CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-10045
4.3 MEDIUM

The Transients Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.6. This is due to missing …

Oct 23, 2024
CVE-2024-9947
8.1 HIGH

The ProfilePress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.11.1. This is due to insufficient verification …

Oct 23, 2024
CVE-2024-9583
4.3 MEDIUM

The RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging plugin for WordPress is vulnerable to unauthorized use of functionality due to …

Oct 23, 2024
CVE-2024-9829
6.5 MEDIUM

The Download Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability checks on the 'dpwap_handle_download_user' and 'dpwap_handle_download_comment' functions …

Oct 23, 2024
CVE-2024-50066
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: mm/mremap: fix move_normal_pmd/retract_page_tables race In mremap(), move_page_tables() looks at the type of the PMD entry …

Oct 23, 2024
CVE-2024-9927
7.2 HIGH

The WooCommerce Order Proposal plugin for WordPress is vulnerable to privilege escalation via order proposal in all versions up to and including 2.0.5. This is …

Oct 23, 2024
CVE-2024-31880
5.3 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to a denial of service, under specific configurations, …

Oct 23, 2024
CVE-2024-7587
7.8 HIGH

Incorrect Default Permissions vulnerability in GenBroker32, which is included in the installers for Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric Iconics Digital Solutions …

Oct 22, 2024
CVE-2024-48657
7.2 HIGH

SQL Injection vulnerability in hospital management system in php with source code v.1.0.0 allows a remote attacker to execute arbitrary code.

Oct 22, 2024
CVE-2024-48656
4.8 MEDIUM

Cross Site Scripting vulnerability in student management system in php with source code v.1.0.0 allows a remote attacker to execute arbitrary code.

Oct 22, 2024
CVE-2024-48652
4.8 MEDIUM

Cross Site Scripting vulnerability in camaleon-cms v.2.7.5 allows remote attacker to execute arbitrary code via the content group name field.

Oct 22, 2024
CVE-2024-48644
5.3 MEDIUM

Accounts enumeration vulnerability in the Login Component of Reolink Duo 2 WiFi Camera (Firmware Version v3.0.0.1889_23031701) allows remote attackers to determine valid user accounts via …

Oct 22, 2024
CVE-2024-48415
5.0 MEDIUM

itsourcecode Loan Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload to the lastname, firstname, middlename, address, contact_no, email and …

Oct 22, 2024
CVE-2024-46914

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been …

Oct 22, 2024
CVE-2024-46483
9.8 CRITICAL

Xlight FTP Server <3.9.4.3 has an integer overflow vulnerability in the packet parsing logic of the SFTP server, which can lead to a heap overflow …

Oct 22, 2024
CVE-2024-46482
8.2 HIGH

An arbitrary file upload vulnerability in the Ticket Generation function of Ladybird Web Solution Faveo-Helpdesk v2.0.3 allows attackers to execute arbitrary code via uploading a …

Oct 22, 2024
CVE-2024-44812
9.8 CRITICAL

SQL Injection vulnerability in Online Complaint Site v.1.0 allows a remote attacker to escalate privileges via the username and password parameters in the /admin.index.php component.

Oct 22, 2024
CVE-2024-44331
7.5 HIGH

Incorrect Access Control in GStreamer RTSP server 1.25.0 in gst-rtsp-server/rtsp-media.c allows remote attackers to cause a denial of service via a series of specially crafted …

Oct 22, 2024
CVE-2024-43812
8.4 HIGH

Kieback & Peter's DDC4000 series has an insufficiently protected credentials vulnerability, which may allow an unauthenticated attacker with access to /etc/passwd to read the password …

Oct 22, 2024
CVE-2024-43698
9.8 CRITICAL

Kieback & Peter's DDC4000 series uses weak credentials, which may allow an unauthenticated attacker to get full admin rights on the system.

Oct 22, 2024
CVE-2024-42643
7.5 HIGH

Integer Overflow in fast_ping.c in SmartDNS Release46 allows remote attackers to cause a Denial of Service via misaligned memory access.

Oct 22, 2024
CVE-2024-41717
9.8 CRITICAL

Kieback & Peter's DDC4000 series is vulnerable to a path traversal vulnerability, which may allow an unauthenticated attacker to read files on the system.

Oct 22, 2024
CVE-2024-40494
9.8 CRITICAL

Buffer Overflow in coap_msg.c in FreeCoAP allows remote attackers to execute arbitrary code or cause a denial of service (stack buffer overflow) via a crafted …

Oct 22, 2024
CVE-2024-40493
9.8 CRITICAL

Null Pointer Dereference in `coap_client_exchange_blockwise2` function in Keith Cullen FreeCoAP 1.0 allows remote attackers to cause a denial of service and potentially execute arbitrary code …

Oct 22, 2024
CVE-2024-31029
8.2 HIGH

An issue in the server_handle_regular function of the test_coap_server.c file within the FreeCoAP project allows remote attackers to cause a Denial of Service through specially …

Oct 22, 2024
CVE-2024-26519
9.0 CRITICAL

An issue in Casa Systems NTC-221 version 2.0.99.0 and before allows a remote attacker to execute arbitrary code via a crafted payload to the /www/cgi-bin/nas.cgi …

Oct 22, 2024
CVE-2024-10231
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 130.0.6723.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Oct 22, 2024
CVE-2024-10230
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 130.0.6723.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Oct 22, 2024
CVE-2024-10229
8.1 HIGH

Inappropriate implementation in Extensions in Google Chrome prior to 130.0.6723.69 allowed a remote attacker to bypass site isolation via a crafted Chrome Extension. (Chromium security …

Oct 22, 2024
CVE-2024-48919

Cursor is a code editor built for programming with AI. Prior to Sep 27, 2024, if a user generated a terminal command via Cursor's Terminal …

Oct 22, 2024
CVE-2024-45526
5.3 MEDIUM

An issue was discovered in OPC Foundation OPCFoundation/UA-.NETStandard through 1.5.374.78. A remote attacker can send requests with invalid credentials and cause the server performance to …

Oct 22, 2024
CVE-2024-48904
9.8 CRITICAL

An command injection vulnerability in Trend Micro Cloud Edge could allow a remote attacker to execute arbitrary code on affected appliances. Please note: authentication is …

Oct 22, 2024
CVE-2024-48903
7.8 HIGH

An improper access control vulnerability in Trend Micro Deep Security Agent 20 could allow a local attacker to escalate privileges on affected installations. Please note: …

Oct 22, 2024
CVE-2024-46903
6.5 MEDIUM

A vulnerability in Trend Micro Deep Discovery Inspector (DDI) versions 5.8 and above could allow an attacker to disclose sensitive information affected installations. Please note: …

Oct 22, 2024
CVE-2024-46902
8.4 HIGH

A vulnerability in Trend Micro Deep Discovery Inspector (DDI) versions 5.8 and above could allow an attacker to disclose sensitive information affected installations. Please note: …

Oct 22, 2024
CVE-2024-45335
8.4 HIGH

Trend Micro Antivirus One, version 3.10.4 and below contains a vulnerability that could allow an attacker to use a specifically crafted virus to allow itself …

Oct 22, 2024
CVE-2024-45334
7.8 HIGH

Trend Micro Antivirus One versions 3.10.4 and below (Consumer) is vulnerable to an Arbitrary Configuration Update that could allow unauthorized access to product configurations and …

Oct 22, 2024
CVE-2024-41183
7.8 HIGH

Trend Micro VPN, version 5.8.1012 and below is vulnerable to an arbitrary file overwrite under specific conditions that can lead to elevation of privileges.

Oct 22, 2024
CVE-2024-39753
7.5 HIGH

An modOSCE SQL Injection vulnerability in Trend Micro Apex One could allow a remote attacker to execute arbitrary code on affected installations. Please note: an …

Oct 22, 2024
CVE-2024-10183

A vulnerability in Jamf Pro's Jamf Remote Assist tool allows a local, non-privileged user to escalate their privileges to root on MacOS systems.

Oct 22, 2024
CVE-2024-9287
7.8 HIGH

A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, …

Oct 22, 2024
CVE-2024-9129

In versions of Zend Server 8.5 and prior to version 9.2 a format string injection was discovered. Reported by Dylan Marino

Oct 22, 2024
CVE-2024-49211
5.2 MEDIUM

Reflected XSS was discovered in a Dashboard Listing Archer Platform UX page in Archer Platform 6.x before version 2024.08. A remote unauthenticated attacker could potentially …

Oct 22, 2024
CVE-2024-49210
5.2 MEDIUM

Reflected XSS was discovered in an iView List Archer Platform UX page in Archer Platform 6.x before version 2024.09. A remote unauthenticated attacker could potentially …

Oct 22, 2024
CVE-2024-49209
6.5 MEDIUM

Archer Platform 2024.03 before version 2024.09 is affected by an API authorization bypass vulnerability related to supporting application files. A remote unprivileged attacker could potentially …

Oct 22, 2024
CVE-2024-49208
5.9 MEDIUM

Archer Platform 2024.03 before version 2024.08 is affected by an authorization bypass vulnerability related to supporting application files. A remote unprivileged attacker could potentially exploit …

Oct 22, 2024
CVE-2024-48708
5.4 MEDIUM

Collabtive 3.1 is vulnerable to Cross-Site Scripting (XSS) via the name parameter in (a) file tasklist.php under action = add/edit and in (b) file admin.php …

Oct 22, 2024
CVE-2024-48707
5.4 MEDIUM

Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the name parameter under (a) action=add or action=edit within managemilestone.php file and (b) action=addpro within admin.php …

Oct 22, 2024
CVE-2024-48706
5.4 MEDIUM

Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the title parameter with action=add or action=editform within the (a) managemessage.php file and (b) managetask.php file …

Oct 22, 2024
CVE-2024-48570
7.5 HIGH

Client Management System 1.0 was discovered to contain a SQL injection vulnerability via the Between Dates Reports parameter at /admin/bwdates-reports-ds.php.

Oct 22, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.