CVE Database

39716+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-53555
8.8 HIGH

A CSV injection vulnerability in Taiga v6.8.1 allows attackers to execute arbitrary code via uploading a crafted CSV file.

Nov 26, 2024
CVE-2024-11407
7.5 HIGH

There exists a denial of service through Data corruption in gRPC-C++ - gRPC-C++ servers with transmit zero copy enabled through the channel arg GRPC_ARG_TCP_TX_ZEROCOPY_ENABLED can …

Nov 26, 2024
CVE-2024-52336
7.8 HIGH

A script injection vulnerability was identified in the Tuned package. The `instance_create()` D-Bus function can be called by locally logged-in users without authentication. This flaw …

Nov 26, 2024
CVE-2024-9461
7.2 HIGH

The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Remote Code Execution in all versions …

Nov 26, 2024
CVE-2024-11702
7.5 HIGH

Copying sensitive information from Private Browsing tabs on Android, such as passwords, may have inadvertently stored data in the cloud-based clipboard history if enabled. This …

Nov 26, 2024
CVE-2024-11700
8.1 HIGH

Malicious websites may have been able to perform user intent confirmation through tapjacking. This could have led to users unknowingly approving the launch of external …

Nov 26, 2024
CVE-2024-11699
8.8 HIGH

Memory safety bugs present in Firefox 132, Firefox ESR 128.4, and Thunderbird 128.4. Some of these bugs showed evidence of memory corruption and we presume …

Nov 26, 2024
CVE-2024-11697
8.8 HIGH

When handling keypress events, an attacker may have been able to trick a user into bypassing the "Open Executable File?" confirmation dialog. This could have …

Nov 26, 2024
CVE-2024-11691
8.8 HIGH

Certain WebGL operations on Apple silicon M series devices could have lead to an out-of-bounds write and memory corruption due to a flaw in Apple's …

Nov 26, 2024
CVE-2018-5852
8.4 HIGH

An unsigned integer underflow vulnerability in IPA driver result into a buffer over-read while reading NAT entry using debugfs command 'cat /sys/kernel/debug/ipa/ip4_nat'

Nov 26, 2024
CVE-2018-11816
7.8 HIGH

Crafted Binder Request Causes Heap UAF in MediaServer

Nov 26, 2024
CVE-2017-18307
8.4 HIGH

Information disclosure possible while audio playback.

Nov 26, 2024
CVE-2017-18306
8.4 HIGH

Information disclosure due to uninitialized variable.

Nov 26, 2024
CVE-2016-10408
8.4 HIGH

QSEE will randomly experience a fatal error during execution due to speculative instruction fetches from device memory. Device memory is not valid executable memory.

Nov 26, 2024
CVE-2024-51569
7.5 HIGH

Out-of-bounds Read vulnerability in Apache NimBLE. Missing proper validation of HCI Number Of Completed Packets could lead to out-of-bound access when parsing HCI event and …

Nov 26, 2024
CVE-2024-38832
7.1 HIGH

VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to views may be able to inject malicious script leading …

Nov 26, 2024
CVE-2024-38831
7.8 HIGH

VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privileges can insert malicious commands into the properties file to …

Nov 26, 2024
CVE-2024-38830
7.8 HIGH

VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privileges may trigger this vulnerability to escalate privileges to root …

Nov 26, 2024
CVE-2023-1521
7.8 HIGH

On Linux the sccache client can execute arbitrary code with the privileges of a local sccache server, by preloading the code in a shared library …

Nov 26, 2024
CVE-2023-0163
8.4 HIGH

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability in Mozilla Convict. This allows an attacker to inject attributes that are used in other …

Nov 26, 2024
CVE-2024-50376
7.3 HIGH

A CWE-79 "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD …

Nov 26, 2024
CVE-2024-50369
7.2 HIGH

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G …

Nov 26, 2024
CVE-2024-50368
7.2 HIGH

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G …

Nov 26, 2024
CVE-2024-50367
7.2 HIGH

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G …

Nov 26, 2024
CVE-2024-50366
7.2 HIGH

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G …

Nov 26, 2024
CVE-2024-50365
7.2 HIGH

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G …

Nov 26, 2024
CVE-2024-50364
7.2 HIGH

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G …

Nov 26, 2024
CVE-2024-50363
7.2 HIGH

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G …

Nov 26, 2024
CVE-2024-50362
7.2 HIGH

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G …

Nov 26, 2024
CVE-2024-50361
7.2 HIGH

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G …

Nov 26, 2024
CVE-2024-50360
7.2 HIGH

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G …

Nov 26, 2024
CVE-2024-50359
7.2 HIGH

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G …

Nov 26, 2024
CVE-2024-50358
7.2 HIGH

A CWE-15 "External Control of System or Configuration Setting" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and …

Nov 26, 2024
CVE-2018-11952
8.4 HIGH

An image with a version lower than the fuse version may potentially be booted lead to improper authentication.

Nov 26, 2024
CVE-2017-18153
8.4 HIGH

A race condition exists in a driver potentially leading to a use-after-free condition.

Nov 26, 2024
CVE-2017-15832
8.4 HIGH

Buffer overwrite in the WLAN host driver by leveraging a compromised WLAN FW

Nov 26, 2024
CVE-2016-10394
8.4 HIGH

Initial xbl_sec revision does not have all the debug policy features and critical checks.

Nov 26, 2024
CVE-2024-9504
7.2 HIGH

The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and …

Nov 26, 2024
CVE-2024-47257
7.5 HIGH

Florent Thiéry has found that selected Axis devices were vulnerable to handling certain ethernet frames which could lead to the Axis device becoming unavailable in …

Nov 26, 2024
CVE-2024-36254
7.5 HIGH

Out-of-bounds read vulnerability exists in Sharp Corporation and Toshiba Tec Corporation multiple MFPs (multifunction printers), which may lead to a denial-of-service (DoS) condition.

Nov 26, 2024
CVE-2024-36251
7.5 HIGH

The web interface of the affected devices process some crafted HTTP requests improperly, leading to a device crash. More precisely, a crafted parameter to billcodedef_sub_sel.html …

Nov 26, 2024
CVE-2024-36249
7.4 HIGH

Cross-site scripting vulnerability exists in Sharp Corporation and Toshiba Tech Corporation multiple MFPs (multifunction printers). If this vulnerability is exploited, an arbitrary script may be …

Nov 26, 2024
CVE-2024-33605
7.5 HIGH

Improper processing of some parameters of installed_emanual_list.html leads to a path traversal vulnerability. As for the details of affected product names, model numbers, and versions, …

Nov 26, 2024
CVE-2024-10781
8.1 HIGH

The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an missing empty value check on …

Nov 26, 2024
CVE-2024-10570
7.5 HIGH

The Security & Malware scan by CleanTalk plugin for WordPress is vulnerable to unauthorized SQL Injection due to an authorization bypass via reverse DNS spoofing …

Nov 26, 2024
CVE-2024-49353
7.5 HIGH

IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data 4.0.0 through 5.0.2 does not properly check inputs to resources that are used concurrently, …

Nov 26, 2024
CVE-2024-49597
7.6 HIGH

Dell Wyse Management Suite, versions WMS 4.4 and prior, contain an Improper Restriction of Excessive Authentication Attempts vulnerability. A high privileged attacker with remote access …

Nov 26, 2024
CVE-2024-49595
7.6 HIGH

Dell Wyse Management Suite, version WMS 4.4 and before, contain an Authentication Bypass by Capture-replay vulnerability. A high privileged attacker with remote access could potentially …

Nov 26, 2024
CVE-2024-10729
8.8 HIGH

The Booking & Appointment Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …

Nov 26, 2024
CVE-2024-52899
8.5 HIGH

IBM Data Virtualization Manager for z/OS 1.1 and 1.2 could allow an authenticated user to inject malicious JDBC URL parameters and execute code on the …

Nov 26, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.