CVE Database

39885+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-46722
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix mc_data out-of-bounds read warning Clear warning that read mc_data[i-1] may out-of-bounds.

Sep 18, 2024
CVE-2024-43778
8.8 HIGH

OS command injection vulnerability in multiple digital video recorders provided by TAKENAKA ENGINEERING CO., LTD. allows a remote authenticated attacker to execute an arbitrary OS …

Sep 18, 2024
CVE-2024-41929
8.8 HIGH

Improper authentication vulnerability in multiple digital video recorders provided by TAKENAKA ENGINEERING CO., LTD. allows a remote authenticated attacker to execute an arbitrary OS command …

Sep 18, 2024
CVE-2024-42404
8.8 HIGH

SQL injection vulnerability in Welcart e-Commerce prior to 2.11.2 allows an attacker who can login to the product to obtain or alter the information stored …

Sep 18, 2024
CVE-2024-45679
8.4 HIGH

Heap-based buffer overflow vulnerability in Assimp versions prior to 5.4.3 allows a local attacker to execute arbitrary code by importing a specially crafted file into …

Sep 18, 2024
CVE-2024-44003
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in spicethemes Spice Starter Sites spice-starter-sites allows Reflected XSS.This issue affects Spice Starter Sites: …

Sep 18, 2024
CVE-2024-44002
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Team Showcase team allows Reflected XSS.This issue affects Team Showcase: from n/a …

Sep 18, 2024
CVE-2024-43975
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in highwarden Super Store Finder superstorefinder-wp.This issue affects Super Store Finder: from n/a through …

Sep 18, 2024
CVE-2024-43971
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart.This issue affects Sunshine Photo Cart: from n/a through …

Sep 18, 2024
CVE-2024-43970
7.1 HIGH

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SureCart allows Reflected XSS.This issue affects SureCart: from n/a through 2.29.3.

Sep 18, 2024
CVE-2024-44064
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LikeBtn Like Button Rating likebtn-like-button.This issue affects Like Button Rating: from n/a through …

Sep 17, 2024
CVE-2024-44009
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WC Lovers WCFM Marketplace wc-multivendor-marketplace allows Reflected XSS.This issue affects WCFM Marketplace: from …

Sep 17, 2024
CVE-2024-44007
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT Templates – Elementor & Gutenberg templates skt-templates allows Reflected XSS.This issue …

Sep 17, 2024
CVE-2024-43969
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Spiffy Plugins Spiffy Calendar allows SQL Injection.This issue affects Spiffy Calendar: …

Sep 17, 2024
CVE-2024-46982
7.5 HIGH

Next.js is a React framework for building full-stack web applications. By sending a crafted HTTP request, it is possible to poison the cache of a …

Sep 17, 2024
CVE-2024-8957
7.2 HIGH KEV

PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an OS command injection issue. The camera does not sufficiently validate the ntp_addr configuration value which may …

Sep 17, 2024
CVE-2024-8905
8.8 HIGH

Inappropriate implementation in V8 in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page. (Chromium …

Sep 17, 2024
CVE-2024-8904
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Sep 17, 2024
CVE-2024-45606
7.1 HIGH

Sentry is a developer-first error tracking and performance monitoring platform. An authenticated user can mute alert rules from arbitrary organizations and projects with a know …

Sep 17, 2024
CVE-2024-45398
8.3 HIGH

Contao is an Open Source CMS. In affected versions a back end user with access to the file manager can upload malicious files and execute …

Sep 17, 2024
CVE-2024-8948
7.3 HIGH

A vulnerability was found in MicroPython 1.23.0. It has been rated as critical. Affected by this issue is the function mpz_as_bytes of the file py/objint.c. …

Sep 17, 2024
CVE-2024-8946
7.3 HIGH

A vulnerability was found in MicroPython 1.23.0. It has been classified as critical. Affected is the function mp_vfs_umount of the file extmod/vfs.c of the component …

Sep 17, 2024
CVE-2024-8900
7.5 HIGH

An attacker could write data to the user's clipboard, bypassing the user prompt, during a certain sequence of navigational events. This vulnerability affects Firefox < …

Sep 17, 2024
CVE-2024-43460
8.1 HIGH

Improper authorization in Dynamics 365 Business Central resulted in a vulnerability that allows an authenticated attacker to elevate privileges over a network.

Sep 17, 2024
CVE-2024-8944
7.3 HIGH

A vulnerability, which was classified as critical, was found in code-projects Hospital Management System 1.0. This affects an unknown part of the file check_availability.php. The …

Sep 17, 2024
CVE-2024-45682
8.8 HIGH

There is a command injection vulnerability that may allow an attacker to inject malicious input on the device's operating system.

Sep 17, 2024
CVE-2024-42503
7.2 HIGH

Authenticated command execution vulnerability exist in the ArubaOS command line interface (CLI). Successful exploitation of this vulnerabilities result in the ability to run arbitrary commands …

Sep 17, 2024
CVE-2024-42502
7.2 HIGH

Authenticated command injection vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability result in the ability to inject shell commands on …

Sep 17, 2024
CVE-2024-42501
7.2 HIGH

An authenticated Path Traversal vulnerabilities exists in the ArubaOS. Successful exploitation of this vulnerability allows an attacker to install unsigned packages on the underlying operating …

Sep 17, 2024
CVE-2024-38813
7.5 HIGH KEV

The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to …

Sep 17, 2024
CVE-2024-8768
7.5 HIGH

A flaw was found in the vLLM library. A completions API request with an empty prompt will crash the vLLM API server, resulting in a …

Sep 17, 2024
CVE-2024-7788
7.8 HIGH

Improper Digital Signature Invalidation vulnerability in Zip Repair Mode of The Document Foundation LibreOffice allows Signature forgery vulnerability in LibreOfficeThis issue affects LibreOffice: from 24.2 …

Sep 17, 2024
CVE-2021-27916
8.1 HIGH

Prior to the patched version, logged in users of Mautic are vulnerable to Relative Path Traversal/Arbitrary File Deletion. Regardless of the level of access the …

Sep 17, 2024
CVE-2024-47049
8.2 HIGH

The czim/file-handling package before 1.5.0 and 2.x before 2.3.0 (used with PHP Composer) does not properly validate URLs within makeFromUrl and makeFromAny, leading to SSRF, …

Sep 17, 2024
CVE-2024-47047
7.5 HIGH

An issue was discovered in the powermail extension through 12.4.0 for TYPO3. It fails to validate the mail parameter of the createAction, resulting in Insecure …

Sep 17, 2024
CVE-2024-22303
8.8 HIGH

Incorrect Privilege Assignment vulnerability in favethemes Houzez allows Privilege Escalation.This issue affects Houzez: from n/a through 3.2.4.

Sep 17, 2024
CVE-2024-21743
8.8 HIGH

Privilege Escalation vulnerability in favethemes Houzez Login Register houzez-login-register.This issue affects Houzez Login Register: from n/a through 3.2.5.

Sep 17, 2024
CVE-2021-27915
7.6 HIGH

Prior to the patched version, there is an XSS vulnerability in the description fields within the Mautic application which could be exploited by a logged …

Sep 17, 2024
CVE-2024-46362
8.8 HIGH

FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/create_directory

Sep 17, 2024
CVE-2024-46085
8.8 HIGH

FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/rename

Sep 17, 2024
CVE-2024-5998
7.8 HIGH

A vulnerability in the FAISS.deserialize_from_bytes function of langchain-ai/langchain allows for pickle deserialization of untrusted data. This can lead to the execution of arbitrary commands via …

Sep 17, 2024
CVE-2024-8761
7.2 HIGH

The Share This Image plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.03. This is due to insufficient …

Sep 17, 2024
CVE-2024-8490
8.8 HIGH

The PropertyHive plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.19. This is due to missing or …

Sep 17, 2024
CVE-2024-8110
7.5 HIGH

Denial of Service (DoS) vulnerability has been found in Dual-redundant Platform for Computer. If a computer on which the affected product is installed receives a …

Sep 17, 2024
CVE-2024-44189
7.5 HIGH

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15. A logic issue existed where a process may be able …

Sep 17, 2024
CVE-2024-44165
7.5 HIGH

A logic issue was addressed with improved checks. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia …

Sep 17, 2024
CVE-2024-44164
7.1 HIGH

This issue was addressed with improved checks. This issue is fixed in iOS 17.7 and iPadOS 17.7, macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura …

Sep 17, 2024
CVE-2024-44162
7.8 HIGH

This issue was addressed by enabling hardened runtime. This issue is fixed in Xcode 16. A malicious application may gain access to a user's Keychain …

Sep 17, 2024
CVE-2024-44152
7.5 HIGH

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15. An app may be …

Sep 17, 2024
CVE-2024-44149
7.5 HIGH

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. An app may be able to access protected user …

Sep 17, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.