CVE Database

4634+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-12845
3.5 LOW

A vulnerability classified as problematic was found in Emlog Pro up to 2.4.1. Affected by this vulnerability is an unknown functionality in the library /include/lib/common.php. …

Dec 20, 2024
CVE-2024-44298
3.3 LOW

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.1. An app may be …

Dec 20, 2024
CVE-2020-9250
3.3 LOW

There is an insufficient authentication vulnerability in some Huawei smart phone. An unauthenticated, local attacker can crafts software package to exploit this vulnerability. Due to …

Dec 20, 2024
CVE-2024-52589
2.2 LOW

Discourse is an open source platform for community discussion. Moderators can see the Screened emails list in the admin dashboard, and through that can learn …

Dec 19, 2024
CVE-2024-12790
3.5 LOW

A vulnerability was found in code-projects Hostel Management Site 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file room-details.php. …

Dec 19, 2024
CVE-2024-38864
3.3 LOW

Incorrect permissions on the Checkmk Windows Agent's data directory in Checkmk < 2.3.0p23, < 2.2.0p38 and <= 2.1.0p49 (EOL) allows a local attacker to read …

Dec 19, 2024
CVE-2024-12783
3.5 LOW

A vulnerability was found in itsourcecode Vehicle Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /billaction.php. The …

Dec 19, 2024
CVE-2024-49820
3.7 LOW

IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information, caused by the failure to …

Dec 17, 2024
CVE-2024-42194
3.1 LOW

An improper handling of insufficient permissions or privileges affects HCL BigFix Inventory. An attacker having access via a read-only account can possibly change certain configuration …

Dec 17, 2024
CVE-2024-9654
3.7 LOW

The Easy Digital Downloads plugin for WordPress is vulnerable to Improper Authorization in versions 3.1 through 3.3.4. This is due to a lack of sufficient …

Dec 17, 2024
CVE-2024-54125
3.3 LOW

Improper authorization in handler for custom URL scheme issue in "Shonen Jump+" App for Android versions prior to 4.0.0 allows an attacker to lead a …

Dec 17, 2024
CVE-2024-12667
3.7 LOW

A vulnerability was found in InvoicePlane up to 1.6.1 and classified as problematic. Affected by this issue is some unknown functionality of the file /invoices/view. …

Dec 16, 2024
CVE-2024-12665
3.5 LOW

A vulnerability, which was classified as problematic, was found in ruifang-tech Rebuild 3.8.5. Affected is an unknown function of the component Task Comment Attachment Upload. …

Dec 16, 2024
CVE-2024-12664
3.5 LOW

A vulnerability, which was classified as problematic, has been found in ruifang-tech Rebuild 3.8.5. This issue affects some unknown processing of the component Project Task …

Dec 16, 2024
CVE-2024-12663
3.7 LOW

A vulnerability classified as problematic was found in funnyzpc Mee-Admin up to 1.6. This vulnerability affects unknown code of the file /mee/login of the component …

Dec 16, 2024
CVE-2024-56082
3.5 LOW

ChatBar.tsx in Lumos before 1.0.17 parses raw HTML in Markdown because the markdown-to-jsx package is used without disableParsingRawHTML set to true.

Dec 15, 2024
CVE-2023-41695
3.5 LOW

Missing Authorization vulnerability in Adnan Analytify wp-analytify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Analytify: from n/a through <= 5.1.0.

Dec 13, 2024
CVE-2022-45819
3.5 LOW

Missing Authorization vulnerability in Popup Maker Popup Maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Popup Maker: from n/a through 1.17.1.

Dec 13, 2024
CVE-2021-32007
3.5 LOW

This issue affects: Secomea GateManager Version 9.5 and all prior versions. Protection Mechanism Failure vulnerability in web server of Secomea GateManager to potentially leak information …

Dec 13, 2024
CVE-2024-12300
3.7 LOW

The AR for WordPress plugin for WordPress is vulnerable to unauthorized double extension file upload due to a missing capability check on the set_ar_featured_image() function …

Dec 13, 2024
CVE-2024-10043
3.1 LOW

An issue has been discovered in GitLab EE affecting all versions starting from 14.3 before 17.4.6, all versions starting from 17.5 before 17.5.4 all versions …

Dec 12, 2024
CVE-2024-54493
3.3 LOW

This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.2. Privacy indicators for microphone access may be attributed incorrectly.

Dec 12, 2024
CVE-2024-54491
3.3 LOW

The issue was resolved by sanitizing logging. This issue is fixed in macOS Sequoia 15.2. A malicious application may be able to determine a user's …

Dec 12, 2024
CVE-2024-54485
2.4 LOW

The issue was addressed by adding additional logic. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2. An attacker …

Dec 12, 2024
CVE-2024-44290
3.3 LOW

This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, watchOS 11.1. …

Dec 12, 2024
CVE-2024-44200
3.3 LOW

This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1. An app …

Dec 12, 2024
CVE-2024-12536
3.5 LOW

A vulnerability, which was classified as problematic, has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0. Affected by this issue is some …

Dec 12, 2024
CVE-2024-12503
2.4 LOW

A vulnerability classified as problematic was found in ClassCMS 4.8. Affected by this vulnerability is an unknown functionality of the file /index.php/admin of the component …

Dec 12, 2024
CVE-2024-12483
3.7 LOW

A vulnerability classified as problematic has been found in Dromara UJCMS up to 9.6.3. This affects an unknown part of the file /users/id of the …

Dec 12, 2024
CVE-2023-23472
3.1 LOW

IBM InfoSphere DataStage Flow Designer (InfoSphere Information Server 11.7) could allow an authenticated user to obtain sensitive information that could aid in further attacks against …

Dec 11, 2024
CVE-2024-11053
3.4 LOW

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host …

Dec 11, 2024
CVE-2023-37395
2.5 LOW

IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information due to improper encryption of certain data.

Dec 11, 2024
CVE-2024-52831
3.5 LOW

Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass. A low-privileged …

Dec 10, 2024
CVE-2024-43755
3.5 LOW

Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass. A low-privileged …

Dec 10, 2024
CVE-2024-55550
2.7 LOW KEV

Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A …

Dec 10, 2024
CVE-2024-53245
3.1 LOW

In Splunk Enterprise versions below 9.3.0, 9.2.4, and 9.1.7 and Splunk Cloud Platform versions below 9.1.2312.206, a low-privileged user that does not hold the “admin“ …

Dec 10, 2024
CVE-2024-47577
2.7 LOW

Webservice API endpoints for Assisted Service Module within SAP Commerce Cloud has information disclosure vulnerability. When an authorized agent searches for customer to manage their …

Dec 10, 2024
CVE-2024-47576
3.3 LOW

SAP Product Lifecycle Costing Client (versions below 4.7.1) application loads on demand a DLL that is available with Windows OS. This DLL is loaded from …

Dec 10, 2024
CVE-2024-12174
2.7 LOW

An Improper Certificate Validation vulnerability exists in Tenable Security Center where an authenticated, privileged attacker could intercept email messages sent from Security Center via a …

Dec 9, 2024
CVE-2023-28168
3.7 LOW

Missing Authorization vulnerability in Jerod Santo WordPress Console allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress Console: from n/a through 0.3.9.

Dec 9, 2024
CVE-2023-24375
3.5 LOW

Missing Authorization vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress …

Dec 9, 2024
CVE-2023-23825
3.1 LOW

Missing Authorization vulnerability in Brainstorm Force Spectra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through 2.3.0.

Dec 9, 2024
CVE-2023-23814
3.8 LOW

Missing Authorization vulnerability in CodePeople CP Multi View Event Calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CP Multi View Event Calendar …

Dec 9, 2024
CVE-2024-46901
3.1 LOW

Insufficient validation of filenames against control characters in Apache Subversion repositories served via mod_dav_svn allows authenticated users with commit access to commit a corrupted revision, …

Dec 9, 2024
CVE-2024-12359
3.5 LOW

A vulnerability was found in code-projects Admin Dashboard 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /vendor_management.php. The …

Dec 9, 2024
CVE-2024-12355
3.3 LOW

A vulnerability has been found in SourceCodester Phone Contact Manager System 1.0 and classified as problematic. Affected by this vulnerability is the function ContactBook::adding of …

Dec 9, 2024
CVE-2024-12353
3.3 LOW

A vulnerability, which was classified as problematic, has been found in SourceCodester Phone Contact Manager System 1.0. This issue affects the function UserInterface::MenuDisplayStart of the …

Dec 9, 2024
CVE-2024-12348
3.5 LOW

A vulnerability was found in Guizhou Xiaoma Technology jpress 5.1.2. It has been classified as problematic. Affected is the function AttachmentUtils.isUnSafe of the file /commons/attachment/upload …

Dec 9, 2024
CVE-2024-12346
3.5 LOW

A vulnerability has been found in Talentera up to 20241128 and classified as problematic. This vulnerability affects unknown code of the file /app/control/byt_cv_manager. The manipulation …

Dec 9, 2024
CVE-2024-6219
3.8 LOW

Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust store with its restrictions not …

Dec 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.