CVE Database

39716+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-12230
7.3 HIGH

A vulnerability, which was classified as critical, has been found in PHPGurukul Complaint Management System 1.0. Affected by this issue is some unknown functionality of …

Dec 5, 2024
CVE-2024-12229
7.3 HIGH

A vulnerability classified as critical was found in PHPGurukul Complaint Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/complaint-search.php. …

Dec 5, 2024
CVE-2024-11941
7.5 HIGH

A vulnerability in Drupal Core allows Excessive Allocation.This issue affects Drupal Core: from 10.2.0 before 10.2.2, from 10.1.0 before 10.1.8.

Dec 5, 2024
CVE-2024-53703
8.1 HIGH

A vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions mod_httprp library loaded by the Apache web server allows remote attackers to cause …

Dec 5, 2024
CVE-2024-45318
8.1 HIGH

A vulnerability in the SonicWall SMA100 SSLVPN web management interface allows remote attackers to cause Stack-based buffer overflow and potentially lead to code execution.

Dec 5, 2024
CVE-2024-40763
7.5 HIGH

Heap-based buffer overflow vulnerability in the SonicWall SMA100 SSLVPN due to the use of strcpy. This allows remote authenticated attackers to cause Heap-based buffer overflow …

Dec 5, 2024
CVE-2024-12228
7.3 HIGH

A vulnerability classified as critical has been found in PHPGurukul Complaint Management System 1.0. Affected is an unknown function of the file /admin/user-search.php. The manipulation …

Dec 5, 2024
CVE-2024-51546
7.5 HIGH

Credentials Disclosure vulnerabilities allow access to on board project back-up bundles. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

Dec 5, 2024
CVE-2024-51544
8.2 HIGH

Service Control vulnerabilities allow access to service restart requests and vm configuration settings. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series …

Dec 5, 2024
CVE-2024-51543
8.2 HIGH

Information Disclosure vulnerabilities allow access to application configuration information. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

Dec 5, 2024
CVE-2024-51542
8.2 HIGH

Configuration Download vulnerabilities allow access to dependency configuration information. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

Dec 5, 2024
CVE-2024-51541
8.2 HIGH

Local File Inclusion vulnerabilities allow access to sensitive system information. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02

Dec 5, 2024
CVE-2024-48847
8.2 HIGH

MD5 Checksum Bypass vulnerabilities where found exploiting a weakness in the way an application dependency calculates or validates MD5 checksum hashes. Affected products: ABB ASPECT …

Dec 5, 2024
CVE-2024-48846
7.1 HIGH

Cross Site Request Forgery vulnerabilities where found providing a potiential for exposing sensitive information or changing system settings. Affected products: ABB ASPECT - Enterprise v3.08.02; …

Dec 5, 2024
CVE-2024-48844
7.7 HIGH

Denial of Service vulnerabilities where found providing a potiential for device service disruptions. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series …

Dec 5, 2024
CVE-2024-48843
7.7 HIGH

Denial of Service vulnerabilities where found providing a potiential for device service disruptions. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series …

Dec 5, 2024
CVE-2024-11316
7.5 HIGH

Fileszie Check vulnerabilities allow a malicious user to bypass size limits or overload to the product. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series …

Dec 5, 2024
CVE-2024-52564
7.5 HIGH

Inclusion of undocumented features or chicken bits issue exists in UD-LT1 firmware Ver.2.1.8 and earlier and UD-LT1/EX firmware Ver.2.1.8 and earlier. A remote attacker may …

Dec 5, 2024
CVE-2024-47133
7.2 HIGH

UD-LT1 firmware Ver.2.1.9 and earlier and UD-LT1/EX firmware Ver.2.1.9 and earlier allow a remote authenticated attacker with an administrative account to execute arbitrary OS commands.

Dec 5, 2024
CVE-2022-41137
8.3 HIGH

Apache Hive Metastore (HMS) uses SerializationUtilities#deserializeObjectWithTypeInformation method when filtering and fetching partitions that is unsafe and can lead to Remote Code Execution (RCE) since it …

Dec 5, 2024
CVE-2024-11429
8.8 HIGH

The Free Responsive Testimonials, Social Proof Reviews, and Customer Reviews – Stars Testimonials plugin for WordPress is vulnerable to Local File Inclusion in all versions …

Dec 5, 2024
CVE-2024-12188
7.3 HIGH

A vulnerability was found in 1000 Projects Library Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Dec 5, 2024
CVE-2024-12187
7.3 HIGH

A vulnerability was found in 1000 Projects Library Management System 1.0. It has been classified as critical. Affected is an unknown function of the file …

Dec 5, 2024
CVE-2018-9402
7.8 HIGH

In multiple functions of gl_proc.c, there is a buffer overwrite due to a missing bounds check. This could lead to escalation of privileges in the …

Dec 5, 2024
CVE-2024-50947
7.5 HIGH

An issue in kmqtt v0.2.7 allows attackers to cause a Denial of Service (DoS) via a crafted request.

Dec 4, 2024
CVE-2024-39219
8.8 HIGH

An issue in Aginode GigaSwitch V5 before version 7.06G allows authenticated attackers with Administrator privileges to upload an earlier firmware version, exposing the device to …

Dec 4, 2024
CVE-2024-12149
8.1 HIGH

Incorrect permission assignment in temporary access requests component in Devolutions Remote Desktop Manager 2024.3.19.0 and earlier on Windows allows an authenticated user that request temporary …

Dec 4, 2024
CVE-2024-39163
8.8 HIGH

binux pyspider up to v0.3.10 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Flask endpoints.

Dec 4, 2024
CVE-2024-37575
7.5 HIGH

The Mister org.mistergroup.shouldianswer application 1.4.264 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted …

Dec 4, 2024
CVE-2024-37574
8.2 HIGH

The GriceMobile com.grice.call application 4.5.2 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted …

Dec 4, 2024
CVE-2024-11643
8.8 HIGH

The Accessibility by AllAccessible plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability …

Dec 4, 2024
CVE-2024-53139
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: sctp: fix possible UAF in sctp_v6_available() A lockdep report [1] with CONFIG_PROVE_RCU_LIST=y hints that sctp_v6_available() …

Dec 4, 2024
CVE-2024-53133
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Handle dml allocation failure to avoid crash [Why] In the case where a dml …

Dec 4, 2024
CVE-2024-53126
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: vdpa: solidrun: Fix UB bug with devres In psnet_open_pf_bar() and snet_open_vf_bar() a string later passed …

Dec 4, 2024
CVE-2024-51465
8.8 HIGH

IBM App Connect Enterprise Certified Container 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, and 12.3 could allow a remote authenticated attacker to execute arbitrary commands on …

Dec 4, 2024
CVE-2024-54154
8.0 HIGH

In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox

Dec 4, 2024
CVE-2024-52269
8.1 HIGH

User Interface (UI) Misrepresentation of Critical Information vulnerability in DocuSign allows Content Spoofing. The SaaS AI assistant ignores hidden content that is rendered after signing, …

Dec 4, 2024
CVE-2024-52276
7.5 HIGH

User Interface (UI) Misrepresentation of Critical Information vulnerability in DocuSign allows Content Spoofing. 1. Displayed version does not show the layer flattened version, which is …

Dec 4, 2024
CVE-2024-12107
7.5 HIGH

Double-Free Vulnerability in uD3TN BPv7 Caused by Malformed Endpoint Identifier allows remote attacker to reliably cause DoS

Dec 4, 2024
CVE-2024-11952
7.5 HIGH

The Classic Addons – WPBakery Page Builder plugin for WordPress is vulnerable to Limited Local PHP File Inclusion in all versions up to, and including, …

Dec 4, 2024
CVE-2024-10567
7.5 HIGH

The TI WooCommerce Wishlist plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wizard' function in …

Dec 4, 2024
CVE-2024-11293
8.1 HIGH

The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction Social Sites Login plugin for WordPress is vulnerable …

Dec 4, 2024
CVE-2024-45717
7.0 HIGH

The SolarWinds Platform was susceptible to a XSS vulnerability that affects the search and node information section of the user interface. This vulnerability requires authentication …

Dec 4, 2024
CVE-2024-11398
8.1 HIGH

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in OTP reset functionality in Synology Router Manager (SRM) before 1.3.1-9346-9 allows remote …

Dec 4, 2024
CVE-2024-9404
7.5 HIGH

This vulnerability could lead to denial-of-service or service crashes. Exploitation of the moxa_cmd service, because of insufficient input validation, allows attackers to disrupt operations. If …

Dec 4, 2024
CVE-2024-10952
7.3 HIGH

The The Authors List plugin for WordPress is vulnerable to arbitrary shortcode execution via update_authors_list_ajax AJAX action in all versions up to, and including, 2.0.4. …

Dec 4, 2024
CVE-2024-10587
8.8 HIGH

The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free plugin for WordPress is vulnerable to PHP Object …

Dec 4, 2024
CVE-2024-45207
7.0 HIGH

DLL injection in Veeam Agent for Windows can occur if the system's PATH variable includes insecure locations. When the agent runs, it searches these directories …

Dec 4, 2024
CVE-2024-45205
7.1 HIGH

An Improper Certificate Validation on the UniFi iOS App managing a standalone UniFi Access Point (not using UniFi Network Application) could allow a malicious actor …

Dec 4, 2024
CVE-2024-42456
8.8 HIGH

A vulnerability in Veeam Backup & Replication platform allows a low-privileged user with a specific role to exploit a method that updates critical configuration settings, …

Dec 4, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.