CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-45313
5.4 MEDIUM

Overleaf is a web-based collaborative LaTeX editor. When installing Server Pro using the Overleaf Toolkit from before 2024-07-17 or legacy docker-compose.yml from before 2024-08-28, the …

Sep 2, 2024
CVE-2024-45312
5.3 MEDIUM

Overleaf is a web-based collaborative LaTeX editor. Overleaf Community Edition and Server Pro prior to version 5.0.7 (or 4.2.7 for the 4.x series) contain a …

Sep 2, 2024
CVE-2024-45311
7.5 HIGH

Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. As of quinn-proto 0.11, it is possible for a server to `accept()`, `retry()`, …

Sep 2, 2024
CVE-2024-45308
6.5 MEDIUM

HedgeDoc is an open source, real-time, collaborative, markdown notes application. When using HedgeDoc 1 with MySQL or MariaDB, it is possible to create notes with …

Sep 2, 2024
CVE-2024-45306
4.5 MEDIUM

Vim is an open source, command line text editor. Patch v9.1.0038 optimized how the cursor position is calculated and removed a loop, that verified that …

Sep 2, 2024
CVE-2024-45305
2.5 LOW

gix-path is a crate of the gitoxide project dealing with git paths and their conversions. `gix-path` executes `git` to find the path of a configuration …

Sep 2, 2024
CVE-2024-44947
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fuse: Initialize beyond-EOF page contents before setting uptodate fuse_notify_store(), unlike fuse_do_readpage(), does not enable page …

Sep 2, 2024
CVE-2024-43801
4.6 MEDIUM

Jellyfin is an open source self hosted media server. The Jellyfin user profile image upload accepts SVG files, allowing for a stored XSS attack against …

Sep 2, 2024
CVE-2024-43797
6.3 MEDIUM

audiobookshelf is a self-hosted audiobook and podcast server. A non-admin user is not allowed to create libraries (or access only the ones they have permission …

Sep 2, 2024
CVE-2024-43792
6.3 MEDIUM

Halo is an open source website building tool. A security vulnerability has been identified in versions prior to 2.17.0 of the Halo project. This vulnerability …

Sep 2, 2024
CVE-2024-42471
7.3 HIGH

actions/artifact is the GitHub ToolKit for developing GitHub Actions. Versions of `actions/artifact` on the 2.x branch before 2.1.2 are vulnerable to arbitrary file write when …

Sep 2, 2024
CVE-2024-28100
8.9 HIGH

eLabFTW is an open source electronic lab notebook for research labs. By uploading specially crafted files, a regular user can create a circumstance where a …

Sep 2, 2024
CVE-2023-7279
2.6 LOW

A vulnerability has been found in Secure Systems Engineering Connaisseur up to 3.3.0 and classified as problematic. This vulnerability affects unknown code of the file …

Sep 2, 2024
CVE-2020-36830
4.3 MEDIUM

A vulnerability was found in nescalante urlregex up to 0.5.0 and classified as problematic. This issue affects some unknown processing of the file index.js of …

Sep 2, 2024
CVE-2024-8004
8.7 HIGH

A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary …

Sep 2, 2024
CVE-2024-7939
8.7 HIGH

A stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser …

Sep 2, 2024
CVE-2024-7938
8.7 HIGH

A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script …

Sep 2, 2024
CVE-2024-7932
8.7 HIGH

A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer on Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser …

Sep 2, 2024
CVE-2024-5148
7.5 HIGH

A flaw was found in the gnome-remote-desktop package. The gnome-remote-desktop system daemon performs inadequate validation of session agents using D-Bus methods related to transitioning a …

Sep 2, 2024
CVE-2024-38858
6.1 MEDIUM

Improper neutralization of input in Checkmk before version 2.3.0p14 allows attackers to inject and run malicious scripts in the Robotmk logs view.

Sep 2, 2024
CVE-2024-38402
7.8 HIGH

Memory corruption while processing IOCTL call for getting group info.

Sep 2, 2024
CVE-2024-38401
7.8 HIGH

Memory corruption while processing concurrent IOCTL calls.

Sep 2, 2024
CVE-2024-33060
8.4 HIGH

Memory corruption when two threads try to map and unmap a single node simultaneously.

Sep 2, 2024
CVE-2024-33057
7.5 HIGH

Transient DOS while parsing the multi-link element Control field when common information length check is missing before updating the location.

Sep 2, 2024
CVE-2024-33054
7.8 HIGH

Memory corruption during the handshake between the Primary Virtual Machine and Trusted Virtual Machine.

Sep 2, 2024
CVE-2024-33052
7.8 HIGH

Memory corruption when user provides data for FM HCI command control operations.

Sep 2, 2024
CVE-2024-33051
7.5 HIGH

Transient DOS while processing TIM IE from beacon frame as there is no check for IE length.

Sep 2, 2024
CVE-2024-33050
7.5 HIGH

Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improper.

Sep 2, 2024
CVE-2024-33048
7.5 HIGH

Transient DOS while parsing the received TID-to-link mapping element of beacon/probe response frame.

Sep 2, 2024
CVE-2024-33047
8.4 HIGH

Memory corruption when the captureRead QDCM command is invoked from user-space.

Sep 2, 2024
CVE-2024-33045
8.4 HIGH

Memory corruption when BTFM client sends new messages over Slimbus to ADSP.

Sep 2, 2024
CVE-2024-33043
5.5 MEDIUM

Transient DOS while handling PS event when Program Service name length offset value is set to 255.

Sep 2, 2024
CVE-2024-33042
7.8 HIGH

Memory corruption when Alternative Frequency offset value is set to 255.

Sep 2, 2024
CVE-2024-33038
7.8 HIGH

Memory corruption while passing untrusted/corrupted pointers from DSP to EVA.

Sep 2, 2024
CVE-2024-33035
8.4 HIGH

Memory corruption while calculating total metadata size when a very high reserved size is requested by gralloc clients.

Sep 2, 2024
CVE-2024-33016
6.8 MEDIUM

memory corruption when an invalid firehose patch command is invoked.

Sep 2, 2024
CVE-2024-23365
8.4 HIGH

Memory corruption while releasing shared resources in MinkSocket listener thread.

Sep 2, 2024
CVE-2024-23364
7.5 HIGH

Transient DOS when processing the non-transmitted BSSID profile sub-elements present within the MBSSID Information Element (IE) of a beacon frame that is received from over-the-air …

Sep 2, 2024
CVE-2024-23362
7.1 HIGH

Cryptographic issue while parsing RSA keys in COBR format.

Sep 2, 2024
CVE-2024-23359
8.2 HIGH

Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network.

Sep 2, 2024
CVE-2024-23358
7.5 HIGH

Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in Modem.

Sep 2, 2024
CVE-2024-7692
6.1 MEDIUM

The Flaming Forms WordPress plugin through 1.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Sep 2, 2024
CVE-2024-7691
6.1 MEDIUM

The Flaming Forms WordPress plugin through 1.0.1 does not sanitise and escape some parameters, which could allow unauthenticated users to perform Cross-Site Scripting attacks against …

Sep 2, 2024
CVE-2024-7690
4.3 MEDIUM

The DN Popup WordPress plugin through 1.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

Sep 2, 2024
CVE-2024-7354
6.1 MEDIUM

The Ninja Forms WordPress plugin before 3.8.11 does not escape an URL before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting …

Sep 2, 2024
CVE-2024-8365
6.2 MEDIUM

Vault Community Edition and Vault Enterprise experienced a regression where functionality that HMAC’d sensitive headers in the configured audit device, specifically client tokens and token …

Sep 2, 2024
CVE-2024-7871
8.8 HIGH

SQL Injection in online dictionary function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the …

Sep 2, 2024
CVE-2024-45528
5.4 MEDIUM

CodeAstro MembershipM-PHP (aka Membership Management System in PHP) 1.0 allows add_members.php fullname stored XSS.

Sep 2, 2024
CVE-2024-45527
6.1 MEDIUM

REDCap 14.7.0 allows HTML injection via the project title of a New Project action. This can lead to resultant logout CSRF via index.php?logout=1, and can …

Sep 2, 2024
CVE-2024-43776
8.8 HIGH

SQL Injection in mock exam function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the …

Sep 2, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.