CVE Database

38893+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-11289
8.1 HIGH

The Soledad theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.5.9 via several functions like penci_archive_more_post_ajax_func, penci_more_post_ajax_func, …

Dec 6, 2024
CVE-2024-11323
8.8 HIGH

The AI Quiz | Quiz Maker plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a …

Dec 6, 2024
CVE-2024-11178
8.1 HIGH

The Login With OTP plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.4.2. This is due to the plugin …

Dec 6, 2024
CVE-2024-11585
7.5 HIGH

The WP Hide & Security Enhancer plugin for WordPress is vulnerable to arbitrary file contents deletion due to a missing authorization and insufficient file path …

Dec 6, 2024
CVE-2024-10578
8.8 HIGH

The Pubnews theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the pubnews_importer_plugin_action_for_notice() function in all versions …

Dec 6, 2024
CVE-2024-10247
7.2 HIGH

The Video Gallery – Best WordPress YouTube Gallery Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the orderby parameter in all versions …

Dec 6, 2024
CVE-2024-11149
7.9 HIGH

In OpenBSD 7.4 before errata 014, vmm(4) did not restore GDTR limits properly on Intel (VMX) CPUs.

Dec 6, 2024
CVE-2024-38910
7.5 HIGH

Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble version was discovered to contain a use-after-free in the nav2_amcl process. This vulnerability is triggered …

Dec 5, 2024
CVE-2024-37862
7.3 HIGH

Buffer Overflow vulnerability in Open Robotic Robotic Operating System 2 ROS2 navigation2- ROS2-humble&& navigation2-humble allows a local attacker to execute arbitrary code via a crafted …

Dec 5, 2024
CVE-2024-37860
7.3 HIGH

Buffer Overflow vulnerability in Open Robotic Operating System 2 ROS2 navigation2- ROS2-humble&& navigation2-humble allows a local attacker to execute arbitrary code via a crafted .yaml …

Dec 5, 2024
CVE-2024-30964
7.8 HIGH

Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble allows a local attacker to execute arbitrary code via …

Dec 5, 2024
CVE-2024-30963
7.8 HIGH

Buffer Overflow vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble allows a local attacker to execute arbitrary code via …

Dec 5, 2024
CVE-2024-30962
7.8 HIGH

Buffer Overflow vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble allows a local attacker to execute arbitrary code via …

Dec 5, 2024
CVE-2024-30961
7.8 HIGH

Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble allows a local attacker to execute arbitrary code via …

Dec 5, 2024
CVE-2024-53523
7.5 HIGH

JSFinder commit d70ab9bc5221e016c08cffaf0d9ac79646c90645 is vulnerable to Directory Traversal in the find_by_file function.

Dec 5, 2024
CVE-2024-53589
8.4 HIGH

GNU objdump 2.43 is vulnerable to Buffer Overflow in the BFD (Binary File Descriptor) library's handling of tekhex format files.

Dec 5, 2024
CVE-2024-11148
7.5 HIGH

In OpenBSD 7.4 before errata 006 and OpenBSD 7.3 before errata 020, httpd(8) is vulnerable to a NULL dereference when handling a malformed fastcgi request.

Dec 5, 2024
CVE-2024-12130
7.8 HIGH

An “out of bounds read” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file …

Dec 5, 2024
CVE-2024-11156
7.8 HIGH

An “out of bounds write” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the boundaries …

Dec 5, 2024
CVE-2024-11155
7.8 HIGH

A “use after free” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and …

Dec 5, 2024
CVE-2024-53490
7.5 HIGH

Favorites-web 1.3.0 favorites-web has a directory traversal vulnerability in SecurityFilter.java.

Dec 5, 2024
CVE-2024-12234
7.3 HIGH

A vulnerability was found in 1000 Projects Beauty Parlour Management System 1.0. It has been classified as critical. Affected is an unknown function of the …

Dec 5, 2024
CVE-2024-12233
7.3 HIGH

A vulnerability was found in code-projects Online Notice Board up to 1.0 and classified as critical. This issue affects some unknown processing of the file …

Dec 5, 2024
CVE-2024-53857
7.5 HIGH

rPGP is a pure Rust implementation of OpenPGP. Prior to 0.14.1, rPGP allows attackers to trigger resource exhaustion vulnerabilities in rpgp by providing crafted messages. …

Dec 5, 2024
CVE-2024-53856
7.5 HIGH

rPGP is a pure Rust implementation of OpenPGP. Prior to 0.14.1, rPGP allows an attacker to trigger rpgp crashes by providing crafted data. This vulnerability …

Dec 5, 2024
CVE-2024-53472
8.8 HIGH

WeGIA v3.2.0 was discovered to contain a Cross-Site Request Forgery (CSRF).

Dec 5, 2024
CVE-2024-12231
7.3 HIGH

A vulnerability, which was classified as critical, was found in CodeZips Project Management System 1.0. This affects an unknown part of the file /index.php. The …

Dec 5, 2024
CVE-2024-12230
7.3 HIGH

A vulnerability, which was classified as critical, has been found in PHPGurukul Complaint Management System 1.0. Affected by this issue is some unknown functionality of …

Dec 5, 2024
CVE-2024-12229
7.3 HIGH

A vulnerability classified as critical was found in PHPGurukul Complaint Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/complaint-search.php. …

Dec 5, 2024
CVE-2024-11941
7.5 HIGH

A vulnerability in Drupal Core allows Excessive Allocation.This issue affects Drupal Core: from 10.2.0 before 10.2.2, from 10.1.0 before 10.1.8.

Dec 5, 2024
CVE-2024-53703
8.1 HIGH

A vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions mod_httprp library loaded by the Apache web server allows remote attackers to cause …

Dec 5, 2024
CVE-2024-45318
8.1 HIGH

A vulnerability in the SonicWall SMA100 SSLVPN web management interface allows remote attackers to cause Stack-based buffer overflow and potentially lead to code execution.

Dec 5, 2024
CVE-2024-40763
7.5 HIGH

Heap-based buffer overflow vulnerability in the SonicWall SMA100 SSLVPN due to the use of strcpy. This allows remote authenticated attackers to cause Heap-based buffer overflow …

Dec 5, 2024
CVE-2024-12228
7.3 HIGH

A vulnerability classified as critical has been found in PHPGurukul Complaint Management System 1.0. Affected is an unknown function of the file /admin/user-search.php. The manipulation …

Dec 5, 2024
CVE-2024-51546
7.5 HIGH

Credentials Disclosure vulnerabilities allow access to on board project back-up bundles. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

Dec 5, 2024
CVE-2024-51544
8.2 HIGH

Service Control vulnerabilities allow access to service restart requests and vm configuration settings. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series …

Dec 5, 2024
CVE-2024-51543
8.2 HIGH

Information Disclosure vulnerabilities allow access to application configuration information. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

Dec 5, 2024
CVE-2024-51542
8.2 HIGH

Configuration Download vulnerabilities allow access to dependency configuration information. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

Dec 5, 2024
CVE-2024-51541
8.2 HIGH

Local File Inclusion vulnerabilities allow access to sensitive system information. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

Dec 5, 2024
CVE-2024-48847
8.2 HIGH

MD5 Checksum Bypass vulnerabilities where found exploiting a weakness in the way an application dependency calculates or validates MD5 checksum hashes. Affected products: ABB ASPECT …

Dec 5, 2024
CVE-2024-48846
7.1 HIGH

Cross Site Request Forgery vulnerabilities where found providing a potiential for exposing sensitive information or changing system settings. Affected products: ABB ASPECT - Enterprise v3.08.02; …

Dec 5, 2024
CVE-2024-48844
7.7 HIGH

Denial of Service vulnerabilities where found providing a potiential for device service disruptions. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series …

Dec 5, 2024
CVE-2024-48843
7.7 HIGH

Denial of Service vulnerabilities where found providing a potiential for device service disruptions. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series …

Dec 5, 2024
CVE-2024-11316
7.5 HIGH

Fileszie Check vulnerabilities allow a malicious user to bypass size limits or overload to the product. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series …

Dec 5, 2024
CVE-2024-52564
7.5 HIGH

Inclusion of undocumented features or chicken bits issue exists in UD-LT1 firmware Ver.2.1.8 and earlier and UD-LT1/EX firmware Ver.2.1.8 and earlier. A remote attacker may …

Dec 5, 2024
CVE-2024-47133
7.2 HIGH

UD-LT1 firmware Ver.2.1.9 and earlier and UD-LT1/EX firmware Ver.2.1.9 and earlier allow a remote authenticated attacker with an administrative account to execute arbitrary OS commands.

Dec 5, 2024
CVE-2022-41137
8.3 HIGH

Apache Hive Metastore (HMS) uses SerializationUtilities#deserializeObjectWithTypeInformation method when filtering and fetching partitions that is unsafe and can lead to Remote Code Execution (RCE) since it …

Dec 5, 2024
CVE-2024-11429
8.8 HIGH

The Free Responsive Testimonials, Social Proof Reviews, and Customer Reviews – Stars Testimonials plugin for WordPress is vulnerable to Local File Inclusion in all versions …

Dec 5, 2024
CVE-2024-12188
7.3 HIGH

A vulnerability was found in 1000 Projects Library Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Dec 5, 2024
CVE-2024-12187
7.3 HIGH

A vulnerability was found in 1000 Projects Library Management System 1.0. It has been classified as critical. Affected is an unknown function of the file …

Dec 5, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.