CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-43417
6.5 MEDIUM

GLPI is a free asset and IT management software package. An unauthenticated user can provide a malicious link to a GLPI technician in order to …

Nov 15, 2024
CVE-2024-41679
6.5 MEDIUM

GLPI is a free asset and IT management software package. An authenticated user can exploit a SQL injection vulnerability from the ticket form. Upgrade to …

Nov 15, 2024
CVE-2024-24446
6.5 MEDIUM

An uninitialized pointer dereference in OpenAirInterface CN5G AMF up to v2.0.0 allows attackers to cause a Denial of Service (DoS) via a crafted InitialContextSetupResponse message …

Nov 15, 2024
CVE-2024-24425
6.5 MEDIUM

Magma v1.8.0 and OAI EPC Federation v1.20 were discovered to contain an out-of-bounds read in the amf_as_establish_req function at /tasks/amf/amf_as.cpp. This vulnerability allows attackers to …

Nov 15, 2024
CVE-2024-23169
4.6 MEDIUM

The web interface in RSA NetWitness 11.7.2.0 allows Cross-Site Scripting (XSS) via the Where textbox on the Reports screen during new rule creation.

Nov 15, 2024
CVE-2024-52514
4.1 MEDIUM

Nextcloud Server is a self hosted personal cloud system. After a user received a share with some files inside being blocked by the files access …

Nov 15, 2024
CVE-2024-52511
6.3 MEDIUM

Nextcloud Tables allows users to to create tables with individual columns. By directly specifying the ID of a table or view, a malicious user could …

Nov 15, 2024
CVE-2024-52510
4.2 MEDIUM

The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. The Desktop client did not stop with an error …

Nov 15, 2024
CVE-2024-50800
5.4 MEDIUM

Cross Site Scripting vulnerability in M2000 Smart4Web before v.5.020241004 allows a remote attacker to execute arbitrary code via the error parameter in URL

Nov 15, 2024
CVE-2024-47759
4.8 MEDIUM

GLPI is a free Asset and IT management software package. An technician can upload a SVG containing a malicious script. The script will then be …

Nov 15, 2024
CVE-2024-41678
6.5 MEDIUM

GLPI is a free asset and IT management software package. An unauthenticated user can provide a malicious link to a GLPI technician in order to …

Nov 15, 2024
CVE-2024-24450
5.3 MEDIUM

Stack-based memcpy buffer overflow in the ngap_handle_pdu_session_resource_setup_response routine in OpenAirInterface CN5G AMF <= 2.0.0 allows a remote attacker with access to the N2 interface to …

Nov 15, 2024
CVE-2024-24449
6.5 MEDIUM

An uninitialized pointer dereference in the NasPdu::NasPdu component of OpenAirInterface CN5G AMF up to v2.0.0 allows attackers to cause a Denial of Service (DoS) via …

Nov 15, 2024
CVE-2024-24447
5.3 MEDIUM

A buffer overflow in the ngap_amf_handle_pdu_session_resource_setup_response function of oai-cn5g-amf up to v2.0.0 allows attackers to cause a Denial of Service (DoS) via a PDU Session …

Nov 15, 2024
CVE-2024-11251
6.3 MEDIUM

A vulnerability was found in erzhongxmu Jeewms up to 20241108. It has been rated as critical. This issue affects some unknown processing of the file …

Nov 15, 2024
CVE-2024-11250
6.3 MEDIUM

A vulnerability was found in code-projects Inventory Management up to 1.0. It has been declared as critical. This vulnerability affects unknown code of the file …

Nov 15, 2024
CVE-2024-52523
4.6 MEDIUM

Nextcloud Server is a self hosted personal cloud system. After setting up a user or administrator defined external storage with fixed credentials, the API returns …

Nov 15, 2024
CVE-2024-52520
5.7 MEDIUM

Nextcloud Server is a self hosted personal cloud system. Due to a pre-flighted HEAD request, the link reference provider could be tricked into downloading bigger …

Nov 15, 2024
CVE-2024-52518
4.4 MEDIUM

Nextcloud Server is a self hosted personal cloud system. After an attacker got access to the session of a user or administrator, the attacker would …

Nov 15, 2024
CVE-2024-52517
4.6 MEDIUM

Nextcloud Server is a self hosted personal cloud system. After storing "Global credentials" on the server, the API returns them and adds them into the …

Nov 15, 2024
CVE-2024-52515
5.7 MEDIUM

Nextcloud Server is a self hosted personal cloud system. After an admin enables the default-disabled SVG preview provider, a malicious user could upload a manipulated …

Nov 15, 2024
CVE-2024-50655
5.4 MEDIUM

emlog pro <=2.3.18 is vulnerable to Cross Site Scripting (XSS), which allows attackers to write malicious JavaScript code in published articles.

Nov 15, 2024
CVE-2022-20633
5.3 MEDIUM

A vulnerability in the web-based management interface of Cisco&nbsp;ECE could allow an unauthenticated, remote attacker to perform a username enumeration attack against an affected device. …

Nov 15, 2024
CVE-2022-20632
6.1 MEDIUM

A vulnerability in the web-based management interface of Cisco&nbsp;ECE could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the …

Nov 15, 2024
CVE-2021-34753
5.8 MEDIUM

A vulnerability in the payload inspection for Ethernet Industrial Protocol (ENIP) traffic for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker …

Nov 15, 2024
CVE-2021-34752
6.7 MEDIUM

A vulnerability in the CLI of Cisco&nbsp;FTD Software could allow an authenticated, local attacker with administrative privileges to execute arbitrary commands with root privileges on …

Nov 15, 2024
CVE-2021-34751
4.3 MEDIUM

A vulnerability in the administrative web-based GUI configuration manager of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to access sensitive …

Nov 15, 2024
CVE-2021-34750
4.3 MEDIUM

A vulnerability in the administrative web-based GUI configuration manager of Cisco Firepower Management Center Software could allow an authenticated, remote attacker to access sensitive configuration …

Nov 15, 2024
CVE-2021-1494
5.8 MEDIUM

Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file …

Nov 15, 2024
CVE-2021-1491
6.5 MEDIUM

A vulnerability in the web-based management interface of Cisco&nbsp;SD-WAN vManage Software could allow an authenticated, remote attacker to read arbitrary files on the underlying file …

Nov 15, 2024
CVE-2021-1484
6.5 MEDIUM

A vulnerability in the web UI of Cisco&nbsp;SD-WAN vManage Software could allow an authenticated, remote attacker to inject arbitrary commands on an affected system and …

Nov 15, 2024
CVE-2021-1483
6.4 MEDIUM

A vulnerability in the web UI of Cisco&nbsp;SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that …

Nov 15, 2024
CVE-2021-1482
6.4 MEDIUM

A vulnerability in the web-based management interface of Cisco&nbsp;SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization checking and gain access to …

Nov 15, 2024
CVE-2021-1481
4.3 MEDIUM

A vulnerability in the web-based management interface of Cisco&nbsp;SD-WAN vManage Software could allow an authenticated, remote attacker to conduct Cypher query language injection attacks on …

Nov 15, 2024
CVE-2021-1470
4.9 MEDIUM

A vulnerability in the web-based management interface of Cisco&nbsp;SD-WAN vManage Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected …

Nov 15, 2024
CVE-2021-1466
5.4 MEDIUM

A vulnerability in the vDaemon service of Cisco&nbsp;SD-WAN vManage Software could allow an authenticated, local attacker to cause a buffer overflow on an affected system, …

Nov 15, 2024
CVE-2021-1464
5.0 MEDIUM

A vulnerability in Cisco&nbsp;SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization checking and gain restricted access to the configuration information of …

Nov 15, 2024
CVE-2024-52555
6.3 MEDIUM

In JetBrains WebStorm before 2024.3 code execution in Untrusted Project mode was possible via type definitions installer script

Nov 15, 2024
CVE-2024-52526
4.8 MEDIUM

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Services" tab of the Device page allows authenticated users …

Nov 15, 2024
CVE-2024-51497
4.8 MEDIUM

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Custom OID" tab of a device allows authenticated users …

Nov 15, 2024
CVE-2024-51496
4.8 MEDIUM

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Reflected Cross-Site Scripting (XSS) vulnerability in the "metric" parameter of the "/wireless" and "/health" endpoints allows …

Nov 15, 2024
CVE-2024-51495
4.8 MEDIUM

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the Device Overview page allows authenticated users to inject arbitrary …

Nov 15, 2024
CVE-2024-51494
4.8 MEDIUM

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Port Settings" page allows authenticated users to inject arbitrary …

Nov 15, 2024
CVE-2024-50652
4.3 MEDIUM

A file upload vulnerability in java_shop 1.0 allows attackers to upload arbitrary files by modifying the avatar function.

Nov 15, 2024
CVE-2024-50651
6.5 MEDIUM

java_shop 1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of users with different IDs by modifying the ID parameter.

Nov 15, 2024
CVE-2024-50355
4.8 MEDIUM

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. User with Admin role can edit the Display Name of a device, the application did not properly …

Nov 15, 2024
CVE-2024-50352
4.8 MEDIUM

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Services" section of the Device Overview page allows authenticated …

Nov 15, 2024
CVE-2024-50351
4.8 MEDIUM

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Reflected Cross-Site Scripting (XSS) vulnerability in the "section" parameter of the "logs" tab of a device …

Nov 15, 2024
CVE-2024-50350
4.8 MEDIUM

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Port Settings" page allows authenticated users to inject arbitrary …

Nov 15, 2024
CVE-2024-49764
4.8 MEDIUM

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Capture Debug Information" page allows authenticated users to inject …

Nov 15, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.