CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-50177
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: fix a UBSAN warning in DML2.1 When programming phantom pipe, since cursor_width is explicity …

Nov 8, 2024
CVE-2024-50176
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: remoteproc: k3-r5: Fix error handling when power-up failed By simply bailing out, the driver was …

Nov 8, 2024
CVE-2024-50175
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: qcom: camss: Remove use_count guard in stop_streaming The use_count check was introduced so that …

Nov 8, 2024
CVE-2024-50174
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Fix race when converting group handle to group object XArray provides it's own internal …

Nov 8, 2024
CVE-2024-50173
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Fix access to uninitialized variable in tick_ctx_cleanup() The group variable can't be used to …

Nov 8, 2024
CVE-2024-10994
6.3 MEDIUM

A vulnerability has been found in Codezips Online Institute Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Nov 8, 2024
CVE-2024-10993
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Codezips Online Institute Management System 1.0. Affected is an unknown function of the file /manage_website.php. …

Nov 8, 2024
CVE-2024-10621
6.4 MEDIUM

The Simple Shortcode for Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's pw_map shortcode in all versions up to, …

Nov 8, 2024
CVE-2024-21538
7.5 HIGH

Versions of the package cross-spawn before 6.0.6, from 7.0.0 and before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input …

Nov 8, 2024
CVE-2024-10991
7.3 HIGH

A vulnerability, which was classified as critical, has been found in Codezips Hospital Appointment System 1.0. This issue affects some unknown processing of the file …

Nov 8, 2024
CVE-2024-10990
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Online Veterinary Appointment System 1.0. This vulnerability affects unknown code of the file /admin/services/view_service.php. The manipulation …

Nov 8, 2024
CVE-2023-27195
9.8 CRITICAL

Trimble TM4Web 22.2.0 allows unauthenticated attackers to access /inc/tm_ajax.msw?func=UserfromUUID&uuid= to retrieve the last registration access code and use this access code to register a valid …

Nov 8, 2024
CVE-2020-8007
9.8 CRITICAL

The pwrstudio web application of EV Charger (in the server in Circontrol Raption through 5.6.2) is vulnerable to OS command injection via three fields of …

Nov 8, 2024
CVE-2024-10989
6.3 MEDIUM

A vulnerability classified as critical has been found in code-projects E-Health Care System 1.0. This affects an unknown part of the file /Admin/detail.php. The manipulation …

Nov 8, 2024
CVE-2024-10988
7.3 HIGH

A vulnerability was found in code-projects E-Health Care System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Nov 8, 2024
CVE-2024-10987
6.3 MEDIUM

A vulnerability was found in code-projects E-Health Care System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Nov 8, 2024
CVE-2024-48011
3.1 LOW

Dell PowerProtect DD, versions prior to 7.7.5.50, contains an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. A low privileged attacker with remote access …

Nov 8, 2024
CVE-2024-48010
6.5 MEDIUM

Dell PowerProtect DD, versions prior to 8.1.0.0, 7.13.1.10, 7.10.1.40, and 7.7.5.50, contains an access control vulnerability. A remote high privileged attacker could potentially exploit this …

Nov 8, 2024
CVE-2024-45759
6.8 MEDIUM

Dell PowerProtect Data Domain, versions prior to 8.1.0.0, 7.13.1.10, 7.10.1.40, and 7.7.5.50, contains an escalation of privilege vulnerability. A local low privileged attacker could potentially …

Nov 8, 2024
CVE-2024-8424
7.8 HIGH

Improper Privilege Management vulnerability in WatchGuard EPDR, Panda AD360 and Panda Dome on Windows (PSANHost.exe module) allows arbitrary file delete with SYSTEM permissions. This issue …

Nov 8, 2024
CVE-2024-51998
8.6 HIGH

changedetection.io is a free open source web page change detection tool. The validation for the file URI scheme falls short, and results in an attacker …

Nov 8, 2024
CVE-2024-51987
5.4 MEDIUM

Duende.AccessTokenManagement.OpenIdConnect is a set of .NET libraries that manage OAuth and OpenId Connect access tokens. HTTP Clients created by `AddUserAccessTokenHttpClient` may use a different user's …

Nov 8, 2024
CVE-2024-47072
7.5 HIGH

XStream is a simple library to serialize objects to XML and back again. This vulnerability may allow a remote attacker to terminate the application with …

Nov 8, 2024
CVE-2024-8810
6.5 MEDIUM

A GitHub App installed in organizations could upgrade some permissions from read to write access without approval from an organization administrator. An attacker would require …

Nov 7, 2024
CVE-2024-51434
6.1 MEDIUM

Inconsistent <plaintext> tag parsing allows for XSS in Froala WYSIWYG editor 4.3.0 and earlier.

Nov 7, 2024
CVE-2024-50766
9.8 CRITICAL

SourceCodester Survey Application System 1.0 is vulnerable to SQL Injection in takeSurvey.php via the id parameter.

Nov 7, 2024
CVE-2024-49524
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute …

Nov 7, 2024
CVE-2024-49523
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject …

Nov 7, 2024
CVE-2024-46961
8.1 HIGH

The Inshot com.downloader.privatebrowser (aka Video Downloader - XDownloader) application through 1.3.5 for Android allows an attacker to execute arbitrary JavaScript code via the com.downloader.privatebrowser.activity.PrivateMainActivity component.

Nov 7, 2024
CVE-2024-46960
8.8 HIGH

The ASD com.rocks.video.downloader (aka HD Video Downloader All Format) application through 7.0.129 for Android allows an attacker to execute arbitrary JavaScript code via the com.rocks.video.downloader.MainBrowserActivity …

Nov 7, 2024
CVE-2024-36064
6.2 MEDIUM

The NLL com.nll.cb (aka ACR Phone) application through 0.330-playStore-NoAccessibility-arm8 for Android allows any installed application (with no permissions) to place phone calls without user interaction …

Nov 7, 2024
CVE-2024-36063
7.5 HIGH

The Goodwy com.goodwy.dialer (aka Right Dialer) application through 5.1.0 for Android enables any application (with no permissions) to place phone calls without user interaction by …

Nov 7, 2024
CVE-2024-36062
4.0 MEDIUM

The com.callassistant.android (aka AI Call Assistant & Screener) application 1.174 for Android enables any installed application (with no permissions) to place phone calls without user …

Nov 7, 2024
CVE-2024-10824
6.5 MEDIUM

An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed unauthorized internal users to access sensitive secret scanning alert data intended only for …

Nov 7, 2024
CVE-2024-50599
6.1 MEDIUM

A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Zimbra Collaboration Suite (ZCS) 8.8.15, affecting one of the webmail calendar endpoints. This arises from …

Nov 7, 2024
CVE-2024-10975
7.7 HIGH

Nomad Community and Nomad Enterprise ("Nomad") volume specification is vulnerable to arbitrary cross-namespace volume creation through unauthorized Container Storage Interface (CSI) volume writes. This vulnerability, …

Nov 7, 2024
CVE-2024-10007
9.1 CRITICAL

A path collision and arbitrary code execution vulnerability was identified in GitHub Enterprise Server that allowed container escape to escalate to root via ghe-firejail path. …

Nov 7, 2024
CVE-2019-20472
6.2 MEDIUM

An issue was discovered on One2Track 2019-12-08 devices. Any SIM card used with the device cannot have a PIN configured. If a PIN is configured, …

Nov 7, 2024
CVE-2019-20469
4.6 MEDIUM

An issue was discovered on One2Track 2019-12-08 devices. Confidential information is needlessly stored on the smartwatch. Audio files are stored in .amr format, in the …

Nov 7, 2024
CVE-2019-20462
5.3 MEDIUM

An issue was discovered on Alecto IVM-100 2019-11-12 devices. The device comes with a serial interface at the board level. By attaching to this serial …

Nov 7, 2024
CVE-2019-20461
9.8 CRITICAL

An issue was discovered on Alecto IVM-100 2019-11-12 devices. The device uses a custom UDP protocol to start and control video and audio services. The …

Nov 7, 2024
CVE-2019-20460
8.8 HIGH

An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices. POST requests don't require (anti-)CSRF tokens or other mechanisms for validating that the request …

Nov 7, 2024
CVE-2024-10969
7.3 HIGH

A vulnerability was found in 1000 Projects Bookstore Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

Nov 7, 2024
CVE-2024-10968
7.3 HIGH

A vulnerability was found in 1000 Projects Bookstore Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Nov 7, 2024
CVE-2024-51995
7.1 HIGH

Combodo iTop is a web based IT Service Management tool. An attacker can request any `route` we want as long as we specify an `operation` …

Nov 7, 2024
CVE-2024-51994
5.4 MEDIUM

Combodo iTop is a web based IT Service Management tool. In affected versions uploading a text file containing some java script in the portal will …

Nov 7, 2024
CVE-2024-51993
3.4 LOW

Combodo iTop is a web based IT Service Management tool. An attacker accessing a backup file or the database can read some passwords for misconfigured …

Nov 7, 2024
CVE-2024-51989
7.1 HIGH

Password Pusher is an open source application to communicate sensitive information over the web. A cross-site scripting (XSS) vulnerability was identified in the PasswordPusher application, …

Nov 7, 2024
CVE-2024-51758

Filament is a collection of full-stack components for accelerated Laravel development. All Filament features that interact with storage use the `default_filesystem_disk` config option. This allows …

Nov 7, 2024
CVE-2024-51428
7.5 HIGH

An issue in Espressif Esp idf v5.3.0 allows attackers to cause a Denial of Service (DoS) via a crafted data channel packet.

Nov 7, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.