CVE Database

120754+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-50840
5.4 MEDIUM

A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/class.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary …

Nov 14, 2024
CVE-2024-50839
5.4 MEDIUM

A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/add_subject.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary …

Nov 14, 2024
CVE-2024-11215
6.5 MEDIUM

Absolute path traversal (incorrect restriction of a path to a restricted directory) vulnerability in the EasyPHP web server, affecting version 14.1. This vulnerability could allow …

Nov 14, 2024
CVE-2024-11209
6.3 MEDIUM

A vulnerability was found in Apereo CAS 6.6. It has been classified as critical. This affects an unknown part of the file /login?service of the …

Nov 14, 2024
CVE-2024-11208
3.7 LOW

A vulnerability was found in Apereo CAS 6.6 and classified as problematic. Affected by this issue is some unknown functionality of the file /login?service. The …

Nov 14, 2024
CVE-2024-10962
8.8 HIGH

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0.9.107 via deserialization …

Nov 14, 2024
CVE-2024-8648
6.1 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 16 before 17.3.7, 17.4 before 17.4.4, and 17.5 before 17.5.2. The vulnerability could …

Nov 14, 2024
CVE-2024-7404
6.8 MEDIUM

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 prior to 17.3.7, starting from 17.4 prior to 17.4.4 and starting from …

Nov 14, 2024
CVE-2024-11207
4.3 MEDIUM

A vulnerability has been found in Apereo CAS 6.6 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /login. …

Nov 14, 2024
CVE-2024-10979
8.8 HIGH

Incorrect control of environment variables in PostgreSQL PL/Perl allows an unprivileged database user to change sensitive process environment variables (e.g. PATH). That often suffices to …

Nov 14, 2024
CVE-2024-10978
4.2 MEDIUM

Incorrect privilege assignment in PostgreSQL allows a less-privileged application user to view or change different rows from those intended. An attack requires the application to …

Nov 14, 2024
CVE-2024-10977
3.1 LOW

Client use of server error message in PostgreSQL allows a server not trusted under current SSL or GSS settings to furnish arbitrary non-NUL bytes to …

Nov 14, 2024
CVE-2024-10976
4.2 MEDIUM

Incomplete tracking in PostgreSQL of tables with row security allows a reused query to view or change different rows from those intended. CVE-2023-2455 and CVE-2016-2193 …

Nov 14, 2024
CVE-2024-7730
7.4 HIGH

A heap buffer overflow was found in the virtio-snd device in QEMU. When reading input audio in the virtio-snd input callback, virtio_snd_pcm_in_cb, the function did …

Nov 14, 2024
CVE-2024-45670
5.6 MEDIUM

IBM Security SOAR 51.0.1.0 and earlier contains a mechanism for users to recover or change their passwords without knowing the original password, but the user …

Nov 14, 2024
CVE-2024-45642
5.3 MEDIUM

IBM Security ReaQta 3.12 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus …

Nov 14, 2024
CVE-2024-45099
3.1 LOW

IBM Security ReaQta 3.12 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus …

Nov 14, 2024
CVE-2024-3447
6.0 MEDIUM

A heap-based buffer overflow was found in the SDHCI device emulation of QEMU. The bug is triggered when both `s->data_count` and the size of `s->fifo_buffer` …

Nov 14, 2024
CVE-2023-4458
4.0 MEDIUM

A flaw was found within the parsing of extended attributes in the kernel ksmbd module. The issue results from the lack of proper validation of …

Nov 14, 2024
CVE-2022-31671
7.4 HIGH

Harbor fails to validate user permissions when reading and updating job execution logs through the P2P preheat execution logs. By sending a request that attempts …

Nov 14, 2024
CVE-2022-31670
7.7 HIGH

Harbor fails to validate the user permissions when updating tag retention policies. By sending a request to update a tag retention policy with an id …

Nov 14, 2024
CVE-2022-31669
6.4 MEDIUM

Harbor fails to validate the user permissions when updating tag immutability policies. By sending a request to update a tag immutability policy with an id …

Nov 14, 2024
CVE-2022-31668
7.4 HIGH

Harbor fails to validate the user permissions when updating p2p preheat policies. By sending a request to update a p2p preheat policy with an id …

Nov 14, 2024
CVE-2022-31667
6.4 MEDIUM

Harbor fails to validate the user permissions when updating a robot account that belongs to a project that the authenticated user doesn’t have access to. …

Nov 14, 2024
CVE-2022-31666
7.7 HIGH

Harbor fails to validate user permissions while deleting Webhook policies, allowing malicious users to view, update and delete Webhook policies of other users. The attacker …

Nov 14, 2024
CVE-2024-9693
8.5 HIGH

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.0 prior to 17.3.7, starting from 17.4 prior to 17.4.4, and starting from …

Nov 14, 2024
CVE-2024-8180
5.4 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.3.7, 17.4 before 17.4.4, and 17.5 before 17.5.2. Improper output encoding …

Nov 14, 2024
CVE-2024-10571
9.8 CRITICAL

The Chartify – WordPress Chart Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.9.5 via the …

Nov 14, 2024
CVE-2023-4134
5.5 MEDIUM

A use-after-free vulnerability was found in the cyttsp4_core driver in the Linux kernel. This issue occurs in the device cleanup routine due to a possible …

Nov 14, 2024
CVE-2024-9472

A null pointer dereference in Palo Alto Networks PAN-OS software on PA-800 Series, PA-3200 Series, PA-5200 Series, and PA-7000 Series hardware platforms when Decryption policy …

Nov 14, 2024
CVE-2024-5920
4.8 MEDIUM

A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write Panorama administrator to push a specially crafted configuration to a …

Nov 14, 2024
CVE-2024-5919
6.5 MEDIUM

A blind XML External Entities (XXE) injection vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker to exfiltrate arbitrary files from firewalls …

Nov 14, 2024
CVE-2024-5918
4.3 MEDIUM

An improper certificate validation vulnerability in Palo Alto Networks PAN-OS software enables an authorized user with a specially crafted client certificate to connect to an …

Nov 14, 2024
CVE-2024-5917
4.9 MEDIUM

A server-side request forgery in PAN-OS software enables an authenticated attacker with administrative privileges to use the administrative web interface as a proxy, which enables …

Nov 14, 2024
CVE-2024-50306
9.1 CRITICAL

Unchecked return value can allow Apache Traffic Server to retain privileges on startup. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.5, from 10.0.0 …

Nov 14, 2024
CVE-2024-50305
7.5 HIGH

Valid Host header field can cause Apache Traffic Server to crash on some platforms. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.5. Users …

Nov 14, 2024
CVE-2024-47916
7.5 HIGH

Boa web server - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Nov 14, 2024
CVE-2024-47915
7.5 HIGH

VaeMendis - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Nov 14, 2024
CVE-2024-47914
4.5 MEDIUM

VaeMendis - CWE-352: Cross-Site Request Forgery (CSRF)

Nov 14, 2024
CVE-2024-45254
7.5 HIGH

VaeMendis - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Nov 14, 2024
CVE-2024-45253
7.5 HIGH

Avigilon – CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Nov 14, 2024
CVE-2024-38479
7.5 HIGH

Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.5. Users are recommended …

Nov 14, 2024
CVE-2024-2552
6.0 MEDIUM

A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions in the management plane and delete files …

Nov 14, 2024
CVE-2024-2551
7.5 HIGH

A null pointer dereference vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to stop a core system service on the firewall by …

Nov 14, 2024
CVE-2024-2550
7.5 HIGH

A null pointer dereference vulnerability in the GlobalProtect gateway in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to stop the GlobalProtect service on …

Nov 14, 2024
CVE-2024-7787

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ITG Computer Technology vSRM Supplier Relationship Management System allows Reflected XSS, …

Nov 14, 2024
CVE-2024-11206
7.5 HIGH

Unauthorized access vulnerability in the mobile application (com.transsion.phoenix) can lead to the leakage of user information.

Nov 14, 2024
CVE-2024-9186
8.6 HIGH

The Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit WordPress plugin before 3.3.0 does not sanitize and escape the bwfan-track-id parameter before …

Nov 14, 2024
CVE-2024-10146
5.4 MEDIUM

The Simple File List WordPress plugin before 6.1.13 does not sanitise and escape a generated URL before outputting it back in an attribute, leading to …

Nov 14, 2024
CVE-2023-34049
6.7 MEDIUM

The Salt-SSH pre-flight option copies the script to the target at a predictable path, which allows an attacker to force Salt-SSH to run their script. …

Nov 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.