CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-51565
6.5 MEDIUM

The hda driver is vulnerable to a buffer over-read from a guest-controlled value.

Nov 12, 2024
CVE-2024-51563
6.5 MEDIUM

The virtio_vq_recordon function is subject to a time-of-check to time-of-use (TOCTOU) race condition.

Nov 12, 2024
CVE-2024-51562
6.5 MEDIUM

The NVMe driver function nvme_opc_get_log_page is vulnerable to a buffer over-read from a guest-controlled value.

Nov 12, 2024
CVE-2024-39281
5.3 MEDIUM

The command ctl_persistent_reserve_out allows the caller to specify an arbitrary size which will be passed to the kernel's memory allocator.

Nov 12, 2024
CVE-2024-33660
4.3 MEDIUM

An exploit is possible where an actor with physical access can manipulate SPI flash without being detected.

Nov 12, 2024
CVE-2024-11127
6.3 MEDIUM

A vulnerability was found in code-projects Job Recruitment up to 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Nov 12, 2024
CVE-2024-11125
4.3 MEDIUM

A vulnerability was found in GetSimpleCMS 3.3.16 and classified as problematic. This issue affects some unknown processing of the file /admin/profile.php. The manipulation leads to …

Nov 12, 2024
CVE-2024-11124
4.7 MEDIUM

A vulnerability has been found in TimGeyssens UIOMatic 5 and classified as critical. This vulnerability affects unknown code of the file /src/UIOMatic/wwwroot/backoffice/resources/uioMaticObject.r. The manipulation leads …

Nov 12, 2024
CVE-2024-50561
4.3 MEDIUM

A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V8.2), SCALANCE …

Nov 12, 2024
CVE-2024-50559
4.3 MEDIUM

A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V8.2), SCALANCE …

Nov 12, 2024
CVE-2024-50558
4.3 MEDIUM

A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V8.2), SCALANCE …

Nov 12, 2024
CVE-2024-50313
5.3 MEDIUM

A vulnerability has been identified in Mendix Runtime V10 (All versions < V10.16.0 only if the basic authentication mechanism is used by the application), Mendix …

Nov 12, 2024
CVE-2024-46894
6.3 MEDIUM

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly validate authorization of a …

Nov 12, 2024
CVE-2024-46892
4.9 MEDIUM

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly invalidate sessions when the …

Nov 12, 2024
CVE-2024-46891
5.3 MEDIUM

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly restrict the size of …

Nov 12, 2024
CVE-2024-46889
5.3 MEDIUM

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application uses hard-coded cryptographic key material to obfuscate …

Nov 12, 2024
CVE-2024-36140
6.8 MEDIUM

A vulnerability has been identified in OZW672 (All versions < V5.2), OZW772 (All versions < V5.2). The user accounts tab of affected devices is vulnerable …

Nov 12, 2024
CVE-2024-11123
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in 上海灵当信息科技有限公司 Lingdang CRM up to 8.6.4.3. This affects an unknown part of the file /crm/data/pdf.php. …

Nov 12, 2024
CVE-2024-11122
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in 上海灵当信息科技有限公司 Lingdang CRM up to 8.6.4.3. Affected by this issue is some unknown functionality …

Nov 12, 2024
CVE-2024-11121
6.3 MEDIUM

A vulnerability classified as critical was found in 上海灵当信息科技有限公司 Lingdang CRM up to 8.6.4.3. Affected by this vulnerability is an unknown functionality of the file …

Nov 12, 2024
CVE-2024-10323
6.4 MEDIUM

The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and …

Nov 12, 2024
CVE-2024-10179
6.4 MEDIUM

The Slickstream: Engagement and Conversions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's slick-grid shortcode in all versions up to, and …

Nov 12, 2024
CVE-2024-9836
5.9 MEDIUM

The RSS Feed Widget WordPress plugin before 3.0.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post …

Nov 12, 2024
CVE-2024-9835
4.8 MEDIUM

The RSS Feed Widget WordPress plugin before 3.0.1 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to …

Nov 12, 2024
CVE-2024-9357
6.1 MEDIUM

The xili-tidy-tags plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'action' parameter in all versions up to, and including, 1.12.04 due to …

Nov 12, 2024
CVE-2024-29075
4.6 MEDIUM

Active debug code vulnerability exists in Mesh Wi-Fi router RP562B firmware version v1.0.2 and earlier. If this vulnerability is exploited, a network-adjacent authenticated attacker may …

Nov 12, 2024
CVE-2024-10790
5.4 MEDIUM

The Admin and Site Enhancements (ASE) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and …

Nov 12, 2024
CVE-2024-11101
4.7 MEDIUM

A vulnerability was found in 1000 Projects Beauty Parlour Management System 1.0. It has been classified as critical. Affected is an unknown function of the …

Nov 12, 2024
CVE-2024-10695
4.3 MEDIUM

The Futurio Extra plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.0.13 via the 'elementor-template' shortcode due to …

Nov 12, 2024
CVE-2024-10685
6.1 MEDIUM

The Contact Form 7 Redirect & Thank You Page plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions …

Nov 12, 2024
CVE-2024-10538
6.4 MEDIUM

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the before_label parameter in the Image Comparison widget in all …

Nov 12, 2024
CVE-2024-49395
5.3 MEDIUM

In mutt and neomutt, PGP encryption does not use the --hidden-recipient mode which may leak the Bcc email header field by inferring from the recipients …

Nov 12, 2024
CVE-2024-49394
5.3 MEDIUM

In mutt and neomutt the In-Reply-To email header field is not protected by cryptographic signing which allows an attacker to reuse an unencrypted but signed …

Nov 12, 2024
CVE-2024-8882
4.5 MEDIUM

A buffer overflow vulnerability in the CGI program in the Zyxel GS1900-48 switch firmware version V2.80(AAHN.1)C0 and earlier could allow an authenticated, LAN-based attacker with …

Nov 12, 2024
CVE-2024-8881
6.8 MEDIUM

A post-authentication command injection vulnerability in the CGI program in the Zyxel GS1900-48 switch firmware version V2.80(AAHN.1)C0 and earlier could allow an authenticated, LAN-based attacker …

Nov 12, 2024
CVE-2024-49393
6.5 MEDIUM

In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercepts a message to …

Nov 12, 2024
CVE-2024-47595
6.3 MEDIUM

An attacker who gains local membership to sapsys group could replace local files usually protected by privileged access. On successful exploitation the attacker could cause …

Nov 12, 2024
CVE-2024-47593
4.3 MEDIUM

SAP NetWeaver Application Server ABAP allows an unauthenticated attacker with network access to read files from the server, which otherwise would be restricted.This attack is …

Nov 12, 2024
CVE-2024-47592
5.3 MEDIUM

SAP NetWeaver AS Java allows an unauthenticated attacker to brute force the login functionality in order to identify the legitimate user IDs. This has an …

Nov 12, 2024
CVE-2024-47588
4.7 MEDIUM

In SAP NetWeaver Java (Software Update Manager 1.1), under certain conditions when a software upgrade encounters errors, credentials are written in plaintext to a log …

Nov 12, 2024
CVE-2024-47586
5.3 MEDIUM

SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated attacker to send a maliciously crafted http request which could cause a null …

Nov 12, 2024
CVE-2024-42372
6.5 MEDIUM

Due to missing authorization check in SAP NetWeaver AS Java (System Landscape Directory) an unauthorized user can read and modify some restricted global SLD configurations …

Nov 12, 2024
CVE-2024-11096
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in code-projects Task Manager 1.0. This affects an unknown part of the file /newProject.php. The manipulation …

Nov 12, 2024
CVE-2024-11079
5.5 MEDIUM

A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. …

Nov 12, 2024
CVE-2024-51213
6.1 MEDIUM

Cross Site Scripting vulnerability in Online Shop Store v.1.0 allows a remote attacker to execute arbitrary code via the login.php component.

Nov 11, 2024
CVE-2024-50601
6.1 MEDIUM

Persistent and reflected XSS vulnerabilities in the themeMode cookie and _h URL parameter of Axigen Mail Server up to version 10.5.28 allow attackers to execute …

Nov 11, 2024
CVE-2024-51026
5.4 MEDIUM

The NetAdmin IAM system (version 4.0.30319) has a Cross Site Scripting (XSS) vulnerability in the /BalloonSave.ashx endpoint, where it is possible to inject a malicious …

Nov 11, 2024
CVE-2024-52531
6.5 MEDIUM

GNOME libsoup before 3.6.1 allows a buffer overflow in applications that perform conversion to UTF-8 in soup_header_parse_param_list_strict. There is a plausible way to reach this …

Nov 11, 2024
CVE-2024-52288
5.1 MEDIUM

libosdp is an implementation of IEC 60839-11-5 OSDP (Open Supervised Device Protocol) and provides a C library with support for C++, Rust and Python3. In …

Nov 11, 2024
CVE-2024-51992
4.1 MEDIUM

Orchid is a @laravel package that allows for rapid application development of back-office applications, admin/user panels, and dashboards. This vulnerability is a method exposure issue …

Nov 11, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.