CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-48290
4.3 MEDIUM

An issue in the Bluetooth Low Energy implementation of Realtek RTL8762E BLE SDK v1.4.0 allows attackers to cause a Denial of Service (DoS) via supplying …

Nov 7, 2024
CVE-2024-47073
9.1 CRITICAL

DataEase is an open source data visualization analysis tool that helps users quickly analyze data and gain insights into business trends. In affected versions a …

Nov 7, 2024
CVE-2024-45794
8.3 HIGH

devtron is an open source tool integration platform for Kubernetes. In affected versions an authenticated user (with minimum permission) could utilize and exploit SQL Injection …

Nov 7, 2024
CVE-2024-10967
7.3 HIGH

A vulnerability was found in code-projects E-Health Care System 1.0. It has been classified as critical. Affected is an unknown function of the file /Doctor/delete_user_appointment_request.php. …

Nov 7, 2024
CVE-2024-10966
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in TOTOLINK X18 9.1.0cu.2024_B20220329. Affected by this issue is some unknown functionality of the file …

Nov 7, 2024
CVE-2020-11926
7.5 HIGH

An issue was discovered in Luvion Grand Elite 3 Connect through 2020-02-25. Clients can authenticate themselves to the device using a username and password. These …

Nov 7, 2024
CVE-2020-11921
8.8 HIGH

An issue was discovered in Lush 2 through 2020-02-25. Due to the lack of Bluetooth traffic encryption, it is possible to hijack an ongoing Bluetooth …

Nov 7, 2024
CVE-2020-11919
8.0 HIGH

An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. There is no CSRF protection.

Nov 7, 2024
CVE-2020-11918
5.4 MEDIUM

An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. When a backup file is created through the web interface, information on all users, including passwords, can …

Nov 7, 2024
CVE-2020-11917
4.3 MEDIUM

An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. It uses a default SSID value, which makes it easier for remote attackers to discover the physical …

Nov 7, 2024
CVE-2020-11916
6.3 MEDIUM

An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. The password for the root user is hashed using an old and deprecated hashing technique. Because of …

Nov 7, 2024
CVE-2019-20459
8.4 HIGH

An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices. With the SNMPv1 public community, all values can be read, and with the epson …

Nov 7, 2024
CVE-2019-20458
8.8 HIGH

An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices. By default, the device comes (and functions) without a password. The user is at …

Nov 7, 2024
CVE-2019-20457
9.1 CRITICAL

An issue was discovered on Brother MFC-J491DW C1806180757 devices. The printer's web-interface password hash can be retrieved without authentication, because the response header of any …

Nov 7, 2024
CVE-2024-48954
6.4 MEDIUM

An issue was discovered in Logpoint before 7.5.0. Unvalidated input during the EventHub Collector setup by an authenticated user leads to Remote Code execution.

Nov 7, 2024
CVE-2024-48953
7.5 HIGH

An issue was discovered in Logpoint before 7.5.0. Endpoints for creating, editing, or deleting third-party authentication modules lacked proper authorization checks. This allowed unauthenticated users …

Nov 7, 2024
CVE-2024-48952
6.4 MEDIUM

An issue was discovered in Logpoint before 7.5.0. SOAR uses a static JWT secret key to generate tokens that allow access to SOAR API endpoints …

Nov 7, 2024
CVE-2024-48951
7.5 HIGH

An issue was discovered in Logpoint before 7.5.0. Server-Side Request Forgery (SSRF) on SOAR can be used to leak Logpoint's API Token leading to authentication …

Nov 7, 2024
CVE-2024-48950
7.5 HIGH

An issue was discovered in Logpoint before 7.5.0. An endpoint used by Distributed Logpoint Setup was exposed, allowing unauthenticated attackers to bypass CSRF protections and …

Nov 7, 2024
CVE-2024-40715
7.7 HIGH

A vulnerability in Veeam Backup & Replication Enterprise Manager has been identified, which allows attackers to perform authentication bypass. Attackers must be able to perform …

Nov 7, 2024
CVE-2024-10965
4.3 MEDIUM

A vulnerability classified as problematic was found in emqx neuron up to 2.10.0. Affected by this vulnerability is an unknown functionality of the file /api/v2/schema …

Nov 7, 2024
CVE-2024-10964
6.3 MEDIUM

A vulnerability classified as critical has been found in emqx neuron up to 2.10.0. Affected is the function handle_add_plugin in the library cmd.library of the …

Nov 7, 2024
CVE-2024-8378
4.8 MEDIUM

The Safe SVG WordPress plugin before 2.2.6 has its sanitisation code is only running for paths that call wp_handle_upload, but not for example for code …

Nov 7, 2024
CVE-2024-10963
7.4 HIGH

A flaw was found in pam_access, where certain rules in its configuration file are mistakenly treated as hostnames. This vulnerability allows attackers to trick the …

Nov 7, 2024
CVE-2024-10668
7.5 HIGH

There exists an auth bypass in Google Quickshare where an attacker can upload an unknown file type to a victim. The root cause of the …

Nov 7, 2024
CVE-2024-9926
4.3 MEDIUM

The Jetpack WordPress plugin does not have proper authorisation in one of its REST endpoint, allowing any authenticated users, such as subscriber to read arbitrary …

Nov 7, 2024
CVE-2024-43440
7.5 HIGH

A flaw was found in moodle. A local file may include risks when restoring block backups.

Nov 7, 2024
CVE-2024-43438
7.5 HIGH

A flaw was found in Feedback. Bulk messaging in the activity's non-respondents report did not verify message recipients belonging to the set of users returned …

Nov 7, 2024
CVE-2024-43436
7.2 HIGH

A SQL injection risk flaw was found in the XMLDB editor tool available to site administrators.

Nov 7, 2024
CVE-2024-43434
8.1 HIGH

The bulk message sending feature in Moodle's Feedback module's non-respondents report had an incorrect CSRF token check, leading to a CSRF vulnerability.

Nov 7, 2024
CVE-2024-43431
7.5 HIGH

A vulnerability was found in Moodle. Insufficient capability checks made it possible to delete badges that a user does not have permission to access.

Nov 7, 2024
CVE-2024-43428
7.7 HIGH

To address a cache poisoning risk in Moodle, additional validation for local storage was required.

Nov 7, 2024
CVE-2024-43426
7.5 HIGH

A flaw was found in pdfTeX. Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is …

Nov 7, 2024
CVE-2024-43425
8.1 HIGH

A flaw was found in Moodle. Additional restrictions are required to avoid a remote code execution risk in calculated question types. Note: This requires the …

Nov 7, 2024
CVE-2024-8442
6.4 MEDIUM

The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Nov 7, 2024
CVE-2024-24914
8.0 HIGH

Authenticated Gaia users can inject code or commands by global variables through special HTTP requests. A Security fix that mitigates this vulnerability is available.

Nov 7, 2024
CVE-2024-10526

Rapid7 Velociraptor MSI Installer versions below 0.73.3 suffer from a vulnerability whereby it creates the installation directory with WRITE_DACL permission to the BUILTIN\\Users group. This …

Nov 7, 2024
CVE-2024-51504
9.1 CRITICAL

When using IPAuthenticationProvider in ZooKeeper Admin Server there is a possibility of Authentication Bypass by Spoofing -- this only impacts IP based authentication implemented in …

Nov 7, 2024
CVE-2024-50172
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Fix a possible memory leak In bnxt_re_setup_chip_ctx() when bnxt_qplib_map_db_bar() fails driver is not freeing …

Nov 7, 2024
CVE-2024-50171
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: systemport: fix potential memory leak in bcm_sysport_xmit() The bcm_sysport_xmit() returns NETDEV_TX_OK without freeing skb …

Nov 7, 2024
CVE-2024-50170
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: bcmasp: fix potential memory leak in bcmasp_xmit() The bcmasp_xmit() returns NETDEV_TX_OK without freeing skb …

Nov 7, 2024
CVE-2024-50169
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: vsock: Update rx_bytes on read_skb() Make sure virtio_transport_inc_rx_pkt() and virtio_transport_dec_rx_pkt() calls are balanced (i.e. virtio_vsock_sock::rx_bytes …

Nov 7, 2024
CVE-2024-50168
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/sun3_82586: fix potential memory leak in sun3_82586_send_packet() The sun3_82586_send_packet() returns NETDEV_TX_OK without freeing skb in …

Nov 7, 2024
CVE-2024-50167
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: be2net: fix potential memory leak in be_xmit() The be_xmit() returns NETDEV_TX_OK without freeing skb in …

Nov 7, 2024
CVE-2024-50166
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fsl/fman: Fix refcount handling of fman-related devices In mac_probe() there are multiple calls to of_find_device_by_node(), …

Nov 7, 2024
CVE-2024-50165
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: Preserve param->string when parsing mount options In bpf_parse_param(), keep the value of param->string intact …

Nov 7, 2024
CVE-2024-50164
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix overloading of MEM_UNINIT's meaning Lonial reported an issue in the BPF verifier where …

Nov 7, 2024
CVE-2024-50163
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: Make sure internal and UAPI bpf_redirect flags don't overlap The bpf_redirect_info is shared between …

Nov 7, 2024
CVE-2024-50162
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: devmap: provide rxq after redirect rxq contains a pointer to the device from where …

Nov 7, 2024
CVE-2024-50161
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: Check the remaining info_cnt before repeating btf fields When trying to repeat the btf …

Nov 7, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.