CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-50657
6.8 MEDIUM

An issue in Owncloud android apk v.4.3.1 allows a physically proximate attacker to escalate privileges via the PassCodeViewModel class, specifically in the checkPassCodeIsValid method

Nov 22, 2024
CVE-2024-37783
5.4 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in Gladinet CentreStack v13.12.9934.54690 allows attackers to inject malicious JavaScript into the web browser of a victim via the …

Nov 22, 2024
CVE-2024-37782
9.8 CRITICAL

An LDAP injection vulnerability in the login page of Gladinet CentreStack v13.12.9934.54690 allows attackers to access sensitive data or execute arbitrary commands via a crafted …

Nov 22, 2024
CVE-2024-53438
9.8 CRITICAL

EventAttendance.php in ChurchCRM 5.7.0 is vulnerable to SQL injection. An attacker can exploit this vulnerability by manipulating the 'Event' parameter, which is directly interpolated into …

Nov 22, 2024
CVE-2024-44786
7.5 HIGH

Incorrect access control in Meabilis CMS 1.0 allows attackers to access other users' address books via unspecified vectors.

Nov 22, 2024
CVE-2024-10220
8.1 HIGH

The Kubernetes kubelet component allows arbitrary command execution via specially crafted gitRepo volumes.This issue affects kubelet: through 1.28.11, from 1.29.0 through 1.29.6, from 1.30.0 through …

Nov 22, 2024
CVE-2024-52814
2.8 LOW

Argo Helm is a collection of community maintained charts for `argoproj.github.io` projects. Prior to version 0.45.0, the `workflow-role`) lacks granularity in its privileges, giving permissions …

Nov 22, 2024
CVE-2024-52804
7.5 HIGH

Tornado is a Python web framework and asynchronous networking library. The algorithm used for parsing HTTP cookies in Tornado versions prior to 6.4.2 sometimes has …

Nov 22, 2024
CVE-2024-52802
7.5 HIGH

RIOT is an operating system for internet of things (IoT) devices. In version 2024.04 and prior, the function `_parse_advertise`, located in `/sys/net/application_layer/dhcpv6/client.c`, has no minimum …

Nov 22, 2024
CVE-2024-52793

The Deno Standard Library provides APIs for Deno and the Web. Prior to version 1.0.11, `http/file-server`'s `serveDir` with `showDirListing: true` option is vulnerable to cross-site …

Nov 22, 2024
CVE-2024-52723
9.8 CRITICAL

In TOTOLINK X6000R V9.4.0cu.1041_B20240224 in the shttpd file, the Uci_Set Str function is used without strict parameter filtering. An attacker can achieve arbitrary command execution …

Nov 22, 2024
CVE-2024-51074
6.7 MEDIUM

Incorrect access control in KIA Seltos vehicle instrument cluster with software and hardware v1.0 allows attackers to arbitrarily change odometer readings in the vehicle by …

Nov 22, 2024
CVE-2024-51073
6.7 MEDIUM

An issue in KIA Seltos vehicle instrument cluster with software and hardware v1.0 allows attackers to control or disrupt CAN communication between the instrument cluster …

Nov 22, 2024
CVE-2024-51072
5.3 MEDIUM

An issue in KIA Seltos vehicle instrument cluster with software and hardware v1.0 allows attackers to cause a Denial of Service (DoS) via ECU reset …

Nov 22, 2024
CVE-2024-50965
5.4 MEDIUM

Cross Site Scripting vulnerability in Public Knowledge Project PKP Platform OJS/OMP/OPS- before v.3.3.0.16 allows an attacker to execute arbitrary code and escalate privileges via a …

Nov 22, 2024
CVE-2024-50401
7.2 HIGH

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers …

Nov 22, 2024
CVE-2024-50400
7.2 HIGH

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers …

Nov 22, 2024
CVE-2024-50399
7.2 HIGH

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers …

Nov 22, 2024
CVE-2024-50398
7.2 HIGH

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers …

Nov 22, 2024
CVE-2024-50397
8.8 HIGH

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers …

Nov 22, 2024
CVE-2024-50396
8.8 HIGH

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers …

Nov 22, 2024
CVE-2024-50395
8.8 HIGH

An authorization bypass through user-controlled key vulnerability has been reported to affect Media Streaming add-on. If exploited, the vulnerability could allow local network attackers to …

Nov 22, 2024
CVE-2024-48862
9.8 CRITICAL

A link following vulnerability has been reported to affect QuLog Center. If exploited, the vulnerability could allow remote attackers to traverse the file system to …

Nov 22, 2024
CVE-2024-48861
7.8 HIGH

An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow local network attackers to execute commands. …

Nov 22, 2024
CVE-2024-48860
9.8 CRITICAL

An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow remote attackers to execute commands. We …

Nov 22, 2024
CVE-2024-38647
7.5 HIGH

An exposure of sensitive information vulnerability has been reported to affect QNAP AI Core. If exploited, the vulnerability could allow remote attackers to compromise the …

Nov 22, 2024
CVE-2024-38646
6.0 MEDIUM

An incorrect permission assignment for critical resource vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow local authenticated attackers …

Nov 22, 2024
CVE-2024-38645
6.5 MEDIUM

A server-side request forgery (SSRF) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote authenticated attackers to read …

Nov 22, 2024
CVE-2024-38644
8.8 HIGH

An OS command injection vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote authenticated attackers to execute commands. …

Nov 22, 2024
CVE-2024-38643
9.8 CRITICAL

A missing authentication for critical function vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote attackers to gain …

Nov 22, 2024
CVE-2024-37050
6.5 MEDIUM

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow …

Nov 22, 2024
CVE-2024-37049
6.5 MEDIUM

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow …

Nov 22, 2024
CVE-2024-37048
4.9 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have …

Nov 22, 2024
CVE-2024-37047
6.5 MEDIUM

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow …

Nov 22, 2024
CVE-2024-37046
4.9 MEDIUM

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained …

Nov 22, 2024
CVE-2024-37045
4.9 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have …

Nov 22, 2024
CVE-2024-37044
7.2 HIGH

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow …

Nov 22, 2024
CVE-2024-37043
4.9 MEDIUM

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained …

Nov 22, 2024
CVE-2024-37042
4.9 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have …

Nov 22, 2024
CVE-2024-37041
7.2 HIGH

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow …

Nov 22, 2024
CVE-2024-32770
6.3 MEDIUM

A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow remote attackers who have gained user access …

Nov 22, 2024
CVE-2024-32769
6.3 MEDIUM

A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow remote attackers who have gained user access …

Nov 22, 2024
CVE-2024-32768
6.3 MEDIUM

A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow remote attackers who have gained user access …

Nov 22, 2024
CVE-2024-32767
6.3 MEDIUM

A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow remote attackers who have gained user access …

Nov 22, 2024
CVE-2024-10863

: Insufficient Logging vulnerability in OpenText Secure Content Manager on Windows allows Audit Log Manipulation.This issue affects Secure Content Manager: from 10.1 before <24.4. End-users …

Nov 22, 2024
CVE-2023-24467
8.8 HIGH

Possible Command Injection in iManager GET parameter has been discovered in OpenText™ iManager 3.2.6.0000.

Nov 22, 2024
CVE-2023-24466
7.5 HIGH

Possible XML External Entity Injection in iManager GET parameter has been discovered in OpenText™ iManager 3.2.6.0200.

Nov 22, 2024
CVE-2022-26324
7.6 HIGH

Possible XSS in iManager URL for access Component has been discovered in OpenText™ iManager 3.2.6.0000.

Nov 22, 2024
CVE-2021-38135
8.6 HIGH

Possible External Service Interaction attack in iManager has been discovered in OpenText™ iManager 3.2.6.0000.

Nov 22, 2024
CVE-2021-38134
6.1 MEDIUM

Possible XSS in iManager URL for access Component has been discovered in OpenText™ iManager 3.2.5.0000.

Nov 22, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.