CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-48011
3.1 LOW

Dell PowerProtect DD, versions prior to 7.7.5.50, contains an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. A low privileged attacker with remote access …

Nov 8, 2024
CVE-2024-48010
6.5 MEDIUM

Dell PowerProtect DD, versions prior to 8.1.0.0, 7.13.1.10, 7.10.1.40, and 7.7.5.50, contains an access control vulnerability. A remote high privileged attacker could potentially exploit this …

Nov 8, 2024
CVE-2024-45759
6.8 MEDIUM

Dell PowerProtect Data Domain, versions prior to 8.1.0.0, 7.13.1.10, 7.10.1.40, and 7.7.5.50, contains an escalation of privilege vulnerability. A local low privileged attacker could potentially …

Nov 8, 2024
CVE-2024-8424
7.8 HIGH

Improper Privilege Management vulnerability in WatchGuard EPDR, Panda AD360 and Panda Dome on Windows (PSANHost.exe module) allows arbitrary file delete with SYSTEM permissions. This issue …

Nov 8, 2024
CVE-2024-51998
8.6 HIGH

changedetection.io is a free open source web page change detection tool. The validation for the file URI scheme falls short, and results in an attacker …

Nov 8, 2024
CVE-2024-51987
5.4 MEDIUM

Duende.AccessTokenManagement.OpenIdConnect is a set of .NET libraries that manage OAuth and OpenId Connect access tokens. HTTP Clients created by `AddUserAccessTokenHttpClient` may use a different user's …

Nov 8, 2024
CVE-2024-47072
7.5 HIGH

XStream is a simple library to serialize objects to XML and back again. This vulnerability may allow a remote attacker to terminate the application with …

Nov 8, 2024
CVE-2024-8810
6.5 MEDIUM

A GitHub App installed in organizations could upgrade some permissions from read to write access without approval from an organization administrator. An attacker would require …

Nov 7, 2024
CVE-2024-51434
6.1 MEDIUM

Inconsistent <plaintext> tag parsing allows for XSS in Froala WYSIWYG editor 4.3.0 and earlier.

Nov 7, 2024
CVE-2024-50766
9.8 CRITICAL

SourceCodester Survey Application System 1.0 is vulnerable to SQL Injection in takeSurvey.php via the id parameter.

Nov 7, 2024
CVE-2024-49524
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute …

Nov 7, 2024
CVE-2024-49523
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject …

Nov 7, 2024
CVE-2024-46961
8.1 HIGH

The Inshot com.downloader.privatebrowser (aka Video Downloader - XDownloader) application through 1.3.5 for Android allows an attacker to execute arbitrary JavaScript code via the com.downloader.privatebrowser.activity.PrivateMainActivity component.

Nov 7, 2024
CVE-2024-46960
8.8 HIGH

The ASD com.rocks.video.downloader (aka HD Video Downloader All Format) application through 7.0.129 for Android allows an attacker to execute arbitrary JavaScript code via the com.rocks.video.downloader.MainBrowserActivity …

Nov 7, 2024
CVE-2024-36064
6.2 MEDIUM

The NLL com.nll.cb (aka ACR Phone) application through 0.330-playStore-NoAccessibility-arm8 for Android allows any installed application (with no permissions) to place phone calls without user interaction …

Nov 7, 2024
CVE-2024-36063
7.5 HIGH

The Goodwy com.goodwy.dialer (aka Right Dialer) application through 5.1.0 for Android enables any application (with no permissions) to place phone calls without user interaction by …

Nov 7, 2024
CVE-2024-36062
4.0 MEDIUM

The com.callassistant.android (aka AI Call Assistant & Screener) application 1.174 for Android enables any installed application (with no permissions) to place phone calls without user …

Nov 7, 2024
CVE-2024-10824
6.5 MEDIUM

An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed unauthorized internal users to access sensitive secret scanning alert data intended only for …

Nov 7, 2024
CVE-2024-50599
6.1 MEDIUM

A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Zimbra Collaboration Suite (ZCS) 8.8.15, affecting one of the webmail calendar endpoints. This arises from …

Nov 7, 2024
CVE-2024-10975
7.7 HIGH

Nomad Community and Nomad Enterprise ("Nomad") volume specification is vulnerable to arbitrary cross-namespace volume creation through unauthorized Container Storage Interface (CSI) volume writes. This vulnerability, …

Nov 7, 2024
CVE-2024-10007
9.1 CRITICAL

A path collision and arbitrary code execution vulnerability was identified in GitHub Enterprise Server that allowed container escape to escalate to root via ghe-firejail path. …

Nov 7, 2024
CVE-2019-20472
6.2 MEDIUM

An issue was discovered on One2Track 2019-12-08 devices. Any SIM card used with the device cannot have a PIN configured. If a PIN is configured, …

Nov 7, 2024
CVE-2019-20469
4.6 MEDIUM

An issue was discovered on One2Track 2019-12-08 devices. Confidential information is needlessly stored on the smartwatch. Audio files are stored in .amr format, in the …

Nov 7, 2024
CVE-2019-20462
5.3 MEDIUM

An issue was discovered on Alecto IVM-100 2019-11-12 devices. The device comes with a serial interface at the board level. By attaching to this serial …

Nov 7, 2024
CVE-2019-20461
9.8 CRITICAL

An issue was discovered on Alecto IVM-100 2019-11-12 devices. The device uses a custom UDP protocol to start and control video and audio services. The …

Nov 7, 2024
CVE-2019-20460
8.8 HIGH

An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices. POST requests don't require (anti-)CSRF tokens or other mechanisms for validating that the request …

Nov 7, 2024
CVE-2024-10969
7.3 HIGH

A vulnerability was found in 1000 Projects Bookstore Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

Nov 7, 2024
CVE-2024-10968
7.3 HIGH

A vulnerability was found in 1000 Projects Bookstore Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Nov 7, 2024
CVE-2024-51995
7.1 HIGH

Combodo iTop is a web based IT Service Management tool. An attacker can request any `route` we want as long as we specify an `operation` …

Nov 7, 2024
CVE-2024-51994
5.4 MEDIUM

Combodo iTop is a web based IT Service Management tool. In affected versions uploading a text file containing some java script in the portal will …

Nov 7, 2024
CVE-2024-51993
3.4 LOW

Combodo iTop is a web based IT Service Management tool. An attacker accessing a backup file or the database can read some passwords for misconfigured …

Nov 7, 2024
CVE-2024-51989
7.1 HIGH

Password Pusher is an open source application to communicate sensitive information over the web. A cross-site scripting (XSS) vulnerability was identified in the PasswordPusher application, …

Nov 7, 2024
CVE-2024-51758

Filament is a collection of full-stack components for accelerated Laravel development. All Filament features that interact with storage use the `default_filesystem_disk` config option. This allows …

Nov 7, 2024
CVE-2024-51428
7.5 HIGH

An issue in Espressif Esp idf v5.3.0 allows attackers to cause a Denial of Service (DoS) via a crafted data channel packet.

Nov 7, 2024
CVE-2024-48290
4.3 MEDIUM

An issue in the Bluetooth Low Energy implementation of Realtek RTL8762E BLE SDK v1.4.0 allows attackers to cause a Denial of Service (DoS) via supplying …

Nov 7, 2024
CVE-2024-47073
9.1 CRITICAL

DataEase is an open source data visualization analysis tool that helps users quickly analyze data and gain insights into business trends. In affected versions a …

Nov 7, 2024
CVE-2024-45794
8.3 HIGH

devtron is an open source tool integration platform for Kubernetes. In affected versions an authenticated user (with minimum permission) could utilize and exploit SQL Injection …

Nov 7, 2024
CVE-2024-10967
7.3 HIGH

A vulnerability was found in code-projects E-Health Care System 1.0. It has been classified as critical. Affected is an unknown function of the file /Doctor/delete_user_appointment_request.php. …

Nov 7, 2024
CVE-2024-10966
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in TOTOLINK X18 9.1.0cu.2024_B20220329. Affected by this issue is some unknown functionality of the file …

Nov 7, 2024
CVE-2020-11926
7.5 HIGH

An issue was discovered in Luvion Grand Elite 3 Connect through 2020-02-25. Clients can authenticate themselves to the device using a username and password. These …

Nov 7, 2024
CVE-2020-11921
8.8 HIGH

An issue was discovered in Lush 2 through 2020-02-25. Due to the lack of Bluetooth traffic encryption, it is possible to hijack an ongoing Bluetooth …

Nov 7, 2024
CVE-2020-11919
8.0 HIGH

An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. There is no CSRF protection.

Nov 7, 2024
CVE-2020-11918
5.4 MEDIUM

An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. When a backup file is created through the web interface, information on all users, including passwords, can …

Nov 7, 2024
CVE-2020-11917
4.3 MEDIUM

An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. It uses a default SSID value, which makes it easier for remote attackers to discover the physical …

Nov 7, 2024
CVE-2020-11916
6.3 MEDIUM

An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. The password for the root user is hashed using an old and deprecated hashing technique. Because of …

Nov 7, 2024
CVE-2019-20459
8.4 HIGH

An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices. With the SNMPv1 public community, all values can be read, and with the epson …

Nov 7, 2024
CVE-2019-20458
8.8 HIGH

An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices. By default, the device comes (and functions) without a password. The user is at …

Nov 7, 2024
CVE-2019-20457
9.1 CRITICAL

An issue was discovered on Brother MFC-J491DW C1806180757 devices. The printer's web-interface password hash can be retrieved without authentication, because the response header of any …

Nov 7, 2024
CVE-2024-48954
6.4 MEDIUM

An issue was discovered in Logpoint before 7.5.0. Unvalidated input during the EventHub Collector setup by an authenticated user leads to Remote Code execution.

Nov 7, 2024
CVE-2024-48953
7.5 HIGH

An issue was discovered in Logpoint before 7.5.0. Endpoints for creating, editing, or deleting third-party authentication modules lacked proper authorization checks. This allowed unauthenticated users …

Nov 7, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.