CVE Database

38969+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2021-38133
7.4 HIGH

Possible External Service Interaction attack in eDirectory has been discovered in OpenText™ eDirectory. This impact all version before 9.2.6.0000.

Sep 12, 2024
CVE-2021-22532
7.6 HIGH

Possible NLDAP Denial of Service attack Vulnerability in eDirectory has been discovered in OpenText™ eDirectory before 9.2.4.0000.

Sep 12, 2024
CVE-2024-8749
8.8 HIGH

SQL injection vulnerability in idoit pro version 28. This vulnerability could allow an attacker to send a specially crafted query to the ID parameter in …

Sep 12, 2024
CVE-2024-7766
7.2 HIGH

The Adicon Server WordPress plugin through 1.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform …

Sep 12, 2024
CVE-2024-45624
7.5 HIGH

Exposure of sensitive information due to incompatible policies issue exists in Pgpool-II. If a database user accesses a query cache, table data unauthorized for the …

Sep 12, 2024
CVE-2024-37397
8.2 HIGH

An External XML Entity (XXE) vulnerability in the provisioning web service of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote …

Sep 12, 2024
CVE-2024-34785
7.2 HIGH

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve …

Sep 12, 2024
CVE-2024-34783
7.2 HIGH

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve …

Sep 12, 2024
CVE-2024-34779
7.2 HIGH

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve …

Sep 12, 2024
CVE-2024-32848
7.2 HIGH

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve …

Sep 12, 2024
CVE-2024-32846
7.2 HIGH

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve …

Sep 12, 2024
CVE-2024-32845
7.2 HIGH

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve …

Sep 12, 2024
CVE-2024-32843
7.2 HIGH

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve …

Sep 12, 2024
CVE-2024-32842
7.2 HIGH

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve …

Sep 12, 2024
CVE-2024-32840
7.2 HIGH

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve …

Sep 12, 2024
CVE-2024-28981
8.5 HIGH

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.8, including 8.3.x, discloses database passwords when searching metadata injectable fields.

Sep 12, 2024
CVE-2024-7890
7.3 HIGH

Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows

Sep 11, 2024
CVE-2024-7889
7.3 HIGH

Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows

Sep 11, 2024
CVE-2024-42760
7.5 HIGH

SQL Injection vulnerability in Ellevo v.6.2.0.38160 allows a remote attacker to obtain sensitive information via the /api/mob/instrucao/conta/destinatarios component.

Sep 11, 2024
CVE-2024-8691
7.1 HIGH

A vulnerability in the GlobalProtect portal in Palo Alto Networks PAN-OS software enables a malicious authenticated GlobalProtect user to impersonate another GlobalProtect user. Active GlobalProtect …

Sep 11, 2024
CVE-2024-8687
7.1 HIGH

An information exposure vulnerability exists in Palo Alto Networks PAN-OS software that enables a GlobalProtect end user to learn both the configured GlobalProtect uninstall password …

Sep 11, 2024
CVE-2024-8686
7.2 HIGH

A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as root on …

Sep 11, 2024
CVE-2024-44577
8.8 HIGH

RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the time_date function.

Sep 11, 2024
CVE-2024-44574
8.8 HIGH

RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the sys_conf function.

Sep 11, 2024
CVE-2024-44572
8.8 HIGH

RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the sys_mgmt function.

Sep 11, 2024
CVE-2024-44571
8.8 HIGH

RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain incorrect access control in the mService function at phpinf.php.

Sep 11, 2024
CVE-2024-44570
8.8 HIGH

RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a code injection vulnerability via the getParams function in phpinf.php.

Sep 11, 2024
CVE-2024-20489
8.4 HIGH

A vulnerability in the storage method of the PON Controller configuration file could allow an authenticated, local attacker with low privileges to obtain the MongoDB …

Sep 11, 2024
CVE-2024-20483
7.2 HIGH

Multiple vulnerabilities in Cisco Routed PON Controller Software, which runs as a docker container on hardware that is supported by Cisco IOS XR Software, could …

Sep 11, 2024
CVE-2024-20406
7.4 HIGH

A vulnerability in the segment routing feature for the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker …

Sep 11, 2024
CVE-2024-20398
8.8 HIGH

A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to obtain read/write file system access on the underlying …

Sep 11, 2024
CVE-2024-20381
8.8 HIGH

A vulnerability in the JSON-RPC API feature in Cisco Crosswork Network Services Orchestrator (NSO) and ConfD that is used by the web-based management interfaces of …

Sep 11, 2024
CVE-2024-20317
7.4 HIGH

A vulnerability in the handling of specific Ethernet frames by Cisco IOS XR Software for various Cisco Network Convergence System (NCS) platforms could allow an …

Sep 11, 2024
CVE-2024-20304
8.6 HIGH

A vulnerability in the multicast traceroute version 2 (Mtrace2) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to exhaust the UDP …

Sep 11, 2024
CVE-2024-5760
7.8 HIGH

The Samsung Universal Print Driver for Windows is potentially vulnerable to escalation of privilege allowing the creation of a reverse shell in the tool. This …

Sep 11, 2024
CVE-2024-45026
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: s390/dasd: fix error recovery leading to data corruption on ESE devices Extent Space Efficient (ESE) …

Sep 11, 2024
CVE-2024-45023
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: md/raid1: Fix data corruption for degraded array with slow disk read_balance() will avoid reading from …

Sep 11, 2024
CVE-2024-39378
7.8 HIGH

Audition versions 24.4.1, 23.6.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the …

Sep 11, 2024
CVE-2024-8306
7.8 HIGH

CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentiality, integrity and availability of the workstation when non-admin authenticated user tries …

Sep 11, 2024
CVE-2024-8642
8.1 HIGH

In Eclipse Dataspace Components, from version 0.5.0 and before version 0.9.0, the ConsumerPullTransferTokenValidationApiController does not check for token validity (expiry, not-before, issuance date), which can …

Sep 11, 2024
CVE-2024-8639
8.8 HIGH

Use after free in Autofill in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a crafted …

Sep 11, 2024
CVE-2024-8638
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium …

Sep 11, 2024
CVE-2024-8637
8.8 HIGH

Use after free in Media Router in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a …

Sep 11, 2024
CVE-2024-8636
8.8 HIGH

Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Sep 11, 2024
CVE-2024-7609
7.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Vidco Software VOC TESTER allows Path Traversal.This issue affects VOC TESTER: before …

Sep 11, 2024
CVE-2024-45788
7.5 HIGH

This vulnerability exists in Reedos aiM-Star version 2.0.1 due to missing rate limiting on OTP requests in certain API endpoints. An authenticated remote attacker could …

Sep 11, 2024
CVE-2024-45327
7.5 HIGH

An improper authorization vulnerability [CWE-285] in FortiSOAR version 7.4.0 through 7.4.3, 7.3.0 through 7.3.2, 7.2.0 through 7.2.2, 7.0.0 through 7.0.3 change password endpoint may allow …

Sep 11, 2024
CVE-2024-7626
8.1 HIGH

The WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) plugin for WordPress is vulnerable to arbitrary file movement and reading due to …

Sep 11, 2024
CVE-2024-43690
8.0 HIGH

Inclusion of Functionality from Untrusted Control Sphere(CWE-829) in the Command Centre Server and Workstations may allow an attacker to perform Remote Code Execution (RCE). This …

Sep 11, 2024
CVE-2024-21529
8.2 HIGH

Versions of the package dset before 3.1.4 are vulnerable to Prototype Pollution via the dset function due improper user input sanitization. This vulnerability allows the …

Sep 11, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.