CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2021-38119
6.1 MEDIUM

Possible Reflected Cross-Site Scripting (XSS) Vulnerability in iManager has been discovered in OpenText™ iManager 3.2.4.0000.

Nov 22, 2024
CVE-2021-38118
5.5 MEDIUM

Possible improper input validation Vulnerability in iManager has been discovered in OpenText™ iManager 3.2.4.0000.

Nov 22, 2024
CVE-2021-38117
8.8 HIGH

Possible Command injection Vulnerability in iManager has been discovered in OpenText™ iManager 3.2.4.0000.

Nov 22, 2024
CVE-2021-38116
8.8 HIGH

Possible Elevation of Privilege Vulnerability in iManager has been discovered in OpenText™ iManager. This impacts all versions before 3.2.5

Nov 22, 2024
CVE-2024-49054
4.3 MEDIUM

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Nov 22, 2024
CVE-2024-45719
2.6 LOW

Inadequate Encryption Strength vulnerability in Apache Answer. This issue affects Apache Answer: through 1.4.0. The ids generated using the UUID v1 version are to some …

Nov 22, 2024
CVE-2024-51766
6.5 MEDIUM

A potential security vulnerability has been identified in the HPE NonStop DISK UTIL (T9208) product. This vulnerability could be exploited to cause a denial of …

Nov 22, 2024
CVE-2024-41781
5.1 MEDIUM

IBM PowerVM Platform KeyStore (IBM PowerVM Hypervisor FW950.00 through FW950.90, FW1030.00 through FW1030.60, FW1050.00 through FW1050.20, and FW1060.00 through FW1060.10 functionality can be compromised if …

Nov 22, 2024
CVE-2024-41779
9.8 CRITICAL

IBM Engineering Systems Design Rhapsody - Model Manager 7.0.2 and 7.0.3 could allow a remote attacker to bypass security restrictions, caused by a race condition. …

Nov 22, 2024
CVE-2021-30299
6.7 MEDIUM

Possible out of bound access in audio module due to lack of validation of user provided input.

Nov 22, 2024
CVE-2017-9711
6.7 MEDIUM

Certain unprivileged processes are able to perform IOCTL calls.

Nov 22, 2024
CVE-2024-7882
6.5 MEDIUM

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Special Minds Design and Software e-Commerce allows SQL Injection.This issue affects …

Nov 22, 2024
CVE-2024-7837
8.2 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Firmanet Software ERP allows SQL Injection.This issue affects ERP: through 22.11.2024. …

Nov 22, 2024
CVE-2024-8929
5.8 MEDIUM

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, a hostile MySQL server can cause the client to disclose the content of …

Nov 22, 2024
CVE-2024-9422
6.6 MEDIUM

The GEO my WP WordPress plugin before 4.5, gmw-premium-settings WordPress plugin before 3.1 does not sufficiently validate files to be uploaded, which could allow attackers …

Nov 22, 2024
CVE-2024-8932
9.8 CRITICAL

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an …

Nov 22, 2024
CVE-2024-8735
6.1 MEDIUM

The MailMunch – Grow your Email List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping …

Nov 22, 2024
CVE-2024-11601
8.1 HIGH

The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart, Blog, Video Gallery) plugin for WordPress is …

Nov 22, 2024
CVE-2024-11381
6.4 MEDIUM

The Control horas plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ch_registro' shortcode in all versions up to, and including, 1.0.1 …

Nov 22, 2024
CVE-2024-11355
4.3 MEDIUM

The Ultimate YouTube Video & Shorts Player With Vimeo plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check …

Nov 22, 2024
CVE-2024-11225
6.1 MEDIUM

The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate …

Nov 22, 2024
CVE-2024-11104
8.1 HIGH

The Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart, Blogs) plugin for WordPress is vulnerable to …

Nov 22, 2024
CVE-2024-10666
4.3 MEDIUM

The Easy Twitter Feed – Twitter feeds plugin for WP plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, …

Nov 22, 2024
CVE-2024-10034
5.5 MEDIUM

The Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native gallery plugin for WordPress is vulnerable to …

Nov 22, 2024
CVE-2024-38296
6.7 MEDIUM

Dell Edge Gateway 3200, versions prior to 15.40.30.2879, and Edge Gateway 5200, versions prior to 12.0.94.2380, contain an Exposure of Sensitive Information in Shared Microarchitectural …

Nov 22, 2024
CVE-2024-47142
5.5 MEDIUM

AIPHONE IXG SYSTEM IXG-2C7 firmware Ver.2.03 and earlier and IXG-2C7-L firmware Ver.2.03 and earlier contain an issue with insufficiently protected credentials, which may allow a …

Nov 22, 2024
CVE-2024-45837
5.4 MEDIUM

Use of hard-coded cryptographic key issue exists in AIPHONE IX SYSTEM, IXG SYSTEM, and System Support Software. A network-adjacent unauthenticated attacker may log in to …

Nov 22, 2024
CVE-2024-39290
6.5 MEDIUM

Insufficiently protected credentials issue exists in AIPHONE IX SYSTEM and IXG SYSTEM. A network-adjacent unauthenticated attacker may obtain sensitive information such as a username and …

Nov 22, 2024
CVE-2024-31408
8.0 HIGH

OS command injection vulnerability exists in AIPHONE IX SYSTEM and IXG SYSTEM. A network-adjacent authenticated attacker may execute an arbitrary OS command with root privileges …

Nov 22, 2024
CVE-2024-52056
6.5 MEDIUM

Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to delete any directory on the file system if …

Nov 21, 2024
CVE-2024-52055
4.9 MEDIUM

Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to read any file on the file system if …

Nov 21, 2024
CVE-2024-52054
2.7 LOW

Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to create an XML definition file anywhere on the …

Nov 21, 2024
CVE-2024-52053
9.6 CRITICAL

Stored Cross-Site Scripting in the Manager component of Wowza Streaming Engine below 4.9.1 allows an unauthenticated attacker to inject client-side JavaScript into the web dashboard …

Nov 21, 2024
CVE-2024-52052
7.2 HIGH

Wowza Streaming Engine below 4.9.1 permits an authenticated Streaming Engine Manager administrator to define a custom application property and poison a stream target for high-privilege …

Nov 21, 2024
CVE-2024-52616
5.3 MEDIUM

A flaw was found in the Avahi-daemon, where it initializes DNS transaction IDs randomly only once at startup, incrementing them sequentially after that. This predictable …

Nov 21, 2024
CVE-2024-52615
5.3 MEDIUM

A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies attacks where malicious DNS responses are …

Nov 21, 2024
CVE-2024-51367
9.8 CRITICAL

An arbitrary file upload vulnerability in the component \Users\username.BlackBoard of BlackBoard v2.0.0.2 allows attackers to execute arbitrary code via uploading a crafted .xml file.

Nov 21, 2024
CVE-2024-51366
9.8 CRITICAL

An arbitrary file upload vulnerability in the component \Roaming\Omega of OmegaT v6.0.1 allows attackers to execute arbitrary code via uploading a crafted .conf file.

Nov 21, 2024
CVE-2024-51365

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not …

Nov 21, 2024
CVE-2024-51364
8.8 HIGH

An arbitrary file upload vulnerability in ModbusMechanic v3.0 allows attackers to execute arbitrary code via uploading a crafted .xml file.

Nov 21, 2024
CVE-2024-49588
6.8 MEDIUM

Multiple endpoints in `oracle-sidecar` in versions 0.347.0 to 0.543.0 were found to be vulnerable to SQL injections.

Nov 21, 2024
CVE-2024-53095
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: smb: client: Fix use-after-free of network namespace. Recently, we got a customer report that CIFS …

Nov 21, 2024
CVE-2024-53094
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Add sendpage_ok() check to disable MSG_SPLICE_PAGES While running ISER over SIW, the initiator machine …

Nov 21, 2024
CVE-2024-53093
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nvme-multipath: defer partition scanning We need to suppress the partition scan from occuring within the …

Nov 21, 2024
CVE-2024-53092
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: virtio_pci: Fix admin vq cleanup by using correct info pointer vp_modern_avq_cleanup() and vp_del_vqs() clean up …

Nov 21, 2024
CVE-2024-53091
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: Add sk_is_inet and IS_ICSK check in tls_sw_has_ctx_tx/rx As the introduction of the support for …

Nov 21, 2024
CVE-2024-53090
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: afs: Fix lock recursion afs_wake_up_async_call() can incur lock recursion. The problem is that it is …

Nov 21, 2024
CVE-2024-53089
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: LoongArch: KVM: Mark hrtimer to expire in hard interrupt context Like commit 2c0d278f3293f ("KVM: LAPIC: …

Nov 21, 2024
CVE-2024-51337
3.5 LOW

Cross Site Scripting vulnerability in Gibbon before v.27.0.01 and fixed in v.28.0.00 allows a remote attacker to obtain sensitive information via the email parameter found …

Nov 21, 2024
CVE-2024-53432
7.5 HIGH

While parsing certain malformed PLY files, PCL version 1.14.1 crashes due to an uncaught std::out_of_range exception in PCLPointCloud2::at. This issue could potentially be exploited to …

Nov 21, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.