CVE Database

38770+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-53162
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: crypto: qat/qat_4xxx - fix off by one in uof_get_name() The fw_objs[] array has "num_objs" elements …

Dec 24, 2024
CVE-2024-53156
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: add range check for conn_rsp_epid in htc_connect_service() I found the following bug in …

Dec 24, 2024
CVE-2024-53155
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: ocfs2: fix uninitialized value in ocfs2_file_read_iter() Syzbot has reported the following KMSAN splat: BUG: KMSAN: …

Dec 24, 2024
CVE-2024-53150
7.1 HIGH KEV

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix out of bounds reads when finding clock sources The current USB-audio driver …

Dec 24, 2024
CVE-2024-53147
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: exfat: fix out-of-bounds access of directory entries In the case of the directory size is …

Dec 24, 2024
CVE-2024-12881
8.8 HIGH

The PlugVersions – Easily rollback to previous versions of your plugins plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability …

Dec 24, 2024
CVE-2024-12594
8.8 HIGH

The Custom Login Page Styler – Login Protected Private Site , Change wp-admin login url , WordPress login logo , Temporary admin login access , …

Dec 24, 2024
CVE-2024-47515
8.1 HIGH

A vulnerability was found in Pagure. Support of symbolic links during repository archiving of repositories allows the disclosure of local files. This flaw allows a …

Dec 24, 2024
CVE-2024-12582
7.1 HIGH

A flaw was found in the skupper console, a read-only interface that renders cluster network, traffic details, and metrics for a network application that a …

Dec 24, 2024
CVE-2024-53961
8.1 HIGH

ColdFusion versions 2023.11, 2021.17 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead …

Dec 23, 2024
CVE-2024-56363
7.8 HIGH

APTRS (Automated Penetration Testing Reporting System) is a Python and Django-based automated reporting tool designed for penetration testers and security organizations. In 1.0, there is …

Dec 23, 2024
CVE-2024-56362
7.1 HIGH

Navidrome is an open source web-based music collection server and streamer. Navidrome stores the JWT secret in plaintext in the navidrome.db database file under the …

Dec 23, 2024
CVE-2024-56326
7.8 HIGH

Jinja is an extensible templating engine. Prior to 3.1.5, An oversight in how the Jinja sandboxed environment detects calls to str.format allows an attacker that …

Dec 23, 2024
CVE-2024-56201
8.8 HIGH

Jinja is an extensible templating engine. In versions on the 3.x branch prior to 3.1.5, a bug in the Jinja compiler allows an attacker that …

Dec 23, 2024
CVE-2024-55947
8.8 HIGH

Gogs is an open source self-hosted Git service. A malicious user is able to write a file to an arbitrary path on the server to …

Dec 23, 2024
CVE-2024-53256
7.8 HIGH

Rizin is a UNIX-like reverse engineering framework and command-line toolset. `rizin.c` still had an old snippet of code which suffered a command injection due the …

Dec 23, 2024
CVE-2024-12903
7.8 HIGH

Incorrect default permissions vulnerability in Evoko Home, affecting version 2.4.2 to 2.7.4. A non-admin user could exploit weak file and folder permissions to escalate privileges, …

Dec 23, 2024
CVE-2024-12902
8.4 HIGH

ANCHOR from Global Wisdom Software is an integrated product running on a Windows virtual machine. The underlying Windows OS of the product contains high-privilege service …

Dec 23, 2024
CVE-2024-54082
7.2 HIGH

home 5G HR02 and Wi-Fi STATION SH-54C contain an OS command injection vulnerability in the configuration restore function. An arbitrary OS command may be executed …

Dec 23, 2024
CVE-2024-45721
7.2 HIGH

home 5G HR02, Wi-Fi STATION SH-52B, and Wi-Fi STATION SH-54C contain an OS command injection vulnerability in the HOST name configuration screen. An arbitrary OS …

Dec 23, 2024
CVE-2024-12899
7.3 HIGH

A vulnerability was found in 1000 Projects Attendance Tracking Management System 1.0. It has been rated as critical. This issue affects some unknown processing of …

Dec 23, 2024
CVE-2024-56375
7.5 HIGH

An integer underflow was discovered in Fort 1.6.3 and 1.6.4 before 1.6.5. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve …

Dec 22, 2024
CVE-2024-56311
8.8 HIGH

REDCap through 14.9.6 has a security flaw in the Notes section of calendar events, exposing users to a Cross-Site Request Forgery (CSRF) attack. An attacker …

Dec 22, 2024
CVE-2024-56310
8.8 HIGH

REDCap through 14.9.6 has a security flaw in the Project Dashboards name, exposing users to a Cross-Site Request Forgery (CSRF) attack. An attacker can exploit …

Dec 22, 2024
CVE-2024-12884
7.3 HIGH

A vulnerability was found in Codezips E-Commerce Website 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the …

Dec 21, 2024
CVE-2024-12771
8.8 HIGH

The eCommerce Product Catalog Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.3.43. This …

Dec 21, 2024
CVE-2024-12721
7.2 HIGH

The Custom Product Tabs For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.2.4 via deserialization …

Dec 21, 2024
CVE-2024-12066
8.8 HIGH

The SMSA Shipping(official) plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the smsa_delete_label() function in all versions …

Dec 21, 2024
CVE-2024-11977
7.3 HIGH

The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up …

Dec 21, 2024
CVE-2023-31279
8.1 HIGH

The AirVantage platform is vulnerable to an unauthorized attacker registering previously unregistered devices on the AirVantage platform when the owner has not disabled the AirVantage …

Dec 21, 2024
CVE-2020-13712
7.8 HIGH

A command injection is possible through the user interface, allowing arbitrary command execution as the root user. oMG2000 running MGOS 3.15.1 or earlier is affected. …

Dec 20, 2024
CVE-2024-56359
8.1 HIGH

grist-core is a spreadsheet hosting server. A user visiting a malicious document and clicking on a link in a HyperLink cell using a control modifier …

Dec 20, 2024
CVE-2024-56358
8.1 HIGH

grist-core is a spreadsheet hosting server. A user visiting a malicious document and previewing an attachment could have their account compromised, because JavaScript in an …

Dec 20, 2024
CVE-2024-56357
8.1 HIGH

grist-core is a spreadsheet hosting server. A user visiting a malicious document or submitting a malicious form could have their account compromised, because it was …

Dec 20, 2024
CVE-2024-56335
7.6 HIGH

vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. In affected versions an attacker is capable of updating or deleting …

Dec 20, 2024
CVE-2024-56334
7.8 HIGH

systeminformation is a System and OS information library for node.js. In affected versions SSIDs are not sanitized when before they are passed as a parameter …

Dec 20, 2024
CVE-2024-37758
8.8 HIGH

Improper access control in the endpoint /RoleMenuMapping/AddRoleMenu of Digiteam v4.21.0.0 allows authenticated attackers to escalate privileges.

Dec 20, 2024
CVE-2024-12677
7.8 HIGH

Delta Electronics DTM Soft deserializes objects, which could allow an attacker to execute arbitrary code.

Dec 20, 2024
CVE-2024-55470
7.5 HIGH

Oqtane Framework 6.0.0 is vulnerable to Incorrect Access Control. By manipulating the entityid parameter, attackers can bypass passcode validation and successfully log into the application …

Dec 20, 2024
CVE-2024-40695
8.0 HIGH

IBM Cognos Analytics 11.2.0 through 11.2.4 FP4 and 12.0.0 through 12.0.4 could be vulnerable to malicious file upload by not validating the content of the …

Dec 20, 2024
CVE-2024-21549
8.6 HIGH

Versions of the package spatie/browsershot before 5.0.3 are vulnerable to Improper Input Validation due to improper URL validation through the setUrl method. An attacker can …

Dec 20, 2024
CVE-2024-44195
7.5 HIGH

A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.1. An app may be able to read arbitrary files.

Dec 20, 2024
CVE-2023-42867
7.8 HIGH

This issue was addressed with improved validation of the process entitlement and Team ID. This issue is fixed in GarageBand 10.4.9. An app may be …

Dec 20, 2024
CVE-2022-34159
7.5 HIGH

Huawei printers have an input verification vulnerability. Successful exploitation of this vulnerability may cause device service exceptions. (Vulnerability ID: HWPSIRT-2022-80078) This vulnerability has been assigned …

Dec 20, 2024
CVE-2022-32204
7.5 HIGH

There is an improper input verification vulnerability in Huawei printer product. Successful exploitation of this vulnerability may cause service abnormal. (Vulnerability ID: HWPSIRT-2022-87185) This vulnerability …

Dec 20, 2024
CVE-2022-32144
8.6 HIGH

There is an insufficient input verification vulnerability in Huawei product. Successful exploitation of this vulnerability may lead to service abnormal. (Vulnerability ID: HWPSIRT-2022-76192) This vulnerability …

Dec 20, 2024
CVE-2024-54538
7.5 HIGH

A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS …

Dec 20, 2024
CVE-2024-12831
7.8 HIGH

Arista NG Firewall uvm_login Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Arista NG Firewall. An …

Dec 20, 2024
CVE-2024-12830
7.3 HIGH

Arista NG Firewall custom_handler Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Arista NG …

Dec 20, 2024
CVE-2024-12829
8.8 HIGH

Arista NG Firewall ExecManagerImpl Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Arista NG …

Dec 20, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.