CVE Database

38770+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-53173
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: NFSv4.0: Fix a use-after-free problem in the asynchronous open() Yang Erkun reports that when two …

Dec 27, 2024
CVE-2024-53171
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ubifs: authentication: Fix use-after-free in ubifs_tnc_end_commit After an insertion in TNC, the tree might split …

Dec 27, 2024
CVE-2024-53170
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: block: fix uaf for flush rq while iterating tags blk_mq_clear_flush_rq_mapping() is not called during scsi …

Dec 27, 2024
CVE-2024-53168
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: sunrpc: fix one UAF issue caused by sunrpc kernel tcp socket BUG: KASAN: slab-use-after-free in …

Dec 27, 2024
CVE-2024-53166
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: block, bfq: fix bfqq uaf in bfq_limit_depth() Set new allocated bfqq to bic or remove …

Dec 27, 2024
CVE-2024-53165
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: sh: intc: Fix use-after-free bug in register_intc_controller() In the error handling for this function, d …

Dec 27, 2024
CVE-2024-3393
7.5 HIGH KEV

A Denial of Service vulnerability in the DNS Security feature of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to send a malicious packet …

Dec 27, 2024
CVE-2020-9236
8.8 HIGH

There is an improper interface design vulnerability in Huawei product. A module interface of the impated product does not deal with some operations properly. Attackers …

Dec 27, 2024
CVE-2020-9222
7.0 HIGH

There is a privilege escalation vulnerability in Huawei FusionCompute product. Due to insufficient verification on specific files that need to be deserialized, local attackers can …

Dec 27, 2024
CVE-2020-9080
7.8 HIGH

There is an improper privilege management vulnerability in Huawei smart phone product. A local, authenticated attacker could craft a specific input to exploit this vulnerability. …

Dec 27, 2024
CVE-2024-56527
7.5 HIGH

An issue was discovered in TCPDF before 6.8.0. The Error function lacks an htmlspecialchars call for the error message.

Dec 27, 2024
CVE-2024-56522
7.5 HIGH

An issue was discovered in TCPDF before 6.8.0. unserializeTCPDFtag uses != (aka loose comparison) and does not use a constant-time function to compare TCPDF tag …

Dec 27, 2024
CVE-2024-56520
7.3 HIGH

An issue was discovered in tc-lib-pdf-font before 2.6.4, as used in TCPDF before 6.8.0 and other products. Fonts are mishandled, e.g., FontBBox for Type 1 …

Dec 27, 2024
CVE-2024-56519
7.5 HIGH

An issue was discovered in TCPDF before 6.8.0. setSVGStyles does not sanitize the SVG font-family attribute.

Dec 27, 2024
CVE-2024-12978
7.3 HIGH

A vulnerability has been found in code-projects Job Recruitment 1.0 and classified as critical. This vulnerability affects the function add_req of the file /_parse/_all_edits.php. The …

Dec 27, 2024
CVE-2024-12976
7.3 HIGH

A vulnerability, which was classified as critical, has been found in CodeZips Hospital Management System 1.0. Affected by this issue is some unknown functionality of …

Dec 27, 2024
CVE-2024-12969
7.3 HIGH

A vulnerability, which was classified as critical, has been found in code-projects Hospital Management System 1.0. Affected by this issue is some unknown functionality of …

Dec 26, 2024
CVE-2024-53850
8.2 HIGH

The Addressing GLPI plugin enables you to create IP reports for visualize IP addresses used and free on a given network.. Starting with 3.0.0 and …

Dec 26, 2024
CVE-2024-45600
7.7 HIGH

Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to 1.21.13, an authenticated user can perform a …

Dec 26, 2024
CVE-2024-12968
7.3 HIGH

A vulnerability classified as critical was found in code-projects Job Recruitment 1.0. Affected by this vulnerability is the function edit_jobpost of the file /_parse/_all_edits.php. The …

Dec 26, 2024
CVE-2024-12967
7.3 HIGH

A vulnerability classified as critical has been found in code-projects Job Recruitment 1.0. Affected is the function fln_update of the file /_parse/_all_edits.php. The manipulation of …

Dec 26, 2024
CVE-2024-12966
7.3 HIGH

A vulnerability was found in code-projects Job Recruitment 1.0. It has been rated as critical. This issue affects the function cn_update of the file /_parse/_all_edits.php. …

Dec 26, 2024
CVE-2024-12965
7.3 HIGH

A vulnerability was found in 1000 Projects Portfolio Management System MCA 1.0. It has been declared as critical. This vulnerability affects unknown code of the …

Dec 26, 2024
CVE-2024-12964
7.3 HIGH

A vulnerability was found in 1000 Projects Daily College Class Work Report Book 1.0. It has been classified as critical. This affects an unknown part …

Dec 26, 2024
CVE-2024-12963
7.3 HIGH

A vulnerability was found in code-projects Job Recruitment 1.0 and classified as critical. Affected by this issue is the function add_xp of the file /_parse/_all_edits.php. …

Dec 26, 2024
CVE-2024-54907
8.8 HIGH

TOTOLINK A3002R V4.0.0-B20230531.1404 is vulnerable to Remote Code Execution in /bin/boa via formWsc.

Dec 26, 2024
CVE-2024-12962
7.3 HIGH

A vulnerability has been found in code-projects Job Recruitment 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file …

Dec 26, 2024
CVE-2024-12961
7.3 HIGH

A vulnerability, which was classified as critical, was found in 1000 Projects Portfolio Management System MCA 1.0. Affected is an unknown function of the file …

Dec 26, 2024
CVE-2024-12960
7.3 HIGH

A vulnerability, which was classified as critical, has been found in 1000 Projects Portfolio Management System MCA 1.0. This issue affects some unknown processing of …

Dec 26, 2024
CVE-2024-51540
8.1 HIGH

Dell ECS, versions prior to 3.8.1.3 contains an arithmetic overflow vulnerability exists in retention period handling of ECS. An authenticated user with bucket or object-level …

Dec 26, 2024
CVE-2024-12959
7.3 HIGH

A vulnerability classified as critical was found in 1000 Projects Portfolio Management System MCA 1.0. This vulnerability affects unknown code of the file /update_personal_details.php. The …

Dec 26, 2024
CVE-2024-12958
7.3 HIGH

A vulnerability classified as critical has been found in 1000 Projects Portfolio Management System MCA 1.0. This affects an unknown part of the file /update_pro_details.php. …

Dec 26, 2024
CVE-2024-12946
7.3 HIGH

A vulnerability, which was classified as critical, has been found in 1000 Projects Attendance Tracking Management System 1.0. This issue affects some unknown processing of …

Dec 26, 2024
CVE-2024-12945
7.3 HIGH

A vulnerability classified as critical was found in code-projects Simple Car Rental System 1.0. This vulnerability affects unknown code of the file /account.php. The manipulation …

Dec 26, 2024
CVE-2024-12944
7.3 HIGH

A vulnerability was found in CodeAstro House Rental Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

Dec 26, 2024
CVE-2024-12943
7.3 HIGH

A vulnerability was found in CodeAstro House Rental Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Dec 26, 2024
CVE-2023-7300
8.0 HIGH

Huawei Home Music System has a path traversal vulnerability. Successful exploitation of this vulnerability may cause the music host file to be deleted or the …

Dec 26, 2024
CVE-2024-12942
7.3 HIGH

A vulnerability was found in 1000 Projects Portfolio Management System MCA 1.0. It has been classified as critical. Affected is an unknown function of the …

Dec 26, 2024
CVE-2024-12940
7.3 HIGH

A vulnerability has been found in 1000 Projects Attendance Tracking Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file …

Dec 26, 2024
CVE-2024-12652
8.8 HIGH

A Improper Control of Generation of Code ('Code Injection') vulnerability in groovy script function in SmartRobot′s Conversational AI Platform before v7.2.0 allows remote authenticated users …

Dec 26, 2024
CVE-2024-12927
7.3 HIGH

A vulnerability, which was classified as critical, has been found in 1000 Projects Attendance Tracking Management System 1.0. Affected by this issue is some unknown …

Dec 25, 2024
CVE-2024-53291
7.5 HIGH

Dell NativeEdge, version(s) 2.1.0.0, contain(s) an Exposure of Sensitive Information Through Metadata vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading …

Dec 25, 2024
CVE-2024-52535
7.1 HIGH

Dell SupportAssist for Home PCs versions 4.6.1 and prior and Dell SupportAssist for Business PCs versions 4.5.0 and prior, contain a symbolic link (symlink) attack …

Dec 25, 2024
CVE-2024-47978
7.8 HIGH

Dell NativeEdge, version(s) 2.1.0.0, contain(s) an Execution with Unnecessary Privileges vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to …

Dec 25, 2024
CVE-2024-12428
7.5 HIGH

The WP Data Access – App, Table, Form and Chart Builder plugin plugin for WordPress is vulnerable to SQL Injection via the 'order[user_login][dir]' parameter in …

Dec 25, 2024
CVE-2024-12272
8.8 HIGH

The WP Travel Engine – Elementor Widgets | Create Travel Booking Website Using WordPress and Elementor plugin for WordPress is vulnerable to Local File Inclusion …

Dec 25, 2024
CVE-2019-2483
8.2 HIGH

Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, …

Dec 24, 2024
CVE-2024-12746
8.0 HIGH

A SQL injection in the Amazon Redshift ODBC Driver v2.1.5.0 (Windows or Linux) allows a user to gain escalated privileges via the SQLTables or SQLColumns …

Dec 24, 2024
CVE-2024-12745
8.0 HIGH

A SQL injection in the Amazon Redshift Python Connector v2.1.4 allows a user to gain escalated privileges via the get_schemas, get_tables, or get_columns Metadata APIs. …

Dec 24, 2024
CVE-2024-12744
8.0 HIGH

A SQL injection in the Amazon Redshift JDBC Driver in v2.1.0.31 allows a user to gain escalated privileges via the getSchemas, getTables, or getColumns Metadata …

Dec 24, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.