CVE Database

38770+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-54663
7.5 HIGH

An issue was discovered in the Webmail Classic UI in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A Local File Inclusion (LFI) vulnerability exists …

Dec 19, 2024
CVE-2024-12700
8.8 HIGH

There is an unrestricted file upload vulnerability where it is possible for an authenticated user (low privileged) to upload an jsp shell and execute code …

Dec 19, 2024
CVE-2024-12729
8.8 HIGH

A post-auth code injection vulnerability in the User Portal allows authenticated users to execute code remotely in Sophos Firewall older than version 21.0 MR1 (21.0.1).

Dec 19, 2024
CVE-2024-12672
7.3 HIGH

A third-party vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the boundaries of allocated memory in a …

Dec 19, 2024
CVE-2024-12175
7.8 HIGH

Another “use after free” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and …

Dec 19, 2024
CVE-2024-11364
7.3 HIGH

Another “uninitialized variable” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force …

Dec 19, 2024
CVE-2024-11157
7.3 HIGH

A third-party vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the boundaries of allocated memory in a …

Dec 19, 2024
CVE-2024-53991
7.5 HIGH

Discourse is an open source platform for community discussion. This vulnerability only impacts Discourse instances configured to use `FileStore::LocalStore` which means uploads and backups are …

Dec 19, 2024
CVE-2024-12111
8.0 HIGH

In a specific scenario a LDAP user can abuse the authentication process using injection attack in OpenText Privileged Access Manager that allows authentication bypass. This …

Dec 19, 2024
CVE-2024-56200
8.6 HIGH

Altair is a fork of Misskey v12. Affected versions lack of request validation and lack of authentication in the image proxy for compressing and resizing …

Dec 19, 2024
CVE-2024-55196
7.5 HIGH

Insufficiently Protected Credentials in the Mail Server Configuration in GoPhish v0.12.1 allows an attacker to access cleartext passwords for the configured IMAP and SMTP servers.

Dec 19, 2024
CVE-2024-38819
7.5 HIGH

Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests …

Dec 19, 2024
CVE-2024-12792
7.3 HIGH

A vulnerability classified as critical was found in Codezips E-Commerce Site 1.0. Affected by this vulnerability is an unknown functionality of the file newadmin.php. The …

Dec 19, 2024
CVE-2024-12791
7.3 HIGH

A vulnerability was found in Codezips E-Commerce Site 1.0. It has been rated as critical. This issue affects some unknown processing of the file signin.php. …

Dec 19, 2024
CVE-2023-7005
7.5 HIGH

A specially crafted message can be sent to the TTLock App that downgrades the encryption protocol used for communication, and can be utilized to compromise …

Dec 19, 2024
CVE-2024-12788
7.3 HIGH

A vulnerability was found in Codezips Technical Discussion Forum 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Dec 19, 2024
CVE-2024-55082
7.5 HIGH

A Server-Side Request Forgery (SSRF) in the endpoint http://{your-server}/url-to-pdf of Stirling-PDF 0.35.1 allows attackers to access sensitive information via a crafted request.

Dec 19, 2024
CVE-2024-12787
7.3 HIGH

A vulnerability has been found in 1000 Projects Attendance Tracking Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality …

Dec 19, 2024
CVE-2024-54790
7.5 HIGH

A SQL Injection vulnerability was found in /index.php in PHPGurukul Pre-School Enrollment System v1.0, which allows remote attackers to execute arbitrary code via the visittime …

Dec 19, 2024
CVE-2024-47093
8.8 HIGH

Improper neutralization of input in Nagvis before version 1.9.42 which can lead to XSS

Dec 19, 2024
CVE-2024-25131
8.8 HIGH

A flaw was found in the MustGather.managed.openshift.io Custom Defined Resource (CRD) of OpenShift Dedicated. A non-privileged user on the cluster can create a MustGather object …

Dec 19, 2024
CVE-2024-12786
7.8 HIGH

A vulnerability, which was classified as critical, was found in X1a0He Adobe Downloader up to 1.3.1 on macOS. Affected is the function shouldAcceptNewConnection of the …

Dec 19, 2024
CVE-2024-12782
7.3 HIGH

A vulnerability has been found in Fujifilm Business Innovation Apeos C3070, Apeos C5570 and Apeos C6580 up to 24.8.28 and classified as critical. This vulnerability …

Dec 19, 2024
CVE-2021-32589
8.1 HIGH

A Use After Free (CWE-416) vulnerability in FortiManager version 7.0.0, version 6.4.5 and below, version 6.2.7 and below, version 6.0.10 and below, version 5.6.10 and …

Dec 19, 2024
CVE-2021-26115
7.8 HIGH

An OS command injection (CWE-78) vulnerability in FortiWAN version 4.5.7 and below Command Line Interface may allow a local, authenticated and unprivileged attacker to escalate …

Dec 19, 2024
CVE-2020-15934
8.8 HIGH

An execution with unnecessary privileges vulnerability in the VCM engine of FortiClient for Linux versions 6.2.7 and below, version 6.4.0. may allow local users to …

Dec 19, 2024
CVE-2024-12569
7.8 HIGH

Disclosure of sensitive information in a Milestone XProtect Device Pack driver’s log file for third-party cameras, allows an attacker to read camera credentials stored in …

Dec 19, 2024
CVE-2024-4230
7.8 HIGH

External Control of File Name or Path vulnerability in Edgecross Basic Software for Windows versions 1.00 and later and Edgecross Basic Software for Developers versions …

Dec 19, 2024
CVE-2024-4229
7.8 HIGH

Incorrect Default Permissions vulnerability in Edgecross Basic Software for Windows versions 1.00 and later and Edgecross Basic Software for Developers versions 1.00 and later allows …

Dec 19, 2024
CVE-2021-26093
7.3 HIGH

An access of uninitialized pointer (CWE-824) vulnerability in FortiWLC versions 8.6.0, 8.5.3 and earlier may allow a local and authenticated attacker to crash the access …

Dec 19, 2024
CVE-2024-11740
7.3 HIGH

The The Download Manager plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.3.03. This is due to …

Dec 19, 2024
CVE-2024-11984
8.8 HIGH

A unrestricted upload of file with dangerous type vulnerability in epaper draft function in Corporate Training Management System before 10.13 allows remote authenticated users to …

Dec 19, 2024
CVE-2024-51532
7.1 HIGH

Dell PowerStore contains an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability. A low privileged attacker with local access could potentially exploit …

Dec 19, 2024
CVE-2024-35141
7.8 HIGH

IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to execution of unnecessary privileges.

Dec 19, 2024
CVE-2023-23354
7.3 HIGH

A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have …

Dec 19, 2024
CVE-2022-27595
7.8 HIGH

An insecure library loading vulnerability has been reported to affect QVPN Device Client. If exploited, the vulnerability could allow local attackers who have gained user …

Dec 19, 2024
CVE-2022-44520
7.8 HIGH

Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary …

Dec 19, 2024
CVE-2022-44518
7.8 HIGH

Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary …

Dec 19, 2024
CVE-2022-44514
7.8 HIGH

Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary …

Dec 19, 2024
CVE-2022-44513
7.8 HIGH

Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by an out-of-bounds write vulnerability that could result in …

Dec 19, 2024
CVE-2022-44512
7.8 HIGH

Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by an out-of-bounds write vulnerability that could result in …

Dec 19, 2024
CVE-2024-56319
7.5 HIGH

In Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0 before e3277eb, unlimited user label appends in a userlabel cluster can lead to a denial of …

Dec 18, 2024
CVE-2024-56318
7.5 HIGH

In raw\TCP.cpp in Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0 before 27ca6ec, there is a NULL pointer dereference in TCPBase::ProcessSingleMessage via TCP packets with …

Dec 18, 2024
CVE-2024-56317
7.5 HIGH

In Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0, the WriteAcl function deletes all existing ACL entries first, and then attempts to recreate them based …

Dec 18, 2024
CVE-2024-56116
8.8 HIGH

A Cross-Site Request Forgery vulnerability in Amiro.CMS before 7.8.4 allows remote attackers to create an administrator account.

Dec 18, 2024
CVE-2024-55506
8.8 HIGH

An IDOR vulnerability in CodeAstro's Complaint Management System v1.0 (version with 0 updates) enables an attacker to execute arbitrary code and obtain sensitive information via …

Dec 18, 2024
CVE-2024-53580
7.5 HIGH

iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function.

Dec 18, 2024
CVE-2024-43106
7.1 HIGH

A library injection vulnerability exists in Microsoft Excel 16.83 for macOS. A specially crafted library can leverage Excel's access privileges, leading to a permission bypass. …

Dec 18, 2024
CVE-2024-42220
7.1 HIGH

A library injection vulnerability exists in Microsoft Outlook 16.83.3 for macOS. A specially crafted library can leverage Outlook's access privileges, leading to a permission bypass. …

Dec 18, 2024
CVE-2024-42004
7.1 HIGH

A library injection vulnerability exists in Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to …

Dec 18, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.