CVE Database

4634+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-9761
3.3 LOW

Tungsten Automation Power PDF PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of …

Nov 22, 2024
CVE-2024-9760
3.3 LOW

Tungsten Automation Power PDF PNG File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of …

Nov 22, 2024
CVE-2024-9759
3.3 LOW

Tungsten Automation Power PDF GIF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of …

Nov 22, 2024
CVE-2024-9757
3.3 LOW

Tungsten Automation Power PDF JP2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of …

Nov 22, 2024
CVE-2024-9754
3.3 LOW

Tungsten Automation Power PDF PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of …

Nov 22, 2024
CVE-2024-9753
3.3 LOW

Tungsten Automation Power PDF PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of …

Nov 22, 2024
CVE-2024-9752
3.3 LOW

Tungsten Automation Power PDF JPG File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of …

Nov 22, 2024
CVE-2024-9749
3.3 LOW

Tungsten Automation Power PDF PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of …

Nov 22, 2024
CVE-2024-52814
2.8 LOW

Argo Helm is a collection of community maintained charts for `argoproj.github.io` projects. Prior to version 0.45.0, the `workflow-role`) lacks granularity in its privileges, giving permissions …

Nov 22, 2024
CVE-2024-45719
2.6 LOW

Inadequate Encryption Strength vulnerability in Apache Answer. This issue affects Apache Answer: through 1.4.0. The ids generated using the UUID v1 version are to some …

Nov 22, 2024
CVE-2024-52054
2.7 LOW

Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to create an XML definition file anywhere on the …

Nov 21, 2024
CVE-2024-51337
3.5 LOW

Cross Site Scripting vulnerability in Gibbon before v.27.0.01 and fixed in v.28.0.00 allows a remote attacker to obtain sensitive information via the email parameter found …

Nov 21, 2024
CVE-2024-11588
3.5 LOW

A vulnerability was found in AVL-DiTEST-DiagDev libdoip 1.0.0. It has been rated as problematic. This issue affects the function DoIPConnection::reactOnReceivedTcpMessage of the file DoIPConnection.cpp. The …

Nov 21, 2024
CVE-2024-11587
3.5 LOW

A vulnerability was found in idcCMS 1.60. It has been classified as problematic. This affects the function GetCityOptionJs of the file /inc/classProvCity.php. The manipulation of …

Nov 21, 2024
CVE-2024-11493
3.5 LOW

A vulnerability classified as problematic was found in 115cms up to 20240807. This vulnerability affects unknown code of the file /index.php/setpage/admin/pageAE.html. The manipulation of the …

Nov 20, 2024
CVE-2024-11492
3.5 LOW

A vulnerability classified as problematic has been found in 115cms up to 20240807. This affects an unknown part of the file /index.php/admin/web/appurladd.html. The manipulation of …

Nov 20, 2024
CVE-2024-11491
3.5 LOW

A vulnerability was found in 115cms up to 20240807. It has been rated as problematic. Affected by this issue is some unknown functionality of the …

Nov 20, 2024
CVE-2024-11490
3.5 LOW

A vulnerability was found in 115cms up to 20240807. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the …

Nov 20, 2024
CVE-2024-11489
3.5 LOW

A vulnerability was found in 115cms up to 20240807. It has been classified as problematic. Affected is an unknown function of the file /index.php/admin/web/file.html. The …

Nov 20, 2024
CVE-2024-11488
3.5 LOW

A vulnerability was found in 115cms up to 20240807 and classified as problematic. This issue affects some unknown processing of the file /app/admin/view/web_user.html. The manipulation …

Nov 20, 2024
CVE-2024-10515
3.5 LOW

In the process of testing the SEO Plugin by Squirrly SEO WordPress plugin before 12.3.21, a vulnerability was found that allows you to implement Stored …

Nov 20, 2024
CVE-2024-51671
2.7 LOW

Missing Authorization vulnerability in Themeisle Otter - Gutenberg Block otter-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Otter - Gutenberg Block: from …

Nov 19, 2024
CVE-2024-5030
3.8 LOW

The CM Table Of Contents WordPress plugin before 1.2.3 does not have CSRF check in place when resetting its settings, which could allow attackers to …

Nov 18, 2024
CVE-2023-0657
3.4 LOW

A flaw was found in Keycloak. This issue occurs due to improperly enforcing token types when validating signatures locally. This could allow an authenticated attacker …

Nov 17, 2024
CVE-2024-11259
3.5 LOW

A vulnerability, which was classified as problematic, has been found in code-projects Farmacia 1.0. This issue affects some unknown processing of the file /fornecedores.php. The …

Nov 15, 2024
CVE-2024-52513
2.6 LOW

Nextcloud Server is a self hosted personal cloud system. After receiving a "Files drop" or "Password protected" share link a malicious user was able to …

Nov 15, 2024
CVE-2024-52512
3.3 LOW

user_oidc app is an OpenID Connect user backend for Nextcloud. A malicious user could send a malformed login link that would redirect the user to …

Nov 15, 2024
CVE-2024-52509
3.5 LOW

Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. The Nextcloud mail app incorrectly allowed attaching shared files without download permissions as …

Nov 15, 2024
CVE-2024-52507
3.5 LOW

Nextcloud Tables allows users to to create tables with individual columns. The information which Table (numeric ID) is shared with which groups and users and …

Nov 15, 2024
CVE-2024-46383
2.4 LOW

Hathway Skyworth Router CM5100-511 v4.1.1.24 was discovered to store sensitive information about USB and Wifi connected devices in plaintext.

Nov 15, 2024
CVE-2024-52525
1.8 LOW

Nextcloud Server is a self hosted personal cloud system. Under certain conditions the password of a user was stored unencrypted in the session data. The …

Nov 15, 2024
CVE-2024-52521
2.6 LOW

Nextcloud Server is a self hosted personal cloud system. MD5 hashes were used to check background jobs for their uniqueness. This increased the chances of …

Nov 15, 2024
CVE-2024-52519
2.7 LOW

Nextcloud Server is a self hosted personal cloud system. The OAuth2 client secrets were stored in a recoverable way, so that an attacker that got …

Nov 15, 2024
CVE-2024-52516
3.0 LOW

Nextcloud Server is a self hosted personal cloud system. When a server is configured to only allow sharing with users that are in ones own …

Nov 15, 2024
CVE-2024-11247
3.5 LOW

A vulnerability has been found in SourceCodester Online Eyewear Shop 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the …

Nov 15, 2024
CVE-2024-11246
3.5 LOW

A vulnerability, which was classified as problematic, was found in code-projects Farmacia 1.0. Affected is an unknown function of the file /adicionar-cliente.php. The manipulation of …

Nov 15, 2024
CVE-2024-11240
3.5 LOW

A vulnerability was found in IBPhoenix ibWebAdmin up to 1.0.2 and classified as problematic. This issue affects some unknown processing of the file /database.php of …

Nov 15, 2024
CVE-2024-42188
3.7 LOW

HCL Connections is vulnerable to a broken access control vulnerability that may allow an unauthorized user to update data in certain scenarios.

Nov 14, 2024
CVE-2024-9633
3.1 LOW

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.3 before 17.4.2, all versions starting from 17.5 before 17.5.4, all versions …

Nov 14, 2024
CVE-2024-11208
3.7 LOW

A vulnerability was found in Apereo CAS 6.6 and classified as problematic. Affected by this issue is some unknown functionality of the file /login?service. The …

Nov 14, 2024
CVE-2024-10977
3.1 LOW

Client use of server error message in PostgreSQL allows a server not trusted under current SSL or GSS settings to furnish arbitrary non-NUL bytes to …

Nov 14, 2024
CVE-2024-45099
3.1 LOW

IBM Security ReaQta 3.12 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus …

Nov 14, 2024
CVE-2024-38660
3.8 LOW

Protection mechanism failure in the SPP for some Intel(R) Xeon(R) processor family (E-Core) may allow an authenticated user to potentially enable escalation of privilege via …

Nov 13, 2024
CVE-2024-33611
3.4 LOW

Improper input validation for some Intel(R) PROSet/Wireless WiFi software for Windows before version 23.60 may allow a privileged user to potentially enable denial of service …

Nov 13, 2024
CVE-2024-32667
3.9 LOW

Out-of-bounds read for some OpenCL(TM) software may allow an authenticated user to potentially enable denial of service via local access.

Nov 13, 2024
CVE-2024-32485
3.9 LOW

Improper Input Validation in some Intel(R) VROC software before version 8.6.0.2003 may allow an authenticated user to potentially enable denial of service via local access.

Nov 13, 2024
CVE-2024-28051
2.2 LOW

Out-of-bounds read in some Intel(R) VPL software before version 24.1.4 may allow an authenticated user to potentially enable information disclosure via local access.

Nov 13, 2024
CVE-2024-28030
2.2 LOW

NULL pointer dereference in some Intel(R) VPL software before version 24.1.4 may allow an authenticated user to potentially enable denial of service via local access.

Nov 13, 2024
CVE-2024-25565
3.8 LOW

Insufficient control flow management in UEFI firmware for some Intel(R) Xeon(R) Processors may allow an authenticated user to enable denial of service via local access.

Nov 13, 2024
CVE-2024-25563
3.4 LOW

Improper initialization in firmware for some Intel(R) PROSet/Wireless Software and Intel(R) Killer(TM) Wi-Fi before version 23.40 may allow a privileged user to potentially enable information …

Nov 13, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.