CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-48941
5.4 MEDIUM

The Syracom Secure Login (2FA) plugin for Jira, Confluence, and Bitbucket through 3.1.4.5 allows remote attackers to bypass 2FA by interacting with the /rest endpoint …

Oct 10, 2024
CVE-2024-8264
5.5 MEDIUM

Fortra's Robot Schedule Enterprise Agent prior to version 3.05 writes FTP username and password information to the agent log file when detailed logging is enabled.

Oct 9, 2024
CVE-2024-48933
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in LemonLDAP::NG before 2.19.3 allows remote attackers to inject arbitrary web script or HTML into the login page via a …

Oct 9, 2024
CVE-2024-7041
6.5 MEDIUM

An Insecure Direct Object Reference (IDOR) vulnerability exists in open-webui/open-webui version v0.3.8. The vulnerability occurs in the API endpoint `http://0.0.0.0:3000/api/v1/memories/{id}/update`, where the decentralization design is …

Oct 9, 2024
CVE-2024-38818
6.7 MEDIUM

VMware NSX contains a local privilege escalation vulnerability. An authenticated malicious actor may exploit this vulnerability to obtain permissions from a separate group role than …

Oct 9, 2024
CVE-2024-38817
6.7 MEDIUM

VMware NSX contains a command injection vulnerability. A malicious actor with access to the NSX Edge CLI terminal may be able to craft malicious payloads …

Oct 9, 2024
CVE-2024-38815
4.3 MEDIUM

VMware NSX contains a content spoofing vulnerability. An unauthenticated malicious actor may be able to craft a URL and redirect a victim to an attacker …

Oct 9, 2024
CVE-2024-47833
6.5 MEDIUM

Taipy is an open-source Python library for easy, end-to-end application development for data scientists and machine learning engineers. In affected versions session cookies are served …

Oct 9, 2024
CVE-2024-47828
5.3 MEDIUM

ampache is a web based audio/video streaming application and file manager. A CSRF attack can be performed in order to delete objects (Playlist, smartlist etc.). …

Oct 9, 2024
CVE-2024-47816
6.4 MEDIUM

ImportDump is a mediawiki extension designed to automate user import requests. A user's local actor ID is stored in the database to tell who made …

Oct 9, 2024
CVE-2024-47815
6.0 MEDIUM

IncidentReporting is a MediaWiki extension for moving incident reports from wikitext to database tables. There are a variety of Cross-site Scripting issues, though all of …

Oct 9, 2024
CVE-2024-47812
6.0 MEDIUM

ImportDump is an extension for mediawiki designed to automate user import requests. Anyone who can edit the interface strings of a wiki (typically administrators and …

Oct 9, 2024
CVE-2024-47763
5.5 MEDIUM

Wasmtime is an open source runtime for WebAssembly. Wasmtime's implementation of WebAssembly tail calls combined with stack traces can result in a runtime crash in …

Oct 9, 2024
CVE-2024-9471
4.7 MEDIUM

A privilege escalation (PE) vulnerability in the XML API of Palo Alto Networks PAN-OS software enables an authenticated PAN-OS administrator with restricted privileges to use …

Oct 9, 2024
CVE-2024-9469
5.5 MEDIUM

A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows non-administrative privileges to …

Oct 9, 2024
CVE-2024-9467
6.1 MEDIUM

A reflected XSS vulnerability in Palo Alto Networks Expedition enables execution of malicious JavaScript in the context of an authenticated Expedition user's browser if that …

Oct 9, 2024
CVE-2024-9466
6.5 MEDIUM

A cleartext storage of sensitive information vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to reveal firewall usernames, passwords, and API keys generated …

Oct 9, 2024
CVE-2024-9464
6.5 MEDIUM

An OS command injection vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to run arbitrary OS commands as root in Expedition, resulting in …

Oct 9, 2024
CVE-2024-42988
4.3 MEDIUM

Lack of access control in ChallengeSolves (/api/v1/challenges/<challenge id>/solves) of CTFd v2.0.0 - v3.7.2 allows authenticated users to retrieve a list of users who have solved …

Oct 9, 2024
CVE-2024-9671
5.3 MEDIUM

A vulnerability was found in 3Scale. There is no auth mechanism to see a PDF invoice of a Developer user if the URL is known. …

Oct 9, 2024
CVE-2024-47673
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: pause TCM when the firmware is stopped Not doing so will make …

Oct 9, 2024
CVE-2024-47671
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: USB: usbtmc: prevent kernel-usb-infoleak The syzbot reported a kernel-usb-infoleak in usbtmc_write, we need to clear …

Oct 9, 2024
CVE-2024-47669
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix state management in error path of log writing function After commit a694291a6211 ("nilfs2: …

Oct 9, 2024
CVE-2024-47668
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: lib/generic-radix-tree.c: Fix rare race in __genradix_ptr_alloc() If we need to increase the tree depth, allocate …

Oct 9, 2024
CVE-2024-47667
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: PCI: keystone: Add workaround for Errata #i2037 (AM65x SR 1.0) Errata #i2037 in AM65x/DRA80xM Processors …

Oct 9, 2024
CVE-2024-47666
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: pm80xx: Set phy->enable_completion only when we wait for it pm8001_phy_control() populates the enable_completion pointer …

Oct 9, 2024
CVE-2024-47665
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: i3c: mipi-i3c-hci: Error out instead on BUG_ON() in IBI DMA setup Definitely condition dma_get_cache_alignment * …

Oct 9, 2024
CVE-2024-47664
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: spi: hisi-kunpeng: Add verification for the max_frequency provided by the firmware If the value of …

Oct 9, 2024
CVE-2024-47663
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: staging: iio: frequency: ad9834: Validate frequency parameter value In ad9834_write_frequency() clk_get_rate() can return 0. In …

Oct 9, 2024
CVE-2024-47662
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Remove register from DCN35 DMCUB diagnostic collection [Why] These registers should not be read …

Oct 9, 2024
CVE-2024-47661
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Avoid overflow from uint32_t to uint8_t [WHAT & HOW] dmub_rb_cmd's ramping_boundary has size of …

Oct 9, 2024
CVE-2024-47660
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fsnotify: clear PARENT_WATCHED flags lazily In some setups directories can have many (usually negative) dentries. …

Oct 9, 2024
CVE-2024-47658
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: crypto: stm32/cryp - call finalize with bh disabled The finalize operation in interrupt mode produce …

Oct 9, 2024
CVE-2024-46870
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Disable DMCUB timeout for DCN35 [Why] DMCUB can intermittently take longer than expected to …

Oct 9, 2024
CVE-2024-46237
5.4 MEDIUM

PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) via the patname, pataddress, and medhis parameters in doctor/add-patient.php and doctor/edit-patient.php.

Oct 9, 2024
CVE-2024-47420
5.5 MEDIUM

Animate versions 23.0.7, 24.0.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage …

Oct 9, 2024
CVE-2024-47419
5.5 MEDIUM

Animate versions 23.0.7, 24.0.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage …

Oct 9, 2024
CVE-2024-45145
5.5 MEDIUM

Lightroom Desktop versions 7.4.1, 13.5, 12.5.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker …

Oct 9, 2024
CVE-2024-20787
5.5 MEDIUM

Substance3D - Painter versions 10.0.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Oct 9, 2024
CVE-2024-9451
6.4 MEDIUM

The Embed PDF Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'height' and 'width' parameters in all versions up to, and …

Oct 9, 2024
CVE-2024-9449
6.4 MEDIUM

The Auto iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' parameter in all versions up to, and including, 1.7 due …

Oct 9, 2024
CVE-2024-39440
6.2 MEDIUM

In DRM service, there is a possible system crash due to null pointer dereference. This could lead to local denial of service with System execution …

Oct 9, 2024
CVE-2024-39439
6.2 MEDIUM

In DRM service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Oct 9, 2024
CVE-2024-39438
6.5 MEDIUM

In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution …

Oct 9, 2024
CVE-2024-39437
6.5 MEDIUM

In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution …

Oct 9, 2024
CVE-2024-39436
6.5 MEDIUM

In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution …

Oct 9, 2024
CVE-2024-5968
4.8 MEDIUM

The Photo Gallery by 10Web WordPress plugin before 1.8.28 does not properly sanitise and escape some of its Gallery settings, which could allow high privilege …

Oct 9, 2024
CVE-2023-45872
6.5 MEDIUM

An issue was discovered in Qt before 6.2.11 and 6.3.x through 6.6.x before 6.6.1. When a QML image refers to an image whose content is …

Oct 9, 2024
CVE-2023-45361
6.1 MEDIUM

An issue was discovered in VectorComponentUserLinks.php in the Vector Skin component in MediaWiki before 1.39.5 and 1.40.x before 1.40.1. vector-intro-page MalformedTitleException is uncaught if it …

Oct 9, 2024
CVE-2023-45359
6.5 MEDIUM

An issue was discovered in the Vector Skin component for MediaWiki before 1.39.5 and 1.40.x before 1.40.1. vector-toc-toggle-button-label is not escaped, but should be, because …

Oct 9, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.