CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-10004
9.1 CRITICAL

Opening an external link to an HTTP website when Firefox iOS was previously closed and had an HTTPS tab open could in some cases result …

Oct 15, 2024
CVE-2024-9966
5.3 MEDIUM

Inappropriate implementation in Navigations in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium …

Oct 15, 2024
CVE-2024-9965
8.8 HIGH

Insufficient data validation in DevTools in Google Chrome on Windows prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific …

Oct 15, 2024
CVE-2024-9964
4.3 MEDIUM

Inappropriate implementation in Payments in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to …

Oct 15, 2024
CVE-2024-9963
4.3 MEDIUM

Insufficient data validation in Downloads in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures …

Oct 15, 2024
CVE-2024-9962
4.3 MEDIUM

Inappropriate implementation in Permissions in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific UI gestures to …

Oct 15, 2024
CVE-2024-9961
8.8 HIGH

Use after free in ParcelTracking in Google Chrome on iOS prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific …

Oct 15, 2024
CVE-2024-9960
7.5 HIGH

Use after free in Dawn in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Oct 15, 2024
CVE-2024-9959
8.8 HIGH

Use after free in DevTools in Google Chrome prior to 130.0.6723.58 allowed a remote attacker who had compromised the renderer process to potentially exploit heap …

Oct 15, 2024
CVE-2024-9958
4.3 MEDIUM

Inappropriate implementation in PictureInPicture in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security …

Oct 15, 2024
CVE-2024-9957
8.8 HIGH

Use after free in UI in Google Chrome on iOS prior to 130.0.6723.58 allowed a remote attacker who convinced a user to engage in specific …

Oct 15, 2024
CVE-2024-9956
7.8 HIGH

Inappropriate implementation in WebAuthentication in Google Chrome on Android prior to 130.0.6723.58 allowed a local attacker to perform privilege escalation via a crafted HTML page. …

Oct 15, 2024
CVE-2024-9955
8.8 HIGH

Use after free in WebAuthentication in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Oct 15, 2024
CVE-2024-9954
8.8 HIGH

Use after free in AI in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Oct 15, 2024
CVE-2024-9594
6.3 MEDIUM

A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build process when using …

Oct 15, 2024
CVE-2024-9486
9.8 CRITICAL

A security issue was discovered in the Kubernetes Image Builder versions <= v0.1.37 where default credentials are enabled during the image build process. Virtual machine …

Oct 15, 2024
CVE-2024-48783
7.5 HIGH

An issue in Ruijie NBR3000D-E Gateway allows a remote attacker to obtain sensitive information via the /tool/shell/postgresql.conf component.

Oct 15, 2024
CVE-2024-48782
9.8 CRITICAL

File Upload vulnerability in DYCMS Open-Source Version v2.0.9.41 allows a remote attacker to execute arbitrary code via the application only detecting the extension of image …

Oct 15, 2024
CVE-2024-48781
9.8 CRITICAL

An issue in Wanxing Technology Yitu Project Management Kirin Edition 2.3.6 allows a remote attacker to execute arbitrary code via a specially constructed so file/opt/EdrawProj-2/plugins/imageformat.

Oct 15, 2024
CVE-2024-48779
9.8 CRITICAL

An issue in Wanxing Technology's Yitu project Management Software 3.2.2 allows a remote attacker to execute arbitrary code via the platformpluginpath parameter to specify that …

Oct 15, 2024
CVE-2024-48714
6.5 MEDIUM

In TP-Link TL-WDR7660 v1.0, the guestRuleJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities.

Oct 15, 2024
CVE-2024-48713
6.5 MEDIUM

In TP-Link TL-WDR7660 1.0, the wacWhitelistJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities.

Oct 15, 2024
CVE-2024-48712
6.5 MEDIUM

In TP-Link TL-WDR7660 1.0, the rtRuleJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities.

Oct 15, 2024
CVE-2024-48710
6.5 MEDIUM

In TP-Link TL-WDR7660 1.0, the wlanTimerRuleJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities.

Oct 15, 2024
CVE-2024-48411
9.8 CRITICAL

itsourcecode Online Tours and Travels Management System v1.0 is vulnerable to SQL Injection (SQLI) via a crafted payload to the val-email parameter in forget_password.php.

Oct 15, 2024
CVE-2024-44775
7.5 HIGH

kmqtt v0.2.7 is vulnerable to Denial of Service (DoS) due to a Null Pointer Exception. A remote attacker can cause the broker to crash by …

Oct 15, 2024
CVE-2024-41311
8.1 HIGH

In Libheif 1.17.6, insufficient checks in ImageOverlay::parse() decoding a heif file containing an overlay image with forged offsets can lead to an out-of-bounds read and …

Oct 15, 2024
CVE-2024-31955
4.9 MEDIUM

An issue was discovered in Samsung eMMC with KLMAG2GE4A and KLM8G1WEMB firmware. Code bypass through Electromagnetic Fault Injection allows an attacker to successfully authenticate and …

Oct 15, 2024
CVE-2024-49195
9.8 CRITICAL

Mbed TLS 3.5.x through 3.6.x before 3.6.2 has a buffer underrun in pkwrite when writing an opaque key pair

Oct 15, 2024
CVE-2024-44337
5.1 MEDIUM

The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Prior to pseudoversion `v0.0.0-20240729232818-a2a9c4f`, which corresponds with commit `a2a9c4f76ef5a5c32108e36f7c47f8d310322252`, there …

Oct 15, 2024
CVE-2024-21286
5.4 MEDIUM

Vulnerability in the PeopleSoft Enterprise ELM Enterprise Learning Management product of Oracle PeopleSoft (component: Enterprise Learning Management). The supported version that is affected is 9.2. …

Oct 15, 2024
CVE-2024-21285
7.1 HIGH

Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Reports). The supported version that is affected is 14.5.0.12.0. Difficult to …

Oct 15, 2024
CVE-2024-21284
7.1 HIGH

Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Reports). The supported version that is affected is 14.5.0.12.0. Difficult to …

Oct 15, 2024
CVE-2024-21283
8.1 HIGH

Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Core product of Oracle PeopleSoft (component: Global Payroll for Core). Supported versions that are affected are 9.2.48-9.2.50. …

Oct 15, 2024
CVE-2024-21282
8.1 HIGH

Vulnerability in the Oracle Financials product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low …

Oct 15, 2024
CVE-2024-21281
5.3 MEDIUM

Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Infrastructure). The supported version that is affected is 14.7.0.6.0. Difficult to …

Oct 15, 2024
CVE-2024-21280
8.1 HIGH

Vulnerability in the Oracle Service Contracts product of Oracle E-Business Suite (component: Authoring). Supported versions that are affected are 12.2.5-12.2.13. Easily exploitable vulnerability allows low …

Oct 15, 2024
CVE-2024-21279
8.1 HIGH

Vulnerability in the Oracle Sourcing product of Oracle E-Business Suite (component: Auctions). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged …

Oct 15, 2024
CVE-2024-21278
8.1 HIGH

Vulnerability in the Oracle Contract Lifecycle Management for Public Sector product of Oracle E-Business Suite (component: Award Processes). Supported versions that are affected are 12.2.3-12.2.13. …

Oct 15, 2024
CVE-2024-21277
8.1 HIGH

Vulnerability in the Oracle MES for Process Manufacturing product of Oracle E-Business Suite (component: Device Integration). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable …

Oct 15, 2024
CVE-2024-21276
8.1 HIGH

Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Messages). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows …

Oct 15, 2024
CVE-2024-21275
8.1 HIGH

Vulnerability in the Oracle Quoting product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.2.7-12.2.13. Easily exploitable vulnerability allows low …

Oct 15, 2024
CVE-2024-21274
7.5 HIGH

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability …

Oct 15, 2024
CVE-2024-21273
6.0 MEDIUM

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.22 and prior to 7.1.2. …

Oct 15, 2024
CVE-2024-21272
7.5 HIGH

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Python). Supported versions that are affected are 9.0.0 and prior. Difficult to exploit vulnerability allows …

Oct 15, 2024
CVE-2024-21271
8.1 HIGH

Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Field Service Engineer Portal). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable …

Oct 15, 2024
CVE-2024-21270
8.1 HIGH

Vulnerability in the Oracle Common Applications Calendar product of Oracle E-Business Suite (component: Tasks). Supported versions that are affected are 12.2.6-12.2.13. Easily exploitable vulnerability allows …

Oct 15, 2024
CVE-2024-21269
8.1 HIGH

Vulnerability in the Oracle Incentive Compensation product of Oracle E-Business Suite (component: Compensation Plan). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows …

Oct 15, 2024
CVE-2024-21268
8.1 HIGH

Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Diagnostics). Supported versions that are affected are 12.2.11-12.2.13. Easily exploitable vulnerability allows low …

Oct 15, 2024
CVE-2024-21267
8.1 HIGH

Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported versions that are affected are 12.2.12-12.2.13. Easily exploitable vulnerability allows …

Oct 15, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.