CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-47949
4.9 MEDIUM

In JetBrains TeamCity before 2024.07.3 path traversal allowed backup file write to arbitrary location

Oct 8, 2024
CVE-2024-47948
4.9 MEDIUM

In JetBrains TeamCity before 2024.07.3 path traversal leading to information disclosure was possible via server backups

Oct 8, 2024
CVE-2024-47161
4.3 MEDIUM

In JetBrains TeamCity before 2024.07.3 password could be exposed via Sonar runner REST API

Oct 8, 2024
CVE-2024-45231
5.3 MEDIUM

An issue was discovered in Django v5.1.1, v5.0.9, and v4.2.16. The django.contrib.auth.forms.PasswordResetForm class, when used in a view implementing password reset flows, allows remote attackers …

Oct 8, 2024
CVE-2024-8482
6.4 MEDIUM

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and …

Oct 8, 2024
CVE-2024-8431
4.3 MEDIUM

The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check …

Oct 8, 2024
CVE-2024-9207
6.1 MEDIUM

The BuddyPress Docs plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in …

Oct 8, 2024
CVE-2024-8488
4.4 MEDIUM

The Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Survey fields in all versions up to, and including, 4.9.7 due to …

Oct 8, 2024
CVE-2024-8629
6.1 MEDIUM

The WooCommerce Multilingual & Multicurrency with WPML plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping …

Oct 8, 2024
CVE-2024-8433
6.4 MEDIUM

The Easy Mega Menu Plugin for WordPress – ThemeHunk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘themehunk_megamenu_bg_image' parameter in all versions …

Oct 8, 2024
CVE-2024-3506
6.7 MEDIUM

A possible buffer overflow in selected cameras' drivers from XProtect Device Pack can allow an attacker with access to internal network to execute commands on …

Oct 8, 2024
CVE-2024-47565
4.3 MEDIUM

A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate that user input complies with …

Oct 8, 2024
CVE-2024-47563
5.3 MEDIUM

A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate a file path that is …

Oct 8, 2024
CVE-2024-47196
6.7 MEDIUM

A vulnerability has been identified in ModelSim (All versions < V2025.2), Questa (All versions < V2025.2). vsimk.exe in affected applications allows a specific tcl file …

Oct 8, 2024
CVE-2024-47195
6.7 MEDIUM

A vulnerability has been identified in ModelSim (All versions < V2024.3), Questa (All versions < V2024.3). gdb.exe in affected applications allows a specific executable file …

Oct 8, 2024
CVE-2024-47194
6.7 MEDIUM

A vulnerability has been identified in ModelSim (All versions < V2024.3), Questa (All versions < V2024.3). vish2.exe in affected applications allows a specific DLL file …

Oct 8, 2024
CVE-2024-46887
5.3 MEDIUM

The web server of affected devices do not properly authenticate user request to the '/ClientArea/RuntimeInfoData.mwsl' endpoint. This could allow an unauthenticated remote attacker to gain …

Oct 8, 2024
CVE-2024-46886
4.7 MEDIUM

The web server of affected devices does not properly validate input that is used for a user redirection. This could allow an attacker to make …

Oct 8, 2024
CVE-2022-4534
5.3 MEDIUM

The Limit Login Attempts (Spam Protection) plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 5.3. This is due …

Oct 8, 2024
CVE-2024-8964
6.4 MEDIUM

The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up …

Oct 8, 2024
CVE-2024-34672
5.5 MEDIUM

Improper input validation in SamsungVideoPlayer prior to versions 7.3.29.1 in Android 12, 7.3.36.1 in Android 13, and 7.3.41.230 in Android 14 allows local attackers to …

Oct 8, 2024
CVE-2024-34670
4.0 MEDIUM

Use of implicit intent for sensitive communication in Sound Assistant prior to version 6.1.0.9 allows local attackers to get sensitive information.

Oct 8, 2024
CVE-2024-34664
4.1 MEDIUM

Improper check for exception conditions in Knox Guard prior to SMR Oct-2024 Release 1 allows physical attackers to bypass Knox Guard in a multi-user environment.

Oct 8, 2024
CVE-2024-34663
5.3 MEDIUM

Integer overflow in libSEF.quram.so prior to SMR Oct-2024 Release 1 allows local attackers to write out-of-bounds memory.

Oct 8, 2024
CVE-2024-34662
6.2 MEDIUM

Improper access control in ActivityManager prior to SMR Oct-2024 Release 1 in select Android 12, 13 and SMR Sep-2024 Release 1 in select Android 14 …

Oct 8, 2024
CVE-2024-9292
6.4 MEDIUM

The Bridge Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'formforall' shortcode in versions up to, and including, 3.2.0 due to insufficient …

Oct 8, 2024
CVE-2024-9021
5.4 MEDIUM

In the process of testing the Relevanssi WordPress plugin before 4.23.1, a vulnerability was found that allows you to implement Stored XSS on behalf of …

Oct 8, 2024
CVE-2024-8983
4.8 MEDIUM

Custom Twitter Feeds WordPress plugin before 2.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Oct 8, 2024
CVE-2024-21533
6.5 MEDIUM

All versions of the package ggit are vulnerable to Arbitrary Argument Injection via the clone() API, which allows specifying the remote URL to clone and …

Oct 8, 2024
CVE-2024-47594
5.4 MEDIUM

SAP NetWeaver Enterprise Portal (KMC) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting vulnerability in KMC servlet. An attacker could craft a script …

Oct 8, 2024
CVE-2024-45282
4.3 MEDIUM

Fields which are in 'read only' state in Bank Statement Draft in Manage Bank Statements application, could be modified by MERGE method. The property of …

Oct 8, 2024
CVE-2024-45278
5.4 MEDIUM

SAP Commerce Backoffice does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. After successful exploitation, an attacker can cause limited impact …

Oct 8, 2024
CVE-2024-45277
4.3 MEDIUM

The SAP HANA Node.js client package versions from 2.0.0 before 2.21.31 is impacted by Prototype Pollution vulnerability allowing an attacker to add arbitrary properties to …

Oct 8, 2024
CVE-2024-39831
4.4 MEDIUM

in OpenHarmony v4.1.0 allow a local attacker with high privileges arbitrary code execution in pre-installed apps through use after free.

Oct 8, 2024
CVE-2024-39806
5.5 MEDIUM

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.

Oct 8, 2024
CVE-2024-47969
6.2 MEDIUM

Improper resource management in firmware of some Solidigm DC Products may allow an attacker to potentially enable denial of service.

Oct 7, 2024
CVE-2024-47968
4.4 MEDIUM

Improper resource shutdown in middle of certain operations on some Solidigm DC Products may allow an attacker to potentially enable denial of service.

Oct 7, 2024
CVE-2024-47818
6.5 MEDIUM

Saltcorn is an extensible, open source, no-code database application builder. A logged-in user with any role can delete arbitrary files on the filesystem by calling …

Oct 7, 2024
CVE-2024-47817
6.1 MEDIUM

Lara-zeus Dynamic Dashboard simple way to manage widgets for your website landing page, and filament dashboard and Lara-zeus artemis is a collection of themes for …

Oct 7, 2024
CVE-2024-47781
6.1 MEDIUM

CreateWiki is an extension used at Miraheze for requesting & creating wikis. The name of requested wikis is not escaped on Special:RequestWikiQueue, so a user …

Oct 7, 2024
CVE-2024-47974
4.4 MEDIUM

Race condition during resource shutdown in some Solidigm DC Products may allow an attacker to potentially enable denial of service.

Oct 7, 2024
CVE-2024-47973
5.1 MEDIUM

In some Solidigm DC Products, a defect in device overprovisioning may provide information disclosure to an attacker.

Oct 7, 2024
CVE-2024-47967
4.4 MEDIUM

Improper resource initialization handling in firmware of some Solidigm DC Products may allow an attacker to potentially enable denial of service.

Oct 7, 2024
CVE-2024-47772
6.5 MEDIUM

Discourse is an open source platform for community discussion. An attacker can execute arbitrary JavaScript on users' browsers by sending a maliciously crafted chat message …

Oct 7, 2024
CVE-2024-45919
6.5 MEDIUM

A security flaw has been discovered in Solvait version 24.4.2 that allows an attacker to elevate their privileges. By manipulating the Request ID and Action …

Oct 7, 2024
CVE-2024-45297
5.3 MEDIUM

Discourse is an open source platform for community discussion. Users can see topics with a hidden tag if they know the label/name of that tag. …

Oct 7, 2024
CVE-2024-45291
6.3 MEDIUM

PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. It's possible for an attacker to construct an XLSX file that links images …

Oct 7, 2024
CVE-2024-43365
5.7 MEDIUM

Cacti is an open source performance and fault management framework. The`consolenewsection` parameter is not properly sanitized when saving external links in links.php . Morever, the …

Oct 7, 2024
CVE-2024-43364
5.7 MEDIUM

Cacti is an open source performance and fault management framework. The `title` parameter is not properly sanitized when saving external links in links.php . Morever, …

Oct 7, 2024
CVE-2024-47976
6.7 MEDIUM

Improper access removal handling in firmware of some Solidigm DC Products may allow an attacker with physical access to gain unauthorized access.

Oct 7, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.