CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-47497
7.5 HIGH

An Uncontrolled Resource Consumption vulnerability in the http daemon (httpd) of Juniper Networks Junos OS on SRX Series, QFX Series, MX Series and EX Series …

Oct 11, 2024
CVE-2024-47496
5.5 MEDIUM

A NULL Pointer Dereference vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS allows a local, low-privileged attacker to cause a Denial-of-Service …

Oct 11, 2024
CVE-2024-47495
6.7 MEDIUM

An Authorization Bypass Through User-Controlled Key vulnerability allows a locally authenticated attacker with shell access to gain full control of the device when Dual Routing …

Oct 11, 2024
CVE-2024-47494
5.9 MEDIUM

A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in the AgentD process of Juniper Networks Junos OS allows an attacker who is already causing impact to …

Oct 11, 2024
CVE-2024-47493
6.5 MEDIUM

A Missing Release of Memory after Effective Lifetime vulnerability in the Packet Forwarding Engine (PFE) of the Juniper Networks Junos OS on the MX Series …

Oct 11, 2024
CVE-2024-47491
5.9 MEDIUM

An Improper Handling of Exceptional Conditions vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based, …

Oct 11, 2024
CVE-2024-47490
8.2 HIGH

An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved on ACX 7000 …

Oct 11, 2024
CVE-2024-47489
5.8 MEDIUM

An Improper Handling of Exceptional Conditions vulnerability in the Packet Forwarding Engine (pfe) of the Juniper Networks Junos OS Evolved on ACX Series devices allows …

Oct 11, 2024
CVE-2024-46088
9.8 CRITICAL

An arbitrary file upload vulnerability in the ProductAction.entphone interface of Zhejiang University Entersoft Customer Resource Management System v2002 to v2024 allows attackers to execute arbitrary …

Oct 11, 2024
CVE-2024-44730
9.1 CRITICAL

Incorrect access control in the function handleDataChannelChat(dataMessage) of Mirotalk before commit c21d58 allows attackers to forge chat messages using an arbitrary sender name.

Oct 11, 2024
CVE-2024-44729
7.5 HIGH

Incorrect access control in the component app/src/server.js of Mirotalk before commit 9de226 allows unauthenticated attackers without presenter privileges to arbitrarily eject users from a meeting.

Oct 11, 2024
CVE-2024-42640
9.8 CRITICAL

angular-base64-upload prior to v0.1.21 is vulnerable to unauthenticated remote code execution via demo/server.php. Exploiting this vulnerability allows an attacker to upload arbitrary content to the …

Oct 11, 2024
CVE-2024-39563
7.3 HIGH

A Command Injection vulnerability in Juniper Networks Junos Space allows an unauthenticated, network-based attacker sending a specially crafted request to execute arbitrary shell commands on …

Oct 11, 2024
CVE-2024-39547
7.5 HIGH

An Improper Handling of Exceptional Conditions vulnerability in the rpd-server of Juniper Networks Junos OS and Junos OS Evolved within cRPD allows an unauthenticated network-based …

Oct 11, 2024
CVE-2024-39544
5.0 MEDIUM

An Incorrect Default Permissions vulnerability in the command line interface (CLI) of Juniper Networks Junos OS Evolved allows a low privileged local attacker to view …

Oct 11, 2024
CVE-2024-39534
5.4 MEDIUM

An Incorrect Comparison vulnerability in the local address verification API of Juniper Networks Junos OS Evolved allows an unauthenticated network-adjacent attacker to create sessions or …

Oct 11, 2024
CVE-2024-39527
5.5 MEDIUM

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the command-line interface (CLI) of Juniper Networks Junos OS on SRX Series devices allows …

Oct 11, 2024
CVE-2024-39526
6.5 MEDIUM

An Improper Handling of Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS on MX Series with MPC10/MPC11/LC9600 line cards, EX9200 with EX9200-15C …

Oct 11, 2024
CVE-2024-33582
7.8 HIGH

A DLL hijack vulnerability was reported in Lenovo Service Framework that could allow a local attacker to execute code with elevated privileges.

Oct 11, 2024
CVE-2024-33581
7.8 HIGH

A DLL hijack vulnerability was reported in Lenovo PC Manager AI intelligent scenario that could allow a local attacker to execute code with elevated privileges.

Oct 11, 2024
CVE-2024-33580
7.8 HIGH

A DLL hijack vulnerability was reported in Lenovo Personal Cloud that could allow a local attacker to execute code with elevated privileges.

Oct 11, 2024
CVE-2024-33579
7.8 HIGH

A DLL hijack vulnerability was reported in Lenovo Baiying that could allow a local attacker to execute code with elevated privileges.

Oct 11, 2024
CVE-2024-33578
7.8 HIGH

A DLL hijack vulnerability was reported in Lenovo Leyun that could allow a local attacker to execute code with elevated privileges.

Oct 11, 2024
CVE-2024-8755
8.4 HIGH

Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 …

Oct 11, 2024
CVE-2024-47875
10.0 CRITICAL

DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMpurify was vulnerable to nesting-based mXSS. This vulnerability is fixed in 2.5.0 …

Oct 11, 2024
CVE-2024-47830
9.3 CRITICAL

Plane is an open-source project management tool. Plane uses the ** wildcard support to retrieve the image from any hostname as in /web/next.config.js. This may …

Oct 11, 2024
CVE-2024-47074
9.8 CRITICAL

DataEase is an open source data visualization analysis tool. In Dataease, the PostgreSQL data source in the data source function can customize the JDBC connection …

Oct 11, 2024
CVE-2024-45403
3.7 LOW

h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. When h2o is configured as a reverse proxy and HTTP/3 requests are cancelled …

Oct 11, 2024
CVE-2024-45402
8.6 HIGH

Picotls is a TLS protocol library that allows users select different crypto backends based on their use case. When parsing a spoofed TLS handshake message, …

Oct 11, 2024
CVE-2024-45397
5.9 MEDIUM

h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. When an HTTP request using TLS/1.3 early data on top of TCP Fast …

Oct 11, 2024
CVE-2024-45396
7.5 HIGH

Quicly is an IETF QUIC protocol implementation. Quicly up to commtit d720707 is susceptible to a denial-of-service attack. A remote attacker can exploit these bugs …

Oct 11, 2024
CVE-2024-25622
3.1 LOW

h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. The configuration directives provided by the headers handler allows users to modify the …

Oct 11, 2024
CVE-2024-9002
7.8 HIGH

CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentiality, integrity, and availability of the workstation when non-admin authenticated user tries …

Oct 11, 2024
CVE-2024-8531
7.2 HIGH

CWE-347: Improper Verification of Cryptographic Signature vulnerability exists that could compromise the Data Center Expert software when an upgrade bundle is manipulated to include arbitrary …

Oct 11, 2024
CVE-2024-8530
5.9 MEDIUM

CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause exposure of private data when an already generated “logcaptures” archive is accessed directly by …

Oct 11, 2024
CVE-2024-6657
6.5 MEDIUM

A denial of service may be caused to a single peripheral device in a BLE network when multiple central devices continuously connect and disconnect to …

Oct 11, 2024
CVE-2024-9856
2.4 LOW

A vulnerability was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM 1.3.8. It has been rated as problematic. Affected by this issue is some unknown functionality of …

Oct 11, 2024
CVE-2024-9855
4.7 MEDIUM

A vulnerability was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM 1.3.8. It has been declared as critical. Affected by this vulnerability is the function uploadFile of …

Oct 11, 2024
CVE-2024-9707
9.8 CRITICAL

The Hunk Companion plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing capability check on the /wp-json/hc/v1/themehunk-import REST API endpoint in …

Oct 11, 2024
CVE-2024-9616
6.1 MEDIUM

The BlockMeister – Block Pattern Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on …

Oct 11, 2024
CVE-2024-9611
6.1 MEDIUM

The Increase upload file size & Maximum Execution Time limit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg …

Oct 11, 2024
CVE-2024-9610
6.1 MEDIUM

The Language Switcher plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in …

Oct 11, 2024
CVE-2024-9587
5.4 MEDIUM

The Linkz.ai plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ajax_linkz' function in versions up …

Oct 11, 2024
CVE-2024-9586
6.5 MEDIUM

The Linkz.ai plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'check_auth' and 'check_logout' functions in …

Oct 11, 2024
CVE-2024-9543
6.4 MEDIUM

The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'skipto' shortcode in all versions up to, …

Oct 11, 2024
CVE-2024-9538
4.3 MEDIUM

The ShopLentor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.8 via the 'render' function in includes/addons/wl_faq.php. …

Oct 11, 2024
CVE-2024-9507
4.9 MEDIUM

The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable …

Oct 11, 2024
CVE-2024-9436
6.1 MEDIUM

The PublishPress Revisions: Duplicate Posts, Submit, Approve and Schedule Content Changes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of …

Oct 11, 2024
CVE-2024-9346
6.1 MEDIUM

The Embed videos and respect privacy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'v' parameter in all versions up to, and …

Oct 11, 2024
CVE-2024-9234
9.8 CRITICAL

The GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor plugin for WordPress is vulnerable to arbitrary file uploads due to a …

Oct 11, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.