CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-42901
4.8 MEDIUM

A CSV injection vulnerability in Lime Survey v6.5.12 allows attackers to execute arbitrary code via uploading a crafted CSV file.

Sep 3, 2024
CVE-2024-38456
7.8 HIGH

HIGH-LEIT V05.08.01.03 and HIGH-LEIT V04.25.00.00 to 4.25.01.01 for Windows from Vivavis contain an insecure file and folder permissions vulnerability in prunsrv.exe. A regular user (non-admin) …

Sep 3, 2024
CVE-2024-43412
4.6 MEDIUM

Xibo is an open source digital signage platform with a web content management system (CMS). Prior to version 4.1.0, a cross-site scripting vulnerability in Xibo …

Sep 3, 2024
CVE-2023-49233
8.8 HIGH

Insufficient access checks in Visual Planning Admin Center 8 before v.1 Build 240207 allow attackers in possession of a non-administrative Visual Planning account to utilize …

Sep 3, 2024
CVE-2024-6119
7.5 HIGH

Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination …

Sep 3, 2024
CVE-2024-42991
8.1 HIGH

MCMS v5.4.1 has front-end file upload vulnerability which can lead to remote command execution.

Sep 3, 2024
CVE-2024-7654
8.3 HIGH

An ActiveMQ Discovery service was reachable by default from an OpenEdge Management installation when an OEE/OEM auto-discovery feature was activated. Unauthorized access to the discovery …

Sep 3, 2024
CVE-2024-7346
7.2 HIGH

Host name validation for TLS certificates is bypassed when the installed OpenEdge default certificates are used to perform the TLS handshake for a networked connection. …

Sep 3, 2024
CVE-2024-7345
8.3 HIGH

Local ABL Client bypass of the required PASOE security checks may allow an attacker to commit unauthorized code injection into Multi-Session Agents on supported OpenEdge …

Sep 3, 2024
CVE-2024-4259
9.8 CRITICAL

Missing Authorization vulnerability in SAMPAŞ Holding AKOS (AkosCepVatandasService), SAMPAŞ Holding AKOS (TahsilatService) allows Collect Data as Provided by Users. This issue affects AKOS (AkosCepVatandasService): before …

Sep 3, 2024
CVE-2024-34463
5.1 MEDIUM

BPL Personal Weighing Scale PWS-01BT IND/09/18/599 devices send sensitive information in unencrypted BLE packets. (The packet data also lacks authentication and integrity protection.)

Sep 3, 2024
CVE-2024-8389
9.8 CRITICAL

Memory safety bugs present in Firefox 129. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of …

Sep 3, 2024
CVE-2024-8388
5.3 MEDIUM

Multiple prompts and panels from both Firefox and the Android OS could be used to obscure the notification announcing the transition to fullscreen mode after …

Sep 3, 2024
CVE-2024-8387
9.8 CRITICAL

Memory safety bugs present in Firefox 129, Firefox ESR 128.1, and Thunderbird 128.1. Some of these bugs showed evidence of memory corruption and we presume …

Sep 3, 2024
CVE-2024-8386
6.1 MEDIUM

If a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of another site to …

Sep 3, 2024
CVE-2024-8385
9.8 CRITICAL

A difference in the handling of StructFields and ArrayTypes in WASM could be used to trigger an exploitable type confusion vulnerability. This vulnerability affects Firefox …

Sep 3, 2024
CVE-2024-8384
9.8 CRITICAL

The JavaScript garbage collector could mis-color cross-compartment objects if OOM conditions were detected at the right point between two passes. This could have led to …

Sep 3, 2024
CVE-2024-8383
7.5 HIGH

Firefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that the browser does not support. It …

Sep 3, 2024
CVE-2024-8382
8.8 HIGH

Internal browser event interfaces were exposed to web content when privileged EventHandler listener callbacks ran for those events. Web content that tried to use those …

Sep 3, 2024
CVE-2024-8381
9.8 CRITICAL

A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as the `with` environment. This vulnerability …

Sep 3, 2024
CVE-2024-8371

Rejected reason: Duplicate of CVE-2024-45305.

Sep 3, 2024
CVE-2024-6232
7.5 HIGH

There is a MEDIUM severity vulnerability affecting CPython. Regular expressions that allowed excessive backtracking during tarfile.TarFile header parsing are vulnerable to ReDoS via specifically-crafted tar …

Sep 3, 2024
CVE-2024-44921
9.8 CRITICAL

SeaCMS v12.9 was discovered to contain a SQL injection vulnerability via the id parameter at /dmplayer/dmku/index.php?ac=del.

Sep 3, 2024
CVE-2024-44920
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in the component admin_collect_news.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload …

Sep 3, 2024
CVE-2024-6473
7.8 HIGH

Yandex Browser for Desktop before 24.7.1.380 has a DLL Hijacking Vulnerability because an untrusted search path is used.

Sep 3, 2024
CVE-2024-45588
8.1 HIGH

This vulnerability exists in Symphony XTS Web Trading platform version 2.0.0.1_P160 due to improper access controls on APIs in the Preference module of the application. …

Sep 3, 2024
CVE-2024-8374
7.8 HIGH

UltiMaker Cura slicer versions 5.7.0-beta.1 through 5.7.2 are vulnerable to code injection via the 3MF format reader (/plugins/ThreeMFReader.py). The vulnerability arises from improper handling of …

Sep 3, 2024
CVE-2024-45587
8.8 HIGH

This vulnerability exists in Symphony XTS Web Trading platform version 2.0.0.1_P160 due to improper access controls on APIs in the Transaction module of vulnerable application. …

Sep 3, 2024
CVE-2024-45586
8.8 HIGH

This vulnerability exists due to improper access controls on APIs in the Authentication module of Symphony XTS Web Trading and Mobile Trading platforms (version 2.0.0.1_P160). …

Sep 3, 2024
CVE-2024-3655
7.8 HIGH

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel …

Sep 3, 2024
CVE-2024-38811
8.8 HIGH

VMware Fusion (13.x before 13.6) contains a code-execution vulnerability due to the usage of an insecure environment variable. A malicious actor with standard user privileges …

Sep 3, 2024
CVE-2024-37136
6.8 MEDIUM

Dell Path to PowerProtect, versions 1.1, 1.2, contains an Exposure of Private Personal Information to an Unauthorized Actor vulnerability. A remote high privileged attacker could …

Sep 3, 2024
CVE-2024-7261
9.8 CRITICAL

The improper neutralization of special elements in the parameter "host" in the CGI program of Zyxel NWA1123ACv3 firmware version 6.70(ABVT.4) and earlier, WAC500 firmware version …

Sep 3, 2024
CVE-2024-42061
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in the CGI program "dynamic_script.cgi" of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware …

Sep 3, 2024
CVE-2024-7203
7.2 HIGH

A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.60 through V5.38 and USG FLEX series firmware versions from V4.60 through V5.38 …

Sep 3, 2024
CVE-2024-6343
4.9 MEDIUM

A buffer overflow vulnerability in the CGI program of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 …

Sep 3, 2024
CVE-2024-5412
7.5 HIGH

A buffer overflow vulnerability in the library "libclinkc" of the Zyxel VMG8825-T50K firmware version 5.50(ABOM.8)C0 could allow an unauthenticated attacker to cause denial of service …

Sep 3, 2024
CVE-2024-42060
7.2 HIGH

A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG …

Sep 3, 2024
CVE-2024-42059
7.2 HIGH

A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V5.00 through V5.38, USG FLEX series firmware versions from V5.00 through V5.38, USG …

Sep 3, 2024
CVE-2024-42058
7.5 HIGH

A null pointer dereference vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG …

Sep 3, 2024
CVE-2024-42057
8.1 HIGH

A command injection vulnerability in the IPSec VPN feature of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from …

Sep 3, 2024
CVE-2024-8380
6.3 MEDIUM

A vulnerability was found in SourceCodester Contact Manager with Export to VCF 1.0. It has been rated as critical. This issue affects some unknown processing …

Sep 3, 2024
CVE-2024-45623
9.8 CRITICAL

D-Link DAP-2310 Hardware A Firmware 1.16RC028 allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the ATP binary that handles PHP …

Sep 2, 2024
CVE-2024-1621
7.5 HIGH

The registration process of uniFLOW Online (NT-ware product) apps, prior to and including version 2024.1.0, can be compromised when email login is enabled on the …

Sep 2, 2024
CVE-2024-45622
9.8 CRITICAL

ASIS (aka Aplikasi Sistem Sekolah using CodeIgniter 3) 3.0.0 through 3.2.0 allows index.php username SQL injection for Authentication Bypass.

Sep 2, 2024
CVE-2024-45621
5.4 MEDIUM

The Electron desktop application of Rocket.Chat through 6.3.4 allows stored XSS via links in an uploaded file, related to failure to use a separate browser …

Sep 2, 2024
CVE-2024-6921
7.5 HIGH

Cleartext Storage of Sensitive Information vulnerability in NAC Telecommunication Systems Inc. NACPremium allows Retrieve Embedded Sensitive Data.This issue affects NACPremium: through 01082024.

Sep 2, 2024
CVE-2024-6920
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NAC Telecommunication Systems Inc. NACPremium allows Stored XSS.This issue affects NACPremium: through 01082024.

Sep 2, 2024
CVE-2024-6919
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NAC Telecommunication Systems Inc. NACPremium allows Blind SQL Injection.This issue affects …

Sep 2, 2024
CVE-2024-45388
7.5 HIGH

Hoverfly is a lightweight service virtualization/ API simulation / API mocking tool for developers and testers. The `/api/v2/simulation` POST handler allows users to create new …

Sep 2, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.