CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2021-1234
5.3 MEDIUM

A vulnerability in the cluster management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to view sensitive information on an affected system. …

Nov 18, 2024
CVE-2021-1232
6.5 MEDIUM

A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to read arbitrary files on the underlying filesystem …

Nov 18, 2024
CVE-2021-1132
5.3 MEDIUM

A vulnerability in the API subsystem and in the web-management interface of Cisco Network Services Orchestrator (NSO) could allow an unauthenticated, remote attacker to access sensitive …

Nov 18, 2024
CVE-2020-3548
5.3 MEDIUM

A vulnerability in the Transport Layer Security (TLS) protocol implementation of Cisco AsyncOS software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to …

Nov 18, 2024
CVE-2020-3539
6.3 MEDIUM

A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete …

Nov 18, 2024
CVE-2020-3538
4.6 MEDIUM

A vulnerability in a certain REST API endpoint of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to perform a path …

Nov 18, 2024
CVE-2020-3532
6.1 MEDIUM

A vulnerability in the web-based management interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, and …

Nov 18, 2024
CVE-2020-3525
4.3 MEDIUM

A vulnerability in the Admin portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to recover service account passwords that are saved …

Nov 18, 2024
CVE-2020-3431
6.1 MEDIUM

A vulnerability in the web-based management interface of Cisco Small Business RV042 Dual WAN VPN Routers and Cisco Small Business RV042G Dual Gigabit WAN VPN Routers could …

Nov 18, 2024
CVE-2020-3420
5.4 MEDIUM

A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) …

Nov 18, 2024
CVE-2020-27124
8.6 HIGH

A vulnerability in the SSL/TLS handler of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause the affected device to reload …

Nov 18, 2024
CVE-2020-26074
7.8 HIGH

A vulnerability in system file transfer functions of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to gain escalated privileges on the underlying operating …

Nov 18, 2024
CVE-2020-26073
7.5 HIGH

A vulnerability in the application data endpoints of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability …

Nov 18, 2024
CVE-2020-26071
8.4 HIGH

A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to create or overwrite arbitrary files on an affected device, which …

Nov 18, 2024
CVE-2020-26063
5.4 MEDIUM

A vulnerability in the API endpoints of Cisco Integrated Management Controller could allow an authenticated, remote attacker to bypass authorization and take actions on a vulnerable …

Nov 18, 2024
CVE-2020-26062
5.3 MEDIUM

A vulnerability in Cisco Integrated Management Controller could allow an unauthenticated, remote attacker to enumerate valid usernames within the vulnerable application. The vulnerability is due to …

Nov 18, 2024
CVE-2024-52436
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal Post SMTP post-smtp allows Blind SQL Injection.This issue affects …

Nov 18, 2024
CVE-2024-52435
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjada WPDM – Premium Packages wpdm-premium-packages.This issue affects WPDM – Premium …

Nov 18, 2024
CVE-2024-52434
9.1 CRITICAL

Deserialization of Untrusted Data vulnerability in supsystic Popup by Supsystic popup-by-supsystic allows Command Injection.This issue affects Popup by Supsystic: from n/a through <= 1.10.29.

Nov 18, 2024
CVE-2024-52433
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in Mindstien Technologies My Geo Posts Free my-geo-posts-free allows Object Injection.This issue affects My Geo Posts Free: from n/a through …

Nov 18, 2024
CVE-2024-52432
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in NIX Solutions Ltd NIX Anti-Spam Light nix-anti-spam-light allows Object Injection.This issue affects NIX Anti-Spam Light: from n/a through <= …

Nov 18, 2024
CVE-2024-52431
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pressaholic WordPress Video Robot - The Ultimate Video Importer allows SQL …

Nov 18, 2024
CVE-2024-52430
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in bublick Lis Video Gallery lis-video-gallery allows Object Injection.This issue affects Lis Video Gallery: from n/a through <= 0.2.1.

Nov 18, 2024
CVE-2024-52429
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in AntonHoelstad WP Quick Setup wp-quick-setup allows Upload a Web Shell to a Web Server.This issue affects …

Nov 18, 2024
CVE-2024-52428
8.1 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Peter Ads Booster by Ads Pro free-wp-booster-by-ads-pro allows PHP …

Nov 18, 2024
CVE-2024-52427
9.9 CRITICAL

Deserialization of Untrusted Data vulnerability in Vollstart Event Tickets with Ticket Scanner event-tickets-with-ticket-scanner allows Server Side Include (SSI) Injection.This issue affects Event Tickets with Ticket …

Nov 18, 2024
CVE-2024-37155
6.5 MEDIUM

OpenCTI is an open source platform allowing organizations to manage their cyber threat intelligence knowledge and observables. Prior to version 6.1.9, the regex validation used …

Nov 18, 2024
CVE-2024-28058
7.5 HIGH

In RSA NetWitness (NW) Platform before 12.5.1, even when an administrator revokes the access of a specific user with an active session, an internal threat …

Nov 18, 2024
CVE-2024-11304

Missing input validation in the SEH Computertechnik utnserver Pro, SEH Computertechnik utnserver ProMAX, SEH Computertechnik INU-100 web-interface allows stored Cross-Site Scripting (XSS). This issue affects …

Nov 18, 2024
CVE-2024-9526
5.4 MEDIUM

There exists a stored XSS Vulnerability in Kubeflow Pipeline View web UI. The Kubeflow Web UI allows to create new pipelines. When creating a new …

Nov 18, 2024
CVE-2024-8781

Execution with Unnecessary Privileges, : Improper Protection of Alternate Path vulnerability in TR7 Application Security Platform (ASP) allows Privilege Escalation, -Privilege Abuse.This issue affects Application …

Nov 18, 2024
CVE-2024-11318
7.5 HIGH

An IDOR (Insecure Direct Object Reference) vulnerability has been discovered in AbsysNet, affecting version 2.3.1. This vulnerability could allow a remote attacker to obtain the …

Nov 18, 2024
CVE-2024-11303

The pathname of the root directory to a Restricted Directory ('Path Traversal') vulnerability in Korenix JetPort 5601 allows Path Traversal.This issue affects JetPort 5601: through …

Nov 18, 2024
CVE-2024-52318
6.1 MEDIUM

Incorrect object recycling and reuse vulnerability in Apache Tomcat. This issue affects Apache Tomcat: 11.0.0, 10.1.31, 9.0.96. Users are recommended to upgrade to version 11.0.1, …

Nov 18, 2024
CVE-2024-3370
8.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Egebilgi Software Website Template allows SQL Injection.This issue affects Website Template: …

Nov 18, 2024
CVE-2024-52317
6.5 MEDIUM

Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response used by HTTP/2 requests could lead to request and/or …

Nov 18, 2024
CVE-2024-52316
9.8 CRITICAL

Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuthContext component which may throw an …

Nov 18, 2024
CVE-2024-48901
4.3 MEDIUM

A vulnerability was found in Moodle. Additional checks are required to ensure users can only access the schedule of a report if they have permission …

Nov 18, 2024
CVE-2024-48898
4.3 MEDIUM

A vulnerability was found in Moodle. Users with access to delete audiences from reports could delete audiences from other reports that they do not have …

Nov 18, 2024
CVE-2024-48897
4.3 MEDIUM

A vulnerability was found in Moodle. Additional checks are required to ensure users can only edit or delete RSS feeds that they have permission to …

Nov 18, 2024
CVE-2024-48896
4.3 MEDIUM

A vulnerability was found in Moodle. It is possible for users with the "send message" capability to view other users' names that they may not …

Nov 18, 2024
CVE-2024-11319
4.8 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in django CMS Association django-cms allows Cross-Site Scripting (XSS).This issue affects django-cms: …

Nov 18, 2024
CVE-2024-11023
6.1 MEDIUM

Firebase JavaScript SDK utilizes a "FIREBASE_DEFAULTS" cookie to store configuration data, including an "_authTokenSyncURL" field used for session synchronization. If this cookie field is preset …

Nov 18, 2024
CVE-2024-42392
4.0 MEDIUM

Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an infinite loop bug if the input string contains unexpected characters.

Nov 18, 2024
CVE-2024-42391
4.3 MEDIUM

Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application …

Nov 18, 2024
CVE-2024-42390
4.3 MEDIUM

Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application …

Nov 18, 2024
CVE-2024-42389
5.3 MEDIUM

Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application …

Nov 18, 2024
CVE-2024-42388
5.3 MEDIUM

Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application …

Nov 18, 2024
CVE-2024-42387
5.3 MEDIUM

Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application …

Nov 18, 2024
CVE-2024-42386
8.2 HIGH

Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation …

Nov 18, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.