CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-48793
5.9 MEDIUM

An issue in INATRONIC com.inatronic.bmw 2.7.1 allows a remote attacker to obtain sensitive information via the firmware update process.

Oct 14, 2024
CVE-2024-48792
7.5 HIGH

An issue in Hideez com.hideez 2.7.8.3 allows a remote attacker to obtain sensitive information via the firmware update process.

Oct 14, 2024
CVE-2024-48791
7.5 HIGH

An issue in Plug n Play Camera com.starvedia.mCamView.zwave 5.5.1 allows a remote attacker to obtain sensitive information via the firmware update process

Oct 14, 2024
CVE-2024-48790
5.3 MEDIUM

An issue in ILIFE com.ilife.home.global 1.8.7 allows a remote attacker to obtain sensitive information via the firmware update process.

Oct 14, 2024
CVE-2024-48789
7.5 HIGH

An issue in INATRONIC com.inatronic.drivedeck.home 2.6.23 allows a remote attacker to obtain sensitve information via the firmware update process.

Oct 14, 2024
CVE-2024-47831
5.9 MEDIUM

Next.js is a React Framework for the Web. Cersions on the 10.x, 11.x, 12.x, 13.x, and 14.x branches before version 14.2.7 contain a vulnerability in …

Oct 14, 2024
CVE-2024-47826
3.5 LOW

eLabFTW is an open source electronic lab notebook for research labs. A vulnerability in versions prior to 5.1.5 allows an attacker to inject arbitrary HTML …

Oct 14, 2024
CVE-2024-47767
4.3 MEDIUM

Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.113, Tuleap Enterprise Edition 15.13-5, and …

Oct 14, 2024
CVE-2024-47766
4.9 MEDIUM

Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.110, Tuleap Enterprise Edition 15.13-5, and …

Oct 14, 2024
CVE-2024-46988
4.8 MEDIUM

Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.40, Tuleap Enterprise Edition 15.13-3, and …

Oct 14, 2024
CVE-2024-46980
4.8 MEDIUM

Tuleap is a tool for end to end traceability of application and system developments. Prior to Tuleap Community Edition 15.13.99.37, Tuleap Enterprise Edition 15.13-3, and …

Oct 14, 2024
CVE-2024-46528
4.3 MEDIUM

An Insecure Direct Object Reference (IDOR) vulnerability in KubeSphere 4.x before 4.1.3 and 3.x through 3.4.1 and KubeSphere Enterprise 4.x before 4.1.3 and 3.x through …

Oct 14, 2024
CVE-2024-48799
7.5 HIGH

An issue in LOREX TECHNOLOGY INC com.lorexcorp.lorexping 1.4.22 allows a remote attacker to obtain sensitive information via the firmware update process.

Oct 14, 2024
CVE-2024-48798
7.5 HIGH

An issue in Hubble Connected (com.hubbleconnected.vervelife) 2.00.81 allows a remote attacker to obtain sensitive information via the firmware update process.

Oct 14, 2024
CVE-2024-48797
7.5 HIGH

An issue in PCS Engineering Preston Cinema (com.prestoncinema.app) 0.2.0 allows a remote attacker to obtain sensitive information via the firmware update process.

Oct 14, 2024
CVE-2024-48796
7.5 HIGH

An issue in EQUES com.eques.plug 1.0.1 allows a remote attacker to obtain sensitive information via the firmware update process.

Oct 14, 2024
CVE-2024-48168
9.8 CRITICAL

A stack overflow vulnerability exists in the sub_402280 function of the HNAP service of D-Link DCS-960L 1.09, allowing an attacker to execute arbitrary code.

Oct 14, 2024
CVE-2024-46535
9.8 CRITICAL

Jepaas v7.2.8 was discovered to contain a SQL injection vulnerability via the orderSQL parameter at /homePortal/loadUserMsg.

Oct 14, 2024
CVE-2024-45741
5.4 MEDIUM

In Splunk Enterprise versions below 9.2.3 and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.108 and 9.1.2312.205, a low-privileged user that does not hold the …

Oct 14, 2024
CVE-2024-45740
5.4 MEDIUM

In Splunk Enterprise versions below 9.2.3 and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403, a low-privileged user that does not hold the "admin" or …

Oct 14, 2024
CVE-2024-45739
4.9 MEDIUM

In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6, the software potentially exposes plaintext passwords for local native authentication Splunk users. This exposure could happen …

Oct 14, 2024
CVE-2024-45738
4.9 MEDIUM

In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6, the software potentially exposes sensitive HTTP parameters to the `_internal` index. This exposure could happen if …

Oct 14, 2024
CVE-2024-45737
4.3 MEDIUM

In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.108, and 9.1.2312.204, a low-privileged user that does not hold …

Oct 14, 2024
CVE-2024-45736
6.5 MEDIUM

In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.107, 9.1.2312.204, and 9.1.2312.111, a low-privileged user that does not …

Oct 14, 2024
CVE-2024-45735
4.3 MEDIUM

In Splunk Enterprise versions below 9.2.3 and 9.1.6, and Splunk Secure Gateway versions on Splunk Cloud Platform versions below 3.4.259, 3.6.17, and 3.7.0, a low-privileged …

Oct 14, 2024
CVE-2024-45734
4.3 MEDIUM

In Splunk Enterprise versions 9.3.0, 9.2.3, and 9.1.6, a low-privileged user that does not hold the "admin" or "power" Splunk roles could view images on …

Oct 14, 2024
CVE-2024-45733
8.8 HIGH

In Splunk Enterprise for Windows versions below 9.2.3 and 9.1.6, a low-privileged user that does not hold the "admin" or "power" Splunk roles could perform …

Oct 14, 2024
CVE-2024-45732
7.1 HIGH

In Splunk Enterprise versions below 9.3.1, and 9.2.0 versions below 9.2.3, and Splunk Cloud Platform versions below 9.2.2403.103, 9.1.2312.200, 9.1.2312.110 and 9.1.2308.208, a low-privileged user …

Oct 14, 2024
CVE-2024-45731
8.0 HIGH

In Splunk Enterprise for Windows versions below 9.3.1, 9.2.3, and 9.1.6, a low-privileged user that does not hold the "admin" or "power" Splunk roles could …

Oct 14, 2024
CVE-2024-8184
5.9 MEDIUM

There exists a security vulnerability in Jetty's ThreadLimitHandler.getRemote() which can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack. By repeatedly sending crafted …

Oct 14, 2024
CVE-2024-6763
3.7 LOW

Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class, HttpURI, for URI/URL parsing. The HttpURI …

Oct 14, 2024
CVE-2024-6762
3.1 LOW

Jetty PushSessionCacheFilter can be exploited by unauthenticated users to launch remote DoS attacks by exhausting the server’s memory.

Oct 14, 2024
CVE-2024-48153
9.8 CRITICAL

DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the get_subconfig function.

Oct 14, 2024
CVE-2024-48150
9.8 CRITICAL

D-Link DIR-820L 1.05B03 has a stack overflow vulnerability in the sub_451208 function.

Oct 14, 2024
CVE-2024-41997
6.6 MEDIUM

An issue was discovered in version of Warp Terminal prior to 2024.07.18 (v0.2024.07.16.08.02). A command injection vulnerability exists in the Docker integration functionality. An attacker …

Oct 14, 2024
CVE-2023-50780
8.8 HIGH

Apache ActiveMQ Artemis allows access to diagnostic information and controls through MBeans, which are also exposed through the authenticated Jolokia endpoint. Before version 2.29.0, this …

Oct 14, 2024
CVE-2024-9823
5.3 MEDIUM

There exists a security vulnerability in Jetty's DosFilter which can be exploited by unauthorized users to cause remote denial-of-service (DoS) attack on the server using …

Oct 14, 2024
CVE-2024-48261

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-48251. Reason: This candidate is a reservation duplicate of CVE-2024-48251. Notes: All CVE users should reference …

Oct 14, 2024
CVE-2024-48259
7.3 HIGH

Cloudlog 2.6.15 allows Oqrs.php request_form SQL injection via station_id or callsign.

Oct 14, 2024
CVE-2024-48257
9.8 CRITICAL

Wavelog 1.8.5 allows Oqrs_model.php get_worked_modes station_id SQL injectioin.

Oct 14, 2024
CVE-2024-48251
9.8 CRITICAL

Wavelog 1.8.5 allows Activated_gridmap_model.php get_band_confirmed SQL injection via band, sat, propagation, or mode.

Oct 14, 2024
CVE-2024-48249
7.3 HIGH

Wavelog 1.8.5 allows Gridmap_model.php get_band_confirmed SQL injection via band, sat, propagation, or mode.

Oct 14, 2024
CVE-2024-40616

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not …

Oct 14, 2024
CVE-2024-9936
6.5 MEDIUM

When manipulating the selection node cache, an attacker may have been able to cause unexpected behavior, potentially leading to an exploitable crash. This vulnerability affects …

Oct 14, 2024
CVE-2024-8602

When the XML is read from the codes in the PDF and parsed using a DocumentBuilder, the default settings of the DocumentBuilder allow for an …

Oct 14, 2024
CVE-2024-7847
7.7 HIGH

VULNERABILITY DETAILS Rockwell Automation used the latest versions of the CVSS scoring system to assess the following vulnerabilities. The following vulnerabilities were reported to us …

Oct 14, 2024
CVE-2024-48255
9.8 CRITICAL

Cloudlog 2.6.15 allows Oqrs.php get_station_info station_id SQL injection.

Oct 14, 2024
CVE-2024-48253
9.8 CRITICAL

Cloudlog 2.6.15 allows Oqrs.php delete_oqrs_line id SQL injection.

Oct 14, 2024
CVE-2024-48120
5.4 MEDIUM

X2CRM v8.5 is vulnerable to a stored Cross-Site Scripting (XSS) in the "Opportunities" module. An attacker can inject malicious JavaScript code into the "Name" field …

Oct 14, 2024
CVE-2024-48119
5.4 MEDIUM

Vtiger CRM v8.2.0 has a HTML Injection vulnerability in the module parameter. Authenticated users can inject arbitrary HTML.

Oct 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.