CVE Database

38893+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-50367
7.2 HIGH

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G …

Nov 26, 2024
CVE-2024-50366
7.2 HIGH

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G …

Nov 26, 2024
CVE-2024-50365
7.2 HIGH

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G …

Nov 26, 2024
CVE-2024-50364
7.2 HIGH

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G …

Nov 26, 2024
CVE-2024-50363
7.2 HIGH

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G …

Nov 26, 2024
CVE-2024-50362
7.2 HIGH

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G …

Nov 26, 2024
CVE-2024-50361
7.2 HIGH

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G …

Nov 26, 2024
CVE-2024-50360
7.2 HIGH

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G …

Nov 26, 2024
CVE-2024-50359
7.2 HIGH

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G …

Nov 26, 2024
CVE-2024-50358
7.2 HIGH

A CWE-15 "External Control of System or Configuration Setting" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and …

Nov 26, 2024
CVE-2018-11952
8.4 HIGH

An image with a version lower than the fuse version may potentially be booted lead to improper authentication.

Nov 26, 2024
CVE-2017-18153
8.4 HIGH

A race condition exists in a driver potentially leading to a use-after-free condition.

Nov 26, 2024
CVE-2017-15832
8.4 HIGH

Buffer overwrite in the WLAN host driver by leveraging a compromised WLAN FW

Nov 26, 2024
CVE-2016-10394
8.4 HIGH

Initial xbl_sec revision does not have all the debug policy features and critical checks.

Nov 26, 2024
CVE-2024-9504
7.2 HIGH

The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and …

Nov 26, 2024
CVE-2024-47257
7.5 HIGH

Florent Thiéry has found that selected Axis devices were vulnerable to handling certain ethernet frames which could lead to the Axis device becoming unavailable in …

Nov 26, 2024
CVE-2024-36254
7.5 HIGH

Out-of-bounds read vulnerability exists in Sharp Corporation and Toshiba Tec Corporation multiple MFPs (multifunction printers), which may lead to a denial-of-service (DoS) condition.

Nov 26, 2024
CVE-2024-36251
7.5 HIGH

The web interface of the affected devices process some crafted HTTP requests improperly, leading to a device crash. More precisely, a crafted parameter to billcodedef_sub_sel.html …

Nov 26, 2024
CVE-2024-36249
7.4 HIGH

Cross-site scripting vulnerability exists in Sharp Corporation and Toshiba Tech Corporation multiple MFPs (multifunction printers). If this vulnerability is exploited, an arbitrary script may be …

Nov 26, 2024
CVE-2024-33605
7.5 HIGH

Improper processing of some parameters of installed_emanual_list.html leads to a path traversal vulnerability. As for the details of affected product names, model numbers, and versions, …

Nov 26, 2024
CVE-2024-10781
8.1 HIGH

The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an missing empty value check on …

Nov 26, 2024
CVE-2024-10570
7.5 HIGH

The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to unauthorized SQL Injection due to an authorization bypass via reverse DNS spoofing …

Nov 26, 2024
CVE-2024-49353
7.5 HIGH

IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data 4.0.0 through 5.0.2 does not properly check inputs to resources that are used concurrently, …

Nov 26, 2024
CVE-2024-49597
7.6 HIGH

Dell Wyse Management Suite, versions WMS 4.4 and prior, contain an Improper Restriction of Excessive Authentication Attempts vulnerability. A high privileged attacker with remote access …

Nov 26, 2024
CVE-2024-49595
7.6 HIGH

Dell Wyse Management Suite, version WMS 4.4 and before, contain an Authentication Bypass by Capture-replay vulnerability. A high privileged attacker with remote access could potentially …

Nov 26, 2024
CVE-2024-10729
8.8 HIGH

The Booking & Appointment Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …

Nov 26, 2024
CVE-2024-52899
8.5 HIGH

IBM Data Virtualization Manager for z/OS 1.1 and 1.2 could allow an authenticated user to inject malicious JDBC URL parameters and execute code on the …

Nov 26, 2024
CVE-2024-53843
8.1 HIGH

@dapperduckling/keycloak-connector-server is an opinionated series of libraries for Node.js applications and frontend clients to interface with keycloak. A Reflected Cross-Site Scripting (XSS) vulnerability was discovered …

Nov 26, 2024
CVE-2024-53554
8.0 HIGH

A Client-Side Template Injection (CSTI) vulnerability in the component /project/new/scrum of Taiga v 8.6.1 allows remote attackers to execute arbitrary code by injecting a malicious …

Nov 25, 2024
CVE-2024-53099
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: bpf: Check validity of link->type in bpf_link_show_fdinfo() If a newly-added link type doesn't invoke BPF_LINK_TYPE(), …

Nov 25, 2024
CVE-2024-53098
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/xe/ufence: Prefetch ufence addr to catch bogus address access_ok() only checks for addr overflow so …

Nov 25, 2024
CVE-2024-53096
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: mm: resolve faulty mmap_region() error path behaviour The mmap_region() function is somewhat terrifying, with spaghetti-like …

Nov 25, 2024
CVE-2024-53268
7.2 HIGH

Joplin is an open source, privacy-focused note taking app with sync capabilities for Windows, macOS, Linux, Android and iOS. In affected versions attackers are able …

Nov 25, 2024
CVE-2024-52811
8.2 HIGH

The ngtcp2 project is an effort to implement IETF QUIC protocol in C. In affected versions acks are not validated before being written to the …

Nov 25, 2024
CVE-2024-8272
7.8 HIGH

The com.uaudio.bsd.helper service, responsible for handling privileged operations, fails to implement critical client validation during XPC inter-process communication (IPC). Specifically, the service does not verify …

Nov 25, 2024
CVE-2024-7915
7.8 HIGH

The application Sensei Mac Cleaner contains a local privilege escalation vulnerability, allowing an attacker to perform multiple operations as the root user. These operations include …

Nov 25, 2024
CVE-2024-45756
7.2 HIGH

An issue was discovered in Centreon centreon-open-tickets 24.10.x before 24.10.0, 24.04.x before 24.04.2, 23.10.x before 23.10.1, 23.04.x before 23.04.3, and 22.10.x before 22.10.2. SQL injection …

Nov 25, 2024
CVE-2024-45755
7.2 HIGH

An issue was discovered in Centreon centreon-dsm-server 24.10.x before 24.10.0, 24.04.x before 24.04.3, 23.10.x before 23.10.1, 23.04.x before 23.04.3, and 22.10.x before 22.10.2. SQL injection …

Nov 25, 2024
CVE-2024-27134
7.0 HIGH

Excessive directory permissions in MLflow leads to local privilege escalation when using spark_udf. This behavior can be exploited by a local attacker to gain elevated …

Nov 25, 2024
CVE-2024-11498
7.5 HIGH

There exists a stack buffer overflow in libjxl. A specifically-crafted file can cause the JPEG XL decoder to use large amounts of stack space (up …

Nov 25, 2024
CVE-2024-11664
8.8 HIGH

A vulnerability, which was classified as critical, has been found in eNMS up to 4.2. Affected by this issue is the function multiselect_filtering of the …

Nov 25, 2024
CVE-2024-11663
7.3 HIGH

A vulnerability classified as critical was found in Codezips E-Commerce Site 1.0. Affected by this vulnerability is an unknown functionality of the file search.php. The …

Nov 25, 2024
CVE-2024-11649
7.3 HIGH

A vulnerability has been found in 1000 Projects Beauty Parlour Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file …

Nov 25, 2024
CVE-2024-11648
7.3 HIGH

A vulnerability, which was classified as critical, was found in 1000 Projects Beauty Parlour Management System 1.0. This affects an unknown part of the file …

Nov 25, 2024
CVE-2024-11647
7.3 HIGH

A vulnerability, which was classified as critical, has been found in 1000 Projects Beauty Parlour Management System 1.0. Affected by this issue is some unknown …

Nov 25, 2024
CVE-2024-53916
7.5 HIGH

In OpenStack Neutron before 25.0.1, neutron/extensions/tagging.py can use an incorrect ID during policy enforcement. It does not apply the proper policy check for changing network …

Nov 25, 2024
CVE-2024-11646
7.3 HIGH

A vulnerability classified as critical was found in 1000 Projects Beauty Parlour Management System 1.0. Affected by this vulnerability is an unknown functionality of the …

Nov 25, 2024
CVE-2024-11665
8.8 HIGH

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in hardy-barth cph2_echarge_firmware allows OS Command Injection.This issue affects cph2_echarge_firmware: through 2.0.4.

Nov 24, 2024
CVE-2024-53899
7.8 HIGH

virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this …

Nov 24, 2024
CVE-2024-11632
7.3 HIGH

A vulnerability was found in code-projects Simple Car Rental System 1.0. It has been classified as critical. Affected is an unknown function of the file …

Nov 23, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.