CVE Database

38969+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-47502
7.5 HIGH

An Allocation of Resources Without Limits or Throttling vulnerability in the kernel of Juniper Networks Junos OS Evolved allows an unauthenticated, network based attacker to …

Oct 11, 2024
CVE-2024-47499
7.5 HIGH

An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows …

Oct 11, 2024
CVE-2024-47497
7.5 HIGH

An Uncontrolled Resource Consumption vulnerability in the http daemon (httpd) of Juniper Networks Junos OS on SRX Series, QFX Series, MX Series and EX Series …

Oct 11, 2024
CVE-2024-47490
8.2 HIGH

An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved on ACX 7000 …

Oct 11, 2024
CVE-2024-44729
7.5 HIGH

Incorrect access control in the component app/src/server.js of Mirotalk before commit 9de226 allows unauthenticated attackers without presenter privileges to arbitrarily eject users from a meeting.

Oct 11, 2024
CVE-2024-39563
7.3 HIGH

A Command Injection vulnerability in Juniper Networks Junos Space allows an unauthenticated, network-based attacker sending a specially crafted request to execute arbitrary shell commands on …

Oct 11, 2024
CVE-2024-39547
7.5 HIGH

An Improper Handling of Exceptional Conditions vulnerability in the rpd-server of Juniper Networks Junos OS and Junos OS Evolved within cRPD allows an unauthenticated network-based …

Oct 11, 2024
CVE-2024-33582
7.8 HIGH

A DLL hijack vulnerability was reported in Lenovo Service Framework that could allow a local attacker to execute code with elevated privileges.

Oct 11, 2024
CVE-2024-33581
7.8 HIGH

A DLL hijack vulnerability was reported in Lenovo PC Manager AI intelligent scenario that could allow a local attacker to execute code with elevated privileges.

Oct 11, 2024
CVE-2024-33580
7.8 HIGH

A DLL hijack vulnerability was reported in Lenovo Personal Cloud that could allow a local attacker to execute code with elevated privileges.

Oct 11, 2024
CVE-2024-33579
7.8 HIGH

A DLL hijack vulnerability was reported in Lenovo Baiying that could allow a local attacker to execute code with elevated privileges.

Oct 11, 2024
CVE-2024-33578
7.8 HIGH

A DLL hijack vulnerability was reported in Lenovo Leyun that could allow a local attacker to execute code with elevated privileges.

Oct 11, 2024
CVE-2024-8755
8.4 HIGH

Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 …

Oct 11, 2024
CVE-2024-45402
8.6 HIGH

Picotls is a TLS protocol library that allows users select different crypto backends based on their use case. When parsing a spoofed TLS handshake message, …

Oct 11, 2024
CVE-2024-45396
7.5 HIGH

Quicly is an IETF QUIC protocol implementation. Quicly up to commtit d720707 is susceptible to a denial-of-service attack. A remote attacker can exploit these bugs …

Oct 11, 2024
CVE-2024-9002
7.8 HIGH

CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentiality, integrity, and availability of the workstation when non-admin authenticated user tries …

Oct 11, 2024
CVE-2024-8531
7.2 HIGH

CWE-347: Improper Verification of Cryptographic Signature vulnerability exists that could compromise the Data Center Expert software when an upgrade bundle is manipulated to include arbitrary …

Oct 11, 2024
CVE-2024-8970
8.2 HIGH

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.6 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from …

Oct 11, 2024
CVE-2024-45317
7.5 HIGH

A Server-Side Request Forgery (SSRF) vulnerability in SMA1000 appliance firmware versions 12.4.3-02676 and earlier allows a remote, unauthenticated attacker to cause the SMA1000 server-side application …

Oct 11, 2024
CVE-2024-45316
7.8 HIGH

The Improper link resolution before file access ('Link Following') vulnerability in SonicWall Connect Tunnel (version 12.4.3.271 and earlier of Windows client) allows users with standard …

Oct 11, 2024
CVE-2024-9818
7.3 HIGH

A vulnerability classified as critical has been found in SourceCodester Online Veterinary Appointment System 1.0. Affected is an unknown function of the file /admin/categories/manage_category.php. The …

Oct 10, 2024
CVE-2024-47870
8.1 HIGH

Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves a **race condition** in the `update_root_in_config` function, allowing an attacker to modify …

Oct 10, 2024
CVE-2024-47868
7.5 HIGH

Gradio is an open-source Python package designed for quick prototyping. This is a **data validation vulnerability** affecting several Gradio components, which allows arbitrary file leaks …

Oct 10, 2024
CVE-2024-47867
7.5 HIGH

Gradio is an open-source Python package designed for quick prototyping. This vulnerability is a **lack of integrity check** on the downloaded FRP client, which could …

Oct 10, 2024
CVE-2024-9814
7.3 HIGH

A vulnerability, which was classified as critical, was found in Codezips Pharmacy Management System 1.0. Affected is an unknown function of the file product/update.php. The …

Oct 10, 2024
CVE-2024-47084
8.3 HIGH

Gradio is an open-source Python package designed for quick prototyping. This vulnerability is related to **CORS origin validation**, where the Gradio server fails to validate …

Oct 10, 2024
CVE-2024-9813
7.3 HIGH

A vulnerability, which was classified as critical, has been found in Codezips Pharmacy Management System 1.0. This issue affects some unknown processing of the file …

Oct 10, 2024
CVE-2024-9812
7.3 HIGH

A vulnerability classified as critical was found in code-projects Crud Operation System 1.0. This vulnerability affects unknown code of the file delete.php. The manipulation of …

Oct 10, 2024
CVE-2024-9811
7.3 HIGH

A vulnerability classified as critical has been found in code-projects Restaurant Reservation System 1.0. This affects an unknown part of the file filter3.php. The manipulation …

Oct 10, 2024
CVE-2024-9180
7.2 HIGH

A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their own or another user’s privileges to Vault’s root policy. …

Oct 10, 2024
CVE-2024-47966
7.8 HIGH

Delta Electronics CNCSoft-G2 lacks proper initialization of memory prior to accessing it. An attacker can manipulate users to visit a malicious page or file to …

Oct 10, 2024
CVE-2024-47965
7.8 HIGH

Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can …

Oct 10, 2024
CVE-2024-47964
7.8 HIGH

Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can manipulate …

Oct 10, 2024
CVE-2024-47963
7.8 HIGH

Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can …

Oct 10, 2024
CVE-2024-47962
7.8 HIGH

Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can manipulate …

Oct 10, 2024
CVE-2024-9797
7.3 HIGH

A vulnerability, which was classified as critical, was found in code-projects Blood Bank System 1.0. Affected is an unknown function of the file register.php. The …

Oct 10, 2024
CVE-2024-9312
7.5 HIGH

Authd, through version 0.3.6, did not sufficiently randomize user IDs to prevent collisions. A local attacker who can register user names could spoof another user's …

Oct 10, 2024
CVE-2024-9786
8.8 HIGH

A vulnerability, which was classified as critical, has been found in D-Link DIR-619L B1 2.06. Affected by this issue is the function formSetLog of the …

Oct 10, 2024
CVE-2024-9785
8.8 HIGH

A vulnerability classified as critical was found in D-Link DIR-619L B1 2.06. Affected by this vulnerability is the function formSetDDNS of the file /goform/formSetDDNS. The …

Oct 10, 2024
CVE-2024-35202
7.5 HIGH

Bitcoin Core before 25.0 allows remote attackers to cause a denial of service (blocktxn message-handling assertion and node exit) by including transactions in a blocktxn …

Oct 10, 2024
CVE-2024-9784
8.8 HIGH

A vulnerability classified as critical has been found in D-Link DIR-619L B1 2.06. Affected is the function formResetStatistic of the file /goform/formResetStatistic. The manipulation of …

Oct 10, 2024
CVE-2024-9783
8.8 HIGH

A vulnerability was found in D-Link DIR-619L B1 2.06. It has been rated as critical. This issue affects the function formLogDnsquery of the file /goform/formLogDnsquery. …

Oct 10, 2024
CVE-2024-9782
8.8 HIGH

A vulnerability was found in D-Link DIR-619L B1 2.06. It has been declared as critical. This vulnerability affects the function formEasySetupWWConfig of the file /goform/formEasySetupWWConfig. …

Oct 10, 2024
CVE-2024-6530
7.3 HIGH

A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 17.1 prior 17.2.9, starting from 17.3 prior to 17.3.5, and starting …

Oct 10, 2024
CVE-2024-8977
8.2 HIGH

An issue has been discovered in GitLab EE affecting all versions starting from 15.10 prior to 17.2.9, from 17.3 prior to 17.3.5, and from 17.4 …

Oct 10, 2024
CVE-2024-45148
8.8 HIGH

Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authentication vulnerability that could result in a security feature bypass. A …

Oct 10, 2024
CVE-2024-45117
7.6 HIGH

Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. …

Oct 10, 2024
CVE-2024-45116
8.1 HIGH

Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a Cross-Site Scripting (XSS) vulnerability that could be exploited to execute arbitrary code. …

Oct 10, 2024
CVE-2024-9781
7.8 HIGH

AppleTalk and RELOAD Framing dissector crash in Wireshark 4.4.0 and 4.2.0 to 4.2.7 allows denial of service via packet injection or crafted capture file

Oct 10, 2024
CVE-2024-9780
7.8 HIGH

ITS dissector crash in Wireshark 4.4.0 allows denial of service via packet injection or crafted capture file

Oct 10, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.