CVE Database

39885+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-44132
8.8 HIGH

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15. An app may be able to break out …

Sep 17, 2024
CVE-2024-40861
7.8 HIGH

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15. An app may be able to gain root privileges.

Sep 17, 2024
CVE-2024-40856
7.5 HIGH

An integrity issue was addressed with Beacon Protection. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18. An attacker …

Sep 17, 2024
CVE-2024-40848
7.5 HIGH

A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7. An attacker …

Sep 17, 2024
CVE-2024-40770
7.5 HIGH

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. A non-privileged user may be able to modify restricted …

Sep 17, 2024
CVE-2024-27879
7.5 HIGH

The issue was addressed with improved bounds checks. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18. An attacker …

Sep 17, 2024
CVE-2024-27874
7.5 HIGH

This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18. A remote attacker may be able to …

Sep 17, 2024
CVE-2024-27795
7.5 HIGH

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. A camera extension may be able to access the …

Sep 17, 2024
CVE-2024-45416
8.1 HIGH

The HTTPD binary in multiple ZTE routers has a local file inclusion vulnerability in session_init function. The session -LUA- files are stored in the directory …

Sep 16, 2024
CVE-2024-45413
8.1 HIGH

The HTTPD binary in multiple ZTE routers has a stack-based buffer overflow vulnerability in rsa_decrypt function. This function is an API wrapper for LUA to …

Sep 16, 2024
CVE-2024-42798
7.6 HIGH

An Incorrect Access Control vulnerability was found in /music/index.php?page=user_list and /music/index.php?page=edit_user in Kashipara Music Management System v1.0. This allows a low privileged attacker to take …

Sep 16, 2024
CVE-2024-45801
7.3 HIGH

DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. It has been discovered that malicious HTML using special nesting techniques can …

Sep 16, 2024
CVE-2024-45799
7.3 HIGH

FluxCP is a web-based Control Panel for rAthena servers written in PHP. A javascript injection is possible via venders/buyers list pages and shop names, that …

Sep 16, 2024
CVE-2023-45854
7.5 HIGH

A Business Logic vulnerability in Shopkit 1.0 allows an attacker to add products with negative quantities to the shopping cart via the qtd parameter in …

Sep 16, 2024
CVE-2024-23599
7.9 HIGH

Race condition in Seamless Firmware Updates for some Intel(R) reference platforms may allow a privileged user to potentially enable denial of service via local access.

Sep 16, 2024
CVE-2024-21871
7.5 HIGH

Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

Sep 16, 2024
CVE-2024-21829
7.5 HIGH

Improper input validation in UEFI firmware error handler for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local …

Sep 16, 2024
CVE-2024-21781
7.2 HIGH

Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to enable information disclosure or denial of service via local …

Sep 16, 2024
CVE-2023-43626
7.5 HIGH

Improper access control in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

Sep 16, 2024
CVE-2023-42772
8.2 HIGH

Untrusted pointer dereference in UEFI firmware for some Intel(R) reference processors may allow a privileged user to potentially enable escalation of privilege via local access.

Sep 16, 2024
CVE-2023-41833
7.5 HIGH

A race condition in UEFI firmware for some Intel(R) processors may allow a privileged user to potentially enable escalation of privilege via local access.

Sep 16, 2024
CVE-2024-8752
7.5 HIGH

The Windows version of WebIQ 2.15.9 is affected by a directory traversal vulnerability that allows remote attackers to read any file on the system.

Sep 16, 2024
CVE-2024-46937
7.5 HIGH

An improper access control (IDOR) vulnerability in the /api-selfportal/get-info-token-properties endpoint in MFASOFT Secure Authentication Server (SAS) 1.8.x through 1.9.x before 1.9.040924 allows remote attackers gain …

Sep 16, 2024
CVE-2024-46424
7.5 HIGH

TOTOLINK AC1200 T8 v4.1.5cu.861_B20230220 has a buffer overflow vulnerability in the UploadCustomModule function, which allows attackers to cause a Denial of Service (DoS) via the …

Sep 16, 2024
CVE-2024-45696
8.8 HIGH

Certain models of D-Link wireless routers contain hidden functionality. By sending specific packets to the web service, the attacker can forcibly enable the telnet service …

Sep 16, 2024
CVE-2024-8779
8.8 HIGH

OMFLOW from The SYSCOM Group does not properly restrict access to the system settings modification functionality, allowing remote attackers with regular privileges to update system …

Sep 16, 2024
CVE-2024-8777
7.5 HIGH

OMFLOW from The SYSCOM Group has an information leakage vulnerability, allowing unauthorized remote attackers to read arbitrary system configurations. If LDAP authentication is enabled, attackers …

Sep 16, 2024
CVE-2024-46943
7.5 HIGH

An issue was discovered in OpenDaylight Authentication, Authorization and Accounting (AAA) through 0.19.3. A rogue controller can join a cluster to impersonate an offline peer, …

Sep 15, 2024
CVE-2024-46938
7.5 HIGH

An issue was discovered in Sitecore Experience Platform (XP), Experience Manager (XM), and Experience Commerce (XC) 8.0 Initial Release through 10.4 Initial Release. An unauthenticated …

Sep 15, 2024
CVE-2024-44053
7.1 HIGH

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Mohammad Arif Opor Ayam allows Reflected XSS.This issue affects Opor Ayam: …

Sep 15, 2024
CVE-2024-45459
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Product Slider for WooCommerce woocommerce-products-slider allows Reflected XSS.This issue affects Product Slider …

Sep 15, 2024
CVE-2024-45458
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Spiffy Plugins Spiffy Calendar spiffy-calendar allows Reflected XSS.This issue affects Spiffy Calendar: from …

Sep 15, 2024
CVE-2024-44060
7.1 HIGH

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jennifer Hall Filmix allows Reflected XSS.This issue affects Filmix: from n/a …

Sep 15, 2024
CVE-2024-8868
7.3 HIGH

A vulnerability was found in code-projects Crud Operation System 1.0. It has been rated as critical. This issue affects some unknown processing of the file …

Sep 15, 2024
CVE-2024-8862
7.3 HIGH

A vulnerability, which was classified as critical, has been found in h2oai h2o-3 3.46.0.4. This issue affects the function getConnectionSafe of the file /dtale/chart-data/1 of …

Sep 14, 2024
CVE-2024-6482
8.8 HIGH

The Login with phone number plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.7.49. This is due to …

Sep 14, 2024
CVE-2024-8479
7.3 HIGH

The The Simple Spoiler plugin for WordPress is vulnerable to arbitrary shortcode execution in versions 1.2 to 1.3. This is due to the plugin adding …

Sep 14, 2024
CVE-2024-8246
8.8 HIGH

The Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) plugin for WordPress is vulnerable …

Sep 14, 2024
CVE-2024-8271
7.3 HIGH

The The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, …

Sep 14, 2024
CVE-2024-6259
7.6 HIGH

BT: HCI: adv_ext_report Improper discarding in adv_ext_report

Sep 13, 2024
CVE-2024-44095
7.8 HIGH

In ppmp_protect_mfcfw_buf of code/drm_fw.c, there is a possible corrupt memory due to a logic error in the code. This could lead to local escalation of …

Sep 13, 2024
CVE-2024-44094
7.8 HIGH

In ppmp_protect_mfcfw_buf of code/drm_fw.c, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege with no …

Sep 13, 2024
CVE-2024-44093
7.8 HIGH

In ppmp_unprotect_buf of drm/code/drm_fw.c, there is a possible memory corruption due to a logic error in the code. This could lead to local escalation of …

Sep 13, 2024
CVE-2024-44092
7.8 HIGH

There is a possible LCS signing enforcement missing due to test/debugging code left in a production build. This could lead to local escalation of privilege …

Sep 13, 2024
CVE-2024-29779
7.8 HIGH

there is a possible escalation of privilege due to an unusual root cause. This could lead to local escalation of privilege with no additional execution …

Sep 13, 2024
CVE-2024-6137
7.6 HIGH

BT: Classic: SDP OOB access in get_att_search_list

Sep 13, 2024
CVE-2024-6135
7.6 HIGH

BT:Classic: Multiple missing buf length checks

Sep 13, 2024
CVE-2024-5754
8.2 HIGH

BT: Encryption procedure host vulnerability

Sep 13, 2024
CVE-2024-8281
7.2 HIGH

An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection through specially …

Sep 13, 2024
CVE-2024-8280
7.2 HIGH

An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection or cause …

Sep 13, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.