CVE Database

38893+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-52940
7.5 HIGH

AnyDesk through 8.1.0 on Windows, when Allow Direct Connections is enabled, inadvertently exposes a public IP address within network traffic. The attacker must know the …

Nov 18, 2024
CVE-2024-43704
8.4 HIGH

Software installed and run as a non-privileged user may conduct improper GPU system calls to gain access to the graphics buffers of a parent process.

Nov 18, 2024
CVE-2024-52920
7.5 HIGH

Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (infinite loop) via a malformed GETDATA message.

Nov 18, 2024
CVE-2024-52916
7.5 HIGH

Bitcoin Core before 0.15.0 allows a denial of service (OOM kill of a daemon process) via a flood of minimum difficulty headers.

Nov 18, 2024
CVE-2024-52915
7.5 HIGH

Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (memory consumption) via a crafted INV message.

Nov 18, 2024
CVE-2024-52914
7.5 HIGH

In Bitcoin Core before 0.18.0, a node could be stalled for hours when processing the orphans of a crafted unconfirmed transaction.

Nov 18, 2024
CVE-2024-52912
7.5 HIGH

Bitcoin Core before 0.21.0 allows a network split that is resultant from an integer overflow (calculating the time offset for newly connecting peers) and an …

Nov 18, 2024
CVE-2019-25220
7.5 HIGH

Bitcoin Core before 24.0.1 allows remote attackers to cause a denial of service (daemon crash) via a flood of low-difficulty header chains (aka a "Chain …

Nov 18, 2024
CVE-2024-0793
7.7 HIGH

A flaw was found in kube-controller-manager. This issue occurs when the initial application of a HPA config YAML lacking a .spec.behavior.scaleUp block causes a denial …

Nov 17, 2024
CVE-2023-4639
7.4 HIGH

A flaw was found in Undertow, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct …

Nov 17, 2024
CVE-2020-25720
7.5 HIGH

A vulnerability was found in Samba where a delegated administrator with permission to create objects in Active Directory can write to all attributes of the …

Nov 17, 2024
CVE-2024-52876
7.5 HIGH

Holy Stone Remote ID Module HSRID01, firmware distributed with the Drone Go2 mobile application before 1.1.8, allows unauthenticated "remote power off" actions (in broadcast mode) …

Nov 17, 2024
CVE-2024-52872
7.5 HIGH

In Flagsmith before 2.134.1, the get_document endpoint is not correctly protected by permissions.

Nov 17, 2024
CVE-2024-52871
7.5 HIGH

In Flagsmith before 2.134.1, it is possible to bypass the ALLOW_REGISTRATION_WITHOUT_INVITE setting.

Nov 17, 2024
CVE-2024-52867
8.1 HIGH

guix-daemon in GNU Guix before 5ab3c4c allows privilege escalation because build outputs are accessible by local users before file metadata concerns (e.g., for setuid and …

Nov 17, 2024
CVE-2024-52415
8.8 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in skipstorm SK WP Settings Backup sk-wp-settings-backup allows Object Injection.This issue affects SK WP Settings Backup: from n/a through <= …

Nov 16, 2024
CVE-2024-9887
7.2 HIGH

The Login using WordPress Users ( WP as SAML IDP ) plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in …

Nov 16, 2024
CVE-2024-10645
7.5 HIGH

The Blogger 301 Redirect plugin for WordPress is vulnerable to blind time-based SQL Injection via the ‘br’ parameter in all versions up to, and including, …

Nov 16, 2024
CVE-2024-10728
8.8 HIGH

The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing capability …

Nov 16, 2024
CVE-2024-9935
7.5 HIGH

The PDF Generator Addon for Elementor Page Builder plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.0.0 via …

Nov 16, 2024
CVE-2024-9849
8.8 HIGH

The Real3D Flipbook Lite – 3D FlipBook, PDF Viewer, PDF Embedder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type …

Nov 16, 2024
CVE-2024-9839
7.3 HIGH

The The Uix Slideshow plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.6.5. This is due to …

Nov 16, 2024
CVE-2024-9192
8.8 HIGH

The WordPress Video Robot - The Ultimate Video Importer plugin for WordPress is vulnerable to privilege escalation due to insufficient validation on user meta that …

Nov 16, 2024
CVE-2024-9500
7.8 HIGH

A maliciously crafted DLL file when placed in temporary files and folders that are leveraged by the Autodesk Installer could lead to escalation of privileges …

Nov 15, 2024
CVE-2017-13314
7.8 HIGH

In setAllowOnlyVpnForUids of NetworkManagementService.java, there is a possible security settings bypass due to a missing permission check. This could lead to local escalation of privilege …

Nov 15, 2024
CVE-2017-13312
7.8 HIGH

In createFromParcel of MediaCas.java, there is a possible parcel read/write mismatch due to improper input validation. This could lead to local escalation of privilege where …

Nov 15, 2024
CVE-2017-13310
7.8 HIGH

In createFromParcel of ViewPager.java, there is a possible read/write serialization issue leading to a permissions bypass. This could lead to local escalation of privilege where …

Nov 15, 2024
CVE-2024-49060
8.8 HIGH

Azure Stack HCI Elevation of Privilege Vulnerability

Nov 15, 2024
CVE-2024-44759
7.5 HIGH

An arbitrary file download vulnerability in the component /Doc/DownloadFile of NUS-M9 ERP Management Software v3.0.0 allows attackers to download arbitrary files and access sensitive information …

Nov 15, 2024
CVE-2024-11258
7.3 HIGH

A vulnerability classified as critical was found in 1000 Projects Beauty Parlour Management System 1.0. This vulnerability affects unknown code of the file /admin/index.php. The …

Nov 15, 2024
CVE-2024-11257
7.3 HIGH

A vulnerability classified as critical has been found in 1000 Projects Beauty Parlour Management System 1.0. This affects an unknown part of the file /admin/forgot-password.php. …

Nov 15, 2024
CVE-2024-11256
7.3 HIGH

A vulnerability was found in 1000 Projects Portfolio Management System MCA 1.0 and classified as critical. This issue affects some unknown processing of the file …

Nov 15, 2024
CVE-2024-51141
7.8 HIGH

An issue in TOTOLINK Bluetooth Wireless Adapter A600UB allows a local attacker to execute arbitrary code via the WifiAutoInstallDriver.exe and MSASN1.dll components.

Nov 15, 2024
CVE-2024-45969
7.5 HIGH

NULL pointer dereference in the MMS Client in MZ Automation LibIEC1850 before commit 7afa40390b26ad1f4cf93deaa0052fe7e357ef33 allows a malicious server to Cause a Denial-of-Service via the MMS …

Nov 15, 2024
CVE-2024-24431
7.5 HIGH

A reachable assertion in the ogs_nas_emm_decode function of Open5GS v2.7.0 allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet with …

Nov 15, 2024
CVE-2024-24426
7.5 HIGH

Reachable assertions in the NGAP_FIND_PROTOCOLIE_BY_ID function of OpenAirInterface Magma v1.8.0 and OAI EPC Federation v1.2.0 allow attackers to cause a Denial of Service (DoS) via …

Nov 15, 2024
CVE-2024-52508
8.2 HIGH

Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. When a user is trying to set up a mail account with an …

Nov 15, 2024
CVE-2024-46467
7.8 HIGH

By default, dedicated folders of ZONEPOINT for Windows up to 2024.1 can be accessed by other users to misuse technical files and make them perform …

Nov 15, 2024
CVE-2024-46466
7.8 HIGH

By default, dedicated folders of ZONECENTRAL for Windows up to 2024.3 or up to Q.2021.2 (ANSSI qualification submission) can be accessed by other users to …

Nov 15, 2024
CVE-2024-46465
7.8 HIGH

By default, dedicated folders of CRYHOD for Windows up to 2024.3 can be accessed by other users to misuse technical files and make them perform …

Nov 15, 2024
CVE-2024-46463
7.8 HIGH

By default, dedicated folders of ORIZON for Windows up to 2024.3 can be accessed by other users to misuse technical files and make them perform …

Nov 15, 2024
CVE-2024-46462
7.8 HIGH

By default, dedicated folders of ZEDMAIL for Windows up to 2024.3 can be accessed by other users to misuse technical files and make them perform …

Nov 15, 2024
CVE-2024-40638
8.1 HIGH

GLPI is a free asset and IT management software package. An authenticated user can exploit multiple SQL injection vulnerabilities. One of them can be used …

Nov 15, 2024
CVE-2024-50654
7.5 HIGH

lilishop <=4.2.4 is vulnerable to Incorrect Access Control, which can allow attackers to obtain coupons beyond the quantity limit by capturing and sending the data …

Nov 15, 2024
CVE-2024-50653
7.5 HIGH

CRMEB <=5.4.0 is vulnerable to Incorrect Access Control. Users can bypass the front-end restriction of only being able to claim coupons once by capturing packets …

Nov 15, 2024
CVE-2024-44625
8.8 HIGH

Gogs <=0.13.0 is vulnerable to Directory Traversal via the editFilePost function of internal/route/repo/editor.go.

Nov 15, 2024
CVE-2024-39726
8.2 HIGH

IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A …

Nov 15, 2024
CVE-2024-11248
8.8 HIGH

A vulnerability was found in Tenda AC10 16.03.10.13 and classified as critical. Affected by this issue is the function formSetRebootTimer of the file /goform/SetSysAutoRebbotCfg. The …

Nov 15, 2024
CVE-2024-50650
7.5 HIGH

python_book V1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of users with different IDs by modifying the ID parameter.

Nov 15, 2024
CVE-2024-50647
7.5 HIGH

The python_food ordering system V1.0 has an unauthorized vulnerability that leads to the leakage of sensitive user information. Attackers can access it through https://ip:port/api/myapp/index/user/info?id=1 And …

Nov 15, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.