CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-47414
7.8 HIGH

Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of …

Oct 9, 2024
CVE-2024-47413
7.8 HIGH

Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of …

Oct 9, 2024
CVE-2024-47412
7.8 HIGH

Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of …

Oct 9, 2024
CVE-2024-47411
7.8 HIGH

Animate versions 23.0.7, 24.0.4 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context …

Oct 9, 2024
CVE-2024-47410
7.8 HIGH

Animate versions 23.0.7, 24.0.4 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of …

Oct 9, 2024
CVE-2024-45145
5.5 MEDIUM

Lightroom Desktop versions 7.4.1, 13.5, 12.5.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker …

Oct 9, 2024
CVE-2024-45150
7.8 HIGH

Dimension versions 4.0.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current …

Oct 9, 2024
CVE-2024-45146
7.8 HIGH

Dimension versions 4.0.3 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the …

Oct 9, 2024
CVE-2024-20787
5.5 MEDIUM

Substance3D - Painter versions 10.0.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Oct 9, 2024
CVE-2024-9451
6.4 MEDIUM

The Embed PDF Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'height' and 'width' parameters in all versions up to, and …

Oct 9, 2024
CVE-2024-9449
6.4 MEDIUM

The Auto iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' parameter in all versions up to, and including, 1.7 due …

Oct 9, 2024
CVE-2024-39586
2.9 LOW

Dell AppSync Server, version 4.3 through 4.6, contains an XML External Entity Injection vulnerability. An adjacent high privileged attacker could potentially exploit this vulnerability, leading …

Oct 9, 2024
CVE-2024-39440
6.2 MEDIUM

In DRM service, there is a possible system crash due to null pointer dereference. This could lead to local denial of service with System execution …

Oct 9, 2024
CVE-2024-39439
6.2 MEDIUM

In DRM service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Oct 9, 2024
CVE-2024-39438
6.5 MEDIUM

In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution …

Oct 9, 2024
CVE-2024-39437
6.5 MEDIUM

In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution …

Oct 9, 2024
CVE-2024-39436
6.5 MEDIUM

In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution …

Oct 9, 2024
CVE-2024-5968
4.8 MEDIUM

The Photo Gallery by 10Web WordPress plugin before 1.8.28 does not properly sanitise and escape some of its Gallery settings, which could allow high privilege …

Oct 9, 2024
CVE-2023-46586
9.1 CRITICAL

cgi.c in weborf .0.17, 0.18, 0.19, and 0.20 (before 1.0) lacks '\0' termination of the path for CGI scripts because strncpy is misused.

Oct 9, 2024
CVE-2023-45872
6.5 MEDIUM

An issue was discovered in Qt before 6.2.11 and 6.3.x through 6.6.x before 6.6.1. When a QML image refers to an image whose content is …

Oct 9, 2024
CVE-2023-45361
6.1 MEDIUM

An issue was discovered in VectorComponentUserLinks.php in the Vector Skin component in MediaWiki before 1.39.5 and 1.40.x before 1.40.1. vector-intro-page MalformedTitleException is uncaught if it …

Oct 9, 2024
CVE-2023-45359
6.5 MEDIUM

An issue was discovered in the Vector Skin component for MediaWiki before 1.39.5 and 1.40.x before 1.40.1. vector-toc-toggle-button-label is not escaped, but should be, because …

Oct 9, 2024
CVE-2023-37154
8.4 HIGH

check_by_ssh in Nagios nagios-plugins 2.4.5 allows arbitrary command execution via ProxyCommand, LocalCommand, and PermitLocalCommand with \${IFS}. This has been categorized both as fixed in e8810de, …

Oct 9, 2024
CVE-2023-36325
3.7 LOW

i2p before 2.3.0 (Java) allows de-anonymizing the public IPv4 and IPv6 addresses of i2p hidden services (aka eepsites) via a correlation attack across the IPv4 …

Oct 9, 2024
CVE-2024-47191
7.1 HIGH

pam_oath.so in oath-toolkit 2.6.7 through 2.6.11 before 2.6.12 allows root privilege escalation because, in the context of PAM code running as root, it mishandles usersfile …

Oct 9, 2024
CVE-2024-45160
9.1 CRITICAL

Incorrect credential validation in LemonLDAP::NG 2.18.x and 2.19.x before 2.19.2 allows attackers to bypass OAuth2 client authentication via an empty client_password parameter (client secret).

Oct 9, 2024
CVE-2024-42934
5.0 MEDIUM

OpenIPMI before 2.0.36 has an out-of-bounds array access (for authentication type) in the ipmi_sim simulator, resulting in denial of service or (with very low probability) …

Oct 9, 2024
CVE-2024-32608
9.8 CRITICAL

HDF5 library through 1.14.3 has memory corruption in H5A__close resulting in the corruption of the instruction pointer and causing denial of service or potential code …

Oct 9, 2024
CVE-2024-45179
7.2 HIGH

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to insufficient input validation, the C-MOR web interface is vulnerable to OS …

Oct 9, 2024
CVE-2024-35288
7.8 HIGH

Nitro PDF Pro before 13.70.8.82 and 14.x before 14.26.1.0 allows Local Privilege Escalation in the MSI Installer because custom actions occur unsafely in repair mode. …

Oct 9, 2024
CVE-2024-25286

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been …

Oct 9, 2024
CVE-2024-25285

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been …

Oct 9, 2024
CVE-2024-25284

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been …

Oct 9, 2024
CVE-2024-25283

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been …

Oct 9, 2024
CVE-2024-25282

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been …

Oct 9, 2024
CVE-2024-7963
6.4 MEDIUM

The CMSMasters Content Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's multiple shortcodes in all versions up to, and including, …

Oct 9, 2024
CVE-2024-9603
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 129.0.6668.100 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Oct 8, 2024
CVE-2024-9602
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 129.0.6668.100 allowed a remote attacker to perform an out of bounds memory write via a crafted …

Oct 8, 2024
CVE-2024-9412

An improper authorization vulnerability exists in the Rockwell Automation affected products that could allow an unauthorized user to sign in. While removal of all role …

Oct 8, 2024
CVE-2024-36814
4.9 MEDIUM

An arbitrary file read vulnerability in Adguard Home before v0.107.52 allows authenticated attackers to access arbitrary files as root on the underlying Operating System via …

Oct 8, 2024
CVE-2024-27457
2.5 LOW

Improper check for unusual or exceptional conditions in Intel(R) TDX Module firmware before version 1.5.06 may allow a privileged user to potentially enable information disclosure …

Oct 8, 2024
CVE-2024-47823
9.8 CRITICAL

Livewire is a full-stack framework for Laravel that allows for dynamic UI components without leaving PHP. In livewire/livewire prior to `2.12.7` and `v3.5.2`, the file …

Oct 8, 2024
CVE-2024-47822
4.2 MEDIUM

Directus is a real-time API and App dashboard for managing SQL database content. Access tokens from query strings are not redacted and are potentially exposed …

Oct 8, 2024
CVE-2024-47780
3.1 LOW

TYPO3 is a free and open source Content Management Framework. Backend users could see items in the backend page tree without having access if the …

Oct 8, 2024
CVE-2024-47773
8.2 HIGH

Discourse is an open source platform for community discussion. An attacker can make several XHR requests until the cache is poisoned with a response without …

Oct 8, 2024
CVE-2024-46539
8.2 HIGH

Insecure permissions in the Bluetooth Low Energy (BLE) component of Fire-Boltt Artillery Smart Watch NJ-R6E-10.3 allow attackers to cause a Denial of Service (DoS).

Oct 8, 2024
CVE-2024-46410
4.8 MEDIUM

PublicCMS V4.0.202406.d was discovered to contain a cross-site scripting (XSS) vulnerability via a crafted script to the Category Managment feature

Oct 8, 2024
CVE-2024-43616
7.8 HIGH

Microsoft Office Remote Code Execution Vulnerability

Oct 8, 2024
CVE-2024-43615
7.1 HIGH

Microsoft OpenSSH for Windows Remote Code Execution Vulnerability

Oct 8, 2024
CVE-2024-43614
5.5 MEDIUM

Relative path traversal in Microsoft Defender for Endpoint allows an authorized attacker to perform spoofing locally.

Oct 8, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.