CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-45537
6.5 MEDIUM

Apache Druid allows users with certain permissions to read data from other database systems using JDBC. This functionality allows trusted users to set up Druid …

Sep 17, 2024
CVE-2024-45384
5.3 MEDIUM

Padding Oracle vulnerability in Apache Druid extension, druid-pac4j. This could allow an attacker to manipulate a pac4j session cookie. This issue affects Apache Druid versions …

Sep 17, 2024
CVE-2024-43460
8.1 HIGH

Improper authorization in Dynamics 365 Business Central resulted in a vulnerability that allows an authenticated attacker to elevate privileges over a network.

Sep 17, 2024
CVE-2024-38183
9.8 CRITICAL

An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network.

Sep 17, 2024
CVE-2024-8945
5.5 MEDIUM

A vulnerability has been found in CodeCanyon RISE Ultimate Project Manager 3.7.0 and classified as critical. This vulnerability affects unknown code of the file /index.php/dashboard/save. …

Sep 17, 2024
CVE-2024-8944
7.3 HIGH

A vulnerability, which was classified as critical, was found in code-projects Hospital Management System 1.0. This affects an unknown part of the file check_availability.php. The …

Sep 17, 2024
CVE-2024-8796
5.3 MEDIUM

Under the default configuration, Devise-Two-Factor versions >= 2.2.0 & < 6.0.0 generate TOTP shared secrets that are 120 bits instead of the 128-bit minimum defined …

Sep 17, 2024
CVE-2024-45804

Rejected reason: This CVE is a duplicate of another CVE.

Sep 17, 2024
CVE-2024-45682
8.8 HIGH

There is a command injection vulnerability that may allow an attacker to inject malicious input on the device's operating system.

Sep 17, 2024
CVE-2024-42503
7.2 HIGH

Authenticated command execution vulnerability exist in the ArubaOS command line interface (CLI). Successful exploitation of this vulnerabilities result in the ability to run arbitrary commands …

Sep 17, 2024
CVE-2024-42502
7.2 HIGH

Authenticated command injection vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability result in the ability to inject shell commands on …

Sep 17, 2024
CVE-2024-42501
7.2 HIGH

An authenticated Path Traversal vulnerabilities exists in the ArubaOS. Successful exploitation of this vulnerability allows an attacker to install unsigned packages on the underlying operating …

Sep 17, 2024
CVE-2024-38813
7.5 HIGH KEV

The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to …

Sep 17, 2024
CVE-2024-38812
9.8 CRITICAL KEV

The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger …

Sep 17, 2024
CVE-2024-38380
5.5 MEDIUM

This vulnerability occurs when user-supplied input is improperly sanitized and then reflected back to the user's browser, allowing an attacker to execute arbitrary JavaScript in …

Sep 17, 2024
CVE-2024-8939
6.2 MEDIUM

A vulnerability was found in the ilab model serve component, where improper handling of the best_of parameter in the vllm JSON web API can lead …

Sep 17, 2024
CVE-2024-8768
7.5 HIGH

A flaw was found in the vLLM library. A completions API request with an empty prompt will crash the vLLM API server, resulting in a …

Sep 17, 2024
CVE-2024-7788
7.8 HIGH

Improper Digital Signature Invalidation vulnerability in Zip Repair Mode of The Document Foundation LibreOffice allows Signature forgery vulnerability in LibreOfficeThis issue affects LibreOffice: from 24.2 …

Sep 17, 2024
CVE-2021-27916
8.1 HIGH

Prior to the patched version, logged in users of Mautic are vulnerable to Relative Path Traversal/Arbitrary File Deletion. Regardless of the level of access the …

Sep 17, 2024
CVE-2024-47049
8.2 HIGH

The czim/file-handling package before 1.5.0 and 2.x before 2.3.0 (used with PHP Composer) does not properly validate URLs within makeFromUrl and makeFromAny, leading to SSRF, …

Sep 17, 2024
CVE-2024-47047
7.5 HIGH

An issue was discovered in the powermail extension through 12.4.0 for TYPO3. It fails to validate the mail parameter of the createAction, resulting in Insecure …

Sep 17, 2024
CVE-2024-38860
6.1 MEDIUM

Improper neutralization of input in Checkmk before versions 2.3.0p16 and 2.2.0p34 allows attackers to craft malicious links that can facilitate phishing attacks.

Sep 17, 2024
CVE-2024-22303
8.8 HIGH

Incorrect Privilege Assignment vulnerability in favethemes Houzez allows Privilege Escalation.This issue affects Houzez: from n/a through 3.2.4.

Sep 17, 2024
CVE-2024-21743
8.8 HIGH

Privilege Escalation vulnerability in favethemes Houzez Login Register houzez-login-register.This issue affects Houzez Login Register: from n/a through 3.2.5.

Sep 17, 2024
CVE-2021-27915
7.6 HIGH

Prior to the patched version, there is an XSS vulnerability in the description fields within the Mautic application which could be exploited by a logged …

Sep 17, 2024
CVE-2024-8897
6.1 MEDIUM

Under certain conditions, an attacker with the ability to redirect users to a malicious site via an open redirect on a trusted site, may be …

Sep 17, 2024
CVE-2024-7873

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Encoding or Escaping of Output, CWE - 83 Improper Neutralization of Script …

Sep 17, 2024
CVE-2024-46362
8.8 HIGH

FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/create_directory

Sep 17, 2024
CVE-2024-46085
8.8 HIGH

FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/rename

Sep 17, 2024
CVE-2024-5998
7.8 HIGH

A vulnerability in the FAISS.deserialize_from_bytes function of langchain-ai/langchain allows for pickle deserialization of untrusted data. This can lead to the execution of arbitrary commands via …

Sep 17, 2024
CVE-2024-8767
9.9 CRITICAL

Sensitive data disclosure and manipulation due to unnecessary privileges assignment. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build …

Sep 17, 2024
CVE-2024-8761
7.2 HIGH

The Share This Image plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.03. This is due to insufficient …

Sep 17, 2024
CVE-2024-8490
8.8 HIGH

The PropertyHive plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.19. This is due to missing or …

Sep 17, 2024
CVE-2024-8093
6.5 MEDIUM

The Posts reminder WordPress plugin through 0.20 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

Sep 17, 2024
CVE-2024-8092
5.4 MEDIUM

The Accordion Image Menu WordPress plugin through 3.1.3 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which …

Sep 17, 2024
CVE-2024-8091
6.5 MEDIUM

The Enhanced Search Box WordPress plugin through 0.6.1 does not have CSRF check in place when updating its settings, which could allow attackers to make …

Sep 17, 2024
CVE-2024-8052
6.1 MEDIUM

The Review Ratings WordPress plugin through 1.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could …

Sep 17, 2024
CVE-2024-8051
5.4 MEDIUM

The Special Feed Items WordPress plugin through 1.0.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which …

Sep 17, 2024
CVE-2024-8047
6.5 MEDIUM

The Visual Sound (old) WordPress plugin through 1.06 does not have CSRF check in place when updating its settings, which could allow attackers to make …

Sep 17, 2024
CVE-2024-8044
6.5 MEDIUM

The infolinks Ad Wrap WordPress plugin through 1.0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make …

Sep 17, 2024
CVE-2024-8043
5.4 MEDIUM

The Vikinghammer Tweet WordPress plugin through 0.2.4 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could …

Sep 17, 2024
CVE-2024-5170
4.8 MEDIUM

The Logo Manager For Enamad WordPress plugin through 0.7.1 does not sanitise and escape in its widgets settings, which could allow high privilege users such …

Sep 17, 2024
CVE-2024-8110
7.5 HIGH

Denial of Service (DoS) vulnerability has been found in Dual-redundant Platform for Computer. If a computer on which the affected product is installed receives a …

Sep 17, 2024
CVE-2024-7387
9.1 CRITICAL

A flaw was found in openshift/builder. This vulnerability allows command injection via path traversal, where a malicious user can execute arbitrary commands on the OpenShift …

Sep 17, 2024
CVE-2024-45496
9.9 CRITICAL

A flaw was found in OpenShift. This issue occurs due to the misuse of elevated privileges in the OpenShift Container Platform's build process. During the …

Sep 17, 2024
CVE-2024-44202
5.3 MEDIUM

An authentication issue was addressed with improved state management. This issue is fixed in Safari 18, iOS 18 and iPadOS 18. Private Browsing tabs may …

Sep 17, 2024
CVE-2024-44198
5.5 MEDIUM

An integer overflow was addressed through improved input validation. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS …

Sep 17, 2024
CVE-2024-44191
5.5 MEDIUM

This issue was addressed through improved state management. This issue is fixed in Xcode 16, iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, …

Sep 17, 2024
CVE-2024-44190
5.5 MEDIUM

A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7. An app …

Sep 17, 2024
CVE-2024-44189
7.5 HIGH

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15. A logic issue existed where a process may be able …

Sep 17, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.