CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-49596
5.9 MEDIUM

Dell Wyse Management Suite, version WMS 4.4 and prior, contain a Missing Authorization vulnerability. A high privileged attacker with remote access could potentially exploit this …

Nov 26, 2024
CVE-2024-49595
7.6 HIGH

Dell Wyse Management Suite, version WMS 4.4 and before, contain an Authentication Bypass by Capture-replay vulnerability. A high privileged attacker with remote access could potentially …

Nov 26, 2024
CVE-2024-11678
3.5 LOW

A vulnerability was found in CodeAstro Hospital Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /backend/doc/his_doc_register_patient.php. …

Nov 26, 2024
CVE-2024-11677
3.5 LOW

A vulnerability was found in CodeAstro Hospital Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /backend/admin/his_admin_add_vendor.php …

Nov 26, 2024
CVE-2024-10729
8.8 HIGH

The Booking & Appointment Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …

Nov 26, 2024
CVE-2024-52899
8.5 HIGH

IBM Data Virtualization Manager for z/OS 1.1 and 1.2 could allow an authenticated user to inject malicious JDBC URL parameters and execute code on the …

Nov 26, 2024
CVE-2024-11676
3.5 LOW

A vulnerability was found in CodeAstro Hospital Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file …

Nov 26, 2024
CVE-2024-11675
3.5 LOW

A vulnerability has been found in CodeAstro Hospital Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the …

Nov 26, 2024
CVE-2024-53843
8.1 HIGH

@dapperduckling/keycloak-connector-server is an opinionated series of libraries for Node.js applications and frontend clients to interface with keycloak. A Reflected Cross-Site Scripting (XSS) vulnerability was discovered …

Nov 26, 2024
CVE-2024-11674
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in CodeAstro Hospital Management System 1.0. Affected is an unknown function of the file /backend/doc/his_doc_update-account.php. The …

Nov 26, 2024
CVE-2024-11673
4.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in 1000 Projects Bookstore Management System 1.0. This issue affects some unknown processing. The manipulation …

Nov 25, 2024
CVE-2024-53597
6.3 MEDIUM

masterstack_imgcap v0.0.1 was discovered to contain a SQL injection vulnerability via the endpoint /submit.

Nov 25, 2024
CVE-2024-53554
8.0 HIGH

A Client-Side Template Injection (CSTI) vulnerability in the component /project/new/scrum of Taiga v 8.6.1 allows remote attackers to execute arbitrary code by injecting a malicious …

Nov 25, 2024
CVE-2024-53102

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Nov 25, 2024
CVE-2024-53101
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fs: Fix uninitialized value issue in from_kuid and from_kgid ocfs2_setattr() uses attr->ia_mode, attr->ia_uid and attr->ia_gid …

Nov 25, 2024
CVE-2024-53100
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nvme: tcp: avoid race between queue_lock lock and destroy Commit 76d54bf20cdc ("nvme-tcp: don't access released …

Nov 25, 2024
CVE-2024-53099
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: bpf: Check validity of link->type in bpf_link_show_fdinfo() If a newly-added link type doesn't invoke BPF_LINK_TYPE(), …

Nov 25, 2024
CVE-2024-53098
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/xe/ufence: Prefetch ufence addr to catch bogus address access_ok() only checks for addr overflow so …

Nov 25, 2024
CVE-2024-53097
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm: krealloc: Fix MTE false alarm in __do_krealloc This patch addresses an issue introduced by …

Nov 25, 2024
CVE-2024-53096
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: mm: resolve faulty mmap_region() error path behaviour The mmap_region() function is somewhat terrifying, with spaghetti-like …

Nov 25, 2024
CVE-2024-53556
6.1 MEDIUM

An Open Redirect vulnerability in Taiga v6.8.1 allows attackers to redirect users to arbitrary websites via appending a crafted link to /login?next= in the login …

Nov 25, 2024
CVE-2024-50672
9.8 CRITICAL

A NoSQL injection vulnerability in Adapt Learning Adapt Authoring Tool <= 0.11.3 allows unauthenticated attackers to reset user and administrator account passwords via the "Reset …

Nov 25, 2024
CVE-2024-50671
4.3 MEDIUM

Incorrect access control in Adapt Learning Adapt Authoring Tool <= 0.11.3 allows attackers with Authenticated User roles to obtain email addresses via the "Get users" …

Nov 25, 2024
CVE-2024-53268
7.2 HIGH

Joplin is an open source, privacy-focused note taking app with sync capabilities for Windows, macOS, Linux, Android and iOS. In affected versions attackers are able …

Nov 25, 2024
CVE-2024-53262
5.4 MEDIUM

SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. The static error.html template for errors contains placeholders that are replaced without …

Nov 25, 2024
CVE-2024-53261
5.4 MEDIUM

SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. "Unsanitized input from *the request URL* flows into `end`, where it is …

Nov 25, 2024
CVE-2024-53258
5.3 MEDIUM

Autolab is a course management service that enables auto-graded programming assignments. From Autolab versions v.3.0.0 onward students can download all assignments from another student, as …

Nov 25, 2024
CVE-2024-53599
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability in the /scroll.php endpoint of LafeLabs Chaos v0.0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted …

Nov 25, 2024
CVE-2024-53255
5.4 MEDIUM

BoidCMS is a free and open-source flat file CMS for building simple websites and blogs, developed using PHP and uses JSON as a database. In …

Nov 25, 2024
CVE-2024-52811
8.2 HIGH

The ngtcp2 project is an effort to implement IETF QUIC protocol in C. In affected versions acks are not validated before being written to the …

Nov 25, 2024
CVE-2024-52529
5.8 MEDIUM

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. For users with the following configuration: 1. An allow policy that selects a …

Nov 25, 2024
CVE-2024-51723
4.6 MEDIUM

A Stored Cross-Site Scripting (XSS) vulnerability in the Management Console of BlackBerry AtHoc version 7.15 could allow an attacker to potentially execute actions in the …

Nov 25, 2024
CVE-2024-32468
5.4 MEDIUM

Deno is a runtime for JavaScript and TypeScript written in rust. Several cross-site scripting vulnerabilities existed in the `deno_doc` crate which lead to Self-XSS with …

Nov 25, 2024
CVE-2024-8272
7.8 HIGH

The com.uaudio.bsd.helper service, responsible for handling privileged operations, fails to implement critical client validation during XPC inter-process communication (IPC). Specifically, the service does not verify …

Nov 25, 2024
CVE-2024-7915
7.8 HIGH

The application Sensei Mac Cleaner contains a local privilege escalation vulnerability, allowing an attacker to perform multiple operations as the root user. These operations include …

Nov 25, 2024
CVE-2024-52787
9.1 CRITICAL

An issue in the upload_documents method of libre-chat v0.0.6 allows attackers to execute a path traversal via supplying a crafted filename in an uploaded file.

Nov 25, 2024
CVE-2024-45756
7.2 HIGH

An issue was discovered in Centreon centreon-open-tickets 24.10.x before 24.10.0, 24.04.x before 24.04.2, 23.10.x before 23.10.1, 23.04.x before 23.04.3, and 22.10.x before 22.10.2. SQL injection …

Nov 25, 2024
CVE-2024-45755
7.2 HIGH

An issue was discovered in Centreon centreon-dsm-server 24.10.x before 24.10.0, 24.04.x before 24.04.3, 23.10.x before 23.10.1, 23.04.x before 23.04.3, and 22.10.x before 22.10.2. SQL injection …

Nov 25, 2024
CVE-2023-45181
6.1 MEDIUM

IBM Jazz Foundation 7.0.2 and below are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus …

Nov 25, 2024
CVE-2023-26280
5.3 MEDIUM

IBM Jazz Foundation 7.0.2 and 7.0.3 could allow a user to change their dashboard using a specially crafted HTTP request due to improper access control.

Nov 25, 2024
CVE-2024-11672
4.3 MEDIUM

Incorrect authorization in the add permission component in Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows an authenticated malicious user to bypass the …

Nov 25, 2024
CVE-2024-11671
5.4 MEDIUM

Improper authentication in SQL data source MFA validation in Devolutions Remote Desktop Manager 2024.3.17 and earlier on Windows allows an authenticated user to bypass the …

Nov 25, 2024
CVE-2024-11670
5.4 MEDIUM

Incorrect authorization in the permission validation component of Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows a malicious authenticated user to bypass the …

Nov 25, 2024
CVE-2024-27134
7.0 HIGH

Excessive directory permissions in MLflow leads to local privilege escalation when using spark_udf. This behavior can be exploited by a local attacker to gain elevated …

Nov 25, 2024
CVE-2024-11498
7.5 HIGH

There exists a stack buffer overflow in libjxl. A specifically-crafted file can cause the JPEG XL decoder to use large amounts of stack space (up …

Nov 25, 2024
CVE-2024-11403
9.8 CRITICAL

There exists an out of bounds read/write in LibJXL versions prior to commit 9cc451b91b74ba470fd72bd48c121e9f33d24c99. The JPEG decoder used by the JPEG XL encoder when doing …

Nov 25, 2024
CVE-2020-12492

Improper handling of WiFi information by framework services can allow certain malicious applications to obtain sensitive information.

Nov 25, 2024
CVE-2020-12491

Improper control of framework service permissions with possibility of some sensitive device information leakage.

Nov 25, 2024
CVE-2024-11664
8.8 HIGH

A vulnerability, which was classified as critical, has been found in eNMS up to 4.2. Affected by this issue is the function multiselect_filtering of the …

Nov 25, 2024
CVE-2024-11663
7.3 HIGH

A vulnerability classified as critical was found in Codezips E-Commerce Site 1.0. Affected by this vulnerability is an unknown functionality of the file search.php. The …

Nov 25, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.