CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-20511
6.1 MEDIUM

A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) …

Nov 6, 2024
CVE-2024-20507
4.3 MEDIUM

A vulnerability in the logging subsystem of Cisco Meeting Management could allow an authenticated, remote attacker to view sensitive information in clear text on an …

Nov 6, 2024
CVE-2024-20504
5.4 MEDIUM

A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, Secure Email Gateway, and Secure Web Appliance …

Nov 6, 2024
CVE-2024-20487
4.3 MEDIUM

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct a stored XSS attack against a user …

Nov 6, 2024
CVE-2024-20484
7.5 HIGH

A vulnerability in the External Agent Assignment Service (EAAS) feature of Cisco Enterprise Chat and Email (ECE) could allow an unauthenticated, remote attacker to cause …

Nov 6, 2024
CVE-2024-20476
4.3 MEDIUM

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to bypass the authorization mechanisms for specific file management …

Nov 6, 2024
CVE-2024-20457
6.5 MEDIUM

A vulnerability in the logging component of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an authenticated, remote attacker to …

Nov 6, 2024
CVE-2024-20445
5.3 MEDIUM

A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 could …

Nov 6, 2024
CVE-2024-20418
10.0 CRITICAL

A vulnerability in the web-based management interface of Cisco Unified Industrial Wireless Software for Cisco Ultra-Reliable Wireless Backhaul (URWB) Access Points could allow an unauthenticated, …

Nov 6, 2024
CVE-2024-20371
5.3 MEDIUM

A vulnerability in the access control list (ACL) programming of Cisco Nexus 3550-F Switches could allow an unauthenticated, remote attacker to send traffic that should …

Nov 6, 2024
CVE-2024-10827
8.8 HIGH

Use after free in Serial in Google Chrome prior to 130.0.6723.116 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Nov 6, 2024
CVE-2024-10826
8.8 HIGH

Use after free in Family Experiences in Google Chrome on Android prior to 130.0.6723.116 allowed a remote attacker to potentially exploit heap corruption via a …

Nov 6, 2024
CVE-2024-10318
5.4 MEDIUM

A session fixation issue was discovered in the NGINX OpenID Connect reference implementation, where a nonce was not checked at login time. This flaw allows …

Nov 6, 2024
CVE-2024-10920
3.1 LOW

A vulnerability was found in mariazevedo88 travels-java-api up to 5.0.1 and classified as problematic. Affected by this issue is the function doFilterInternal of the file …

Nov 6, 2024
CVE-2024-10919
6.3 MEDIUM

A vulnerability has been found in didi Super-Jacoco 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /cov/triggerUnitCover. …

Nov 6, 2024
CVE-2024-6861
7.5 HIGH

A disclosure of sensitive information flaw was found in foreman via the GraphQL API. If the introspection feature is enabled, it is possible for attackers …

Nov 6, 2024
CVE-2024-35146
5.4 MEDIUM

IBM Maximo Application Suite - Monitor Component 8.10.11, 8.11.8, and 9.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary …

Nov 6, 2024
CVE-2024-10916
5.3 MEDIUM

A vulnerability classified as problematic has been found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. This affects an unknown part of the …

Nov 6, 2024
CVE-2024-10082
8.7 HIGH

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication method confusion allows logging in as …

Nov 6, 2024
CVE-2024-10081
10.0 CRITICAL

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication bypass occurs when the API URL …

Nov 6, 2024
CVE-2024-10915
8.1 HIGH

A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been rated as critical. Affected by this issue is …

Nov 6, 2024
CVE-2024-10914
8.1 HIGH

A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been declared as critical. Affected by this vulnerability is …

Nov 6, 2024
CVE-2020-11859
7.6 HIGH

Improper Input Validation vulnerability in OpenText iManager allows Cross-Site Scripting (XSS). This issue affects iManager before 3.2.3

Nov 6, 2024
CVE-2024-10186
6.4 MEDIUM

The Event post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's events_cal shortcode in all versions up to, and including, 5.9.6 …

Nov 6, 2024
CVE-2024-8323
6.4 MEDIUM

The Pricing Tables WordPress Plugin – Easy Pricing Tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘fontFamily’ attribute in all versions …

Nov 6, 2024
CVE-2024-10168
6.4 MEDIUM

The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's woot_button shortcode …

Nov 6, 2024
CVE-2024-10715
6.4 MEDIUM

The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Map block in all versions up to, and …

Nov 6, 2024
CVE-2024-9902
6.3 MEDIUM

A flaw was found in Ansible. The ansible-core `user` module can allow an unprivileged user to silently create or replace the contents of any file …

Nov 6, 2024
CVE-2024-8615
10.0 CRITICAL

The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jobsearch_location_load_excel_file_callback() function in …

Nov 6, 2024
CVE-2024-8614
9.9 CRITICAL

The JobSearch WP Job Board plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jobsearch_wp_handle_upload() function in …

Nov 6, 2024
CVE-2024-9681
6.5 MEDIUM

When curl is asked to use HSTS, the expiry time for a subdomain might overwrite a parent domain's cache entry, making it end sooner or …

Nov 6, 2024
CVE-2024-52043
5.3 MEDIUM

Generation of Error Message Containing Sensitive Information in HumHub GmbH & Co. KG - HumHub on Linux allows: Excavation (user enumeration).This issue affects all released …

Nov 6, 2024
CVE-2024-9946
8.1 HIGH

The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to authentication bypass in all versions up to, …

Nov 6, 2024
CVE-2024-9307
9.9 CRITICAL

The mFolio Lite plugin for WordPress is vulnerable to file uploads due to a missing capability check in all versions up to, and including, 1.2.1. …

Nov 6, 2024
CVE-2024-6626
5.3 MEDIUM

The EleForms – All In One Form Integration including DB for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a …

Nov 6, 2024
CVE-2024-10543
4.3 MEDIUM

The Tumult Hype Animations plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the hypeanimations_getcontent function in …

Nov 6, 2024
CVE-2024-10535
5.3 MEDIUM

The Video Gallery for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the remove_unused_thumbnails() function …

Nov 6, 2024
CVE-2024-10020
8.1 HIGH

The Heateor Social Login WordPress plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.1.35. This is due to …

Nov 6, 2024
CVE-2024-9934
6.1 MEDIUM

The Wp-ImageZoom WordPress plugin through 1.1.0 does not sanitise and escape some parameters before outputting them back in a page, leading to a Reflected Cross-Site …

Nov 6, 2024
CVE-2024-7879
4.8 MEDIUM

The WP ULike WordPress plugin before 4.7.5 does not sanitise and escape some of its settings, which could allow high privilege users such as editors …

Nov 6, 2024
CVE-2024-49409
6.4 MEDIUM

Out-of-bounds write in Battery Full Capacity node prior to Firmware update Sep-2024 Release on Galaxy S24 allows local attackers to write out-of-bounds memory. System privilege …

Nov 6, 2024
CVE-2024-49408
6.4 MEDIUM

Out-of-bounds write in usb driver prior to Firmware update Sep-2024 Release on Galaxy S24 allows local attackers to write out-of-bounds memory. System privilege is required …

Nov 6, 2024
CVE-2024-49407
4.6 MEDIUM

Improper access control in Samsung Flow prior to version 4.9.15.7 allows physical attackers to access data across multiple user profiles.

Nov 6, 2024
CVE-2024-49406
6.7 MEDIUM

Improper validation of integrity check value in Blockchain Keystore prior to version 1.3.16 allows local attackers to modify transaction. Root privilege is required for triggering …

Nov 6, 2024
CVE-2024-49405
5.3 MEDIUM

Improper authentication in Private Info in Samsung Pass in prior to version 4.4.04.7 allows physical attackers to access sensitive information in a specific scenario.

Nov 6, 2024
CVE-2024-49404
5.5 MEDIUM

Improper Access Control in Samsung Video Player prior to versions 7.3.29.1 in Android 12, 7.3.36.1 in Android 13, and 7.3.41.230 in Android 14 allows physical …

Nov 6, 2024
CVE-2024-49403
4.6 MEDIUM

Improper access control in Samsung Voice Recorder prior to version 21.5.40.37 allows physical attackers to access recording files on the lock screen.

Nov 6, 2024
CVE-2024-49402
4.6 MEDIUM

Improper input validation in Dressroom prior to SMR Nov-2024 Release 1 allow physical attackers to access data across multiple user profiles.

Nov 6, 2024
CVE-2024-49401
5.1 MEDIUM

Improper input validation in Settings Suggestions prior to SMR Nov-2024 Release 1 allows local attackers to launch privileged activities.

Nov 6, 2024
CVE-2024-34682
2.4 LOW

Improper authorization in Settings prior to SMR Nov-2024 Release 1 allows physical attackers to access stored WiFi password in Maintenance Mode.

Nov 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.