CVE Database

38969+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-20499
8.6 HIGH

Multiple vulnerabilities in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote …

Oct 2, 2024
CVE-2024-20498
8.6 HIGH

Multiple vulnerabilities in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote …

Oct 2, 2024
CVE-2024-46626
8.8 HIGH

OS4ED openSIS-Classic v9.1 was discovered to contain a SQL injection vulnerability via a crafted payload.

Oct 2, 2024
CVE-2024-41290
8.1 HIGH

FlatPress CMS v1.3.1 1.3 was discovered to use insecure methods to store authentication data via the cookie's component.

Oct 2, 2024
CVE-2024-20470
7.2 HIGH

A vulnerability in the web-based management interface of Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an authenticated, …

Oct 2, 2024
CVE-2024-20449
8.8 HIGH

A vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, remote attacker with low privileges to execute arbitrary code on an affected …

Oct 2, 2024
CVE-2024-20393
8.8 HIGH

A vulnerability in the web-based management interface of Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an authenticated, …

Oct 2, 2024
CVE-2024-47807
8.1 HIGH

Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `iss` (Issuer) claim of an ID Token, allowing attackers to subvert the authentication …

Oct 2, 2024
CVE-2024-47806
8.1 HIGH

Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `aud` (Audience) claim of an ID Token, allowing attackers to subvert the authentication …

Oct 2, 2024
CVE-2024-47805
7.5 HIGH

Jenkins Credentials Plugin 1380.va_435002fa_924 and earlier, except 1371.1373.v4eb_fa_b_7161e9, does not redact encrypted values of credentials using the `SecretBytes` type when accessing item `config.xml` via REST …

Oct 2, 2024
CVE-2024-44193
7.8 HIGH

A logic issue was addressed with improved restrictions. This issue is fixed in iTunes 12.13.3 for Windows. A local attacker may be able to elevate …

Oct 2, 2024
CVE-2024-8885
8.8 HIGH

A local privilege escalation vulnerability in Sophos Intercept X for Windows with Central Device Encryption 2024.2.0 and older allows writing of arbitrary files.

Oct 2, 2024
CVE-2024-8038
7.9 HIGH

Vulnerable juju introspection abstract UNIX domain socket. An abstract UNIX domain socket responsible for introspection is available without authentication locally to network namespace users. This …

Oct 2, 2024
CVE-2024-7558
8.7 HIGH

JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju charm container (on Kubernetes), an unprivileged user in the same network namespace …

Oct 2, 2024
CVE-2024-44030
7.2 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mestres do WP Checkout Mestres WP checkout-mestres-wp allows Absolute Path Traversal.This issue …

Oct 2, 2024
CVE-2024-44017
7.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in MinHyeong Lim MH Board mh-board allows PHP Local File Inclusion.This issue affects …

Oct 2, 2024
CVE-2024-7315
7.5 HIGH

The Migration, Backup, Staging WordPress plugin before 0.9.106 does not use sufficient randomness in the filename that is created when generating a backup, which could …

Oct 2, 2024
CVE-2024-7855
8.8 HIGH

The WP Hotel Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_review() function in all …

Oct 2, 2024
CVE-2024-33662
7.5 HIGH

Portainer before 2.20.2 improperly uses an encryption algorithm in the AesEncrypt function.

Oct 2, 2024
CVE-2024-47527
7.5 HIGH

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Device Dependencies" feature allows authenticated users to inject arbitrary …

Oct 1, 2024
CVE-2024-47525
7.5 HIGH

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Alert Rules" feature allows authenticated users to inject arbitrary …

Oct 1, 2024
CVE-2024-47524
7.2 HIGH

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. User with Admin role can create a Device Groups, the application did not properly sanitize the user …

Oct 1, 2024
CVE-2024-47523
7.5 HIGH

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Alert Transports" feature allows authenticated users to inject arbitrary …

Oct 1, 2024
CVE-2024-46084
8.0 HIGH

Scriptcase 9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_unzip function.

Oct 1, 2024
CVE-2024-46080
8.0 HIGH

Scriptcase v9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_zip function.

Oct 1, 2024
CVE-2024-42514
8.1 HIGH

A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.1.0.4 could allow an unauthenticated attacker to conduct an unauthorized access attack …

Oct 1, 2024
CVE-2024-9403
7.3 HIGH

Memory safety bugs present in Firefox 130. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of …

Oct 1, 2024
CVE-2024-9400
8.8 HIGH

A potential memory corruption vulnerability could be triggered if an attacker had the ability to trigger an OOM at a specific moment during JIT compilation. …

Oct 1, 2024
CVE-2024-9399
7.5 HIGH

A website configured to initiate a specially crafted WebTransport session could crash the Firefox process leading to a denial of service condition. This vulnerability affects …

Oct 1, 2024
CVE-2024-9396
8.8 HIGH

It is currently unknown if this issue is exploitable but a condition may arise where the structured clone of certain objects could lead to memory …

Oct 1, 2024
CVE-2024-9394
7.5 HIGH

An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://devtools` origin. This could allow them to access cross-origin JSON content. …

Oct 1, 2024
CVE-2024-9393
7.5 HIGH

An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://pdf.js` origin. This could allow them to access cross-origin PDF content. …

Oct 1, 2024
CVE-2024-47604
8.2 HIGH

NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability in its handling of HTML element attributes, which allows an …

Oct 1, 2024
CVE-2024-25659
7.2 HIGH

In Infinera TNMS (Transcend Network Management System) 19.10.3, an insecure default configuration of the internal SFTP server on Linux servers allows remote attacker to access …

Oct 1, 2024
CVE-2024-45408
7.5 HIGH

eLabFTW is an open source electronic lab notebook for research labs. An incorrect permission check has been found that could allow an authenticated user to …

Oct 1, 2024
CVE-2024-41673
7.1 HIGH

Decidim is a participatory democracy framework. The version control feature used in resources is subject to potential XSS attack through a malformed URL. This vulnerability …

Oct 1, 2024
CVE-2024-25661
7.7 HIGH

In Infinera TNMS (Transcend Network Management System) 19.10.3, cleartext storage of sensitive information in memory of the desktop application TNMS Client allows guest OS administrators …

Oct 1, 2024
CVE-2024-25632
8.6 HIGH

eLabFTW is an open source electronic lab notebook for research labs. In the context of eLabFTW, an administrator is a user account with certain privileges …

Oct 1, 2024
CVE-2024-46276
7.8 HIGH

cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_chunk() function at cute_png.h.

Oct 1, 2024
CVE-2024-46274
7.8 HIGH

cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_stored() function at cute_png.h.

Oct 1, 2024
CVE-2024-46267
7.8 HIGH

cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_block() function at cute_png.h.

Oct 1, 2024
CVE-2024-46264
7.8 HIGH

cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_find() function at cute_png.h.

Oct 1, 2024
CVE-2024-46263
7.8 HIGH

cute_png v1.05 was discovered to contain a stack overflow via the cp_dynamic() function at cute_png.h.

Oct 1, 2024
CVE-2024-46261
7.8 HIGH

cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_make32() function at cute_png.h.

Oct 1, 2024
CVE-2024-46259
7.8 HIGH

cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_unfilter() function at cute_png.h.

Oct 1, 2024
CVE-2024-46258
7.8 HIGH

cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_load_png_mem() function at cute_png.h.

Oct 1, 2024
CVE-2024-9018
8.8 HIGH

The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the ‘key’ parameter in all versions up …

Oct 1, 2024
CVE-2024-8548
8.1 HIGH

The KB Support – WordPress Help Desk and Knowledge Base plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a …

Oct 1, 2024
CVE-2024-7869
7.2 HIGH

The 123.chat - Video Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.3.1 due to insufficient …

Oct 1, 2024
CVE-2024-7434
8.8 HIGH

The UltraPress theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.2.2 via deserialization of untrusted input. This …

Oct 1, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.