CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-11257
7.3 HIGH

A vulnerability classified as critical has been found in 1000 Projects Beauty Parlour Management System 1.0. This affects an unknown part of the file /admin/forgot-password.php. …

Nov 15, 2024
CVE-2024-11256
7.3 HIGH

A vulnerability was found in 1000 Projects Portfolio Management System MCA 1.0 and classified as critical. This issue affects some unknown processing of the file …

Nov 15, 2024
CVE-2024-10934
9.8 CRITICAL

In OpenBSD 7.5 before errata 008 and OpenBSD 7.4 before errata 021, avoid possible mbuf double free in NFS client and server implementation, do not …

Nov 15, 2024
CVE-2024-51330
4.4 MEDIUM

An issue in UltiMaker Cura v.4.41 and 5.8.1 and before allows a local attacker to execute arbitrary code via Inter-process communication (IPC) mechanism between Cura …

Nov 15, 2024
CVE-2024-51142
5.4 MEDIUM

Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows an attacker to execute arbitrary code via the svkey parameter of the storageapi.php file.

Nov 15, 2024
CVE-2024-51141
7.8 HIGH

An issue in TOTOLINK Bluetooth Wireless Adapter A600UB allows a local attacker to execute arbitrary code via the WifiAutoInstallDriver.exe and MSASN1.dll components.

Nov 15, 2024
CVE-2024-51037
5.3 MEDIUM

An issue in kodbox v.1.52.04 and before allows a remote attacker to obtain sensitive information via the captcha feature in the password reset function.

Nov 15, 2024
CVE-2024-45971
9.8 CRITICAL

Multiple Buffer overflows in the MMS Client in MZ Automation LibIEC61850 before commit 1f52be9ddeae00e69cd43e4cac3cb4f0c880c4f0 allow a malicious server to cause a stack-based buffer overflow via …

Nov 15, 2024
CVE-2024-45970
9.8 CRITICAL

Multiple Buffer overflows in the MMS Client in MZ Automation LibIEC61850 before commit ac925fae8e281ac6defcd630e9dd756264e9c5bc allow a malicious server to cause a stack-based buffer overflow via …

Nov 15, 2024
CVE-2024-45969
7.5 HIGH

NULL pointer dereference in the MMS Client in MZ Automation LibIEC1850 before commit 7afa40390b26ad1f4cf93deaa0052fe7e357ef33 allows a malicious server to Cause a Denial-of-Service via the MMS …

Nov 15, 2024
CVE-2024-45608
6.5 MEDIUM

GLPI is a free asset and IT management software package. An authenticated user can perfom a SQL injection by changing its preferences. Upgrade to 10.0.17.

Nov 15, 2024
CVE-2024-43418
6.5 MEDIUM

GLPI is a free asset and IT management software package. An unauthenticated user can provide a malicious link to a GLPI technician in order to …

Nov 15, 2024
CVE-2024-43417
6.5 MEDIUM

GLPI is a free asset and IT management software package. An unauthenticated user can provide a malicious link to a GLPI technician in order to …

Nov 15, 2024
CVE-2024-41679
6.5 MEDIUM

GLPI is a free asset and IT management software package. An authenticated user can exploit a SQL injection vulnerability from the ticket form. Upgrade to …

Nov 15, 2024
CVE-2024-24446
6.5 MEDIUM

An uninitialized pointer dereference in OpenAirInterface CN5G AMF up to v2.0.0 allows attackers to cause a Denial of Service (DoS) via a crafted InitialContextSetupResponse message …

Nov 15, 2024
CVE-2024-24431
7.5 HIGH

A reachable assertion in the ogs_nas_emm_decode function of Open5GS v2.7.0 allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet with …

Nov 15, 2024
CVE-2024-24426
7.5 HIGH

Reachable assertions in the NGAP_FIND_PROTOCOLIE_BY_ID function of OpenAirInterface Magma v1.8.0 and OAI EPC Federation v1.2.0 allow attackers to cause a Denial of Service (DoS) via …

Nov 15, 2024
CVE-2024-24425
6.5 MEDIUM

Magma v1.8.0 and OAI EPC Federation v1.20 were discovered to contain an out-of-bounds read in the amf_as_establish_req function at /tasks/amf/amf_as.cpp. This vulnerability allows attackers to …

Nov 15, 2024
CVE-2024-23169
4.6 MEDIUM

The web interface in RSA NetWitness 11.7.2.0 allows Cross-Site Scripting (XSS) via the Where textbox on the Reports screen during new rule creation.

Nov 15, 2024
CVE-2024-52522

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Insecure handling of symlinks with --links and --metadata …

Nov 15, 2024
CVE-2024-52514
4.1 MEDIUM

Nextcloud Server is a self hosted personal cloud system. After a user received a share with some files inside being blocked by the files access …

Nov 15, 2024
CVE-2024-52513
2.6 LOW

Nextcloud Server is a self hosted personal cloud system. After receiving a "Files drop" or "Password protected" share link a malicious user was able to …

Nov 15, 2024
CVE-2024-52512
3.3 LOW

user_oidc app is an OpenID Connect user backend for Nextcloud. A malicious user could send a malformed login link that would redirect the user to …

Nov 15, 2024
CVE-2024-52511
6.3 MEDIUM

Nextcloud Tables allows users to to create tables with individual columns. By directly specifying the ID of a table or view, a malicious user could …

Nov 15, 2024
CVE-2024-52510
4.2 MEDIUM

The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. The Desktop client did not stop with an error …

Nov 15, 2024
CVE-2024-52509
3.5 LOW

Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. The Nextcloud mail app incorrectly allowed attaching shared files without download permissions as …

Nov 15, 2024
CVE-2024-52508
8.2 HIGH

Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. When a user is trying to set up a mail account with an …

Nov 15, 2024
CVE-2024-52507
3.5 LOW

Nextcloud Tables allows users to to create tables with individual columns. The information which Table (numeric ID) is shared with which groups and users and …

Nov 15, 2024
CVE-2024-50800
5.4 MEDIUM

Cross Site Scripting vulnerability in M2000 Smart4Web before v.5.020241004 allows a remote attacker to execute arbitrary code via the error parameter in URL

Nov 15, 2024
CVE-2024-47759
4.8 MEDIUM

GLPI is a free Asset and IT management software package. An technician can upload a SVG containing a malicious script. The script will then be …

Nov 15, 2024
CVE-2024-46467
7.8 HIGH

By default, dedicated folders of ZONEPOINT for Windows up to 2024.1 can be accessed by other users to misuse technical files and make them perform …

Nov 15, 2024
CVE-2024-46466
7.8 HIGH

By default, dedicated folders of ZONECENTRAL for Windows up to 2024.3 or up to Q.2021.2 (ANSSI qualification submission) can be accessed by other users to …

Nov 15, 2024
CVE-2024-46465
7.8 HIGH

By default, dedicated folders of CRYHOD for Windows up to 2024.3 can be accessed by other users to misuse technical files and make them perform …

Nov 15, 2024
CVE-2024-46463
7.8 HIGH

By default, dedicated folders of ORIZON for Windows up to 2024.3 can be accessed by other users to misuse technical files and make them perform …

Nov 15, 2024
CVE-2024-46462
7.8 HIGH

By default, dedicated folders of ZEDMAIL for Windows up to 2024.3 can be accessed by other users to misuse technical files and make them perform …

Nov 15, 2024
CVE-2024-46383
2.4 LOW

Hathway Skyworth Router CM5100-511 v4.1.1.24 was discovered to store sensitive information about USB and Wifi connected devices in plaintext.

Nov 15, 2024
CVE-2024-41678
6.5 MEDIUM

GLPI is a free asset and IT management software package. An unauthenticated user can provide a malicious link to a GLPI technician in order to …

Nov 15, 2024
CVE-2024-40638
8.1 HIGH

GLPI is a free asset and IT management software package. An authenticated user can exploit multiple SQL injection vulnerabilities. One of them can be used …

Nov 15, 2024
CVE-2024-24450
5.3 MEDIUM

Stack-based memcpy buffer overflow in the ngap_handle_pdu_session_resource_setup_response routine in OpenAirInterface CN5G AMF <= 2.0.0 allows a remote attacker with access to the N2 interface to …

Nov 15, 2024
CVE-2024-24449
6.5 MEDIUM

An uninitialized pointer dereference in the NasPdu::NasPdu component of OpenAirInterface CN5G AMF up to v2.0.0 allows attackers to cause a Denial of Service (DoS) via …

Nov 15, 2024
CVE-2024-24447
5.3 MEDIUM

A buffer overflow in the ngap_amf_handle_pdu_session_resource_setup_response function of oai-cn5g-amf up to v2.0.0 allows attackers to cause a Denial of Service (DoS) via a PDU Session …

Nov 15, 2024
CVE-2024-11251
6.3 MEDIUM

A vulnerability was found in erzhongxmu Jeewms up to 20241108. It has been rated as critical. This issue affects some unknown processing of the file …

Nov 15, 2024
CVE-2024-11250
6.3 MEDIUM

A vulnerability was found in code-projects Inventory Management up to 1.0. It has been declared as critical. This vulnerability affects unknown code of the file …

Nov 15, 2024
CVE-2024-52528

Budget Control Gateway acts as an entry point for incoming requests and routes them to the appropriate microservices for Budget Control. Budget Control Gateway does …

Nov 15, 2024
CVE-2024-52525
1.8 LOW

Nextcloud Server is a self hosted personal cloud system. Under certain conditions the password of a user was stored unencrypted in the session data. The …

Nov 15, 2024
CVE-2024-52523
4.6 MEDIUM

Nextcloud Server is a self hosted personal cloud system. After setting up a user or administrator defined external storage with fixed credentials, the API returns …

Nov 15, 2024
CVE-2024-52521
2.6 LOW

Nextcloud Server is a self hosted personal cloud system. MD5 hashes were used to check background jobs for their uniqueness. This increased the chances of …

Nov 15, 2024
CVE-2024-52520
5.7 MEDIUM

Nextcloud Server is a self hosted personal cloud system. Due to a pre-flighted HEAD request, the link reference provider could be tricked into downloading bigger …

Nov 15, 2024
CVE-2024-52519
2.7 LOW

Nextcloud Server is a self hosted personal cloud system. The OAuth2 client secrets were stored in a recoverable way, so that an attacker that got …

Nov 15, 2024
CVE-2024-52518
4.4 MEDIUM

Nextcloud Server is a self hosted personal cloud system. After an attacker got access to the session of a user or administrator, the attacker would …

Nov 15, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.