CVE Database

54581+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-53526
6.4 MEDIUM

composio >=0.5.40 is vulnerable to Command Execution in composio_openai, composio_claude, and composio_julep via the handle_tool_calls function.

Jan 8, 2025
CVE-2024-13188
5.3 MEDIUM

A vulnerability was found in MicroWorld eScan Antivirus 7.0.32 on Linux. It has been rated as critical. Affected by this issue is some unknown functionality …

Jan 8, 2025
CVE-2024-6350
6.5 MEDIUM

A malformed 802.15.4 packet causes a buffer overflow to occur leading to an assert and a denial of service. A watchdog reset clears the error …

Jan 8, 2025
CVE-2024-56787
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: soc: imx8m: Probe the SoC driver as platform driver With driver_async_probe=* on kernel command line, …

Jan 8, 2025
CVE-2024-56785
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: MIPS: Loongson64: DTS: Really fix PCIe port nodes for ls7a Fix the dtc warnings: arch/mips/boot/dts/loongson/ls7a-pch.dtsi:68.16-416.5: …

Jan 8, 2025
CVE-2024-56783
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_socket: remove WARN_ON_ONCE on maximum cgroup level cgroup maximum depth is INT_MAX by default, …

Jan 8, 2025
CVE-2024-56782
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ACPI: x86: Add adev NULL check to acpi_quirk_skip_serdev_enumeration() acpi_dev_hid_match() does not check for adev == …

Jan 8, 2025
CVE-2024-56780
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: quota: flush quota_release_work upon quota writeback One of the paths quota writeback is called from …

Jan 8, 2025
CVE-2024-56779
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix nfs4_openowner leak when concurrent nfsd4_open occur The action force umount(umount -f) will attempt …

Jan 8, 2025
CVE-2024-56778
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/sti: avoid potential dereference of error pointers in sti_hqvdp_atomic_check The return value of drm_atomic_get_crtc_state() needs …

Jan 8, 2025
CVE-2024-56777
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/sti: avoid potential dereference of error pointers in sti_gdp_atomic_check The return value of drm_atomic_get_crtc_state() needs …

Jan 8, 2025
CVE-2024-56776
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/sti: avoid potential dereference of error pointers The return value of drm_atomic_get_crtc_state() needs to be …

Jan 8, 2025
CVE-2024-56774
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: add a sanity check for btrfs root in btrfs_search_slot() Syzbot reports a null-ptr-deref in …

Jan 8, 2025
CVE-2024-56773
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: kunit: Fix potential null dereference in kunit_device_driver_test() kunit_kzalloc() may return a NULL pointer, dereferencing it …

Jan 8, 2025
CVE-2024-56771
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mtd: spinand: winbond: Fix 512GW, 01GW, 01JW and 02JW ECC information These four chips: * …

Jan 8, 2025
CVE-2025-20168
5.4 MEDIUM

A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) …

Jan 8, 2025
CVE-2025-20167
5.4 MEDIUM

A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) …

Jan 8, 2025
CVE-2025-20166
5.4 MEDIUM

A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) …

Jan 8, 2025
CVE-2024-56770
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/sched: netem: account for backlog updates from child qdisc In general, 'qlen' of any classful …

Jan 8, 2025
CVE-2024-55459
6.5 MEDIUM

An issue in keras 3.7.0 allows attackers to write arbitrary files to the user's machine via downloading a crafted tar file through the get_file function.

Jan 8, 2025
CVE-2024-13187
5.3 MEDIUM

A vulnerability was found in Kingsoft WPS Office 6.14.0 on macOS. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Jan 8, 2025
CVE-2025-20126
4.8 MEDIUM

A vulnerability in certification validation routines of Cisco ThousandEyes Endpoint Agent for macOS and RoomOS could allow an unauthenticated, remote attacker to intercept or manipulate …

Jan 8, 2025
CVE-2025-20123
4.8 MEDIUM

Multiple vulnerabilities in the web-based management interface of Cisco Crosswork Network Controller could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against …

Jan 8, 2025
CVE-2024-12337
6.1 MEDIUM

The Shipping via Planzer for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘processed-ids’ parameter in all versions up to, and …

Jan 8, 2025
CVE-2024-11830
6.4 MEDIUM

The PDF Flipbook, 3D Flipbook—DearFlip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via outline settings in all versions up to 2.3.52 due to …

Jan 8, 2025
CVE-2024-12712
5.3 MEDIUM

The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the webhook …

Jan 8, 2025
CVE-2024-12855
4.3 MEDIUM

The AdForest theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX actions like 'sb_remove_ad' in …

Jan 8, 2025
CVE-2024-12328
6.4 MEDIUM

The MAS Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.1.7 due …

Jan 8, 2025
CVE-2024-12045
4.4 MEDIUM

The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the maker title value …

Jan 8, 2025
CVE-2025-22215
4.3 MEDIUM

VMware Aria Automation contains a server-side request forgery (SSRF) vulnerability. A malicious actor with "Organization Member" access to Aria Automation may exploit this vulnerability enumerate …

Jan 8, 2025
CVE-2024-8002
4.3 MEDIUM

A vulnerability has been found in VIWIS LMS 9.11 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component File …

Jan 8, 2025
CVE-2024-12852
6.4 MEDIUM

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ha_cmc_text' parameter of the Happy Mouse Cursor in all …

Jan 8, 2025
CVE-2024-12851
6.4 MEDIUM

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Jan 8, 2025
CVE-2024-12584
4.3 MEDIUM

The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and …

Jan 8, 2025
CVE-2024-12585
6.1 MEDIUM

The Property Hive WordPress plugin before 2.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Jan 8, 2025
CVE-2024-10585
5.3 MEDIUM

The InfiniteWP Client plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.13.0 via the 'historyID' parameter of the …

Jan 8, 2025
CVE-2024-10151
5.4 MEDIUM

The Auto iFrame WordPress plugin before 2.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where …

Jan 8, 2025
CVE-2024-54731
4.0 MEDIUM

cpdf through 2.8 allows stack consumption via a crafted PDF document.

Jan 8, 2025
CVE-2024-12205
6.4 MEDIUM

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the TF E Slider Widget in all versions up to, …

Jan 8, 2025
CVE-2024-12030
6.5 MEDIUM

The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to SQL Injection via the 'key' attribute of the 'mdf_value' shortcode in …

Jan 8, 2025
CVE-2025-21603
4.8 MEDIUM

Cross-site scripting vulnerability exists in MZK-DP300N firmware versions 1.05 and earlier. If an attacker logs in to the affected product and manipulates the device settings, …

Jan 8, 2025
CVE-2024-56456
6.8 MEDIUM

Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.

Jan 8, 2025
CVE-2024-56455
5.5 MEDIUM

Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.

Jan 8, 2025
CVE-2024-56454
5.5 MEDIUM

Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.

Jan 8, 2025
CVE-2024-56453
6.8 MEDIUM

Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.

Jan 8, 2025
CVE-2024-56452
5.5 MEDIUM

Vulnerability of input parameters not being verified during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.

Jan 8, 2025
CVE-2024-56450
6.3 MEDIUM

Buffer overflow vulnerability in the component driver module Impact: Successful exploitation of this vulnerability may affect availability.

Jan 8, 2025
CVE-2024-56449
6.6 MEDIUM

Privilege escalation vulnerability in the Account module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jan 8, 2025
CVE-2024-56448
6.7 MEDIUM

Vulnerability of improper access control in the home screen widget module Impact: Successful exploitation of this vulnerability may affect availability.

Jan 8, 2025
CVE-2024-54121
6.2 MEDIUM

Startup control vulnerability in the ability module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.

Jan 8, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.