CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-11918
4.3 MEDIUM

The Image Alt Text plugin for WordPress is vulnerable to unauthorized modification of data| due to a missing capability check on the iat_add_alt_txt_action and iat_update_alt_txt_action …

Nov 28, 2024
CVE-2024-10896
5.4 MEDIUM

The Logo Slider WordPress plugin before 4.5.0 does not sanitise and escape some of its Logo and Slider settings, which could allow high privilege users …

Nov 28, 2024
CVE-2024-10510
4.8 MEDIUM

The adBuddy+ (AdBlocker Detection) by NetfunkDesign WordPress plugin through 1.1.3 does not sanitise and escape some of its settings, which could allow high privilege users …

Nov 28, 2024
CVE-2024-10493
5.4 MEDIUM

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) WordPress plugin before 5.10.3 does not validate and escape some …

Nov 28, 2024
CVE-2024-10473
5.4 MEDIUM

The Logo Slider WordPress plugin before 4.5.0 does not sanitise and escape some of its Logo Settings when outputing them in pages where the Logo …

Nov 28, 2024
CVE-2024-46939

The game extension engine of versions 1.2.7.0 and earlier exposes some components, and attackers can construct parameters to perform path traversal attacks, which can overwrite …

Nov 28, 2024
CVE-2024-53008
5.3 MEDIUM

Inconsistent interpretation of HTTP requests ('HTTP Request/Response Smuggling') issue exists in HAProxy. If this vulnerability is exploited, a remote attacker may access a path that …

Nov 28, 2024
CVE-2024-38658
7.8 HIGH

There is an Out-of-bounds read vulnerability in V-Server (v4.0.19.0 and earlier) and V-Server Lite (v4.0.19.0 and earlier). If a user opens a specially crafted file, …

Nov 28, 2024
CVE-2024-38389
7.8 HIGH

There is an Out-of-bounds read vulnerability in TELLUS (v4.0.19.0 and earlier) and TELLUS Lite (v4.0.19.0 and earlier). If a user opens a specially crafted file, …

Nov 28, 2024
CVE-2024-38309
7.8 HIGH

There are multiple stack-based buffer overflow vulnerabilities in V-SFT (v6.2.2.0 and earlier), TELLUS (v4.0.19.0 and earlier), and TELLUS Lite (v4.0.19.0 and earlier). If a user …

Nov 28, 2024
CVE-2018-9377
5.5 MEDIUM

In getIntentForIntentSender of ActivityManagerService.java, there is a possible way to access user metadata due to a pending intent. This could lead to local escalation of …

Nov 28, 2024
CVE-2024-11933
7.8 HIGH

Fuji Electric Monitouch V-SFT X1 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected …

Nov 28, 2024
CVE-2024-11803
7.8 HIGH

Fuji Electric Tellus Lite V-Simulator 5 V8 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on …

Nov 28, 2024
CVE-2024-11802
7.8 HIGH

Fuji Electric Tellus Lite V-Simulator 5 V8 File Parsing Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code …

Nov 28, 2024
CVE-2024-11801
7.8 HIGH

Fuji Electric Tellus Lite V-Simulator 5 V8 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on …

Nov 28, 2024
CVE-2024-11800
7.8 HIGH

Fuji Electric Tellus Lite V-Simulator 5 V8 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code …

Nov 28, 2024
CVE-2024-11799
7.8 HIGH

Fuji Electric Tellus Lite V-Simulator 5 V8 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code …

Nov 28, 2024
CVE-2024-11798
7.8 HIGH

Fuji Electric Monitouch V-SFT X1 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations …

Nov 28, 2024
CVE-2024-11797
7.8 HIGH

Fuji Electric Monitouch V-SFT V8 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations …

Nov 28, 2024
CVE-2024-11796
7.8 HIGH

Fuji Electric Monitouch V-SFT V9C File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations …

Nov 28, 2024
CVE-2024-11795
7.8 HIGH

Fuji Electric Monitouch V-SFT V8 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected …

Nov 28, 2024
CVE-2024-11794
7.8 HIGH

Fuji Electric Monitouch V-SFT V10 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations …

Nov 28, 2024
CVE-2024-11793
7.8 HIGH

Fuji Electric Monitouch V-SFT V9C File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations …

Nov 28, 2024
CVE-2024-11792
7.8 HIGH

Fuji Electric Monitouch V-SFT V8 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected …

Nov 28, 2024
CVE-2024-11791
7.8 HIGH

Fuji Electric Monitouch V-SFT V8C File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected …

Nov 28, 2024
CVE-2024-11790
7.8 HIGH

Fuji Electric Monitouch V-SFT V10 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected …

Nov 28, 2024
CVE-2024-11789
7.8 HIGH

Fuji Electric Monitouch V-SFT V10 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected …

Nov 28, 2024
CVE-2024-11787
7.8 HIGH

Fuji Electric Monitouch V-SFT V10 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected …

Nov 28, 2024
CVE-2018-9374
7.8 HIGH

In installPackageLI of PackageManagerService.java, there is a possible permissions bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction …

Nov 28, 2024
CVE-2018-9354
6.5 MEDIUM

In VideoFrameScheduler.cpp of VideoFrameScheduler::PLL::fit, there is a possible remote denial of service due to divide by 0. This could lead to remote denial of service …

Nov 27, 2024
CVE-2018-9353
6.5 MEDIUM

In ihevcd_parse_slice_data of ihevcd_parse_slice.c there is a possible heap buffer out of bound read due to a missing bounds check. This could lead to remote …

Nov 27, 2024
CVE-2018-9352
6.5 MEDIUM

In ihevcd_allocate_dynamic_bufs of ihevcd_api.c there is a possible resource exhaustion due to integer overflow. This could lead to remote denial of service with no additional …

Nov 27, 2024
CVE-2018-9351
6.5 MEDIUM

In ih264e_fmt_conv_420p_to_420sp of ih264e_fmt_conv.c there is a possible out of bound read due to missing bounds check. This could lead to remote denial of service …

Nov 27, 2024
CVE-2024-53860
8.6 HIGH

sp-php-email-handler is a PHP package for handling contact form submissions. Messages sent using this script are vulnerable to abuse, as the script allows anybody to …

Nov 27, 2024
CVE-2024-53859
6.5 MEDIUM

go-gh is a Go module for interacting with the `gh` utility and the GitHub API from the command line. A security vulnerability has been identified …

Nov 27, 2024
CVE-2024-53858
6.5 MEDIUM

The gh cli is GitHub’s official command line tool. A security vulnerability has been identified in the GitHub CLI that could leak authentication tokens when …

Nov 27, 2024
CVE-2024-53260
6.8 MEDIUM

Autolab is a course management service that enables auto-graded programming assignments. A user can modify their first and or last name to include a valid …

Nov 27, 2024
CVE-2018-9350
6.5 MEDIUM

In ih264d_assign_pic_num of ih264d_utils.c there is a possible out of bound read due to missing bounds check. This could lead to a denial of service …

Nov 27, 2024
CVE-2018-9349
6.5 MEDIUM

In mv_err_cost of mcomp.c there is a possible out of bounds read due to missing bounds check. This could lead to denial of service with …

Nov 27, 2024
CVE-2017-13323
7.8 HIGH

In String16 of String16.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege …

Nov 27, 2024
CVE-2017-13321
5.5 MEDIUM

In SensorService::isDataInjectionEnabled of frameworks/native/services/sensorservice/SensorService.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure …

Nov 27, 2024
CVE-2017-13320
6.5 MEDIUM

In impeg2d_bit_stream_flush() of libmpeg2dec there is a possible OOB read due to a missing bounds check. This could lead to Remote DoS with no additional …

Nov 27, 2024
CVE-2017-13319
7.5 HIGH

In pvmp3_get_main_data_size of pvmp3_get_main_data_size.cpp, there is a possible buffer overread due to a missing bounds check. This could lead to remote information disclosure of global …

Nov 27, 2024
CVE-2017-13316
7.8 HIGH

In checkPermissions of RecognitionService.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege with …

Nov 27, 2024
CVE-2024-53855
1.9 LOW

Centurion ERP (Enterprise Rescource Planning) is a simple application developed to provide open source IT management with a large emphasis on the IT Service Management …

Nov 27, 2024
CVE-2024-53264

bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). A open redirect vulnerability exists in the loading endpoint, allowing attackers to redirect authenticated users …

Nov 27, 2024
CVE-2024-47181
7.5 HIGH

Contiki-NG is an open-source, cross-platform operating system for IoT devices. An unaligned memory access can be triggered in the two RPL implementations of the Contiki-NG …

Nov 27, 2024
CVE-2024-41126
8.3 HIGH

Contiki-NG is an open-source, cross-platform operating system for IoT devices. An out-of-bounds read of 1 byte can be triggered when sending a packet to a …

Nov 27, 2024
CVE-2024-41125
8.3 HIGH

Contiki-NG is an open-source, cross-platform operating system for IoT devices. An out-of-bounds read of 1 byte can be triggered when sending a packet to a …

Nov 27, 2024
CVE-2023-29001
7.5 HIGH

Contiki-NG is an open-source, cross-platform operating system for IoT devices. The Contiki-NG operating system processes source routing headers (SRH) in its two alternative RPL protocol …

Nov 27, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.