CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-45624
7.5 HIGH

Exposure of sensitive information due to incompatible policies issue exists in Pgpool-II. If a database user accesses a query cache, table data unauthorized for the …

Sep 12, 2024
CVE-2024-8711
5.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in SourceCodester Food Ordering Management System 1.0. Affected by this issue is some unknown functionality …

Sep 12, 2024
CVE-2024-8710
6.3 MEDIUM

A vulnerability classified as critical was found in code-projects Inventory Management 1.0. Affected by this vulnerability is an unknown functionality of the file /model/viewProduct.php of …

Sep 12, 2024
CVE-2024-8709
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Best House Rental Management System 1.0. Affected is the function delete_user/save_user of the file /admin_class.php. …

Sep 12, 2024
CVE-2024-38222
6.5 MEDIUM

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

Sep 12, 2024
CVE-2024-8708
3.5 LOW

A vulnerability was found in SourceCodester Best House Rental Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of …

Sep 12, 2024
CVE-2024-37397
8.2 HIGH

An External XML Entity (XXE) vulnerability in the provisioning web service of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote …

Sep 12, 2024
CVE-2024-34785
7.2 HIGH

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve …

Sep 12, 2024
CVE-2024-34783
7.2 HIGH

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve …

Sep 12, 2024
CVE-2024-34779
7.2 HIGH

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve …

Sep 12, 2024
CVE-2024-32848
7.2 HIGH

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve …

Sep 12, 2024
CVE-2024-32846
7.2 HIGH

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve …

Sep 12, 2024
CVE-2024-32845
7.2 HIGH

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve …

Sep 12, 2024
CVE-2024-32843
7.2 HIGH

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve …

Sep 12, 2024
CVE-2024-32842
7.2 HIGH

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve …

Sep 12, 2024
CVE-2024-32840
7.2 HIGH

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve …

Sep 12, 2024
CVE-2024-29847
9.8 CRITICAL

Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to …

Sep 12, 2024
CVE-2024-8707
4.3 MEDIUM

A vulnerability was found in 云课网络科技有限公司 Yunke Online School System up to 3.0.6. It has been declared as problematic. This vulnerability affects the function downfile …

Sep 12, 2024
CVE-2024-8706
4.3 MEDIUM

A vulnerability was found in JFinalCMS up to 20240903. It has been classified as problematic. This affects the function update of the file /admin/template/update of …

Sep 12, 2024
CVE-2024-28981
8.5 HIGH

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.8, including 8.3.x, discloses database passwords when searching metadata injectable fields.

Sep 12, 2024
CVE-2024-8705
6.3 MEDIUM

A vulnerability was found in Shandong Star Measurement and Control Equipment Heating Network Wireless Monitoring System 5.6.2 and classified as critical. Affected by this issue …

Sep 11, 2024
CVE-2024-7890
7.3 HIGH

Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows

Sep 11, 2024
CVE-2024-7889
7.3 HIGH

Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows

Sep 11, 2024
CVE-2024-8694
3.8 LOW

A vulnerability, which was classified as problematic, was found in JFinalCMS up to 20240903. This affects the function update of the file /admin/template/update of the …

Sep 11, 2024
CVE-2024-8693
2.4 LOW

A vulnerability, which was classified as problematic, has been found in Kaon CG3000 1.01.43. Affected by this issue is some unknown functionality of the component …

Sep 11, 2024
CVE-2024-8692
5.3 MEDIUM

A vulnerability classified as critical was found in TDuckCloud TDuckPro up to 6.3. Affected by this vulnerability is an unknown functionality. The manipulation leads to …

Sep 11, 2024
CVE-2024-44541
9.8 CRITICAL

evilnapsis Inventio Lite Versions v4 and before is vulnerable to SQL Injection via the "username" parameter in "/?action=processlogin."

Sep 11, 2024
CVE-2024-42760
7.5 HIGH

SQL Injection vulnerability in Ellevo v.6.2.0.38160 allows a remote attacker to obtain sensitive information via the /api/mob/instrucao/conta/destinatarios component.

Sep 11, 2024
CVE-2024-8691
7.1 HIGH

A vulnerability in the GlobalProtect portal in Palo Alto Networks PAN-OS software enables a malicious authenticated GlobalProtect user to impersonate another GlobalProtect user. Active GlobalProtect …

Sep 11, 2024
CVE-2024-8690
4.4 MEDIUM

A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows administrator privileges to …

Sep 11, 2024
CVE-2024-8689

A problem with the ActiveMQ integration for both Cortex XSOAR and Cortex XSIAM can result in the cleartext exposure of the configured ActiveMQ credentials in …

Sep 11, 2024
CVE-2024-8688
4.4 MEDIUM

An improper neutralization of matching symbols vulnerability in the Palo Alto Networks PAN-OS command line interface (CLI) enables authenticated administrators (including read-only administrators) with access …

Sep 11, 2024
CVE-2024-8687
7.1 HIGH

An information exposure vulnerability exists in Palo Alto Networks PAN-OS software that enables a GlobalProtect end user to learn both the configured GlobalProtect uninstall password …

Sep 11, 2024
CVE-2024-8686
7.2 HIGH

A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as root on …

Sep 11, 2024
CVE-2024-8097

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Payara Platform Payara Server (Logging modules) allows Sensitive credentials posted in plain-text on the server …

Sep 11, 2024
CVE-2024-44577
8.8 HIGH

RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the time_date function.

Sep 11, 2024
CVE-2024-44575
3.7 LOW

RELY-PCIe v22.2.1 to v23.1.0 does not set the Secure attribute for sensitive cookies in HTTPS sessions, which could cause the user agent to send those …

Sep 11, 2024
CVE-2024-44574
8.8 HIGH

RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the sys_conf function.

Sep 11, 2024
CVE-2024-44573
4.7 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the VLAN configuration of RELY-PCIe v22.2.1 to v23.1.0 allows attackers to execute arbitrary web scripts or HTML via …

Sep 11, 2024
CVE-2024-44572
8.8 HIGH

RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the sys_mgmt function.

Sep 11, 2024
CVE-2024-44571
8.8 HIGH

RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain incorrect access control in the mService function at phpinf.php.

Sep 11, 2024
CVE-2024-44570
8.8 HIGH

RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a code injection vulnerability via the getParams function in phpinf.php.

Sep 11, 2024
CVE-2024-20489
8.4 HIGH

A vulnerability in the storage method of the PON Controller configuration file could allow an authenticated, local attacker with low privileges to obtain the MongoDB …

Sep 11, 2024
CVE-2024-20483
7.2 HIGH

Multiple vulnerabilities in Cisco Routed PON Controller Software, which runs as a docker container on hardware that is supported by Cisco IOS XR Software, could …

Sep 11, 2024
CVE-2024-20406
7.4 HIGH

A vulnerability in the segment routing feature for the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker …

Sep 11, 2024
CVE-2024-20398
8.8 HIGH

A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to obtain read/write file system access on the underlying …

Sep 11, 2024
CVE-2024-20390
5.3 MEDIUM

A vulnerability in the Dedicated XML Agent feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service …

Sep 11, 2024
CVE-2024-20381
8.8 HIGH

A vulnerability in the JSON-RPC API feature in Cisco Crosswork Network Services Orchestrator (NSO) and ConfD that is used by the web-based management interfaces of …

Sep 11, 2024
CVE-2024-20343
5.5 MEDIUM

A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to read any file in the file system of …

Sep 11, 2024
CVE-2024-20317
7.4 HIGH

A vulnerability in the handling of specific Ethernet frames by Cisco IOS XR Software for various Cisco Network Convergence System (NCS) platforms could allow an …

Sep 11, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.