CVE Database

39885+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-8279
7.2 HIGH

A privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection via specially …

Sep 13, 2024
CVE-2024-8278
7.2 HIGH

A privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection via specially …

Sep 13, 2024
CVE-2024-39924
8.8 HIGH

An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A vulnerability has been identified in the authentication and authorization process of the endpoint responsible for …

Sep 13, 2024
CVE-2024-6862
8.1 HIGH

A Cross-Site Request Forgery (CSRF) vulnerability exists in lunary-ai/lunary version 1.2.34 due to overly permissive CORS settings. This vulnerability allows an attacker to sign up …

Sep 13, 2024
CVE-2024-45368
8.8 HIGH

The H2-DM1E PLC's authentication protocol appears to utilize either a custom encoding scheme or a challenge-response protocol. However, there's an observed anomaly in the H2-DM1E …

Sep 13, 2024
CVE-2024-43099
8.8 HIGH

The session hijacking attack targets the application layer's control mechanism, which manages authenticated sessions between a host PC and a PLC. During such sessions, a …

Sep 13, 2024
CVE-2024-6587
7.5 HIGH

A Server-Side Request Forgery (SSRF) vulnerability exists in berriai/litellm version 1.38.10. This vulnerability allows users to specify the `api_base` parameter when making requests to `POST …

Sep 13, 2024
CVE-2024-42025
7.8 HIGH

A Command Injection vulnerability found in a Self-Hosted UniFi Network Servers (Linux) with UniFi Network Application (Version 8.3.32 and earlier) allows a malicious actor with …

Sep 13, 2024
CVE-2024-8269
7.3 HIGH

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized user registration in all versions …

Sep 13, 2024
CVE-2024-7423
8.8 HIGH

The Stream plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.0.1. This is due to missing or …

Sep 13, 2024
CVE-2024-46713
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: perf/aux: Fix AUX buffer serialization Ole reported that event->mmap_mutex is strictly insufficient to serialize the …

Sep 13, 2024
CVE-2022-2446
7.2 HIGH

The WP Editor plugin for WordPress is vulnerable to deserialization of untrusted input via the 'current_theme_root' parameter in versions up to, and including 1.2.9. This …

Sep 13, 2024
CVE-2024-46047
7.5 HIGH

Tenda FH451 v1.0.0.9 has a stack overflow vulnerability in the fromDhcpListClient function.

Sep 13, 2024
CVE-2024-45113
7.5 HIGH

ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability …

Sep 13, 2024
CVE-2024-45109
7.8 HIGH

Photoshop Desktop versions 24.7.4, 25.11 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Sep 13, 2024
CVE-2024-45108
7.8 HIGH

Photoshop Desktop versions 24.7.4, 25.11 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Sep 13, 2024
CVE-2024-43760
7.8 HIGH

Photoshop Desktop versions 24.7.4, 25.11 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Sep 13, 2024
CVE-2024-43756
7.8 HIGH

Photoshop Desktop versions 24.7.4, 25.11 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Sep 13, 2024
CVE-2024-45112
7.8 HIGH

Acrobat Reader versions 24.002.21005, 24.001.30159, 20.005.30655, 24.003.20054 and earlier are affected by a Type Confusion vulnerability that could result in arbitrary code execution in the …

Sep 13, 2024
CVE-2024-43758
7.8 HIGH

Illustrator versions 28.6, 27.9.5 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of …

Sep 13, 2024
CVE-2024-41869
7.8 HIGH

Acrobat Reader versions 24.002.21005, 24.001.30159, 20.005.30655, 24.003.20054 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in …

Sep 13, 2024
CVE-2024-41859
7.8 HIGH

After Effects versions 23.6.6, 24.5 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Sep 13, 2024
CVE-2024-41857
7.8 HIGH

Illustrator versions 28.6, 27.9.5 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the …

Sep 13, 2024
CVE-2024-39384
7.8 HIGH

Premiere Pro versions 24.5, 23.6.8 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Sep 13, 2024
CVE-2024-39381
7.8 HIGH

After Effects versions 23.6.6, 24.5 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Sep 13, 2024
CVE-2024-39380
7.8 HIGH

After Effects versions 23.6.6, 24.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Sep 13, 2024
CVE-2024-34121
7.8 HIGH

Illustrator versions 28.6, 27.9.5 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context …

Sep 13, 2024
CVE-2024-39377
7.8 HIGH

Media Encoder versions 24.5, 23.6.8 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Sep 13, 2024
CVE-2024-7129
7.2 HIGH

The Appointment Booking Calendar WordPress plugin before 1.6.7.43 does not escape template syntax provided via user input, leading to Twig Template Injection which further exploited …

Sep 13, 2024
CVE-2024-46699
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Disable preemption while updating GPU stats We forgot to disable preemption around the write_seqcount_begin/end() …

Sep 13, 2024
CVE-2024-46696
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: nfsd: fix potential UAF in nfsd4_cb_getattr_release Once we drop the delegation reference, the fields embedded …

Sep 13, 2024
CVE-2024-46687
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix a use-after-free when hitting errors inside btrfs_submit_chunk() [BUG] There is an internal report …

Sep 13, 2024
CVE-2024-46683
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/xe: prevent UAF around preempt fence The fence lock is part of the queue, therefore …

Sep 13, 2024
CVE-2024-46674
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: usb: dwc3: st: fix probed platform device ref count on probe error path The probe …

Sep 13, 2024
CVE-2024-46673
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: scsi: aacraid: Fix double-free on probe failure aac_probe_one() calls hardware-specific init functions through the aac_driver_ident::init …

Sep 13, 2024
CVE-2024-38816
7.5 HIGH

Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests …

Sep 13, 2024
CVE-2024-8751
7.5 HIGH

A vulnerability in the MSC800 allows an unauthenticated attacker to modify the product’s IP address over Sopas ET. This can lead to Denial of Service. …

Sep 12, 2024
CVE-2024-8533
8.8 HIGH

A privilege escalation vulnerability exists in the Rockwell Automation affected products. The vulnerability occurs due to improper default file permissions allowing users to exfiltrate credentials …

Sep 12, 2024
CVE-2024-6077
7.5 HIGH

A denial-of-service vulnerability exists in the Rockwell Automation affected products when specially crafted packets are sent to the CIP Security Object. If exploited the device …

Sep 12, 2024
CVE-2024-44460
7.5 HIGH

An invalid read size in Nanomq v0.21.9 allows attackers to cause a Denial of Service (DoS).

Sep 12, 2024
CVE-2024-44459
7.5 HIGH

A memory allocation issue in vernemq v2.0.1 allows attackers to cause a Denial of Service (DoS) via excessive memory consumption.

Sep 12, 2024
CVE-2024-20430
7.3 HIGH

A vulnerability in Cisco Meraki Systems Manager (SM) Agent for Windows could allow an authenticated, local attacker to execute arbitrary code with elevated privileges.  This …

Sep 12, 2024
CVE-2024-45181
7.8 HIGH

An issue was discovered in WibuKey64.sys in WIBU-SYSTEMS WibuKey before v6.70 and fixed in v.6.70. An improper bounds check allows crafted packets to cause an …

Sep 12, 2024
CVE-2024-34334
7.5 HIGH

ORDAT FOSS-Online before v2.24.01 was discovered to contain a SQL injection vulnerability via the forgot password function.

Sep 12, 2024
CVE-2024-8640
8.5 HIGH

An issue has been discovered in GitLab EE affecting all versions starting from 16.11 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 …

Sep 12, 2024
CVE-2024-8635
7.7 HIGH

A server-side request forgery issue has been discovered in GitLab EE affecting all versions starting from 16.8 prior to 17.1.7, from 17.2 prior to 17.2.5, …

Sep 12, 2024
CVE-2024-8124
7.5 HIGH

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.1.7, starting from 17.2 prior to 17.2.5, starting from 17.3 …

Sep 12, 2024
CVE-2024-6658
8.4 HIGH

Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows OS Command Injection.This issue affects: Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.0 (inclusive) …

Sep 12, 2024
CVE-2024-6510
7.8 HIGH

Local Privilege Escalation in AVG Internet Security v24 on Windows allows a local unprivileged user to escalate privileges to SYSTEM via COM-Hijacking.

Sep 12, 2024
CVE-2024-45825
7.5 HIGH

CVE-2024-45825 IMPACT A denial-of-service vulnerability exists in the affected products. The vulnerability occurs when a malformed CIP packet is sent over the network to the …

Sep 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.