CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-45292
5.4 MEDIUM

PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. `\PhpOffice\PhpSpreadsheet\Writer\Html` does not sanitize "javascript:" URLs from hyperlink `href` attributes, resulting in a …

Oct 7, 2024
CVE-2024-31449
7.0 HIGH

Redis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua script to trigger a stack …

Oct 7, 2024
CVE-2024-31228
5.5 MEDIUM

Redis is an open source, in-memory database that persists on disk. Authenticated users can trigger a denial-of-service by using specially crafted, long string match patterns …

Oct 7, 2024
CVE-2024-31227
4.4 MEDIUM

Redis is an open source, in-memory database that persists on disk. An authenticated with sufficient privileges may create a malformed ACL selector which, when accessed, …

Oct 7, 2024
CVE-2024-47975
7.0 HIGH

Improper access control validation in firmware of some Solidigm DC Products may allow an attacker with physical access to gain unauthorized access or an attacker …

Oct 7, 2024
CVE-2024-47559
7.6 HIGH

Authenticated RCE via Path Traversal

Oct 7, 2024
CVE-2024-47558
7.6 HIGH

Authenticated RCE via Path Traversal

Oct 7, 2024
CVE-2024-47557
8.3 HIGH

Pre-Auth RCE via Path Traversal

Oct 7, 2024
CVE-2024-47556
8.3 HIGH

Pre-Auth RCE via Path Traversal

Oct 7, 2024
CVE-2024-45894
4.9 MEDIUM

BlueCMS 1.6 suffers from Arbitrary File Deletion via the file_name parameter in an /admin/database.php?act=del request.

Oct 7, 2024
CVE-2024-44068
8.1 HIGH

An issue was discovered in the m2m scaler driver in Samsung Mobile Processor and Wearable Processor Exynos 9820, 9825, 980, 990, 850,and W920. A Use-After-Free …

Oct 7, 2024
CVE-2024-47555
8.3 HIGH

Missing Authentication - User & System Configuration

Oct 7, 2024
CVE-2024-46076
9.8 CRITICAL

RuoYi v4.7.9 and before has a security flaw that allows escaping from comments within the code generation feature, enabling the injection of malicious code.

Oct 7, 2024
CVE-2024-44674
5.7 MEDIUM

D-Link COVR-2600R FW101b05 is vulnerable to Buffer Overflow. In the function sub_24E28, the HTTP_REFERER is obtained through an environment variable, and this field is controllable, …

Oct 7, 2024
CVE-2024-42831
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in Elaine's Realtime CRM Automation v6.18.17 allows attackers to execute arbitrary JavaScript code in the web browser of a …

Oct 7, 2024
CVE-2024-46300
6.1 MEDIUM

itsourcecode Placement Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Full Name field in registration.php.

Oct 7, 2024
CVE-2024-27458
8.8 HIGH

A potential security vulnerability has been identified in the HP Hotkey Support software, which might allow local escalation of privilege. HP is releasing mitigation for …

Oct 7, 2024
CVE-2024-9570
8.8 HIGH

A vulnerability was found in D-Link DIR-619L B1 2.06 and classified as critical. Affected by this issue is the function formEasySetTimezone of the file /goform/formEasySetTimezone. …

Oct 7, 2024
CVE-2024-46446
9.8 CRITICAL

Mecha CMS 3.0.0 is vulnerable to Directory Traversal. An attacker can construct cookies and URIs that bypass user identity checks. Parameters can then be passed …

Oct 7, 2024
CVE-2024-46278
8.4 HIGH

Teedy 1.11 is vulnerable to Cross Site Scripting (XSS) via the management console.

Oct 7, 2024
CVE-2024-46041
8.8 HIGH

IoT Haat Smart Plug IH-IN-16A-S v5.16.1 is vulnerable to Authentication Bypass by Capture-replay.

Oct 7, 2024
CVE-2024-46040
6.5 MEDIUM

IoT Haat Smart Plug IH-IN-16A-S IH-IN-16A-S v5.16.1 suffers from Insufficient Session Expiration. The lack of validation of the authentication token at the IoT Haat during …

Oct 7, 2024
CVE-2024-45932
4.8 MEDIUM

Krayin CRM v1.3.0 is vulnerable to Cross Site Scripting (XSS) via the organization name field in /admin/contacts/organizations/edit/2.

Oct 7, 2024
CVE-2024-28710
6.1 MEDIUM

Cross Site Scripting vulnerability in LimeSurvey before 6.5.0+240319 allows a remote attacker to execute arbitrary code via a lack of input validation and output encoding …

Oct 7, 2024
CVE-2024-28709
6.1 MEDIUM

Cross Site Scripting vulnerability in LimeSurvey before 6.5.12+240611 allows a remote attacker to execute arbitrary code via a crafted script to the title and comment …

Oct 7, 2024
CVE-2024-9576
7.0 HIGH

Vulnerability in Distro Linux Workbooth v2.5 that allows to escalate privileges to the root user by manipulating the network configuration script.

Oct 7, 2024
CVE-2024-9574
9.8 CRITICAL

SQL injection vulnerability in SOPlanning <1.45, via /soplanning/www/user_groupes.php in the by parameter, which could allow a remote user to submit a specially crafted query, allowing …

Oct 7, 2024
CVE-2024-9573
6.3 MEDIUM

SQL injection vulnerability in SOPlanning <1.45, through /soplanning/www/groupe_list.php, in the by parameter, which could allow a remote user to send a specially crafted query and …

Oct 7, 2024
CVE-2024-9572
6.3 MEDIUM

Cross-Site Scripting (XSS) vulnerability in SOPlanning <1.45, due to lack of proper validation of user input via /soplanning/www/process/groupe_save.php, in the groupe_id parameter. This could allow …

Oct 7, 2024
CVE-2024-9571
6.3 MEDIUM

Cross-Site Scripting (XSS) vulnerability in SOPlanning <1.45, due to lack of proper validation of user input via /soplanning/www/process/xajax_server.php, affecting multiple parameters. This could allow a …

Oct 7, 2024
CVE-2024-9569
8.8 HIGH

A vulnerability has been found in D-Link DIR-619L B1 2.06 and classified as critical. Affected by this vulnerability is the function formEasySetPassword of the file …

Oct 7, 2024
CVE-2024-9568
8.8 HIGH

A vulnerability, which was classified as critical, was found in D-Link DIR-619L B1 2.06. Affected is the function formAdvNetwork of the file /goform/formAdvNetwork. The manipulation …

Oct 7, 2024
CVE-2024-45933
6.6 MEDIUM

OnlineNewsSite v1.0 is vulnerable to Cross Site Scripting (XSS) which allows attackers to execute arbitrary code via the Title and summary fields in the /admin/post/edit/ …

Oct 7, 2024
CVE-2023-6362
7.3 HIGH

A vulnerability has been discovered in Winhex affecting version 16.1 SR-1 and 20.4. This vulnerability consists of a buffer overflow controlling the Structured Exception Handler …

Oct 7, 2024
CVE-2023-6361
7.3 HIGH

A vulnerability has been discovered in Winhex affecting version 16.1 SR-1 and 20.4. This vulnerability consists of a buffer overflow controlling the Structured Exception Handler …

Oct 7, 2024
CVE-2024-9567
8.8 HIGH

A vulnerability, which was classified as critical, has been found in D-Link DIR-619L B1 2.06. This issue affects the function formAdvFirewall of the file /goform/formAdvFirewall. …

Oct 7, 2024
CVE-2024-9566
8.8 HIGH

A vulnerability classified as critical was found in D-Link DIR-619L B1 2.06. This vulnerability affects the function formDeviceReboot of the file /goform/formDeviceReboot. The manipulation of …

Oct 7, 2024
CVE-2024-46325
5.5 MEDIUM

TP-Link WR740N V6 has a stack overflow vulnerability via the ssid parameter in /userRpm/popupSiteSurveyRpm.htm url.

Oct 7, 2024
CVE-2024-45153
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to …

Oct 7, 2024
CVE-2024-43047
7.8 HIGH KEV

Memory corruption while maintaining memory maps of HLOS memory.

Oct 7, 2024
CVE-2024-42027
6.7 MEDIUM

The E2EE password entropy generated by Rocket.Chat Mobile prior to version 4.5.1 is insufficient, allowing attackers to crack it if they have the appropriate time …

Oct 7, 2024
CVE-2024-38425
6.1 MEDIUM

Information disclosure while sending implicit broadcast containing APP launch information.

Oct 7, 2024
CVE-2024-38399
8.4 HIGH

Memory corruption while processing user packets to generate page faults.

Oct 7, 2024
CVE-2024-38397
7.5 HIGH

Transient DOS while parsing probe response and assoc response frame.

Oct 7, 2024
CVE-2024-33073
8.2 HIGH

Information disclosure while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.

Oct 7, 2024
CVE-2024-33071
7.5 HIGH

Transient DOS while parsing the MBSSID IE from the beacons when IE length is 0.

Oct 7, 2024
CVE-2024-33070
7.5 HIGH

Transient DOS while parsing ESP IE from beacon/probe response frame.

Oct 7, 2024
CVE-2024-33069
7.5 HIGH

Transient DOS when transmission of management frame sent by host is not successful and error status is received in the host.

Oct 7, 2024
CVE-2024-33066
9.8 CRITICAL

Memory corruption while redirecting log file to any file location with any file name.

Oct 7, 2024
CVE-2024-33065
8.4 HIGH

Memory corruption while taking snapshot when an offset variable is set by camera driver.

Oct 7, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.