CVE Database

39716+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-11800
7.8 HIGH

Fuji Electric Tellus Lite V-Simulator 5 V8 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code …

Nov 28, 2024
CVE-2024-11799
7.8 HIGH

Fuji Electric Tellus Lite V-Simulator 5 V8 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code …

Nov 28, 2024
CVE-2024-11798
7.8 HIGH

Fuji Electric Monitouch V-SFT X1 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations …

Nov 28, 2024
CVE-2024-11797
7.8 HIGH

Fuji Electric Monitouch V-SFT V8 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations …

Nov 28, 2024
CVE-2024-11796
7.8 HIGH

Fuji Electric Monitouch V-SFT V9C File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations …

Nov 28, 2024
CVE-2024-11795
7.8 HIGH

Fuji Electric Monitouch V-SFT V8 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected …

Nov 28, 2024
CVE-2024-11794
7.8 HIGH

Fuji Electric Monitouch V-SFT V10 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations …

Nov 28, 2024
CVE-2024-11793
7.8 HIGH

Fuji Electric Monitouch V-SFT V9C File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations …

Nov 28, 2024
CVE-2024-11792
7.8 HIGH

Fuji Electric Monitouch V-SFT V8 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected …

Nov 28, 2024
CVE-2024-11791
7.8 HIGH

Fuji Electric Monitouch V-SFT V8C File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected …

Nov 28, 2024
CVE-2024-11790
7.8 HIGH

Fuji Electric Monitouch V-SFT V10 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected …

Nov 28, 2024
CVE-2024-11789
7.8 HIGH

Fuji Electric Monitouch V-SFT V10 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected …

Nov 28, 2024
CVE-2024-11787
7.8 HIGH

Fuji Electric Monitouch V-SFT V10 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected …

Nov 28, 2024
CVE-2018-9374
7.8 HIGH

In installPackageLI of PackageManagerService.java, there is a possible permissions bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction …

Nov 28, 2024
CVE-2024-53860
8.6 HIGH

sp-php-email-handler is a PHP package for handling contact form submissions. Messages sent using this script are vulnerable to abuse, as the script allows anybody to …

Nov 27, 2024
CVE-2017-13323
7.8 HIGH

In String16 of String16.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege …

Nov 27, 2024
CVE-2017-13319
7.5 HIGH

In pvmp3_get_main_data_size of pvmp3_get_main_data_size.cpp, there is a possible buffer overread due to a missing bounds check. This could lead to remote information disclosure of global …

Nov 27, 2024
CVE-2017-13316
7.8 HIGH

In checkPermissions of RecognitionService.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege with …

Nov 27, 2024
CVE-2024-47181
7.5 HIGH

Contiki-NG is an open-source, cross-platform operating system for IoT devices. An unaligned memory access can be triggered in the two RPL implementations of the Contiki-NG …

Nov 27, 2024
CVE-2024-41126
8.3 HIGH

Contiki-NG is an open-source, cross-platform operating system for IoT devices. An out-of-bounds read of 1 byte can be triggered when sending a packet to a …

Nov 27, 2024
CVE-2024-41125
8.3 HIGH

Contiki-NG is an open-source, cross-platform operating system for IoT devices. An out-of-bounds read of 1 byte can be triggered when sending a packet to a …

Nov 27, 2024
CVE-2023-29001
7.5 HIGH

Contiki-NG is an open-source, cross-platform operating system for IoT devices. The Contiki-NG operating system processes source routing headers (SRH) in its two alternative RPL protocol …

Nov 27, 2024
CVE-2024-7025
8.8 HIGH

Integer overflow in Layout in Google Chrome prior to 129.0.6668.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Nov 27, 2024
CVE-2024-54003
8.0 HIGH

Jenkins Simple Queue Plugin 1.4.4 and earlier does not escape the view name, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with …

Nov 27, 2024
CVE-2024-31976
8.0 HIGH

EnGenius EWS356-FIR 1.1.30 and earlier devices allow a remote attacker to execute arbitrary OS commands via the Controller connectivity parameter.

Nov 27, 2024
CVE-2024-53920
7.8 HIGH

In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger …

Nov 27, 2024
CVE-2024-52951
8.0 HIGH

Stored Cross-Site Scripting in the Access Request History in Omada Identity before version 15 update 1 allows an authenticated attacker to execute arbitrary code in …

Nov 27, 2024
CVE-2024-53603
7.3 HIGH

A SQL Injection vulnerability was found in /covid-tms/password-recovery.php in PHPGurukul COVID 19 Testing Management System v1.0, which allows remote attackers to execute arbitrary code via …

Nov 27, 2024
CVE-2024-52323
8.1 HIGH

Zohocorp ManageEngine Analytics Plus versions below 6100 are vulnerable to authenticated sensitive data exposure which allows the users to retrieve sensitive tokens associated to the …

Nov 27, 2024
CVE-2024-11667
7.5 HIGH KEV

A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through …

Nov 27, 2024
CVE-2024-36467
7.5 HIGH

An authenticated user with API access (e.g.: user with default User role), more specifically a user with access to the user.update API endpoint is enough …

Nov 27, 2024
CVE-2024-52959
7.2 HIGH

A Improper Control of Generation of Code ('Code Injection') vulnerability in plugin management in iota C.ai Conversational Platform from 1.0.0 through 2.1.3 allows remote authenticated …

Nov 27, 2024
CVE-2024-52958
7.2 HIGH

A improper verification of cryptographic signature vulnerability in plugin management in iota C.ai Conversational Platform from 1.0.0 through 2.1.3 allows remote authenticated users to load …

Nov 27, 2024
CVE-2024-5921
8.8 HIGH

An insufficient certification validation issue in the Palo Alto Networks GlobalProtect app enables attackers to connect the GlobalProtect app to arbitrary servers. This can enable …

Nov 27, 2024
CVE-2024-11819
7.3 HIGH

A vulnerability classified as critical was found in 1000 Projects Portfolio Management System MCA 1.0. This vulnerability affects unknown code of the file /forgot_password_process.php. The …

Nov 27, 2024
CVE-2024-11818
7.3 HIGH

A vulnerability classified as critical has been found in PHPGurukul User Registration & Login and User Management System 1.0. This affects an unknown part of …

Nov 27, 2024
CVE-2024-11817
7.3 HIGH

A vulnerability was found in PHPGurukul User Registration & Login and User Management System 1.0. It has been rated as critical. Affected by this issue …

Nov 26, 2024
CVE-2024-53675
7.3 HIGH

An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.

Nov 26, 2024
CVE-2024-53674
7.3 HIGH

An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.

Nov 26, 2024
CVE-2024-53673
8.1 HIGH

A java deserialization vulnerability in HPE Remote Insight Support may allow an unauthenticated attacker to execute code.

Nov 26, 2024
CVE-2024-11622
7.3 HIGH

An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.

Nov 26, 2024
CVE-2024-11745
8.8 HIGH

A vulnerability was found in Tenda AC8 16.03.34.09 and classified as critical. Affected by this issue is the function route_static_check of the file /goform/SetStaticRouteCfg. The …

Nov 26, 2024
CVE-2024-11744
7.3 HIGH

A vulnerability has been found in 1000 Projects Portfolio Management System MCA 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality …

Nov 26, 2024
CVE-2024-8676
7.4 HIGH

A vulnerability was found in CRI-O, where it can be requested to take a checkpoint archive of a container and later be asked to restore …

Nov 26, 2024
CVE-2024-49053
7.6 HIGH

Microsoft Dynamics 365 Sales Spoofing Vulnerability

Nov 26, 2024
CVE-2024-49052
8.2 HIGH

Missing authentication for critical function in Microsoft Azure PolicyWatch allows an unauthorized attacker to elevate privileges over a network.

Nov 26, 2024
CVE-2024-49035
8.7 HIGH KEV

An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network.

Nov 26, 2024
CVE-2024-8114
8.2 HIGH

An issue has been discovered in GitLab CE/EE affecting all versions from 8.12 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. This issue allows …

Nov 26, 2024
CVE-2024-52008
8.8 HIGH

Fides is an open-source privacy engineering platform. The user invite acceptance API endpoint lacks server-side password policy enforcement, allowing users to set arbitrarily weak passwords …

Nov 26, 2024
CVE-2024-32965
8.1 HIGH

Lobe Chat is an open-source, AI chat framework. Versions of lobe-chat prior to 1.19.13 have an unauthorized ssrf vulnerability. An attacker can construct malicious requests …

Nov 26, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.