CVE Database

39716+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-55500
8.8 HIGH

Cross-Site Request Forgery (CSRF) in Avenwu Whistle v.2.9.90 and before allows attackers to perform malicious API calls, resulting in the execution of arbitrary code on …

Dec 10, 2024
CVE-2024-54008
7.2 HIGH

An authenticated Remote Code Execution (RCE) vulnerability exists in the AirWave CLI. Successful exploitation of this vulnerability could allow a remote authenticated threat actor to …

Dec 10, 2024
CVE-2024-50930
8.8 HIGH

An issue in Silicon Labs Z-Wave Series 500 v6.84.0 allows attackers to execute arbitrary code.

Dec 10, 2024
CVE-2024-50920
8.8 HIGH

Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to create a fake node via supplying crafted packets.

Dec 10, 2024
CVE-2024-50699
8.0 HIGH

TP-Link TL-WR845N(UN)_V4_201214, TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 were discovered to contain weak default credentials for the Administrator account.

Dec 10, 2024
CVE-2024-10256
7.1 HIGH

Insufficient permissions in Ivanti Patch SDK before version 9.7.703 allows a local authenticated attacker to delete arbitrary files.

Dec 10, 2024
CVE-2024-53247
8.8 HIGH

In Splunk Enterprise versions below 9.3.2, 9.2.4, and 9.1.7, and versions below 3.4.261 and 3.7.13 of the Splunk Secure Gateway app on Splunk Cloud Platform, …

Dec 10, 2024
CVE-2024-55602
7.6 HIGH

PwnDoc is a penetration test report generator. Prior to commit 1d4219c596f4f518798492e48386a20c6e9a2fe6, an authenticated user who is able to update and download templates can inject path …

Dec 10, 2024
CVE-2024-55548
7.5 HIGH

Improper check of password character lenght in ORing IAP-420 allows a forced deadlock. This issue affects IAP-420: through 2.01e.

Dec 10, 2024
CVE-2024-55544
8.8 HIGH

Missing input validation in the ORing IAP-420 web-interface allows authenticated Command Injections on OS level.This issue affects IAP-420 version 2.01e and below.

Dec 10, 2024
CVE-2024-10496
7.8 HIGH

An out of bounds read due to improper input validation in BuildFontMap in fontmgr.cpp in NI LabVIEW may disclose information or result in arbitrary code …

Dec 10, 2024
CVE-2024-10495
7.8 HIGH

An out of bounds read due to improper input validation when loading the font table in fontmgr.cpp in NI LabVIEW may disclose information or result …

Dec 10, 2024
CVE-2024-10494
7.8 HIGH

An out of bounds read due to improper input validation in HeapObjMapImpl.cpp in NI LabVIEW may disclose information or result in arbitrary code execution. Successful …

Dec 10, 2024
CVE-2024-54095
7.8 HIGH

A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 10). The affected application is vulnerable to integer underflow vulnerability which …

Dec 10, 2024
CVE-2024-54094
7.8 HIGH

A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 5). The affected application is vulnerable to heap-based buffer overflow while …

Dec 10, 2024
CVE-2024-54093
7.8 HIGH

A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 5). The affected application is vulnerable to heap-based buffer overflow while …

Dec 10, 2024
CVE-2024-54091
7.8 HIGH

A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 12), Solid Edge SE2025 (All versions < V225.0 Update 3). The …

Dec 10, 2024
CVE-2024-53242
7.8 HIGH

A vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versions < V14.3.0.12), Teamcenter Visualization V2312 (All versions …

Dec 10, 2024
CVE-2024-53041
7.8 HIGH

A vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versions < V14.3.0.12), Teamcenter Visualization V2312 (All versions …

Dec 10, 2024
CVE-2024-52051
7.3 HIGH

A vulnerability has been identified in SIMATIC S7-PLCSIM V17 (All versions), SIMATIC S7-PLCSIM V18 (All versions), SIMATIC STEP 7 Safety V17 (All versions < V17 …

Dec 10, 2024
CVE-2024-49849
7.8 HIGH

A vulnerability has been identified in SIMATIC S7-PLCSIM V16 (All versions), SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 Safety V16 (All versions), SIMATIC STEP …

Dec 10, 2024
CVE-2020-28398
8.8 HIGH

A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions …

Dec 10, 2024
CVE-2024-52538
7.6 HIGH

Dell Avamar, versions prior to 19.12 with patch 338905, excluding 19.10 and 19.10SP1 with patch 338869, contains an Improper Neutralization of Special Elements used in …

Dec 10, 2024
CVE-2024-47977
7.1 HIGH

Dell Avamar, versions prior to 19.12 with patch 338905, excluding 19.10 and 19.10SP1 with patch 338869, contains an Improper Neutralization of Special Elements used in …

Dec 10, 2024
CVE-2024-47484
8.2 HIGH

Dell Avamar, versions prior to 19.12 with patch 338905, excluding 19.10 and 19.10SP1 with patch 338869, contains an Improper Neutralization of Special Elements used in …

Dec 10, 2024
CVE-2024-10959
7.3 HIGH

The The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to arbitrary shortcode execution via woot_get_smth AJAX action …

Dec 10, 2024
CVE-2024-47946
7.2 HIGH

If the attacker has access to a valid Poweruser session, remote code execution is possible because specially crafted valid PNG files with injected PHP content …

Dec 10, 2024
CVE-2024-28138
7.3 HIGH

An unauthenticated attacker with network access to the affected device's web interface can execute any system command via the "msg_events.php" script as the www-data user. …

Dec 10, 2024
CVE-2023-6947
7.7 HIGH

The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.26. This makes …

Dec 10, 2024
CVE-2024-21542
8.6 HIGH

Versions of the package luigi before 3.6.0 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) due to improper destination file path validation …

Dec 10, 2024
CVE-2024-11205
8.5 HIGH

The WPForms plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wpforms_is_admin_page' function in versions starting …

Dec 10, 2024
CVE-2024-37144
8.2 HIGH

Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack versions prior to RCM 3.8.1.0 (for RCM 3.8.x train) and prior …

Dec 10, 2024
CVE-2024-53919
7.6 HIGH

An injection vulnerability in Barco ClickShare CX-30/20, C-5/10, and ClickShare Bar Pro and Core models, running firmware before 2.21.1, allows physically proximate attackers or local …

Dec 10, 2024
CVE-2024-54198
8.5 HIGH

In certain conditions, SAP NetWeaver Application Server ABAP allows an authenticated attacker to craft a Remote Function Call (RFC) request to restricted destinations, which can …

Dec 10, 2024
CVE-2024-54197
7.2 HIGH

SAP NetWeaver Administrator(System Overview) allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by specially crafting HTTP requests. On successful exploitation …

Dec 10, 2024
CVE-2024-55634
8.1 HIGH

A vulnerability in Drupal Core allows Privilege Escalation.This issue affects Drupal Core: from 8.0.0 before 10.2.11, from 10.3.0 before 10.3.9, from 11.0.0 before 11.0.8.

Dec 10, 2024
CVE-2024-50628
8.8 HIGH

An issue was discovered in the web services of Digi ConnectPort LTS before 1.4.12. It allows an attacker on the local area network to achieve …

Dec 9, 2024
CVE-2024-50627
8.8 HIGH

An issue was discovered in Digi ConnectPort LTS before 1.4.12. A Privilege Escalation vulnerability exists in the file upload feature. It allows an attacker on …

Dec 9, 2024
CVE-2024-50626
8.8 HIGH

An issue was discovered in Digi ConnectPort LTS before 1.4.12. A Directory Traversal vulnerability exists in WebFS. This allows an attacker on the local area …

Dec 9, 2024
CVE-2024-50625
8.0 HIGH

An issue was discovered in Digi ConnectPort LTS before 1.4.12. A vulnerability in the file upload handling of a web application allows manipulation of file …

Dec 9, 2024
CVE-2024-54151
7.5 HIGH

Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 11.0.0 and prior to version 11.3.0, when setting `WEBSOCKETS_GRAPHQL_AUTH` …

Dec 9, 2024
CVE-2024-54149
8.4 HIGH

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Winter CMS prior to versions 1.2.7, 1.1.11, and 1.0.476 allow …

Dec 9, 2024
CVE-2024-54938
7.5 HIGH

A Directory Listing issue was found in Kashipara E-Learning Management System v1.0, which allows remote attackers to access sensitive files and directories via /admin/uploads.

Dec 9, 2024
CVE-2024-54928
7.2 HIGH

kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_teacher.php,

Dec 9, 2024
CVE-2024-54927
7.2 HIGH

Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_users.php.

Dec 9, 2024
CVE-2024-46547
7.5 HIGH

A vulnerability was found in Romain Bourdon Wampserver all versions (discovered in v3.2.3 and v3.2.6) where unauthorized users could access sensitive information due to improper …

Dec 9, 2024
CVE-2024-54933
7.2 HIGH

Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_content.php.

Dec 9, 2024
CVE-2024-54930
7.2 HIGH

Kashipara E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_student.php.

Dec 9, 2024
CVE-2024-54922
7.2 HIGH

A SQL Injection was found in /admin/edit_user.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized …

Dec 9, 2024
CVE-2024-11608
7.8 HIGH

A maliciously crafted SKP file, when linked or imported into Autodesk Revit, can be used to cause a Heap-based Overflow. A malicious actor can leverage …

Dec 9, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.