CVE Database

38969+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-47010
7.3 HIGH

Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.

Oct 8, 2024
CVE-2024-47009
7.3 HIGH

Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.

Oct 8, 2024
CVE-2024-47008
7.5 HIGH

Server-side request forgery in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information.

Oct 8, 2024
CVE-2024-47007
7.5 HIGH

A NULL pointer dereference in WLAvalancheService.exe of Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to cause a denial of service.

Oct 8, 2024
CVE-2024-8215
8.4 HIGH

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Payara Platform Payara Server (Admin Console modules) allows Remote Code Inclusion.This …

Oct 8, 2024
CVE-2024-45230
7.5 HIGH

An issue was discovered in Django 5.1 before 5.1.1, 5.0 before 5.0.9, and 4.2 before 4.2.16. The urlize() and urlizetrunc() template filters are subject to …

Oct 8, 2024
CVE-2024-45880
8.0 HIGH

A command injection vulnerability exists in Motorola CX2L router v1.0.2 and below. The vulnerability is present in the SetStationSettings function. The system directly invokes the …

Oct 8, 2024
CVE-2024-45330
7.2 HIGH

A use of externally-controlled format string in Fortinet FortiAnalyzer versions 7.4.0 through 7.4.3, 7.2.2 through 7.2.5 allows attacker to escalate its privileges via specially crafted …

Oct 8, 2024
CVE-2024-8422
7.8 HIGH

CWE-416: Use After Free vulnerability exists that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when application user opens …

Oct 8, 2024
CVE-2024-47562
8.8 HIGH

A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly neutralize special elements in user input …

Oct 8, 2024
CVE-2024-47046
7.8 HIGH

A vulnerability has been identified in Simcenter Femap V2306 (All versions), Simcenter Femap V2401 (All versions), Simcenter Femap V2406 (All versions). The affected application is …

Oct 8, 2024
CVE-2024-45475
7.8 HIGH

A vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versions < V14.3.0.12), Teamcenter Visualization V2312 (All versions …

Oct 8, 2024
CVE-2024-45474
7.8 HIGH

A vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versions < V14.3.0.12), Teamcenter Visualization V2312 (All versions …

Oct 8, 2024
CVE-2024-45473
7.8 HIGH

A vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versions < V14.3.0.12), Teamcenter Visualization V2312 (All versions …

Oct 8, 2024
CVE-2024-45472
7.8 HIGH

A vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versions < V14.3.0.12), Teamcenter Visualization V2312 (All versions …

Oct 8, 2024
CVE-2024-45471
7.8 HIGH

A vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versions < V14.3.0.12), Teamcenter Visualization V2312 (All versions …

Oct 8, 2024
CVE-2024-45470
7.8 HIGH

A vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versions < V14.3.0.12), Teamcenter Visualization V2312 (All versions …

Oct 8, 2024
CVE-2024-45469
7.8 HIGH

A vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versions < V14.3.0.12), Teamcenter Visualization V2312 (All versions …

Oct 8, 2024
CVE-2024-45468
7.8 HIGH

A vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versions < V14.3.0.12), Teamcenter Visualization V2312 (All versions …

Oct 8, 2024
CVE-2024-45467
7.8 HIGH

A vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versions < V14.3.0.12), Teamcenter Visualization V2312 (All versions …

Oct 8, 2024
CVE-2024-45466
7.8 HIGH

A vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versions < V14.3.0.12), Teamcenter Visualization V2312 (All versions …

Oct 8, 2024
CVE-2024-45465
7.8 HIGH

A vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versions < V14.3.0.12), Teamcenter Visualization V2312 (All versions …

Oct 8, 2024
CVE-2024-45464
7.8 HIGH

A vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versions < V14.3.0.12), Teamcenter Visualization V2312 (All versions …

Oct 8, 2024
CVE-2024-45463
7.8 HIGH

A vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versions < V14.3.0.12), Teamcenter Visualization V2312 (All versions …

Oct 8, 2024
CVE-2024-41981
7.8 HIGH

A vulnerability has been identified in Simcenter Femap V2306 (All versions), Simcenter Femap V2401 (All versions), Simcenter Femap V2406 (All versions). The affected application is …

Oct 8, 2024
CVE-2024-41902
7.8 HIGH

A vulnerability has been identified in JT2Go (All versions < V2406.0003). The affected application contains a stack-based buffer overflow vulnerability that could be triggered while …

Oct 8, 2024
CVE-2023-52952
8.5 HIGH

A vulnerability has been identified in HiMed Cockpit 12 pro (J31032-K2017-H259) (All versions >= V11.5.1 < V11.6.2), HiMed Cockpit 14 pro+ (J31032-K2017-H435) (All versions >= …

Oct 8, 2024
CVE-2024-34669
7.5 HIGH

Out-of-bounds write in parsing h.263+ format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User …

Oct 8, 2024
CVE-2024-34668
7.5 HIGH

Out-of-bounds write in parsing h.263 format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User …

Oct 8, 2024
CVE-2024-34667
7.5 HIGH

Out-of-bounds write in parsing h.265 format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User …

Oct 8, 2024
CVE-2024-34666
7.5 HIGH

Out-of-bounds write in parsing h.264 format in a specific mode in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code …

Oct 8, 2024
CVE-2024-34665
7.5 HIGH

Out-of-bounds write in parsing h.264 format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User …

Oct 8, 2024
CVE-2024-21532
7.3 HIGH

All versions of the package ggit are vulnerable to Command Injection via the fetchTags(branch) API, which allows user input to specify the branch to be …

Oct 8, 2024
CVE-2024-8927
7.5 HIGH

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, HTTP_REDIRECT_STATUS variable is used to check whether or not CGI binary is being …

Oct 8, 2024
CVE-2024-8926
8.1 HIGH

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using a certain non-standard configurations of Windows codepages, the fixes for CVE-2024-4577 …

Oct 8, 2024
CVE-2024-37179
7.7 HIGH

SAP BusinessObjects Business Intelligence Platform allows an authenticated user to send a specially crafted request to the Web Intelligence Reporting Server to download any file …

Oct 8, 2024
CVE-2024-47782
7.6 HIGH

WikiDiscover is an extension designed for use with a CreateWiki managed farm to display wikis. Special:WikiDiscover is a special page that lists all wikis on …

Oct 7, 2024
CVE-2024-47610
7.3 HIGH

InvenTree is an Open Source Inventory Management System. In affected versions of InvenTree it is possible for a registered user to store javascript in markdown …

Oct 7, 2024
CVE-2024-45290
7.7 HIGH

PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. It's possible for an attacker to construct an XLSX file which links media …

Oct 7, 2024
CVE-2024-45060
7.1 HIGH

PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. One of the sample scripts in PhpSpreadsheet is susceptible to a cross-site scripting …

Oct 7, 2024
CVE-2024-45051
8.2 HIGH

Discourse is an open source platform for community discussion. A maliciously crafted email address could allow an attacker to bypass domain-based restrictions and gain access …

Oct 7, 2024
CVE-2024-43789
7.5 HIGH

Discourse is an open source platform for community discussion. A user can create a post with many replies, and then attempt to fetch them all …

Oct 7, 2024
CVE-2024-43363
7.2 HIGH

Cacti is an open source performance and fault management framework. An admin user can create a device with a malicious hostname containing php code and …

Oct 7, 2024
CVE-2024-43362
7.3 HIGH

Cacti is an open source performance and fault management framework. The `fileurl` parameter is not properly sanitized when saving external links in `links.php` . Morever, …

Oct 7, 2024
CVE-2024-45293
7.5 HIGH

PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. The security scanner responsible for preventing XXE attacks in the XLSX reader can …

Oct 7, 2024
CVE-2024-31449
7.0 HIGH

Redis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua script to trigger a stack …

Oct 7, 2024
CVE-2024-47975
7.0 HIGH

Improper access control validation in firmware of some Solidigm DC Products may allow an attacker with physical access to gain unauthorized access or an attacker …

Oct 7, 2024
CVE-2024-47559
7.6 HIGH

Authenticated RCE via Path Traversal

Oct 7, 2024
CVE-2024-47558
7.6 HIGH

Authenticated RCE via Path Traversal

Oct 7, 2024
CVE-2024-47557
8.3 HIGH

Pre-Auth RCE via Path Traversal

Oct 7, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.