CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-9369
9.6 CRITICAL

Insufficient data validation in Mojo in Google Chrome prior to 129.0.6668.89 allowed a remote attacker who had compromised the renderer process to perform an out …

Nov 27, 2024
CVE-2024-7025
8.8 HIGH

Integer overflow in Layout in Google Chrome prior to 129.0.6668.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Nov 27, 2024
CVE-2024-53254

Rejected reason: This CVE is a duplicate of another CVE.

Nov 27, 2024
CVE-2024-54004
4.3 MEDIUM

Jenkins Filesystem List Parameter Plugin 0.0.14 and earlier does not restrict the path used for the File system objects list Parameter, allowing attackers with Item/Configure …

Nov 27, 2024
CVE-2024-54003
8.0 HIGH

Jenkins Simple Queue Plugin 1.4.4 and earlier does not escape the view name, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with …

Nov 27, 2024
CVE-2024-51228
6.8 MEDIUM

An issue in TOTOLINK-CX-A3002RU V1.0.4-B20171106.1512 and TOTOLINK-CX-N150RT V2.1.6-B20171121.1002 and TOTOLINK-CX-N300RT V2.1.6-B20170724.1420 and TOTOLINK-CX-N300RT V2.1.8-B20171113.1408 and TOTOLINK-CX-N300RT V2.1.8-B20191010.1107 and TOTOLINK-CX-N302RE V2.0.2-B20170511.1523 allows a remote attacker to …

Nov 27, 2024
CVE-2024-37816
4.2 MEDIUM

Quectel EC25-EUX EC25EUXGAR08A05M1G was discovered to contain a stack overflow.

Nov 27, 2024
CVE-2024-31976
8.0 HIGH

EnGenius EWS356-FIR 1.1.30 and earlier devices allow a remote attacker to execute arbitrary OS commands via the Controller connectivity parameter.

Nov 27, 2024
CVE-2024-21703
6.4 MEDIUM

This Medium severity Security Misconfiguration vulnerability was introduced in version 8.8.1 of Confluence Data Center and Server for Windows installations. This Security Misconfiguration vulnerability, with …

Nov 27, 2024
CVE-2024-11860
6.5 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Best House Rental Management System 1.0. This affects an unknown part of the file /rental/ajax.php?action=delete_tenant …

Nov 27, 2024
CVE-2024-53920
7.8 HIGH

In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger …

Nov 27, 2024
CVE-2024-52951
8.0 HIGH

Stored Cross-Site Scripting in the Access Request History in Omada Identity before version 15 update 1 allows an authenticated attacker to execute arbitrary code in …

Nov 27, 2024
CVE-2024-46055
4.8 MEDIUM

OpenVidReview 1.0 is vulnerable to Cross Site Scripting (XSS) in review names.

Nov 27, 2024
CVE-2024-46054
9.8 CRITICAL

OpenVidReview 1.0 is vulnerable to Incorrect Access Control. The /upload route is accessible without authentication, allowing any user to upload files.

Nov 27, 2024
CVE-2024-11862

Non constant time cryptographic operation in Devolutions.XTS.NET 2024.11.19 and earlier allows an attacker to render half of the encryption key obsolete via a timing attacks

Nov 27, 2024
CVE-2024-53635
4.8 MEDIUM

A Reflected Cross Site Scripting (XSS) vulnerability was found in /covid-tms/patient-search-report.php in PHPGurukul COVID 19 Testing Management System v1.0, which allows remote attackers to execute …

Nov 27, 2024
CVE-2024-53604
9.8 CRITICAL

A SQL Injection vulnerability was found in /covid-tms/check_availability.php in PHPGurukul COVID 19 Testing Management System v1.0, which allows remote attackers to execute arbitrary code via …

Nov 27, 2024
CVE-2024-53603
7.3 HIGH

A SQL Injection vulnerability was found in /covid-tms/password-recovery.php in PHPGurukul COVID 19 Testing Management System v1.0, which allows remote attackers to execute arbitrary code via …

Nov 27, 2024
CVE-2024-36464
2.7 LOW

When exporting media types, the password is exported in the YAML in plain text. This appears to be a best practices type issue and may …

Nov 27, 2024
CVE-2024-42333
2.7 LOW

The researcher is showing that it is possible to leak a small amount of Zabbix Server memory using an out of bounds read in src/libs/zbxmedia/email.c

Nov 27, 2024
CVE-2024-42332
3.7 LOW

The researcher is showing that due to the way the SNMP trap log is parsed, an attacker can craft an SNMP trap with additional lines …

Nov 27, 2024
CVE-2024-42331
3.3 LOW

In the src/libs/zbxembed/browser.c file, the es_browser_ctor method retrieves a heap pointer from the Duktape JavaScript engine. This heap pointer is subsequently utilized by the browser_push_error …

Nov 27, 2024
CVE-2024-42330
9.1 CRITICAL

The HttpRequest object allows to get the HTTP headers from the server's response after sending the request. The problem is that the returned strings are …

Nov 27, 2024
CVE-2024-42329
3.3 LOW

The webdriver for the Browser object expects an error object to be initialized when the webdriver_session_query function fails. But this function can fail for various …

Nov 27, 2024
CVE-2024-42328
3.3 LOW

When the webdriver for the Browser object downloads data from a HTTP server, the data pointer is set to NULL and is allocated only in …

Nov 27, 2024
CVE-2024-42327
9.9 CRITICAL

A non-admin user account on the Zabbix frontend with the default User role, or with any other role that gives API access can exploit this …

Nov 27, 2024
CVE-2024-42326
4.4 MEDIUM

There was discovered a use after free bug in browser.c in the es_browser_get_variant function

Nov 27, 2024
CVE-2024-36468
3.0 LOW

The reported vulnerability is a stack buffer overflow in the zbx_snmp_cache_handle_engineid function within the Zabbix server/proxy code. This issue occurs when copying data from session->securityEngineID …

Nov 27, 2024
CVE-2024-11009
4.9 MEDIUM

The Internal Linking for SEO traffic & Ranking – Auto internal links (100% automatic) plugin for WordPress is vulnerable to time-based SQL Injection via the …

Nov 27, 2024
CVE-2024-11025
5.4 MEDIUM

An authenticated attacker with low privileges may use a SQL Injection vulnerability in the affected products administration panel to gain read and write access to …

Nov 27, 2024
CVE-2024-10521
4.3 MEDIUM

The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.2. This is …

Nov 27, 2024
CVE-2024-52323
8.1 HIGH

Zohocorp ManageEngine Analytics Plus versions below 6100 are vulnerable to authenticated sensitive data exposure which allows the users to retrieve sensitive tokens associated to the …

Nov 27, 2024
CVE-2024-11667
7.5 HIGH KEV

A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through …

Nov 27, 2024
CVE-2024-36467
7.5 HIGH

An authenticated user with API access (e.g.: user with default User role), more specifically a user with access to the user.update API endpoint is enough …

Nov 27, 2024
CVE-2024-10895
6.4 MEDIUM

The Counter Up – Animated Number Counter & Milestone Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'lgx-counter' shortcode in …

Nov 27, 2024
CVE-2024-10580
5.3 MEDIUM

The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized form submissions due to a missing capability check on …

Nov 27, 2024
CVE-2024-10175
6.4 MEDIUM

The Pricing Tables For WPBakery Page Builder (formerly Visual Composer) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wdo_pricing_tables shortcode in …

Nov 27, 2024
CVE-2024-52959
7.2 HIGH

A Improper Control of Generation of Code ('Code Injection') vulnerability in plugin management in iota C.ai Conversational Platform from 1.0.0 through 2.1.3 allows remote authenticated …

Nov 27, 2024
CVE-2024-52958
7.2 HIGH

A improper verification of cryptographic signature vulnerability in plugin management in iota C.ai Conversational Platform from 1.0.0 through 2.1.3 allows remote authenticated users to load …

Nov 27, 2024
CVE-2024-11219
5.3 MEDIUM

The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Path Traversal in all versions up …

Nov 27, 2024
CVE-2024-11083
5.3 MEDIUM

The ProfilePress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.15.18 via the WordPress core search feature. …

Nov 27, 2024
CVE-2024-5921
8.8 HIGH

An insufficient certification validation issue in the Palo Alto Networks GlobalProtect app enables attackers to connect the GlobalProtect app to arbitrary servers. This can enable …

Nov 27, 2024
CVE-2024-53676
9.8 CRITICAL

A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution.

Nov 27, 2024
CVE-2024-11820
3.5 LOW

A vulnerability, which was classified as problematic, has been found in code-projects Crud Operation System 1.0. This issue affects some unknown processing of the file …

Nov 27, 2024
CVE-2024-53849

editorconfig-core-c is theEditorConfig core library written in C (for use by plugins supporting EditorConfig parsing). In affected versions several overflows may occur in switch case …

Nov 27, 2024
CVE-2024-11819
7.3 HIGH

A vulnerability classified as critical was found in 1000 Projects Portfolio Management System MCA 1.0. This vulnerability affects unknown code of the file /forgot_password_process.php. The …

Nov 27, 2024
CVE-2024-11818
7.3 HIGH

A vulnerability classified as critical has been found in PHPGurukul User Registration & Login and User Management System 1.0. This affects an unknown part of …

Nov 27, 2024
CVE-2024-11817
7.3 HIGH

A vulnerability was found in PHPGurukul User Registration & Login and User Management System 1.0. It has been rated as critical. Affected by this issue …

Nov 26, 2024
CVE-2024-53675
7.3 HIGH

An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.

Nov 26, 2024
CVE-2024-53674
7.3 HIGH

An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.

Nov 26, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.