CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-34681
6.6 MEDIUM

Improper input validation in BluetoothAdapter prior to SMR Nov-2024 Release 1 allows local attackers to cause local permanent denial of service on Galaxy Watch.

Nov 6, 2024
CVE-2024-34680
4.0 MEDIUM

Use of implicit intent for sensitive communication in WlanTest prior to SMR Nov-2024 Release 1 allows local attackers to get sensitive information.

Nov 6, 2024
CVE-2024-34679
4.0 MEDIUM

Incorrect default permissions in Crane prior to SMR Nov-2024 Release 1 allows local attackers to access files with phone privilege.

Nov 6, 2024
CVE-2024-34678
5.9 MEDIUM

Out-of-bounds write in libsapeextractor.so prior to SMR Nov-2024 Release 1 allows local attackers to cause memory corruption.

Nov 6, 2024
CVE-2024-34677
4.0 MEDIUM

Exposure of sensitive information in System UI prior to SMR Nov-2024 Release 1 allow local attackers to make malicious apps appear as legitimate.

Nov 6, 2024
CVE-2024-34676
4.4 MEDIUM

Out-of-bounds write in parsing subtitle file in libsubextractor.so prior to SMR Nov-2024 Release 1 allows local attackers to cause memory corruption. User interaction is required …

Nov 6, 2024
CVE-2024-34675
2.4 LOW

Improper access control in Dex Mode prior to SMR Nov-2024 Release 1 allows physical attackers to temporarily access to unlocked screen.

Nov 6, 2024
CVE-2024-34674
4.6 MEDIUM

Improper access control in Contacts prior to SMR Nov-2024 Release 1 allows physical attackers to access data across multiple user profiles.

Nov 6, 2024
CVE-2024-34673
4.1 MEDIUM

Improper Input Validation in IpcProtocol in Modem prior to SMR Nov-2024 Release 1 allows local attackers to cause Denial-of-Service.

Nov 6, 2024
CVE-2024-10647
6.1 MEDIUM

The WS Form LITE – Drag & Drop Contact Form Builder for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the …

Nov 6, 2024
CVE-2024-10028
7.5 HIGH

The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up …

Nov 6, 2024
CVE-2024-51358
9.8 CRITICAL

An issue in Linux Server Heimdall v.2.6.1 allows a remote attacker to execute arbitrary code via a crafted script to the Add new application.

Nov 5, 2024
CVE-2024-51115
9.8 CRITICAL

DCME-320 v7.4.12.90 was discovered to contain a command injection vulnerability.

Nov 5, 2024
CVE-2024-48746
9.8 CRITICAL

An issue in Lens Visual integration with Power BI v.4.0.0.3 allows a remote attacker to execute arbitrary code via the Natural language processing component

Nov 5, 2024
CVE-2024-48176
9.8 CRITICAL

Lylme Spage v1.9.5 is vulnerable to Incorrect Access Control. There is no limit on the number of login attempts, and the verification code will not …

Nov 5, 2024
CVE-2024-47464
6.8 MEDIUM

An authenticated Path Traversal vulnerability exists in Instant AOS-8 and AOS-10. Successful exploitation of this vulnerability allows an attacker to copy arbitrary files to a …

Nov 5, 2024
CVE-2024-47463
7.2 HIGH

An arbitrary file creation vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. Successful exploitation of this vulnerability could allow an authenticated remote …

Nov 5, 2024
CVE-2024-47462
7.2 HIGH

An arbitrary file creation vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. Successful exploitation of this vulnerability could allow an authenticated remote …

Nov 5, 2024
CVE-2024-47461
7.2 HIGH

An authenticated command injection vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. A successful exploitation of this vulnerability results in the ability …

Nov 5, 2024
CVE-2024-47460
9.0 CRITICAL

Command injection vulnerability in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's …

Nov 5, 2024
CVE-2024-42509
9.8 CRITICAL

Command injection vulnerability in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's …

Nov 5, 2024
CVE-2024-51756

The cap-std project is organized around the eponymous `cap-std` crate, and develops libraries to make it easy to write capability-based code. cap-std's filesystem sandbox implementation …

Nov 5, 2024
CVE-2024-51745
10.0 CRITICAL

Wasmtime is a fast and secure runtime for WebAssembly. Wasmtime's filesystem sandbox implementation on Windows blocks access to special device filenames such as "COM1", "COM2", …

Nov 5, 2024
CVE-2024-51116
8.8 HIGH

Tenda AC6 v2.0 V15.03.06.50 was discovered to contain a buffer overflow in the function 'formSetPPTPServer'.

Nov 5, 2024
CVE-2024-10084
4.3 MEDIUM

The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Basic Information Disclosure in all versions up to, and including, 4.5 …

Nov 5, 2024
CVE-2024-7995
7.8 HIGH

A maliciously crafted binary file when downloaded could lead to escalation of privileges to NT AUTHORITY/SYSTEM due to an untrusted search path being utilized in …

Nov 5, 2024
CVE-2024-51753

The AuthKit library for Remix provides convenient helpers for authentication and session management using WorkOS & AuthKit with Remix. In affected versions refresh tokens are …

Nov 5, 2024
CVE-2024-51752
5.5 MEDIUM

The AuthKit library for Next.js provides convenient helpers for authentication and session management using WorkOS & AuthKit with Next.js. In affected versions refresh tokens are …

Nov 5, 2024
CVE-2024-51746

Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. gitsign may select the wrong Rekor entry …

Nov 5, 2024
CVE-2024-51740
4.3 MEDIUM

Combodo iTop is a simple, web based IT Service Management tool. This vulnerability can be used to create HTTP requests on behalf of the server, …

Nov 5, 2024
CVE-2024-51735

Osmedeus is a Workflow Engine for Offensive Security. Cross-site Scripting (XSS) occurs on the Osmedues web server when viewing results from the workflow, allowing commands …

Nov 5, 2024
CVE-2024-51493
5.3 MEDIUM

OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.10.2 contain a vulnerability that allows an attacker that …

Nov 5, 2024
CVE-2024-51382
8.4 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in JATOS v3.9.3 allows an attacker to reset the administrator's password. This critical security flaw can result in unauthorized access …

Nov 5, 2024
CVE-2024-51381
8.4 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in JATOS v3.9.3 that allows attackers to perform actions reserved for administrators, including creating admin accounts. This critical flaw can …

Nov 5, 2024
CVE-2024-51380
8.4 HIGH

Stored Cross-Site Scripting (XSS) vulnerability discovered in the Properties Component of JATOS v3.9.3. This flaw allows an attacker to inject malicious JavaScript into the properties …

Nov 5, 2024
CVE-2024-51379
8.4 HIGH

Stored Cross-Site Scripting (XSS) vulnerability discovered in JATOS v3.9.3. The vulnerability exists in the description component of the study section, where an attacker can inject …

Nov 5, 2024
CVE-2024-51240
8.0 HIGH

An issue in the luci-mod-rpc package in OpenWRT Luci LTS allows for privilege escalation from an admin account to root via the JSON-RPC-API, which is …

Nov 5, 2024
CVE-2024-50335
4.9 MEDIUM

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. The "Publish Key" field in SuiteCRM's Edit Profile page is vulnerable to Reflected Cross-Site …

Nov 5, 2024
CVE-2024-50333
6.6 MEDIUM

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. User input is not validated and is written to the filesystem. The ParserLabel::addLabels() function …

Nov 5, 2024
CVE-2024-50332
8.8 HIGH

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Insufficient input value validation causes Blind SQL injection in DeleteRelationShip. This issue has been …

Nov 5, 2024
CVE-2024-49774
7.2 HIGH

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. SuiteCRM relies on the blacklist of functions/methods to prevent installation of malicious MLPs. But …

Nov 5, 2024
CVE-2024-49773
5.3 MEDIUM

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Poor input validation in export allows authenticated user do a SQL injection attack. User-controlled …

Nov 5, 2024
CVE-2024-49772
8.8 HIGH

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In SuiteCRM versions 7.14.4, poor input validation allows authenticated user do a SQL injection …

Nov 5, 2024
CVE-2024-49377
5.5 MEDIUM

OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.10.2 contain reflected XSS vulnerabilities in the login dialog …

Nov 5, 2024
CVE-2024-0134
4.1 MEDIUM

NVIDIA Container Toolkit and NVIDIA GPU Operator for Linux contain a UNIX vulnerability where a specially crafted container image can lead to the creation of …

Nov 5, 2024
CVE-2024-51739
7.5 HIGH

Combodo iTop is a simple, web based IT Service Management tool. Unauthenticated user can perform users enumeration, which can make it easier to bruteforce a …

Nov 5, 2024
CVE-2024-50138
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: Use raw_spinlock_t in ringbuf The function __bpf_ringbuf_reserve is invoked from a tracepoint, which disables …

Nov 5, 2024
CVE-2024-50137
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: reset: starfive: jh71x0: Fix accessing the empty member on JH7110 SoC data->asserted will be NULL …

Nov 5, 2024
CVE-2024-50136
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Unregister notifier on eswitch init failure It otherwise remains registered and a subsequent attempt …

Nov 5, 2024
CVE-2024-50135
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nvme-pci: fix race condition between reset and nvme_dev_disable() nvme_dev_disable() modifies the dev->online_queues field, therefore nvme_pci_update_nr_queues() …

Nov 5, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.