CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-30118
3.5 LOW

HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to because of …

Oct 9, 2024
CVE-2024-7038
2.7 LOW

An information disclosure vulnerability exists in open-webui version 0.3.8. The vulnerability is related to the embedding model update feature under admin settings. When a user …

Oct 9, 2024
CVE-2024-47833
6.5 MEDIUM

Taipy is an open-source Python library for easy, end-to-end application development for data scientists and machine learning engineers. In affected versions session cookies are served …

Oct 9, 2024
CVE-2024-47832
9.8 CRITICAL

ssoready is a single sign on provider implemented via docker. Affected versions are vulnerable to XML signature bypass attacks. An attacker can carry out signature …

Oct 9, 2024
CVE-2024-47828
5.3 MEDIUM

ampache is a web based audio/video streaming application and file manager. A CSRF attack can be performed in order to delete objects (Playlist, smartlist etc.). …

Oct 9, 2024
CVE-2024-47816
6.4 MEDIUM

ImportDump is a mediawiki extension designed to automate user import requests. A user's local actor ID is stored in the database to tell who made …

Oct 9, 2024
CVE-2024-47815
6.0 MEDIUM

IncidentReporting is a MediaWiki extension for moving incident reports from wikitext to database tables. There are a variety of Cross-site Scripting issues, though all of …

Oct 9, 2024
CVE-2024-47812
6.0 MEDIUM

ImportDump is an extension for mediawiki designed to automate user import requests. Anyone who can edit the interface strings of a wiki (typically administrators and …

Oct 9, 2024
CVE-2024-3656
8.1 HIGH

A flaw was found in Keycloak. Certain endpoints in Keycloak's admin REST API allow low-privilege users to access administrative functionalities. This flaw allows users to …

Oct 9, 2024
CVE-2024-47813
2.9 LOW

Wasmtime is an open source runtime for WebAssembly. Under certain concurrent event orderings, a `wasmtime::Engine`'s internal type registry was susceptible to double-unregistration bugs due to …

Oct 9, 2024
CVE-2024-47763
5.5 MEDIUM

Wasmtime is an open source runtime for WebAssembly. Wasmtime's implementation of WebAssembly tail calls combined with stack traces can result in a runtime crash in …

Oct 9, 2024
CVE-2024-9473
7.8 HIGH

A privilege escalation vulnerability in the Palo Alto Networks GlobalProtect app on Windows allows a locally authenticated non-administrative Windows user to escalate their privileges to …

Oct 9, 2024
CVE-2024-9471
4.7 MEDIUM

A privilege escalation (PE) vulnerability in the XML API of Palo Alto Networks PAN-OS software enables an authenticated PAN-OS administrator with restricted privileges to use …

Oct 9, 2024
CVE-2024-9470

A vulnerability in Cortex XSOAR allows the disclosure of incident data to users who do not have the privilege to view the data.

Oct 9, 2024
CVE-2024-9469
5.5 MEDIUM

A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows non-administrative privileges to …

Oct 9, 2024
CVE-2024-9468
7.5 HIGH

A memory corruption vulnerability in Palo Alto Networks PAN-OS software allows an unauthenticated attacker to crash PAN-OS due to a crafted packet through the data …

Oct 9, 2024
CVE-2024-9467
6.1 MEDIUM

A reflected XSS vulnerability in Palo Alto Networks Expedition enables execution of malicious JavaScript in the context of an authenticated Expedition user's browser if that …

Oct 9, 2024
CVE-2024-9466
6.5 MEDIUM

A cleartext storage of sensitive information vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to reveal firewall usernames, passwords, and API keys generated …

Oct 9, 2024
CVE-2024-9465
9.1 CRITICAL KEV

An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, …

Oct 9, 2024
CVE-2024-9464
6.5 MEDIUM

An OS command injection vulnerability in Palo Alto Networks Expedition allows an authenticated attacker to run arbitrary OS commands as root in Expedition, resulting in …

Oct 9, 2024
CVE-2024-9463
7.5 HIGH KEV

An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in …

Oct 9, 2024
CVE-2024-46307
7.5 HIGH

A loop hole in the payment logic of Sparkshop v1.16 allows attackers to arbitrarily modify the number of products.

Oct 9, 2024
CVE-2024-45746
9.8 CRITICAL

An issue was discovered in Trusted Firmware-M through 2.1.0. User provided (and controlled) mailbox messages contain a pointer to a list of input arguments (in_vec) …

Oct 9, 2024
CVE-2024-43610
7.4 HIGH

Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view sensitive information through network attack vector

Oct 9, 2024
CVE-2024-42988
4.3 MEDIUM

Lack of access control in ChallengeSolves (/api/v1/challenges/<challenge id>/solves) of CTFd v2.0.0 - v3.7.2 allows authenticated users to retrieve a list of users who have solved …

Oct 9, 2024
CVE-2024-46316
8.0 HIGH

DrayTek Vigor3900 v1.5.1.6 was discovered to contain a command injection vulnerability via the sub_2C920 function at /cgi-bin/mainfunction.cgi. This vulnerability allows attackers to execute arbitrary commands …

Oct 9, 2024
CVE-2024-46304
7.5 HIGH

A NULL pointer dereference in libcoap v4.3.5-rc2 and below allows a remote attacker to cause a denial of service via the coap_handle_request_put_block function in src/coap_block.c.

Oct 9, 2024
CVE-2024-46292
7.5 HIGH

A buffer overflow in modsecurity v3.0.12 allows attackers to cause a Denial of Service (DoS) via a crafted input inserted into the name parameter. NOTE: …

Oct 9, 2024
CVE-2024-25825
9.8 CRITICAL

FydeOS for PC 17.1 R114, FydeOS for VMware 17.0 R114, FydeOS for You 17.1 R114, and OpenFyde R114 were discovered to be configured with the …

Oct 9, 2024
CVE-2024-9675
7.8 HIGH

A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are within our cache directory, allowing a …

Oct 9, 2024
CVE-2024-9671
5.3 MEDIUM

A vulnerability was found in 3Scale. There is no auth mechanism to see a PDF invoice of a Developer user if the URL is known. …

Oct 9, 2024
CVE-2024-8048
7.8 HIGH

In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible using object injection via insecure expression evaluation.

Oct 9, 2024
CVE-2024-8015
9.1 CRITICAL

In Progress Telerik Report Server versions prior to 2024 Q3 (10.2.24.924), a remote code execution attack is possible through object injection via an insecure type …

Oct 9, 2024
CVE-2024-8014
8.8 HIGH

In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible through object injection via an insecure type resolution vulnerability.

Oct 9, 2024
CVE-2024-7840
7.8 HIGH

In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a command injection attack is possible through improper neutralization of hyperlink elements.

Oct 9, 2024
CVE-2024-7294
7.5 HIGH

In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), an HTTP DoS attack is possible on anonymous endpoints without rate limiting.

Oct 9, 2024
CVE-2024-7293
7.5 HIGH

In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a password brute forcing attack is possible through weak password requirements.

Oct 9, 2024
CVE-2024-7292
7.5 HIGH

In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a credential stuffing attack is possible through improper restriction of excessive login attempts.

Oct 9, 2024
CVE-2024-47673
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: pause TCM when the firmware is stopped Not doing so will make …

Oct 9, 2024
CVE-2024-47672

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Oct 9, 2024
CVE-2024-47671
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: USB: usbtmc: prevent kernel-usb-infoleak The syzbot reported a kernel-usb-infoleak in usbtmc_write, we need to clear …

Oct 9, 2024
CVE-2024-47670
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ocfs2: add bounds checking to ocfs2_xattr_find_entry() Add a paranoia check to make sure it doesn't …

Oct 9, 2024
CVE-2024-47669
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix state management in error path of log writing function After commit a694291a6211 ("nilfs2: …

Oct 9, 2024
CVE-2024-47668
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: lib/generic-radix-tree.c: Fix rare race in __genradix_ptr_alloc() If we need to increase the tree depth, allocate …

Oct 9, 2024
CVE-2024-47667
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: PCI: keystone: Add workaround for Errata #i2037 (AM65x SR 1.0) Errata #i2037 in AM65x/DRA80xM Processors …

Oct 9, 2024
CVE-2024-47666
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: pm80xx: Set phy->enable_completion only when we wait for it pm8001_phy_control() populates the enable_completion pointer …

Oct 9, 2024
CVE-2024-47665
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: i3c: mipi-i3c-hci: Error out instead on BUG_ON() in IBI DMA setup Definitely condition dma_get_cache_alignment * …

Oct 9, 2024
CVE-2024-47664
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: spi: hisi-kunpeng: Add verification for the max_frequency provided by the firmware If the value of …

Oct 9, 2024
CVE-2024-47663
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: staging: iio: frequency: ad9834: Validate frequency parameter value In ad9834_write_frequency() clk_get_rate() can return 0. In …

Oct 9, 2024
CVE-2024-47662
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Remove register from DCN35 DMCUB diagnostic collection [Why] These registers should not be read …

Oct 9, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.