability in the handling of popovers.

Nov 29, 2024
CVE-2024-36610

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been …

Nov 29, 2024
CVE-2024-35371
7.5 HIGH

Ant-Media-Serverv2.8.2 is affected by Improper Output Neutralization for Logs. The vulnerability stems from insufficient input sanitization in the logging mechanism. Without proper filtering or validation, …

Nov 29, 2024
CVE-2024-35368
9.8 CRITICAL

FFmpeg n7.0 is affected by a Double Free via the rkmpp_retrieve_frame function within libavcodec/rkmppdec.c.

Nov 29, 2024
CVE-2024-35367
9.1 CRITICAL

FFmpeg n6.1.1 has an Out-of-bounds Read via libavcodec/ppc/vp8dsp_altivec.c, static const vec_s8 h_subpel_filters_outer

Nov 29, 2024
CVE-2024-35366
9.1 CRITICAL

FFmpeg n6.1.1 is Integer Overflow. The vulnerability exists in the parse_options function of sbgdec.c within the libavformat module. When parsing certain options, the software does …

Nov 29, 2024
CVE-2024-53983
5.4 MEDIUM

The Backstage Scaffolder plugin Houses types and utilities for building scaffolder-related modules. A vulnerability is identified in Backstage Scaffolder template functionality where Server-Side Template Injection …

Nov 29, 2024
CVE-2024-53980
7.5 HIGH

RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) devices and other embedded devices. A malicious actor …

Nov 29, 2024
CVE-2024-53979
8.2 HIGH

ibm.ibm_zhmc is an Ansible collection for the IBM Z HMC. The Ansible collection "ibm.ibm_zhmc" writes password-like properties in clear text into its log file and …

Nov 29, 2024
CVE-2024-53865
8.2 HIGH

zhmcclient is a pure Python client library for the IBM Z HMC Web Services API. In affected versions the Python package "zhmcclient" writes password-like properties …

Nov 29, 2024
CVE-2024-53864

Ibexa Admin UI Bundle is all the necessary parts to run the Ibexa DXP Back Office interface. The Content name pattern is used to build …

Nov 29, 2024
CVE-2024-53861
2.2 LOW

pyjwt is a JSON Web Token implementation in Python. An incorrect string comparison is run for `iss` checking, resulting in `"acb"` being accepted for `"_abc_"`. …

Nov 29, 2024
CVE-2024-53848
7.1 HIGH

check-jsonschema is a CLI and set of pre-commit hooks for jsonschema validation. The default cache strategy uses the basename of a remote schema as the …

Nov 29, 2024
CVE-2024-52810

@intlify/shared is a shared library for the intlify project. The latest version of @intlify/shared (10.0.4) is vulnerable to Prototype Pollution through the entry function(s) lib.deepCopy. …

Nov 29, 2024
CVE-2024-52809

vue-i18n is an internationalization plugin for Vue.js. In affected versions vue-i18n can be passed locale messages to `createI18n` or `useI18n`. When locale message ASTs are …

Nov 29, 2024
CVE-2024-52801

sftpgo is a full-featured and highly configurable event-driven file transfer solution. Server protocols: SFTP, HTTP/S, FTP/S, WebDAV. The OpenID Connect implementation allows authenticated users to …

Nov 29, 2024
CVE-2024-52800

veraPDF is an open source PDF/A validation library. Executing policy checks using custom schematron files via the CLI invokes an XSL transformation that may theoretically …

Nov 29, 2024
CVE-2024-52003
6.1 MEDIUM

Traefik (pronounced traffic) is an HTTP reverse proxy and load balancer. There is a vulnerability in Traefik that allows the client to provide the X-Forwarded-Prefix …

Nov 29, 2024
CVE-2024-36616
6.5 MEDIUM

An integer overflow in the component /libavformat/westwood_vqa.c of FFmpeg n6.1.1 allows attackers to cause a denial of service in the application via a crafted VQA …

Nov 29, 2024
CVE-2024-36615
5.9 MEDIUM

FFmpeg n7.0 has a race condition vulnerability in the VP9 decoder. This could lead to a data race if video encoding parameters were being exported, …

Nov 29, 2024
CVE-2024-36611
7.5 HIGH

In Symfony v7.07, a security vulnerability was identified in the FormLoginAuthenticator component, where it failed to adequately handle cases where the username or password field …

Nov 29, 2024
CVE-2024-49360
9.2 CRITICAL

Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. An authenticated user (**UserA**) with no privileges is authorized to read …

Nov 29, 2024
CVE-2024-36624
5.4 MEDIUM

Zulip 8.3 is vulnerable to Cross Site Scripting (XSS) via the construct_copy_div function in copy_and_paste.js.

Nov 29, 2024
CVE-2024-36623
8.1 HIGH

moby through v25.0.3 has a Race Condition vulnerability in the streamformatter package which can be used to trigger multiple concurrent write operations resulting in data …

Nov 29, 2024
CVE-2024-36622
9.8 CRITICAL

In RaspAP raspap-webgui 3.0.9 and earlier, a command injection vulnerability exists in the clearlog.php script. The vulnerability is due to improper sanitization of user input …

Nov 29, 2024
CVE-2024-36621
6.5 MEDIUM

moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go. The vulnerability could be used to trigger concurrent builds that call the EnsureLayer function resulting …

Nov 29, 2024
CVE-2024-36620
6.5 MEDIUM

moby v25.0.0 - v26.0.2 is vulnerable to NULL Pointer Dereference via daemon/images/image_history.go.

Nov 29, 2024
CVE-2024-36618
6.2 MEDIUM

FFmpeg n6.1.1 has a vulnerability in the AVI demuxer of the libavformat library which allows for an integer overflow, potentially resulting in a denial-of-service (DoS) …

Nov 29, 2024
CVE-2024-36617
6.2 MEDIUM

FFmpeg n6.1.1 has an integer overflow vulnerability in the FFmpeg CAF decoder.

Nov 29, 2024
CVE-2024-49806
9.4 CRITICAL

IBM Security Verify Access Appliance 10.0.0 through 10.0.8 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound …

Nov 29, 2024
CVE-2024-49805
9.4 CRITICAL

IBM Security Verify Access Appliance 10.0.0 through 10.0.8 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound …

Nov 29, 2024
CVE-2024-49804
7.8 HIGH

IBM Security Verify Access Appliance 10.0.0 through 10.0.8 could allow a locally authenticated non-administrative user to escalate their privileges due to unnecessary permissions used to …

Nov 29, 2024
CVE-2024-49803
9.8 CRITICAL

IBM Security Verify Access Appliance 10.0.0 through 10.0.8 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially …

Nov 29, 2024
CVE-2024-47193
5.5 MEDIUM

WithSecure Elements Agent for Mac before 24.3, MDR before 24.3, and Elements Client Security for Mac before 16.10 allow a remote Denial of Service.

Nov 29, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.