CVE Database

38893+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2018-9402
7.8 HIGH

In multiple functions of gl_proc.c, there is a buffer overwrite due to a missing bounds check. This could lead to escalation of privileges in the …

Dec 5, 2024
CVE-2024-50947
7.5 HIGH

An issue in kmqtt v0.2.7 allows attackers to cause a Denial of Service (DoS) via a crafted request.

Dec 4, 2024
CVE-2024-39219
8.8 HIGH

An issue in Aginode GigaSwitch V5 before version 7.06G allows authenticated attackers with Administrator privileges to upload an earlier firmware version, exposing the device to …

Dec 4, 2024
CVE-2024-12149
8.1 HIGH

Incorrect permission assignment in temporary access requests component in Devolutions Remote Desktop Manager 2024.3.19.0 and earlier on Windows allows an authenticated user that request temporary …

Dec 4, 2024
CVE-2024-39163
8.8 HIGH

binux pyspider up to v0.3.10 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Flask endpoints.

Dec 4, 2024
CVE-2024-37575
7.5 HIGH

The Mister org.mistergroup.shouldianswer application 1.4.264 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted …

Dec 4, 2024
CVE-2024-37574
8.2 HIGH

The GriceMobile com.grice.call application 4.5.2 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted …

Dec 4, 2024
CVE-2024-11643
8.8 HIGH

The Accessibility by AllAccessible plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability …

Dec 4, 2024
CVE-2024-53139
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: sctp: fix possible UAF in sctp_v6_available() A lockdep report [1] with CONFIG_PROVE_RCU_LIST=y hints that sctp_v6_available() …

Dec 4, 2024
CVE-2024-53133
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Handle dml allocation failure to avoid crash [Why] In the case where a dml …

Dec 4, 2024
CVE-2024-53126
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: vdpa: solidrun: Fix UB bug with devres In psnet_open_pf_bar() and snet_open_vf_bar() a string later passed …

Dec 4, 2024
CVE-2024-51465
8.8 HIGH

IBM App Connect Enterprise Certified Container 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, and 12.3 could allow a remote authenticated attacker to execute arbitrary commands on …

Dec 4, 2024
CVE-2024-54154
8.0 HIGH

In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox

Dec 4, 2024
CVE-2024-52269
8.1 HIGH

User Interface (UI) Misrepresentation of Critical Information vulnerability in DocuSign allows Content Spoofing. The SaaS AI assistant ignores hidden content that is rendered after signing, …

Dec 4, 2024
CVE-2024-52276
7.5 HIGH

User Interface (UI) Misrepresentation of Critical Information vulnerability in DocuSign allows Content Spoofing. 1. Displayed version does not show the layer flattened version, which is …

Dec 4, 2024
CVE-2024-12107
7.5 HIGH

Double-Free Vulnerability in uD3TN BPv7 Caused by Malformed Endpoint Identifier allows remote attacker to reliably cause DoS

Dec 4, 2024
CVE-2024-11952
7.5 HIGH

The Classic Addons – WPBakery Page Builder plugin for WordPress is vulnerable to Limited Local PHP File Inclusion in all versions up to, and including, …

Dec 4, 2024
CVE-2024-10567
7.5 HIGH

The TI WooCommerce Wishlist plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wizard' function in …

Dec 4, 2024
CVE-2024-11293
8.1 HIGH

The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction Social Sites Login plugin for WordPress is vulnerable …

Dec 4, 2024
CVE-2024-45717
7.0 HIGH

The SolarWinds Platform was susceptible to a XSS vulnerability that affects the search and node information section of the user interface. This vulnerability requires authentication …

Dec 4, 2024
CVE-2024-11398
8.1 HIGH

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in OTP reset functionality in Synology Router Manager (SRM) before 1.3.1-9346-9 allows remote …

Dec 4, 2024
CVE-2024-9404
7.5 HIGH

This vulnerability could lead to denial-of-service or service crashes. Exploitation of the moxa_cmd service, because of insufficient input validation, allows attackers to disrupt operations. If …

Dec 4, 2024
CVE-2024-10952
7.3 HIGH

The The Authors List plugin for WordPress is vulnerable to arbitrary shortcode execution via update_authors_list_ajax AJAX action in all versions up to, and including, 2.0.4. …

Dec 4, 2024
CVE-2024-10587
8.8 HIGH

The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free plugin for WordPress is vulnerable to PHP Object …

Dec 4, 2024
CVE-2024-45207
7.0 HIGH

DLL injection in Veeam Agent for Windows can occur if the system's PATH variable includes insecure locations. When the agent runs, it searches these directories …

Dec 4, 2024
CVE-2024-45205
7.1 HIGH

An Improper Certificate Validation on the UniFi iOS App managing a standalone UniFi Access Point (not using UniFi Network Application) could allow a malicious actor …

Dec 4, 2024
CVE-2024-42456
8.8 HIGH

A vulnerability in Veeam Backup & Replication platform allows a low-privileged user with a specific role to exploit a method that updates critical configuration settings, …

Dec 4, 2024
CVE-2024-42455
8.1 HIGH

A vulnerability in Veeam Backup & Replication allows a low-privileged user to connect to remoting services and exploit insecure deserialization by sending a serialized temporary …

Dec 4, 2024
CVE-2024-42453
8.1 HIGH

A vulnerability Veeam Backup & Replication allows low-privileged users to control and modify configurations on connected virtual infrastructure hosts. This includes the ability to power …

Dec 4, 2024
CVE-2024-42452
8.8 HIGH

A vulnerability in Veeam Backup & Replication allows a low-privileged user to start an agent remotely in server mode and obtain credentials, effectively escalating privileges …

Dec 4, 2024
CVE-2024-42449
7.1 HIGH

From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is possible to remove arbitrary files on …

Dec 4, 2024
CVE-2024-40717
8.8 HIGH

A vulnerability in Veeam Backup & Replication allows a low-privileged user with certain roles to perform remote code execution (RCE) by updating existing jobs. These …

Dec 4, 2024
CVE-2024-46624
8.8 HIGH

An issue in InfoDom Performa 365 v4.0.1 allows authenticated attackers to elevate their privileges to Administrator via a crafted payload sent to /api/users.

Dec 3, 2024
CVE-2024-46625
8.8 HIGH

An authenticated arbitrary file upload vulnerability in the /documentCache/upload endpoint of InfoDom Performa 365 v4.0.1 allows attackers to execute arbitrary code via uploading a crafted …

Dec 3, 2024
CVE-2024-45757
7.2 HIGH

An issue was discovered in Centreon centreon-bam 24.04, 23.10, 23.04, and 22.10. SQL injection can occur in the user-settings form. Exploitation is only accessible to …

Dec 3, 2024
CVE-2024-51771
7.2 HIGH

A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authenticated remote threat actor to conduct a remote code …

Dec 3, 2024
CVE-2024-51114
8.8 HIGH

An issue in Beijing Digital China Yunke Information Technology Co.Ltd v.7.2.6.120 allows a remote attacker to execute arbitrary code via the code/function/dpi/web_auth/customizable.php file

Dec 3, 2024
CVE-2024-50948
7.5 HIGH

mochiMQTT v2.6.3 is vulnerable to Denial of Service (DoS) due to improper resource management. An attacker can exhaust system memory and crash the broker by …

Dec 3, 2024
CVE-2024-48080
7.5 HIGH

An issue in aedes v0.51.2 allows attackers to cause a Denial of Service(DoS) via a crafted request. NOTE: the Supplier indicates that exploitation cannot occur …

Dec 3, 2024
CVE-2024-12053
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 131.0.6778.108 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium …

Dec 3, 2024
CVE-2024-52547
7.2 HIGH

An authenticated attacker can trigger a stack based buffer overflow in the DHIP Service (TCP port 80). This vulnerability has been resolved in firmware version …

Dec 3, 2024
CVE-2024-41777
7.5 HIGH

IBM Cognos Controller 11.0.0 and 11.0.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound …

Dec 3, 2024
CVE-2024-52805
7.5 HIGH

Synapse is an open-source Matrix homeserver. In Synapse before 1.120.1, multipart/form-data requests can in certain configurations transiently increase memory consumption beyond expected levels while processing …

Dec 3, 2024
CVE-2024-40691
8.0 HIGH

IBM Cognos Controller 11.0.0 and 11.0.1 could be vulnerable to malicious file upload by not validating the content of the file uploaded to the web …

Dec 3, 2024
CVE-2024-37302
7.5 HIGH

Synapse is an open-source Matrix homeserver. Synapse versions before 1.106 are vulnerable to a disk fill attack, where an unauthenticated adversary can induce Synapse to …

Dec 3, 2024
CVE-2024-29404
7.8 HIGH

An issue in Razer Synapse 3 v.3.9.131.20813 and Synapse 3 App v.20240213 allows a local attacker to execute arbitrary code via the export parameter of …

Dec 3, 2024
CVE-2024-54000
7.5 HIGH

Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. In versions prior to 3.9.7, …

Dec 3, 2024
CVE-2024-53999
8.1 HIGH

Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. The application allows users to …

Dec 3, 2024
CVE-2024-11391
7.5 HIGH

The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the 'class_fma_connector.php' file in all …

Dec 3, 2024
CVE-2024-42422
8.3 HIGH

Dell NetWorker, version(s) 19.10, contain(s) an Authorization Bypass Through User-Controlled Key vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to …

Dec 3, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.