CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-25073
5.9 MEDIUM

An issue was discovered in Samsung Semiconductor Mobile Processor and Modem Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos 850, Exynos 1080, Exynos 2100, …

Sep 10, 2024
CVE-2024-23185
7.5 HIGH

Very large headers can cause resource exhaustion when parsing message. The message-parser normally reads reasonably sized chunks of the message. However, when it feeds them …

Sep 10, 2024
CVE-2024-23184
5.0 MEDIUM

Having a large number of address headers (From, To, Cc, Bcc, etc.) becomes excessively CPU intensive. With 100k header lines CPU usage is already 12 …

Sep 10, 2024
CVE-2024-21753
5.5 MEDIUM

A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiClientEMS versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.13, 6.4.0 through 6.4.9, …

Sep 10, 2024
CVE-2023-44254
5.0 MEDIUM

An authorization bypass through user-controlled key [CWE-639] vulnerability in FortiAnalyzer version 7.4.1 and before 7.2.5 and FortiManager version 7.4.1 and before 7.2.5 may allow a …

Sep 10, 2024
CVE-2022-45856
4.8 MEDIUM

An improper certificate validation vulnerability [CWE-295] in FortiClientWindows 6.4 all versions, 7.0.0 through 7.0.7, FortiClientMac 6.4 all versions, 7.0 all versions, 7.2.0 through 7.2.4, FortiClientLinux …

Sep 10, 2024
CVE-2024-8654
5.0 MEDIUM

MongoDB Server may access non-initialized region of memory leading to unexpected behaviour when zero arguments are called in internal aggregation stage. This issue affected MongoDB …

Sep 10, 2024
CVE-2024-8443
2.9 LOW

A heap-based buffer overflow vulnerability was found in the libopensc OpenPGP driver. A crafted USB device or smart card with malicious responses to the APDUs …

Sep 10, 2024
CVE-2024-44867
7.5 HIGH

phpok v3.0 was discovered to contain an arbitrary file read vulnerability via the component /autoload/file.php.

Sep 10, 2024
CVE-2024-37728
7.5 HIGH

Arbitrary File Read vulnerability in Xi'an Daxi Information Technology Co., Ltd OfficeWeb365 v.7.18.23.0 and v8.6.1.0 allows a remote attacker to obtain sensitive information via the …

Sep 10, 2024
CVE-2023-37231
9.8 CRITICAL

Loftware Spectrum before 4.6 HF14 uses a Hard-coded Password.

Sep 10, 2024
CVE-2023-37230
8.8 HIGH

Loftware Spectrum (testDeviceConnection) before 5.1 allows SSRF.

Sep 10, 2024
CVE-2023-37229
8.8 HIGH

Loftware Spectrum before 5.1 allows SSRF.

Sep 10, 2024
CVE-2023-37227
9.8 CRITICAL

Loftware Spectrum before 4.6 HF13 Deserializes Untrusted Data.

Sep 10, 2024
CVE-2023-37226
9.8 CRITICAL

Loftware Spectrum before 4.6 HF14 has Missing Authentication for a Critical Function.

Sep 10, 2024
CVE-2024-8369
5.3 MEDIUM

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access to Private or Password-protected events due to missing authorization …

Sep 10, 2024
CVE-2024-6282
5.4 MEDIUM

The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-jltma-wrapper-link …

Sep 10, 2024
CVE-2024-7770
8.8 HIGH

The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to arbitrary file …

Sep 10, 2024
CVE-2024-45845

Rejected reason: DO NOT USE THIS CVE RECORD. Consult IDs: CVE-2024-45593. Reason: This record is a reservation duplicate of CVE-2024-45593. Notes: All CVE users should …

Sep 10, 2024
CVE-2024-40754
9.8 CRITICAL

Heap-based Buffer Overflow vulnerability in Samsung Open Source Escargot JavaScript engine allows Overflow Buffers.This issue affects Escargot: 4.0.0.

Sep 10, 2024
CVE-2024-8645
5.5 MEDIUM

SPRT dissector crash in Wireshark 4.2.0 to 4.0.5 and 4.0.0 to 4.0.15 allows denial of service via packet injection or crafted capture file

Sep 10, 2024
CVE-2024-8543
6.4 MEDIUM

The Slider comparison image before and after plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [sciba] shortcode in all versions up …

Sep 10, 2024
CVE-2024-8241
6.4 MEDIUM

The Nova Blocks by Pixelgrade plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'align' attribute of the 'wp:separator' Gutenberg block in all …

Sep 10, 2024
CVE-2024-45032
10.0 CRITICAL

A vulnerability has been identified in Industrial Edge Management Pro (All versions < V1.9.5), Industrial Edge Management Virtual (All versions < V2.3.1-1). Affected components do …

Sep 10, 2024
CVE-2024-44087
8.6 HIGH

A vulnerability has been identified in Automation License Manager V5 (All versions), Automation License Manager V6.0 (All versions < V6.0 SP12 Upd3), Automation License Manager …

Sep 10, 2024
CVE-2024-43781
5.5 MEDIUM

A vulnerability has been identified in SINUMERIK 828D V4 (All versions < V4.95 SP3), SINUMERIK 840D sl V4 (All versions < V4.95 SP3 in connection …

Sep 10, 2024
CVE-2024-43647
7.5 HIGH

A vulnerability has been identified in SIMATIC S7-200 SMART CPU CR40 (6ES7288-1CR40-0AA0) (All versions), SIMATIC S7-200 SMART CPU CR60 (6ES7288-1CR60-0AA0) (All versions), SIMATIC S7-200 SMART …

Sep 10, 2024
CVE-2024-42345
4.3 MEDIUM

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP2). The affected application does not properly handle user session establishment …

Sep 10, 2024
CVE-2024-42344
4.4 MEDIUM

A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 SP2). The affected application inserts sensitive information into a log file …

Sep 10, 2024
CVE-2024-41171
8.8 HIGH

A vulnerability has been identified in SINUMERIK 828D V4 (All versions), SINUMERIK 828D V5 (All versions < V5.24), SINUMERIK 840D sl V4 (All versions), SINUMERIK …

Sep 10, 2024
CVE-2024-41170
7.8 HIGH

A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0015), Tecnomatix Plant Simulation V2404 (All versions < V2404.0004). The affected applications …

Sep 10, 2024
CVE-2024-37995
2.7 LOW

A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6BC10-0AA0) (All versions < V4.2), SIMATIC …

Sep 10, 2024
CVE-2024-37994
4.3 MEDIUM

A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6BC10-0AA0) (All versions < V4.2), SIMATIC …

Sep 10, 2024
CVE-2024-37993
5.3 MEDIUM

A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6BC10-0AA0) (All versions < V4.2), SIMATIC …

Sep 10, 2024
CVE-2024-37992
4.9 MEDIUM

A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6BC10-0AA0) (All versions < V4.2), SIMATIC …

Sep 10, 2024
CVE-2024-37991
5.3 MEDIUM

A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6BC10-0AA0) (All versions < V4.2), SIMATIC …

Sep 10, 2024
CVE-2024-37990
6.5 MEDIUM

A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6BC10-0AA0) (All versions < V4.2), SIMATIC …

Sep 10, 2024
CVE-2024-35783
9.1 CRITICAL

A vulnerability has been identified in SIMATIC BATCH V9.1 (All versions), SIMATIC Information Server 2020 (All versions < V2020 SP2 Update 5), SIMATIC Information Server …

Sep 10, 2024
CVE-2024-33698
9.8 CRITICAL

A vulnerability has been identified in Opcenter Quality (All versions < V2406), Opcenter RDnL (All versions < V2410), SIMATIC PCS neo V4.0 (All versions), SIMATIC …

Sep 10, 2024
CVE-2024-32006
4.3 MEDIUM

A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 SP2). The affected application does not expire the user session on …

Sep 10, 2024
CVE-2023-49069
5.3 MEDIUM

A vulnerability has been identified in Mendix Runtime V10 (All versions < V10.17.0 only if the basic authentication mechanism is used by the application), Mendix …

Sep 10, 2024
CVE-2023-30756
5.9 MEDIUM

A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 (incl. SIPLUS variants) (All versions …

Sep 10, 2024
CVE-2023-30755
4.4 MEDIUM

A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 (incl. SIPLUS variants) (All versions …

Sep 10, 2024
CVE-2023-2919
4.3 MEDIUM

The Tutor LMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.4. This is due to missing or …

Sep 10, 2024
CVE-2023-28827
5.9 MEDIUM

A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 (incl. SIPLUS variants) (All versions …

Sep 10, 2024
CVE-2024-8258
7.8 HIGH

Improper Control of Generation of Code ('Code Injection') in Electron Fuses in Logitech Options Plus version 1.60.496306 on macOS allows attackers to execute arbitrary code …

Sep 10, 2024
CVE-2024-7699
8.8 HIGH

An low privileged remote attacker can execute OS commands with root privileges due to improper neutralization of special elements in user data.

Sep 10, 2024
CVE-2024-7698
5.7 MEDIUM

A low privileged remote attacker can get access to CSRF tokens of higher privileged users which can be abused to mount CSRF attacks.

Sep 10, 2024
CVE-2024-43393
8.1 HIGH

A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the …

Sep 10, 2024
CVE-2024-43392
8.1 HIGH

A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the …

Sep 10, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.