CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-39436
6.5 MEDIUM

In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution …

Oct 9, 2024
CVE-2024-5968
4.8 MEDIUM

The Photo Gallery by 10Web WordPress plugin before 1.8.28 does not properly sanitise and escape some of its Gallery settings, which could allow high privilege …

Oct 9, 2024
CVE-2023-46586
9.1 CRITICAL

cgi.c in weborf .0.17, 0.18, 0.19, and 0.20 (before 1.0) lacks '\0' termination of the path for CGI scripts because strncpy is misused.

Oct 9, 2024
CVE-2023-45872
6.5 MEDIUM

An issue was discovered in Qt before 6.2.11 and 6.3.x through 6.6.x before 6.6.1. When a QML image refers to an image whose content is …

Oct 9, 2024
CVE-2023-45361
6.1 MEDIUM

An issue was discovered in VectorComponentUserLinks.php in the Vector Skin component in MediaWiki before 1.39.5 and 1.40.x before 1.40.1. vector-intro-page MalformedTitleException is uncaught if it …

Oct 9, 2024
CVE-2023-45359
6.5 MEDIUM

An issue was discovered in the Vector Skin component for MediaWiki before 1.39.5 and 1.40.x before 1.40.1. vector-toc-toggle-button-label is not escaped, but should be, because …

Oct 9, 2024
CVE-2023-37154
8.4 HIGH

check_by_ssh in Nagios nagios-plugins 2.4.5 allows arbitrary command execution via ProxyCommand, LocalCommand, and PermitLocalCommand with \${IFS}. This has been categorized both as fixed in e8810de, …

Oct 9, 2024
CVE-2023-36325
3.7 LOW

i2p before 2.3.0 (Java) allows de-anonymizing the public IPv4 and IPv6 addresses of i2p hidden services (aka eepsites) via a correlation attack across the IPv4 …

Oct 9, 2024
CVE-2024-47191
7.1 HIGH

pam_oath.so in oath-toolkit 2.6.7 through 2.6.11 before 2.6.12 allows root privilege escalation because, in the context of PAM code running as root, it mishandles usersfile …

Oct 9, 2024
CVE-2024-45160
9.1 CRITICAL

Incorrect credential validation in LemonLDAP::NG 2.18.x and 2.19.x before 2.19.2 allows attackers to bypass OAuth2 client authentication via an empty client_password parameter (client secret).

Oct 9, 2024
CVE-2024-42934
5.0 MEDIUM

OpenIPMI before 2.0.36 has an out-of-bounds array access (for authentication type) in the ipmi_sim simulator, resulting in denial of service or (with very low probability) …

Oct 9, 2024
CVE-2024-32608
9.8 CRITICAL

HDF5 library through 1.14.3 has memory corruption in H5A__close resulting in the corruption of the instruction pointer and causing denial of service or potential code …

Oct 9, 2024
CVE-2024-45179
7.2 HIGH

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to insufficient input validation, the C-MOR web interface is vulnerable to OS …

Oct 9, 2024
CVE-2024-35288
7.8 HIGH

Nitro PDF Pro before 13.70.8.82 and 14.x before 14.26.1.0 allows Local Privilege Escalation in the MSI Installer because custom actions occur unsafely in repair mode. …

Oct 9, 2024
CVE-2024-25286

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been …

Oct 9, 2024
CVE-2024-25285

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been …

Oct 9, 2024
CVE-2024-25284

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been …

Oct 9, 2024
CVE-2024-25283

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been …

Oct 9, 2024
CVE-2024-25282

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been …

Oct 9, 2024
CVE-2024-7963
6.4 MEDIUM

The CMSMasters Content Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's multiple shortcodes in all versions up to, and including, …

Oct 9, 2024
CVE-2024-9603
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 129.0.6668.100 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Oct 8, 2024
CVE-2024-9602
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 129.0.6668.100 allowed a remote attacker to perform an out of bounds memory write via a crafted …

Oct 8, 2024
CVE-2024-9412

An improper authorization vulnerability exists in the Rockwell Automation affected products that could allow an unauthorized user to sign in. While removal of all role …

Oct 8, 2024
CVE-2024-36814
4.9 MEDIUM

An arbitrary file read vulnerability in Adguard Home before v0.107.52 allows authenticated attackers to access arbitrary files as root on the underlying Operating System via …

Oct 8, 2024
CVE-2024-27457
2.5 LOW

Improper check for unusual or exceptional conditions in Intel(R) TDX Module firmware before version 1.5.06 may allow a privileged user to potentially enable information disclosure …

Oct 8, 2024
CVE-2024-47823
9.8 CRITICAL

Livewire is a full-stack framework for Laravel that allows for dynamic UI components without leaving PHP. In livewire/livewire prior to `2.12.7` and `v3.5.2`, the file …

Oct 8, 2024
CVE-2024-47822
4.2 MEDIUM

Directus is a real-time API and App dashboard for managing SQL database content. Access tokens from query strings are not redacted and are potentially exposed …

Oct 8, 2024
CVE-2024-47780
3.1 LOW

TYPO3 is a free and open source Content Management Framework. Backend users could see items in the backend page tree without having access if the …

Oct 8, 2024
CVE-2024-47773
8.2 HIGH

Discourse is an open source platform for community discussion. An attacker can make several XHR requests until the cache is poisoned with a response without …

Oct 8, 2024
CVE-2024-46539
8.2 HIGH

Insecure permissions in the Bluetooth Low Energy (BLE) component of Fire-Boltt Artillery Smart Watch NJ-R6E-10.3 allow attackers to cause a Denial of Service (DoS).

Oct 8, 2024
CVE-2024-46410
4.8 MEDIUM

PublicCMS V4.0.202406.d was discovered to contain a cross-site scripting (XSS) vulnerability via a crafted script to the Category Managment feature

Oct 8, 2024
CVE-2024-43616
7.8 HIGH

Microsoft Office Remote Code Execution Vulnerability

Oct 8, 2024
CVE-2024-43615
7.1 HIGH

Microsoft OpenSSH for Windows Remote Code Execution Vulnerability

Oct 8, 2024
CVE-2024-43614
5.5 MEDIUM

Relative path traversal in Microsoft Defender for Endpoint allows an authorized attacker to perform spoofing locally.

Oct 8, 2024
CVE-2024-43612
6.9 MEDIUM

Power BI Report Server Spoofing Vulnerability

Oct 8, 2024
CVE-2024-43611
8.8 HIGH

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

Oct 8, 2024
CVE-2024-43609
6.5 MEDIUM

Microsoft Office Spoofing Vulnerability

Oct 8, 2024
CVE-2024-43608
8.8 HIGH

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

Oct 8, 2024
CVE-2024-43607
8.8 HIGH

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

Oct 8, 2024
CVE-2024-43604
5.7 MEDIUM

Outlook for Android Elevation of Privilege Vulnerability

Oct 8, 2024
CVE-2024-43603
5.5 MEDIUM

Visual Studio Collector Service Denial of Service Vulnerability

Oct 8, 2024
CVE-2024-43601
7.8 HIGH

Visual Studio Code for Linux Remote Code Execution Vulnerability

Oct 8, 2024
CVE-2024-43599
8.8 HIGH

Remote Desktop Client Remote Code Execution Vulnerability

Oct 8, 2024
CVE-2024-43593
8.8 HIGH

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

Oct 8, 2024
CVE-2024-43592
8.8 HIGH

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

Oct 8, 2024
CVE-2024-43591
8.7 HIGH

Azure Command Line Integration (CLI) Elevation of Privilege Vulnerability

Oct 8, 2024
CVE-2024-43590
7.8 HIGH

Visual C++ Redistributable Installer Elevation of Privilege Vulnerability

Oct 8, 2024
CVE-2024-43589
8.8 HIGH

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

Oct 8, 2024
CVE-2024-43585
5.5 MEDIUM

Code Integrity Guard Security Feature Bypass Vulnerability

Oct 8, 2024
CVE-2024-43584
7.7 HIGH

Windows Scripting Engine Security Feature Bypass Vulnerability

Oct 8, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.