CVE Database

4634+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-6156
3.8 LOW

Mark Laing discovered that LXD's PKI mode, until version 5.21.2, could be bypassed if the client's certificate was present in the trust store.

Dec 6, 2024
CVE-2024-12232
3.5 LOW

A vulnerability has been found in code-projects Simple CRUD Functionality 1.0 and classified as problematic. This vulnerability affects unknown code of the file /index.php. The …

Dec 5, 2024
CVE-2024-42195
3.1 LOW

HCL DevOps Deploy / HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web …

Dec 5, 2024
CVE-2024-54014
3.6 LOW

Improper authorization in handler for custom URL scheme issue in 'Skylark' App for Android 6.2.13 and earlier and 'Skylark' App for iOS 6.2.13 and earlier …

Dec 5, 2024
CVE-2024-12183
3.5 LOW

A vulnerability, which was classified as problematic, was found in DedeCMS 5.7.116. This affects the function RemoveXSS of the file /plus/carbuyaction.php of the component HTTP …

Dec 4, 2024
CVE-2024-12182
3.5 LOW

A vulnerability, which was classified as problematic, has been found in DedeCMS 5.7.116. Affected by this issue is some unknown functionality of the file /member/soft_add.php. …

Dec 4, 2024
CVE-2024-12181
3.5 LOW

A vulnerability classified as problematic was found in DedeCMS 5.7.116. Affected by this vulnerability is an unknown functionality of the file /member/uploads_add.php of the component …

Dec 4, 2024
CVE-2024-12180
3.5 LOW

A vulnerability classified as problematic has been found in DedeCMS 5.7.116. Affected is an unknown function of the file /member/article_add.php. The manipulation of the argument …

Dec 4, 2024
CVE-2024-38829
3.7 LOW

A vulnerability in Spring LDAP allows data exposure for case sensitive comparisons.This issue affects Spring LDAP: from 2.4.0 through 2.4.3, from 3.0.0 through 3.0.9, from …

Dec 4, 2024
CVE-2024-54158
3.5 LOW

In JetBrains YouTrack before 2024.3.52635 potential spoofing attack was possible via lack of Punycode encoding

Dec 4, 2024
CVE-2024-54155
3.7 LOW

In JetBrains YouTrack before 2024.3.51866 improper access control allowed listing of project names during app import without authentication

Dec 4, 2024
CVE-2024-54153
3.1 LOW

In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible via vulnerable query parameter

Dec 4, 2024
CVE-2024-53502
3.8 LOW

Seecms v4.8 was discovered to contain a SQL injection vulnerability in the SEMCMS_SeoAndTag.php page.

Dec 3, 2024
CVE-2024-53921
2.8 LOW

An issue was discovered in the installer in Samsung Magician 8.1.0 on Windows. An attacker can create arbitrary folders in the system permission directory via …

Dec 3, 2024
CVE-2024-49417
2.0 LOW

Use of implicit intent for sensitive communication in Smart Touch Call prior to 1.0.0.8 allows local attackers to launch privileged activities. User interaction is required …

Dec 3, 2024
CVE-2024-49414
2.4 LOW

Authentication Bypass Using an Alternate Path in Dex Mode prior to SMR Dec-2024 Release 1 allows physical attackers to temporarily access to recent app list.

Dec 3, 2024
CVE-2024-53564
2.2 LOW

A vulnerability was discovered in FreePBX 17.0.19.17. It does not verify the type of uploaded (valid FreePBX module) files, allowing high-privilege administrators to insert unwanted …

Dec 2, 2024
CVE-2024-11856
3.7 LOW

A security vulnerability in HPE IceWall products could be exploited remotely to cause Unauthorized Data Modification.

Dec 2, 2024
CVE-2024-12001
3.5 LOW

A vulnerability classified as problematic has been found in code-projects Wazifa System 1.0. Affected is an unknown function of the file /controllers/updatesettings.php of the component …

Nov 30, 2024
CVE-2024-12000
3.5 LOW

A vulnerability was found in code-projects Blood Bank System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file …

Nov 30, 2024
CVE-2024-11997
3.5 LOW

A vulnerability was found in code-projects Farmacia 1.0. It has been classified as problematic. This affects an unknown part of the file /vendas.php. The manipulation …

Nov 30, 2024
CVE-2024-11996
3.5 LOW

A vulnerability was found in code-projects Farmacia 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /editar-fornecedor.php. The …

Nov 30, 2024
CVE-2024-11995
3.5 LOW

A vulnerability has been found in code-projects Farmacia 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /pagamento.php. …

Nov 29, 2024
CVE-2024-53861
2.2 LOW

pyjwt is a JSON Web Token implementation in Python. An incorrect string comparison is run for `iss` checking, resulting in `"acb"` being accepted for `"_abc_"`. …

Nov 29, 2024
CVE-2024-53701
3.1 LOW

Multiple FCNT Android devices provide the original security features such as "privacy mode" where arbitrary applications can be set not to be displayed, etc. Under …

Nov 29, 2024
CVE-2024-11971
3.5 LOW

A vulnerability classified as problematic was found in Guizhou Xiaoma Technology jpress 5.1.2. Affected by this vulnerability is an unknown functionality of the file /commons/attachment/upload …

Nov 28, 2024
CVE-2024-49503
3.5 LOW

A Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SUSE manager allows attackers to execute Javascript code in the …

Nov 28, 2024
CVE-2024-49502
3.5 LOW

A Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in the Setup Wizard, HTTP Proxy credentials pane in spacewalk-web allows …

Nov 28, 2024
CVE-2024-53855
1.9 LOW

Centurion ERP (Enterprise Rescource Planning) is a simple application developed to provide open source IT management with a large emphasis on the IT Service Management …

Nov 27, 2024
CVE-2024-36464
2.7 LOW

When exporting media types, the password is exported in the YAML in plain text. This appears to be a best practices type issue and may …

Nov 27, 2024
CVE-2024-42333
2.7 LOW

The researcher is showing that it is possible to leak a small amount of Zabbix Server memory using an out of bounds read in src/libs/zbxmedia/email.c

Nov 27, 2024
CVE-2024-42332
3.7 LOW

The researcher is showing that due to the way the SNMP trap log is parsed, an attacker can craft an SNMP trap with additional lines …

Nov 27, 2024
CVE-2024-42331
3.3 LOW

In the src/libs/zbxembed/browser.c file, the es_browser_ctor method retrieves a heap pointer from the Duktape JavaScript engine. This heap pointer is subsequently utilized by the browser_push_error …

Nov 27, 2024
CVE-2024-42329
3.3 LOW

The webdriver for the Browser object expects an error object to be initialized when the webdriver_session_query function fails. But this function can fail for various …

Nov 27, 2024
CVE-2024-42328
3.3 LOW

When the webdriver for the Browser object downloads data from a HTTP server, the data pointer is set to NULL and is allocated only in …

Nov 27, 2024
CVE-2024-36468
3.0 LOW

The reported vulnerability is a stack buffer overflow in the zbx_snmp_cache_handle_engineid function within the Zabbix server/proxy code. This issue occurs when copying data from session->securityEngineID …

Nov 27, 2024
CVE-2024-11820
3.5 LOW

A vulnerability, which was classified as problematic, has been found in code-projects Crud Operation System 1.0. This issue affects some unknown processing of the file …

Nov 27, 2024
CVE-2024-11742
3.5 LOW

A vulnerability, which was classified as problematic, has been found in SourceCodester Best House Rental Management System 1.0. This issue affects some unknown processing of …

Nov 26, 2024
CVE-2024-22117
2.2 LOW

When a URL is added to the map element, it is recorded in the database with sequential IDs. Upon adding a new URL, the system …

Nov 26, 2024
CVE-2024-8160
3.8 LOW

Erik de Jong, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API ftptest.cgi did not have a sufficient input validation …

Nov 26, 2024
CVE-2024-11678
3.5 LOW

A vulnerability was found in CodeAstro Hospital Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /backend/doc/his_doc_register_patient.php. …

Nov 26, 2024
CVE-2024-11677
3.5 LOW

A vulnerability was found in CodeAstro Hospital Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /backend/admin/his_admin_add_vendor.php …

Nov 26, 2024
CVE-2024-11676
3.5 LOW

A vulnerability was found in CodeAstro Hospital Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file …

Nov 26, 2024
CVE-2024-11675
3.5 LOW

A vulnerability has been found in CodeAstro Hospital Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the …

Nov 26, 2024
CVE-2024-10492
2.7 LOW

A vulnerability was found in Keycloak. A user with high privileges could read sensitive information from a Vault file that is not within the expected …

Nov 25, 2024
CVE-2024-11660
3.5 LOW

A vulnerability was found in code-projects Farmacia 1.0. It has been classified as problematic. This affects an unknown part of the file usuario.php. The manipulation …

Nov 25, 2024
CVE-2024-7056
3.5 LOW

The WPForms WordPress plugin before 1.9.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as Admin to …

Nov 25, 2024
CVE-2024-10710
3.5 LOW

The YaDisk Files WordPress plugin through 1.2.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Nov 25, 2024
CVE-2024-9763
3.3 LOW

Tungsten Automation Power PDF PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of …

Nov 22, 2024
CVE-2024-9762
3.3 LOW

Tungsten Automation Power PDF OXPS File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of …

Nov 22, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.