CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-29847
9.8 CRITICAL

Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to …

Sep 12, 2024
CVE-2024-8707
4.3 MEDIUM

A vulnerability was found in 云课网络科技有限公司 Yunke Online School System up to 3.0.6. It has been declared as problematic. This vulnerability affects the function downfile …

Sep 12, 2024
CVE-2024-8706
4.3 MEDIUM

A vulnerability was found in JFinalCMS up to 20240903. It has been classified as problematic. This affects the function update of the file /admin/template/update of …

Sep 12, 2024
CVE-2024-28981
8.5 HIGH

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.8, including 8.3.x, discloses database passwords when searching metadata injectable fields.

Sep 12, 2024
CVE-2024-8705
6.3 MEDIUM

A vulnerability was found in Shandong Star Measurement and Control Equipment Heating Network Wireless Monitoring System 5.6.2 and classified as critical. Affected by this issue …

Sep 11, 2024
CVE-2024-7890
7.3 HIGH

Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows

Sep 11, 2024
CVE-2024-7889
7.3 HIGH

Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows

Sep 11, 2024
CVE-2024-8694
3.8 LOW

A vulnerability, which was classified as problematic, was found in JFinalCMS up to 20240903. This affects the function update of the file /admin/template/update of the …

Sep 11, 2024
CVE-2024-8693
2.4 LOW

A vulnerability, which was classified as problematic, has been found in Kaon CG3000 1.01.43. Affected by this issue is some unknown functionality of the component …

Sep 11, 2024
CVE-2024-8692
5.3 MEDIUM

A vulnerability classified as critical was found in TDuckCloud TDuckPro up to 6.3. Affected by this vulnerability is an unknown functionality. The manipulation leads to …

Sep 11, 2024
CVE-2024-44541
9.8 CRITICAL

evilnapsis Inventio Lite Versions v4 and before is vulnerable to SQL Injection via the "username" parameter in "/?action=processlogin."

Sep 11, 2024
CVE-2024-42760
7.5 HIGH

SQL Injection vulnerability in Ellevo v.6.2.0.38160 allows a remote attacker to obtain sensitive information via the /api/mob/instrucao/conta/destinatarios component.

Sep 11, 2024
CVE-2024-8691
7.1 HIGH

A vulnerability in the GlobalProtect portal in Palo Alto Networks PAN-OS software enables a malicious authenticated GlobalProtect user to impersonate another GlobalProtect user. Active GlobalProtect …

Sep 11, 2024
CVE-2024-8690
4.4 MEDIUM

A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows administrator privileges to …

Sep 11, 2024
CVE-2024-8689

A problem with the ActiveMQ integration for both Cortex XSOAR and Cortex XSIAM can result in the cleartext exposure of the configured ActiveMQ credentials in …

Sep 11, 2024
CVE-2024-8688
4.4 MEDIUM

An improper neutralization of matching symbols vulnerability in the Palo Alto Networks PAN-OS command line interface (CLI) enables authenticated administrators (including read-only administrators) with access …

Sep 11, 2024
CVE-2024-8687
7.1 HIGH

An information exposure vulnerability exists in Palo Alto Networks PAN-OS software that enables a GlobalProtect end user to learn both the configured GlobalProtect uninstall password …

Sep 11, 2024
CVE-2024-8686
7.2 HIGH

A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as root on …

Sep 11, 2024
CVE-2024-8097

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Payara Platform Payara Server (Logging modules) allows Sensitive credentials posted in plain-text on the server …

Sep 11, 2024
CVE-2024-44577
8.8 HIGH

RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the time_date function.

Sep 11, 2024
CVE-2024-44575
3.7 LOW

RELY-PCIe v22.2.1 to v23.1.0 does not set the Secure attribute for sensitive cookies in HTTPS sessions, which could cause the user agent to send those …

Sep 11, 2024
CVE-2024-44574
8.8 HIGH

RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the sys_conf function.

Sep 11, 2024
CVE-2024-44573
4.7 MEDIUM

A stored cross-site scripting (XSS) vulnerability in the VLAN configuration of RELY-PCIe v22.2.1 to v23.1.0 allows attackers to execute arbitrary web scripts or HTML via …

Sep 11, 2024
CVE-2024-44572
8.8 HIGH

RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the sys_mgmt function.

Sep 11, 2024
CVE-2024-44571
8.8 HIGH

RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain incorrect access control in the mService function at phpinf.php.

Sep 11, 2024
CVE-2024-44570
8.8 HIGH

RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a code injection vulnerability via the getParams function in phpinf.php.

Sep 11, 2024
CVE-2024-20489
8.4 HIGH

A vulnerability in the storage method of the PON Controller configuration file could allow an authenticated, local attacker with low privileges to obtain the MongoDB …

Sep 11, 2024
CVE-2024-20483
7.2 HIGH

Multiple vulnerabilities in Cisco Routed PON Controller Software, which runs as a docker container on hardware that is supported by Cisco IOS XR Software, could …

Sep 11, 2024
CVE-2024-20406
7.4 HIGH

A vulnerability in the segment routing feature for the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker …

Sep 11, 2024
CVE-2024-20398
8.8 HIGH

A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to obtain read/write file system access on the underlying …

Sep 11, 2024
CVE-2024-20390
5.3 MEDIUM

A vulnerability in the Dedicated XML Agent feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service …

Sep 11, 2024
CVE-2024-20381
8.8 HIGH

A vulnerability in the JSON-RPC API feature in Cisco Crosswork Network Services Orchestrator (NSO) and ConfD that is used by the web-based management interfaces of …

Sep 11, 2024
CVE-2024-20343
5.5 MEDIUM

A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to read any file in the file system of …

Sep 11, 2024
CVE-2024-20317
7.4 HIGH

A vulnerability in the handling of specific Ethernet frames by Cisco IOS XR Software for various Cisco Network Convergence System (NCS) platforms could allow an …

Sep 11, 2024
CVE-2024-20304
8.6 HIGH

A vulnerability in the multicast traceroute version 2 (Mtrace2) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to exhaust the UDP …

Sep 11, 2024
CVE-2024-7312
6.1 MEDIUM

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Payara Platform Payara Server (REST Management Interface modules) allows Session Hijacking.This issue affects Payara Server: from …

Sep 11, 2024
CVE-2024-5760
7.8 HIGH

The Samsung Universal Print Driver for Windows is potentially vulnerable to escalation of privilege allowing the creation of a reverse shell in the tool. This …

Sep 11, 2024
CVE-2024-46672
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: cfg80211: Handle SSID based pmksa deletion wpa_supplicant 2.11 sends since 1efdba5fdc2c ("Handle PMKSA …

Sep 11, 2024
CVE-2024-45030
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: igb: cope with large MAX_SKB_FRAGS Sabrina reports that the igb driver does not cope well …

Sep 11, 2024
CVE-2024-45029
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: i2c: tegra: Do not mark ACPI devices as irq safe On ACPI machines, the tegra …

Sep 11, 2024
CVE-2024-45028
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mmc: mmc_test: Fix NULL dereference on allocation failure If the "test->highmem = alloc_pages()" allocation fails …

Sep 11, 2024
CVE-2024-45027
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: xhci: Check for xhci->interrupters being allocated in xhci_mem_clearup() If xhci_mem_init() fails, it calls into …

Sep 11, 2024
CVE-2024-45026
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: s390/dasd: fix error recovery leading to data corruption on ESE devices Extent Space Efficient (ESE) …

Sep 11, 2024
CVE-2024-45025
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fix bitmap corruption on close_range() with CLOSE_RANGE_UNSHARE copy_fd_bitmaps(new, old, count) is expected to copy the …

Sep 11, 2024
CVE-2024-45024
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: fix hugetlb vs. core-mm PT locking We recently made GUP's common page table walking …

Sep 11, 2024
CVE-2024-45023
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: md/raid1: Fix data corruption for degraded array with slow disk read_balance() will avoid reading from …

Sep 11, 2024
CVE-2024-45022
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/vmalloc: fix page mapping if vm_area_alloc_pages() with high order fallback to order 0 The __vmap_pages_range_noflush() …

Sep 11, 2024
CVE-2024-45021
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: memcg_write_event_control(): fix a user-triggerable oops we are *not* guaranteed that anything past the terminating NUL …

Sep 11, 2024
CVE-2024-45020
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix a kernel verifier crash in stacksafe() Daniel Hodges reported a kernel verifier crash …

Sep 11, 2024
CVE-2024-45019
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Take state lock during tx timeout reporter mlx5e_safe_reopen_channels() requires the state lock taken. The …

Sep 11, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.