CVE Database

39716+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-47758
8.8 HIGH

GLPI is a free asset and IT management software package. Starting in version 9.3.0 and prior to version 10.0.17, an authenticated user can use the …

Dec 11, 2024
CVE-2024-28139
8.8 HIGH

The www-data user can elevate its privileges because sudo is configured to allow the execution of the mount command as root without a password. Therefore, …

Dec 11, 2024
CVE-2024-11840
7.1 HIGH

The RapidLoad – Optimize Web Vitals Automatically plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing …

Dec 11, 2024
CVE-2024-12363
7.1 HIGH

Insufficient permissions in the TeamViewer Patch & Asset Management component prior to version 24.12 on Windows allows a local authenticated user to delete arbitrary files. …

Dec 11, 2024
CVE-2024-53292
7.2 HIGH

Dell VxVerify, versions prior to x.40.405, contain a Plain-text Password Storage Vulnerability in the shell wrapper. A local high privileged attacker could potentially exploit this …

Dec 11, 2024
CVE-2024-53290
8.4 HIGH

Dell ThinOS version 2408 contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with local access could …

Dec 11, 2024
CVE-2024-53289
7.8 HIGH

Dell ThinOS version 2408 contains a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading …

Dec 11, 2024
CVE-2024-53959
7.8 HIGH

Adobe Framemaker versions 2020.7, 2022.5 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Dec 10, 2024
CVE-2024-53958
7.8 HIGH

Substance3D - Painter versions 10.1.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Dec 10, 2024
CVE-2024-53957
7.8 HIGH

Substance3D - Painter versions 10.1.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Dec 10, 2024
CVE-2024-53956
7.8 HIGH

Premiere Pro versions 25.0, 24.6.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Dec 10, 2024
CVE-2024-53955
7.8 HIGH

Bridge versions 14.1.3, 15.0 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the …

Dec 10, 2024
CVE-2024-53003
7.8 HIGH

Substance3D - Modeler versions 1.14.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Dec 10, 2024
CVE-2024-53002
7.8 HIGH

Substance3D - Modeler versions 1.14.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Dec 10, 2024
CVE-2024-53001
7.8 HIGH

Substance3D - Modeler versions 1.14.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Dec 10, 2024
CVE-2024-53000
7.8 HIGH

Substance3D - Modeler versions 1.14.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Dec 10, 2024
CVE-2024-52999
7.8 HIGH

Substance3D - Modeler versions 1.14.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Dec 10, 2024
CVE-2024-54037
8.1 HIGH

Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute …

Dec 10, 2024
CVE-2024-53954
7.8 HIGH

Animate versions 23.0.8, 24.0.5 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the …

Dec 10, 2024
CVE-2024-53953
7.8 HIGH

Animate versions 23.0.8, 24.0.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of …

Dec 10, 2024
CVE-2024-52997
7.8 HIGH

Photoshop Desktop versions 26.0 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of …

Dec 10, 2024
CVE-2024-52996
7.8 HIGH

Substance3D - Sampler versions 4.5.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Dec 10, 2024
CVE-2024-52995
7.8 HIGH

Substance3D - Sampler versions 4.5.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Dec 10, 2024
CVE-2024-52994
7.8 HIGH

Substance3D - Sampler versions 4.5.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Dec 10, 2024
CVE-2024-52990
7.8 HIGH

Animate versions 23.0.8, 24.0.5 and earlier are affected by a Buffer Underwrite ('Buffer Underflow') vulnerability that could result in arbitrary code execution in the context …

Dec 10, 2024
CVE-2024-52989
7.8 HIGH

Animate versions 23.0.8, 24.0.5 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the …

Dec 10, 2024
CVE-2024-52988
7.8 HIGH

Animate versions 23.0.8, 24.0.5 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the …

Dec 10, 2024
CVE-2024-52987
7.8 HIGH

Animate versions 23.0.8, 24.0.5 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the …

Dec 10, 2024
CVE-2024-52986
7.8 HIGH

Animate versions 23.0.8, 24.0.5 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the …

Dec 10, 2024
CVE-2024-52985
7.8 HIGH

Animate versions 23.0.8, 24.0.5 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the …

Dec 10, 2024
CVE-2024-52984
7.8 HIGH

Animate versions 23.0.8, 24.0.5 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the …

Dec 10, 2024
CVE-2024-52983
7.8 HIGH

Animate versions 23.0.8, 24.0.5 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context …

Dec 10, 2024
CVE-2024-52982
7.8 HIGH

Animate versions 23.0.8, 24.0.5 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of …

Dec 10, 2024
CVE-2024-49545
7.8 HIGH

InDesign Desktop versions ID19.5, ID18.5.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Dec 10, 2024
CVE-2024-49544
7.8 HIGH

InDesign Desktop versions ID19.5, ID18.5.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Dec 10, 2024
CVE-2024-49543
7.8 HIGH

InDesign Desktop versions ID19.5, ID18.5.4 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Dec 10, 2024
CVE-2024-49538
7.8 HIGH

Illustrator versions 29.0.0, 28.7.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the …

Dec 10, 2024
CVE-2024-49537
7.8 HIGH

After Effects versions 24.6.2, 25.0.1 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Dec 10, 2024
CVE-2024-49513
7.8 HIGH

PDFL SDK versions 21.0.0.5 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the …

Dec 10, 2024
CVE-2024-45156
7.8 HIGH

Animate versions 23.0.8, 24.0.5 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in arbitrary code execution in the context of …

Dec 10, 2024
CVE-2024-45155
7.8 HIGH

Animate versions 23.0.8, 24.0.5 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context …

Dec 10, 2024
CVE-2024-51165
7.5 HIGH

SQL injection vulnerability in JEPAAS7.2.8, via /je/rbac/rbac/loadLoginCount in the dateVal parameter, which could allow a remote user to submit a specially crafted query, allowing an …

Dec 10, 2024
CVE-2024-49553
7.8 HIGH

Media Encoder versions 25.0, 24.6.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Dec 10, 2024
CVE-2024-49552
7.8 HIGH

Media Encoder versions 25.0, 24.6.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Dec 10, 2024
CVE-2024-49551
7.8 HIGH

Media Encoder versions 25.0, 24.6.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Dec 10, 2024
CVE-2024-49530
7.8 HIGH

Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution …

Dec 10, 2024
CVE-2024-46341
8.0 HIGH

TP-Link TL-WR845N(UN)_V4_190219 was discovered to transmit credentials in base64 encoded form, which can be easily decoded by an attacker executing a man-in-the-middle attack.

Dec 10, 2024
CVE-2024-9844
7.1 HIGH

Insufficient server-side controls in Secure Application Manager of Ivanti Connect Secure before version 22.7R2.4 allows a remote authenticated attacker to bypass restrictions.

Dec 10, 2024
CVE-2024-8540
8.8 HIGH

Insecure permissions in Ivanti Sentry before versions 9.20.2 and 10.0.2 or 10.1.0 allow a local authenticated attacker to modify sensitive application components.

Dec 10, 2024
CVE-2024-7572
7.1 HIGH

Insufficient permissions in Ivanti DSM before version 2024.3.5740 allows a local authenticated attacker to delete arbitrary files.

Dec 10, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.