CVE Database

120754+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-11217
4.9 MEDIUM

A vulnerability was found in the OAuth-server. OAuth-server logs the OAuth2 client secret when the logLevel is Debug higher for OIDC/GitHub/GitLab/Google IDPs login options.

Nov 15, 2024
CVE-2017-13309
5.5 MEDIUM

In readEncryptedData of ConscryptEngine.java, there is a possible plaintext leak due to improperly used crypto. This could lead to local information disclosure with no additional …

Nov 15, 2024
CVE-2024-49536
5.5 MEDIUM

Audition versions 23.6.9, 24.4.6 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage …

Nov 15, 2024
CVE-2024-45609
6.5 MEDIUM

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An unauthenticated user can …

Nov 15, 2024
CVE-2024-44759
7.5 HIGH

An arbitrary file download vulnerability in the component /Doc/DownloadFile of NUS-M9 ERP Management Software v3.0.0 allows attackers to download arbitrary files and access sensitive information …

Nov 15, 2024
CVE-2024-3334
4.3 MEDIUM

A security bypass vulnerability exists in the Removable Media Encryption (RME)component of Digital Guardian Windows Agents prior to version 8.2.0. This allows a user to …

Nov 15, 2024
CVE-2024-24459
5.9 MEDIUM

An invalid memory access when handling the ProtocolIE_ID field of S1Setup Request messages in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial of …

Nov 15, 2024
CVE-2024-24458
5.9 MEDIUM

An invalid memory access when handling the ENB Configuration Transfer messages containing invalid PLMN Identities in Athonet vEPC MME v11.4.0 allows attackers to cause a …

Nov 15, 2024
CVE-2024-24457
5.9 MEDIUM

An invalid memory access when handling the ProtocolIE_ID field of E-RAB Setup List Context SURes messages in Athonet vEPC MME v11.4.0 allows attackers to cause …

Nov 15, 2024
CVE-2024-24455
5.9 MEDIUM

An invalid memory access when handling a UE Context Release message containing an invalid UE identifier in Athonet vEPC MME v11.4.0 allows attackers to cause …

Nov 15, 2024
CVE-2024-24454
5.9 MEDIUM

An invalid memory access when handling the ProtocolIE_ID field of E-RAB Modify Request messages in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial …

Nov 15, 2024
CVE-2024-24453
5.9 MEDIUM

An invalid memory access when handling the ProtocolIE_ID field of E-RAB NotToBeModifiedBearerModInd information element in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial …

Nov 15, 2024
CVE-2024-24452
5.9 MEDIUM

An invalid memory access when handling the ProtocolIE_ID field of E-RAB Release Indication messages in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial …

Nov 15, 2024
CVE-2024-11259
3.5 LOW

A vulnerability, which was classified as problematic, has been found in code-projects Farmacia 1.0. This issue affects some unknown processing of the file /fornecedores.php. The …

Nov 15, 2024
CVE-2024-11258
7.3 HIGH

A vulnerability classified as critical was found in 1000 Projects Beauty Parlour Management System 1.0. This vulnerability affects unknown code of the file /admin/index.php. The …

Nov 15, 2024
CVE-2024-11257
7.3 HIGH

A vulnerability classified as critical has been found in 1000 Projects Beauty Parlour Management System 1.0. This affects an unknown part of the file /admin/forgot-password.php. …

Nov 15, 2024
CVE-2024-11256
7.3 HIGH

A vulnerability was found in 1000 Projects Portfolio Management System MCA 1.0 and classified as critical. This issue affects some unknown processing of the file …

Nov 15, 2024
CVE-2024-10934
9.8 CRITICAL

In OpenBSD 7.5 before errata 008 and OpenBSD 7.4 before errata 021, avoid possible mbuf double free in NFS client and server implementation, do not …

Nov 15, 2024
CVE-2024-51330
4.4 MEDIUM

An issue in UltiMaker Cura v.4.41 and 5.8.1 and before allows a local attacker to execute arbitrary code via Inter-process communication (IPC) mechanism between Cura …

Nov 15, 2024
CVE-2024-51142
5.4 MEDIUM

Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows an attacker to execute arbitrary code via the svkey parameter of the storageapi.php file.

Nov 15, 2024
CVE-2024-51141
7.8 HIGH

An issue in TOTOLINK Bluetooth Wireless Adapter A600UB allows a local attacker to execute arbitrary code via the WifiAutoInstallDriver.exe and MSASN1.dll components.

Nov 15, 2024
CVE-2024-51037
5.3 MEDIUM

An issue in kodbox v.1.52.04 and before allows a remote attacker to obtain sensitive information via the captcha feature in the password reset function.

Nov 15, 2024
CVE-2024-45971
9.8 CRITICAL

Multiple Buffer overflows in the MMS Client in MZ Automation LibIEC61850 before commit 1f52be9ddeae00e69cd43e4cac3cb4f0c880c4f0 allow a malicious server to cause a stack-based buffer overflow via …

Nov 15, 2024
CVE-2024-45970
9.8 CRITICAL

Multiple Buffer overflows in the MMS Client in MZ Automation LibIEC61850 before commit ac925fae8e281ac6defcd630e9dd756264e9c5bc allow a malicious server to cause a stack-based buffer overflow via …

Nov 15, 2024
CVE-2024-45969
7.5 HIGH

NULL pointer dereference in the MMS Client in MZ Automation LibIEC1850 before commit 7afa40390b26ad1f4cf93deaa0052fe7e357ef33 allows a malicious server to Cause a Denial-of-Service via the MMS …

Nov 15, 2024
CVE-2024-45608
6.5 MEDIUM

GLPI is a free asset and IT management software package. An authenticated user can perfom a SQL injection by changing its preferences. Upgrade to 10.0.17.

Nov 15, 2024
CVE-2024-43418
6.5 MEDIUM

GLPI is a free asset and IT management software package. An unauthenticated user can provide a malicious link to a GLPI technician in order to …

Nov 15, 2024
CVE-2024-43417
6.5 MEDIUM

GLPI is a free asset and IT management software package. An unauthenticated user can provide a malicious link to a GLPI technician in order to …

Nov 15, 2024
CVE-2024-41679
6.5 MEDIUM

GLPI is a free asset and IT management software package. An authenticated user can exploit a SQL injection vulnerability from the ticket form. Upgrade to …

Nov 15, 2024
CVE-2024-24446
6.5 MEDIUM

An uninitialized pointer dereference in OpenAirInterface CN5G AMF up to v2.0.0 allows attackers to cause a Denial of Service (DoS) via a crafted InitialContextSetupResponse message …

Nov 15, 2024
CVE-2024-24431
7.5 HIGH

A reachable assertion in the ogs_nas_emm_decode function of Open5GS v2.7.0 allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet with …

Nov 15, 2024
CVE-2024-24426
7.5 HIGH

Reachable assertions in the NGAP_FIND_PROTOCOLIE_BY_ID function of OpenAirInterface Magma v1.8.0 and OAI EPC Federation v1.2.0 allow attackers to cause a Denial of Service (DoS) via …

Nov 15, 2024
CVE-2024-24425
6.5 MEDIUM

Magma v1.8.0 and OAI EPC Federation v1.20 were discovered to contain an out-of-bounds read in the amf_as_establish_req function at /tasks/amf/amf_as.cpp. This vulnerability allows attackers to …

Nov 15, 2024
CVE-2024-23169
4.6 MEDIUM

The web interface in RSA NetWitness 11.7.2.0 allows Cross-Site Scripting (XSS) via the Where textbox on the Reports screen during new rule creation.

Nov 15, 2024
CVE-2024-52522

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Insecure handling of symlinks with --links and --metadata …

Nov 15, 2024
CVE-2024-52514
4.1 MEDIUM

Nextcloud Server is a self hosted personal cloud system. After a user received a share with some files inside being blocked by the files access …

Nov 15, 2024
CVE-2024-52513
2.6 LOW

Nextcloud Server is a self hosted personal cloud system. After receiving a "Files drop" or "Password protected" share link a malicious user was able to …

Nov 15, 2024
CVE-2024-52512
3.3 LOW

user_oidc app is an OpenID Connect user backend for Nextcloud. A malicious user could send a malformed login link that would redirect the user to …

Nov 15, 2024
CVE-2024-52511
6.3 MEDIUM

Nextcloud Tables allows users to to create tables with individual columns. By directly specifying the ID of a table or view, a malicious user could …

Nov 15, 2024
CVE-2024-52510
4.2 MEDIUM

The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. The Desktop client did not stop with an error …

Nov 15, 2024
CVE-2024-52509
3.5 LOW

Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. The Nextcloud mail app incorrectly allowed attaching shared files without download permissions as …

Nov 15, 2024
CVE-2024-52508
8.2 HIGH

Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. When a user is trying to set up a mail account with an …

Nov 15, 2024
CVE-2024-52507
3.5 LOW

Nextcloud Tables allows users to to create tables with individual columns. The information which Table (numeric ID) is shared with which groups and users and …

Nov 15, 2024
CVE-2024-50800
5.4 MEDIUM

Cross Site Scripting vulnerability in M2000 Smart4Web before v.5.020241004 allows a remote attacker to execute arbitrary code via the error parameter in URL

Nov 15, 2024
CVE-2024-47759
4.8 MEDIUM

GLPI is a free Asset and IT management software package. An technician can upload a SVG containing a malicious script. The script will then be …

Nov 15, 2024
CVE-2024-46467
7.8 HIGH

By default, dedicated folders of ZONEPOINT for Windows up to 2024.1 can be accessed by other users to misuse technical files and make them perform …

Nov 15, 2024
CVE-2024-46466
7.8 HIGH

By default, dedicated folders of ZONECENTRAL for Windows up to 2024.3 or up to Q.2021.2 (ANSSI qualification submission) can be accessed by other users to …

Nov 15, 2024
CVE-2024-46465
7.8 HIGH

By default, dedicated folders of CRYHOD for Windows up to 2024.3 can be accessed by other users to misuse technical files and make them perform …

Nov 15, 2024
CVE-2024-46463
7.8 HIGH

By default, dedicated folders of ORIZON for Windows up to 2024.3 can be accessed by other users to misuse technical files and make them perform …

Nov 15, 2024
CVE-2024-46462
7.8 HIGH

By default, dedicated folders of ZEDMAIL for Windows up to 2024.3 can be accessed by other users to misuse technical files and make them perform …

Nov 15, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.