CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-8652
6.1 MEDIUM

A vulnerability in NetCat CMS allows an attacker to execute JavaScript code in a user's browser when they visit specific path on the site. This …

Sep 19, 2024
CVE-2024-8651
5.3 MEDIUM

A vulnerability in NetCat CMS allows an attacker to send a specially crafted http request that can be used to check whether a user exists …

Sep 19, 2024
CVE-2024-38016
7.8 HIGH

Microsoft Office Visio Remote Code Execution Vulnerability

Sep 19, 2024
CVE-2024-31570
9.8 CRITICAL

libfreeimage in FreeImage 3.4.0 through 3.18.0 has a stack-based buffer overflow in the PluginXPM.cpp Load function via an XPM file.

Sep 19, 2024
CVE-2024-8883
6.1 MEDIUM

A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' …

Sep 19, 2024
CVE-2024-8698
7.7 HIGH

A flaw exists in the SAML signature validation method within the Keycloak XMLSignatureUtil class. The method incorrectly determines whether a SAML signature is for the …

Sep 19, 2024
CVE-2024-8375
7.8 HIGH

There exists a use after free vulnerability in Reverb. Reverb supports the VARIANT datatype, which is supposed to represent an arbitrary object in C++. When …

Sep 19, 2024
CVE-2024-7737
8.7 HIGH

A stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script …

Sep 19, 2024
CVE-2024-7736
8.7 HIGH

A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary …

Sep 19, 2024
CVE-2024-45862
7.5 HIGH

Kastle Systems firmware prior to May 1, 2024, stored machine credentials in cleartext, which may allow an attacker to access sensitive information.

Sep 19, 2024
CVE-2024-45861
7.5 HIGH

Kastle Systems firmware prior to May 1, 2024, contained a hard-coded credential, which if accessed may allow an attacker to access sensitive information.

Sep 19, 2024
CVE-2024-45752
8.5 HIGH

logiops through 0.3.4, in its default configuration, allows any unprivileged user to configure its logid daemon via an unrestricted D-Bus service, including setting malicious keyboard …

Sep 19, 2024
CVE-2024-7785

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ece Software Electronic Ticket System allows Reflected XSS, Cross-Site Scripting (XSS).This …

Sep 19, 2024
CVE-2024-46394
8.8 HIGH

FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/?/user/add

Sep 19, 2024
CVE-2024-46382
7.5 HIGH

A SQL injection vulnerability in linlinjava litemall 1.8.0 allows a remote attacker to obtain sensitive information via the goodsId, goodsSn, and name parameters in AdminOrderController.java.

Sep 19, 2024
CVE-2024-8986

The grafana plugin SDK bundles build metadata into the binaries it compiles; this metadata includes the repository URI for the plugin being built, as retrieved …

Sep 19, 2024
CVE-2024-8354
5.5 MEDIUM

A flaw was found in QEMU. An assertion failure was present in the usb_ep_get() function in hw/net/core.c when trying to get the USB endpoint from …

Sep 19, 2024
CVE-2024-45770
4.4 MEDIUM

A vulnerability was found in Performance Co-Pilot (PCP). This flaw can only be exploited if an attacker has access to a compromised PCP system account. …

Sep 19, 2024
CVE-2024-45769
5.5 MEDIUM

A vulnerability was found in Performance Co-Pilot (PCP). This flaw allows an attacker to send specially crafted data to the system, which could cause the …

Sep 19, 2024
CVE-2024-47089
6.5 MEDIUM

This vulnerability exists in the Apex Softcell LD Geo due to improper validation of the transaction token ID in the API endpoint. An authenticated remote …

Sep 19, 2024
CVE-2024-47088
9.8 CRITICAL

This vulnerability exists in Apex Softcell LD Geo due to missing restrictions for excessive failed authentication attempts on its API based login. A remote attacker …

Sep 19, 2024
CVE-2024-47087
6.5 MEDIUM

This vulnerability exists in Apex Softcell LD Geo due to improper validation of the certain parameters (Client ID, DPID or BOID) in the API endpoint. …

Sep 19, 2024
CVE-2024-47086
6.5 MEDIUM

This vulnerability exists in Apex Softcell LD DP Back Office due to improper implementation of OTP validation mechanism in certain API endpoints. An authenticated remote …

Sep 19, 2024
CVE-2024-47085
6.5 MEDIUM

This vulnerability exists in Apex Softcell LD DP Back Office due to improper validation of certain parameters (cCdslClicentcode and cLdClientCode) in the API endpoint. An …

Sep 19, 2024
CVE-2024-46946
9.8 CRITICAL

langchain_experimental (aka LangChain Experimental) 0.1.17 through 0.3.0 for LangChain allows attackers to execute arbitrary code through sympy.sympify (which uses eval) in LLMSymbolicMathChain. LLMSymbolicMathChain was introduced …

Sep 19, 2024
CVE-2024-8850
6.1 MEDIUM

The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'email' parameter when a placeholder such as {email} is …

Sep 19, 2024
CVE-2024-8364
6.4 MEDIUM

The WP Custom Fields Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpcfs-preset shortcode in all versions up to, and …

Sep 19, 2024
CVE-2022-4533
5.3 MEDIUM

The Limit Login Attempts Plus plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.1.0. This is due to …

Sep 19, 2024
CVE-2024-7254
7.5 HIGH

Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags can corrupted by exceeding the …

Sep 19, 2024
CVE-2024-47059
4.3 MEDIUM

When logging in with the correct username and incorrect weak password, the user receives the notification, that their password is too weak. However when an …

Sep 18, 2024
CVE-2024-37406
7.5 HIGH

In Brave Android prior to v1.67.116, domains in the Brave Shields popup are elided from the right instead of the left, which may lead to …

Sep 18, 2024
CVE-2022-25770
7.8 HIGH

Mautic allows you to update the application via an upgrade script. The upgrade logic isn't shielded off correctly, which may lead to vulnerable situation. This …

Sep 18, 2024
CVE-2021-27917
7.3 HIGH

Prior to this patch, a stored XSS vulnerability existed in the contact tracking and page hits report.

Sep 18, 2024
CVE-2024-47058
2.9 LOW

With access to edit a Mautic form, the attacker can add Cross-Site Scripting stored in the html filed. This could be used to steal sensitive …

Sep 18, 2024
CVE-2024-47050
5.4 MEDIUM

Prior to this patch being applied, Mautic's tracking was vulnerable to Cross-Site Scripting through the Page URL variable.

Sep 18, 2024
CVE-2024-46377
9.8 CRITICAL

Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the save_settings() function of the file rental/admin_class.php.

Sep 18, 2024
CVE-2024-46376
9.8 CRITICAL

Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the update_account() function of the file rental/admin_class.php.

Sep 18, 2024
CVE-2024-46375
9.8 CRITICAL

Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the signup() function of the file rental/admin_class.php.

Sep 18, 2024
CVE-2024-46374
9.8 CRITICAL

Best House Rental Management System 1.0 contains a SQL injection vulnerability in the delete_category() function of the file rental/admin_class.php.

Sep 18, 2024
CVE-2024-46373
8.8 HIGH

Dedecms V5.7.115 contains an arbitrary code execution via file upload vulnerability in the backend.

Sep 18, 2024
CVE-2024-46372
6.1 MEDIUM

DedeCMS 5.7.115 is vulnerable to Cross Site Scripting (XSS) via the advertisement code box in the advertisement management module.

Sep 18, 2024
CVE-2024-40568
9.8 CRITICAL

Buffer Overflow vulnerability in btstack mesh commit before v.864e2f2b6b7878c8fab3cf5ee84ae566e3380c58 allows a remote attacker to execute arbitrary code via the pb_adv_handle_tranaction_cont function in the src/mesh/pb_adv.c component

Sep 18, 2024
CVE-2023-30464
7.5 HIGH

CoreDNS through 1.10.1 enables attackers to achieve DNS cache poisoning and inject fake responses via a birthday attack.

Sep 18, 2024
CVE-2022-25768
7.0 HIGH

The logic in place to facilitate the update process via the user interface lacks access control to verify if permission exists to perform the tasks. …

Sep 18, 2024
CVE-2024-44589
8.8 HIGH

Stack overflow vulnerability in the Login function in the HNAP service in D-Link DCS-960L with firmware 1.09 allows attackers to execute of arbitrary code.

Sep 18, 2024
CVE-2024-43025
6.1 MEDIUM

An HTML injection vulnerability in RWS MultiTrans v7.0.23324.2 and earlier allows attackers to alter the HTML-layout and possibly execute a phishing attack via a crafted …

Sep 18, 2024
CVE-2024-43024
6.1 MEDIUM

Multiple stored cross-site scripting (XSS) vulnerabilities in RWS MultiTrans v7.0.23324.2 and earlier allow attackers to execute arbitrary web scripts or HTML via a crafted payload.

Sep 18, 2024
CVE-2024-39339
7.5 HIGH

A vulnerability has been discovered in all versions of Smartplay headunits, which are widely used in Suzuki and Toyota cars. This misconfiguration can lead to …

Sep 18, 2024
CVE-2024-8287
7.5 HIGH

Anbox Management Service, in versions 1.17.0 through 1.23.0, does not validate the TLS certificate provided to it by the Anbox Stream Agent. An attacker must …

Sep 18, 2024
CVE-2024-34057
7.5 HIGH

Triangle Microworks TMW IEC 61850 Client source code libraries before 12.2.0 lack a buffer size check when processing received messages. The resulting buffer overflow can …

Sep 18, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.