CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-9622
5.3 MEDIUM

A vulnerability was found in the resteasy-netty4 library arising from improper handling of HTTP requests using smuggling techniques. When an HTTP smuggling request with an …

Oct 8, 2024
CVE-2024-9621
5.3 MEDIUM

A vulnerability was found in Quarkus CXF. Passwords and other secrets may appear in the application log in spite of the user configuring them to …

Oct 8, 2024
CVE-2024-9620
5.3 MEDIUM

A flaw was found in Event-Driven Automation (EDA) in Ansible Automation Platform (AAP), which lacks encryption of sensitive information. An attacker with network access could …

Oct 8, 2024
CVE-2024-9381
7.2 HIGH

Path traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass restrictions.

Oct 8, 2024
CVE-2024-9380
7.2 HIGH KEV

An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to …

Oct 8, 2024
CVE-2024-9379
6.5 MEDIUM KEV

SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL …

Oct 8, 2024
CVE-2024-9167
7.8 HIGH

Under specific circumstances, insecure permissions in Ivanti Velocity License Server before version 5.2 allows a local authenticated attacker to achieve local privilege escalation.

Oct 8, 2024
CVE-2024-9124
7.5 HIGH

A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 600T. If the device is overloaded with requests, it will become unavailable. The device may require …

Oct 8, 2024
CVE-2024-8626
7.5 HIGH

Due to a memory leak, a denial-of-service vulnerability exists in the Rockwell Automation affected products. A malicious actor could exploit this vulnerability by performing multiple …

Oct 8, 2024
CVE-2024-7612
8.8 HIGH

Insecure permissions in Ivanti EPMM before 12.1.0.4 allow a local authenticated attacker to modify sensitive application components.

Oct 8, 2024
CVE-2024-47011
7.5 HIGH

Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information

Oct 8, 2024
CVE-2024-47010
7.3 HIGH

Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.

Oct 8, 2024
CVE-2024-47009
7.3 HIGH

Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.

Oct 8, 2024
CVE-2024-47008
7.5 HIGH

Server-side request forgery in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information.

Oct 8, 2024
CVE-2024-47007
7.5 HIGH

A NULL pointer dereference in WLAvalancheService.exe of Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to cause a denial of service.

Oct 8, 2024
CVE-2024-45918
9.8 CRITICAL

Fujian Kelixin Communication Command and Dispatch Platform <=7.6.6.4391 is vulnerable to SQL Injection via /client/get_gis_fence.php.

Oct 8, 2024
CVE-2024-44349
9.8 CRITICAL

A SQL injection vulnerability in login portal in AnteeoWMS before v4.7.34 allows unauthenticated attackers to execute arbitrary SQL commands via the username parameter and disclosure …

Oct 8, 2024
CVE-2024-3057
9.8 CRITICAL

A flaw exists whereby a user can make a specific call to a FlashArray endpoint allowing privilege escalation.

Oct 8, 2024
CVE-2024-8215
8.4 HIGH

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Payara Platform Payara Server (Admin Console modules) allows Remote Code Inclusion.This …

Oct 8, 2024
CVE-2024-47951
3.5 LOW

In JetBrains TeamCity before 2024.07.3 stored XSS was possible via server global settings

Oct 8, 2024
CVE-2024-47950
3.5 LOW

In JetBrains TeamCity before 2024.07.3 stored XSS was possible in Backup configuration settings

Oct 8, 2024
CVE-2024-47949
4.9 MEDIUM

In JetBrains TeamCity before 2024.07.3 path traversal allowed backup file write to arbitrary location

Oct 8, 2024
CVE-2024-47948
4.9 MEDIUM

In JetBrains TeamCity before 2024.07.3 path traversal leading to information disclosure was possible via server backups

Oct 8, 2024
CVE-2024-47161
4.3 MEDIUM

In JetBrains TeamCity before 2024.07.3 password could be exposed via Sonar runner REST API

Oct 8, 2024
CVE-2024-45231
5.3 MEDIUM

An issue was discovered in Django v5.1.1, v5.0.9, and v4.2.16. The django.contrib.auth.forms.PasswordResetForm class, when used in a view implementing password reset flows, allows remote attackers …

Oct 8, 2024
CVE-2024-45230
7.5 HIGH

An issue was discovered in Django 5.1 before 5.1.1, 5.0 before 5.0.9, and 4.2 before 4.2.16. The urlize() and urlizetrunc() template filters are subject to …

Oct 8, 2024
CVE-2024-45880
8.0 HIGH

A command injection vulnerability exists in Motorola CX2L router v1.0.2 and below. The vulnerability is present in the SetStationSettings function. The system directly invokes the …

Oct 8, 2024
CVE-2024-45330
7.2 HIGH

A use of externally-controlled format string in Fortinet FortiAnalyzer versions 7.4.0 through 7.4.3, 7.2.2 through 7.2.5 allows attacker to escalate its privileges via specially crafted …

Oct 8, 2024
CVE-2024-33506
3.3 LOW

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiManager 7.4.2 and below, 7.2.5 and below, 7.0.12 and below allows a remote …

Oct 8, 2024
CVE-2024-8482
6.4 MEDIUM

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and …

Oct 8, 2024
CVE-2024-8431
4.3 MEDIUM

The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check …

Oct 8, 2024
CVE-2024-9207
6.1 MEDIUM

The BuddyPress Docs plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in …

Oct 8, 2024
CVE-2024-9005

CWE-502: Deserialization of Untrusted Data vulnerability exists that could allow code to be remotely executed on the server when unsafely deserialized data is posted to …

Oct 8, 2024
CVE-2024-8884
9.8 CRITICAL

CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause exposure of credentials when attacker has access to application on network …

Oct 8, 2024
CVE-2024-8488
4.4 MEDIUM

The Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Survey fields in all versions up to, and including, 4.9.7 due to …

Oct 8, 2024
CVE-2024-8629
6.1 MEDIUM

The WooCommerce Multilingual & Multicurrency with WPML plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping …

Oct 8, 2024
CVE-2024-8518
3.3 LOW

CWE-20: Improper Input Validation vulnerability exists that could cause a crash of the Zelio Soft 2 application when a specially crafted project file is loaded …

Oct 8, 2024
CVE-2024-8433
6.4 MEDIUM

The Easy Mega Menu Plugin for WordPress – ThemeHunk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘themehunk_megamenu_bg_image' parameter in all versions …

Oct 8, 2024
CVE-2024-8422
7.8 HIGH

CWE-416: Use After Free vulnerability exists that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when application user opens …

Oct 8, 2024
CVE-2024-3506
6.7 MEDIUM

A possible buffer overflow in selected cameras' drivers from XProtect Device Pack can allow an attacker with access to internal network to execute commands on …

Oct 8, 2024
CVE-2024-8943
9.8 CRITICAL

The LatePoint plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.0.12. This is due to insufficient verification on the …

Oct 8, 2024
CVE-2024-8911
9.8 CRITICAL

The LatePoint plugin for WordPress is vulnerable to Arbitrary User Password Change via SQL Injection in versions up to, and including, 5.0.11. This is due …

Oct 8, 2024
CVE-2024-47565
4.3 MEDIUM

A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate that user input complies with …

Oct 8, 2024
CVE-2024-47563
5.3 MEDIUM

A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate a file path that is …

Oct 8, 2024
CVE-2024-47562
8.8 HIGH

A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly neutralize special elements in user input …

Oct 8, 2024
CVE-2024-47553
9.9 CRITICAL

A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate user input to the ```ssmctl-client``` …

Oct 8, 2024
CVE-2024-47196
6.7 MEDIUM

A vulnerability has been identified in ModelSim (All versions < V2025.2), Questa (All versions < V2025.2). vsimk.exe in affected applications allows a specific tcl file …

Oct 8, 2024
CVE-2024-47195
6.7 MEDIUM

A vulnerability has been identified in ModelSim (All versions < V2024.3), Questa (All versions < V2024.3). gdb.exe in affected applications allows a specific executable file …

Oct 8, 2024
CVE-2024-47194
6.7 MEDIUM

A vulnerability has been identified in ModelSim (All versions < V2024.3), Questa (All versions < V2024.3). vish2.exe in affected applications allows a specific DLL file …

Oct 8, 2024
CVE-2024-47046
7.8 HIGH

A vulnerability has been identified in Simcenter Femap V2306 (All versions), Simcenter Femap V2401 (All versions), Simcenter Femap V2406 (All versions). The affected application is …

Oct 8, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.