CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-34662
6.2 MEDIUM

Improper access control in ActivityManager prior to SMR Oct-2024 Release 1 in select Android 12, 13 and SMR Sep-2024 Release 1 in select Android 14 …

Oct 8, 2024
CVE-2024-9292
6.4 MEDIUM

The Bridge Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'formforall' shortcode in versions up to, and including, 3.2.0 due to insufficient …

Oct 8, 2024
CVE-2024-9021
5.4 MEDIUM

In the process of testing the Relevanssi WordPress plugin before 4.23.1, a vulnerability was found that allows you to implement Stored XSS on behalf of …

Oct 8, 2024
CVE-2024-8983
4.8 MEDIUM

Custom Twitter Feeds WordPress plugin before 2.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Oct 8, 2024
CVE-2024-21533
6.5 MEDIUM

All versions of the package ggit are vulnerable to Arbitrary Argument Injection via the clone() API, which allows specifying the remote URL to clone and …

Oct 8, 2024
CVE-2024-21532
7.3 HIGH

All versions of the package ggit are vulnerable to Command Injection via the fetchTags(branch) API, which allows user input to specify the branch to be …

Oct 8, 2024
CVE-2024-9026
3.3 LOW

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using PHP-FPM SAPI and it is configured to catch workers output through …

Oct 8, 2024
CVE-2024-8927
7.5 HIGH

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, HTTP_REDIRECT_STATUS variable is used to check whether or not CGI binary is being …

Oct 8, 2024
CVE-2024-8926
8.1 HIGH

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using a certain non-standard configurations of Windows codepages, the fixes for CVE-2024-4577 …

Oct 8, 2024
CVE-2024-8925
3.1 LOW

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, erroneous parsing of multipart form data contained in an HTTP POST request could …

Oct 8, 2024
CVE-2024-47594
5.4 MEDIUM

SAP NetWeaver Enterprise Portal (KMC) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting vulnerability in KMC servlet. An attacker could craft a script …

Oct 8, 2024
CVE-2024-45382
3.3 LOW

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS through out-of-bounds write.

Oct 8, 2024
CVE-2024-45282
4.3 MEDIUM

Fields which are in 'read only' state in Bank Statement Draft in Manage Bank Statements application, could be modified by MERGE method. The property of …

Oct 8, 2024
CVE-2024-45278
5.4 MEDIUM

SAP Commerce Backoffice does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. After successful exploitation, an attacker can cause limited impact …

Oct 8, 2024
CVE-2024-45277
4.3 MEDIUM

The SAP HANA Node.js client package versions from 2.0.0 before 2.21.31 is impacted by Prototype Pollution vulnerability allowing an attacker to add arbitrary properties to …

Oct 8, 2024
CVE-2024-43697
3.3 LOW

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS through improper input.

Oct 8, 2024
CVE-2024-43696
3.3 LOW

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS by memory leak.

Oct 8, 2024
CVE-2024-39831
4.4 MEDIUM

in OpenHarmony v4.1.0 allow a local attacker with high privileges arbitrary code execution in pre-installed apps through use after free.

Oct 8, 2024
CVE-2024-39806
5.5 MEDIUM

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.

Oct 8, 2024
CVE-2024-37179
7.7 HIGH

SAP BusinessObjects Business Intelligence Platform allows an authenticated user to send a specially crafted request to the Web Intelligence Reporting Server to download any file …

Oct 8, 2024
CVE-2024-47969
6.2 MEDIUM

Improper resource management in firmware of some Solidigm DC Products may allow an attacker to potentially enable denial of service.

Oct 7, 2024
CVE-2024-47968
4.4 MEDIUM

Improper resource shutdown in middle of certain operations on some Solidigm DC Products may allow an attacker to potentially enable denial of service.

Oct 7, 2024
CVE-2024-47818
6.5 MEDIUM

Saltcorn is an extensible, open source, no-code database application builder. A logged-in user with any role can delete arbitrary files on the filesystem by calling …

Oct 7, 2024
CVE-2024-47817
6.1 MEDIUM

Lara-zeus Dynamic Dashboard simple way to manage widgets for your website landing page, and filament dashboard and Lara-zeus artemis is a collection of themes for …

Oct 7, 2024
CVE-2024-47814
3.9 LOW

Vim is an open source, command line text editor. A use-after-free was found in Vim < 9.1.0764. When closing a buffer (visible in a window) …

Oct 7, 2024
CVE-2024-47782
7.6 HIGH

WikiDiscover is an extension designed for use with a CreateWiki managed farm to display wikis. Special:WikiDiscover is a special page that lists all wikis on …

Oct 7, 2024
CVE-2024-47781
6.1 MEDIUM

CreateWiki is an extension used at Miraheze for requesting & creating wikis. The name of requested wikis is not escaped on Special:RequestWikiQueue, so a user …

Oct 7, 2024
CVE-2024-45874
9.8 CRITICAL

A DLL hijacking vulnerability in VegaBird Vooki 5.2.9 allows attackers to execute arbitrary code / maintain persistence via placing a crafted DLL file in the …

Oct 7, 2024
CVE-2024-45873
9.8 CRITICAL

A DLL hijacking vulnerability in VegaBird Yaazhini 2.0.2 allows attackers to execute arbitrary code / maintain persistence via placing a crafted DLL file in the …

Oct 7, 2024
CVE-2024-47974
4.4 MEDIUM

Race condition during resource shutdown in some Solidigm DC Products may allow an attacker to potentially enable denial of service.

Oct 7, 2024
CVE-2024-47973
5.1 MEDIUM

In some Solidigm DC Products, a defect in device overprovisioning may provide information disclosure to an attacker.

Oct 7, 2024
CVE-2024-47967
4.4 MEDIUM

Improper resource initialization handling in firmware of some Solidigm DC Products may allow an attacker to potentially enable denial of service.

Oct 7, 2024
CVE-2024-47772
6.5 MEDIUM

Discourse is an open source platform for community discussion. An attacker can execute arbitrary JavaScript on users' browsers by sending a maliciously crafted chat message …

Oct 7, 2024
CVE-2024-47610
7.3 HIGH

InvenTree is an Open Source Inventory Management System. In affected versions of InvenTree it is possible for a registered user to store javascript in markdown …

Oct 7, 2024
CVE-2024-45919
6.5 MEDIUM

A security flaw has been discovered in Solvait version 24.4.2 that allows an attacker to elevate their privileges. By manipulating the Request ID and Action …

Oct 7, 2024
CVE-2024-45297
5.3 MEDIUM

Discourse is an open source platform for community discussion. Users can see topics with a hidden tag if they know the label/name of that tag. …

Oct 7, 2024
CVE-2024-45291
6.3 MEDIUM

PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. It's possible for an attacker to construct an XLSX file that links images …

Oct 7, 2024
CVE-2024-45290
7.7 HIGH

PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. It's possible for an attacker to construct an XLSX file which links media …

Oct 7, 2024
CVE-2024-45060
7.1 HIGH

PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. One of the sample scripts in PhpSpreadsheet is susceptible to a cross-site scripting …

Oct 7, 2024
CVE-2024-45051
8.2 HIGH

Discourse is an open source platform for community discussion. A maliciously crafted email address could allow an attacker to bypass domain-based restrictions and gain access …

Oct 7, 2024
CVE-2024-43789
7.5 HIGH

Discourse is an open source platform for community discussion. A user can create a post with many replies, and then attempt to fetch them all …

Oct 7, 2024
CVE-2024-43365
5.7 MEDIUM

Cacti is an open source performance and fault management framework. The`consolenewsection` parameter is not properly sanitized when saving external links in links.php . Morever, the …

Oct 7, 2024
CVE-2024-43364
5.7 MEDIUM

Cacti is an open source performance and fault management framework. The `title` parameter is not properly sanitized when saving external links in links.php . Morever, …

Oct 7, 2024
CVE-2024-43363
7.2 HIGH

Cacti is an open source performance and fault management framework. An admin user can create a device with a malicious hostname containing php code and …

Oct 7, 2024
CVE-2024-43362
7.3 HIGH

Cacti is an open source performance and fault management framework. The `fileurl` parameter is not properly sanitized when saving external links in `links.php` . Morever, …

Oct 7, 2024
CVE-2024-47976
6.7 MEDIUM

Improper access removal handling in firmware of some Solidigm DC Products may allow an attacker with physical access to gain unauthorized access.

Oct 7, 2024
CVE-2024-47972
4.0 MEDIUM

Improper resource management in firmware of some Solidigm DC Products may allow an attacker to potentially control the performance of the resource.

Oct 7, 2024
CVE-2024-47971
6.5 MEDIUM

Improper error handling in firmware of some SSD DC Products may allow an attacker to enable denial of service.

Oct 7, 2024
CVE-2024-47079
6.4 MEDIUM

Meshtastic is an open source, off-grid, decentralized, mesh network built to run on affordable, low-power devices. Meshtastic firmware is an open source firmware implementation for …

Oct 7, 2024
CVE-2024-45293
7.5 HIGH

PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. The security scanner responsible for preventing XXE attacks in the XLSX reader can …

Oct 7, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.