CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-45489
9.8 CRITICAL

Arc before 2024-08-26 allows remote code execution in JavaScript boosts. Boosts that run JavaScript cannot be shared by default; however (because of misconfigured Firebase ACLs), …

Sep 20, 2024
CVE-2024-37879
4.8 MEDIUM

Improper input validation in /admin/config/save in User-friendly SVN (USVN) before v1.0.12 and below allows administrators to execute arbitrary code via the fields "siteTitle", "siteIco" and …

Sep 20, 2024
CVE-2023-47480
8.4 HIGH

An issue in Pure Data 0.54-0 and fixed in 0.54-1 allows a local attacker to escalate privileges via the set*id () function.

Sep 20, 2024
CVE-2024-9039
7.3 HIGH

A vulnerability, which was classified as critical, has been found in SourceCodester Best House Rental Management System 1.0. Affected by this issue is some unknown …

Sep 20, 2024
CVE-2024-9038
4.3 MEDIUM

A vulnerability classified as problematic was found in Codezips Online Shopping Portal 1.0. Affected by this vulnerability is an unknown functionality of the file insert-product.php. …

Sep 20, 2024
CVE-2024-9037
7.3 HIGH

A vulnerability classified as critical has been found in Codezips Internal Marks Calculation 1.0. Affected is an unknown function of the file index.php. The manipulation …

Sep 20, 2024
CVE-2024-9036
6.3 MEDIUM

A vulnerability was found in itsourcecode Online Bookstore 1.0. It has been rated as critical. This issue affects some unknown processing of the file admin_add.php. …

Sep 20, 2024
CVE-2024-46652
9.8 CRITICAL

Tenda AC8v4 V16.03.34.06 has a stack overflow vulnerability in the fromAdvSetMacMtuWan function.

Sep 20, 2024
CVE-2024-9035
7.3 HIGH

A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been classified as critical. This affects an unknown part of the file …

Sep 20, 2024
CVE-2024-9034
7.3 HIGH

A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Sep 20, 2024
CVE-2024-9033
3.5 LOW

A vulnerability has been found in SourceCodester Best House Rental Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality …

Sep 20, 2024
CVE-2024-9032
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in SourceCodester Simple Forum-Discussion System 1.0. Affected is an unknown function of the file /index.php. The …

Sep 20, 2024
CVE-2024-9031
3.5 LOW

A vulnerability, which was classified as problematic, has been found in CodeCanyon CRMGo SaaS up to 7.2. This issue affects some unknown processing of the …

Sep 20, 2024
CVE-2024-9030
3.5 LOW

A vulnerability classified as problematic was found in CodeCanyon CRMGo SaaS 7.2. This vulnerability affects unknown code of the file /deal/{note_id}/note. The manipulation of the …

Sep 20, 2024
CVE-2024-9043
9.8 CRITICAL

Secure Email Gateway from Cellopoint has Buffer Overflow Vulnerability in authentication process. Remote unauthenticated attackers can send crafted packets to crash the process, thereby bypassing …

Sep 20, 2024
CVE-2024-8853
9.8 CRITICAL

The Webo-facto plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.40 due to insufficient restriction on the 'doSsoAuthentification' function. …

Sep 20, 2024
CVE-2024-41721
8.1 HIGH

An insufficient boundary validation in the USB code could lead to an out-of-bounds read on the heap, which could potentially lead to an arbitrary write …

Sep 20, 2024
CVE-2024-9011
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in code-projects Crud Operation System 1.0. Affected is an unknown function of the file updata.php. The …

Sep 20, 2024
CVE-2024-9009
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in code-projects Online Quiz Site 1.0. This issue affects some unknown processing of the file …

Sep 20, 2024
CVE-2024-47060
4.3 MEDIUM

Zitadel is an open source identity management platform. In Zitadel, even after an organization is deactivated, associated projects, respectively their applications remain active. Users across …

Sep 20, 2024
CVE-2024-47000
8.1 HIGH

Zitadel is an open source identity management platform. ZITADEL's user account deactivation mechanism did not work correctly with service accounts. Deactivated service accounts retained the …

Sep 20, 2024
CVE-2024-46999
7.3 HIGH

Zitadel is an open source identity management platform. ZITADEL's user grants deactivation mechanism did not work correctly. Deactivated user grants were still provided in token, …

Sep 20, 2024
CVE-2024-45810
6.5 MEDIUM

Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy will crash when the http async client is handling `sendLocalReply` under some circumstance, e.g., websocket upgrade, and …

Sep 20, 2024
CVE-2024-45809
5.3 MEDIUM

Envoy is a cloud-native high-performance edge/middle/service proxy. Jwt filter will lead to an Envoy crash when clear route cache with remote JWKs. In the following …

Sep 20, 2024
CVE-2024-45808
6.5 MEDIUM

Envoy is a cloud-native high-performance edge/middle/service proxy. A vulnerability has been identified in Envoy that allows malicious attackers to inject unexpected content into access logs. …

Sep 20, 2024
CVE-2024-45807
7.5 HIGH

Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy's 1.31 is using `oghttp` as the default HTTP/2 codec, and there are potential bugs around stream management …

Sep 20, 2024
CVE-2024-45806
6.5 MEDIUM

Envoy is a cloud-native high-performance edge/middle/service proxy. A security vulnerability in Envoy allows external clients to manipulate Envoy headers, potentially leading to unauthorized access or …

Sep 20, 2024
CVE-2024-9008
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Best Online News Portal 1.0. This vulnerability affects unknown code of the file /news-details.php of the …

Sep 19, 2024
CVE-2024-9007
3.5 LOW

A vulnerability classified as problematic has been found in jeanmarc77 123solar 1.8.4.5. This affects an unknown part of the file /detailed.php. The manipulation of the …

Sep 19, 2024
CVE-2024-9006
6.3 MEDIUM

A vulnerability was found in jeanmarc77 123solar 1.8.4.5. It has been rated as critical. Affected by this issue is some unknown functionality of the file …

Sep 19, 2024
CVE-2024-7207

Rejected reason: Duplicate of CVE-2024-45806.

Sep 19, 2024
CVE-2024-46984
8.6 HIGH

The reference validator is a tool to perform advanced validation of FHIR resources for TI applications and interoperability standards. The profile location routine in the …

Sep 19, 2024
CVE-2024-46983
9.8 CRITICAL

sofa-hessian is an internal improved version of Hessian3/4 powered by Ant Group CO., Ltd. The SOFA Hessian protocol uses a blacklist mechanism to restrict deserialization …

Sep 19, 2024
CVE-2024-45614
5.4 MEDIUM

Puma is a Ruby/Rack web server built for parallelism. In affected versions clients could clobber values set by intermediate proxies (such as X-Forwarded-For) by providing …

Sep 19, 2024
CVE-2024-45410
9.8 CRITICAL

Traefik is a golang, Cloud Native Application Proxy. When a HTTP request is processed by Traefik, certain HTTP headers such as X-Forwarded-Host or X-Forwarded-Port are …

Sep 19, 2024
CVE-2023-27584
9.8 CRITICAL

Dragonfly is an open source P2P-based file distribution and image acceleration system. It is hosted by the Cloud Native Computing Foundation (CNCF) as an Incubating …

Sep 19, 2024
CVE-2024-9004
6.3 MEDIUM

A vulnerability classified as critical has been found in D-Link DAR-7000 up to 20240912. Affected is an unknown function of the file /view/DBManage/Backup_Server_commit.php. The manipulation …

Sep 19, 2024
CVE-2024-9003
4.3 MEDIUM

A vulnerability was found in Jinan Chicheng Company JFlow 2.0.0. It has been rated as problematic. This issue affects the function AttachmentUploadController of the file …

Sep 19, 2024
CVE-2024-43496
6.5 MEDIUM

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Sep 19, 2024
CVE-2024-43489
6.5 MEDIUM

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Sep 19, 2024
CVE-2024-38221
4.3 MEDIUM

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Sep 19, 2024
CVE-2024-9001
6.3 MEDIUM

A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been declared as critical. This vulnerability affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi. The …

Sep 19, 2024
CVE-2024-40125
9.8 CRITICAL

An arbitrary file upload vulnerability in the Media Manager function of Closed-Loop Technology CLESS Server v4.5.2 allows attackers to execute arbitrary code via uploading a …

Sep 19, 2024
CVE-2024-33109
9.9 CRITICAL

Directory Traversal in the web interface of the Tiptel IP 286 with firmware version 2.61.13.10 allows attackers to overwrite arbitrary files on the phone via …

Sep 19, 2024
CVE-2024-25673
6.1 MEDIUM

Couchbase Server 7.6.x before 7.6.2, 7.2.x before 7.2.6, and all earlier versions allows HTTP Host header injection.

Sep 19, 2024
CVE-2024-8963
9.4 CRITICAL KEV

Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.

Sep 19, 2024
CVE-2024-47162
4.1 MEDIUM

In JetBrains YouTrack before 2024.3.44799 token could be revealed on Imports page

Sep 19, 2024
CVE-2024-47160
4.3 MEDIUM

In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible

Sep 19, 2024
CVE-2024-47159
4.3 MEDIUM

In JetBrains YouTrack before 2024.3.44799 user without appropriate permissions could restore workflows attached to a project

Sep 19, 2024
CVE-2024-8653
6.1 MEDIUM

A vulnerability in NetCat CMS allows an attacker to execute JavaScript code in a user's browser when they visit specific paths on the site. This …

Sep 19, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.