CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-8544
6.1 MEDIUM

The Pixel Cat – Conversion Pixel Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping …

Sep 24, 2024
CVE-2024-8432
4.3 MEDIUM

The Appointment & Event Booking Calendar Plugin – Webba Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability …

Sep 24, 2024
CVE-2024-38269
4.9 MEDIUM

An improper restriction of operations within the bounds of a memory buffer in the USB file-sharing handler of the Zyxel VMG8825-T50K firmware versions through 5.50(ABOM.8)C0 …

Sep 24, 2024
CVE-2024-38268
4.9 MEDIUM

An improper restriction of operations within the bounds of a memory buffer in the MAC address parser of the Zyxel VMG8825-T50K firmware versions through 5.50(ABOM.8)C0 …

Sep 24, 2024
CVE-2024-38267
4.9 MEDIUM

An improper restriction of operations within the bounds of a memory buffer in the IPv6 address parser of the Zyxel VMG8825-T50K firmware versions through 5.50(ABOM.8)C0 …

Sep 24, 2024
CVE-2024-38266
4.9 MEDIUM

An improper restriction of operations within the bounds of a memory buffer in the parameter type parser of the Zyxel VMG8825-T50K firmware versions through 5.50(ABOM.8)C0 …

Sep 24, 2024
CVE-2024-7024
9.6 CRITICAL

Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. …

Sep 23, 2024
CVE-2024-7023
8.8 HIGH

Insufficient data validation in Updater in Google Chrome prior to 128.0.6537.0 allowed a remote attacker to perform privilege escalation via a malicious file. (Chromium security …

Sep 23, 2024
CVE-2024-7022
4.3 MEDIUM

Uninitialized Use in V8 in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform out of bounds memory access via a crafted HTML …

Sep 23, 2024
CVE-2024-7020
4.3 MEDIUM

Inappropriate implementation in Autofill in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security …

Sep 23, 2024
CVE-2024-7019
4.3 MEDIUM

Inappropriate implementation in UI in Google Chrome prior to 124.0.6367.60 allowed a remote attacker who convinced a user to engage in specific UI gestures to …

Sep 23, 2024
CVE-2024-7018
7.8 HIGH

Heap buffer overflow in PDF in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. …

Sep 23, 2024
CVE-2023-7282
4.3 MEDIUM

Inappropriate implementation in Navigation in Google Chrome prior to 113.0.5672.63 allowed a remote attacker who convinced a user to engage in specific UI gestures to …

Sep 23, 2024
CVE-2023-7281
4.3 MEDIUM

Inappropriate implementation in Compositing in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security …

Sep 23, 2024
CVE-2021-38023
8.8 HIGH

Use after free in Extensions in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Sep 23, 2024
CVE-2018-20072
7.8 HIGH

Insufficient data validation in PDF in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform out of bounds memory access via a crafted …

Sep 23, 2024
CVE-2024-8770
6.1 MEDIUM

A Cross-Site Scripting (XSS) vulnerability was identified in the repository transfer feature of GitHub Enterprise Server, which allows attackers to steal sensitive user information via …

Sep 23, 2024
CVE-2024-8263
2.7 LOW

An improper privilege management vulnerability allowed arbitrary workflows to be committed using an improperly scoped PAT through the use of nested tags. This vulnerability affected …

Sep 23, 2024
CVE-2024-42861
7.5 HIGH

An issue in IEEE 802.1AS linuxptp v.4.2 and before allowing a remote attacker to cause a denial of service via a crafted Pdelay_Req message to …

Sep 23, 2024
CVE-2024-47222
9.8 CRITICAL

New Cloud MyOffice SDK Collaborative Editing Server 2.2.2 through 2.8 allows SSRF via manipulation of requests from external document storage via the MS-WOPI protocol.

Sep 23, 2024
CVE-2024-46639
7.6 HIGH

A cross-site scripting (XSS) vulnerability in HelpDeskZ v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name …

Sep 23, 2024
CVE-2024-44540
6.6 MEDIUM

Ubiquiti AirMax firmware version firmware version 8 allows attackers with physical access to gain a privileged command shell via the UART Debugging Port.

Sep 23, 2024
CVE-2024-43201
8.8 HIGH

The Planet Fitness Workouts iOS and Android mobile apps fail to properly validate TLS certificates, allowing an attacker with appropriate network access to obtain session …

Sep 23, 2024
CVE-2024-37779
8.8 HIGH

WoodWing Elvis DAM v6.98.1 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the Apache Ant script functionality.

Sep 23, 2024
CVE-2024-39843
6.7 MEDIUM

A SQL injection vulnerability in Centreon 24.04.2 allows a remote high-privileged attacker to execute arbitrary SQL command via create user form inputs.

Sep 23, 2024
CVE-2024-39842
7.2 HIGH

A SQL injection vulnerability in Centreon 24.04.2 allows a remote high-privileged attacker to execute arbitrary SQL command via user massive changes inputs.

Sep 23, 2024
CVE-2024-39342
6.6 MEDIUM

Entrust Instant Financial Issuance (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and 6.8.x and earlier uses a DLL library (i.e. DCG.Security.dll) with a custom …

Sep 23, 2024
CVE-2024-39341
5.9 MEDIUM

Entrust Instant Financial Issuance (On Premise) Software (formerly known as Cardwizard) 6.10.0, 6.9.0, 6.9.1, 6.9.2, and 6.8.x and earlier leaves behind a configuration file (i.e. …

Sep 23, 2024
CVE-2024-0005
9.1 CRITICAL

A condition exists in FlashArray and FlashBlade Purity whereby a malicious user could execute arbitrary commands remotely through a specifically crafted SNMP configuration.

Sep 23, 2024
CVE-2024-0004
9.1 CRITICAL

A condition exists in FlashArray Purity whereby an user with array admin role can execute arbitrary commands remotely to escalate privilege on the array.

Sep 23, 2024
CVE-2024-0003
9.1 CRITICAL

A condition exists in FlashArray Purity whereby a malicious user could use a remote administrative service to create an account on the array allowing privileged …

Sep 23, 2024
CVE-2024-0002
10.0 CRITICAL

A condition exists in FlashArray Purity whereby an attacker can employ a privileged account allowing remote access to the array.

Sep 23, 2024
CVE-2024-0001
10.0 CRITICAL

A condition exists in FlashArray Purity whereby a local account intended for initial array configuration remains active potentially allowing a malicious actor to gain elevated …

Sep 23, 2024
CVE-2023-46948
5.4 MEDIUM

A reflected Cross-Site Scripting (XSS) vulnerability was found on Temenos T24 Browser R19.40 that enables a remote attacker to execute arbitrary JavaScript code via the …

Sep 23, 2024
CVE-2024-9014
9.9 CRITICAL

pgAdmin versions 8.11 and earlier are vulnerable to a security flaw in OAuth2 authentication. This vulnerability allows an attacker to potentially obtain the client ID …

Sep 23, 2024
CVE-2024-40442
7.2 HIGH

An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pipeline module to annotate a document automatically v.0.1.23 …

Sep 23, 2024
CVE-2024-40441
6.6 MEDIUM

An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pipeline module to annotate a document automatically v.0.1.23 …

Sep 23, 2024
CVE-2024-47069
6.1 MEDIUM

Oveleon Cookie Bar is a cookie bar is for the Contao Open Source CMS and allows a visitor to define cookie & privacy settings for …

Sep 23, 2024
CVE-2024-47068
6.1 MEDIUM

Rollup is a module bundler for JavaScript. Versions prior to 2.79.2, 3.29.5, and 4.22.4 are susceptible to a DOM Clobbering vulnerability when bundling scripts with …

Sep 23, 2024
CVE-2024-47066
9.0 CRITICAL

Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.19.13, server-side request forgery protection implemented in `src/app/api/proxy/route.ts` does not consider redirect and …

Sep 23, 2024
CVE-2024-46997
9.8 CRITICAL

DataEase is an open source data visualization analysis tool. Prior to version 2.10.1, an attacker can achieve remote command execution by adding a carefully constructed …

Sep 23, 2024
CVE-2024-46985
7.5 HIGH

DataEase is an open source data visualization analysis tool. Prior to version 2.10.1, there is an XML external entity injection vulnerability in the static resource …

Sep 23, 2024
CVE-2024-41228
7.6 HIGH

A symlink following vulnerability in the pouch cp function of AliyunContainerService pouch v1.3.1 allows attackers to escalate privileges and write arbitrary files.

Sep 23, 2024
CVE-2024-34331
9.8 CRITICAL

A lack of code signature verification in Parallels Desktop for Mac v19.3.0 and below allows attackers to escalate privileges via a crafted macOS installer, because …

Sep 23, 2024
CVE-2024-23972
6.8 MEDIUM

Sony XAV-AX5500 USB Configuration Descriptor Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of …

Sep 23, 2024
CVE-2024-23934
8.8 HIGH

Sony XAV-AX5500 WMV/ASF Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sony …

Sep 23, 2024
CVE-2024-23933
6.8 MEDIUM

Sony XAV-AX5500 CarPlay TLV Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of …

Sep 23, 2024
CVE-2024-23922
6.8 MEDIUM

Sony XAV-AX5500 Insufficient Firmware Update Validation Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Sony …

Sep 23, 2024
CVE-2024-46241
5.9 MEDIUM

PHPGurukul Dairy Farm Shop Management System v1.1 is vulnerable to Cross-Site Scripting (XSS) via the pname parameter in add_product.php and edit_product.php.

Sep 23, 2024
CVE-2024-7835

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Exnet Informatics Software Ferry Reservation System allows Reflected XSS.This issue affects …

Sep 23, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.