CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-51677
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ajay Knowledge Base knowledgebase allows Stored XSS.This issue affects Knowledge Base: from n/a …

Nov 4, 2024
CVE-2024-51665
4.9 MEDIUM

Server-Side Request Forgery (SSRF) vulnerability in Noor Alam Magical Addons For Elementor magical-addons-for-elementor allows Server Side Request Forgery.This issue affects Magical Addons For Elementor: from …

Nov 4, 2024
CVE-2024-9147
6.1 MEDIUM

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Bna Informatics PosPratik allows XSS Through HTTP Query Strings.This issue affects …

Nov 4, 2024
CVE-2024-51560
4.3 MEDIUM

This vulnerability exists in the Wave 2.0 due to improper exception handling for invalid inputs at certain API endpoint. An authenticated remote attacker could exploit …

Nov 4, 2024
CVE-2024-51559
6.5 MEDIUM

This vulnerability exists in the Wave 2.0 due to improper authorization checks on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by …

Nov 4, 2024
CVE-2024-51557
6.5 MEDIUM

This vulnerability exists in the Wave 2.0 due to missing rate limiting on OTP requests in an API endpoint. An authenticated remote attacker could exploit …

Nov 4, 2024
CVE-2024-51556
6.5 MEDIUM

This vulnerability exists in the Wave 2.0 due to insufficient encryption of sensitive data received at the API response. An authenticated remote attacker could exploit …

Nov 4, 2024
CVE-2024-10523
4.6 MEDIUM

This vulnerability exists in TP-Link IoT Smart Hub due to storage of Wi-Fi credentials in plain text within the device firmware. An attacker with physical …

Nov 4, 2024
CVE-2024-33033
6.7 MEDIUM

Memory corruption while processing IOCTL calls to unmap the buffers.

Nov 4, 2024
CVE-2024-33032
6.7 MEDIUM

Memory corruption when the user application modifies the same shared memory asynchronously when kernel is accessing it.

Nov 4, 2024
CVE-2024-33031
6.7 MEDIUM

Memory corruption while processing the update SIM PB records request.

Nov 4, 2024
CVE-2024-33030
6.7 MEDIUM

Memory corruption while parsing IPC frequency table parameters for LPLH that has size greater than expected size.

Nov 4, 2024
CVE-2024-33029
6.7 MEDIUM

Memory corruption while handling the PDR in driver for getting the remote heap maps.

Nov 4, 2024
CVE-2024-23386
6.7 MEDIUM

memory corruption when WiFi display APIs are invoked with large random inputs.

Nov 4, 2024
CVE-2024-23377
6.7 MEDIUM

Memory corruption while invoking IOCTL command from user-space, when a user modifies the original packet size of the command after system properties have been already …

Nov 4, 2024
CVE-2024-10761
4.3 MEDIUM

A vulnerability was found in Umbraco CMS up to 10.7.7/12.3.6/13.5.2/14.3.1/15.1.1. It has been classified as problematic. Affected is an unknown function of the file /Umbraco/preview/frame?id{} …

Nov 4, 2024
CVE-2024-10760
6.3 MEDIUM

A vulnerability was found in code-projects University Event Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /dodelete.php. …

Nov 4, 2024
CVE-2024-10759
6.3 MEDIUM

A vulnerability has been found in itsourcecode Farm Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /edit-pig.php. The …

Nov 4, 2024
CVE-2024-20124
4.4 MEDIUM

In vdec, there is a possible out of bounds read due to improper structure design. This could lead to local information disclosure with System execution …

Nov 4, 2024
CVE-2024-20123
4.4 MEDIUM

In vdec, there is a possible out of bounds read due to improper structure design. This could lead to local information disclosure with System execution …

Nov 4, 2024
CVE-2024-20122
4.4 MEDIUM

In vdec, there is a possible out of bounds read due to improper structure design. This could lead to local information disclosure with System execution …

Nov 4, 2024
CVE-2024-20121
6.7 MEDIUM

In KeyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Nov 4, 2024
CVE-2024-20120
6.7 MEDIUM

In KeyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Nov 4, 2024
CVE-2024-20119
6.7 MEDIUM

In mms, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with …

Nov 4, 2024
CVE-2024-20118
6.7 MEDIUM

In mms, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with …

Nov 4, 2024
CVE-2024-20117
4.4 MEDIUM

In vdec, there is a possible out of bounds read due to improper structure design. This could lead to local information disclosure with System execution …

Nov 4, 2024
CVE-2024-20115
6.7 MEDIUM

In ccu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Nov 4, 2024
CVE-2024-20114
6.7 MEDIUM

In ccu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Nov 4, 2024
CVE-2024-20113
6.7 MEDIUM

In ccu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Nov 4, 2024
CVE-2024-20112
4.4 MEDIUM

In isp, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with …

Nov 4, 2024
CVE-2024-20111
6.7 MEDIUM

In ccu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Nov 4, 2024
CVE-2024-20110
6.7 MEDIUM

In ccu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Nov 4, 2024
CVE-2024-20109
6.7 MEDIUM

In ccu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Nov 4, 2024
CVE-2024-20108
6.7 MEDIUM

In atci, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Nov 4, 2024
CVE-2024-20107
6.2 MEDIUM

In da, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no …

Nov 4, 2024
CVE-2024-20106
6.7 MEDIUM

In m4u, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Nov 4, 2024
CVE-2024-10751
6.3 MEDIUM

A vulnerability was found in Codezips ISP Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Nov 4, 2024
CVE-2024-10750
6.5 MEDIUM

A vulnerability has been found in Tenda i22 1.0.0.3(4687) and classified as problematic. Affected by this vulnerability is the function websReadEvent of the file /goform/GetIPTV?fgHPOST/goform/SysToo. …

Nov 4, 2024
CVE-2024-10749
5.0 MEDIUM

A vulnerability, which was classified as critical, was found in ThinkAdmin up to 6.1.67. Affected is the function script of the file /app/admin/controller/api/Plugs.php. The manipulation …

Nov 4, 2024
CVE-2024-10742
6.3 MEDIUM

A vulnerability was found in code-projects Wazifa System 1.0 and classified as critical. This issue affects some unknown processing of the file /controllers/control.php. The manipulation …

Nov 3, 2024
CVE-2024-10740
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in code-projects E-Health Care System up to 1.0. This affects an unknown part of the file …

Nov 3, 2024
CVE-2024-10738
6.3 MEDIUM

A vulnerability classified as critical was found in itsourcecode Farm Management System 1.0. Affected by this vulnerability is an unknown functionality of the file manage-breed.php. …

Nov 3, 2024
CVE-2024-10735
6.3 MEDIUM

A vulnerability was found in Project Worlds Life Insurance Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the …

Nov 3, 2024
CVE-2024-10734
6.3 MEDIUM

A vulnerability was found in Project Worlds Life Insurance Management System 1.0. It has been classified as critical. This affects an unknown part of the …

Nov 3, 2024
CVE-2024-10732
6.3 MEDIUM

A vulnerability has been found in Tongda OA 2017 up to 11.10 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Nov 3, 2024
CVE-2024-10731
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Tongda OA up to 11.10. Affected is an unknown function of the file /pda/appcenter/check_seal.php. The …

Nov 3, 2024
CVE-2024-10730
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Tongda OA up to 11.6. This issue affects some unknown processing of the file …

Nov 3, 2024
CVE-2024-10700
6.3 MEDIUM

A vulnerability was found in code-projects University Event Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file …

Nov 2, 2024
CVE-2024-10697
6.3 MEDIUM

A vulnerability has been found in Tenda AC6 15.03.05.19 and classified as critical. Affected by this vulnerability is the function formWriteFacMac of the file /goform/WriteFacMac …

Nov 2, 2024
CVE-2024-9896
6.1 MEDIUM

The BBP Core – Expand bbPress powered forums with useful features plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of …

Nov 2, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.