CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-7423
8.8 HIGH

The Stream plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.0.1. This is due to missing or …

Sep 13, 2024
CVE-2024-6544
5.3 MEDIUM

The Custom Post Limits plugin for WordPress is vulnerable to full path disclosure in all versions up to, and including, 4.4.1. This is due to …

Sep 13, 2024
CVE-2024-5884
6.4 MEDIUM

The Beauty theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tpl_featured_cat_id’ parameter in all versions up to, and including, 1.1.4 due to …

Sep 13, 2024
CVE-2024-5870
6.4 MEDIUM

The Tweaker5 theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the theme's Button shortcode in all versions up to, …

Sep 13, 2024
CVE-2024-5869
6.4 MEDIUM

The Neighborly theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the theme's Button shortcode in all versions up to, …

Sep 13, 2024
CVE-2024-5867
6.4 MEDIUM

The Delicate theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' parameter within the theme's Button shortcode in all versions up to, …

Sep 13, 2024
CVE-2024-5789
6.4 MEDIUM

The Triton Lite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' attribute within the theme's Button shortcode in all versions up …

Sep 13, 2024
CVE-2024-46713
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: perf/aux: Fix AUX buffer serialization Ole reported that event->mmap_mutex is strictly insufficient to serialize the …

Sep 13, 2024
CVE-2022-2446
7.2 HIGH

The WP Editor plugin for WordPress is vulnerable to deserialization of untrusted input via the 'current_theme_root' parameter in versions up to, and including 1.2.9. This …

Sep 13, 2024
CVE-2024-46049
9.8 CRITICAL

Tenda O6 V3.0 firmware V1.0.0.7(2054) contains a stack overflow vulnerability in the formexeCommand function.

Sep 13, 2024
CVE-2024-46048
9.8 CRITICAL

Tenda FH451 v1.0.0.9 has a command injection vulnerability in the formexeCommand function i

Sep 13, 2024
CVE-2024-46047
7.5 HIGH

Tenda FH451 v1.0.0.9 has a stack overflow vulnerability in the fromDhcpListClient function.

Sep 13, 2024
CVE-2024-46046
9.8 CRITICAL

Tenda FH451 v1.0.0.9 has a stack overflow vulnerability located in the RouteStatic function.

Sep 13, 2024
CVE-2024-46045
9.8 CRITICAL

Tenda CH22 V1.0.0.6(468) has a stack overflow vulnerability located in the frmL7PlotForm function.

Sep 13, 2024
CVE-2024-46044
9.8 CRITICAL

CH22 V1.0.0.6(468) has a stack overflow vulnerability located in the fromqossetting function.

Sep 13, 2024
CVE-2024-45113
7.5 HIGH

ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability …

Sep 13, 2024
CVE-2024-45109
7.8 HIGH

Photoshop Desktop versions 24.7.4, 25.11 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Sep 13, 2024
CVE-2024-45108
7.8 HIGH

Photoshop Desktop versions 24.7.4, 25.11 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Sep 13, 2024
CVE-2024-43760
7.8 HIGH

Photoshop Desktop versions 24.7.4, 25.11 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Sep 13, 2024
CVE-2024-43756
7.8 HIGH

Photoshop Desktop versions 24.7.4, 25.11 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Sep 13, 2024
CVE-2024-41874
9.8 CRITICAL

ColdFusion versions 2023.9, 2021.15 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context …

Sep 13, 2024
CVE-2024-6656
9.8 CRITICAL

Use of Hard-coded Credentials vulnerability in TNB Mobile Solutions Cockpit Software allows Read Sensitive Strings Within an Executable.This issue affects Cockpit Software: before v2.13.

Sep 13, 2024
CVE-2024-45112
7.8 HIGH

Acrobat Reader versions 24.002.21005, 24.001.30159, 20.005.30655, 24.003.20054 and earlier are affected by a Type Confusion vulnerability that could result in arbitrary code execution in the …

Sep 13, 2024
CVE-2024-45111
5.5 MEDIUM

Illustrator versions 28.6, 27.9.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage …

Sep 13, 2024
CVE-2024-43759
5.5 MEDIUM

Illustrator versions 28.6, 27.9.5 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to an application denial-of-service (DoS). An attacker could …

Sep 13, 2024
CVE-2024-43758
7.8 HIGH

Illustrator versions 28.6, 27.9.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of …

Sep 13, 2024
CVE-2024-41869
7.8 HIGH

Acrobat Reader versions 24.002.21005, 24.001.30159, 20.005.30655, 24.003.20054 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in …

Sep 13, 2024
CVE-2024-41867
5.5 MEDIUM

After Effects versions 23.6.6, 24.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Sep 13, 2024
CVE-2024-41859
7.8 HIGH

After Effects versions 23.6.6, 24.5 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Sep 13, 2024
CVE-2024-41857
7.8 HIGH

Illustrator versions 28.6, 27.9.5 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the …

Sep 13, 2024
CVE-2024-39385
5.5 MEDIUM

Premiere Pro versions 24.5, 23.6.8 and earlier are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker …

Sep 13, 2024
CVE-2024-39384
7.8 HIGH

Premiere Pro versions 24.5, 23.6.8 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Sep 13, 2024
CVE-2024-39382
5.5 MEDIUM

After Effects versions 23.6.6, 24.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Sep 13, 2024
CVE-2024-39381
7.8 HIGH

After Effects versions 23.6.6, 24.5 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Sep 13, 2024
CVE-2024-39380
7.8 HIGH

After Effects versions 23.6.6, 24.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Sep 13, 2024
CVE-2024-34121
7.8 HIGH

Illustrator versions 28.6, 27.9.5 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context …

Sep 13, 2024
CVE-2024-8742
6.4 MEDIUM

The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Sep 13, 2024
CVE-2024-8665
6.1 MEDIUM

The YITH Custom Login plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL …

Sep 13, 2024
CVE-2024-8664
6.1 MEDIUM

The WP Test Email plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL …

Sep 13, 2024
CVE-2024-8663
6.1 MEDIUM

The WP Simple Booking Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping …

Sep 13, 2024
CVE-2024-7888
6.3 MEDIUM

The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on …

Sep 13, 2024
CVE-2024-5567
6.4 MEDIUM

The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 27.5.5 due to …

Sep 13, 2024
CVE-2024-46712
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Disable coherent dumb buffers without 3d Coherent surfaces make only sense if the host …

Sep 13, 2024
CVE-2024-46711
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: fix ID 0 endp usage after multiple re-creations 'local_addr_used' and 'add_addr_accepted' are decremented …

Sep 13, 2024
CVE-2024-46710
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Prevent unmapping active read buffers The kms paths keep a persistent map active to …

Sep 13, 2024
CVE-2024-46709
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix prime with external buffers Make sure that for external buffers mapping goes through …

Sep 13, 2024
CVE-2024-46708
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: pinctrl: qcom: x1e80100: Fix special pin offsets Remove the erroneus 0x100000 offset to prevent the …

Sep 13, 2024
CVE-2024-46707
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Make ICC_*SGI*_EL1 undef in the absence of a vGICv3 On a system with …

Sep 13, 2024
CVE-2024-46706
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tty: serial: fsl_lpuart: mark last busy before uart_add_one_port With "earlycon initcall_debug=1 loglevel=8" in bootargs, kernel …

Sep 13, 2024
CVE-2024-46705
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/xe: reset mmio mappings with devm Set our various mmio mappings to NULL. This should …

Sep 13, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.