CVE Database

38893+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-43048
7.8 HIGH

Memory corruption when invalid input is passed to invoke GPU Headroom API call.

Dec 2, 2024
CVE-2024-33063
7.5 HIGH

Transient DOS while parsing the ML IE when a beacon with common info length of the ML IE greater than the ML IE inside which …

Dec 2, 2024
CVE-2024-33056
8.4 HIGH

Memory corruption when allocating and accessing an entry in an SMEM partition continuously.

Dec 2, 2024
CVE-2024-33044
8.4 HIGH

Memory corruption while Configuring the SMR/S2CR register in Bypass mode.

Dec 2, 2024
CVE-2024-53104
7.8 HIGH KEV

In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format This can lead to out …

Dec 2, 2024
CVE-2024-53103
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: hv_sock: Initializing vsk->trans to NULL to prevent a dangling pointer When hvs is released, there …

Dec 2, 2024
CVE-2024-20138
7.5 HIGH

In wlan driver, there is a possible out of bound read due to improper input validation. This could lead to remote information disclosure with no …

Dec 2, 2024
CVE-2024-20137
7.5 HIGH

In wlan driver, there is a possible client disconnection due to improper handling of exceptional conditions. This could lead to remote denial of service with …

Dec 2, 2024
CVE-2024-20129
7.5 HIGH

In Telephony, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with …

Dec 2, 2024
CVE-2024-20128
7.5 HIGH

In Telephony, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with …

Dec 2, 2024
CVE-2024-20127
7.5 HIGH

In Telephony, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with …

Dec 2, 2024
CVE-2024-53605
7.5 HIGH

Incorrect access control in the component content://com.handcent.messaging.provider.MessageProvider/ of Handcent NextSMS v10.9.9.7 allows attackers to access sensitive data.

Dec 2, 2024
CVE-2024-53750
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Maeve Lander PayPal Responder allows Stored XSS.This issue affects PayPal Responder: from n/a through 1.2.

Dec 1, 2024
CVE-2024-53742
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Prism I.T. Systems Multilevel Referral Affiliate Plugin for WooCommerce multilevel-referral-plugin-for-woocommerce allows Reflected XSS.This …

Dec 1, 2024
CVE-2024-45520
7.5 HIGH

WithSecure Atlant (formerly F-Secure Atlant) 1.0.35-1 allows a remote Denial of Service because of memory corruption during scanning of a PE32 file.

Dec 1, 2024
CVE-2024-53778
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Essential Marketer Essential Breadcrumbs essential-breadcrumbs allows Stored XSS.This issue affects Essential Breadcrumbs: from n/a through <= 1.1.1.

Nov 30, 2024
CVE-2024-53783
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Anzar Ahmed Ni WooCommerce Cost Of Goods ni-woocommerce-cost-of-goods.This issue affects Ni …

Nov 30, 2024
CVE-2024-53739
8.1 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Cool Plugins Cryptocurrency Widgets For Elementor cryptocurrency-widgets-for-elementor allows PHP …

Nov 30, 2024
CVE-2024-43703
8.1 HIGH

Software installed and run as a non-privileged user may conduct improper GPU system calls to achieve unauthorised reads and writes of physical memory from the …

Nov 30, 2024
CVE-2024-43702
8.1 HIGH

Software installed and run as a non-privileged user may conduct improper GPU system calls to allow unprivileged access to arbitrary physical memory page.

Nov 30, 2024
CVE-2024-53623
7.5 HIGH

Incorrect access control in the component l_0_0.xml of TP-Link ARCHER-C7 v5 allows attackers to access sensitive information.

Nov 29, 2024
CVE-2024-36612
7.5 HIGH

Zulip from 8.0 to 8.3 contains a memory leak vulnerability in the handling of popovers.

Nov 29, 2024
CVE-2024-35371
7.5 HIGH

Ant-Media-Serverv2.8.2 is affected by Improper Output Neutralization for Logs. The vulnerability stems from insufficient input sanitization in the logging mechanism. Without proper filtering or validation, …

Nov 29, 2024
CVE-2024-53980
7.5 HIGH

RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) devices and other embedded devices. A malicious actor …

Nov 29, 2024
CVE-2024-53979
8.2 HIGH

ibm.ibm_zhmc is an Ansible collection for the IBM Z HMC. The Ansible collection "ibm.ibm_zhmc" writes password-like properties in clear text into its log file and …

Nov 29, 2024
CVE-2024-53865
8.2 HIGH

zhmcclient is a pure Python client library for the IBM Z HMC Web Services API. In affected versions the Python package "zhmcclient" writes password-like properties …

Nov 29, 2024
CVE-2024-53848
7.1 HIGH

check-jsonschema is a CLI and set of pre-commit hooks for jsonschema validation. The default cache strategy uses the basename of a remote schema as the …

Nov 29, 2024
CVE-2024-36611
7.5 HIGH

In Symfony v7.07, a security vulnerability was identified in the FormLoginAuthenticator component, where it failed to adequately handle cases where the username or password field …

Nov 29, 2024
CVE-2024-36623
8.1 HIGH

moby through v25.0.3 has a Race Condition vulnerability in the streamformatter package which can be used to trigger multiple concurrent write operations resulting in data …

Nov 29, 2024
CVE-2024-49804
7.8 HIGH

IBM Security Verify Access Appliance 10.0.0 through 10.0.8 could allow a locally authenticated non-administrative user to escalate their privileges due to unnecessary permissions used to …

Nov 29, 2024
CVE-2024-11983
7.2 HIGH

Certain models of routers from Billion Electric has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject arbitrary system commands into …

Nov 29, 2024
CVE-2024-11982
7.2 HIGH

Certain models of routers from Billion Electric has a Plaintext Storage of a Password vulnerability. Remote attackers with administrator privileges can access the user settings …

Nov 29, 2024
CVE-2024-11481
8.2 HIGH

A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API. This leads to improper handling of path traversal, insecure forwarding to an …

Nov 29, 2024
CVE-2024-11013
7.2 HIGH

Command Injection vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 up to Ver10.8.27, for Ver10.9 up to Ver10.9.14 and UNIVERGE IX-R/IX-V …

Nov 29, 2024
CVE-2024-11981
7.5 HIGH

Certain models of routers from Billion Electric has an Authentication Bypass vulnerability, allowing unautheticated attackers to retrive contents of arbitrary web pages.

Nov 29, 2024
CVE-2024-11980
8.6 HIGH

Certain modes of routers from Billion Electric have a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access the specific functionality to obtain partial …

Nov 29, 2024
CVE-2024-48651
7.5 HIGH

In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of the lack of supplemental groups from mod_sql.

Nov 29, 2024
CVE-2024-54124
8.8 HIGH

In Click Studios Passwordstate before build 9920, there is a potential permission escalation on the edit folder screen.

Nov 29, 2024
CVE-2024-11978
7.5 HIGH

DreamMaker from Interinfo has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.

Nov 29, 2024
CVE-2024-9852
7.8 HIGH

Uncontrolled Search Path Element vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.3 and prior, Mitsubishi Electric Hyper Historian …

Nov 28, 2024
CVE-2024-8300
7.0 HIGH

Dead Code vulnerability in Mitsubishi Electric GENESIS64 Version 10.97.2, 10.97.2 CFR1, 10.97.2 CRF2 and 10.97.3, Mitsubishi Electric Iconics Digital Solutions GENESIS64 Version 10.97.2, 10.97.2 CFR1, …

Nov 28, 2024
CVE-2024-8299
7.8 HIGH

Uncontrolled Search Path Element vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.3 and prior, Mitsubishi Electric Hyper Historian …

Nov 28, 2024
CVE-2024-11970
7.3 HIGH

A vulnerability classified as critical has been found in code-projects Concert Ticket Ordering System 1.0. Affected is an unknown function of the file /tour(cor).php. The …

Nov 28, 2024
CVE-2024-11967
7.3 HIGH

A vulnerability was found in PHPGurukul Complaint Management system 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/reset-password.php. …

Nov 28, 2024
CVE-2024-11966
7.3 HIGH

A vulnerability was found in PHPGurukul Complaint Management system 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/index.php. The …

Nov 28, 2024
CVE-2024-11965
7.3 HIGH

A vulnerability has been found in PHPGurukul Complaint Management system 1.0 and classified as critical. This vulnerability affects unknown code of the file /user/reset-password.php. The …

Nov 28, 2024
CVE-2024-11964
7.3 HIGH

A vulnerability, which was classified as critical, was found in PHPGurukul Complaint Management system 1.0. This affects an unknown part of the file /user/index.php. The …

Nov 28, 2024
CVE-2024-11969
8.8 HIGH

The NetCloud Exchange client for Windows, version 1.110.50, contains an insecure file and folder permissions vulnerability. A normal (non-admin) user could exploit the weakness in …

Nov 28, 2024
CVE-2024-11962
7.3 HIGH

A vulnerability classified as critical was found in code-projects Simple Car Rental System 1.0. Affected by this vulnerability is an unknown functionality of the file …

Nov 28, 2024
CVE-2024-11960
8.8 HIGH

A vulnerability was found in D-Link DIR-605L 2.13B01. It has been declared as critical. This vulnerability affects the function formSetPortTr of the file /goform/formSetPortTr. The …

Nov 28, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.