CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-50144
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/xe: fix unbalanced rpm put() with fence_fini() Currently we can call fence_fini() twice if something …

Nov 7, 2024
CVE-2024-50143
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: udf: fix uninit-value use in udf_get_fileshortad Check for overflow when computing alen in udf_current_aext to …

Nov 7, 2024
CVE-2024-50142
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: xfrm: validate new SA's prefixlen using SA family when sel.family is unset This expands the …

Nov 7, 2024
CVE-2024-50141
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ACPI: PRM: Find EFI_MEMORY_RUNTIME block for PRM handler and context PRMT needs to find the …

Nov 7, 2024
CVE-2024-50140
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sched/core: Disable page allocation in task_tick_mm_cid() With KASAN and PREEMPT_RT enabled, calling task_work_add() in task_tick_mm_cid() …

Nov 7, 2024
CVE-2024-50139
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Fix shift-out-of-bounds bug Fix a shift-out-of-bounds bug reported by UBSAN when running VM …

Nov 7, 2024
CVE-2024-10203
7.0 HIGH

Zohocorp ManageEngine EndPoint Central versions 11.3.2416.21 and below, 11.3.2428.9 and below are vulnerable to Arbitrary File Deletion in the agent installed machines.

Nov 7, 2024
CVE-2023-1973
7.5 HIGH

A flaw was found in Undertow package. Using the FormAuthenticationMechanism, a malicious user could trigger a Denial of Service by sending crafted requests, leading the …

Nov 7, 2024
CVE-2023-1932
6.1 MEDIUM

A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. …

Nov 7, 2024
CVE-2024-30142
3.8 LOW

HCL BigFix Compliance is affected by a missing secure flag on a cookie. If a secure flag is not set, cookies may be stolen by …

Nov 7, 2024
CVE-2024-30141
4.7 MEDIUM

HCL BigFix Compliance is vulnerable to the generation of error messages containing sensitive information. Detailed error messages can provide enticement information or expose information about …

Nov 7, 2024
CVE-2024-30140
5.4 MEDIUM

HCL BigFix Compliance is affected by unvalidated redirects and forwards. The HOST header can be manipulated by an attacker and as a result, it can …

Nov 7, 2024
CVE-2024-38286
8.6 HIGH

Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from …

Nov 7, 2024
CVE-2024-10027
4.8 MEDIUM

The WP Booking Calendar WordPress plugin before 10.6.3 does not sanitise and escape some of its Widgets settings, which could allow high privilege users such …

Nov 7, 2024
CVE-2024-10947
4.7 MEDIUM

A vulnerability classified as critical was found in Guangzhou Tuchuang Computer Software Development Interlib Library Cluster Automation Management System up to 2.0.1. This vulnerability affects …

Nov 7, 2024
CVE-2024-10946
4.7 MEDIUM

A vulnerability classified as critical has been found in Guangzhou Tuchuang Computer Software Development Interlib Library Cluster Automation Management System up to 2.0.1. This affects …

Nov 7, 2024
CVE-2024-51990

jj, or Jujutsu, is a Git-compatible VCS written in rust. In affected versions specially crafted Git repositories can cause `jj` to write files outside the …

Nov 7, 2024
CVE-2024-51409
6.5 MEDIUM

Buffer Overflow vulnerability in Tenda O3 v.1.0.0.5 allows a remote attacker to cause a denial of service via a network packet in a fixed format …

Nov 6, 2024
CVE-2024-48325
8.1 HIGH

Portabilis i-Educar 2.8.0 is vulnerable to SQL Injection in the "getDocuments" function of the "InstituicaoDocumentacaoController" class. The "instituicao_id" parameter in "/module/Api/InstituicaoDocumentacao?oper=get&resource=getDocuments&instituicao_id" is not properly sanitized, …

Nov 6, 2024
CVE-2024-10928
3.5 LOW

A vulnerability was found in MonoCMS up to 20240528. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the …

Nov 6, 2024
CVE-2024-10927
3.5 LOW

A vulnerability was found in MonoCMS up to 20240528. It has been classified as problematic. Affected is an unknown function of the file /monofiles/account.php of …

Nov 6, 2024
CVE-2024-51736
0.0 NONE

Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. On Windows, when an executable file named `cmd.exe` is located …

Nov 6, 2024
CVE-2024-50345
3.1 LOW

symfony/http-foundation is a module for the Symphony PHP framework which defines an object-oriented layer for the HTTP specification. The `Request` class, does not parse URI …

Nov 6, 2024
CVE-2024-50343
3.1 LOW

symfony/validator is a module for the Symphony PHP framework which provides tools to validate values. It is possible to trick a `Validator` configured with a …

Nov 6, 2024
CVE-2024-50342
3.1 LOW

symfony/http-client is a module for the Symphony PHP framework which provides powerful methods to fetch HTTP resources synchronously or asynchronously. When using the `NoPrivateNetworkHttpClient`, some …

Nov 6, 2024
CVE-2024-50341
3.1 LOW

symfony/security-bundle is a module for the Symphony PHP framework which provides a tight integration of the Security component into the Symfony full-stack framework. The custom …

Nov 6, 2024
CVE-2024-50340
7.3 HIGH

symfony/runtime is a module for the Symphony PHP framework which enables decoupling PHP applications from global state. When the `register_argv_argc` php directive is set to …

Nov 6, 2024
CVE-2024-10941
6.5 MEDIUM

A malicious website could have included an iframe with an malformed URI resulting in a non-exploitable browser crash. This vulnerability affects Firefox < 126.

Nov 6, 2024
CVE-2024-10926
3.5 LOW

A vulnerability was found in IBPhoenix ibWebAdmin up to 1.0.2 and classified as problematic. This issue affects some unknown processing of the file /toggle_fold_panel.php of …

Nov 6, 2024
CVE-2024-51988
6.5 MEDIUM

RabbitMQ is a feature rich, multi-protocol messaging and streaming broker. In affected versions queue deletion via the HTTP API was not verifying the `configure` permission …

Nov 6, 2024
CVE-2024-51757

happy-dom is a JavaScript implementation of a web browser without its graphical user interface. Versions of happy-dom prior to 15.10.2 may execute code on the …

Nov 6, 2024
CVE-2024-51755
2.2 LOW

Twig is a template language for PHP. In a sandbox, an attacker can access attributes of Array-like objects as they were not checked by the …

Nov 6, 2024
CVE-2024-51754
2.2 LOW

Twig is a template language for PHP. In a sandbox, an attacker can call `__toString()` on an object even if the `__toString()` method is not …

Nov 6, 2024
CVE-2024-51751
6.5 MEDIUM

Gradio is an open-source Python package designed to enable quick builds of a demo or web application. If File or UploadButton components are used as …

Nov 6, 2024
CVE-2024-50637
5.4 MEDIUM

UnoPim 0.1.3 and below is vulnerable to Cross Site Scripting (XSS) in the Create User function. This allows attackers to perform XSS via an SVG …

Nov 6, 2024
CVE-2024-20540
5.4 MEDIUM

A vulnerability in the web-based management interface of Cisco Unified Contact Center Management Portal (Unified CCMP) could allow an authenticated, remote attacker with low privileges …

Nov 6, 2024
CVE-2024-20539
4.8 MEDIUM

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct a stored XSS attack against a user …

Nov 6, 2024
CVE-2024-20538
6.1 MEDIUM

A vulnerability in the web-based management interface of Cisco ISE could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of …

Nov 6, 2024
CVE-2024-20537
6.5 MEDIUM

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to bypass the authorization mechanisms for specific administrative functions. …

Nov 6, 2024
CVE-2024-20536
8.8 HIGH

A vulnerability in a REST API endpoint and web-based management interface of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, remote attacker with …

Nov 6, 2024
CVE-2024-20534
4.8 MEDIUM

A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 6800, 7800, and 8800 Series, and Cisco Video Phone 8875 …

Nov 6, 2024
CVE-2024-20533
4.8 MEDIUM

A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 6800, 7800, and 8800 Series, and Cisco Video Phone 8875 …

Nov 6, 2024
CVE-2024-20532
5.5 MEDIUM

A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read and delete arbitrary files on an affected device. To …

Nov 6, 2024
CVE-2024-20531
5.5 MEDIUM

A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system of an …

Nov 6, 2024
CVE-2024-20530
6.1 MEDIUM

A vulnerability in the web-based management interface of Cisco ISE could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of …

Nov 6, 2024
CVE-2024-20529
5.5 MEDIUM

A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read and delete arbitrary files on an affected device. To …

Nov 6, 2024
CVE-2024-20528
3.8 LOW

A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to upload files to arbitrary locations on the underlying operating system …

Nov 6, 2024
CVE-2024-20527
5.5 MEDIUM

A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read and delete arbitrary files on an affected device. To …

Nov 6, 2024
CVE-2024-20525
6.1 MEDIUM

A vulnerability in the web-based management interface of Cisco ISE could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of …

Nov 6, 2024
CVE-2024-20514
5.4 MEDIUM

A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, low-privileged, remote attacker …

Nov 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.