CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-43696
3.3 LOW

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS by memory leak.

Oct 8, 2024
CVE-2024-39831
4.4 MEDIUM

in OpenHarmony v4.1.0 allow a local attacker with high privileges arbitrary code execution in pre-installed apps through use after free.

Oct 8, 2024
CVE-2024-39806
5.5 MEDIUM

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.

Oct 8, 2024
CVE-2024-37179
7.7 HIGH

SAP BusinessObjects Business Intelligence Platform allows an authenticated user to send a specially crafted request to the Web Intelligence Reporting Server to download any file …

Oct 8, 2024
CVE-2024-47969
6.2 MEDIUM

Improper resource management in firmware of some Solidigm DC Products may allow an attacker to potentially enable denial of service.

Oct 7, 2024
CVE-2024-47968
4.4 MEDIUM

Improper resource shutdown in middle of certain operations on some Solidigm DC Products may allow an attacker to potentially enable denial of service.

Oct 7, 2024
CVE-2024-47818
6.5 MEDIUM

Saltcorn is an extensible, open source, no-code database application builder. A logged-in user with any role can delete arbitrary files on the filesystem by calling …

Oct 7, 2024
CVE-2024-47817
6.1 MEDIUM

Lara-zeus Dynamic Dashboard simple way to manage widgets for your website landing page, and filament dashboard and Lara-zeus artemis is a collection of themes for …

Oct 7, 2024
CVE-2024-47814
3.9 LOW

Vim is an open source, command line text editor. A use-after-free was found in Vim < 9.1.0764. When closing a buffer (visible in a window) …

Oct 7, 2024
CVE-2024-47782
7.6 HIGH

WikiDiscover is an extension designed for use with a CreateWiki managed farm to display wikis. Special:WikiDiscover is a special page that lists all wikis on …

Oct 7, 2024
CVE-2024-47781
6.1 MEDIUM

CreateWiki is an extension used at Miraheze for requesting & creating wikis. The name of requested wikis is not escaped on Special:RequestWikiQueue, so a user …

Oct 7, 2024
CVE-2024-45874
9.8 CRITICAL

A DLL hijacking vulnerability in VegaBird Vooki 5.2.9 allows attackers to execute arbitrary code / maintain persistence via placing a crafted DLL file in the …

Oct 7, 2024
CVE-2024-45873
9.8 CRITICAL

A DLL hijacking vulnerability in VegaBird Yaazhini 2.0.2 allows attackers to execute arbitrary code / maintain persistence via placing a crafted DLL file in the …

Oct 7, 2024
CVE-2024-47974
4.4 MEDIUM

Race condition during resource shutdown in some Solidigm DC Products may allow an attacker to potentially enable denial of service.

Oct 7, 2024
CVE-2024-47973
5.1 MEDIUM

In some Solidigm DC Products, a defect in device overprovisioning may provide information disclosure to an attacker.

Oct 7, 2024
CVE-2024-47967
4.4 MEDIUM

Improper resource initialization handling in firmware of some Solidigm DC Products may allow an attacker to potentially enable denial of service.

Oct 7, 2024
CVE-2024-47772
6.5 MEDIUM

Discourse is an open source platform for community discussion. An attacker can execute arbitrary JavaScript on users' browsers by sending a maliciously crafted chat message …

Oct 7, 2024
CVE-2024-47610
7.3 HIGH

InvenTree is an Open Source Inventory Management System. In affected versions of InvenTree it is possible for a registered user to store javascript in markdown …

Oct 7, 2024
CVE-2024-45919
6.5 MEDIUM

A security flaw has been discovered in Solvait version 24.4.2 that allows an attacker to elevate their privileges. By manipulating the Request ID and Action …

Oct 7, 2024
CVE-2024-45297
5.3 MEDIUM

Discourse is an open source platform for community discussion. Users can see topics with a hidden tag if they know the label/name of that tag. …

Oct 7, 2024
CVE-2024-45291
6.3 MEDIUM

PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. It's possible for an attacker to construct an XLSX file that links images …

Oct 7, 2024
CVE-2024-45290
7.7 HIGH

PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. It's possible for an attacker to construct an XLSX file which links media …

Oct 7, 2024
CVE-2024-45060
7.1 HIGH

PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. One of the sample scripts in PhpSpreadsheet is susceptible to a cross-site scripting …

Oct 7, 2024
CVE-2024-45051
8.2 HIGH

Discourse is an open source platform for community discussion. A maliciously crafted email address could allow an attacker to bypass domain-based restrictions and gain access …

Oct 7, 2024
CVE-2024-43789
7.5 HIGH

Discourse is an open source platform for community discussion. A user can create a post with many replies, and then attempt to fetch them all …

Oct 7, 2024
CVE-2024-43365
5.7 MEDIUM

Cacti is an open source performance and fault management framework. The`consolenewsection` parameter is not properly sanitized when saving external links in links.php . Morever, the …

Oct 7, 2024
CVE-2024-43364
5.7 MEDIUM

Cacti is an open source performance and fault management framework. The `title` parameter is not properly sanitized when saving external links in links.php . Morever, …

Oct 7, 2024
CVE-2024-43363
7.2 HIGH

Cacti is an open source performance and fault management framework. An admin user can create a device with a malicious hostname containing php code and …

Oct 7, 2024
CVE-2024-43362
7.3 HIGH

Cacti is an open source performance and fault management framework. The `fileurl` parameter is not properly sanitized when saving external links in `links.php` . Morever, …

Oct 7, 2024
CVE-2024-47976
6.7 MEDIUM

Improper access removal handling in firmware of some Solidigm DC Products may allow an attacker with physical access to gain unauthorized access.

Oct 7, 2024
CVE-2024-47972
4.0 MEDIUM

Improper resource management in firmware of some Solidigm DC Products may allow an attacker to potentially control the performance of the resource.

Oct 7, 2024
CVE-2024-47971
6.5 MEDIUM

Improper error handling in firmware of some SSD DC Products may allow an attacker to enable denial of service.

Oct 7, 2024
CVE-2024-47079
6.4 MEDIUM

Meshtastic is an open source, off-grid, decentralized, mesh network built to run on affordable, low-power devices. Meshtastic firmware is an open source firmware implementation for …

Oct 7, 2024
CVE-2024-45293
7.5 HIGH

PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. The security scanner responsible for preventing XXE attacks in the XLSX reader can …

Oct 7, 2024
CVE-2024-45292
5.4 MEDIUM

PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. `\PhpOffice\PhpSpreadsheet\Writer\Html` does not sanitize "javascript:" URLs from hyperlink `href` attributes, resulting in a …

Oct 7, 2024
CVE-2024-31449
7.0 HIGH

Redis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua script to trigger a stack …

Oct 7, 2024
CVE-2024-31228
5.5 MEDIUM

Redis is an open source, in-memory database that persists on disk. Authenticated users can trigger a denial-of-service by using specially crafted, long string match patterns …

Oct 7, 2024
CVE-2024-31227
4.4 MEDIUM

Redis is an open source, in-memory database that persists on disk. An authenticated with sufficient privileges may create a malformed ACL selector which, when accessed, …

Oct 7, 2024
CVE-2024-47975
7.0 HIGH

Improper access control validation in firmware of some Solidigm DC Products may allow an attacker with physical access to gain unauthorized access or an attacker …

Oct 7, 2024
CVE-2024-47559
7.6 HIGH

Authenticated RCE via Path Traversal

Oct 7, 2024
CVE-2024-47558
7.6 HIGH

Authenticated RCE via Path Traversal

Oct 7, 2024
CVE-2024-47557
8.3 HIGH

Pre-Auth RCE via Path Traversal

Oct 7, 2024
CVE-2024-47556
8.3 HIGH

Pre-Auth RCE via Path Traversal

Oct 7, 2024
CVE-2024-45894
4.9 MEDIUM

BlueCMS 1.6 suffers from Arbitrary File Deletion via the file_name parameter in an /admin/database.php?act=del request.

Oct 7, 2024
CVE-2024-44068
8.1 HIGH

An issue was discovered in the m2m scaler driver in Samsung Mobile Processor and Wearable Processor Exynos 9820, 9825, 980, 990, 850,and W920. A Use-After-Free …

Oct 7, 2024
CVE-2024-47555
8.3 HIGH

Missing Authentication - User & System Configuration

Oct 7, 2024
CVE-2024-46076
9.8 CRITICAL

RuoYi v4.7.9 and before has a security flaw that allows escaping from comments within the code generation feature, enabling the injection of malicious code.

Oct 7, 2024
CVE-2024-44674
5.7 MEDIUM

D-Link COVR-2600R FW101b05 is vulnerable to Buffer Overflow. In the function sub_24E28, the HTTP_REFERER is obtained through an environment variable, and this field is controllable, …

Oct 7, 2024
CVE-2024-42831
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in Elaine's Realtime CRM Automation v6.18.17 allows attackers to execute arbitrary JavaScript code in the web browser of a …

Oct 7, 2024
CVE-2024-46300
6.1 MEDIUM

itsourcecode Placement Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Full Name field in registration.php.

Oct 7, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.