CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-45871
6.3 MEDIUM

Bandisoft BandiView 7.05 is Incorrect Access Control via sub_0x232bd8 resulting in denial of service (DOS).

Oct 3, 2024
CVE-2024-0125
3.3 LOW

NVIDIA CUDA Toolkit for Windows and Linux contains a vulnerability in the nvdisam command line tool, where a user can cause a NULL pointer dereference …

Oct 3, 2024
CVE-2024-0124
3.3 LOW

NVIDIA CUDA Toolkit for Windows and Linux contains a vulnerability in the nvdisam command line tool, where a user can cause nvdisasm to read freed …

Oct 3, 2024
CVE-2024-0123
3.3 LOW

NVIDIA CUDA toolkit for Windows and Linux contains a vulnerability in the nvdisasm command line tool where an attacker may cause an improper validation in …

Oct 3, 2024
CVE-2024-45870
6.5 MEDIUM

Bandisoft BandiView 7.05 is vulnerable to Incorrect Access Control in sub_0x3d80fc via a crafted POC file.

Oct 3, 2024
CVE-2024-42415
8.4 HIGH

An integer overflow vulnerability exists in the Compound Document Binary File format parser of v1.14.52 of the GNOME Project G Structured File Library (libgsf). A …

Oct 3, 2024
CVE-2024-41922
7.5 HIGH

A directory traversal vulnerability exists in the log files download functionality of Veertu Anka Build 1.42.0. A specially crafted HTTP request can lead to a …

Oct 3, 2024
CVE-2024-41163
7.5 HIGH

A directory traversal vulnerability exists in the archive functionality of Veertu Anka Build 1.42.0. A specially crafted HTTP request can lead to a disclosure of …

Oct 3, 2024
CVE-2024-39755
7.8 HIGH

A privilege escalation vulnerability exists in the node update functionality of Veertu Anka Build 1.42.0. A specially crafted PKG file can lead to execute priviledged …

Oct 3, 2024
CVE-2024-36474
8.4 HIGH

An integer overflow vulnerability exists in the Compound Document Binary File format parser of the GNOME Project G Structured File Library (libgsf) version v1.14.52. A …

Oct 3, 2024
CVE-2024-25590
7.5 HIGH

An attacker can publish a zone containing specific Resource Record Sets. Repeatedly processing and caching results for these sets can lead to a denial of …

Oct 3, 2024
CVE-2024-9460
7.3 HIGH

A vulnerability was found in Codezips Online Shopping Portal 1.0. It has been classified as critical. Affected is an unknown function of the file index.php. …

Oct 3, 2024
CVE-2024-9100
6.5 MEDIUM

Zohocorp ManageEngine Analytics Plus versions before 5410 and Zoho Analytics On-Premise versions before 5410 are vulnerable to Path traversal.

Oct 3, 2024
CVE-2024-5803
7.5 HIGH

The AVGUI.exe of AVG/Avast Antivirus before versions before 24.1 can allow a local attacker to escalate privileges via an COM hijack in a time-of-check to …

Oct 3, 2024
CVE-2024-47618
5.4 MEDIUM

Sulu is a PHP content management system. Sulu is vulnerable against XSS whereas a low privileged user with access to the “Media” section can upload …

Oct 3, 2024
CVE-2024-47617
6.1 MEDIUM

Sulu is a PHP content management system. This vulnerability allows an attacker to inject arbitrary HTML/JavaScript code through the media download URL in Sulu CMS. …

Oct 3, 2024
CVE-2024-47614
7.5 HIGH

async-graphql is a GraphQL server library implemented in Rust. async-graphql before 7.0.10 does not limit the number of directives for a field. This can lead …

Oct 3, 2024
CVE-2024-47554
4.3 MEDIUM

Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input. This issue affects Apache …

Oct 3, 2024
CVE-2024-9313
8.8 HIGH

Authd PAM module before version 0.3.5 can allow broker-managed users to impersonate any other user managed by the same broker and perform any PAM operation …

Oct 3, 2024
CVE-2024-47561
7.3 HIGH

Schema parsing in the Java SDK of Apache Avro 1.11.3 and previous versions allows bad actors to execute arbitrary code. Users are recommended to upgrade …

Oct 3, 2024
CVE-2024-42504
4.3 MEDIUM

A security vulnerability in HPE IceWall Agent products could be exploited remotely to cause a Cross-Site Request Forgery (CSRF) in the login flow.

Oct 3, 2024
CVE-2024-8159
6.4 MEDIUM

Deep Freeze 9.00.020.5760 is vulnerable to an out-of-bounds read vulnerability by triggering the 0x70014 IOCTL code of the FarDisk.sys driver.

Oct 3, 2024
CVE-2024-8352
7.5 HIGH

The Social Web Suite – Social Media Auto Post, Social Media Auto Publish plugin for WordPress is vulnerable to Directory Traversal in all versions up …

Oct 3, 2024
CVE-2024-47136
7.8 HIGH

Out-of-bounds read vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) Version 1.6.14.0 and earlier. Having a user open a specially …

Oct 3, 2024
CVE-2024-47135
7.8 HIGH

Stack-based buffer overflow vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) Version 1.6.14.0 and earlier. Having a user open a …

Oct 3, 2024
CVE-2024-47134
7.8 HIGH

Out-of-bounds write vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) Version 1.6.14.0 and earlier. Having a user open a specially …

Oct 3, 2024
CVE-2024-47616
6.8 MEDIUM

Pomerium is an identity and context-aware access proxy. The Pomerium databroker service is responsible for managing all persistent Pomerium application state. Requests to the databroker …

Oct 2, 2024
CVE-2024-45519
10.0 CRITICAL KEV

The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1 sometimes allows …

Oct 2, 2024
CVE-2024-28888
8.8 HIGH

A use-after-free vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a checkbox field object. A specially crafted Javascript code inside a malicious PDF document …

Oct 2, 2024
CVE-2024-24117
9.8 CRITICAL

Insecure Permissions vulnerability in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release (9736) allows a remote attacker to gain privileges via the login check state component.

Oct 2, 2024
CVE-2024-8733
8.0 HIGH

A potential security vulnerability has been identified in the HP One Agent for certain HP PC products, which might allow for escalation of privilege. HP …

Oct 2, 2024
CVE-2024-47529
6.5 MEDIUM

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. OpenC3 COSMOS stores the password of …

Oct 2, 2024
CVE-2024-46977
6.5 MEDIUM

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. A path traversal vulnerability inside of …

Oct 2, 2024
CVE-2024-45965
6.4 MEDIUM

Contao before 5.5.6 allows XSS via an SVG document. This affects (in contao/core-bundle in Composer) 4.x before 4.13.54, 5.0.x through 5.3.x before 5.3.30, and 5.4.x …

Oct 2, 2024
CVE-2024-45964
4.8 MEDIUM

Zenario 9.7.61188 is vulnerable to Cross Site Scripting (XSS) in the Image library via the "Organizer tags" field.

Oct 2, 2024
CVE-2024-45962
4.7 MEDIUM

October 3.6.30 allows an authenticated admin account to upload a PDF file containing malicious JavaScript into the target system. If the file is accessed through …

Oct 2, 2024
CVE-2024-45960
4.8 MEDIUM

Zenario 9.7.61188 allows authenticated admin users to upload PDF files containing malicious code into the target system. If the PDF file is accessed through the …

Oct 2, 2024
CVE-2024-43795
6.1 MEDIUM

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. The login functionality contains a reflected …

Oct 2, 2024
CVE-2024-9441
9.8 CRITICAL

The Linear eMerge e3-Series through version 1.00-07 is vulnerable to an OS command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary OS commands …

Oct 2, 2024
CVE-2024-9440
5.4 MEDIUM

Slim Select 2.0 versions through 2.9.0 are affected by a potential cross-site scripting vulnerability. In select.ts:createOption(), the text variable from the user-provided Options object is …

Oct 2, 2024
CVE-2024-24116
9.8 CRITICAL

An issue in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release(9736) allows a remote attacker to gain privileges via the system/config_menu.htm.

Oct 2, 2024
CVE-2024-20513
5.8 MEDIUM

A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote …

Oct 2, 2024
CVE-2024-20509
5.8 MEDIUM

A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote …

Oct 2, 2024
CVE-2024-20502
5.8 MEDIUM

A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote …

Oct 2, 2024
CVE-2024-20501
8.6 HIGH

Multiple vulnerabilities in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote …

Oct 2, 2024
CVE-2024-20500
5.8 MEDIUM

A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote …

Oct 2, 2024
CVE-2024-20499
8.6 HIGH

Multiple vulnerabilities in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote …

Oct 2, 2024
CVE-2024-20498
8.6 HIGH

Multiple vulnerabilities in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote …

Oct 2, 2024
CVE-2024-24122
3.3 LOW

A remote code execution vulnerability in the project management of Wanxing Technology's Yitu project which allows an attacker to use the exp.adpx file as a …

Oct 2, 2024
CVE-2024-46626
8.8 HIGH

OS4ED openSIS-Classic v9.1 was discovered to contain a SQL injection vulnerability via a crafted payload.

Oct 2, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.