CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-51665
4.9 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in Noor Alam Magical Addons For Elementor magical-addons-for-elementor allows Server Side Request Forgery.This issue affects Magical Addons For Elementor: from …

Nov 4, 2024
CVE-2024-51582
7.5 HIGH

Path Traversal: '.../...//' vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows PHP Local File Inclusion.This issue affects WP Hotel Booking: from n/a through <= 2.2.9.

Nov 4, 2024
CVE-2024-51408
8.5 HIGH

AppSmith Community 1.8.3 before 1.46 allows SSRF via New DataSource for application/json requests to 169.254.169.254 to retrieve AWS metadata credentials.

Nov 4, 2024
CVE-2024-51253
8.0 HIGH

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doL2TP function.

Nov 4, 2024
CVE-2024-51251
8.0 HIGH

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the backup function.

Nov 4, 2024
CVE-2024-51249
8.0 HIGH

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the reboot function.

Nov 4, 2024
CVE-2024-51246
8.0 HIGH

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPTP function.

Nov 4, 2024
CVE-2024-50531
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in davidfcarr RSVPMaker for Toastmasters rsvpmaker-for-toastmasters allows Upload a Web Shell to a Web Server.This issue affects …

Nov 4, 2024
CVE-2024-50530
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Myriad Solutionz Stars SMTP Mailer stars-smtp-mailer allows Upload a Web Shell to a Web Server.This issue …

Nov 4, 2024
CVE-2024-50529
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in rudrainn Training – Courses training allows Upload a Web Shell to a Web Server.This issue affects …

Nov 4, 2024
CVE-2024-50528
7.5 HIGH

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Retrieve Embedded Sensitive Data.This issue affects …

Nov 4, 2024
CVE-2024-50527
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Stacks Stacks Mobile App Builder stacks-mobile-app-builder allows Upload a Web Shell to a Web Server.This issue …

Nov 4, 2024
CVE-2024-50526
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Lindeni Mahlalela Multi Purpose Mail Form multi-purpose-mail-form allows Upload a Web Shell to a Web Server.This …

Nov 4, 2024
CVE-2024-50525
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in helloprint Helloprint helloprint allows Upload a Web Shell to a Web Server.This issue affects Helloprint: from …

Nov 4, 2024
CVE-2024-50523
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in RainbowLink Inc. All Post Contact Form allpost-contactform allows Upload a Web Shell to a Web Server.This …

Nov 4, 2024
CVE-2024-45164
7.1 HIGH

Akamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the latest 19.2.0 patch and Apps Portal before 19.2.0.3 or 19.2.0.20240814, …

Nov 4, 2024
CVE-2024-9147
6.1 MEDIUM

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Bna Informatics PosPratik allows XSS Through HTTP Query Strings.This issue affects …

Nov 4, 2024
CVE-2024-51561
7.5 HIGH

This vulnerability exists in Aero due to improper implementation of OTP validation mechanism in certain API endpoints. An authenticated remote attacker could exploit this vulnerability …

Nov 4, 2024
CVE-2024-51560
4.3 MEDIUM

This vulnerability exists in the Wave 2.0 due to improper exception handling for invalid inputs at certain API endpoint. An authenticated remote attacker could exploit …

Nov 4, 2024
CVE-2024-51559
6.5 MEDIUM

This vulnerability exists in the Wave 2.0 due to improper authorization checks on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by …

Nov 4, 2024
CVE-2024-51558
9.8 CRITICAL

This vulnerability exists in the Wave 2.0 due to missing restrictions for excessive failed authentication attempts on its API based login. A remote attacker could …

Nov 4, 2024
CVE-2024-51557
6.5 MEDIUM

This vulnerability exists in the Wave 2.0 due to missing rate limiting on OTP requests in an API endpoint. An authenticated remote attacker could exploit …

Nov 4, 2024
CVE-2024-51556
6.5 MEDIUM

This vulnerability exists in the Wave 2.0 due to insufficient encryption of sensitive data received at the API response. An authenticated remote attacker could exploit …

Nov 4, 2024
CVE-2024-36485
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to SQL Injection in Technician reports option.

Nov 4, 2024
CVE-2024-10523
4.6 MEDIUM

This vulnerability exists in TP-Link IoT Smart Hub due to storage of Wi-Fi credentials in plain text within the device firmware. An attacker with physical …

Nov 4, 2024
CVE-2024-10035
9.8 CRITICAL

Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Special Elements used in a Command ('Command Injection'), Improper Neutralization of Special Elements used …

Nov 4, 2024
CVE-2024-51661
9.1 CRITICAL

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Command Injection.This issue …

Nov 4, 2024
CVE-2024-48878
8.3 HIGH

Zohocorp ManageEngine ADManager Plus versions 7241 and prior are vulnerable to SQL Injection in Archived Audit Report.

Nov 4, 2024
CVE-2024-10389
7.5 HIGH

There exists a Path Traversal vulnerability in Safearchive on Platforms with Case-Insensitive Filesystems (e.g., NTFS). This allows Attackers to Write Arbitrary Files via Archive Extraction …

Nov 4, 2024
CVE-2024-38424
7.8 HIGH

Memory corruption during GNSS HAL process initialization.

Nov 4, 2024
CVE-2024-38423
7.8 HIGH

Memory corruption while processing GPU page table switch.

Nov 4, 2024
CVE-2024-38422
7.8 HIGH

Memory corruption while processing voice packet with arbitrary data received from ADSP.

Nov 4, 2024
CVE-2024-38421
7.8 HIGH

Memory corruption while processing GPU commands.

Nov 4, 2024
CVE-2024-38419
7.8 HIGH

Memory corruption while invoking IOCTL calls from the use-space for HGSL memory node.

Nov 4, 2024
CVE-2024-38415
7.8 HIGH

Memory corruption while handling session errors from firmware.

Nov 4, 2024
CVE-2024-38410
7.8 HIGH

Memory corruption while IOCLT is called when device is in invalid state and the WMI command buffer may be freed twice.

Nov 4, 2024
CVE-2024-38409
7.8 HIGH

Memory corruption while station LL statistic handling.

Nov 4, 2024
CVE-2024-38408
8.2 HIGH

Cryptographic issue when a controller receives an LMP start encryption command under unexpected conditions.

Nov 4, 2024
CVE-2024-38407
7.8 HIGH

Memory corruption while processing input parameters for any IOCTL call in the JPEG Encoder driver.

Nov 4, 2024
CVE-2024-38406
7.8 HIGH

Memory corruption while handling IOCTL calls in JPEG Encoder driver.

Nov 4, 2024
CVE-2024-38405
7.5 HIGH

Transient DOS while processing the CU information from RNR IE.

Nov 4, 2024
CVE-2024-38403
7.5 HIGH

Transient DOS while parsing BTM ML IE when per STA profile is not included.

Nov 4, 2024
CVE-2024-33068
7.5 HIGH

Transient DOS while parsing fragments of MBSSID IE from beacon frame.

Nov 4, 2024
CVE-2024-33033
6.7 MEDIUM

Memory corruption while processing IOCTL calls to unmap the buffers.

Nov 4, 2024
CVE-2024-33032
6.7 MEDIUM

Memory corruption when the user application modifies the same shared memory asynchronously when kernel is accessing it.

Nov 4, 2024
CVE-2024-33031
6.7 MEDIUM

Memory corruption while processing the update SIM PB records request.

Nov 4, 2024
CVE-2024-33030
6.7 MEDIUM

Memory corruption while parsing IPC frequency table parameters for LPLH that has size greater than expected size.

Nov 4, 2024
CVE-2024-33029
6.7 MEDIUM

Memory corruption while handling the PDR in driver for getting the remote heap maps.

Nov 4, 2024
CVE-2024-23590
9.1 CRITICAL

Session Fixation vulnerability in Apache Kylin. This issue affects Apache Kylin: from 2.0.0 through 4.x. Users are recommended to upgrade to version 5.0.0 or above, …

Nov 4, 2024
CVE-2024-23386
6.7 MEDIUM

memory corruption when WiFi display APIs are invoked with large random inputs.

Nov 4, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.