CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-45181
7.8 HIGH

An issue was discovered in WibuKey64.sys in WIBU-SYSTEMS WibuKey before v6.70 and fixed in v.6.70. An improper bounds check allows crafted packets to cause an …

Sep 12, 2024
CVE-2024-36066
3.1 LOW

The CMP CLI client in KeyFactor EJBCA before 8.3.1 has only 6 octets of salt, and is thus not compliant with the security requirements of …

Sep 12, 2024
CVE-2024-34336
5.3 MEDIUM

User enumeration vulnerability in ORDAT FOSS-Online before v2.24.01 allows attackers to determine if an account exists in the application by comparing the server responses of …

Sep 12, 2024
CVE-2024-34335
6.1 MEDIUM

ORDAT FOSS-Online before version 2.24.01 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the login page.

Sep 12, 2024
CVE-2024-34334
7.5 HIGH

ORDAT FOSS-Online before v2.24.01 was discovered to contain a SQL injection vulnerability via the forgot password function.

Sep 12, 2024
CVE-2024-25270
4.3 MEDIUM

An issue in Mirapolis LMS 4.6.XX allows authenticated users to exploit an Insecure Direct Object Reference (IDOR) vulnerability by manipulating the ID parameter and increment …

Sep 12, 2024
CVE-2024-8696
9.8 CRITICAL

A remote code execution (RCE) vulnerability via crafted extension publisher-url/additional-urls could be abused by a malicious extension in Docker Desktop before 4.34.2.

Sep 12, 2024
CVE-2024-8695
9.8 CRITICAL

A remote code execution (RCE) vulnerability via crafted extension description/changelog could be abused by a malicious extension in Docker Desktop before 4.34.2.

Sep 12, 2024
CVE-2024-41629
5.5 MEDIUM

An issue in Texas Instruments Fusion Digital Power Designer v.7.10.1 allows a local attacker to obtain sensitive information via the plaintext storage of credentials

Sep 12, 2024
CVE-2020-24061
4.3 MEDIUM

Cross Site Scripting (XSS) Vulnerability in Firewall menu in Control Panel in KASDA KW5515 version 4.3.1.0, allows attackers to execute arbitrary code and steal cookies …

Sep 12, 2024
CVE-2024-8754
6.4 MEDIUM

An issue has been discovered in GitLab EE/CE affecting all versions from 16.9.7 prior to 17.1.7, 17.2 prior to 17.2.5, and 17.3 prior to 17.3.2. …

Sep 12, 2024
CVE-2024-8640
8.5 HIGH

An issue has been discovered in GitLab EE affecting all versions starting from 16.11 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 …

Sep 12, 2024
CVE-2024-8635
7.7 HIGH

A server-side request forgery issue has been discovered in GitLab EE affecting all versions starting from 16.8 prior to 17.1.7, from 17.2 prior to 17.2.5, …

Sep 12, 2024
CVE-2024-8631
5.5 MEDIUM

A privilege escalation issue has been discovered in GitLab EE affecting all versions starting from 16.6 prior to 17.1.7, from 17.2 prior to 17.2.5, and …

Sep 12, 2024
CVE-2024-8124
7.5 HIGH

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.1.7, starting from 17.2 prior to 17.2.5, starting from 17.3 …

Sep 12, 2024
CVE-2024-6840
6.6 MEDIUM

An improper authorization flaw exists in the Ansible Automation Controller. This flaw allows an attacker using the k8S API server to send an HTTP request …

Sep 12, 2024
CVE-2024-6446
3.5 LOW

An issue has been discovered in GitLab affecting all versions starting from 17.1 to 17.1.7, 17.2 prior to 17.2.5 and 17.3 prior to 17.3.2. A …

Sep 12, 2024
CVE-2024-6389
4.3 MEDIUM

An issue was discovered in GitLab-CE/EE affecting all versions starting with 17.0 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2. An attacker as a …

Sep 12, 2024
CVE-2024-5435
4.5 MEDIUM

An issue has been discovered discovered in GitLab EE/CE affecting all versions starting from 15.10 before 17.1.7, all versions starting from 17.2 before 17.2.5, all …

Sep 12, 2024
CVE-2024-4660
6.5 MEDIUM

An issue has been discovered in GitLab EE affecting all versions starting from 11.2 before 17.1.7, all versions starting from 17.2 before 17.2.5, all versions …

Sep 12, 2024
CVE-2024-4612
6.4 MEDIUM

An issue has been discovered in GitLab EE affecting all versions starting from 12.9 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2. Under certain …

Sep 12, 2024
CVE-2024-2743
5.3 MEDIUM

An issue was discovered in GitLab-EE starting with version 13.3 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2 that would allow an attacker to …

Sep 12, 2024
CVE-2024-6702
5.2 MEDIUM

Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an HTML Injection issue with Stage.

Sep 12, 2024
CVE-2024-6701
5.5 MEDIUM

Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with case type.

Sep 12, 2024
CVE-2024-6700
5.5 MEDIUM

Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an XSS issue with App name.

Sep 12, 2024
CVE-2024-6658
8.4 HIGH

Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows OS Command Injection.This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.0 (inclusive) …

Sep 12, 2024
CVE-2024-6510
7.8 HIGH

Local Privilege Escalation in AVG Internet Security v24 on Windows allows a local unprivileged user to escalate privileges to SYSTEM via COM-Hijacking.

Sep 12, 2024
CVE-2024-45826
6.8 MEDIUM

CVE-2024-45826 IMPACT Due to improper input validation, a path traversal and remote code execution vulnerability exists when the ThinManager® processes a crafted POST request. If …

Sep 12, 2024
CVE-2024-45825
7.5 HIGH

CVE-2024-45825 IMPACT A denial-of-service vulnerability exists in the affected products. The vulnerability occurs when a malformed CIP packet is sent over the network to the …

Sep 12, 2024
CVE-2024-45823
8.1 HIGH

CVE-2024-45823 IMPACT An authentication bypass vulnerability exists in the affected product. The vulnerability exists due to shared secrets across accounts and could allow a threat …

Sep 12, 2024
CVE-2024-42484
6.5 MEDIUM

ESP-NOW Component provides a connectionless Wi-Fi communication protocol. An Out-of-Bound (OOB) vulnerability was discovered in the implementation of the ESP-NOW group type message because there …

Sep 12, 2024
CVE-2024-42483
6.5 MEDIUM

ESP-NOW Component provides a connectionless Wi-Fi communication protocol. An replay attacks vulnerability was discovered in the implementation of the ESP-NOW because the caches is not …

Sep 12, 2024
CVE-2024-45824
9.8 CRITICAL

CVE-2024-45824 IMPACT A remote code vulnerability exists in the affected products. The vulnerability occurs when chained with Path Traversal, Command Injection, and XSS Vulnerabilities and …

Sep 12, 2024
CVE-2024-40457
9.1 CRITICAL

No-IP Dynamic Update Client (DUC) v3.x uses cleartext credentials that may occur on a command line or in a file. NOTE: the vendor's position is …

Sep 12, 2024
CVE-2024-28991
9.0 CRITICAL

SolarWinds Access Rights Manager (ARM) was found to be susceptible to a remote code execution vulnerability. If exploited, this vulnerability would allow an authenticated user …

Sep 12, 2024
CVE-2024-28990
6.3 MEDIUM

SolarWinds Access Rights Manager (ARM) was found to contain a hard-coded credential authentication bypass vulnerability. If exploited, this vulnerability would allow access to the RabbitMQ …

Sep 12, 2024
CVE-2024-45857
7.8 HIGH

Deserialization of untrusted data can occur in versions 2.4.0 or newer of the Cleanlab project, enabling a maliciously crafted datalab.pkl file to run arbitrary code …

Sep 12, 2024
CVE-2024-45856
9.0 CRITICAL

A cross-site scripting (XSS) vulnerability exists in all versions of the MindsDB platform, enabling the execution of a JavaScript payload whenever a user enumerates an …

Sep 12, 2024
CVE-2024-45855
7.1 HIGH

Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code …

Sep 12, 2024
CVE-2024-45854
7.1 HIGH

Deserialization of untrusted data can occur in versions 23.10.3.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code …

Sep 12, 2024
CVE-2024-45853
7.1 HIGH

Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code …

Sep 12, 2024
CVE-2024-45852
8.8 HIGH

Deserialization of untrusted data can occur in versions 23.3.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded model to run arbitrary code on …

Sep 12, 2024
CVE-2024-45851
8.8 HIGH

An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the …

Sep 12, 2024
CVE-2024-45850
8.8 HIGH

An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the …

Sep 12, 2024
CVE-2024-45849
8.8 HIGH

An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the …

Sep 12, 2024
CVE-2024-45848
8.8 HIGH

An arbitrary code execution vulnerability exists in versions 23.12.4.0 up to 24.7.4.1 of the MindsDB platform, when the ChromaDB integration is installed on the server. …

Sep 12, 2024
CVE-2024-45847
8.8 HIGH

An arbitrary code execution vulnerability exists in versions 23.11.4.2 up to 24.7.4.1 of the MindsDB platform, when one of several integrations is installed on the …

Sep 12, 2024
CVE-2024-45846
8.8 HIGH

An arbitrary code execution vulnerability exists in versions 23.10.3.0 up to 24.7.4.1 of the MindsDB platform, when the Weaviate integration is installed on the server. …

Sep 12, 2024
CVE-2024-3306
7.5 HIGH

Authorization Bypass Through User-Controlled Key vulnerability in Utarit Information SoliClub allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SoliClub: before 4.4.0 for iOS, …

Sep 12, 2024
CVE-2024-3305
7.5 HIGH

Authorization Bypass Through User-Controlled Key, Missing Authorization vulnerability in Utarit Information SoliClub allows Retrieve Embedded Sensitive Data. This issue affects SoliClub: before 4.4.0 for iOS, …

Sep 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.