CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-53673
8.1 HIGH

A java deserialization vulnerability in HPE Remote Insight Support may allow an unauthenticated attacker to execute code.

Nov 26, 2024
CVE-2024-11622
7.3 HIGH

An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.

Nov 26, 2024
CVE-2024-50942
9.8 CRITICAL

qiwen-file v1.4.0 was discovered to contain a SQL injection vulnerability via the component /mapper/NoticeMapper.xml.

Nov 26, 2024
CVE-2024-43784
5.7 MEDIUM

lakeFS is an open-source tool that transforms object storage into a Git-like repository. Existing lakeFS users who have issued credentials to users who have been …

Nov 26, 2024
CVE-2024-11745
8.8 HIGH

A vulnerability was found in Tenda AC8 16.03.34.09 and classified as critical. Affected by this issue is the function route_static_check of the file /goform/SetStaticRouteCfg. The …

Nov 26, 2024
CVE-2024-11744
7.3 HIGH

A vulnerability has been found in 1000 Projects Portfolio Management System MCA 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality …

Nov 26, 2024
CVE-2024-8676
7.4 HIGH

A vulnerability was found in CRI-O, where it can be requested to take a checkpoint archive of a container and later be asked to restore …

Nov 26, 2024
CVE-2024-49053
7.6 HIGH

Microsoft Dynamics 365 Sales Spoofing Vulnerability

Nov 26, 2024
CVE-2024-49052
8.2 HIGH

Missing authentication for critical function in Microsoft Azure PolicyWatch allows an unauthorized attacker to elevate privileges over a network.

Nov 26, 2024
CVE-2024-49038
9.3 CRITICAL

Improper neutralization of input during web page generation ('Cross-site Scripting') in Copilot Studio by an unauthorized attacker leads to elevation of privilege over a network.

Nov 26, 2024
CVE-2024-49035
8.7 HIGH KEV

An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network.

Nov 26, 2024
CVE-2024-11743
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in SourceCodester Best House Rental Management System 1.0. Affected is an unknown function of the file …

Nov 26, 2024
CVE-2024-11742
3.5 LOW

A vulnerability, which was classified as problematic, has been found in SourceCodester Best House Rental Management System 1.0. This issue affects some unknown processing of …

Nov 26, 2024
CVE-2024-11145
9.8 CRITICAL

Valor Apps Easy Folder Listing Pro has a deserialization vulnerability that allows an unauthenticated, remote attacker to execute arbitrary code with the privileges of the …

Nov 26, 2024
CVE-2024-10240
5.3 MEDIUM

An issue has been discovered in GitLab EE affecting all versions starting from 17.3 before 17.3.7, all versions starting from 17.4 before 17.4.4, all versions …

Nov 26, 2024
CVE-2019-17082

Insufficiently Protected Credentials vulnerability in OpenText™ AccuRev allows Authentication Bypass. When installed on a Linux or Solaris system the vulnerability could allow anyone who knows …

Nov 26, 2024
CVE-2024-8237
6.5 MEDIUM

A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions prior to 12.6 prior to 17.4.5, 17.5 prior to 17.5.3, …

Nov 26, 2024
CVE-2024-8177
5.3 MEDIUM

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.4.5, starting from 17.5 prior to 17.5.3, starting from 17.6 …

Nov 26, 2024
CVE-2024-8114
8.2 HIGH

An issue has been discovered in GitLab CE/EE affecting all versions from 8.12 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. This issue allows …

Nov 26, 2024
CVE-2024-53844
6.3 MEDIUM

E.D.D.I (Enhanced Dialog Driven Interface) is a middleware to connect and manage LLM API bots. A path traversal vulnerability exists in the backup export functionality …

Nov 26, 2024
CVE-2024-53620
4.8 MEDIUM

A cross-site scripting (XSS) vulnerability in the Article module of SPIP v4.3.3 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a …

Nov 26, 2024
CVE-2024-53619
6.3 MEDIUM

An authenticated arbitrary file upload vulnerability in the Documents module of SPIP v4.3.3 allows attackers to execute arbitrary code via uploading a crafted PDF file.

Nov 26, 2024
CVE-2024-53267
5.5 MEDIUM

sigstore-java is a sigstore java client for interacting with sigstore infrastructure. sigstore-java has insufficient verification for a situation where a validly-signed but "mismatched" bundle is …

Nov 26, 2024
CVE-2024-52008
8.8 HIGH

Fides is an open-source privacy engineering platform. The user invite acceptance API endpoint lacks server-side password policy enforcement, allowing users to set arbitrarily weak passwords …

Nov 26, 2024
CVE-2024-32965
8.1 HIGH

Lobe Chat is an open-source, AI chat framework. Versions of lobe-chat prior to 1.19.13 have an unauthorized ssrf vulnerability. An attacker can construct malicious requests …

Nov 26, 2024
CVE-2024-11828
4.3 MEDIUM

A denial of service (DoS) condition was discovered in GitLab CE/EE affecting all versions from 13.2.4 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. …

Nov 26, 2024
CVE-2024-11669
6.5 MEDIUM

An issue was discovered in GitLab CE/EE affecting all versions from 16.9.8 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. Certain API endpoints could …

Nov 26, 2024
CVE-2024-11668
4.2 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. Long-lived connections could …

Nov 26, 2024
CVE-2024-51058
6.2 MEDIUM

Local File Inclusion (LFI) vulnerability has been discovered in TCPDF 6.7.5. This vulnerability enables a user to read arbitrary files from the server's file system …

Nov 26, 2024
CVE-2024-10878
6.1 MEDIUM

The Sugar Calendar – Simple Event Management plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without …

Nov 26, 2024
CVE-2024-53555
8.8 HIGH

A CSV injection vulnerability in Taiga v6.8.1 allows attackers to execute arbitrary code via uploading a crafted CSV file.

Nov 26, 2024
CVE-2024-53365
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability was identified in PHPGURUKUL Vehicle Parking Management System v1.13 in /users/profile.php. This vulnerability allows authenticated users to inject malicious …

Nov 26, 2024
CVE-2024-11407
7.5 HIGH

There exists a denial of service through Data corruption in gRPC-C++ - gRPC-C++ servers with transmit zero copy enabled through the channel arg GRPC_ARG_TCP_TX_ZEROCOPY_ENABLED can …

Nov 26, 2024
CVE-2024-11177

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Nov 26, 2024
CVE-2024-52337
5.5 MEDIUM

A log spoofing flaw was found in the Tuned package due to improper sanitization of some API arguments. This flaw allows an attacker to pass …

Nov 26, 2024
CVE-2024-52336
7.8 HIGH

A script injection vulnerability was identified in the Tuned package. The `instance_create()` D-Bus function can be called by locally logged-in users without authentication. This flaw …

Nov 26, 2024
CVE-2024-36463
6.5 MEDIUM

The implementation of atob in "Zabbix JS" allows to create a string with arbitrary content and use it to access internal properties of objects.

Nov 26, 2024
CVE-2024-22117
2.2 LOW

When a URL is added to the map element, it is recorded in the database with sequential IDs. Upon adding a new URL, the system …

Nov 26, 2024
CVE-2024-9929
4.3 MEDIUM

A vulnerability exists in NSD570 that allows any authenticated user to access all device logs disclosing login information with timestamps.

Nov 26, 2024
CVE-2024-9928
5.3 MEDIUM

A vulnerability exists in NSD570 login panel that does not restrict excessive authentication attempts. If exploited, this could cause account takeover and unauthorized access to …

Nov 26, 2024
CVE-2024-9461
7.2 HIGH

The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Remote Code Execution in all versions …

Nov 26, 2024
CVE-2024-8236
6.4 MEDIUM

The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter of …

Nov 26, 2024
CVE-2024-53976
5.4 MEDIUM

Under certain circumstances, navigating to a webpage would result in the address missing from the location URL bar, making it unclear what the URL was …

Nov 26, 2024
CVE-2024-53975
5.4 MEDIUM

Accessing a non-secure HTTP site that uses a non-existent port may cause the SSL padlock icon in the location URL bar to, misleadingly, appear secure. …

Nov 26, 2024
CVE-2024-11708
6.5 MEDIUM

Missing thread synchronization primitives could have led to a data race on members of the PlaybackParams structure. This vulnerability affects Firefox < 133 and Thunderbird …

Nov 26, 2024
CVE-2024-11706
6.5 MEDIUM

A null pointer dereference may have inadvertently occurred in `pk12util`, and specifically in the `SEC_ASN1DecodeItem_Util` function, when handling malformed or improperly formatted input files. This …

Nov 26, 2024
CVE-2024-11705
9.1 CRITICAL

`NSC_DeriveKey` inadvertently assumed that the `phKey` parameter is always non-NULL. When it was passed as NULL, a segmentation fault (SEGV) occurred, leading to crashes. This …

Nov 26, 2024
CVE-2024-11704
9.8 CRITICAL

A double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` when handling an error path. Under specific conditions, the same symmetric key could have been freed twice, …

Nov 26, 2024
CVE-2024-11703
5.7 MEDIUM

On Android, Firefox may have inadvertently allowed viewing saved passwords without the required device PIN authentication. This vulnerability affects Firefox < 133.

Nov 26, 2024
CVE-2024-11702
7.5 HIGH

Copying sensitive information from Private Browsing tabs on Android, such as passwords, may have inadvertently stored data in the cloud-based clipboard history if enabled. This …

Nov 26, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.