CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-47972
4.0 MEDIUM

Improper resource management in firmware of some Solidigm DC Products may allow an attacker to potentially control the performance of the resource.

Oct 7, 2024
CVE-2024-47971
6.5 MEDIUM

Improper error handling in firmware of some SSD DC Products may allow an attacker to enable denial of service.

Oct 7, 2024
CVE-2024-47079
6.4 MEDIUM

Meshtastic is an open source, off-grid, decentralized, mesh network built to run on affordable, low-power devices. Meshtastic firmware is an open source firmware implementation for …

Oct 7, 2024
CVE-2024-45292
5.4 MEDIUM

PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. `\PhpOffice\PhpSpreadsheet\Writer\Html` does not sanitize "javascript:" URLs from hyperlink `href` attributes, resulting in a …

Oct 7, 2024
CVE-2024-31228
5.5 MEDIUM

Redis is an open source, in-memory database that persists on disk. Authenticated users can trigger a denial-of-service by using specially crafted, long string match patterns …

Oct 7, 2024
CVE-2024-31227
4.4 MEDIUM

Redis is an open source, in-memory database that persists on disk. An authenticated with sufficient privileges may create a malformed ACL selector which, when accessed, …

Oct 7, 2024
CVE-2024-45894
4.9 MEDIUM

BlueCMS 1.6 suffers from Arbitrary File Deletion via the file_name parameter in an /admin/database.php?act=del request.

Oct 7, 2024
CVE-2024-44674
5.7 MEDIUM

D-Link COVR-2600R FW101b05 is vulnerable to Buffer Overflow. In the function sub_24E28, the HTTP_REFERER is obtained through an environment variable, and this field is controllable, …

Oct 7, 2024
CVE-2024-42831
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in Elaine's Realtime CRM Automation v6.18.17 allows attackers to execute arbitrary JavaScript code in the web browser of a …

Oct 7, 2024
CVE-2024-46300
6.1 MEDIUM

itsourcecode Placement Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Full Name field in registration.php.

Oct 7, 2024
CVE-2024-46040
6.5 MEDIUM

IoT Haat Smart Plug IH-IN-16A-S IH-IN-16A-S v5.16.1 suffers from Insufficient Session Expiration. The lack of validation of the authentication token at the IoT Haat during …

Oct 7, 2024
CVE-2024-45932
4.8 MEDIUM

Krayin CRM v1.3.0 is vulnerable to Cross Site Scripting (XSS) via the organization name field in /admin/contacts/organizations/edit/2.

Oct 7, 2024
CVE-2024-28710
6.1 MEDIUM

Cross Site Scripting vulnerability in LimeSurvey before 6.5.0+240319 allows a remote attacker to execute arbitrary code via a lack of input validation and output encoding …

Oct 7, 2024
CVE-2024-28709
6.1 MEDIUM

Cross Site Scripting vulnerability in LimeSurvey before 6.5.12+240611 allows a remote attacker to execute arbitrary code via a crafted script to the title and comment …

Oct 7, 2024
CVE-2024-9573
6.3 MEDIUM

SQL injection vulnerability in SOPlanning <1.45, through /soplanning/www/groupe_list.php, in the by parameter, which could allow a remote user to send a specially crafted query and …

Oct 7, 2024
CVE-2024-9572
6.3 MEDIUM

Cross-Site Scripting (XSS) vulnerability in SOPlanning <1.45, due to lack of proper validation of user input via /soplanning/www/process/groupe_save.php, in the groupe_id parameter. This could allow …

Oct 7, 2024
CVE-2024-9571
6.3 MEDIUM

Cross-Site Scripting (XSS) vulnerability in SOPlanning <1.45, due to lack of proper validation of user input via /soplanning/www/process/xajax_server.php, affecting multiple parameters. This could allow a …

Oct 7, 2024
CVE-2024-45933
6.6 MEDIUM

OnlineNewsSite v1.0 is vulnerable to Cross Site Scripting (XSS) which allows attackers to execute arbitrary code via the Title and summary fields in the /admin/post/edit/ …

Oct 7, 2024
CVE-2024-46325
5.5 MEDIUM

TP-Link WR740N V6 has a stack overflow vulnerability via the ssid parameter in /userRpm/popupSiteSurveyRpm.htm url.

Oct 7, 2024
CVE-2024-45153
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to …

Oct 7, 2024
CVE-2024-42027
6.7 MEDIUM

The E2EE password entropy generated by Rocket.Chat Mobile prior to version 4.5.1 is insufficient, allowing attackers to crack it if they have the appropriate time …

Oct 7, 2024
CVE-2024-38425
6.1 MEDIUM

Information disclosure while sending implicit broadcast containing APP launch information.

Oct 7, 2024
CVE-2024-23379
6.7 MEDIUM

Memory corruption while unmapping the fastrpc map when two threads can free the same map in concurrent scenario.

Oct 7, 2024
CVE-2024-23378
6.7 MEDIUM

Memory corruption while invoking IOCTL calls for MSM module from the user space during audio playback and record.

Oct 7, 2024
CVE-2024-23376
6.7 MEDIUM

Memory corruption while sending the persist buffer command packet from the user-space to the kernel space through the IOCTL call.

Oct 7, 2024
CVE-2024-23375
6.7 MEDIUM

Memory corruption during the network scan request.

Oct 7, 2024
CVE-2024-23374
6.7 MEDIUM

Memory corruption is possible when an attempt is made from userspace or console to write some haptics effects pattern to the haptics debugfs file.

Oct 7, 2024
CVE-2024-23370
6.7 MEDIUM

Memory corruption when a process invokes IOCTL calls from user-space to create a HAB virtual channel and another process invokes IOCTL calls to destroy the …

Oct 7, 2024
CVE-2024-47344
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Stylemix uListing ulisting.This issue affects uListing: from n/a through <= 2.1.5.

Oct 7, 2024
CVE-2024-20102
4.9 MEDIUM

In wlan driver, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure with System …

Oct 7, 2024
CVE-2024-20099
6.7 MEDIUM

In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Oct 7, 2024
CVE-2024-20098
6.7 MEDIUM

In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Oct 7, 2024
CVE-2024-20097
4.4 MEDIUM

In vdec, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System …

Oct 7, 2024
CVE-2024-20096
4.4 MEDIUM

In m4u, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System …

Oct 7, 2024
CVE-2024-20095
4.4 MEDIUM

In m4u, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System …

Oct 7, 2024
CVE-2024-20093
4.4 MEDIUM

In vdec, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System …

Oct 7, 2024
CVE-2024-20091
4.4 MEDIUM

In vdec, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System …

Oct 7, 2024
CVE-2024-20090
6.7 MEDIUM

In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Oct 7, 2024
CVE-2024-9560
6.3 MEDIUM

A vulnerability was found in ESAFENET CDG V5. It has been rated as critical. Affected by this issue is the function delCatelogs of the file …

Oct 6, 2024
CVE-2024-47650
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Axton WP-WebAuthn wp-webauthn allows Stored XSS.This issue affects WP-WebAuthn: from n/a through <= …

Oct 6, 2024
CVE-2024-45250
4.3 MEDIUM

ZKteco – CWE 200 Exposure of Sensitive Information to an Unauthorized Actor

Oct 6, 2024
CVE-2024-44040
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in plainware ShiftController Employee Shift Scheduling shiftcontroller allows Stored XSS.This issue affects ShiftController Employee …

Oct 6, 2024
CVE-2024-44039
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Travel WP Travel wp-travel allows Stored XSS.This issue affects WP Travel: from …

Oct 6, 2024
CVE-2024-44037
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in magepeopleteam Multipurpose Ticket Booking Manager bus-booking-manager allows Stored XSS.This issue affects Multipurpose Ticket …

Oct 6, 2024
CVE-2024-44036
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pierre Lebedel Kodex Posts likes kodex-posts-likes allows Stored XSS.This issue affects Kodex Posts …

Oct 6, 2024
CVE-2024-44035
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Atawai Gum Elementor Addon gum-elementor-addon allows Stored XSS.This issue affects Gum Elementor Addon: …

Oct 6, 2024
CVE-2024-44033
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nicheaddons Primary Addon for Elementor primary-addon-for-elementor allows Stored XSS.This issue affects Primary Addon …

Oct 6, 2024
CVE-2024-44032
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nicheaddons Restaurant & Cafe Addon for Elementor restaurant-cafe-addon-for-elementor allows Stored XSS.This issue affects …

Oct 6, 2024
CVE-2024-44027
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Atawai Gum Elementor Addon gum-elementor-addon allows Stored XSS.This issue affects Gum Elementor Addon: …

Oct 6, 2024
CVE-2024-44026
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nicheaddons Charity Addon for Elementor charity-addon-for-elementor allows Stored XSS.This issue affects Charity Addon …

Oct 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.