CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-27257
4.3 MEDIUM

IBM OpenPages 8.3 and 9.0 potentially exposes information about client-side source code through use of JavaScript source maps to unauthorized users.

Sep 10, 2024
CVE-2024-25074
5.9 MEDIUM

An issue was discovered in Samsung Semiconductor Mobile Processor and Modem Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos 850, Exynos 1080, Exynos 2100, …

Sep 10, 2024
CVE-2024-25073
5.9 MEDIUM

An issue was discovered in Samsung Semiconductor Mobile Processor and Modem Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos 850, Exynos 1080, Exynos 2100, …

Sep 10, 2024
CVE-2024-23185
7.5 HIGH

Very large headers can cause resource exhaustion when parsing message. The message-parser normally reads reasonably sized chunks of the message. However, when it feeds them …

Sep 10, 2024
CVE-2024-23184
5.0 MEDIUM

Having a large number of address headers (From, To, Cc, Bcc, etc.) becomes excessively CPU intensive. With 100k header lines CPU usage is already 12 …

Sep 10, 2024
CVE-2024-21753
5.5 MEDIUM

A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiClientEMS versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.13, 6.4.0 through 6.4.9, …

Sep 10, 2024
CVE-2023-44254
5.0 MEDIUM

An authorization bypass through user-controlled key [CWE-639] vulnerability in FortiAnalyzer version 7.4.1 and before 7.2.5 and FortiManager version 7.4.1 and before 7.2.5 may allow a …

Sep 10, 2024
CVE-2022-45856
4.8 MEDIUM

An improper certificate validation vulnerability [CWE-295] in FortiClientWindows 6.4 all versions, 7.0.0 through 7.0.7, FortiClientMac 6.4 all versions, 7.0 all versions, 7.2.0 through 7.2.4, FortiClientLinux …

Sep 10, 2024
CVE-2024-8654
5.0 MEDIUM

MongoDB Server may access non-initialized region of memory leading to unexpected behaviour when zero arguments are called in internal aggregation stage. This issue affected MongoDB …

Sep 10, 2024
CVE-2024-8443
2.9 LOW

A heap-based buffer overflow vulnerability was found in the libopensc OpenPGP driver. A crafted USB device or smart card with malicious responses to the APDUs …

Sep 10, 2024
CVE-2024-44867
7.5 HIGH

phpok v3.0 was discovered to contain an arbitrary file read vulnerability via the component /autoload/file.php.

Sep 10, 2024
CVE-2024-37728
7.5 HIGH

Arbitrary File Read vulnerability in Xi'an Daxi Information Technology Co., Ltd OfficeWeb365 v.7.18.23.0 and v8.6.1.0 allows a remote attacker to obtain sensitive information via the …

Sep 10, 2024
CVE-2023-37231
9.8 CRITICAL

Loftware Spectrum before 4.6 HF14 uses a Hard-coded Password.

Sep 10, 2024
CVE-2023-37230
8.8 HIGH

Loftware Spectrum (testDeviceConnection) before 5.1 allows SSRF.

Sep 10, 2024
CVE-2023-37229
8.8 HIGH

Loftware Spectrum before 5.1 allows SSRF.

Sep 10, 2024
CVE-2023-37227
9.8 CRITICAL

Loftware Spectrum before 4.6 HF13 Deserializes Untrusted Data.

Sep 10, 2024
CVE-2023-37226
9.8 CRITICAL

Loftware Spectrum before 4.6 HF14 has Missing Authentication for a Critical Function.

Sep 10, 2024
CVE-2024-8369
5.3 MEDIUM

The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized access to Private or Password-protected events due to missing authorization …

Sep 10, 2024
CVE-2024-6282
5.4 MEDIUM

The Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the data-jltma-wrapper-link …

Sep 10, 2024
CVE-2024-7770
8.8 HIGH

The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to arbitrary file …

Sep 10, 2024
CVE-2024-45845

Rejected reason: DO NOT USE THIS CVE RECORD. Consult IDs: CVE-2024-45593. Reason: This record is a reservation duplicate of CVE-2024-45593. Notes: All CVE users should …

Sep 10, 2024
CVE-2024-40754
9.8 CRITICAL

Heap-based Buffer Overflow vulnerability in Samsung Open Source Escargot JavaScript engine allows Overflow Buffers.This issue affects Escargot: 4.0.0.

Sep 10, 2024
CVE-2024-8645
5.5 MEDIUM

SPRT dissector crash in Wireshark 4.2.0 to 4.0.5 and 4.0.0 to 4.0.15 allows denial of service via packet injection or crafted capture file

Sep 10, 2024
CVE-2024-8543
6.4 MEDIUM

The Slider comparison image before and after plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's [sciba] shortcode in all versions up …

Sep 10, 2024
CVE-2024-8241
6.4 MEDIUM

The Nova Blocks by Pixelgrade plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'align' attribute of the 'wp:separator' Gutenberg block in all …

Sep 10, 2024
CVE-2024-45032
10.0 CRITICAL

A vulnerability has been identified in Industrial Edge Management Pro (All versions < V1.9.5), Industrial Edge Management Virtual (All versions < V2.3.1-1). Affected components do …

Sep 10, 2024
CVE-2024-44087
8.6 HIGH

A vulnerability has been identified in Automation License Manager V5 (All versions), Automation License Manager V6.0 (All versions < V6.0 SP12 Upd3), Automation License Manager …

Sep 10, 2024
CVE-2024-43781
5.5 MEDIUM

A vulnerability has been identified in SINUMERIK 828D V4 (All versions < V4.95 SP3), SINUMERIK 840D sl V4 (All versions < V4.95 SP3 in connection …

Sep 10, 2024
CVE-2024-43647
7.5 HIGH

A vulnerability has been identified in SIMATIC S7-200 SMART CPU CR40 (6ES7288-1CR40-0AA0) (All versions), SIMATIC S7-200 SMART CPU CR60 (6ES7288-1CR60-0AA0) (All versions), SIMATIC S7-200 SMART …

Sep 10, 2024
CVE-2024-42345
4.3 MEDIUM

A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP2). The affected application does not properly handle user session establishment …

Sep 10, 2024
CVE-2024-42344
4.4 MEDIUM

A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 SP2). The affected application inserts sensitive information into a log file …

Sep 10, 2024
CVE-2024-41171
8.8 HIGH

A vulnerability has been identified in SINUMERIK 828D V4 (All versions), SINUMERIK 828D V5 (All versions < V5.24), SINUMERIK 840D sl V4 (All versions), SINUMERIK …

Sep 10, 2024
CVE-2024-41170
7.8 HIGH

A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0015), Tecnomatix Plant Simulation V2404 (All versions < V2404.0004). The affected applications …

Sep 10, 2024
CVE-2024-37995
2.7 LOW

A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6BC10-0AA0) (All versions < V4.2), SIMATIC …

Sep 10, 2024
CVE-2024-37994
4.3 MEDIUM

A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6BC10-0AA0) (All versions < V4.2), SIMATIC …

Sep 10, 2024
CVE-2024-37993
5.3 MEDIUM

A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6BC10-0AA0) (All versions < V4.2), SIMATIC …

Sep 10, 2024
CVE-2024-37992
4.9 MEDIUM

A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6BC10-0AA0) (All versions < V4.2), SIMATIC …

Sep 10, 2024
CVE-2024-37991
5.3 MEDIUM

A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6BC10-0AA0) (All versions < V4.2), SIMATIC …

Sep 10, 2024
CVE-2024-37990
6.5 MEDIUM

A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6BC10-0AA0) (All versions < V4.2), SIMATIC …

Sep 10, 2024
CVE-2024-35783
9.1 CRITICAL

A vulnerability has been identified in SIMATIC BATCH V9.1 (All versions), SIMATIC Information Server 2020 (All versions < V2020 SP2 Update 5), SIMATIC Information Server …

Sep 10, 2024
CVE-2024-33698
9.8 CRITICAL

A vulnerability has been identified in Opcenter Quality (All versions < V2406), Opcenter RDnL (All versions < V2410), SIMATIC PCS neo V4.0 (All versions), SIMATIC …

Sep 10, 2024
CVE-2024-32006
4.3 MEDIUM

A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 SP2). The affected application does not expire the user session on …

Sep 10, 2024
CVE-2023-49069
5.3 MEDIUM

A vulnerability has been identified in Mendix Runtime V10 (All versions < V10.17.0 only if the basic authentication mechanism is used by the application), Mendix …

Sep 10, 2024
CVE-2023-30756
5.9 MEDIUM

A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 (incl. SIPLUS variants) (All versions …

Sep 10, 2024
CVE-2023-30755
4.4 MEDIUM

A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 (incl. SIPLUS variants) (All versions …

Sep 10, 2024
CVE-2023-2919
4.3 MEDIUM

The Tutor LMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.4. This is due to missing or …

Sep 10, 2024
CVE-2023-28827
5.9 MEDIUM

A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 (incl. SIPLUS variants) (All versions …

Sep 10, 2024
CVE-2024-8258
7.8 HIGH

Improper Control of Generation of Code ('Code Injection') in Electron Fuses in Logitech Options Plus version 1.60.496306 on macOS allows attackers to execute arbitrary code …

Sep 10, 2024
CVE-2024-7699
8.8 HIGH

An low privileged remote attacker can execute OS commands with root privileges due to improper neutralization of special elements in user data.

Sep 10, 2024
CVE-2024-7698
5.7 MEDIUM

A low privileged remote attacker can get access to CSRF tokens of higher privileged users which can be abused to mount CSRF attacks.

Sep 10, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.