CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-43978
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in highwarden Super Store Finder superstorefinder-wp.This issue affects Super Store Finder: from …

Sep 17, 2024
CVE-2024-43977
5.9 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POSIMYTH The Plus Addons for Elementor Page Builder Lite the-plus-addons-for-elementor-page-builder allows Stored XSS.This …

Sep 17, 2024
CVE-2024-43976
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in highwarden Super Store Finder superstorefinder-wp.This issue affects Super Store Finder: from …

Sep 17, 2024
CVE-2024-43969
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Spiffy Plugins Spiffy Calendar allows SQL Injection.This issue affects Spiffy Calendar: …

Sep 17, 2024
CVE-2024-43938
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeroen Peters Name Directory name-directory.This issue affects Name Directory: from n/a through <= …

Sep 17, 2024
CVE-2024-37985
5.9 MEDIUM

Windows Kernel Information Disclosure Vulnerability

Sep 17, 2024
CVE-2024-46982
7.5 HIGH

Next.js is a React framework for building full-stack web applications. By sending a crafted HTTP request, it is possible to poison the cache of a …

Sep 17, 2024
CVE-2024-8957
7.2 HIGH KEV

PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an OS command injection issue. The camera does not sufficiently validate the ntp_addr configuration value which may …

Sep 17, 2024
CVE-2024-8909
4.3 MEDIUM

Inappropriate implementation in UI in Google Chrome on iOS prior to 129.0.6668.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. …

Sep 17, 2024
CVE-2024-8908
4.3 MEDIUM

Inappropriate implementation in Autofill in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security …

Sep 17, 2024
CVE-2024-8907
6.1 MEDIUM

Insufficient data validation in Omnibox in Google Chrome on Android prior to 129.0.6668.58 allowed a remote attacker who convinced a user to engage in specific …

Sep 17, 2024
CVE-2024-8906
4.3 MEDIUM

Incorrect security UI in Downloads in Google Chrome prior to 129.0.6668.58 allowed a remote attacker who convinced a user to engage in specific UI gestures …

Sep 17, 2024
CVE-2024-8905
8.8 HIGH

Inappropriate implementation in V8 in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page. (Chromium …

Sep 17, 2024
CVE-2024-8904
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Sep 17, 2024
CVE-2024-46976
6.5 MEDIUM

Backstage is an open framework for building developer portals. An attacker with control of the contents of the TechDocs storage buckets is able to inject …

Sep 17, 2024
CVE-2024-45816
6.5 MEDIUM

Backstage is an open framework for building developer portals. When using the AWS S3 or GCS storage provider for TechDocs it is possible to access …

Sep 17, 2024
CVE-2024-45815
6.5 MEDIUM

Backstage is an open framework for building developer portals. A malicious actor with authenticated access to a Backstage instance with the catalog backend plugin installed …

Sep 17, 2024
CVE-2024-8956
9.1 CRITICAL KEV

PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an insufficient authentication issue. The camera does not properly enforce authentication to /cgi-bin/param.cgi when requests are sent …

Sep 17, 2024
CVE-2024-8951
3.5 LOW

A vulnerability classified as problematic was found in SourceCodester Resort Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the file manage_fee.php. …

Sep 17, 2024
CVE-2024-45812
6.4 MEDIUM

Vite a frontend build tooling framework for javascript. Affected versions of vite were discovered to contain a DOM Clobbering vulnerability when building scripts to `cjs`/`iife`/`umd` …

Sep 17, 2024
CVE-2024-45811
4.8 MEDIUM

Vite a frontend build tooling framework for javascript. In affected versions the contents of arbitrary files can be returned to the browser. `@fs` denies access …

Sep 17, 2024
CVE-2024-45606
7.1 HIGH

Sentry is a developer-first error tracking and performance monitoring platform. An authenticated user can mute alert rules from arbitrary organizations and projects with a know …

Sep 17, 2024
CVE-2024-45605
6.5 MEDIUM

Sentry is a developer-first error tracking and performance monitoring platform. An authenticated user delete the user issue alert notifications for arbitrary users given a know …

Sep 17, 2024
CVE-2024-45604
4.3 MEDIUM

Contao is an Open Source CMS. In affected versions authenticated users in the back end can list files outside the document root in the file …

Sep 17, 2024
CVE-2024-45398
8.3 HIGH

Contao is an Open Source CMS. In affected versions a back end user with access to the file manager can upload malicious files and execute …

Sep 17, 2024
CVE-2024-8949
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Online Eyewear Shop 1.0. This affects an unknown part of the file /classes/Master.php of the …

Sep 17, 2024
CVE-2024-8948
7.3 HIGH

A vulnerability was found in MicroPython 1.23.0. It has been rated as critical. Affected by this issue is the function mpz_as_bytes of the file py/objint.c. …

Sep 17, 2024
CVE-2024-8947
5.6 MEDIUM

A vulnerability was found in MicroPython 1.22.2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file py/objarray.c. …

Sep 17, 2024
CVE-2024-8946
7.3 HIGH

A vulnerability was found in MicroPython 1.23.0. It has been classified as critical. Affected is the function mp_vfs_umount of the file extmod/vfs.c of the component …

Sep 17, 2024
CVE-2024-8900
7.5 HIGH

An attacker could write data to the user's clipboard, bypassing the user prompt, during a certain sequence of navigational events. This vulnerability affects Firefox < …

Sep 17, 2024
CVE-2024-8660
4.8 MEDIUM

Concrete CMS versions 9.0.0 through 9.3.3 are affected by a stored XSS vulnerability in the "Top Navigator Bar" block. Since the "Top Navigator Bar" output …

Sep 17, 2024
CVE-2024-45803
6.1 MEDIUM

Wire UI is a library of components and resources to empower Laravel and Livewire application development. A potential Cross-Site Scripting (XSS) vulnerability has been identified …

Sep 17, 2024
CVE-2024-45798
9.9 CRITICAL

arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. The `arduino-esp32` CI is vulnerable to multiple Poisoned Pipeline Execution …

Sep 17, 2024
CVE-2024-45612
5.3 MEDIUM

Contao is an Open Source CMS. In affected versions an untrusted user can inject insert tags into the canonical tag, which are then replaced on …

Sep 17, 2024
CVE-2024-45537
6.5 MEDIUM

Apache Druid allows users with certain permissions to read data from other database systems using JDBC. This functionality allows trusted users to set up Druid …

Sep 17, 2024
CVE-2024-45384
5.3 MEDIUM

Padding Oracle vulnerability in Apache Druid extension, druid-pac4j. This could allow an attacker to manipulate a pac4j session cookie. This issue affects Apache Druid versions …

Sep 17, 2024
CVE-2024-43460
8.1 HIGH

Improper authorization in Dynamics 365 Business Central resulted in a vulnerability that allows an authenticated attacker to elevate privileges over a network.

Sep 17, 2024
CVE-2024-38183
9.8 CRITICAL

An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network.

Sep 17, 2024
CVE-2024-8945
5.5 MEDIUM

A vulnerability has been found in CodeCanyon RISE Ultimate Project Manager 3.7.0 and classified as critical. This vulnerability affects unknown code of the file /index.php/dashboard/save. …

Sep 17, 2024
CVE-2024-8944
7.3 HIGH

A vulnerability, which was classified as critical, was found in code-projects Hospital Management System 1.0. This affects an unknown part of the file check_availability.php. The …

Sep 17, 2024
CVE-2024-8796
5.3 MEDIUM

Under the default configuration, Devise-Two-Factor versions >= 2.2.0 & < 6.0.0 generate TOTP shared secrets that are 120 bits instead of the 128-bit minimum defined …

Sep 17, 2024
CVE-2024-45804

Rejected reason: This CVE is a duplicate of another CVE.

Sep 17, 2024
CVE-2024-45682
8.8 HIGH

There is a command injection vulnerability that may allow an attacker to inject malicious input on the device's operating system.

Sep 17, 2024
CVE-2024-42503
7.2 HIGH

Authenticated command execution vulnerability exist in the ArubaOS command line interface (CLI). Successful exploitation of this vulnerabilities result in the ability to run arbitrary commands …

Sep 17, 2024
CVE-2024-42502
7.2 HIGH

Authenticated command injection vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability result in the ability to inject shell commands on …

Sep 17, 2024
CVE-2024-42501
7.2 HIGH

An authenticated Path Traversal vulnerabilities exists in the ArubaOS. Successful exploitation of this vulnerability allows an attacker to install unsigned packages on the underlying operating …

Sep 17, 2024
CVE-2024-38813
7.5 HIGH KEV

The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to …

Sep 17, 2024
CVE-2024-38812
9.8 CRITICAL KEV

The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger …

Sep 17, 2024
CVE-2024-38380
5.5 MEDIUM

This vulnerability occurs when user-supplied input is improperly sanitized and then reflected back to the user's browser, allowing an attacker to execute arbitrary JavaScript in …

Sep 17, 2024
CVE-2024-8939
6.2 MEDIUM

A vulnerability was found in the ilab model serve component, where improper handling of the best_of parameter in the vllm JSON web API can lead …

Sep 17, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.