CVE Database

39807+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-50115
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: KVM: nSVM: Ignore nCR3[4:0] when loading PDPTEs from memory Ignore nCR3[4:0] when loading PDPTEs from …

Nov 5, 2024
CVE-2024-50114
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Unregister redistributor for failed vCPU creation Alex reports that syzkaller has managed to …

Nov 5, 2024
CVE-2024-50112
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: x86/lam: Disable ADDRESS_MASKING in most cases Linear Address Masking (LAM) has a weakness related to …

Nov 5, 2024
CVE-2024-50106
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix race between laundromat and free_stateid There is a race between laundromat handling of …

Nov 5, 2024
CVE-2024-9579
7.5 HIGH

A potential vulnerability was discovered in certain Poly video conferencing devices. The firmware flaw does not properly sanitize user input. The exploitation of this vulnerability …

Nov 5, 2024
CVE-2024-49522
7.8 HIGH

Substance3D - Painter versions 10.0.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Nov 5, 2024
CVE-2023-29117
8.8 HIGH

Waybox Enel X web management API authentication could be bypassed and provide administrator’s privileges over the Waybox system.

Nov 5, 2024
CVE-2024-52022
8.0 HIGH

Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a command injection vulnerability in the component wlg_adv.cgi via the …

Nov 5, 2024
CVE-2024-52021
8.0 HIGH

Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the wan_gateway parameter at bsw_fix.cgi. This vulnerability allows attackers to execute arbitrary OS …

Nov 5, 2024
CVE-2024-52020
8.0 HIGH

Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the wan_gateway parameter at wiz_fix2.cgi. This vulnerability allows attackers to execute arbitrary OS …

Nov 5, 2024
CVE-2024-52019
8.0 HIGH

Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the wan_gateway parameter at genie_fix2.cgi. This vulnerability allows attackers to execute arbitrary OS …

Nov 5, 2024
CVE-2024-52018
8.0 HIGH

Netgear XR300 v1.0.3.78 was discovered to contain a command injection vulnerability in the system_name parameter at genie_dyn.cgi. This vulnerability allows attackers to execute arbitrary OS …

Nov 5, 2024
CVE-2024-51024
8.0 HIGH

D-Link DIR_823G 1.0.2B05 was discovered to contain a command injection vulnerability via the HostName parameter in the SetWanSettings function. This vulnerability allows attackers to execute …

Nov 5, 2024
CVE-2024-51023
8.8 HIGH

D-Link DIR_823G 1.0.2B05 was discovered to contain a command injection vulnerability via the Address parameter in the SetNetworkTomographySettings function. This vulnerability allows attackers to execute …

Nov 5, 2024
CVE-2024-51021
8.0 HIGH

Netgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a command injection vulnerability via the wan_gateway parameter at genie_fix2.cgi. This vulnerability …

Nov 5, 2024
CVE-2024-51010
8.0 HIGH

Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a command injection vulnerability in the component ap_mode.cgi via the …

Nov 5, 2024
CVE-2024-51009
8.0 HIGH

Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the wan_gateway parameter at ether.cgi. This vulnerability allows attackers to execute arbitrary OS …

Nov 5, 2024
CVE-2024-51008
8.0 HIGH

Netgear XR300 v1.0.3.78 was discovered to contain a command injection vulnerability in the system_name parameter at wiz_dyn.cgi. This vulnerability allows attackers to execute arbitrary OS …

Nov 5, 2024
CVE-2024-51005
8.0 HIGH

Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the share_name parameter at usb_remote_smb_conf.cgi. This vulnerability allows attackers to execute arbitrary OS …

Nov 5, 2024
CVE-2024-50993
8.0 HIGH

Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the sysNewPasswd parameter at admin_account.cgi. This vulnerability allows attackers to execute arbitrary OS …

Nov 5, 2024
CVE-2024-10845
7.3 HIGH

A vulnerability has been found in 1000 Projects Bookstore Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file book_detail.php. …

Nov 5, 2024
CVE-2024-10844
7.3 HIGH

A vulnerability, which was classified as critical, was found in 1000 Projects Bookstore Management System 1.0. This affects an unknown part of the file search.php. …

Nov 5, 2024
CVE-2024-7059
8.0 HIGH

A high-severity vulnerability that can lead to arbitrary code execution on the system hosting the Web SDK role was found in the Genetec Security Center …

Nov 5, 2024
CVE-2024-10263
7.3 HIGH

The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.5.4.4. This is …

Nov 5, 2024
CVE-2024-51526
8.2 HIGH

Permission control vulnerability in the hidebug module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Nov 5, 2024
CVE-2024-51523
7.1 HIGH

Information management vulnerability in the Gallery module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Nov 5, 2024
CVE-2024-47253
7.2 HIGH

In 2N Access Commander versions 3.1.1.2 and prior, a Path Traversal vulnerability could allow an attacker with administrative privileges to write files on the filesystem …

Nov 5, 2024
CVE-2024-51510
7.6 HIGH

Out-of-bounds access vulnerability in the logo module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Nov 5, 2024
CVE-2024-10711
8.8 HIGH

The WooCommerce Report plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.1. This is due to missing …

Nov 5, 2024
CVE-2024-10114
8.1 HIGH

The WooCommerce - Social Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.7.7. This is due to …

Nov 5, 2024
CVE-2024-47797
8.4 HIGH

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through out-of-bounds write.

Nov 5, 2024
CVE-2024-47404
8.4 HIGH

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through double free.

Nov 5, 2024
CVE-2024-47137
8.4 HIGH

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through out-of-bounds write.

Nov 5, 2024
CVE-2024-10097
8.1 HIGH

The Loginizer Security and Loginizer plugins for WordPress are vulnerable to authentication bypass in all versions up to, and including, 1.9.2. This is due to …

Nov 5, 2024
CVE-2024-9459
8.3 HIGH

Zohocorp ManageEngine Exchange Reporter Plus versions 5718 and prior are vulnerable to authenticated SQL Injection in reports module.

Nov 5, 2024
CVE-2024-31998
8.8 HIGH

Combodo iTop is a simple, web based IT Service Management tool. A CSRF can be performed on CSV import simulation. This issue has been fixed …

Nov 5, 2024
CVE-2024-31448
8.8 HIGH

Combodo iTop is a simple, web based IT Service Management tool. By filling malicious code in a CSV content, an Cross-site Scripting (XSS) attack can …

Nov 5, 2024
CVE-2023-34445
8.8 HIGH

Combodo iTop is a simple, web based IT Service Management tool. When displaying pages/ajax.render.php XSS are possible for scripts outside of script tags. This issue …

Nov 5, 2024
CVE-2023-34444
8.8 HIGH

Combodo iTop is a simple, web based IT Service Management tool. When displaying pages/ajax.searchform.php XSS are possible for scripts outside of script tags. This issue …

Nov 5, 2024
CVE-2023-34443
8.8 HIGH

Combodo iTop is a simple, web based IT Service Management tool. When displaying page Run queries Cross-site Scripting (XSS) are possible for scripts outside of …

Nov 5, 2024
CVE-2024-10791
7.3 HIGH

A vulnerability, which was classified as critical, has been found in Codezips Hospital Appointment System 1.0. This issue affects some unknown processing of the file …

Nov 4, 2024
CVE-2024-30619
7.5 HIGH

Chamilo LMS Version 1.11.26 is vulnerable to Incorrect Access Control. A non-authenticated attacker can request the number of messages and the number of online users …

Nov 4, 2024
CVE-2024-30616
8.8 HIGH

Chamilo LMS 1.11.26 is vulnerable to Incorrect Access Control via main/auth/profile. Non-admin users can manipulate sensitive profiles information, posing a significant risk to data integrity.

Nov 4, 2024
CVE-2024-51329
8.8 HIGH

A Host header injection vulnerability in Agile-Board 1.0 allows attackers to obtain the password reset token via user interaction with a crafted password reset link.

Nov 4, 2024
CVE-2024-51326
7.5 HIGH

SQL Injection vulnerability in projectworlds Travel management System v.1.0 allows a remote attacker to execute arbitrary code via the 't2' parameter in deletesubcategory.php.

Nov 4, 2024
CVE-2024-51127
7.1 HIGH

An issue in the createTempFile method of hornetq v2.4.9 allows attackers to arbitrarily overwrite files or access sensitive information.

Nov 4, 2024
CVE-2024-48336
8.4 HIGH

The install() function of ProviderInstaller.java in Magisk App before canary version 27007 does not verify the GMS app before loading it, which allows a local …

Nov 4, 2024
CVE-2024-48809
7.5 HIGH

An issue in Open Networking Foundations sdran-in-a-box v.1.4.3 and onos-a1t v.0.2.3 allows a remote attacker to cause a denial of service via the onos-a1t component …

Nov 4, 2024
CVE-2024-51626
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in chenyenming Woocommerce Quote Calculator woo-quote-calculator-order allows Blind SQL Injection.This issue affects …

Nov 4, 2024
CVE-2024-45893
8.0 HIGH

DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `setSWMOption.`

Nov 4, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.