CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-23984
5.3 MEDIUM

Observable discrepancy in RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.

Sep 16, 2024
CVE-2024-23599
7.9 HIGH

Race condition in Seamless Firmware Updates for some Intel(R) reference platforms may allow a privileged user to potentially enable denial of service via local access.

Sep 16, 2024
CVE-2024-21871
7.5 HIGH

Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

Sep 16, 2024
CVE-2024-21829
7.5 HIGH

Improper input validation in UEFI firmware error handler for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local …

Sep 16, 2024
CVE-2024-21781
7.2 HIGH

Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to enable information disclosure or denial of service via local …

Sep 16, 2024
CVE-2023-43753
5.3 MEDIUM

Improper conditions check in some Intel(R) Processors with Intel(R) SGX may allow a privileged user to potentially enable information disclosure via local access.

Sep 16, 2024
CVE-2023-43626
7.5 HIGH

Improper access control in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

Sep 16, 2024
CVE-2023-42772
8.2 HIGH

Untrusted pointer dereference in UEFI firmware for some Intel(R) reference processors may allow a privileged user to potentially enable escalation of privilege via local access.

Sep 16, 2024
CVE-2023-41833
7.5 HIGH

A race condition in UEFI firmware for some Intel(R) processors may allow a privileged user to potentially enable escalation of privilege via local access.

Sep 16, 2024
CVE-2023-25546
2.5 LOW

Out-of-bounds read in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable denial of service via local access.

Sep 16, 2024
CVE-2023-23904
6.1 MEDIUM

NULL pointer dereference in the UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

Sep 16, 2024
CVE-2023-22351
6.1 MEDIUM

Out-of-bounds write in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

Sep 16, 2024
CVE-2024-8752
7.5 HIGH

The Windows version of WebIQ 2.15.9 is affected by a directory traversal vulnerability that allows remote attackers to read any file on the system.

Sep 16, 2024
CVE-2024-44623
9.8 CRITICAL

An issue in TuomoKu SPx-GC v.1.3.0 and before allows a remote attacker to execute arbitrary code via the child_process.js function.

Sep 16, 2024
CVE-2024-7104
9.8 CRITICAL

Improper Control of Generation of Code ('Code Injection') vulnerability in SFS Consulting ww.Winsure allows Code Injection.This issue affects ww.Winsure: before 4.6.2.

Sep 16, 2024
CVE-2024-7098
9.8 CRITICAL

Improper Restriction of XML External Entity Reference vulnerability in SFS Consulting ww.Winsure allows XML Injection.This issue affects ww.Winsure: before 4.6.2.

Sep 16, 2024
CVE-2024-6401
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SFS Consulting InsureE GL allows SQL Injection.This issue affects InsureE GL: …

Sep 16, 2024
CVE-2024-45835
2.5 LOW

Mattermost Desktop App versions <=5.8.0 fail to sufficiently configure Electron Fuses which allows an attacker to gather Chromium cookies or abuse other misconfigurations via remote/local …

Sep 16, 2024
CVE-2024-39772
3.7 LOW

Mattermost Desktop App versions <=5.8.0 fail to safeguard screen capture functionality which allows an attacker to silently capture high-quality screenshots via JavaScript APIs.

Sep 16, 2024
CVE-2024-38315
6.3 MEDIUM

IBM Aspera Shares 1.0 through 1.10.0 PL3 does not invalidate session after a password reset which could allow an authenticated user to impersonate another user …

Sep 16, 2024
CVE-2024-46419
9.8 CRITICAL

TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the setWizardCfg function via the ssid5g parameter.

Sep 16, 2024
CVE-2024-46937
7.5 HIGH

An improper access control (IDOR) vulnerability in the /api-selfportal/get-info-token-properties endpoint in MFASOFT Secure Authentication Server (SAS) 1.8.x through 1.9.x before 1.9.040924 allows remote attackers gain …

Sep 16, 2024
CVE-2024-46451
9.8 CRITICAL

TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the setWiFiAclRules function via the desc parameter.

Sep 16, 2024
CVE-2024-46424
7.5 HIGH

TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the UploadCustomModule function, which allows attackers to cause a Denial of Service (DoS) via the …

Sep 16, 2024
CVE-2024-22399
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in Apache Seata. When developers disable authentication on the Seata-Server and do not use the Seata client SDK dependencies, they …

Sep 16, 2024
CVE-2024-46970
3.3 LOW

In JetBrains IntelliJ IDEA before 2024.1 hTML injection via the project name was possible

Sep 16, 2024
CVE-2024-45833
4.5 MEDIUM

Mattermost Mobile Apps versions <=2.18.0 fail to disable autocomplete during login while typing the password and visible password is selected, which allows the password to …

Sep 16, 2024
CVE-2024-45698
9.8 CRITICAL

Certain models of D-Link wireless routers do not properly validate user input in the telnet service, allowing unauthenticated remote attackers to use hard-coded credentials to …

Sep 16, 2024
CVE-2024-45697
9.8 CRITICAL

Certain models of D-Link wireless routers have a hidden functionality where the telnet service is enabled when the WAN port is plugged in. Unauthorized remote …

Sep 16, 2024
CVE-2024-45696
8.8 HIGH

Certain models of D-Link wireless routers contain hidden functionality. By sending specific packets to the web service, the attacker can forcibly enable the telnet service …

Sep 16, 2024
CVE-2024-45695
9.8 CRITICAL

The web service of certain models of D-Link wireless routers contains a Stack-based Buffer Overflow vulnerability, which allows unauthenticated remote attackers to exploit this vulnerability …

Sep 16, 2024
CVE-2024-45694
9.8 CRITICAL

The web service of certain models of D-Link wireless routers contains a Stack-based Buffer Overflow vulnerability, which allows unauthenticated remote attackers to exploit this vulnerability …

Sep 16, 2024
CVE-2024-39613
5.3 MEDIUM

Mattermost Desktop App versions <=5.8.0 fail to specify an absolute path when searching the cmd.exe file, which allows a local attacker who is able to …

Sep 16, 2024
CVE-2024-1578
5.3 MEDIUM

The MiCard PLUS Ci and MiCard PLUS BLE reader products developed by rf IDEAS and rebranded by NT-ware have a firmware fault that may result …

Sep 16, 2024
CVE-2024-8780
6.5 MEDIUM

OMFLOW from The SYSCOM Group does not properly restrict the query range of its data query functionality, allowing remote attackers with regular privileges to obtain …

Sep 16, 2024
CVE-2024-8779
8.8 HIGH

OMFLOW from The SYSCOM Group does not properly restrict access to the system settings modification functionality, allowing remote attackers with regular privileges to update system …

Sep 16, 2024
CVE-2024-8778
6.5 MEDIUM

OMFLOW from The SYSCOM Group does not properly validate user input of the download functionality, allowing remote attackers with regular privileges to read arbitrary system …

Sep 16, 2024
CVE-2024-8777
7.5 HIGH

OMFLOW from The SYSCOM Group has an information leakage vulnerability, allowing unauthorized remote attackers to read arbitrary system configurations. If LDAP authentication is enabled, attackers …

Sep 16, 2024
CVE-2024-8776
6.1 MEDIUM

SmartRobot from INTUMIT does not properly validate a specific page parameter, allowing unautheticated remote attackers to inject JavaScript code to the parameter for Reflected Cross-site …

Sep 16, 2024
CVE-2024-46958
9.1 CRITICAL

In Nextcloud Desktop Client 3.13.1 through 3.13.3 on Linux, synchronized files (between the server and client) may become world writable or world readable. This is …

Sep 16, 2024
CVE-2024-8880
5.6 MEDIUM

A vulnerability classified as critical has been found in playSMS 1.4.4/1.4.5/1.4.6/1.4.7. Affected is an unknown function of the file /playsms/index.php?app=main&inc=core_auth&route=forgot&op=forgot of the component Template Handler. …

Sep 16, 2024
CVE-2024-46943
7.5 HIGH

An issue was discovered in OpenDaylight Authentication, Authorization and Accounting (AAA) through 0.19.3. A rogue controller can join a cluster to impersonate an offline peer, …

Sep 15, 2024
CVE-2024-46942
6.5 MEDIUM

In OpenDaylight Model-Driven Service Abstraction Layer (MD-SAL) through 13.0.1, a controller with a follower role can configure flow entries in an OpenDaylight clustering deployment.

Sep 15, 2024
CVE-2024-8876
4.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in xiaohe4966 TpMeCMS up to 1.3.3.1. Affected by this issue is some unknown functionality of …

Sep 15, 2024
CVE-2024-8875
5.4 MEDIUM

A vulnerability classified as critical was found in vedees wcms up to 0.3.2. Affected by this vulnerability is an unknown functionality of the file /wex/finder.php. …

Sep 15, 2024
CVE-2024-46938
7.5 HIGH

An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release through 10.4 Initial Release. An unauthenticated …

Sep 15, 2024
CVE-2024-46918
4.9 MEDIUM

app/Controller/UserLoginProfilesController.php in MISP before 2.4.198 does not prevent an org admin from viewing sensitive login fields of another org admin in the same org.

Sep 15, 2024
CVE-2024-8869
5.0 MEDIUM

A vulnerability classified as critical has been found in TOTOLINK A720R 4.1.5. Affected is the function exportOvpn. The manipulation leads to os command injection. It …

Sep 15, 2024
CVE-2024-44059
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ronald Huereca Custom Query Blocks post-type-archive-mapping allows DOM-Based XSS.This issue affects Custom Query …

Sep 15, 2024
CVE-2024-44058
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CryoutCreations Parabola allows Stored XSS.This issue affects Parabola: from n/a through …

Sep 15, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.