CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-20467
8.6 HIGH

A vulnerability in the implementation of the IPv4 fragmentation reassembly code in Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a …

Sep 25, 2024
CVE-2024-20465
5.8 MEDIUM

A vulnerability in the access control list (ACL) programming of Cisco IOS Software running on Cisco Industrial Ethernet 4000, 4010, and 5000 Series Switches could …

Sep 25, 2024
CVE-2024-20464
8.6 HIGH

A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of …

Sep 25, 2024
CVE-2024-20455
8.6 HIGH

A vulnerability in the process that classifies traffic that is going to the Unified Threat Defense (UTD) component of Cisco IOS XE Software in controller …

Sep 25, 2024
CVE-2024-20437
8.1 HIGH

A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform a cross-site request forgery (CSRF) …

Sep 25, 2024
CVE-2024-20436
8.6 HIGH

A vulnerability in the HTTP Server feature of Cisco IOS XE Software when the Telephony Service feature is enabled could allow an unauthenticated, remote attacker …

Sep 25, 2024
CVE-2024-20434
4.3 MEDIUM

A vulnerability in Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the control plane …

Sep 25, 2024
CVE-2024-20433
8.6 HIGH

A vulnerability in the Resource Reservation Protocol (RSVP) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to …

Sep 25, 2024
CVE-2024-20414
6.5 MEDIUM

A vulnerability in the web UI feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a …

Sep 25, 2024
CVE-2024-20350
7.5 HIGH

A vulnerability in the SSH server of Cisco Catalyst Center, formerly Cisco DNA Center, could allow an unauthenticated, remote attacker to impersonate a Cisco Catalyst …

Sep 25, 2024
CVE-2024-7421
5.5 MEDIUM

An information exposure in Devolutions Remote Desktop Manager 2024.2.20.0 and earlier on Windows allows local attackers with access to system logs to obtain session credentials …

Sep 25, 2024
CVE-2024-47078
8.1 HIGH

Meshtastic is an open source, off-grid, decentralized, mesh network. Meshtastic uses MQTT to communicate over an internet connection to a shared or private MQTT Server. …

Sep 25, 2024
CVE-2024-46600
4.7 MEDIUM

dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/doAdminAction.php?act=delCate&id=31

Sep 25, 2024
CVE-2024-46485
6.3 MEDIUM

dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/doAdminAction.php?act=addCate

Sep 25, 2024
CVE-2024-44825
7.5 HIGH

Directory Traversal vulnerability in Centro de Tecnologia da Informaco Renato Archer InVesalius3 v3.1.99995 allows attackers to write arbitrary files unto the system via a crafted …

Sep 25, 2024
CVE-2023-25189
3.3 LOW

BTS is affected by information disclosure vulnerability where mobile network operator personnel connected over BTS Web Element Manager, regardless of the access privileges, having a …

Sep 25, 2024
CVE-2024-46461
8.0 HIGH

VLC media player 3.0.20 and earlier is vulnerable to denial of service through an integer overflow which could be triggered with a maliciously crafted mms …

Sep 25, 2024
CVE-2024-43990
5.3 MEDIUM

Insertion of Sensitive Information into Log File vulnerability in StylemixThemes Masterstudy LMS Starter.This issue affects Masterstudy LMS Starter: from n/a through 1.1.8.

Sep 25, 2024
CVE-2024-43959
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Testimonials super-testimonial allows Reflected XSS.This issue affects Testimonials: from n/a through <= …

Sep 25, 2024
CVE-2024-43237
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Steve Burge WordPress Tag Cloud Plugin – Tag Groups tag-groups.This issue affects WordPress Tag Cloud …

Sep 25, 2024
CVE-2024-30128
8.6 HIGH

HCL Nomad server on Domino is affected by an open proxy vulnerability in which an unauthenticated attacker can mask their original source IP address. This …

Sep 25, 2024
CVE-2024-22893
7.5 HIGH

OpenSlides 4.0.15 verifies passwords by comparing password hashes using a function with content-dependent runtime. This can allow attackers to obtain information about the password hash …

Sep 25, 2024
CVE-2024-22892
7.5 HIGH

OpenSlides 4.0.15 was discovered to be using a weak hashing algorithm to store passwords.

Sep 25, 2024
CVE-2024-8316
7.8 HIGH

In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a code execution attack is possible through an insecure deserialization vulnerability.

Sep 25, 2024
CVE-2024-7679
7.8 HIGH

In Progress Telerik UI for WinForms versions prior to 2024 Q3 (2024.3.924), a command injection attack is possible through improper neutralization of hyperlink elements.

Sep 25, 2024
CVE-2024-7576
7.8 HIGH

In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a code execution attack is possible through an insecure deserialization vulnerability.

Sep 25, 2024
CVE-2024-7575
7.8 HIGH

In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a command injection attack is possible through improper neutralization of hyperlink elements.

Sep 25, 2024
CVE-2024-6512
6.5 MEDIUM

Authorization bypass in the PAM access request approval mechanism in Devolutions Server 2024.2.10 and earlier allows authenticated users with permissions to approve their own requests, …

Sep 25, 2024
CVE-2024-45613
6.1 MEDIUM

CKEditor 5 is a JavaScript rich-text editor. Starting in version 40.0.0 and prior to version 43.1.1, a Cross-Site Scripting (XSS) vulnerability is present in the …

Sep 25, 2024
CVE-2024-8546
6.4 MEDIUM

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Video widget in all versions up to, and including, …

Sep 25, 2024
CVE-2024-4657

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Talent Software BAP Automation allows Stored XSS.This issue affects BAP Automation: …

Sep 25, 2024
CVE-2024-6594
7.5 HIGH

Improper Handling of Exceptional Conditions vulnerability in the WatchGuard Single Sign-On Client on Windows causes the client to crash while handling malformed commands. An attacker …

Sep 25, 2024
CVE-2024-6593
9.1 CRITICAL

Incorrect Authorization vulnerability in WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows allows an attacker with network access to execute restricted management commands. This …

Sep 25, 2024
CVE-2024-6592
9.1 CRITICAL

Incorrect Authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on …

Sep 25, 2024
CVE-2024-8858
6.4 MEDIUM

The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘piechart_settings’ parameter in all versions up to, and including, …

Sep 25, 2024
CVE-2024-7481
8.8 HIGH

Improper verification of cryptographic signature during installation of a Printer driver via the TeamViewer_service.exe component of TeamViewer Remote Clients prior version 15.58.4 for Windows allows …

Sep 25, 2024
CVE-2024-7479
8.8 HIGH

Improper verification of cryptographic signature during installation of a VPN driver via the TeamViewer_service.exe component of TeamViewer Remote Clients prior version 15.58.4 for Windows allows …

Sep 25, 2024
CVE-2024-45817
7.3 HIGH

In x86's APIC (Advanced Programmable Interrupt Controller) architecture, error conditions are reported in a status register. Furthermore, the OS can opt to receive an interrupt …

Sep 25, 2024
CVE-2024-31146
7.5 HIGH

When multiple devices share resources and one of them is to be passed through to a guest, security of the entire system and of respective …

Sep 25, 2024
CVE-2024-31145
7.5 HIGH

Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Memory Region Reporting, "RMRR") for Intel VT-d or Unity Mapping …

Sep 25, 2024
CVE-2024-9169
5.5 MEDIUM

The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin debug settings in all versions up to, and including, 6.4.1 due …

Sep 25, 2024
CVE-2024-8175
7.5 HIGH

An unauthenticated remote attacker can causes the CODESYS web server to access invalid memory which results in a DoS.

Sep 25, 2024
CVE-2024-47303
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in livemesh Livemesh Addons for Elementor addons-for-elementor allows Cross-Site Scripting (XSS).This issue affects Livemesh …

Sep 25, 2024
CVE-2024-40761
5.3 MEDIUM

Inadequate Encryption Strength vulnerability in Apache Answer. This issue affects Apache Answer: through 1.3.5. Using the MD5 value of a user's email to access Gravatar …

Sep 25, 2024
CVE-2024-23454
6.2 MEDIUM

Apache Hadoop’s RunJar.run() does not set permissions for temporary directory by default. If sensitive data will be present in this file, all the other local …

Sep 25, 2024
CVE-2024-8910
4.3 MEDIUM

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.5 …

Sep 25, 2024
CVE-2024-8678
5.3 MEDIUM

The Revolut Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /wc/v3/revolut REST …

Sep 25, 2024
CVE-2024-8290
8.8 HIGH

The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all …

Sep 25, 2024
CVE-2024-3866
4.7 MEDIUM

The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Self-Based Cross-Site Scripting via the 'Referer' header in all versions up to, and …

Sep 25, 2024
CVE-2024-8658
5.3 MEDIUM

The myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification …

Sep 25, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.