CVE Database

38893+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-48986
7.5 HIGH

An issue was discovered in MBed OS 6.16.0. Its hci parsing software dynamically determines the length of certain hci packets by reading a byte from …

Nov 20, 2024
CVE-2024-48982
7.5 HIGH

An issue was discovered in MBed OS 6.16.0. Its hci parsing software dynamically determines the length of certain hci packets by reading a byte from …

Nov 20, 2024
CVE-2024-48536
7.5 HIGH

Incorrect access control in eSoft Planner 3.24.08271-USA allow attackers to view all transactions performed by the company via supplying a crafted web request.

Nov 20, 2024
CVE-2024-48530
7.5 HIGH

An issue in the Instructor Appointment Availability module of eSoft Planner 3.24.08271-USA allows attackers to cause a Denial of Service (DoS) via a crafted POST …

Nov 20, 2024
CVE-2024-48985
7.5 HIGH

An issue was discovered in MBed OS 6.16.0. During processing of HCI packets, the software dynamically determines the length of the packet data by reading …

Nov 20, 2024
CVE-2024-48983
7.5 HIGH

An issue was discovered in MBed OS 6.16.0. During processing of HCI packets, the software dynamically determines the length of the packet data by reading …

Nov 20, 2024
CVE-2024-48981
7.5 HIGH

An issue was discovered in MBed OS 6.16.0. During processing of HCI packets, the software dynamically determines the length of the packet header by looking …

Nov 20, 2024
CVE-2024-52739
8.0 HIGH

D-LINK DI-8400 v16.07.26A1 was discovered to contain multiple remote command execution (RCE) vulnerabilities in the msp_info_htm function via the flag and cmd parameters.

Nov 20, 2024
CVE-2018-9484
7.5 HIGH

In l2cu_send_peer_config_rej of l2c_utils.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure …

Nov 20, 2024
CVE-2018-9477
7.8 HIGH

In the development options section of the Settings app, there is a possible authentication bypass due to a missing permission check. This could lead to …

Nov 20, 2024
CVE-2018-9475
8.8 HIGH

In HeadsetInterface::ClccResponse of btif_hf.cc, there is a possible out of bounds stack write due to a missing bounds check. This could lead to remote escalation …

Nov 20, 2024
CVE-2018-9474
7.8 HIGH

In writeToParcel of MediaPlayer.java, there is a possible serialization/deserialization mismatch due to improper input validation. This could lead to local escalation of privilege with no …

Nov 20, 2024
CVE-2018-9472
8.8 HIGH

In xmlMemStrdupLoc of xmlmemory.c, there is a possible out-of-bounds write due to an integer overflow. This could lead to remote code execution in an unprivileged …

Nov 20, 2024
CVE-2018-9471
7.8 HIGH

In the deserialization constructor of NanoAppFilter.java, there is a possible loss of data due to type confusion. This could lead to local escalation of privilege …

Nov 20, 2024
CVE-2018-9470
8.8 HIGH

In bff_Scanner_addOutPos of Scanner.c, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege in …

Nov 20, 2024
CVE-2024-52769
7.2 HIGH

An arbitrary file upload vulnerability in the component /admin/friendlink_edit of DedeBIZ v6.3.0 allows attackers to execute arbitrary code via uploading a crafted file.

Nov 20, 2024
CVE-2024-51163
7.5 HIGH

A Local File Inclusion vulnerability in Vegam Solutions Vegam 4i versions 6.3.47.0 and earlier allows a remote attacker to obtain sensitive information through the print …

Nov 20, 2024
CVE-2024-51162
8.8 HIGH

An issue in Audimex EE versions 15.1.20 and earlier allowing a remote attacker to escalate privileges. Analyzing the offline client code, it was identified that …

Nov 20, 2024
CVE-2018-9469
7.8 HIGH

In multiple functions of ShortcutService.java, there is a possible creation of a spoofed shortcut due to a missing permission check. This could lead to local …

Nov 20, 2024
CVE-2018-9468
7.1 HIGH

In query of DownloadManager.java, there is a possible read/write of arbitrary files due to a permissions bypass. This could lead to local information disclosure and …

Nov 20, 2024
CVE-2024-52598
7.5 HIGH

2FAuth is a web app to manage Two-Factor Authentication (2FA) accounts and generate their security codes. Two interconnected vulnerabilities exist in version 5.4.1 a SSRF …

Nov 20, 2024
CVE-2024-52473
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sandeep Verma HTML5 Lyrics Karaoke Player html5-lyrics-karaoke-player allows Reflected XSS.This issue affects HTML5 …

Nov 20, 2024
CVE-2024-52472
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Weather Atlas Weather Atlas Widget weather-atlas allows Reflected XSS.This issue affects Weather Atlas …

Nov 20, 2024
CVE-2024-52471
7.1 HIGH

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in petesheppard84 Extensions for Elementor allows Reflected XSS.This issue affects Extensions for …

Nov 20, 2024
CVE-2024-52470
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brainvireinfo Dynamic URL SEO dynamic-url-seo allows Reflected XSS.This issue affects Dynamic URL SEO: …

Nov 20, 2024
CVE-2024-51208
7.2 HIGH

File Upload vulnerability in change-image.php in Anuj Kumar's Boat Booking System version 1.0 allows local attackers to upload a malicious PHP script via the Image …

Nov 20, 2024
CVE-2024-10913
8.8 HIGH

The Clone plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.4.6 via deserialization of untrusted input in …

Nov 20, 2024
CVE-2024-11495
7.5 HIGH

Buffer overflow vulnerability in OllyDbg, version 1.10, which could allow a local attacker to execute arbitrary code due to lack of proper bounds checking.

Nov 20, 2024
CVE-2024-52451
8.2 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in aaronrobbins Post Ideas post-ideas allows SQL Injection.This issue affects Post Ideas: from n/a through <= 2.

Nov 20, 2024
CVE-2024-52450
7.5 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in officialprocoders nBlocks nblocks allows PHP Local File Inclusion.This issue …

Nov 20, 2024
CVE-2024-52449
7.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Navneil Naicer Bootscraper allows PHP Local File Inclusion.This issue affects Bootscraper: from …

Nov 20, 2024
CVE-2024-52448
7.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in webcodingplace Ultimate Classified Listings ultimate-classified-listings allows PHP Local File Inclusion.This issue affects …

Nov 20, 2024
CVE-2024-52447
8.6 HIGH

Path Traversal: '.../...//' vulnerability in corporatezen222 Contact Page With Google Map contact-page-with-google-map allows Path Traversal.This issue affects Contact Page With Google Map: from n/a through …

Nov 20, 2024
CVE-2024-52446
8.8 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Buying Buddy Buying Buddy IDX CRM buying-buddy-idx-crm allows Object Injection.This issue affects Buying Buddy IDX CRM: from n/a through …

Nov 20, 2024
CVE-2024-52445
8.8 HIGH

Deserialization of Untrusted Data vulnerability in ModelTheme QRMenu Restaurant QR Menu Lite qrmenu-lite allows Object Injection.This issue affects QRMenu Restaurant QR Menu Lite: from n/a …

Nov 20, 2024
CVE-2024-52444
7.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in wpopal Opal Woo Custom Product Variation opal-woo-custom-product-variation allows Path Traversal.This issue affects …

Nov 20, 2024
CVE-2024-52438
8.8 HIGH

Missing Authentication for Critical Function vulnerability in deco.agency de:branding debranding allows Privilege Escalation.This issue affects de:branding: from n/a through <= 1.0.2.

Nov 20, 2024
CVE-2024-52437
8.8 HIGH

Missing Authentication for Critical Function vulnerability in Saul Morales Pacheco Banner System banner-system allows Privilege Escalation.This issue affects Banner System: from n/a through <= 1.0.0.

Nov 20, 2024
CVE-2024-45690
7.5 HIGH

A flaw was found in Moodle. Additional checks were required to ensure users can only delete their OAuth2-linked accounts.

Nov 20, 2024
CVE-2024-10382
7.5 HIGH

There exists a code execution vulnerability in the Car App Android Jetpack Library. CarAppService uses deserialization logic that allows construction of arbitrary java classes. This …

Nov 20, 2024
CVE-2024-11494
7.5 HIGH

**UNSUPPORTED WHEN ASSIGNED** The improper authentication vulnerability in the Zyxel P-6101C ADSL modem firmware version P-6101CSA6AP_20140331 could allow an unauthenticated attacker to read some device …

Nov 20, 2024
CVE-2024-48895
8.8 HIGH

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Rakuten Turbo 5G firmware version V1.3.18 and earlier. If …

Nov 20, 2024
CVE-2024-10899
7.3 HIGH

The The WooCommerce Product Table Lite plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.8.6. This is …

Nov 20, 2024
CVE-2024-10855
8.1 HIGH

The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of …

Nov 20, 2024
CVE-2024-44308
8.8 HIGH KEV

The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS …

Nov 20, 2024
CVE-2024-44307
7.8 HIGH

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.6. An app may be able to execute …

Nov 20, 2024
CVE-2024-44306
7.8 HIGH

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.6. An app may be able to execute …

Nov 20, 2024
CVE-2018-9466
8.8 HIGH

In the xmlSnprintfElementContent function of valid.c, there is a possible out of bounds write. This could lead to remote escalation of privilege in an unprivileged …

Nov 19, 2024
CVE-2018-9456
7.5 HIGH

In sdpu_extract_attr_seq of sdp_utils.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote denial of …

Nov 19, 2024
CVE-2024-52595
7.7 HIGH

lxml_html_clean is a project for HTML cleaning functionalities copied from `lxml.html.clean`. Prior to version 0.4.0, the HTML Parser in lxml does not properly handle context-switching …

Nov 19, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.