CVE Database

39807+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-8755
8.4 HIGH

Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 …

Oct 11, 2024
CVE-2024-45402
8.6 HIGH

Picotls is a TLS protocol library that allows users select different crypto backends based on their use case. When parsing a spoofed TLS handshake message, …

Oct 11, 2024
CVE-2024-45396
7.5 HIGH

Quicly is an IETF QUIC protocol implementation. Quicly up to commtit d720707 is susceptible to a denial-of-service attack. A remote attacker can exploit these bugs …

Oct 11, 2024
CVE-2024-9002
7.8 HIGH

CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentiality, integrity, and availability of the workstation when non-admin authenticated user tries …

Oct 11, 2024
CVE-2024-8531
7.2 HIGH

CWE-347: Improper Verification of Cryptographic Signature vulnerability exists that could compromise the Data Center Expert software when an upgrade bundle is manipulated to include arbitrary …

Oct 11, 2024
CVE-2024-8970
8.2 HIGH

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.6 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from …

Oct 11, 2024
CVE-2024-45317
7.5 HIGH

A Server-Side Request Forgery (SSRF) vulnerability in SMA1000 appliance firmware versions 12.4.3-02676 and earlier allows a remote, unauthenticated attacker to cause the SMA1000 server-side application …

Oct 11, 2024
CVE-2024-45316
7.8 HIGH

The Improper link resolution before file access ('Link Following') vulnerability in SonicWall Connect Tunnel (version 12.4.3.271 and earlier of Windows client) allows users with standard …

Oct 11, 2024
CVE-2024-9818
7.3 HIGH

A vulnerability classified as critical has been found in SourceCodester Online Veterinary Appointment System 1.0. Affected is an unknown function of the file /admin/categories/manage_category.php. The …

Oct 10, 2024
CVE-2024-47870
8.1 HIGH

Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves a **race condition** in the `update_root_in_config` function, allowing an attacker to modify …

Oct 10, 2024
CVE-2024-47868
7.5 HIGH

Gradio is an open-source Python package designed for quick prototyping. This is a **data validation vulnerability** affecting several Gradio components, which allows arbitrary file leaks …

Oct 10, 2024
CVE-2024-47867
7.5 HIGH

Gradio is an open-source Python package designed for quick prototyping. This vulnerability is a **lack of integrity check** on the downloaded FRP client, which could …

Oct 10, 2024
CVE-2024-9814
7.3 HIGH

A vulnerability, which was classified as critical, was found in Codezips Pharmacy Management System 1.0. Affected is an unknown function of the file product/update.php. The …

Oct 10, 2024
CVE-2024-47084
8.3 HIGH

Gradio is an open-source Python package designed for quick prototyping. This vulnerability is related to **CORS origin validation**, where the Gradio server fails to validate …

Oct 10, 2024
CVE-2024-9813
7.3 HIGH

A vulnerability, which was classified as critical, has been found in Codezips Pharmacy Management System 1.0. This issue affects some unknown processing of the file …

Oct 10, 2024
CVE-2024-9812
7.3 HIGH

A vulnerability classified as critical was found in code-projects Crud Operation System 1.0. This vulnerability affects unknown code of the file delete.php. The manipulation of …

Oct 10, 2024
CVE-2024-9811
7.3 HIGH

A vulnerability classified as critical has been found in code-projects Restaurant Reservation System 1.0. This affects an unknown part of the file filter3.php. The manipulation …

Oct 10, 2024
CVE-2024-9180
7.2 HIGH

A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their own or another user’s privileges to Vault’s root policy. …

Oct 10, 2024
CVE-2024-47966
7.8 HIGH

Delta Electronics CNCSoft-G2 lacks proper initialization of memory prior to accessing it. An attacker can manipulate users to visit a malicious page or file to …

Oct 10, 2024
CVE-2024-47965
7.8 HIGH

Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can …

Oct 10, 2024
CVE-2024-47964
7.8 HIGH

Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can manipulate …

Oct 10, 2024
CVE-2024-47963
7.8 HIGH

Delta Electronics CNCSoft-G2 lacks proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can …

Oct 10, 2024
CVE-2024-47962
7.8 HIGH

Delta Electronics CNCSoft-G2 lacks proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can manipulate …

Oct 10, 2024
CVE-2024-9797
7.3 HIGH

A vulnerability, which was classified as critical, was found in code-projects Blood Bank System 1.0. Affected is an unknown function of the file register.php. The …

Oct 10, 2024
CVE-2024-9312
7.5 HIGH

Authd, through version 0.3.6, did not sufficiently randomize user IDs to prevent collisions. A local attacker who can register user names could spoof another user's …

Oct 10, 2024
CVE-2024-9786
8.8 HIGH

A vulnerability, which was classified as critical, has been found in D-Link DIR-619L B1 2.06. Affected by this issue is the function formSetLog of the …

Oct 10, 2024
CVE-2024-9785
8.8 HIGH

A vulnerability classified as critical was found in D-Link DIR-619L B1 2.06. Affected by this vulnerability is the function formSetDDNS of the file /goform/formSetDDNS. The …

Oct 10, 2024
CVE-2024-35202
7.5 HIGH

Bitcoin Core before 25.0 allows remote attackers to cause a denial of service (blocktxn message-handling assertion and node exit) by including transactions in a blocktxn …

Oct 10, 2024
CVE-2024-9784
8.8 HIGH

A vulnerability classified as critical has been found in D-Link DIR-619L B1 2.06. Affected is the function formResetStatistic of the file /goform/formResetStatistic. The manipulation of …

Oct 10, 2024
CVE-2024-9783
8.8 HIGH

A vulnerability was found in D-Link DIR-619L B1 2.06. It has been rated as critical. This issue affects the function formLogDnsquery of the file /goform/formLogDnsquery. …

Oct 10, 2024
CVE-2024-9782
8.8 HIGH

A vulnerability was found in D-Link DIR-619L B1 2.06. It has been declared as critical. This vulnerability affects the function formEasySetupWWConfig of the file /goform/formEasySetupWWConfig. …

Oct 10, 2024
CVE-2024-6530
7.3 HIGH

A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 17.1 prior 17.2.9, starting from 17.3 prior to 17.3.5, and starting …

Oct 10, 2024
CVE-2024-8977
8.2 HIGH

An issue has been discovered in GitLab EE affecting all versions starting from 15.10 prior to 17.2.9, from 17.3 prior to 17.3.5, and from 17.4 …

Oct 10, 2024
CVE-2024-45148
8.8 HIGH

Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authentication vulnerability that could result in a security feature bypass. A …

Oct 10, 2024
CVE-2024-45117
7.6 HIGH

Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. …

Oct 10, 2024
CVE-2024-45116
8.1 HIGH

Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a Cross-Site Scripting (XSS) vulnerability that could be exploited to execute arbitrary code. …

Oct 10, 2024
CVE-2024-9781
7.8 HIGH

AppleTalk and RELOAD Framing dissector crash in Wireshark 4.4.0 and 4.2.0 to 4.2.7 allows denial of service via packet injection or crafted capture file

Oct 10, 2024
CVE-2024-9780
7.8 HIGH

ITS dissector crash in Wireshark 4.4.0 allows denial of service via packet injection or crafted capture file

Oct 10, 2024
CVE-2024-9156
7.5 HIGH

The TI WooCommerce Wishlist WordPress plugin through 2.8.2 is vulnerable to SQL Injection due to insufficient escaping on the user supplied parameter and lack of …

Oct 10, 2024
CVE-2024-9022
7.2 HIGH

The TS Poll – Survey, Versus Poll, Image Poll, Video Poll plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter in all …

Oct 10, 2024
CVE-2024-9581
7.3 HIGH

The Shortcodes AnyWhere plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.0.1. This is due to the …

Oct 10, 2024
CVE-2024-9522
8.8 HIGH

The WP Users Masquerade plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.0. This is due to incorrect authentication …

Oct 10, 2024
CVE-2024-9519
7.2 HIGH

The UserPlus plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the 'save_metabox_form' function in versions up …

Oct 10, 2024
CVE-2024-48958
7.8 HIGH

execute_filter_delta in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a crafted archive file because src can move beyond dst.

Oct 10, 2024
CVE-2024-48957
7.8 HIGH

execute_filter_audio in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a crafted archive file because src can move beyond dst.

Oct 10, 2024
CVE-2024-7037
7.2 HIGH

In version v0.3.8 of open-webui/open-webui, the endpoint /api/pipelines/upload is vulnerable to arbitrary file write and delete due to unsanitized file.filename concatenation with CACHE_DIR. This vulnerability …

Oct 9, 2024
CVE-2024-39525
7.5 HIGH

An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated …

Oct 9, 2024
CVE-2024-39516
7.5 HIGH

An Out-of-Bounds Read vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker sending …

Oct 9, 2024
CVE-2024-39515
7.5 HIGH

An Improper Validation of Consistency within Input vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an …

Oct 9, 2024
CVE-2024-3656
8.1 HIGH

A flaw was found in Keycloak. Certain endpoints in Keycloak's admin REST API allow low-privilege users to access administrative functionalities. This flaw allows users to …

Oct 9, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.