CVE Database

38893+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-21544
8.6 HIGH

Versions of the package spatie/browsershot before 5.0.1 are vulnerable to Improper Input Validation due to improper URL validation in the setUrl method. An attacker can …

Dec 13, 2024
CVE-2024-21543
7.1 HIGH

Versions of the package djoser before 2.3.0 are vulnerable to Authentication Bypass when the authenticate() function fails. This is because the system falls back to …

Dec 13, 2024
CVE-2024-9508
7.8 HIGH

Horner Automation Cscape contains a memory corruption vulnerability, which could allow an attacker to disclose information and execute arbitrary code.

Dec 13, 2024
CVE-2024-12212
7.8 HIGH

The vulnerability occurs in the parsing of CSP files. The issues result from the lack of proper validation of user-supplied data, which could allow reading …

Dec 13, 2024
CVE-2024-55888
7.1 HIGH

Hush Line is an open-source whistleblower management system. Starting in version 0.1.0 and prior to version 0.3.5, the productions server appeared to have been misconfigured …

Dec 12, 2024
CVE-2024-55885
7.5 HIGH

beego is an open-source web framework for the Go programming language. Versions of beego prior to 2.3.4 use MD5 as a hashing algorithm. MD5 is …

Dec 12, 2024
CVE-2024-47238
7.5 HIGH

Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit …

Dec 12, 2024
CVE-2024-21575
8.6 HIGH

ComfyUI-Impact-Pack is vulnerable to Path Traversal. The issue stems from missing validation of the `image.filename` field in a POST request sent to the `/upload/temp` endpoint …

Dec 12, 2024
CVE-2024-28146
8.4 HIGH

The application uses several hard-coded credentials to encrypt config files during backup, to decrypt the new firmware during an update and some passwords allow a …

Dec 12, 2024
CVE-2024-28143
8.4 HIGH

The password change function at /cgi/admin.cgi does not require the current/old password, which makes the application vulnerable to account takeover. An attacker can use this …

Dec 12, 2024
CVE-2024-8233
7.5 HIGH

An issue has been discovered in GitLab CE/EE affecting all versions from 9.4 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. An attacker could …

Dec 12, 2024
CVE-2024-54107
7.1 HIGH

Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.

Dec 12, 2024
CVE-2024-54106
7.1 HIGH

Null pointer dereference vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.

Dec 12, 2024
CVE-2024-54098
8.5 HIGH

Service logic error vulnerability in the system service module Impact: Successful exploitation of this vulnerability may affect service integrity.

Dec 12, 2024
CVE-2024-54097
7.3 HIGH

Security vulnerability in the HiView module Impact: Successful exploitation of this vulnerability may affect feature implementation and integrity.

Dec 12, 2024
CVE-2024-11274
8.7 HIGH

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from …

Dec 12, 2024
CVE-2024-12397
7.4 HIGH

A flaw was found in Quarkus-HTTP, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct …

Dec 12, 2024
CVE-2024-12312
8.1 HIGH

The Print Science Designer plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.152 via deserialization of untrusted …

Dec 12, 2024
CVE-2024-12172
7.5 HIGH

The WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses plugin for WordPress is vulnerable to unauthorized access due to a …

Dec 12, 2024
CVE-2024-12040
8.8 HIGH

The Product Carousel Slider & Grid Ultimate for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, …

Dec 12, 2024
CVE-2024-11052
7.2 HIGH

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the calculations parameter …

Dec 12, 2024
CVE-2024-10499
7.2 HIGH

The AI Engine WordPress plugin before 2.6.5 does not sanitize and escape a parameter from one of its RESP API endpoint before using it in …

Dec 12, 2024
CVE-2024-10910
7.3 HIGH

The The Grid Plus – Unlimited grid layout plugin for WordPress is vulnerable to arbitrary shortcode execution via grid_plus_load_by_category AJAX action in all versions up …

Dec 12, 2024
CVE-2024-10590
8.8 HIGH

The Opt-In Downloads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the admin_upload() function in all versions …

Dec 12, 2024
CVE-2024-11689
8.8 HIGH

The HQ Rental Software plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.29. This is due to …

Dec 12, 2024
CVE-2024-11443
8.8 HIGH

The de:branding plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on …

Dec 12, 2024
CVE-2024-10111
8.1 HIGH

The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 6.26.3. …

Dec 12, 2024
CVE-2024-55658
7.5 HIGH

SiYuan is a personal knowledge management system. Prior to version 3.1.16, SiYuan's /api/export/exportResources endpoint is vulnerable to arbitary file read via path traversal. It is …

Dec 12, 2024
CVE-2024-55657
7.5 HIGH

SiYuan is a personal knowledge management system. Prior to version 3.1.16, an arbitrary file read vulnerability exists in Siyuan's `/api/template/render` endpoint. The absence of proper …

Dec 12, 2024
CVE-2024-54529
7.8 HIGH

A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An app may …

Dec 12, 2024
CVE-2024-54528
7.1 HIGH

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An app may …

Dec 12, 2024
CVE-2024-54515
7.8 HIGH

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.2. A malicious app may be able to gain root …

Dec 12, 2024
CVE-2024-54514
8.6 HIGH

The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura …

Dec 12, 2024
CVE-2024-54508
7.5 HIGH

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.6, macOS Sequoia 15.2, …

Dec 12, 2024
CVE-2024-54505
8.8 HIGH

A type confusion issue was addressed with improved memory handling. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS …

Dec 12, 2024
CVE-2024-54498
8.8 HIGH

A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An app …

Dec 12, 2024
CVE-2024-54489
7.8 HIGH

A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. Running a …

Dec 12, 2024
CVE-2024-54479
7.5 HIGH

The issue was addressed with improved checks. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, tvOS …

Dec 12, 2024
CVE-2024-44291
7.8 HIGH

A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. A malicious …

Dec 12, 2024
CVE-2024-44245
7.1 HIGH

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, macOS Sonoma …

Dec 12, 2024
CVE-2024-44225
7.8 HIGH

A logic issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, macOS Sonoma …

Dec 12, 2024
CVE-2024-44224
7.8 HIGH

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. A malicious app …

Dec 12, 2024
CVE-2024-42407
8.5 HIGH

Insertion of Sensitive Information into Log File (CWE-532) in the Gallagher Command Centre Alarm Transmitter feature could allow an authenticated Operator to view some security …

Dec 12, 2024
CVE-2024-12497
7.3 HIGH

A vulnerability classified as critical has been found in 1000 Projects Attendance Tracking Management System 1.0. Affected is an unknown function of the file /admin/check_admin_login.php. …

Dec 12, 2024
CVE-2024-55587
8.8 HIGH

python-libarchive through 4.2.1 allows directory traversal (to create files) in extract in zip.py for ZipFile.extractall and ZipFile.extract.

Dec 12, 2024
CVE-2024-49142
7.8 HIGH

Microsoft Access Remote Code Execution Vulnerability

Dec 12, 2024
CVE-2024-49138
7.8 HIGH KEV

Windows Common Log File System Driver Elevation of Privilege Vulnerability

Dec 12, 2024
CVE-2024-49132
8.1 HIGH

Windows Remote Desktop Services Remote Code Execution Vulnerability

Dec 12, 2024
CVE-2024-49129
7.5 HIGH

Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability

Dec 12, 2024
CVE-2024-49128
8.1 HIGH

Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.

Dec 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.