CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-41290
8.1 HIGH

FlatPress CMS v1.3.1 1.3 was discovered to use insecure methods to store authentication data via the cookie's component.

Oct 2, 2024
CVE-2024-20524
6.8 MEDIUM

A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, Administrator-level, remote attacker to …

Oct 2, 2024
CVE-2024-20523
6.8 MEDIUM

A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, Administrator-level, remote attacker to …

Oct 2, 2024
CVE-2024-20522
6.5 MEDIUM

A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, Administrator-level, remote attacker to …

Oct 2, 2024
CVE-2024-20521
6.5 MEDIUM

A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, Administrator-level, remote attacker to …

Oct 2, 2024
CVE-2024-20520
6.5 MEDIUM

A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, Administrator-level, remote attacker to …

Oct 2, 2024
CVE-2024-20519
6.5 MEDIUM

A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, Administrator-level, remote attacker to …

Oct 2, 2024
CVE-2024-20518
6.5 MEDIUM

A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, Administrator-level, remote attacker to …

Oct 2, 2024
CVE-2024-20517
6.8 MEDIUM

A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, Administrator-level, remote attacker to …

Oct 2, 2024
CVE-2024-20516
6.8 MEDIUM

A vulnerability in the web-based management interface of Cisco Small Business RV042, RV042G, RV320, and RV325 Routers could allow an authenticated, Administrator-level, remote attacker to …

Oct 2, 2024
CVE-2024-20515
6.5 MEDIUM

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information from an …

Oct 2, 2024
CVE-2024-20492
6.0 MEDIUM

A vulnerability in the restricted shell of Cisco Expressway Series could allow an authenticated, local attacker to perform command injection attacks on the underlying operating …

Oct 2, 2024
CVE-2024-20491
6.3 MEDIUM

A vulnerability in a logging function of Cisco Nexus Dashboard Insights could allow an attacker with access to a tech support file to view sensitive …

Oct 2, 2024
CVE-2024-20490
6.3 MEDIUM

A vulnerability in a logging function of Cisco Nexus Dashboard Fabric Controller (NDFC) and Cisco Nexus Dashboard Orchestrator (NDO) could allow an attacker with access …

Oct 2, 2024
CVE-2024-20477
5.4 MEDIUM

A vulnerability in a specific REST API endpoint of Cisco NDFC could allow an authenticated, low-privileged, remote attacker to upload or delete files on an …

Oct 2, 2024
CVE-2024-20470
7.2 HIGH

A vulnerability in the web-based management interface of Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an authenticated, …

Oct 2, 2024
CVE-2024-20449
8.8 HIGH

A vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, remote attacker with low privileges to execute arbitrary code on an affected …

Oct 2, 2024
CVE-2024-20448
6.3 MEDIUM

A vulnerability in the Cisco Nexus Dashboard Fabric Controller (NDFC) software, formerly Cisco Data Center Network Manager (DCNM), could allow an attacker with access to …

Oct 2, 2024
CVE-2024-20444
5.5 MEDIUM

A vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC), formerly Cisco Data Center Network Manager (DCNM), could allow an authenticated, remote attacker with network-admin privileges …

Oct 2, 2024
CVE-2024-20442
5.4 MEDIUM

A vulnerability in the REST API endpoints of Cisco Nexus Dashboard could allow an authenticated, low-privileged, remote attacker to perform limited Administrator actions on an …

Oct 2, 2024
CVE-2024-20441
5.7 MEDIUM

A vulnerability in a specific REST API endpoint of Cisco NDFC could allow an authenticated, low-privileged, remote attacker to learn sensitive information on an affected …

Oct 2, 2024
CVE-2024-20438
6.3 MEDIUM

A vulnerability in the REST API endpoints of Cisco NDFC could allow an authenticated, low-privileged, remote attacker to read or write files on an affected …

Oct 2, 2024
CVE-2024-20432
9.9 CRITICAL

A vulnerability in the REST API and web UI of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, low-privileged, remote attacker to perform …

Oct 2, 2024
CVE-2024-20393
8.8 HIGH

A vulnerability in the web-based management interface of Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an authenticated, …

Oct 2, 2024
CVE-2024-20385
5.9 MEDIUM

A vulnerability in the SSL/TLS implementation of Cisco Nexus Dashboard Orchestrator (NDO) could allow an unauthenticated, remote attacker to intercept sensitive information from an affected …

Oct 2, 2024
CVE-2024-20365
6.5 MEDIUM

A vulnerability in the Redfish API of Cisco UCS B-Series, Cisco UCS Managed C-Series, and Cisco UCS X-Series Servers could allow an authenticated, remote attacker …

Oct 2, 2024
CVE-2024-9423
5.3 MEDIUM

Certain HP LaserJet printers may potentially experience a denial of service when a user sends a raw JPEG file to the printer. The printer displays …

Oct 2, 2024
CVE-2024-6360
9.8 CRITICAL

Incorrect Permission Assignment for Critical Resource vulnerability in OpenText™ Vertica could allow Privilege Abuse and result in unauthorized access or privileges to Vertica agent apikey. …

Oct 2, 2024
CVE-2024-47807
8.1 HIGH

Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `iss` (Issuer) claim of an ID Token, allowing attackers to subvert the authentication …

Oct 2, 2024
CVE-2024-47806
8.1 HIGH

Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `aud` (Audience) claim of an ID Token, allowing attackers to subvert the authentication …

Oct 2, 2024
CVE-2024-47805
7.5 HIGH

Jenkins Credentials Plugin 1380.va_435002fa_924 and earlier, except 1371.1373.v4eb_fa_b_7161e9, does not redact encrypted values of credentials using the `SecretBytes` type when accessing item `config.xml` via REST …

Oct 2, 2024
CVE-2024-47804
4.3 MEDIUM

If an attempt is made to create an item of a type prohibited by `ACL#hasCreatePermission2` or `TopLevelItemDescriptor#isApplicableIn(ItemGroup)` through the Jenkins CLI or the REST API …

Oct 2, 2024
CVE-2024-47803
4.3 MEDIUM

Jenkins 2.478 and earlier, LTS 2.462.2 and earlier does not redact multi-line secret values in error messages generated for form submissions involving the `secretTextarea` form …

Oct 2, 2024
CVE-2024-33210
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability has been identified in Flatpress 1.3. This vulnerability allows an attacker to inject malicious scripts into web pages viewed by …

Oct 2, 2024
CVE-2024-33209
5.4 MEDIUM

FlatPress v1.3 is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into the "Add New Entry" section, which allows them …

Oct 2, 2024
CVE-2024-47612
3.5 LOW

DataDump is a MediaWiki extension that provides dumps of wikis. Several interface messages are unescaped (more specifically, (datadump-table-column-queued), (datadump-table-column-in-progress), (datadump-table-column-completed), (datadump-table-column-failed)). If these messages are …

Oct 2, 2024
CVE-2024-47611

XZ Utils provide a general-purpose data-compression library plus command-line tools. When built for native Windows (MinGW-w64 or MSVC), the command line tools from XZ Utils …

Oct 2, 2024
CVE-2024-44193
7.8 HIGH

A logic issue was addressed with improved restrictions. This issue is fixed in iTunes 12.13.3 for Windows. A local attacker may be able to elevate …

Oct 2, 2024
CVE-2024-44097
9.8 CRITICAL

According to the researcher: "The TLS connections are encrypted against tampering or eavesdropping. However, the application does not validate the server certificate properly while initializing …

Oct 2, 2024
CVE-2024-9429
6.3 MEDIUM

A vulnerability has been found in code-projects Restaurant Reservation System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Oct 2, 2024
CVE-2024-8885
8.8 HIGH

A local privilege escalation vulnerability in Sophos Intercept X for Windows with Central Device Encryption 2024.2.0 and older allows writing of arbitrary files.

Oct 2, 2024
CVE-2024-8038
7.9 HIGH

Vulnerable juju introspection abstract UNIX domain socket. An abstract UNIX domain socket responsible for introspection is available without authentication locally to network namespace users. This …

Oct 2, 2024
CVE-2024-8037
6.5 MEDIUM

Vulnerable juju hook tool abstract UNIX domain socket. When combined with an attack of JUJU_CONTEXT_ID, any user on the local system with access to the …

Oct 2, 2024
CVE-2024-7558
8.7 HIGH

JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju charm container (on Kubernetes), an unprivileged user in the same network namespace …

Oct 2, 2024
CVE-2024-35294
6.5 MEDIUM

An unauthenticated remote attacker may use the devices traffic capture without authentication to grab plaintext administrative credentials.

Oct 2, 2024
CVE-2024-8505
6.4 MEDIUM

The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘button_label’ parameter in all versions up …

Oct 2, 2024
CVE-2024-8282
6.4 MEDIUM

The Ibtana – WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ attribute within the 'wp:ive/ive-productscarousel' Gutenberg block in …

Oct 2, 2024
CVE-2024-44030
7.2 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mestres do WP Checkout Mestres WP checkout-mestres-wp allows Absolute Path Traversal.This issue …

Oct 2, 2024
CVE-2024-44017
7.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in MinHyeong Lim MH Board mh-board allows PHP Local File Inclusion.This issue affects …

Oct 2, 2024
CVE-2024-35293
9.1 CRITICAL

An unauthenticated remote attacker may use a missing authentication for critical function vulnerability to reboot or erase the affected devices resulting in data loss and/or …

Oct 2, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.