CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-46808
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Add missing NULL pointer check within dpcd_extend_address_range [Why & How] ASSERT if return NULL …

Sep 27, 2024
CVE-2024-46807
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/amdgpu: Check tbo resource pointer Validate tbo resource pointer, skip if NULL

Sep 27, 2024
CVE-2024-46806
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix the warning division or modulo by zero Checks the partition mode and returns …

Sep 27, 2024
CVE-2024-46805
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix the waring dereferencing hive Check the amdgpu_hive_info *hive that maybe is NULL.

Sep 27, 2024
CVE-2024-46804
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Add array index check for hdcp ddc access [Why] Coverity reports OVERRUN warning. Do …

Sep 27, 2024
CVE-2024-46803
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Check debug trap enable before write dbg_ev_file In interrupt context, write dbg_ev_file will be …

Sep 27, 2024
CVE-2024-46802
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: added NULL check at start of dc_validate_stream [Why] prevent invalid memory access [How] check …

Sep 27, 2024
CVE-2024-46441
8.8 HIGH

An arbitrary file upload vulnerability in YPay 1.2.0 allows attackers to execute arbitrary code via a ZIP archive to themePutFile in app/common/util/Upload.php (called from app/admin/controller/ypay/Home.php). …

Sep 27, 2024
CVE-2024-9280
4.7 MEDIUM

A vulnerability has been found in kalvinGit kvf-admin up to f12a94dc1ebb7d1c51ee978a85e4c7ed75c620ff and classified as critical. This vulnerability affects the function fileUpload of the file FileUploadKit.java. …

Sep 27, 2024
CVE-2024-9279
2.4 LOW

A vulnerability, which was classified as problematic, was found in funnyzpc Mee-Admin up to 1.6. This affects an unknown part of the file /mee/index of …

Sep 27, 2024
CVE-2024-8644
7.5 HIGH

Cleartext Storage of Sensitive Information in a Cookie vulnerability in Oceanic Software ValeApp allows Protocol Manipulation, : JSON Hijacking (aka JavaScript Hijacking).This issue affects ValeApp: …

Sep 27, 2024
CVE-2024-8643
9.8 CRITICAL

Session Fixation vulnerability in Oceanic Software ValeApp allows Brute Force, Session Hijacking.This issue affects ValeApp: before v2.0.0.

Sep 27, 2024
CVE-2024-8609
7.5 HIGH

Insertion of Sensitive Information into Log File vulnerability in Oceanic Software ValeApp allows Query System for Information.This issue affects ValeApp: before v2.0.0.

Sep 27, 2024
CVE-2024-8608
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Oceanic Software ValeApp allows Stored XSS.This issue affects ValeApp: before v2.0.0.

Sep 27, 2024
CVE-2024-8607
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Oceanic Software ValeApp allows SQL Injection.This issue affects ValeApp: before v2.0.0.

Sep 27, 2024
CVE-2024-9278
4.7 MEDIUM

A vulnerability, which was classified as critical, has been found in HuankeMao SCRM up to 0.0.3. Affected by this issue is the function upload_domain_verification_file of …

Sep 27, 2024
CVE-2024-9277
3.5 LOW

A vulnerability classified as problematic was found in Langflow up to 1.0.18. Affected by this vulnerability is an unknown functionality of the file \src\backend\base\langflow\interface\utils.py of …

Sep 27, 2024
CVE-2024-9276
3.5 LOW

A vulnerability classified as problematic has been found in TMsoft MyAuth Gateway 3. Affected is an unknown function of the file /index.php. The manipulation of …

Sep 27, 2024
CVE-2024-9275
6.3 MEDIUM

A vulnerability was found in jeanmarc77 123solar up to 1.8.4.5. It has been rated as critical. This issue affects some unknown processing of the file …

Sep 27, 2024
CVE-2024-9136
6.7 MEDIUM

Access permission verification vulnerability in the App Multiplier module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Sep 27, 2024
CVE-2024-47294
4.4 MEDIUM

Access permission verification vulnerability in the input method framework module Impact: Successful exploitation of this vulnerability may affect availability.

Sep 27, 2024
CVE-2024-47293
4.7 MEDIUM

Out-of-bounds write vulnerability in the HAL-WIFI module Impact: Successful exploitation of this vulnerability may affect availability.

Sep 27, 2024
CVE-2024-47292
6.2 MEDIUM

Path traversal vulnerability in the Bluetooth module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Sep 27, 2024
CVE-2024-47291
5.6 MEDIUM

Permission vulnerability in the ActivityManagerService (AMS) module Impact: Successful exploitation of this vulnerability may affect availability.

Sep 27, 2024
CVE-2024-47290
5.5 MEDIUM

Input validation vulnerability in the USB service module Impact: Successful exploitation of this vulnerability may affect availability.

Sep 27, 2024
CVE-2024-9202
5.3 MEDIUM

In Eclipse Dataspace Components versions 0.1.3 to 0.9.0, the Connector component filters which datasets (= data offers) another party can see in a requested catalog, …

Sep 27, 2024
CVE-2024-6931
7.2 HIGH

The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via RSVP name field in all versions up to, and including, 6.6.3 …

Sep 27, 2024
CVE-2024-6654

Products for macOS enables a user logged on to the system to perform a denial-of-service attack, which could be misused to disable the protection of …

Sep 27, 2024
CVE-2024-41930
6.1 MEDIUM

Cross-site scripting vulnerability exists in MF Teacher Performance Management System version 6. If this vulnerability is exploited, an arbitrary script may be executed on the …

Sep 27, 2024
CVE-2024-38861
7.4 HIGH

Improper Certificate Validation in Checkmk Exchange plugin MikroTik allows attackers in MitM position to intercept traffic. This issue affects MikroTik: from 2.0.0 through 2.5.5, from …

Sep 27, 2024
CVE-2024-39435
6.5 MEDIUM

In Logmanager service, there is a possible missing verification incorrect input. This could lead to local escalation of privilege with no additional execution privileges needed.

Sep 27, 2024
CVE-2024-39434
6.2 MEDIUM

In drm service, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service …

Sep 27, 2024
CVE-2024-39433
6.2 MEDIUM

In drm service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Sep 27, 2024
CVE-2024-39432
8.3 HIGH

In UMTS RLC driver, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of …

Sep 27, 2024
CVE-2024-39431
8.3 HIGH

In UMTS RLC driver, there is a possible out of bounds write due to a missing bounds check. This could lead to remote denial of …

Sep 27, 2024
CVE-2024-9049
6.4 MEDIUM

The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button Group module in all versions …

Sep 27, 2024
CVE-2024-9029
7.5 HIGH

A flaw was found in the freeimage library. Processing a crafted image can cause a buffer over-read of 1 byte in the read_iptc_profile function in …

Sep 27, 2024
CVE-2024-8991
6.4 MEDIUM

The OSM – OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's osm_map and osm_map_v3 shortcodes in all versions up to, …

Sep 27, 2024
CVE-2024-8681
6.4 MEDIUM

The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Media Grid widget in all versions up to, …

Sep 27, 2024
CVE-2024-7400

The vulnerability potentially allowed an attacker to misuse ESET’s file operations during the removal of a detected file on the Windows operating system to delete …

Sep 27, 2024
CVE-2024-9130
7.2 HIGH

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter in all versions up …

Sep 27, 2024
CVE-2024-8965
6.4 MEDIUM

The Absolute Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Name' field of a custom post criteria in all versions up …

Sep 27, 2024
CVE-2024-8922
8.8 HIGH

The Product Enquiry for WooCommerce, WooCommerce product catalog plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.2.33.32 …

Sep 27, 2024
CVE-2024-7714
7.5 HIGH

The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 lacks sufficient access controls allowing an unauthenticated user to disconnect the …

Sep 27, 2024
CVE-2024-7713
7.5 HIGH

The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 discloses the Open AI API Key, allowing unauthenticated users to obtain …

Sep 27, 2024
CVE-2024-7011
6.5 MEDIUM

Sharp NEC Projectors (NP-CB4500UL, NP-CB4500WL, NP-CB4700UL, NP-P525UL, NP-P525UL+, NP-P525ULG, NP-P525ULJL, NP-P525WL, NP-P525WL+, NP-P525WLG, NP-P525WLJL, NP-CG6500UL, NP-CG6500WL, NP-CG6700UL, NP-P605UL, NP-P605UL+, NP-P605ULG, NP-P605ULJL, NP-CA4120X, NP-CA4160W, NP-CA4160X, NP-CA4200U, …

Sep 27, 2024
CVE-2024-8974
2.6 LOW

Information disclosure in Gitlab EE/CE affecting all versions from 15.6 prior to 17.2.8, 17.3 prior to 17.3.4, and 17.4 prior to 17.4.1 in specific conditions …

Sep 26, 2024
CVE-2024-4099
3.1 LOW

An issue has been discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.2.8, from 17.3 prior to 17.3.4, and from 17.4 …

Sep 26, 2024
CVE-2024-47176
5.3 MEDIUM

CUPS is a standards-based, open-source printing system, and `cups-browsed` contains network printing functionality including, but not limited to, auto-discovering print services and shared printers. `cups-browsed` …

Sep 26, 2024
CVE-2024-47175
8.6 HIGH

CUPS is a standards-based, open-source printing system, and `libppd` can be used for legacy PPD file support. The `libppd` function `ppdCreatePPDFromIPP2` does not sanitize IPP …

Sep 26, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.