CVE Database

38969+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-8905
8.8 HIGH

Inappropriate implementation in V8 in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page. (Chromium …

Sep 17, 2024
CVE-2024-8904
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Sep 17, 2024
CVE-2024-45606
7.1 HIGH

Sentry is a developer-first error tracking and performance monitoring platform. An authenticated user can mute alert rules from arbitrary organizations and projects with a know …

Sep 17, 2024
CVE-2024-45398
8.3 HIGH

Contao is an Open Source CMS. In affected versions a back end user with access to the file manager can upload malicious files and execute …

Sep 17, 2024
CVE-2024-8948
7.3 HIGH

A vulnerability was found in MicroPython 1.23.0. It has been rated as critical. Affected by this issue is the function mpz_as_bytes of the file py/objint.c. …

Sep 17, 2024
CVE-2024-8946
7.3 HIGH

A vulnerability was found in MicroPython 1.23.0. It has been classified as critical. Affected is the function mp_vfs_umount of the file extmod/vfs.c of the component …

Sep 17, 2024
CVE-2024-8900
7.5 HIGH

An attacker could write data to the user's clipboard, bypassing the user prompt, during a certain sequence of navigational events. This vulnerability affects Firefox < …

Sep 17, 2024
CVE-2024-43460
8.1 HIGH

Improper authorization in Dynamics 365 Business Central resulted in a vulnerability that allows an authenticated attacker to elevate privileges over a network.

Sep 17, 2024
CVE-2024-8944
7.3 HIGH

A vulnerability, which was classified as critical, was found in code-projects Hospital Management System 1.0. This affects an unknown part of the file check_availability.php. The …

Sep 17, 2024
CVE-2024-45682
8.8 HIGH

There is a command injection vulnerability that may allow an attacker to inject malicious input on the device's operating system.

Sep 17, 2024
CVE-2024-42503
7.2 HIGH

Authenticated command execution vulnerability exist in the ArubaOS command line interface (CLI). Successful exploitation of this vulnerabilities result in the ability to run arbitrary commands …

Sep 17, 2024
CVE-2024-42502
7.2 HIGH

Authenticated command injection vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability result in the ability to inject shell commands on …

Sep 17, 2024
CVE-2024-42501
7.2 HIGH

An authenticated Path Traversal vulnerabilities exists in the ArubaOS. Successful exploitation of this vulnerability allows an attacker to install unsigned packages on the underlying operating …

Sep 17, 2024
CVE-2024-38813
7.5 HIGH KEV

The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to …

Sep 17, 2024
CVE-2024-8768
7.5 HIGH

A flaw was found in the vLLM library. A completions API request with an empty prompt will crash the vLLM API server, resulting in a …

Sep 17, 2024
CVE-2024-7788
7.8 HIGH

Improper Digital Signature Invalidation vulnerability in Zip Repair Mode of The Document Foundation LibreOffice allows Signature forgery vulnerability in LibreOfficeThis issue affects LibreOffice: from 24.2 …

Sep 17, 2024
CVE-2021-27916
8.1 HIGH

Prior to the patched version, logged in users of Mautic are vulnerable to Relative Path Traversal/Arbitrary File Deletion. Regardless of the level of access the …

Sep 17, 2024
CVE-2024-47049
8.2 HIGH

The czim/file-handling package before 1.5.0 and 2.x before 2.3.0 (used with PHP Composer) does not properly validate URLs within makeFromUrl and makeFromAny, leading to SSRF, …

Sep 17, 2024
CVE-2024-47047
7.5 HIGH

An issue was discovered in the powermail extension through 12.4.0 for TYPO3. It fails to validate the mail parameter of the createAction, resulting in Insecure …

Sep 17, 2024
CVE-2024-22303
8.8 HIGH

Incorrect Privilege Assignment vulnerability in favethemes Houzez allows Privilege Escalation.This issue affects Houzez: from n/a through 3.2.4.

Sep 17, 2024
CVE-2024-21743
8.8 HIGH

Privilege Escalation vulnerability in favethemes Houzez Login Register houzez-login-register.This issue affects Houzez Login Register: from n/a through 3.2.5.

Sep 17, 2024
CVE-2021-27915
7.6 HIGH

Prior to the patched version, there is an XSS vulnerability in the description fields within the Mautic application which could be exploited by a logged …

Sep 17, 2024
CVE-2024-46362
8.8 HIGH

FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/create_directory

Sep 17, 2024
CVE-2024-46085
8.8 HIGH

FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/rename

Sep 17, 2024
CVE-2024-5998
7.8 HIGH

A vulnerability in the FAISS.deserialize_from_bytes function of langchain-ai/langchain allows for pickle deserialization of untrusted data. This can lead to the execution of arbitrary commands via …

Sep 17, 2024
CVE-2024-8761
7.2 HIGH

The Share This Image plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.03. This is due to insufficient …

Sep 17, 2024
CVE-2024-8490
8.8 HIGH

The PropertyHive plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.19. This is due to missing or …

Sep 17, 2024
CVE-2024-8110
7.5 HIGH

Denial of Service (DoS) vulnerability has been found in Dual-redundant Platform for Computer. If a computer on which the affected product is installed receives a …

Sep 17, 2024
CVE-2024-44189
7.5 HIGH

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15. A logic issue existed where a process may be able …

Sep 17, 2024
CVE-2024-44165
7.5 HIGH

A logic issue was addressed with improved checks. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia …

Sep 17, 2024
CVE-2024-44164
7.1 HIGH

This issue was addressed with improved checks. This issue is fixed in iOS 17.7 and iPadOS 17.7, macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura …

Sep 17, 2024
CVE-2024-44162
7.8 HIGH

This issue was addressed by enabling hardened runtime. This issue is fixed in Xcode 16. A malicious application may gain access to a user's Keychain …

Sep 17, 2024
CVE-2024-44152
7.5 HIGH

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15. An app may be …

Sep 17, 2024
CVE-2024-44149
7.5 HIGH

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. An app may be able to access protected user …

Sep 17, 2024
CVE-2024-44132
8.8 HIGH

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15. An app may be able to break out …

Sep 17, 2024
CVE-2024-40861
7.8 HIGH

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15. An app may be able to gain root privileges.

Sep 17, 2024
CVE-2024-40856
7.5 HIGH

An integrity issue was addressed with Beacon Protection. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18. An attacker …

Sep 17, 2024
CVE-2024-40848
7.5 HIGH

A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7. An attacker …

Sep 17, 2024
CVE-2024-40770
7.5 HIGH

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. A non-privileged user may be able to modify restricted …

Sep 17, 2024
CVE-2024-27879
7.5 HIGH

The issue was addressed with improved bounds checks. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18. An attacker …

Sep 17, 2024
CVE-2024-27874
7.5 HIGH

This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18. A remote attacker may be able to …

Sep 17, 2024
CVE-2024-27795
7.5 HIGH

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. A camera extension may be able to access the …

Sep 17, 2024
CVE-2024-45416
8.1 HIGH

The HTTPD binary in multiple ZTE routers has a local file inclusion vulnerability in session_init function. The session -LUA- files are stored in the directory …

Sep 16, 2024
CVE-2024-45413
8.1 HIGH

The HTTPD binary in multiple ZTE routers has a stack-based buffer overflow vulnerability in rsa_decrypt function. This function is an API wrapper for LUA to …

Sep 16, 2024
CVE-2024-42798
7.6 HIGH

An Incorrect Access Control vulnerability was found in /music/index.php?page=user_list and /music/index.php?page=edit_user in Kashipara Music Management System v1.0. This allows a low privileged attacker to take …

Sep 16, 2024
CVE-2024-45801
7.3 HIGH

DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. It has been discovered that malicious HTML using special nesting techniques can …

Sep 16, 2024
CVE-2024-45799
7.3 HIGH

FluxCP is a web-based Control Panel for rAthena servers written in PHP. A javascript injection is possible via venders/buyers list pages and shop names, that …

Sep 16, 2024
CVE-2023-45854
7.5 HIGH

A Business Logic vulnerability in Shopkit 1.0 allows an attacker to add products with negative quantities to the shopping cart via the qtd parameter in …

Sep 16, 2024
CVE-2024-23599
7.9 HIGH

Race condition in Seamless Firmware Updates for some Intel(R) reference platforms may allow a privileged user to potentially enable denial of service via local access.

Sep 16, 2024
CVE-2024-21871
7.5 HIGH

Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

Sep 16, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.