CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-52002
8.8 HIGH

Combodo iTop is a simple, web based IT Service Management tool. Several url endpoints are subject to a Cross-Site Request Forgery (CSRF) vulnerability. Please refer …

Nov 8, 2024
CVE-2024-52001
4.3 MEDIUM

Combodo iTop is a simple, web based IT Service Management tool. In affected versions portal users are able to access forbidden services information. This issue …

Nov 8, 2024
CVE-2024-52000
6.1 MEDIUM

Combodo iTop is a simple, web based IT Service Management tool. Affected versions are subject to a reflected Cross-site Scripting (XSS) exploit by way of …

Nov 8, 2024
CVE-2024-35427
5.5 MEDIUM

vmir e8117 was discovered to contain a segmentation violation via the export_function function at /src/vmir_wasm_parser.c.

Nov 8, 2024
CVE-2024-35426
9.8 CRITICAL

vmir e8117 was discovered to contain a stack overflow via the init_local_vars function at /src/vmir_wasm_parser.c.

Nov 8, 2024
CVE-2024-48073
9.8 CRITICAL

sunniwell HT3300 before 1.0.0.B022.2 is vulnerable to Insecure Permissions. The /usr/local/bin/update program, which is responsible for updating the software in the HT3300 device, is given …

Nov 8, 2024
CVE-2024-35425
5.5 MEDIUM

vmir e8117 was discovered to contain a segmentation violation via the function_prepare_parse function at /src/vmir_function.c.

Nov 8, 2024
CVE-2024-35424
5.5 MEDIUM

vmir e8117 was discovered to contain a segmentation violation via the import_function function at /src/vmir_wasm_parser.c.

Nov 8, 2024
CVE-2024-35423
7.8 HIGH

vmir e8117 was discovered to contain a heap buffer overflow via the wasm_parse_section_functions function at /src/vmir_wasm_parser.c.

Nov 8, 2024
CVE-2024-35422
7.8 HIGH

vmir e8117 was discovered to contain a heap buffer overflow via the wasm_call function at /src/vmir_wasm_parser.c.

Nov 8, 2024
CVE-2024-35421
5.5 MEDIUM

vmir e8117 was discovered to contain a segmentation violation via the wasm_parse_block function at /src/vmir_wasm_parser.c.

Nov 8, 2024
CVE-2024-35420
6.2 MEDIUM

wac commit 385e1 was discovered to contain a heap overflow.

Nov 8, 2024
CVE-2024-35419
5.5 MEDIUM

wac commit 385e1 was discovered to contain a heap overflow via the load_module function at /wac-asan/wa.c. This vulnerability allows attackers to cause a Denial of …

Nov 8, 2024
CVE-2024-35418
6.2 MEDIUM

wac commit 385e1 was discovered to contain a heap overflow via the setup_call function at /wac-asan/wa.c. This vulnerability allows attackers to cause a Denial of …

Nov 8, 2024
CVE-2024-35410
6.2 MEDIUM

wac commit 385e1 was discovered to contain a heap overflow via the interpret function at /wac-asan/wa.c. This vulnerability allows attackers to cause a Denial of …

Nov 8, 2024
CVE-2024-27532
7.5 HIGH

wasm-micro-runtime (aka WebAssembly Micro Runtime or WAMR) 06df58f is vulnerable to NULL Pointer Dereference in function `block_type_get_result_types.

Nov 8, 2024
CVE-2024-27530
8.4 HIGH

wasm3 139076a contains a Use-After-Free in ForEachModule.

Nov 8, 2024
CVE-2024-27529
8.4 HIGH

wasm3 139076a contains memory leaks in Read_utf8.

Nov 8, 2024
CVE-2024-27528
8.4 HIGH

wasm3 139076a suffers from Invalid Memory Read, leading to DoS and potential Code Execution.

Nov 8, 2024
CVE-2024-27527
7.5 HIGH

wasm3 139076a is vulnerable to Denial of Service (DoS).

Nov 8, 2024
CVE-2024-11026
3.7 LOW

A vulnerability was found in Intelligent Apps Freenow App 12.10.0 on Android. It has been rated as problematic. Affected by this issue is some unknown …

Nov 8, 2024
CVE-2024-51157
4.7 MEDIUM

07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component http://erp.07fly.net:80/oa/OaSchedule/add.html.

Nov 8, 2024
CVE-2024-50809
8.8 HIGH

The theme.php file in SDCMS 2.8 has a command execution vulnerability that allows for the execution of system commands

Nov 8, 2024
CVE-2024-50808
8.8 HIGH

SeaCms 13.1 is vulnerable to code injection in the notification module of the member message notification module in the backend user module, due to unsafe …

Nov 8, 2024
CVE-2024-21994
4.3 MEDIUM

StorageGRID (formerly StorageGRID Webscale) versions prior to 11.9 are susceptible to a Denial of Service (DoS) vulnerability. Successful exploit by an authenticated attacker could lead …

Nov 8, 2024
CVE-2024-51997
8.1 HIGH

Trustee is a set of tools and components for attesting confidential guests and providing secrets to them. The ART (**Attestation Results Token**) token, generated by …

Nov 8, 2024
CVE-2024-51211
9.8 CRITICAL

SQL injection vulnerability exists in OS4ED openSIS-Classic Version 9.1, specifically in the resetuserinfo.php file. The vulnerability is due to improper input validation of the $username_stn_id …

Nov 8, 2024
CVE-2024-51055
6.5 MEDIUM

An issue Hoosk v1.7.1 allows a remote attacker to execute arbitrary code via a crafted script to the config.php component.

Nov 8, 2024
CVE-2024-50811
9.1 CRITICAL

hopetree izone lts c011b48 contains a server-side request forgery (SSRF) vulnerability in the active push function as \\apps\\tool\\apis\\bd_push.py does not securely filter user input through …

Nov 8, 2024
CVE-2024-50810
5.4 MEDIUM

hopetree izone lts c011b48 contains a Cross Site Scripting (XSS) vulnerability in the article comment function. In \apps\comment\views.py, AddCommintView() does not securely filter user input …

Nov 8, 2024
CVE-2024-44765
6.5 MEDIUM

An Improper Authorization (Access Control Misconfiguration) vulnerability in MGT-COMMERCE GmbH CloudPanel v2.0.0 to v2.4.2 allows low-privilege users to bypass access controls and gain unauthorized access …

Nov 8, 2024
CVE-2024-9841
6.1 MEDIUM

A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Management Center and ArcSight Platform. The vulnerability could be remotely exploited.

Nov 8, 2024
CVE-2024-51152
7.2 HIGH

File Upload vulnerability in Laravel CMS v.1.4.7 and before allows a remote attacker to execute arbitrary code via the shell.php a component.

Nov 8, 2024
CVE-2024-51032
5.4 MEDIUM

A Cross-site Scripting (XSS) vulnerability in manage_recipient.php of Sourcecodester Toll Tax Management System 1.0 allows remote authenticated users to inject arbitrary web scripts via the …

Nov 8, 2024
CVE-2024-51031
5.4 MEDIUM

A Cross-site Scripting (XSS) vulnerability in manage_account.php in Sourcecodester Cab Management System 1.0 allows remote authenticated users to inject arbitrary web scripts via the "First …

Nov 8, 2024
CVE-2024-51030
6.5 MEDIUM

A SQL injection vulnerability in manage_client.php and view_cab.php of Sourcecodester Cab Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the id …

Nov 8, 2024
CVE-2024-40240
6.8 MEDIUM

An incorrect access control issue in HomeServe Home Repair' android app - 3.3.4 allows a physically proximate attacker to escalate privileges via the fingerprint authentication …

Nov 8, 2024
CVE-2024-40239
6.8 MEDIUM

An incorrect access control issue in Life: Personal Diary, Journal android app 17.5.0 allows a physically proximate attacker to escalate privileges via the fingerprint authentication …

Nov 8, 2024
CVE-2024-50634
8.8 HIGH

A vulnerability in a weak JWT token in Watcharr v1.43.0 and below allows attackers to perform privilege escalation using a crafted JWT token. This vulnerability …

Nov 8, 2024
CVE-2024-45763
9.1 CRITICAL

Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high …

Nov 8, 2024
CVE-2024-25431
7.8 HIGH

An issue in bytecodealliance wasm-micro-runtime before v.b3f728c and fixed in commit 06df58f allows a remote attacker to escalate privileges via a crafted file to the …

Nov 8, 2024
CVE-2024-50966
9.3 CRITICAL

dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/doAdminAction.php?act=addAdmin.

Nov 8, 2024
CVE-2024-47190
2.7 LOW

Northern.tech Hosted Mender before 2024.07.11 allows SSRF.

Nov 8, 2024
CVE-2024-46948
4.3 MEDIUM

Northern.tech Mender before 3.6.5 and 3.7.x before 3.7.5 has Incorrect Access Control.

Nov 8, 2024
CVE-2024-46947
6.5 MEDIUM

Northern.tech Mender before 3.6.6 and 3.7.x before 3.7.7 allows SSRF.

Nov 8, 2024
CVE-2024-45765
9.1 CRITICAL

Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high …

Nov 8, 2024
CVE-2024-45764
9.0 CRITICAL

Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) a Missing Critical Step in Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this …

Nov 8, 2024
CVE-2024-50378
4.9 MEDIUM

Airflow versions before 2.10.3 have a vulnerability that allows authenticated users with audit log access to see sensitive values in audit logs which they should …

Nov 8, 2024
CVE-2024-50592
7.0 HIGH

An attacker with local access the to medical office computer can escalate his Windows user privileges to "NT AUTHORITY\SYSTEM" by exploiting a race condition in …

Nov 8, 2024
CVE-2024-50593
7.8 HIGH

An attacker with local access to the medical office computer can access restricted functions of the Elefant Service tool by using a hard-coded "Hotline" password …

Nov 8, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.