CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-45871
6.3 MEDIUM

Bandisoft BandiView 7.05 is Incorrect Access Control via sub_0x232bd8 resulting in denial of service (DOS).

Oct 3, 2024
CVE-2024-45870
6.5 MEDIUM

Bandisoft BandiView 7.05 is vulnerable to Incorrect Access Control in sub_0x3d80fc via a crafted POC file.

Oct 3, 2024
CVE-2024-9100
6.5 MEDIUM

Zohocorp ManageEngine Analytics Plus versions before 5410 and Zoho Analytics On-Premise versions before 5410 are vulnerable to Path traversal.

Oct 3, 2024
CVE-2024-47618
5.4 MEDIUM

Sulu is a PHP content management system. Sulu is vulnerable against XSS whereas a low privileged user with access to the “Media” section can upload …

Oct 3, 2024
CVE-2024-47617
6.1 MEDIUM

Sulu is a PHP content management system. This vulnerability allows an attacker to inject arbitrary HTML/JavaScript code through the media download URL in Sulu CMS. …

Oct 3, 2024
CVE-2024-47554
4.3 MEDIUM

Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input. This issue affects Apache …

Oct 3, 2024
CVE-2024-42504
4.3 MEDIUM

A security vulnerability in HPE IceWall Agent products could be exploited remotely to cause a Cross-Site Request Forgery (CSRF) in the login flow.

Oct 3, 2024
CVE-2024-8159
6.4 MEDIUM

Deep Freeze 9.00.020.5760 is vulnerable to an out-of-bounds read vulnerability by triggering the 0x70014 IOCTL code of the FarDisk.sys driver.

Oct 3, 2024
CVE-2024-47616
6.8 MEDIUM

Pomerium is an identity and context-aware access proxy. The Pomerium databroker service is responsible for managing all persistent Pomerium application state. Requests to the databroker …

Oct 2, 2024
CVE-2024-47529
6.5 MEDIUM

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. OpenC3 COSMOS stores the password of …

Oct 2, 2024
CVE-2024-46977
6.5 MEDIUM

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. A path traversal vulnerability inside of …

Oct 2, 2024
CVE-2024-45965
6.4 MEDIUM

Contao before 5.5.6 allows XSS via an SVG document. This affects (in contao/core-bundle in Composer) 4.x before 4.13.54, 5.0.x through 5.3.x before 5.3.30, and 5.4.x …

Oct 2, 2024
CVE-2024-45964
4.8 MEDIUM

Zenario 9.7.61188 is vulnerable to Cross Site Scripting (XSS) in the Image library via the "Organizer tags" field.

Oct 2, 2024
CVE-2024-45962
4.7 MEDIUM

October 3.6.30 allows an authenticated admin account to upload a PDF file containing malicious JavaScript into the target system. If the file is accessed through …

Oct 2, 2024
CVE-2024-45960
4.8 MEDIUM

Zenario 9.7.61188 allows authenticated admin users to upload PDF files containing malicious code into the target system. If the PDF file is accessed through the …

Oct 2, 2024
CVE-2024-43795
6.1 MEDIUM

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. The login functionality contains a reflected …

Oct 2, 2024
CVE-2024-9440
5.4 MEDIUM

Slim Select 2.0 versions through 2.9.0 are affected by a potential cross-site scripting vulnerability. In select.ts:createOption(), the text variable from the user-provided Options object is …

Oct 2, 2024
CVE-2024-20513
5.8 MEDIUM

A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote …

Oct 2, 2024
CVE-2024-20509
5.8 MEDIUM

A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote …

Oct 2, 2024
CVE-2024-20502
5.8 MEDIUM

A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote …

Oct 2, 2024
CVE-2024-20500
5.8 MEDIUM

A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote …

Oct 2, 2024
CVE-2024-20524
6.8 MEDIUM

A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, Administrator-level, remote attacker to …

Oct 2, 2024
CVE-2024-20523
6.8 MEDIUM

A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, Administrator-level, remote attacker to …

Oct 2, 2024
CVE-2024-20522
6.5 MEDIUM

A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, Administrator-level, remote attacker to …

Oct 2, 2024
CVE-2024-20521
6.5 MEDIUM

A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, Administrator-level, remote attacker to …

Oct 2, 2024
CVE-2024-20520
6.5 MEDIUM

A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, Administrator-level, remote attacker to …

Oct 2, 2024
CVE-2024-20519
6.5 MEDIUM

A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, Administrator-level, remote attacker to …

Oct 2, 2024
CVE-2024-20518
6.5 MEDIUM

A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, Administrator-level, remote attacker to …

Oct 2, 2024
CVE-2024-20517
6.8 MEDIUM

A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, Administrator-level, remote attacker to …

Oct 2, 2024
CVE-2024-20516
6.8 MEDIUM

A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, Administrator-level, remote attacker to …

Oct 2, 2024
CVE-2024-20515
6.5 MEDIUM

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information from an …

Oct 2, 2024
CVE-2024-20492
6.0 MEDIUM

A vulnerability in the restricted shell of Cisco Expressway Series could allow an authenticated, local attacker to perform command injection attacks on the underlying operating …

Oct 2, 2024
CVE-2024-20491
6.3 MEDIUM

A vulnerability in a logging function of Cisco Nexus Dashboard Insights could allow an attacker with access to a tech support file to view sensitive …

Oct 2, 2024
CVE-2024-20490
6.3 MEDIUM

A vulnerability in a logging function of Cisco Nexus Dashboard Fabric Controller (NDFC) and Cisco Nexus Dashboard Orchestrator (NDO) could allow an attacker with access …

Oct 2, 2024
CVE-2024-20477
5.4 MEDIUM

A vulnerability in a specific REST API endpoint of Cisco NDFC could allow an authenticated, low-privileged, remote attacker to upload or delete files on an …

Oct 2, 2024
CVE-2024-20448
6.3 MEDIUM

A vulnerability in the Cisco Nexus Dashboard Fabric Controller (NDFC) software, formerly Cisco Data Center Network Manager (DCNM), could allow an attacker with access to …

Oct 2, 2024
CVE-2024-20444
5.5 MEDIUM

A vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC), formerly Cisco Data Center Network Manager (DCNM), could allow an authenticated, remote attacker with network-admin privileges …

Oct 2, 2024
CVE-2024-20442
5.4 MEDIUM

A vulnerability in the REST API endpoints of Cisco Nexus Dashboard could allow an authenticated, low-privileged, remote attacker to perform limited Administrator actions on an …

Oct 2, 2024
CVE-2024-20441
5.7 MEDIUM

A vulnerability in a specific REST API endpoint of Cisco NDFC could allow an authenticated, low-privileged, remote attacker to learn sensitive information on an affected …

Oct 2, 2024
CVE-2024-20438
6.3 MEDIUM

A vulnerability in the REST API endpoints of Cisco NDFC could allow an authenticated, low-privileged, remote attacker to read or write files on an affected …

Oct 2, 2024
CVE-2024-20385
5.9 MEDIUM

A vulnerability in the SSL/TLS implementation of Cisco Nexus Dashboard Orchestrator (NDO) could allow an unauthenticated, remote attacker to intercept sensitive information from an affected …

Oct 2, 2024
CVE-2024-20365
6.5 MEDIUM

A vulnerability in the Redfish API of Cisco UCS B-Series, Cisco UCS Managed C-Series, and Cisco UCS X-Series Servers could allow an authenticated, remote attacker …

Oct 2, 2024
CVE-2024-9423
5.3 MEDIUM

Certain HP LaserJet printers may potentially experience a denial of service when a user sends a raw JPEG file to the printer. The printer displays …

Oct 2, 2024
CVE-2024-47804
4.3 MEDIUM

If an attempt is made to create an item of a type prohibited by `ACL#hasCreatePermission2` or `TopLevelItemDescriptor#isApplicableIn(ItemGroup)` through the Jenkins CLI or the REST API …

Oct 2, 2024
CVE-2024-47803
4.3 MEDIUM

Jenkins 2.478 and earlier, LTS 2.462.2 and earlier does not redact multi-line secret values in error messages generated for form submissions involving the `secretTextarea` form …

Oct 2, 2024
CVE-2024-33210
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability has been identified in Flatpress 1.3. This vulnerability allows an attacker to inject malicious scripts into web pages viewed by …

Oct 2, 2024
CVE-2024-33209
5.4 MEDIUM

FlatPress v1.3 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into the "Add New Entry" section, which allows them …

Oct 2, 2024
CVE-2024-9429
6.3 MEDIUM

A vulnerability has been found in code-projects Restaurant Reservation System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Oct 2, 2024
CVE-2024-8037
6.5 MEDIUM

Vulnerable juju hook tool abstract UNIX domain socket. When combined with an attack of JUJU_CONTEXT_ID, any user on the local system with access to the …

Oct 2, 2024
CVE-2024-35294
6.5 MEDIUM

An unauthenticated remote attacker may use the devices traffic capture without authentication to grab plaintext administrative credentials.

Oct 2, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.