CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-44812
9.8 CRITICAL

SQL Injection vulnerability in Online Complaint Site v.1.0 allows a remote attacker to escalate privileges via the username and password parameters in the /admin.index.php component.

Oct 22, 2024
CVE-2024-44331
7.5 HIGH

Incorrect Access Control in GStreamer RTSP server 1.25.0 in gst-rtsp-server/rtsp-media.c allows remote attackers to cause a denial of service via a series of specially crafted …

Oct 22, 2024
CVE-2024-43812
8.4 HIGH

Kieback & Peter's DDC4000 series has an insufficiently protected credentials vulnerability, which may allow an unauthenticated attacker with access to /etc/passwd to read the password …

Oct 22, 2024
CVE-2024-43698
9.8 CRITICAL

Kieback & Peter's DDC4000 series uses weak credentials, which may allow an unauthenticated attacker to get full admin rights on the system.

Oct 22, 2024
CVE-2024-42643
7.5 HIGH

Integer Overflow in fast_ping.c in SmartDNS Release46 allows remote attackers to cause a Denial of Service via misaligned memory access.

Oct 22, 2024
CVE-2024-41717
9.8 CRITICAL

Kieback & Peter's DDC4000 series is vulnerable to a path traversal vulnerability, which may allow an unauthenticated attacker to read files on the system.

Oct 22, 2024
CVE-2024-40494
9.8 CRITICAL

Buffer Overflow in coap_msg.c in FreeCoAP allows remote attackers to execute arbitrary code or cause a denial of service (stack buffer overflow) via a crafted …

Oct 22, 2024
CVE-2024-40493
9.8 CRITICAL

Null Pointer Dereference in `coap_client_exchange_blockwise2` function in Keith Cullen FreeCoAP 1.0 allows remote attackers to cause a denial of service and potentially execute arbitrary code …

Oct 22, 2024
CVE-2024-31029
8.2 HIGH

An issue in the server_handle_regular function of the test_coap_server.c file within the FreeCoAP project allows remote attackers to cause a Denial of Service through specially …

Oct 22, 2024
CVE-2024-26519
9.0 CRITICAL

An issue in Casa Systems NTC-221 version 2.0.99.0 and before allows a remote attacker to execute arbitrary code via a crafted payload to the /www/cgi-bin/nas.cgi …

Oct 22, 2024
CVE-2024-10231
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 130.0.6723.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Oct 22, 2024
CVE-2024-10230
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 130.0.6723.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Oct 22, 2024
CVE-2024-10229
8.1 HIGH

Inappropriate implementation in Extensions in Google Chrome prior to 130.0.6723.69 allowed a remote attacker to bypass site isolation via a crafted Chrome Extension. (Chromium security …

Oct 22, 2024
CVE-2024-48919

Cursor is a code editor built for programming with AI. Prior to Sep 27, 2024, if a user generated a terminal command via Cursor's Terminal …

Oct 22, 2024
CVE-2024-45526
5.3 MEDIUM

An issue was discovered in OPC Foundation OPCFoundation/UA-.NETStandard through 1.5.374.78. A remote attacker can send requests with invalid credentials and cause the server performance to …

Oct 22, 2024
CVE-2024-48904
9.8 CRITICAL

An command injection vulnerability in Trend Micro Cloud Edge could allow a remote attacker to execute arbitrary code on affected appliances. Please note: authentication is …

Oct 22, 2024
CVE-2024-48903
7.8 HIGH

An improper access control vulnerability in Trend Micro Deep Security Agent 20 could allow a local attacker to escalate privileges on affected installations. Please note: …

Oct 22, 2024
CVE-2024-46903
6.5 MEDIUM

A vulnerability in Trend Micro Deep Discovery Inspector (DDI) versions 5.8 and above could allow an attacker to disclose sensitive information affected installations. Please note: …

Oct 22, 2024
CVE-2024-46902
8.4 HIGH

A vulnerability in Trend Micro Deep Discovery Inspector (DDI) versions 5.8 and above could allow an attacker to disclose sensitive information affected installations. Please note: …

Oct 22, 2024
CVE-2024-45335
8.4 HIGH

Trend Micro Antivirus One, version 3.10.4 and below contains a vulnerability that could allow an attacker to use a specifically crafted virus to allow itself …

Oct 22, 2024
CVE-2024-45334
7.8 HIGH

Trend Micro Antivirus One versions 3.10.4 and below (Consumer) is vulnerable to an Arbitrary Configuration Update that could allow unauthorized access to product configurations and …

Oct 22, 2024
CVE-2024-41183
7.8 HIGH

Trend Micro VPN, version 5.8.1012 and below is vulnerable to an arbitrary file overwrite under specific conditions that can lead to elevation of privileges.

Oct 22, 2024
CVE-2024-39753
7.5 HIGH

An modOSCE SQL Injection vulnerability in Trend Micro Apex One could allow a remote attacker to execute arbitrary code on affected installations. Please note: an …

Oct 22, 2024
CVE-2024-10183

A vulnerability in Jamf Pro's Jamf Remote Assist tool allows a local, non-privileged user to escalate their privileges to root on MacOS systems.

Oct 22, 2024
CVE-2024-9287
7.8 HIGH

A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, …

Oct 22, 2024
CVE-2024-9129

In versions of Zend Server 8.5 and prior to version 9.2 a format string injection was discovered. Reported by Dylan Marino

Oct 22, 2024
CVE-2024-49211
5.2 MEDIUM

Reflected XSS was discovered in a Dashboard Listing Archer Platform UX page in Archer Platform 6.x before version 2024.08. A remote unauthenticated attacker could potentially …

Oct 22, 2024
CVE-2024-49210
5.2 MEDIUM

Reflected XSS was discovered in an iView List Archer Platform UX page in Archer Platform 6.x before version 2024.09. A remote unauthenticated attacker could potentially …

Oct 22, 2024
CVE-2024-49209
6.5 MEDIUM

Archer Platform 2024.03 before version 2024.09 is affected by an API authorization bypass vulnerability related to supporting application files. A remote unprivileged attacker could potentially …

Oct 22, 2024
CVE-2024-49208
5.9 MEDIUM

Archer Platform 2024.03 before version 2024.08 is affected by an authorization bypass vulnerability related to supporting application files. A remote unprivileged attacker could potentially exploit …

Oct 22, 2024
CVE-2024-48708
5.4 MEDIUM

Collabtive 3.1 is vulnerable to Cross-Site Scripting (XSS) via the name parameter in (a) file tasklist.php under action = add/edit and in (b) file admin.php …

Oct 22, 2024
CVE-2024-48707
5.4 MEDIUM

Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the name parameter under (a) action=add or action=edit within managemilestone.php file and (b) action=addpro within admin.php …

Oct 22, 2024
CVE-2024-48706
5.4 MEDIUM

Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the title parameter with action=add or action=editform within the (a) managemessage.php file and (b) managetask.php file …

Oct 22, 2024
CVE-2024-48570
7.5 HIGH

Client Management System 1.0 was discovered to contain a SQL injection vulnerability via the Between Dates Reports parameter at /admin/bwdates-reports-ds.php.

Oct 22, 2024
CVE-2024-46538
4.8 MEDIUM

A cross-site scripting (XSS) vulnerability in pfsense v2.5.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the $pconfig …

Oct 22, 2024
CVE-2024-45518
8.8 HIGH

An issue was discovered in Zimbra Collaboration (ZCS) 10.1.x before 10.1.1, 10.0.x before 10.0.9, 9.0.0 before Patch 41, and 8.8.15 before Patch 46. It allows …

Oct 22, 2024
CVE-2024-49373
4.1 MEDIUM

No Fuss Computing Centurion ERP is open source enterprise resource planning (ERP) software. Prior to version 1.2.1, an authenticated user can view projects within organizations …

Oct 22, 2024
CVE-2024-48929
4.2 MEDIUM

Umbraco is a free and open source .NET content management system. In versions on the 13.x branch prior to 13.5.2 and versions on the 10.x …

Oct 22, 2024
CVE-2024-48927
4.6 MEDIUM

Umbraco, a free and open source .NET content management system, has a remote code execution issue in versions on the 13.x branch prior to 13.5.2, …

Oct 22, 2024
CVE-2024-48926
4.2 MEDIUM

Umbraco, a free and open source .NET content management system, has an insufficient session expiration issue in versions on the 13.x branch prior to 13.5.2, …

Oct 22, 2024
CVE-2024-48925
0.0 NONE

Umbraco, a free and open source .NET content management system, has an improper access control issue starting in version 14.0.0 and prior to version 14.3.0. …

Oct 22, 2024
CVE-2024-48605
7.8 HIGH

An issue in Helakuru Desktop Application v1.1 allows a local attacker to execute arbitrary code via the lack of proper validation of the wow64log.dll file.

Oct 22, 2024
CVE-2024-47819
4.2 MEDIUM

Umbraco, a free and open source .NET content management system, has a cross-site scripting vulnerability starting in version 14.0.0 and prior to versions 14.3.1 and …

Oct 22, 2024
CVE-2024-46240
4.8 MEDIUM

Collabtive 3.1 is vulnerable to Cross-site scripting (XSS) via the name parameter under action=system and the company/contact parameters under action=addcust within admin.php file.

Oct 22, 2024
CVE-2022-23862
7.8 HIGH

A Local Privilege Escalation issue was discovered in Y Soft SAFEQ 6 Build 53. The SafeQ JMX service running on port 9696 is vulnerable to …

Oct 22, 2024
CVE-2022-23861
5.4 MEDIUM

Multiple Stored Cross-Site Scripting vulnerabilities were discovered in Y Soft SAFEQ 6 Build 53. Multiple fields in the YSoft SafeQ web application can be used …

Oct 22, 2024
CVE-2024-8980
9.6 CRITICAL

The Script Console in Liferay Portal 7.0.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, …

Oct 22, 2024
CVE-2024-43177
5.9 MEDIUM

IBM Concert 1.0.0 and 1.0.1 vulnerable to attacks that rely on the use of cookies without the SameSite attribute.

Oct 22, 2024
CVE-2024-43173
3.7 LOW

IBM Concert 1.0.0 and 1.0.1 vulnerable to attacks that rely on the use of cookies without the SameSite attribute.

Oct 22, 2024
CVE-2024-38002
9.0 CRITICAL

The workflow component in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92 and 7.3 …

Oct 22, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.