CVE Database

4634+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-11175
3.5 LOW

A vulnerability was found in Public CMS 5.202406.d and classified as problematic. This issue affects some unknown processing of the file /admin/cmsVote/save of the component …

Nov 13, 2024
CVE-2024-11168
3.7 LOW

The urllib.parse.urlsplit() and urlparse() functions improperly validated bracketed hosts (`[]`), allowing hosts that weren't IPv6 or IPvFuture. This behavior was not conformant to RFC 3986 …

Nov 12, 2024
CVE-2024-35274
2.3 LOW

An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiAnalyzer versions below 7.4.2, Fortinet FortiManager versions below 7.4.2 …

Nov 12, 2024
CVE-2024-11138
2.7 LOW

A vulnerability classified as problematic has been found in DedeCMS 5.7.116. This affects an unknown part of the file /dede/uploads/dede/friendlink_add.php. The manipulation of the argument …

Nov 12, 2024
CVE-2024-51749
3.5 LOW

Element is a Matrix web client built using the Matrix React SDK. Versions of Element Web and Desktop earlier than 1.11.85 do not check if …

Nov 12, 2024
CVE-2024-11130
2.4 LOW

A vulnerability was found in ZZCMS up to 2023. It has been rated as problematic. Affected by this issue is some unknown functionality of the …

Nov 12, 2024
CVE-2024-11126
3.1 LOW

A vulnerability was found in Digistar AG-30 Plus 2.6b. It has been classified as problematic. Affected is an unknown function of the component Login Page. …

Nov 12, 2024
CVE-2024-50560
3.1 LOW

A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V8.2), SCALANCE …

Nov 12, 2024
CVE-2024-47799
3.5 LOW

Exposure of sensitive system information to an unauthorized control sphere issue exists in Mesh Wi-Fi router RP562B firmware version v1.0.2 and earlier. If this vulnerability …

Nov 12, 2024
CVE-2024-48838
3.3 LOW

Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) a Files or Directories Accessible to External Parties vulnerability. A low privileged attacker with local …

Nov 12, 2024
CVE-2024-11102
3.5 LOW

A vulnerability was found in SourceCodester Hospital Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of …

Nov 12, 2024
CVE-2024-10672
2.7 LOW

The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the mpg_upsert_project_source_block() …

Nov 12, 2024
CVE-2024-11097
3.3 LOW

A vulnerability has been found in SourceCodester Student Record Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the component Main …

Nov 12, 2024
CVE-2024-47587
3.5 LOW

Cash Operations does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges causing low impact to confidentiality to the application.

Nov 12, 2024
CVE-2024-11078
3.5 LOW

A vulnerability has been found in code-projects Job Recruitment 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file …

Nov 11, 2024
CVE-2024-10917
3.7 LOW

In Eclipse OpenJ9 versions up to 0.47, the JNI function GetStringUTFLength may return an incorrect value which has wrapped around. From 0.48 the value is …

Nov 11, 2024
CVE-2024-11070
3.5 LOW

A vulnerability, which was classified as problematic, has been found in Sanluan PublicCMS 5.202406.d. This issue affects some unknown processing of the file /admin/cmsTagType/save of …

Nov 11, 2024
CVE-2024-34015
3.3 LOW

Sensitive information disclosure during file browsing due to improper symbolic link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) …

Nov 11, 2024
CVE-2024-43427
3.7 LOW

A flaw was found in moodle. When creating an export of site administration presets, some sensitive secrets and keys are not being excluded from the …

Nov 11, 2024
CVE-2020-10368
3.5 LOW

Certain Cypress (and Broadcom) Wireless Combo chips, when a January 2021 firmware update is not present, allow memory read access via a "Spectra" attack.

Nov 10, 2024
CVE-2024-11050
3.5 LOW

A vulnerability was found in AMTT Hotel Broadband Operation System up to 3.0.3.151204 and classified as problematic. This issue affects some unknown processing of the …

Nov 10, 2024
CVE-2024-11049
3.7 LOW

A vulnerability classified as problematic has been found in ZKTeco ZKBio Time 9.0.1. Affected is an unknown function of the file /auth_files/photo/ of the component …

Nov 10, 2024
CVE-2024-42000
2.7 LOW

Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 and 10.0.x <= 10.0.0 fail to properly authorize the requests to /api/v4/channels which allows …

Nov 9, 2024
CVE-2024-36250
3.1 LOW

Mattermost versions 9.11.x <= 9.11.2, and 9.5.x <= 9.5.10 fail to protect the mfa code against replay attacks, which allows an attacker to reuse the …

Nov 9, 2024
CVE-2024-11026
3.7 LOW

A vulnerability was found in Intelligent Apps Freenow App 12.10.0 on Android. It has been rated as problematic. Affected by this issue is some unknown …

Nov 8, 2024
CVE-2024-47190
2.7 LOW

Northern.tech Hosted Mender before 2024.07.11 allows SSRF.

Nov 8, 2024
CVE-2024-50211
3.3 LOW

In the Linux kernel, the following vulnerability has been resolved: udf: refactor inode_bmap() to handle error Refactor inode_bmap() to handle error since udf_next_aext() can return …

Nov 8, 2024
CVE-2024-48011
3.1 LOW

Dell PowerProtect DD, versions prior to 7.7.5.50, contains an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. A low privileged attacker with remote access …

Nov 8, 2024
CVE-2024-51993
3.4 LOW

Combodo iTop is a web based IT Service Management tool. An attacker accessing a backup file or the database can read some passwords for misconfigured …

Nov 7, 2024
CVE-2024-30142
3.8 LOW

HCL BigFix Compliance is affected by a missing secure flag on a cookie. If a secure flag is not set, cookies may be stolen by …

Nov 7, 2024
CVE-2024-10928
3.5 LOW

A vulnerability was found in MonoCMS up to 20240528. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the …

Nov 6, 2024
CVE-2024-10927
3.5 LOW

A vulnerability was found in MonoCMS up to 20240528. It has been classified as problematic. Affected is an unknown function of the file /monofiles/account.php of …

Nov 6, 2024
CVE-2024-50345
3.1 LOW

symfony/http-foundation is a module for the Symphony PHP framework which defines an object-oriented layer for the HTTP specification. The `Request` class, does not parse URI …

Nov 6, 2024
CVE-2024-50343
3.1 LOW

symfony/validator is a module for the Symphony PHP framework which provides tools to validate values. It is possible to trick a `Validator` configured with a …

Nov 6, 2024
CVE-2024-50342
3.1 LOW

symfony/http-client is a module for the Symphony PHP framework which provides powerful methods to fetch HTTP resources synchronously or asynchronously. When using the `NoPrivateNetworkHttpClient`, some …

Nov 6, 2024
CVE-2024-50341
3.1 LOW

symfony/security-bundle is a module for the Symphony PHP framework which provides a tight integration of the Security component into the Symfony full-stack framework. The custom …

Nov 6, 2024
CVE-2024-10926
3.5 LOW

A vulnerability was found in IBPhoenix ibWebAdmin up to 1.0.2 and classified as problematic. This issue affects some unknown processing of the file /toggle_fold_panel.php of …

Nov 6, 2024
CVE-2024-51755
2.2 LOW

Twig is a template language for PHP. In a sandbox, an attacker can access attributes of Array-like objects as they were not checked by the …

Nov 6, 2024
CVE-2024-51754
2.2 LOW

Twig is a template language for PHP. In a sandbox, an attacker can call `__toString()` on an object even if the `__toString()` method is not …

Nov 6, 2024
CVE-2024-20528
3.8 LOW

A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to upload files to arbitrary locations on the underlying operating system …

Nov 6, 2024
CVE-2024-10920
3.1 LOW

A vulnerability was found in mariazevedo88 travels-java-api up to 5.0.1 and classified as problematic. Affected by this issue is the function doFilterInternal of the file …

Nov 6, 2024
CVE-2024-34682
2.4 LOW

Improper authorization in Settings prior to SMR Nov-2024 Release 1 allows physical attackers to access stored WiFi password in Maintenance Mode.

Nov 6, 2024
CVE-2024-34675
2.4 LOW

Improper access control in Dex Mode prior to SMR Nov-2024 Release 1 allows physical attackers to temporarily access to unlocked screen.

Nov 6, 2024
CVE-2024-50092
3.3 LOW

In the Linux kernel, the following vulnerability has been resolved: net: netconsole: fix wrong warning A warning is triggered when there is insufficient space in …

Nov 5, 2024
CVE-2024-10842
2.4 LOW

A vulnerability, which was classified as problematic, has been found in romadebrian WEB-Sekolah 1.0. Affected by this issue is some unknown functionality of the file …

Nov 5, 2024
CVE-2024-10840
2.4 LOW

A vulnerability classified as problematic has been found in romadebrian WEB-Sekolah 1.0. Affected is an unknown function of the file /Admin/akun_edit.php of the component Backend. …

Nov 5, 2024
CVE-2024-47402
3.3 LOW

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause DOS through out-of-bounds read.

Nov 5, 2024
CVE-2024-10807
2.4 LOW

A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been rated as problematic. This issue affects some unknown processing of the file …

Nov 5, 2024
CVE-2024-10806
2.4 LOW

A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been declared as problematic. This vulnerability affects unknown code of the file betweendates-detailsreports.php. …

Nov 5, 2024
CVE-2024-51744
3.1 LOW

golang-jwt is a Go implementation of JSON Web Tokens. Unclear documentation of the error behavior in `ParseWithClaims` can lead to situation where users are potentially …

Nov 4, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.