CVE Database

38969+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-21829
7.5 HIGH

Improper input validation in UEFI firmware error handler for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local …

Sep 16, 2024
CVE-2024-21781
7.2 HIGH

Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to enable information disclosure or denial of service via local …

Sep 16, 2024
CVE-2023-43626
7.5 HIGH

Improper access control in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

Sep 16, 2024
CVE-2023-42772
8.2 HIGH

Untrusted pointer dereference in UEFI firmware for some Intel(R) reference processors may allow a privileged user to potentially enable escalation of privilege via local access.

Sep 16, 2024
CVE-2023-41833
7.5 HIGH

A race condition in UEFI firmware for some Intel(R) processors may allow a privileged user to potentially enable escalation of privilege via local access.

Sep 16, 2024
CVE-2024-8752
7.5 HIGH

The Windows version of WebIQ 2.15.9 is affected by a directory traversal vulnerability that allows remote attackers to read any file on the system.

Sep 16, 2024
CVE-2024-46937
7.5 HIGH

An improper access control (IDOR) vulnerability in the /api-selfportal/get-info-token-properties endpoint in MFASOFT Secure Authentication Server (SAS) 1.8.x through 1.9.x before 1.9.040924 allows remote attackers gain …

Sep 16, 2024
CVE-2024-46424
7.5 HIGH

TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the UploadCustomModule function, which allows attackers to cause a Denial of Service (DoS) via the …

Sep 16, 2024
CVE-2024-45696
8.8 HIGH

Certain models of D-Link wireless routers contain hidden functionality. By sending specific packets to the web service, the attacker can forcibly enable the telnet service …

Sep 16, 2024
CVE-2024-8779
8.8 HIGH

OMFLOW from The SYSCOM Group does not properly restrict access to the system settings modification functionality, allowing remote attackers with regular privileges to update system …

Sep 16, 2024
CVE-2024-8777
7.5 HIGH

OMFLOW from The SYSCOM Group has an information leakage vulnerability, allowing unauthorized remote attackers to read arbitrary system configurations. If LDAP authentication is enabled, attackers …

Sep 16, 2024
CVE-2024-46943
7.5 HIGH

An issue was discovered in OpenDaylight Authentication, Authorization and Accounting (AAA) through 0.19.3. A rogue controller can join a cluster to impersonate an offline peer, …

Sep 15, 2024
CVE-2024-46938
7.5 HIGH

An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release through 10.4 Initial Release. An unauthenticated …

Sep 15, 2024
CVE-2024-44053
7.1 HIGH

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Mohammad Arif Opor Ayam allows Reflected XSS.This issue affects Opor Ayam: …

Sep 15, 2024
CVE-2024-45459
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Product Slider for WooCommerce woocommerce-products-slider allows Reflected XSS.This issue affects Product Slider …

Sep 15, 2024
CVE-2024-45458
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spiffy Plugins Spiffy Calendar spiffy-calendar allows Reflected XSS.This issue affects Spiffy Calendar: from …

Sep 15, 2024
CVE-2024-44060
7.1 HIGH

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jennifer Hall Filmix allows Reflected XSS.This issue affects Filmix: from n/a …

Sep 15, 2024
CVE-2024-8868
7.3 HIGH

A vulnerability was found in code-projects Crud Operation System 1.0. It has been rated as critical. This issue affects some unknown processing of the file …

Sep 15, 2024
CVE-2024-8862
7.3 HIGH

A vulnerability, which was classified as critical, has been found in h2oai h2o-3 3.46.0.4. This issue affects the function getConnectionSafe of the file /dtale/chart-data/1 of …

Sep 14, 2024
CVE-2024-6482
8.8 HIGH

The Login with phone number plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.7.49. This is due to …

Sep 14, 2024
CVE-2024-8479
7.3 HIGH

The The Simple Spoiler plugin for WordPress is vulnerable to arbitrary shortcode execution in versions 1.2 to 1.3. This is due to the plugin adding …

Sep 14, 2024
CVE-2024-8246
8.8 HIGH

The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulnerable …

Sep 14, 2024
CVE-2024-8271
7.3 HIGH

The The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, …

Sep 14, 2024
CVE-2024-6259
7.6 HIGH

BT: HCI: adv_ext_report Improper discarding in adv_ext_report

Sep 13, 2024
CVE-2024-44095
7.8 HIGH

In ppmp_protect_mfcfw_buf of code/drm_fw.c, there is a possible corrupt memory due to a logic error in the code. This could lead to local escalation of …

Sep 13, 2024
CVE-2024-44094
7.8 HIGH

In ppmp_protect_mfcfw_buf of code/drm_fw.c, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege with no …

Sep 13, 2024
CVE-2024-44093
7.8 HIGH

In ppmp_unprotect_buf of drm/code/drm_fw.c, there is a possible memory corruption due to a logic error in the code. This could lead to local escalation of …

Sep 13, 2024
CVE-2024-44092
7.8 HIGH

There is a possible LCS signing enforcement missing due to test/debugging code left in a production build. This could lead to local escalation of privilege …

Sep 13, 2024
CVE-2024-29779
7.8 HIGH

there is a possible escalation of privilege due to an unusual root cause. This could lead to local escalation of privilege with no additional execution …

Sep 13, 2024
CVE-2024-6137
7.6 HIGH

BT: Classic: SDP OOB access in get_att_search_list

Sep 13, 2024
CVE-2024-6135
7.6 HIGH

BT:Classic: Multiple missing buf length checks

Sep 13, 2024
CVE-2024-5754
8.2 HIGH

BT: Encryption procedure host vulnerability

Sep 13, 2024
CVE-2024-8281
7.2 HIGH

An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection through specially …

Sep 13, 2024
CVE-2024-8280
7.2 HIGH

An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection or cause …

Sep 13, 2024
CVE-2024-8279
7.2 HIGH

A privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection via specially …

Sep 13, 2024
CVE-2024-8278
7.2 HIGH

A privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection via specially …

Sep 13, 2024
CVE-2024-39924
8.8 HIGH

An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A vulnerability has been identified in the authentication and authorization process of the endpoint responsible for …

Sep 13, 2024
CVE-2024-6862
8.1 HIGH

A Cross-Site Request Forgery (CSRF) vulnerability exists in lunary-ai/lunary version 1.2.34 due to overly permissive CORS settings. This vulnerability allows an attacker to sign up …

Sep 13, 2024
CVE-2024-45368
8.8 HIGH

The H2-DM1E PLC's authentication protocol appears to utilize either a custom encoding scheme or a challenge-response protocol. However, there's an observed anomaly in the H2-DM1E …

Sep 13, 2024
CVE-2024-43099
8.8 HIGH

The session hijacking attack targets the application layer's control mechanism, which manages authenticated sessions between a host PC and a PLC. During such sessions, a …

Sep 13, 2024
CVE-2024-6587
7.5 HIGH

A Server-Side Request Forgery (SSRF) vulnerability exists in berriai/litellm version 1.38.10. This vulnerability allows users to specify the `api_base` parameter when making requests to `POST …

Sep 13, 2024
CVE-2024-42025
7.8 HIGH

A Command Injection vulnerability found in a Self-Hosted UniFi Network Servers (Linux) with UniFi Network Application (Version 8.3.32 and earlier) allows a malicious actor with …

Sep 13, 2024
CVE-2024-8269
7.3 HIGH

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized user registration in all versions …

Sep 13, 2024
CVE-2024-7423
8.8 HIGH

The Stream plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.0.1. This is due to missing or …

Sep 13, 2024
CVE-2024-46713
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: perf/aux: Fix AUX buffer serialization Ole reported that event->mmap_mutex is strictly insufficient to serialize the …

Sep 13, 2024
CVE-2022-2446
7.2 HIGH

The WP Editor plugin for WordPress is vulnerable to deserialization of untrusted input via the 'current_theme_root' parameter in versions up to, and including 1.2.9. This …

Sep 13, 2024
CVE-2024-46047
7.5 HIGH

Tenda FH451 v1.0.0.9 has a stack overflow vulnerability in the fromDhcpListClient function.

Sep 13, 2024
CVE-2024-45113
7.5 HIGH

ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability …

Sep 13, 2024
CVE-2024-45109
7.8 HIGH

Photoshop Desktop versions 24.7.4, 25.11 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Sep 13, 2024
CVE-2024-45108
7.8 HIGH

Photoshop Desktop versions 24.7.4, 25.11 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Sep 13, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.