CVE Database

39885+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-45170
8.1 HIGH

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper or missing access control, low privileged users can use administrative functions of …

Sep 4, 2024
CVE-2024-20440
7.5 HIGH

A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive information. This vulnerability is due to excessive verbosity in …

Sep 4, 2024
CVE-2024-8391
7.5 HIGH

In Eclipse Vert.x version 4.3.0 to 4.5.9, the gRPC server does not limit the maximum length of message payload (Maven GAV: io.vertx:vertx-grpc-server and io.vertx:vertx-grpc-client). This …

Sep 4, 2024
CVE-2024-45075
8.8 HIGH

IBM webMethods Integration 10.15 could allow an authenticated user to create scheduler tasks that would allow them to escalate their privileges to administrator due to …

Sep 4, 2024
CVE-2024-45050
7.1 HIGH

Ringer server is the server code for the Ringer messaging app. Prior to version 1.3.1, there is an issue with the messages loading route where …

Sep 4, 2024
CVE-2024-44859
8.0 HIGH

Tenda FH1201 v1.2.0.14 has a stack buffer overflow vulnerability in `formWrlExtraGet`.

Sep 4, 2024
CVE-2024-44817
8.8 HIGH

SQL Injection vulnerability in ZZCMS v.2023 and before allows a remote attacker to obtain sensitive information via the id parameter in the adv2.php component.

Sep 4, 2024
CVE-2024-43405
7.4 HIGH

Nuclei is a vulnerability scanner powered by YAML based templates. Starting in version 3.0.0 and prior to version 3.3.2, a vulnerability in Nuclei's template signature …

Sep 4, 2024
CVE-2024-43402
8.1 HIGH

Rust is a programming language. The fix for CVE-2024-24576, where `std::process::Command` incorrectly escaped arguments when invoking batch files on Windows, was incomplete. Prior to Rust …

Sep 4, 2024
CVE-2024-8418
7.5 HIGH

A flaw was found in Aardvark-dns, which is vulnerable to a Denial of Service attack due to the serial processing of TCP DNS queries. An …

Sep 4, 2024
CVE-2024-45506
7.5 HIGH

HAProxy 2.9.x before 2.9.10, 3.0.x before 3.0.4, and 3.1.x through 3.1-dev6 allows a remote denial of service for HTTP/2 zero-copy forwarding (h2_send loop) under a …

Sep 4, 2024
CVE-2024-7834
7.8 HIGH

A local privilege escalation is caused by Overwolf loading and executing certain dynamic link library files from a user-writeable folder in SYSTEM context on launch. …

Sep 4, 2024
CVE-2024-45195
7.5 HIGH KEV

Direct Request ('Forced Browsing') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes …

Sep 4, 2024
CVE-2024-8104
8.8 HIGH

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.0.8 via …

Sep 4, 2024
CVE-2024-8102
8.8 HIGH

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due …

Sep 4, 2024
CVE-2024-34660
7.3 HIGH

Heap-based out-of-bounds write in Samsung Notes prior to version 4.4.21.62 allows local attackers to execute arbitrary code.

Sep 4, 2024
CVE-2024-34659
7.5 HIGH

Exposure of sensitive information in GroupSharing prior to version 13.6.13.3 allows remote attackers can force the victim to join the group.

Sep 4, 2024
CVE-2024-34657
8.6 HIGH

Stack-based out-of-bounds write in Samsung Notes prior to version 4.4.21.62 allows remote attackers to execute arbitrary code.

Sep 4, 2024
CVE-2024-34656
7.3 HIGH

Path traversal in Samsung Notes prior to version 4.4.21.62 allows local attackers to execute arbitrary code.

Sep 4, 2024
CVE-2024-39921
7.5 HIGH

Observable timing discrepancy issue exists in IPCOM EX2 Series V01L02NF0001 to V01L06NF0401, V01L20NF0001 to V01L20NF0401, V02L20NF0001 to V02L21NF0301, and IPCOM VE2 Series V01L04NF0001 to V01L06NF0112. …

Sep 4, 2024
CVE-2024-41716
8.1 HIGH

Cleartext storage of sensitive information vulnerability exists in WindLDR and WindO/I-NV4. If this vulnerability is exploited, an attacker who obtained the product's project file may …

Sep 4, 2024
CVE-2024-8362
8.8 HIGH

Use after free in WebAudio in Google Chrome prior to 128.0.6613.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Sep 3, 2024
CVE-2024-7970
8.8 HIGH

Out of bounds write in V8 in Google Chrome prior to 128.0.6613.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

Sep 3, 2024
CVE-2024-45394
8.8 HIGH

Authenticator is a browser extension that generates two-step verification codes. In versions 7.0.0 and below, encryption keys for user data were stored encrypted at-rest using …

Sep 3, 2024
CVE-2024-45391
7.5 HIGH

Tina is an open-source content management system (CMS). Sites building with Tina CMS's command line interface (CLI) prior to version 1.6.2 that use a search …

Sep 3, 2024
CVE-2024-45390
7.3 HIGH

@blakeembrey/template is a string template library. Prior to version 1.2.0, it is possible to inject and run code within the template if the attacker has …

Sep 3, 2024
CVE-2024-45307
8.8 HIGH

SudoBot, a Discord moderation bot, is vulnerable to privilege escalation and exploit of the `-config` command in versions prior to 9.26.7. Anyone is theoretically able …

Sep 3, 2024
CVE-2024-41436
7.5 HIGH

ClickHouse v24.3.3.102 was discovered to contain a buffer overflow via the component DB::evaluateConstantExpressionImpl.

Sep 3, 2024
CVE-2024-41435
7.5 HIGH

YugabyteDB v2.21.1.0 was discovered to contain a buffer overflow via the "insert into" parameter.

Sep 3, 2024
CVE-2024-42902
8.8 HIGH

An issue in the js_localize.php function of LimeSurvey v6.6.2 and before allows attackers to execute arbitrary code via injecting a crafted payload into the lng …

Sep 3, 2024
CVE-2024-38456
7.8 HIGH

HIGH-LEIT V05.08.01.03 and HIGH-LEIT V04.25.00.00 to 4.25.01.01 for Windows from Vivavis contain an insecure file and folder permissions vulnerability in prunsrv.exe. A regular user (non-admin) …

Sep 3, 2024
CVE-2023-49233
8.8 HIGH

Insufficient access checks in Visual Planning Admin Center 8 before v.1 Build 240207 allow attackers in possession of a non-administrative Visual Planning account to utilize …

Sep 3, 2024
CVE-2024-6119
7.5 HIGH

Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination …

Sep 3, 2024
CVE-2024-42991
8.1 HIGH

MCMS v5.4.1 has front-end file upload vulnerability which can lead to remote command execution.

Sep 3, 2024
CVE-2024-7654
8.3 HIGH

An ActiveMQ Discovery service was reachable by default from an OpenEdge Management installation when an OEE/OEM auto-discovery feature was activated. Unauthorized access to the discovery …

Sep 3, 2024
CVE-2024-7346
7.2 HIGH

Host name validation for TLS certificates is bypassed when the installed OpenEdge default certificates are used to perform the TLS handshake for a networked connection. …

Sep 3, 2024
CVE-2024-7345
8.3 HIGH

Local ABL Client bypass of the required PASOE security checks may allow an attacker to commit unauthorized code injection into Multi-Session Agents on supported OpenEdge …

Sep 3, 2024
CVE-2024-8383
7.5 HIGH

Firefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that the browser does not support. It …

Sep 3, 2024
CVE-2024-8382
8.8 HIGH

Internal browser event interfaces were exposed to web content when privileged EventHandler listener callbacks ran for those events. Web content that tried to use those …

Sep 3, 2024
CVE-2024-6232
7.5 HIGH

There is a MEDIUM severity vulnerability affecting CPython. Regular expressions that allowed excessive backtracking during tarfile.TarFile header parsing are vulnerable to ReDoS via specifically-crafted tar …

Sep 3, 2024
CVE-2024-6473
7.8 HIGH

Yandex Browser for Desktop before 24.7.1.380 has a DLL Hijacking Vulnerability because an untrusted search path is used.

Sep 3, 2024
CVE-2024-45588
8.1 HIGH

This vulnerability exists in Symphony XTS Web Trading platform version 2.0.0.1_P160 due to improper access controls on APIs in the Preference module of the application. …

Sep 3, 2024
CVE-2024-8374
7.8 HIGH

UltiMaker Cura slicer versions 5.7.0-beta.1 through 5.7.2 are vulnerable to code injection via the 3MF format reader (/plugins/ThreeMFReader.py). The vulnerability arises from improper handling of …

Sep 3, 2024
CVE-2024-45587
8.8 HIGH

This vulnerability exists in Symphony XTS Web Trading platform version 2.0.0.1_P160 due to improper access controls on APIs in the Transaction module of vulnerable application. …

Sep 3, 2024
CVE-2024-45586
8.8 HIGH

This vulnerability exists due to improper access controls on APIs in the Authentication module of Symphony XTS Web Trading and Mobile Trading platforms (version 2.0.0.1_P160). …

Sep 3, 2024
CVE-2024-3655
7.8 HIGH

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel …

Sep 3, 2024
CVE-2024-38811
8.8 HIGH

VMware Fusion (13.x before 13.6) contains a code-execution vulnerability due to the usage of an insecure environment variable. A malicious actor with standard user privileges …

Sep 3, 2024
CVE-2024-7203
7.2 HIGH

A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.60 through V5.38 and USG FLEX series firmware versions from V4.60 through V5.38 …

Sep 3, 2024
CVE-2024-5412
7.5 HIGH

A buffer overflow vulnerability in the library "libclinkc" of the Zyxel VMG8825-T50K firmware version 5.50(ABOM.8)C0 could allow an unauthenticated attacker to cause denial of service …

Sep 3, 2024
CVE-2024-42060
7.2 HIGH

A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG …

Sep 3, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.