CVE Database

120754+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-11193
6.5 MEDIUM

An information disclosure vulnerability exists in Yugabyte Anywhere, where the LDAP bind password is logged in plaintext within application logs. This flaw results in the …

Nov 13, 2024
CVE-2024-42834
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the Create Customer API in Incognito Service Activation Center (SAC) UI v14.11 allows authenticated attackers to execute arbitrary …

Nov 13, 2024
CVE-2024-40443
4.3 MEDIUM

SQL Injection vulnerability in Simple Laboratory Management System using PHP and MySQL v.1.0 allows a remote attacker to cause a denial of service via the …

Nov 13, 2024
CVE-2023-38920
4.8 MEDIUM

Cross Site Scripting vulnerability in Cyber Cafe Management System v.1.0 allows a local attacker to execute arbitrary code via a crafted script to the adminname …

Nov 13, 2024
CVE-2024-49379

Umbrel is a home server OS for self-hosting. The login functionality of Umbrel before version 1.2.2 contains a reflected cross-site scripting (XSS) vulnerability in use-auth.tsx. …

Nov 13, 2024
CVE-2024-43093
7.3 HIGH KEV

In shouldHideDocument of ExternalStorageProvider.java, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrect unicode …

Nov 13, 2024
CVE-2024-43091
9.8 CRITICAL

In filterMask of SkEmbossMaskFilter.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with …

Nov 13, 2024
CVE-2024-43090
5.0 MEDIUM

In multiple locations, there is a possible cross-user image read due to a missing permission check. This could lead to local information disclosure with User …

Nov 13, 2024
CVE-2024-43089
7.8 HIGH

In updateInternal of MediaProvider.java , there is a possible access of another app's files due to a missing permission check. This could lead to local …

Nov 13, 2024
CVE-2024-43088
7.8 HIGH

In multiple functions in AppInfoBase.java, there is a possible way to manipulate app permission settings belonging to another user on the device due to a …

Nov 13, 2024
CVE-2024-43087
7.8 HIGH

In getInstalledAccessibilityPreferences of AccessibilitySettings.java, there is a possible way to hide an enabled accessibility service in the accessibility service settings due to a logic error …

Nov 13, 2024
CVE-2024-43086
5.5 MEDIUM

In validateAccountsInternal of AccountManagerService.java, there is a possible way to leak account credentials to a third party app due to a confused deputy. This could …

Nov 13, 2024
CVE-2024-43085
7.8 HIGH

In handleMessage of UsbDeviceManager.java, there is a possible method to access device contents over USB without unlocking the device due to a logic error in …

Nov 13, 2024
CVE-2024-43084
5.5 MEDIUM

In visitUris of multiple files, there is a possible information disclosure due to a confused deputy. This could lead to local information disclosure with no …

Nov 13, 2024
CVE-2024-43083
5.5 MEDIUM

In validate of WifiConfigurationUtil.java , there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service …

Nov 13, 2024
CVE-2024-43082
5.5 MEDIUM

In onActivityResult of EditUserPhotoController.java, there is a possible cross-user media read due to a confused deputy. This could lead to local information disclosure with no …

Nov 13, 2024
CVE-2024-43081
7.8 HIGH

In installExistingPackageAsUser of InstallPackageHelper.java, there is a possible carrier restriction bypass due to a logic error in the code. This could lead to local escalation …

Nov 13, 2024
CVE-2024-43080
7.8 HIGH

In onReceive of AppRestrictionsFragment.java, there is a possible escalation of privilege due to unsafe deserialization. This could lead to local escalation of privilege with no …

Nov 13, 2024
CVE-2024-40671
7.8 HIGH

In DevmemIntChangeSparse2 of devicemem_server.c, there is a possible way to achieve arbitrary code execution due to a missing permission check. This could lead to local …

Nov 13, 2024
CVE-2024-40661
7.8 HIGH

In mayAdminGrantPermission of AdminRestrictedPermissionsUtils.java, there is a possible way to access the microphone due to a missing permission check. This could lead to local escalation …

Nov 13, 2024
CVE-2024-40660
7.8 HIGH

In setTransactionState of SurfaceFlinger.cpp, there is a possible way to change protected display attributes due to a logic error in the code. This could lead …

Nov 13, 2024
CVE-2024-34747
7.8 HIGH

In DevmemXIntMapPages of devicemem_server.c, there is a possible use-after-free due to a logic error in the code. This could lead to local escalation of privilege …

Nov 13, 2024
CVE-2024-34729
7.8 HIGH

In multiple locations, there is a possible arbitrary code execution due to a logic error in the code. This could lead to local escalation of …

Nov 13, 2024
CVE-2024-34719
7.8 HIGH

In multiple locations, there is a possible permissions bypass due to a missing null check. This could lead to local escalation of privilege with no …

Nov 13, 2024
CVE-2024-31337
7.8 HIGH

In PVRSRVRGXKickTA3DKM of rgxta3d.c, there is a possible arbitrary code execution due to improper input validation. This could lead to local escalation of privilege in …

Nov 13, 2024
CVE-2024-23715
7.8 HIGH

In PMRWritePMPageList of pmr.c, there is a possible out of bounds write due to a logic error in the code. This could lead to local …

Nov 13, 2024
CVE-2023-35686
7.8 HIGH

In PVRSRVRGXKickTA3DKM of rgxta3d.c, there is a possible arbitrary code execution due to improper input validation. This could lead to local escalation of privilege in …

Nov 13, 2024
CVE-2023-35659
7.8 HIGH

In DevmemIntChangeSparse of devicemem_server.c, there is a possible arbitrary code execution due to a logic error in the code. This could lead to local escalation …

Nov 13, 2024
CVE-2024-9476

A vulnerability in Grafana Labs Grafana OSS and Enterprise allows Privilege Escalation allows users to gain access to resources from other organizations within the same …

Nov 13, 2024
CVE-2024-9413
8.0 HIGH

The transport_message_handler function in SCP-Firmware release versions 2.11.0-2.15.0 does not properly handle errors, potentially allowing an Application Processor (AP) to cause a buffer overflow in …

Nov 13, 2024
CVE-2024-52292
7.7 HIGH

Craft is a content management system (CMS). The dataUrl function can be exploited if an attacker has write permissions on system notification templates. This function …

Nov 13, 2024
CVE-2024-52291
8.4 HIGH

Craft is a content management system (CMS). A vulnerability in CraftCMS allows an attacker to bypass local file system validation by utilizing a double file:// …

Nov 13, 2024
CVE-2024-51996
7.5 HIGH

Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. When consuming a persisted remember-me cookie, Symfony does not check …

Nov 13, 2024
CVE-2024-45594
7.7 HIGH

Decidim is a participatory democracy framework. The meeting embeds feature used in the online or hybrid meetings is subject to potential XSS attack through a …

Nov 13, 2024
CVE-2024-8049
6.5 MEDIUM

In Progress Telerik Document Processing Libraries, versions prior to 2024 Q4 (2024.4.1106), importing a document with unsupported features can lead to excessive processing, leading to …

Nov 13, 2024
CVE-2024-7295
7.1 HIGH

In Progress® Telerik® Report Server versions prior to 2024 Q4 (10.3.24.1112), the encryption of local asset data used an older algorithm which may allow a …

Nov 13, 2024
CVE-2024-52306
7.6 HIGH

FileManager provides a Backpack admin interface for files and folder. Prior to 3.0.9, deserialization of untrusted data from the mimes parameter could lead to remote …

Nov 13, 2024
CVE-2024-52305
6.5 MEDIUM

UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. A vulnerability exists in the Create User process, allowing the creation …

Nov 13, 2024
CVE-2024-52300
9.0 CRITICAL

macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. The width parameter of the PDF viewer macro isn't properly escaped, allowing XSS for …

Nov 13, 2024
CVE-2024-52299
7.5 HIGH

macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. Any user with view right on XWiki.PDFViewerService can access any attachment stored in the …

Nov 13, 2024
CVE-2024-52298
7.5 HIGH

macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. The PDF Viewer macro allows an attacker to view any attachment using the "Delegate …

Nov 13, 2024
CVE-2024-52295
9.8 CRITICAL

DataEase is an open source data visualization analysis tool. Prior to 2.10.2, DataEase allows attackers to forge jwt and take over services. The JWT secret …

Nov 13, 2024
CVE-2024-52293
7.2 HIGH

Craft is a content management system (CMS). Prior to 4.12.2 and 5.4.3, Craft is missing normalizePath in the function FileHelper::absolutePath could lead to Remote Code …

Nov 13, 2024
CVE-2024-50972
7.2 HIGH

A SQL injection vulnerability in printtool.php of Itsourcecode Construction Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the borrow_id parameter.

Nov 13, 2024
CVE-2024-50971
7.2 HIGH

A SQL injection vulnerability in print.php of Itsourcecode Construction Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the map_id parameter.

Nov 13, 2024
CVE-2024-50970
8.8 HIGH

A SQL injection vulnerability in orderview1.php of Itsourcecode Online Furniture Shopping Project 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

Nov 13, 2024
CVE-2024-50969
6.1 MEDIUM

A Reflected cross-site scripting (XSS) vulnerability in browse.php of Code-projects Jonnys Liquor 1.0 allows remote attackers to inject arbitrary web scripts or HTML via the …

Nov 13, 2024
CVE-2024-11175
3.5 LOW

A vulnerability was found in Public CMS 5.202406.d and classified as problematic. This issue affects some unknown processing of the file /admin/cmsVote/save of the component …

Nov 13, 2024
CVE-2024-10013
7.8 HIGH

In Progress Telerik UI for WinForms versions prior to 2024 Q4 (2024.4.1113), a code execution attack is possible through an insecure deserialization vulnerability.

Nov 13, 2024
CVE-2024-10012
7.8 HIGH

In Progress Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1111), a code execution attack is possible through an insecure deserialization vulnerability.

Nov 13, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.