CVE Database

39885+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-41163
7.5 HIGH

A directory traversal vulnerability exists in the archive functionality of Veertu Anka Build 1.42.0. A specially crafted HTTP request can lead to a disclosure of …

Oct 3, 2024
CVE-2024-39755
7.8 HIGH

A privilege escalation vulnerability exists in the node update functionality of Veertu Anka Build 1.42.0. A specially crafted PKG file can lead to execute priviledged …

Oct 3, 2024
CVE-2024-36474
8.4 HIGH

An integer overflow vulnerability exists in the Compound Document Binary File format parser of the GNOME Project G Structured File Library (libgsf) version v1.14.52. A …

Oct 3, 2024
CVE-2024-25590
7.5 HIGH

An attacker can publish a zone containing specific Resource Record Sets. Repeatedly processing and caching results for these sets can lead to a denial of …

Oct 3, 2024
CVE-2024-9460
7.3 HIGH

A vulnerability was found in Codezips Online Shopping Portal 1.0. It has been classified as critical. Affected is an unknown function of the file index.php. …

Oct 3, 2024
CVE-2024-5803
7.5 HIGH

The AVGUI.exe of AVG/Avast Antivirus before versions before 24.1 can allow a local attacker to escalate privileges via an COM hijack in a time-of-check to …

Oct 3, 2024
CVE-2024-47614
7.5 HIGH

async-graphql is a GraphQL server library implemented in Rust. async-graphql before 7.0.10 does not limit the number of directives for a field. This can lead …

Oct 3, 2024
CVE-2024-9313
8.8 HIGH

Authd PAM module before version 0.3.5 can allow broker-managed users to impersonate any other user managed by the same broker and perform any PAM operation …

Oct 3, 2024
CVE-2024-47561
7.3 HIGH

Schema parsing in the Java SDK of Apache Avro 1.11.3 and previous versions allows bad actors to execute arbitrary code. Users are recommended to upgrade …

Oct 3, 2024
CVE-2024-8352
7.5 HIGH

The Social Web Suite – Social Media Auto Post, Social Media Auto Publish plugin for WordPress is vulnerable to Directory Traversal in all versions up …

Oct 3, 2024
CVE-2024-47136
7.8 HIGH

Out-of-bounds read vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) Version 1.6.14.0 and earlier. Having a user open a specially …

Oct 3, 2024
CVE-2024-47135
7.8 HIGH

Stack-based buffer overflow vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) Version 1.6.14.0 and earlier. Having a user open a …

Oct 3, 2024
CVE-2024-47134
7.8 HIGH

Out-of-bounds write vulnerability exists in Kostac PLC Programming Software (Former name: Koyo PLC Programming Software) Version 1.6.14.0 and earlier. Having a user open a specially …

Oct 3, 2024
CVE-2024-28888
8.8 HIGH

A use-after-free vulnerability exists in the way Foxit Reader 2024.1.0.23997 handles a checkbox field object. A specially crafted Javascript code inside a malicious PDF document …

Oct 2, 2024
CVE-2024-8733
8.0 HIGH

A potential security vulnerability has been identified in the HP One Agent for certain HP PC products, which might allow for escalation of privilege. HP …

Oct 2, 2024
CVE-2024-20501
8.6 HIGH

Multiple vulnerabilities in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote …

Oct 2, 2024
CVE-2024-20499
8.6 HIGH

Multiple vulnerabilities in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote …

Oct 2, 2024
CVE-2024-20498
8.6 HIGH

Multiple vulnerabilities in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote …

Oct 2, 2024
CVE-2024-46626
8.8 HIGH

OS4ED openSIS-Classic v9.1 was discovered to contain a SQL injection vulnerability via a crafted payload.

Oct 2, 2024
CVE-2024-41290
8.1 HIGH

FlatPress CMS v1.3.1 1.3 was discovered to use insecure methods to store authentication data via the cookie's component.

Oct 2, 2024
CVE-2024-20470
7.2 HIGH

A vulnerability in the web-based management interface of Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an authenticated, …

Oct 2, 2024
CVE-2024-20449
8.8 HIGH

A vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, remote attacker with low privileges to execute arbitrary code on an affected …

Oct 2, 2024
CVE-2024-20393
8.8 HIGH

A vulnerability in the web-based management interface of Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an authenticated, …

Oct 2, 2024
CVE-2024-47807
8.1 HIGH

Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `iss` (Issuer) claim of an ID Token, allowing attackers to subvert the authentication …

Oct 2, 2024
CVE-2024-47806
8.1 HIGH

Jenkins OpenId Connect Authentication Plugin 4.354.v321ce67a_1de8 and earlier does not check the `aud` (Audience) claim of an ID Token, allowing attackers to subvert the authentication …

Oct 2, 2024
CVE-2024-47805
7.5 HIGH

Jenkins Credentials Plugin 1380.va_435002fa_924 and earlier, except 1371.1373.v4eb_fa_b_7161e9, does not redact encrypted values of credentials using the `SecretBytes` type when accessing item `config.xml` via REST …

Oct 2, 2024
CVE-2024-44193
7.8 HIGH

A logic issue was addressed with improved restrictions. This issue is fixed in iTunes 12.13.3 for Windows. A local attacker may be able to elevate …

Oct 2, 2024
CVE-2024-8885
8.8 HIGH

A local privilege escalation vulnerability in Sophos Intercept X for Windows with Central Device Encryption 2024.2.0 and older allows writing of arbitrary files.

Oct 2, 2024
CVE-2024-8038
7.9 HIGH

Vulnerable juju introspection abstract UNIX domain socket. An abstract UNIX domain socket responsible for introspection is available without authentication locally to network namespace users. This …

Oct 2, 2024
CVE-2024-7558
8.7 HIGH

JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju charm container (on Kubernetes), an unprivileged user in the same network namespace …

Oct 2, 2024
CVE-2024-44030
7.2 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mestres do WP Checkout Mestres WP checkout-mestres-wp allows Absolute Path Traversal.This issue …

Oct 2, 2024
CVE-2024-44017
7.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in MinHyeong Lim MH Board mh-board allows PHP Local File Inclusion.This issue affects …

Oct 2, 2024
CVE-2024-7315
7.5 HIGH

The Migration, Backup, Staging WordPress plugin before 0.9.106 does not use sufficient randomness in the filename that is created when generating a backup, which could …

Oct 2, 2024
CVE-2024-7855
8.8 HIGH

The WP Hotel Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_review() function in all …

Oct 2, 2024
CVE-2024-33662
7.5 HIGH

Portainer before 2.20.2 improperly uses an encryption algorithm in the AesEncrypt function.

Oct 2, 2024
CVE-2024-47527
7.5 HIGH

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Device Dependencies" feature allows authenticated users to inject arbitrary …

Oct 1, 2024
CVE-2024-47525
7.5 HIGH

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Alert Rules" feature allows authenticated users to inject arbitrary …

Oct 1, 2024
CVE-2024-47524
7.2 HIGH

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. User with Admin role can create a Device Groups, the application did not properly sanitize the user …

Oct 1, 2024
CVE-2024-47523
7.5 HIGH

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the "Alert Transports" feature allows authenticated users to inject arbitrary …

Oct 1, 2024
CVE-2024-46084
8.0 HIGH

Scriptcase 9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_unzip function.

Oct 1, 2024
CVE-2024-46080
8.0 HIGH

Scriptcase v9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_zip function.

Oct 1, 2024
CVE-2024-42514
8.1 HIGH

A vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.1.0.4 could allow an unauthenticated attacker to conduct an unauthorized access attack …

Oct 1, 2024
CVE-2024-9403
7.3 HIGH

Memory safety bugs present in Firefox 130. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of …

Oct 1, 2024
CVE-2024-9400
8.8 HIGH

A potential memory corruption vulnerability could be triggered if an attacker had the ability to trigger an OOM at a specific moment during JIT compilation. …

Oct 1, 2024
CVE-2024-9399
7.5 HIGH

A website configured to initiate a specially crafted WebTransport session could crash the Firefox process leading to a denial of service condition. This vulnerability affects …

Oct 1, 2024
CVE-2024-9396
8.8 HIGH

It is currently unknown if this issue is exploitable but a condition may arise where the structured clone of certain objects could lead to memory …

Oct 1, 2024
CVE-2024-9394
7.5 HIGH

An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://devtools` origin. This could allow them to access cross-origin JSON content. …

Oct 1, 2024
CVE-2024-9393
7.5 HIGH

An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://pdf.js` origin. This could allow them to access cross-origin PDF content. …

Oct 1, 2024
CVE-2024-47604
8.2 HIGH

NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability in its handling of HTML element attributes, which allows an …

Oct 1, 2024
CVE-2024-25659
7.2 HIGH

In Infinera TNMS (Transcend Network Management System) 19.10.3, an insecure default configuration of the internal SFTP server on Linux servers allows remote attacker to access …

Oct 1, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.