CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-42385
4.0 MEDIUM

Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an out-of-bound memory write if the PEM certificate contains unexpected characters.

Nov 18, 2024
CVE-2024-42384
7.5 HIGH

Integer Overflow or Wraparound vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault …

Nov 18, 2024
CVE-2024-42383
4.2 MEDIUM

Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows to write a NULL byte value beyond the memory space dedicated for …

Nov 18, 2024
CVE-2024-41974
7.1 HIGH

A low privileged remote attacker may modify the BACNet service properties due to incorrect permission assignment for critical resources which may lead to a DoS …

Nov 18, 2024
CVE-2024-41973
8.1 HIGH

A low privileged remote attacker can specify an arbitrary file on the filesystem which may lead to an arbitrary file writes with root privileges.

Nov 18, 2024
CVE-2024-41972
6.5 MEDIUM

A low privileged remote attacker can overwrite an arbitrary file on the filesystem which may lead to an arbitrary file read with root privileges.

Nov 18, 2024
CVE-2024-41971
8.1 HIGH

A low privileged remote attacker can overwrite an arbitrary file on the filesystem leading to a DoS and data loss.

Nov 18, 2024
CVE-2024-41970
5.7 MEDIUM

A low privileged remote attacker may gain access to forbidden diagnostic data due to incorrect permission assignment for critical resources.

Nov 18, 2024
CVE-2023-39180
4.0 MEDIUM

A flaw was found within the handling of SMB2_READ commands in the kernel ksmbd module. The issue results from not releasing memory after its effective …

Nov 18, 2024
CVE-2023-39179
7.5 HIGH

A flaw was found within the handling of SMB2 read requests in the kernel ksmbd module. The issue results from the lack of proper validation …

Nov 18, 2024
CVE-2023-39176
5.8 MEDIUM

A flaw was found within the parsing of SMB2 requests that have a transform header in the kernel ksmbd module. The issue results from the …

Nov 18, 2024
CVE-2024-48962
8.8 HIGH

Improper Control of Generation of Code ('Code Injection'), Cross-Site Request Forgery (CSRF), : Improper Neutralization of Special Elements Used in a Template Engine vulnerability in …

Nov 18, 2024
CVE-2024-47208
9.8 CRITICAL

Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.17. Users are …

Nov 18, 2024
CVE-2024-45791
7.5 HIGH

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HertzBeat. This issue affects Apache HertzBeat: before 1.6.1. Users are recommended to upgrade to …

Nov 18, 2024
CVE-2024-45505
8.8 HIGH

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache HertzBeat (incubating). This vulnerability can only be exploited by authorized attackers. …

Nov 18, 2024
CVE-2024-41969
8.8 HIGH

A low privileged remote attacker may modify the configuration of the CODESYS V3 service through a missing authentication vulnerability which could lead to full system …

Nov 18, 2024
CVE-2024-41968
5.4 MEDIUM

A low privileged remote attacker may modify the docker settings setup of the device, leading to a limited DoS.

Nov 18, 2024
CVE-2024-41967
8.1 HIGH

A low privileged remote attacker may modify the boot mode configuration setup of the device, leading to modification of the firmware upgrade process or a …

Nov 18, 2024
CVE-2024-41151
8.8 HIGH

Deserialization of Untrusted Data vulnerability in Apache HertzBeat. This vulnerability can only be exploited by authorized attackers. This issue affects Apache HertzBeat: before 1.6.1. Users …

Nov 18, 2024
CVE-2024-49574
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8123 are vulnerable to SQL Injection in the reports module.

Nov 18, 2024
CVE-2024-22067
6.8 MEDIUM

ZTE NH8091 product has an improper permission control vulnerability. Due to improper permission control of the Web module interface, an authenticated attacker may exploit the …

Nov 18, 2024
CVE-2024-11315
9.8 CRITICAL

The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload …

Nov 18, 2024
CVE-2024-11314
9.8 CRITICAL

The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload …

Nov 18, 2024
CVE-2024-11313
9.8 CRITICAL

The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload …

Nov 18, 2024
CVE-2024-11312
9.8 CRITICAL

The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload …

Nov 18, 2024
CVE-2024-11311
9.8 CRITICAL

The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload …

Nov 18, 2024
CVE-2024-5030
3.8 LOW

The CM Table Of Contents WordPress plugin before 1.2.3 does not have CSRF check in place when resetting its settings, which could allow attackers to …

Nov 18, 2024
CVE-2024-52947
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability in LemonLDAP::NG before 2.20.1 allows remote attackers to inject arbitrary web script or HTML via the url parameter of the …

Nov 18, 2024
CVE-2024-52946
8.8 HIGH

An issue was discovered in LemonLDAP::NG before 2.20.1. An Improper Check during session refresh allows an authenticated user to raise their authentication level if the …

Nov 18, 2024
CVE-2024-52945
7.8 HIGH

An issue was discovered in Veritas NetBackup before 10.5. This only applies to NetBackup components running on a Windows Operating System. If a user executes …

Nov 18, 2024
CVE-2024-52944
5.4 MEDIUM

An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24698. It allows an authenticated remote attacker to inject a parameter into an HTTP …

Nov 18, 2024
CVE-2024-52943
5.4 MEDIUM

An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24697. It allows an authenticated remote attacker to inject a parameter into an HTTP …

Nov 18, 2024
CVE-2024-52942
5.4 MEDIUM

An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24696. It allows an authenticated remote attacker to inject a parameter into an HTTP …

Nov 18, 2024
CVE-2024-52941
5.4 MEDIUM

An issue was discovered in Veritas Enterprise Vault before 15.1 UPD882911, ZDI-CAN-24695. It allows an authenticated remote attacker to inject a parameter into an HTTP …

Nov 18, 2024
CVE-2024-11310
7.5 HIGH

The DVC from TRCore has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.

Nov 18, 2024
CVE-2024-11309
7.5 HIGH

The DVC from TRCore has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.

Nov 18, 2024
CVE-2024-11308
6.2 MEDIUM

The DVC from TRCore encrypts files using a hardcoded key. Attackers can use this key to decrypt the files and restore the original content.

Nov 18, 2024
CVE-2024-52940
7.5 HIGH

AnyDesk through 8.1.0 on Windows, when Allow Direct Connections is enabled, inadvertently exposes a public IP address within network traffic. The attacker must know the …

Nov 18, 2024
CVE-2024-43704
8.4 HIGH

Software installed and run as a non-privileged user may conduct improper GPU system calls to gain access to the graphics buffers of a parent process.

Nov 18, 2024
CVE-2024-52926
6.5 MEDIUM

Delinea Privilege Manager before 12.0.2 mishandles the security of the Windows agent.

Nov 18, 2024
CVE-2024-52922
6.5 MEDIUM

In Bitcoin Core before 25.1, an attacker can cause a node to not download the latest block, because there can be minutes of delay when …

Nov 18, 2024
CVE-2024-52921
5.3 MEDIUM

In Bitcoin Core before 25.0, a peer can affect the download state of other peers by sending a mutated block.

Nov 18, 2024
CVE-2024-52920
7.5 HIGH

Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (infinite loop) via a malformed GETDATA message.

Nov 18, 2024
CVE-2024-52919
6.5 MEDIUM

Bitcoin Core before 22.0 has a CAddrMan nIdCount integer overflow and resultant assertion failure (and daemon exit) via a flood of addr messages.

Nov 18, 2024
CVE-2024-52918
6.5 MEDIUM

Bitcoin-Qt in Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (memory consumption and application crash) via a BIP21 r parameter …

Nov 18, 2024
CVE-2024-52917
6.5 MEDIUM

Bitcoin Core before 22.0 has a miniupnp infinite loop in which it allocates memory on the basis of random data received over the network, e.g., …

Nov 18, 2024
CVE-2024-52916
7.5 HIGH

Bitcoin Core before 0.15.0 allows a denial of service (OOM kill of a daemon process) via a flood of minimum difficulty headers.

Nov 18, 2024
CVE-2024-52915
7.5 HIGH

Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (memory consumption) via a crafted INV message.

Nov 18, 2024
CVE-2024-52914
7.5 HIGH

In Bitcoin Core before 0.18.0, a node could be stalled for hours when processing the orphans of a crafted unconfirmed transaction.

Nov 18, 2024
CVE-2024-52913
5.3 MEDIUM

In Bitcoin Core before 0.21.0, an attacker could prevent a node from seeing a specific unconfirmed transaction, because transaction re-requests are mishandled.

Nov 18, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.