CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-8907
6.1 MEDIUM

Insufficient data validation in Omnibox in Google Chrome on Android prior to 129.0.6668.58 allowed a remote attacker who convinced a user to engage in specific …

Sep 17, 2024
CVE-2024-8906
4.3 MEDIUM

Incorrect security UI in Downloads in Google Chrome prior to 129.0.6668.58 allowed a remote attacker who convinced a user to engage in specific UI gestures …

Sep 17, 2024
CVE-2024-46976
6.5 MEDIUM

Backstage is an open framework for building developer portals. An attacker with control of the contents of the TechDocs storage buckets is able to inject …

Sep 17, 2024
CVE-2024-45816
6.5 MEDIUM

Backstage is an open framework for building developer portals. When using the AWS S3 or GCS storage provider for TechDocs it is possible to access …

Sep 17, 2024
CVE-2024-45815
6.5 MEDIUM

Backstage is an open framework for building developer portals. A malicious actor with authenticated access to a Backstage instance with the catalog backend plugin installed …

Sep 17, 2024
CVE-2024-45812
6.4 MEDIUM

Vite a frontend build tooling framework for javascript. Affected versions of vite were discovered to contain a DOM Clobbering vulnerability when building scripts to `cjs`/`iife`/`umd` …

Sep 17, 2024
CVE-2024-45811
4.8 MEDIUM

Vite a frontend build tooling framework for javascript. In affected versions the contents of arbitrary files can be returned to the browser. `@fs` denies access …

Sep 17, 2024
CVE-2024-45605
6.5 MEDIUM

Sentry is a developer-first error tracking and performance monitoring platform. An authenticated user delete the user issue alert notifications for arbitrary users given a know …

Sep 17, 2024
CVE-2024-45604
4.3 MEDIUM

Contao is an Open Source CMS. In affected versions authenticated users in the back end can list files outside the document root in the file …

Sep 17, 2024
CVE-2024-8949
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Online Eyewear Shop 1.0. This affects an unknown part of the file /classes/Master.php of the …

Sep 17, 2024
CVE-2024-8947
5.6 MEDIUM

A vulnerability was found in MicroPython 1.22.2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file py/objarray.c. …

Sep 17, 2024
CVE-2024-8660
4.8 MEDIUM

Concrete CMS versions 9.0.0 through 9.3.3 are affected by a stored XSS vulnerability in the "Top Navigator Bar" block. Since the "Top Navigator Bar" output …

Sep 17, 2024
CVE-2024-45803
6.1 MEDIUM

Wire UI is a library of components and resources to empower Laravel and Livewire application development. A potential Cross-Site Scripting (XSS) vulnerability has been identified …

Sep 17, 2024
CVE-2024-45612
5.3 MEDIUM

Contao is an Open Source CMS. In affected versions an untrusted user can inject insert tags into the canonical tag, which are then replaced on …

Sep 17, 2024
CVE-2024-45537
6.5 MEDIUM

Apache Druid allows users with certain permissions to read data from other database systems using JDBC. This functionality allows trusted users to set up Druid …

Sep 17, 2024
CVE-2024-45384
5.3 MEDIUM

Padding Oracle vulnerability in Apache Druid extension, druid-pac4j. This could allow an attacker to manipulate a pac4j session cookie. This issue affects Apache Druid versions …

Sep 17, 2024
CVE-2024-8945
5.5 MEDIUM

A vulnerability has been found in CodeCanyon RISE Ultimate Project Manager 3.7.0 and classified as critical. This vulnerability affects unknown code of the file /index.php/dashboard/save. …

Sep 17, 2024
CVE-2024-8796
5.3 MEDIUM

Under the default configuration, Devise-Two-Factor versions >= 2.2.0 & < 6.0.0 generate TOTP shared secrets that are 120 bits instead of the 128-bit minimum defined …

Sep 17, 2024
CVE-2024-38380
5.5 MEDIUM

This vulnerability occurs when user-supplied input is improperly sanitized and then reflected back to the user's browser, allowing an attacker to execute arbitrary JavaScript in …

Sep 17, 2024
CVE-2024-8939
6.2 MEDIUM

A vulnerability was found in the ilab model serve component, where improper handling of the best_of parameter in the vllm JSON web API can lead …

Sep 17, 2024
CVE-2024-38860
6.1 MEDIUM

Improper neutralization of input in Checkmk before versions 2.3.0p16 and 2.2.0p34 allows attackers to craft malicious links that can facilitate phishing attacks.

Sep 17, 2024
CVE-2024-8897
6.1 MEDIUM

Under certain conditions, an attacker with the ability to redirect users to a malicious site via an open redirect on a trusted site, may be …

Sep 17, 2024
CVE-2024-8093
6.5 MEDIUM

The Posts reminder WordPress plugin through 0.20 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

Sep 17, 2024
CVE-2024-8092
5.4 MEDIUM

The Accordion Image Menu WordPress plugin through 3.1.3 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which …

Sep 17, 2024
CVE-2024-8091
6.5 MEDIUM

The Enhanced Search Box WordPress plugin through 0.6.1 does not have CSRF check in place when updating its settings, which could allow attackers to make …

Sep 17, 2024
CVE-2024-8052
6.1 MEDIUM

The Review Ratings WordPress plugin through 1.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could …

Sep 17, 2024
CVE-2024-8051
5.4 MEDIUM

The Special Feed Items WordPress plugin through 1.0.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which …

Sep 17, 2024
CVE-2024-8047
6.5 MEDIUM

The Visual Sound (old) WordPress plugin through 1.06 does not have CSRF check in place when updating its settings, which could allow attackers to make …

Sep 17, 2024
CVE-2024-8044
6.5 MEDIUM

The infolinks Ad Wrap WordPress plugin through 1.0.2 does not have CSRF check in place when updating its settings, which could allow attackers to make …

Sep 17, 2024
CVE-2024-8043
5.4 MEDIUM

The Vikinghammer Tweet WordPress plugin through 0.2.4 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could …

Sep 17, 2024
CVE-2024-5170
4.8 MEDIUM

The Logo Manager For Enamad WordPress plugin through 0.7.1 does not sanitise and escape in its widgets settings, which could allow high privilege users such …

Sep 17, 2024
CVE-2024-44202
5.3 MEDIUM

An authentication issue was addressed with improved state management. This issue is fixed in Safari 18, iOS 18 and iPadOS 18. Private Browsing tabs may …

Sep 17, 2024
CVE-2024-44198
5.5 MEDIUM

An integer overflow was addressed through improved input validation. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS …

Sep 17, 2024
CVE-2024-44191
5.5 MEDIUM

This issue was addressed through improved state management. This issue is fixed in Xcode 16, iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, …

Sep 17, 2024
CVE-2024-44190
5.5 MEDIUM

A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7. An app …

Sep 17, 2024
CVE-2024-44188
5.5 MEDIUM

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. An app may be able to access protected user …

Sep 17, 2024
CVE-2024-44187
6.5 MEDIUM

A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of security origins. This issue is fixed in Safari 18, iOS 18 …

Sep 17, 2024
CVE-2024-44186
5.5 MEDIUM

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15. An app may be able to access protected …

Sep 17, 2024
CVE-2024-44184
5.5 MEDIUM

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia …

Sep 17, 2024
CVE-2024-44183
5.5 MEDIUM

A logic error was addressed with improved error handling. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS …

Sep 17, 2024
CVE-2024-44182
5.5 MEDIUM

This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7. An …

Sep 17, 2024
CVE-2024-44181
5.5 MEDIUM

An issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7. An …

Sep 17, 2024
CVE-2024-44178
5.5 MEDIUM

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7. An app …

Sep 17, 2024
CVE-2024-44177
5.5 MEDIUM

A privacy issue was addressed by removing sensitive data. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7. An app …

Sep 17, 2024
CVE-2024-44176
5.5 MEDIUM

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, …

Sep 17, 2024
CVE-2024-44171
4.6 MEDIUM

This issue was addressed through improved state management. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, watchOS 11. …

Sep 17, 2024
CVE-2024-44170
5.5 MEDIUM

A privacy issue was addressed by moving sensitive data to a more secure location. This issue is fixed in iOS 18 and iPadOS 18, macOS …

Sep 17, 2024
CVE-2024-44169
5.5 MEDIUM

The issue was addressed with improved memory handling. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia …

Sep 17, 2024
CVE-2024-44168
5.5 MEDIUM

A library injection issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7. An app …

Sep 17, 2024
CVE-2024-44167
5.5 MEDIUM

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7, …

Sep 17, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.