CVE Database

38893+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-54003
8.0 HIGH

Jenkins Simple Queue Plugin 1.4.4 and earlier does not escape the view name, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with …

Nov 27, 2024
CVE-2024-31976
8.0 HIGH

EnGenius EWS356-FIR 1.1.30 and earlier devices allow a remote attacker to execute arbitrary OS commands via the Controller connectivity parameter.

Nov 27, 2024
CVE-2024-53920
7.8 HIGH

In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger …

Nov 27, 2024
CVE-2024-52951
8.0 HIGH

Stored Cross-Site Scripting in the Access Request History in Omada Identity before version 15 update 1 allows an authenticated attacker to execute arbitrary code in …

Nov 27, 2024
CVE-2024-53603
7.3 HIGH

A SQL Injection vulnerability was found in /covid-tms/password-recovery.php in PHPGurukul COVID 19 Testing Management System v1.0, which allows remote attackers to execute arbitrary code via …

Nov 27, 2024
CVE-2024-52323
8.1 HIGH

Zohocorp ManageEngine Analytics Plus versions below 6100 are vulnerable to authenticated sensitive data exposure which allows the users to retrieve sensitive tokens associated to the …

Nov 27, 2024
CVE-2024-11667
7.5 HIGH KEV

A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through …

Nov 27, 2024
CVE-2024-36467
7.5 HIGH

An authenticated user with API access (e.g.: user with default User role), more specifically a user with access to the user.update API endpoint is enough …

Nov 27, 2024
CVE-2024-52959
7.2 HIGH

A Improper Control of Generation of Code ('Code Injection') vulnerability in plugin management in iota C.ai Conversational Platform from 1.0.0 through 2.1.3 allows remote authenticated …

Nov 27, 2024
CVE-2024-52958
7.2 HIGH

A improper verification of cryptographic signature vulnerability in plugin management in iota C.ai Conversational Platform from 1.0.0 through 2.1.3 allows remote authenticated users to load …

Nov 27, 2024
CVE-2024-5921
8.8 HIGH

An insufficient certification validation issue in the Palo Alto Networks GlobalProtect app enables attackers to connect the GlobalProtect app to arbitrary servers. This can enable …

Nov 27, 2024
CVE-2024-11819
7.3 HIGH

A vulnerability classified as critical was found in 1000 Projects Portfolio Management System MCA 1.0. This vulnerability affects unknown code of the file /forgot_password_process.php. The …

Nov 27, 2024
CVE-2024-11818
7.3 HIGH

A vulnerability classified as critical has been found in PHPGurukul User Registration & Login and User Management System 1.0. This affects an unknown part of …

Nov 27, 2024
CVE-2024-11817
7.3 HIGH

A vulnerability was found in PHPGurukul User Registration & Login and User Management System 1.0. It has been rated as critical. Affected by this issue …

Nov 26, 2024
CVE-2024-53675
7.3 HIGH

An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.

Nov 26, 2024
CVE-2024-53674
7.3 HIGH

An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.

Nov 26, 2024
CVE-2024-53673
8.1 HIGH

A java deserialization vulnerability in HPE Remote Insight Support may allow an unauthenticated attacker to execute code.

Nov 26, 2024
CVE-2024-11622
7.3 HIGH

An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.

Nov 26, 2024
CVE-2024-11745
8.8 HIGH

A vulnerability was found in Tenda AC8 16.03.34.09 and classified as critical. Affected by this issue is the function route_static_check of the file /goform/SetStaticRouteCfg. The …

Nov 26, 2024
CVE-2024-11744
7.3 HIGH

A vulnerability has been found in 1000 Projects Portfolio Management System MCA 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality …

Nov 26, 2024
CVE-2024-8676
7.4 HIGH

A vulnerability was found in CRI-O, where it can be requested to take a checkpoint archive of a container and later be asked to restore …

Nov 26, 2024
CVE-2024-49053
7.6 HIGH

Microsoft Dynamics 365 Sales Spoofing Vulnerability

Nov 26, 2024
CVE-2024-49052
8.2 HIGH

Missing authentication for critical function in Microsoft Azure PolicyWatch allows an unauthorized attacker to elevate privileges over a network.

Nov 26, 2024
CVE-2024-49035
8.7 HIGH KEV

An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network.

Nov 26, 2024
CVE-2024-8114
8.2 HIGH

An issue has been discovered in GitLab CE/EE affecting all versions from 8.12 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. This issue allows …

Nov 26, 2024
CVE-2024-52008
8.8 HIGH

Fides is an open-source privacy engineering platform. The user invite acceptance API endpoint lacks server-side password policy enforcement, allowing users to set arbitrarily weak passwords …

Nov 26, 2024
CVE-2024-32965
8.1 HIGH

Lobe Chat is an open-source, AI chat framework. Versions of lobe-chat prior to 1.19.13 have an unauthorized ssrf vulnerability. An attacker can construct malicious requests …

Nov 26, 2024
CVE-2024-53555
8.8 HIGH

A CSV injection vulnerability in Taiga v6.8.1 allows attackers to execute arbitrary code via uploading a crafted CSV file.

Nov 26, 2024
CVE-2024-11407
7.5 HIGH

There exists a denial of service through Data corruption in gRPC-C++ - gRPC-C++ servers with transmit zero copy enabled through the channel arg GRPC_ARG_TCP_TX_ZEROCOPY_ENABLED can …

Nov 26, 2024
CVE-2024-52336
7.8 HIGH

A script injection vulnerability was identified in the Tuned package. The `instance_create()` D-Bus function can be called by locally logged-in users without authentication. This flaw …

Nov 26, 2024
CVE-2024-9461
7.2 HIGH

The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Remote Code Execution in all versions …

Nov 26, 2024
CVE-2024-11702
7.5 HIGH

Copying sensitive information from Private Browsing tabs on Android, such as passwords, may have inadvertently stored data in the cloud-based clipboard history if enabled. This …

Nov 26, 2024
CVE-2024-11700
8.1 HIGH

Malicious websites may have been able to perform user intent confirmation through tapjacking. This could have led to users unknowingly approving the launch of external …

Nov 26, 2024
CVE-2024-11699
8.8 HIGH

Memory safety bugs present in Firefox 132, Firefox ESR 128.4, and Thunderbird 128.4. Some of these bugs showed evidence of memory corruption and we presume …

Nov 26, 2024
CVE-2024-11697
8.8 HIGH

When handling keypress events, an attacker may have been able to trick a user into bypassing the "Open Executable File?" confirmation dialog. This could have …

Nov 26, 2024
CVE-2024-11691
8.8 HIGH

Certain WebGL operations on Apple silicon M series devices could have lead to an out-of-bounds write and memory corruption due to a flaw in Apple's …

Nov 26, 2024
CVE-2018-5852
8.4 HIGH

An unsigned integer underflow vulnerability in IPA driver result into a buffer over-read while reading NAT entry using debugfs command 'cat /sys/kernel/debug/ipa/ip4_nat'

Nov 26, 2024
CVE-2018-11816
7.8 HIGH

Crafted Binder Request Causes Heap UAF in MediaServer

Nov 26, 2024
CVE-2017-18307
8.4 HIGH

Information disclosure possible while audio playback.

Nov 26, 2024
CVE-2017-18306
8.4 HIGH

Information disclosure due to uninitialized variable.

Nov 26, 2024
CVE-2016-10408
8.4 HIGH

QSEE will randomly experience a fatal error during execution due to speculative instruction fetches from device memory. Device memory is not valid executable memory.

Nov 26, 2024
CVE-2024-51569
7.5 HIGH

Out-of-bounds Read vulnerability in Apache NimBLE. Missing proper validation of HCI Number Of Completed Packets could lead to out-of-bound access when parsing HCI event and …

Nov 26, 2024
CVE-2024-38832
7.1 HIGH

VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to views may be able to inject malicious script leading …

Nov 26, 2024
CVE-2024-38831
7.8 HIGH

VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privileges can insert malicious commands into the properties file to …

Nov 26, 2024
CVE-2024-38830
7.8 HIGH

VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privileges may trigger this vulnerability to escalate privileges to root …

Nov 26, 2024
CVE-2023-1521
7.8 HIGH

On Linux the sccache client can execute arbitrary code with the privileges of a local sccache server, by preloading the code in a shared library …

Nov 26, 2024
CVE-2023-0163
8.4 HIGH

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in Mozilla Convict. This allows an attacker to inject attributes that are used in other …

Nov 26, 2024
CVE-2024-50376
7.3 HIGH

A CWE-79 "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD …

Nov 26, 2024
CVE-2024-50369
7.2 HIGH

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G …

Nov 26, 2024
CVE-2024-50368
7.2 HIGH

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G …

Nov 26, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.