CVE Database

39716+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-11454
7.8 HIGH

A maliciously crafted DLL file, when placed in the same directory as an RVT file could be loaded by Autodesk Revit, and execute arbitrary code …

Dec 9, 2024
CVE-2024-54926
8.8 HIGH

A SQL Injection vulnerability was found in /search_class.php of kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get …

Dec 9, 2024
CVE-2024-53450
7.5 HIGH

RAGFlow 0.13.0 suffers from improper access control in document-hooks.ts, allowing unauthorized access to user documents.

Dec 9, 2024
CVE-2024-40582
7.5 HIGH

Pentaminds CuroVMS v2.0.1 was discovered to contain exposed sensitive information.

Dec 9, 2024
CVE-2024-49600
7.8 HIGH

Dell Power Manager (DPM), versions prior to 3.17, contain an improper access control vulnerability. A low privileged attacker with local access could potentially exploit this …

Dec 9, 2024
CVE-2024-54929
7.2 HIGH

KASHIPARA E-learning Management System v1.0 is vulnerable to SQL Injection in /admin/delete_subject.php.

Dec 9, 2024
CVE-2024-54226
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in karlkiesinger Country Blocker country-blocker allows Stored XSS.This issue affects Country Blocker: from n/a through <= 3.2.

Dec 9, 2024
CVE-2024-54225
7.5 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in codegearthemes Designer designer allows PHP Local File Inclusion.This issue …

Dec 9, 2024
CVE-2024-54220
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in roninwp FAT Services Booking fat-services-booking allows Stored XSS.This issue affects FAT Services Booking: …

Dec 9, 2024
CVE-2024-54219
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in thehp AIO Contact aio-contact.This issue affects AIO Contact: from n/a through <= 2.8.1.

Dec 9, 2024
CVE-2024-53790
7.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ogun Labs Lenxel Core for Lenxel(LNX) LMS lenxel-core allows PHP Local File …

Dec 9, 2024
CVE-2023-51355
8.2 HIGH

Missing Authorization vulnerability in MultiVendorX MultiVendorX dc-woocommerce-multi-vendor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MultiVendorX: from n/a through <= 4.0.23.

Dec 9, 2024
CVE-2023-49856
8.1 HIGH

Missing Authorization vulnerability in EDGARROJAS Smart Forms smart-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Smart Forms: from n/a through <= 2.6.84.

Dec 9, 2024
CVE-2023-49831
7.5 HIGH

Missing Authorization vulnerability in Metagauss RegistrationMagic custom-registration-form-builder-with-submission-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RegistrationMagic: from n/a through <= 5.2.3.0.

Dec 9, 2024
CVE-2023-49817
8.2 HIGH

Missing Authorization vulnerability in heoLixfy Flexible Woocommerce Checkout Field Editor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Flexible Woocommerce Checkout Field Editor: …

Dec 9, 2024
CVE-2023-49158
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Binh Nguyen LadiApp ladipage allows Stored XSS.This issue affects LadiApp: from n/a through …

Dec 9, 2024
CVE-2023-48286
8.2 HIGH

Missing Authorization vulnerability in mra13 Stripe Payments stripe-payments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Stripe Payments: from n/a through <= 2.0.79.

Dec 9, 2024
CVE-2023-47698
8.6 HIGH

Missing Authorization vulnerability in shohei.tanaka Japanized For WooCommerce woocommerce-for-japan allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Japanized For WooCommerce: from n/a through …

Dec 9, 2024
CVE-2023-25714
7.5 HIGH

Missing Authorization vulnerability in Fullworks Quick Paypal Payments allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quick Paypal Payments: from n/a through 5.7.25.

Dec 9, 2024
CVE-2023-22701
7.5 HIGH

Missing Authorization vulnerability in Shopfiles Ltd Ebook Store allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ebook Store: from n/a through 5.775.

Dec 9, 2024
CVE-2024-55580
7.5 HIGH

An issue was discovered in Qlik Sense Enterprise for Windows before November 2024 IR. Unprivileged users with network access may be able to execute remote …

Dec 9, 2024
CVE-2024-55579
8.8 HIGH

An issue was discovered in Qlik Sense Enterprise for Windows before November 2024 IR. An unprivileged user with network access may be able to create …

Dec 9, 2024
CVE-2024-53473
7.5 HIGH

WeGIA 3.2.0 before 3998672 does not verify permission to change a password.

Dec 7, 2024
CVE-2024-47115
7.8 HIGH

IBM AIX 7.2, 7.3 and VIOS 3.1 and 4.1 could allow a local user to execute arbitrary commands on the system due to improper neutralization …

Dec 7, 2024
CVE-2024-11501
8.8 HIGH

The Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3 via deserialization of untrusted input from …

Dec 7, 2024
CVE-2024-12270
7.5 HIGH

The Beautiful taxonomy filters plugin for WordPress is vulnerable to SQL Injection via the 'selects[0][term]' parameter in all versions up to, and including, 2.4.3 due …

Dec 7, 2024
CVE-2024-11010
7.2 HIGH

The FileOrganizer – Manage WordPress and Website Files plugin for WordPress is vulnerable to Local JavaScript File Inclusion in all versions up to, and including, …

Dec 7, 2024
CVE-2024-53143
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: fsnotify: Fix ordering of iput() and watched_objects decrement Ensure the superblock is kept alive until …

Dec 7, 2024
CVE-2024-44856
7.5 HIGH

Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component nav2_smac_planner().

Dec 6, 2024
CVE-2024-44855
7.5 HIGH

Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component nav2_navfn_planner().

Dec 6, 2024
CVE-2024-44854
7.5 HIGH

Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component smoothPlan().

Dec 6, 2024
CVE-2024-44853
7.5 HIGH

Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component computeControl().

Dec 6, 2024
CVE-2024-0130
8.8 HIGH

NVIDIA UFM Enterprise, UFM Appliance, and UFM CyberAI contain a vulnerability where an attacker can cause an improper authentication issue by sending a malformed request …

Dec 6, 2024
CVE-2024-47791
7.5 HIGH

Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could allow an attacker to subscribe to partial possible topics in Ruijie MQTT broker, …

Dec 6, 2024
CVE-2024-46874
8.1 HIGH

Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could allow MQTT clients connecting with device credentials to send messages to some topics. …

Dec 6, 2024
CVE-2024-45722
7.5 HIGH

Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x uses weak credential mechanism that could allow an attacker to easily calculate MQTT credentials.

Dec 6, 2024
CVE-2024-47043
7.5 HIGH

Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could enable an attacker to correlate a device serial number and the user's phone …

Dec 6, 2024
CVE-2024-11220
7.8 HIGH

A local low-level user on the server machine with credentials to the running OAS services can create and execute a report with an rdlx file …

Dec 6, 2024
CVE-2024-54749
7.5 HIGH

Ubiquiti U7-Pro 7.0.35 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root. NOTE: this is disputed …

Dec 6, 2024
CVE-2024-53691
8.8 HIGH

A link following vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained …

Dec 6, 2024
CVE-2024-50404
8.8 HIGH

A link following vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow remote attackers who have gained user access to …

Dec 6, 2024
CVE-2024-50403
7.2 HIGH

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers …

Dec 6, 2024
CVE-2024-50402
7.2 HIGH

A use of externally-controlled format string vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers …

Dec 6, 2024
CVE-2024-48868
7.5 HIGH

An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow …

Dec 6, 2024
CVE-2024-48867
7.5 HIGH

An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow …

Dec 6, 2024
CVE-2024-48865
7.5 HIGH

An improper certificate validation vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow attackers with local network …

Dec 6, 2024
CVE-2024-54137
7.4 HIGH

liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. A correctness error has been identified in the reference implementation of the …

Dec 6, 2024
CVE-2024-12254
7.5 HIGH

Starting in Python 3.12.0, the asyncio._SelectorSocketTransport.writelines() method would not "pause" writing and signal to the Protocol to drain the buffer to the wire once the …

Dec 6, 2024
CVE-2024-54141
8.6 HIGH

phpMyFAQ is an open source FAQ web application for PHP 8.1+ and MySQL, PostgreSQL and other databases. Prior to 4.0.0, phpMyFAQ exposes the database (ie …

Dec 6, 2024
CVE-2024-54216
7.7 HIGH

Path Traversal: '.../...//' vulnerability in reputeinfosystems ARForms arforms allows Path Traversal.This issue affects ARForms: from n/a through <= 6.4.1.

Dec 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.