CVE Database

120754+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-11309
7.5 HIGH

The DVC from TRCore has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.

Nov 18, 2024
CVE-2024-11308
6.2 MEDIUM

The DVC from TRCore encrypts files using a hardcoded key. Attackers can use this key to decrypt the files and restore the original content.

Nov 18, 2024
CVE-2024-52940
7.5 HIGH

AnyDesk through 8.1.0 on Windows, when Allow Direct Connections is enabled, inadvertently exposes a public IP address within network traffic. The attacker must know the …

Nov 18, 2024
CVE-2024-43704
8.4 HIGH

Software installed and run as a non-privileged user may conduct improper GPU system calls to gain access to the graphics buffers of a parent process.

Nov 18, 2024
CVE-2024-52926
6.5 MEDIUM

Delinea Privilege Manager before 12.0.2 mishandles the security of the Windows agent.

Nov 18, 2024
CVE-2024-52922
6.5 MEDIUM

In Bitcoin Core before 25.1, an attacker can cause a node to not download the latest block, because there can be minutes of delay when …

Nov 18, 2024
CVE-2024-52921
5.3 MEDIUM

In Bitcoin Core before 25.0, a peer can affect the download state of other peers by sending a mutated block.

Nov 18, 2024
CVE-2024-52920
7.5 HIGH

Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (infinite loop) via a malformed GETDATA message.

Nov 18, 2024
CVE-2024-52919
6.5 MEDIUM

Bitcoin Core before 22.0 has a CAddrMan nIdCount integer overflow and resultant assertion failure (and daemon exit) via a flood of addr messages.

Nov 18, 2024
CVE-2024-52918
6.5 MEDIUM

Bitcoin-Qt in Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (memory consumption and application crash) via a BIP21 r parameter …

Nov 18, 2024
CVE-2024-52917
6.5 MEDIUM

Bitcoin Core before 22.0 has a miniupnp infinite loop in which it allocates memory on the basis of random data received over the network, e.g., …

Nov 18, 2024
CVE-2024-52916
7.5 HIGH

Bitcoin Core before 0.15.0 allows a denial of service (OOM kill of a daemon process) via a flood of minimum difficulty headers.

Nov 18, 2024
CVE-2024-52915
7.5 HIGH

Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (memory consumption) via a crafted INV message.

Nov 18, 2024
CVE-2024-52914
7.5 HIGH

In Bitcoin Core before 0.18.0, a node could be stalled for hours when processing the orphans of a crafted unconfirmed transaction.

Nov 18, 2024
CVE-2024-52913
5.3 MEDIUM

In Bitcoin Core before 0.21.0, an attacker could prevent a node from seeing a specific unconfirmed transaction, because transaction re-requests are mishandled.

Nov 18, 2024
CVE-2024-52912
7.5 HIGH

Bitcoin Core before 0.21.0 allows a network split that is resultant from an integer overflow (calculating the time offset for newly connecting peers) and an …

Nov 18, 2024
CVE-2024-38828
5.3 MEDIUM

Spring MVC controller methods with an @RequestBody byte[] method parameter are vulnerable to a DoS attack.

Nov 18, 2024
CVE-2019-25220
7.5 HIGH

Bitcoin Core before 24.0.1 allows remote attackers to cause a denial of service (daemon crash) via a flood of low-difficulty header chains (aka a "Chain …

Nov 18, 2024
CVE-2015-20111
9.8 CRITICAL

miniupnp before 4c90b87, as used in Bitcoin Core before 0.12 and other products, lacks checks for snprintf return values, leading to a buffer overflow and …

Nov 18, 2024
CVE-2024-11306
5.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Altenergy Power Control Software up to 20241108. This issue affects some unknown processing of …

Nov 18, 2024
CVE-2024-11305
6.3 MEDIUM

A vulnerability classified as critical was found in Altenergy Power Control Software up to 20241108. This vulnerability affects the function get_status_zigbee of the file /index.php/display/status_zigbee. …

Nov 18, 2024
CVE-2023-43091
9.8 CRITICAL

A flaw was found in GNOME Maps, which is vulnerable to a code injection attack via its service.json configuration file. If the configuration file is …

Nov 17, 2024
CVE-2024-0793
7.7 HIGH

A flaw was found in kube-controller-manager. This issue occurs when the initial application of a HPA config YAML lacking a .spec.behavior.scaleUp block causes a denial …

Nov 17, 2024
CVE-2023-6110
5.5 MEDIUM

A flaw was found in OpenStack. When a user tries to delete a non-existing access rule in it's scope, it deletes other existing access rules …

Nov 17, 2024
CVE-2023-4639
7.4 HIGH

A flaw was found in Undertow, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct …

Nov 17, 2024
CVE-2023-1419
5.9 MEDIUM

A script injection vulnerability was found in the Debezium database connector, where it does not properly sanitize some parameters. This flaw allows an attacker to …

Nov 17, 2024
CVE-2023-0657
3.4 LOW

A flaw was found in Keycloak. This issue occurs due to improperly enforcing token types when validating signatures locally. This could allow an authenticated attacker …

Nov 17, 2024
CVE-2020-25720
7.5 HIGH

A vulnerability was found in Samba where a delegated administrator with permission to create objects in Active Directory can write to all attributes of the …

Nov 17, 2024
CVE-2024-52876
7.5 HIGH

Holy Stone Remote ID Module HSRID01, firmware distributed with the Drone Go2 mobile application before 1.1.8, allows unauthenticated "remote power off" actions (in broadcast mode) …

Nov 17, 2024
CVE-2024-52872
7.5 HIGH

In Flagsmith before 2.134.1, the get_document endpoint is not correctly protected by permissions.

Nov 17, 2024
CVE-2024-52871
7.5 HIGH

In Flagsmith before 2.134.1, it is possible to bypass the ALLOW_REGISTRATION_WITHOUT_INVITE setting.

Nov 17, 2024
CVE-2024-52867
8.1 HIGH

guix-daemon in GNU Guix before 5ab3c4c allows privilege escalation because build outputs are accessible by local users before file metadata concerns (e.g., for setuid and …

Nov 17, 2024
CVE-2024-52397
9.1 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Davor Zeljkovic Convert Docx2post convert-docx2post allows Upload a Web Shell to a Web Server.This issue affects …

Nov 16, 2024
CVE-2024-52416
10.0 CRITICAL

Missing Authorization vulnerability in Eugen Bobrowski Debug Tool debug-tool allows Upload a Web Shell to a Web Server.This issue affects Debug Tool: from n/a through …

Nov 16, 2024
CVE-2024-52415
8.8 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in skipstorm SK WP Settings Backup sk-wp-settings-backup allows Object Injection.This issue affects SK WP Settings Backup: from n/a through <= …

Nov 16, 2024
CVE-2024-52414
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in Anthony Carbon WDES Responsive Mobile Menu wdes-responsive-mobile-menu allows Object Injection.This issue affects WDES Responsive Mobile Menu: from n/a through …

Nov 16, 2024
CVE-2024-52413
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in dmcwebzone Airin Blog airin-blog allows Object Injection.This issue affects Airin Blog: from n/a through <= 1.6.1.

Nov 16, 2024
CVE-2024-52412
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in Stephen Cui Xin allows Object Injection.This issue affects Xin: from n/a through 1.0.8.1.

Nov 16, 2024
CVE-2024-52411
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in flowcraft Advanced Personalization personalization-by-flowcraft allows Object Injection.This issue affects Advanced Personalization: from n/a through <= 1.1.2.

Nov 16, 2024
CVE-2024-52410
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in Phoenixheart Referrer Detector referrer-detector allows Object Injection.This issue affects Referrer Detector: from n/a through <= 4.2.1.0.

Nov 16, 2024
CVE-2024-52409
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in Phoenixheart AJAX Random Posts ajax-random-posts allows Object Injection.This issue affects AJAX Random Posts: from n/a through <= 0.3.3.

Nov 16, 2024
CVE-2024-52408
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in pushassist Push Notifications for WordPress by PushAssist push-notification-for-wp-by-pushassist allows Upload a Web Shell to a Web …

Nov 16, 2024
CVE-2024-52407
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in BasePress BasePress Migration Tools basepress-migration-tools allows Upload a Web Shell to a Web Server.This issue affects …

Nov 16, 2024
CVE-2024-52406
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in wibergsweb CSV to html csv-to-html allows Upload a Web Shell to a Web Server.This issue affects …

Nov 16, 2024
CVE-2024-52405
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in bikramjoshii B-Banner Slider b-banner-slider allows Upload a Web Shell to a Web Server.This issue affects B-Banner …

Nov 16, 2024
CVE-2024-52404
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in bigfiveagency CF7 Reply Manager cf7-reply-manager.This issue affects CF7 Reply Manager: from n/a through <= 1.2.3.

Nov 16, 2024
CVE-2024-52403
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Saad Iqbal User Management user-management allows Upload a Web Shell to a Web Server.This issue affects …

Nov 16, 2024
CVE-2024-52400
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Subhasis Laha Gallerio gallerio allows Upload a Web Shell to a Web Server.This issue affects Gallerio: …

Nov 16, 2024
CVE-2024-52399
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Clarisse K. Writer Helper writer-helper allows Upload a Web Shell to a Web Server.This issue affects …

Nov 16, 2024
CVE-2024-52398
9.1 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Halyra CDI collect-and-deliver-interface-for-woocommerce.This issue affects CDI: from n/a through <= 5.5.3.

Nov 16, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.