CVE Database

46542+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-47894
7.1 HIGH

Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to read data outside the Guest's virtualised GPU …

Jan 13, 2025
CVE-2024-12274
7.5 HIGH

The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.1.23 export settings functionality exports data to a public folder, with an easily guessable …

Jan 13, 2025
CVE-2025-0412
7.8 HIGH

Luxion KeyShot Viewer KSP File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Jan 13, 2025
CVE-2025-0396
7.8 HIGH

A vulnerability, which was classified as critical, has been found in exelban stats up to 2.11.21. This issue affects the function shouldAcceptNewConnection of the component …

Jan 12, 2025
CVE-2024-57876
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/dp_mst: Fix resetting msg rx state after topology removal If the MST topology is removed …

Jan 11, 2025
CVE-2024-57850
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: jffs2: Prevent rtime decompress memory corruption The rtime decompression routine does not fully check bounds …

Jan 11, 2025
CVE-2024-57849
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: s390/cpum_sf: Handle CPU hotplug remove during sampling CPU hotplug remove handling triggers the following function …

Jan 11, 2025
CVE-2024-57838
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: s390/entry: Mark IRQ entries to fix stack depot warnings The stack depot filters out everything …

Jan 11, 2025
CVE-2024-57798
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/dp_mst: Ensure mst_primary pointer is valid in drm_dp_mst_handle_up_req() While receiving an MST up request message …

Jan 11, 2025
CVE-2024-57792
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: power: supply: gpio-charger: Fix set charge current limits Fix set charge current limits for devices …

Jan 11, 2025
CVE-2024-57791
7.5 HIGH

In the Linux kernel, the following vulnerability has been resolved: net/smc: check return value of sock_recvmsg when draining clc data When receiving clc msg, the …

Jan 11, 2025
CVE-2024-52332
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: igb: Fix potential invalid memory access in igb_init_module() The pci_register_driver() can fail and when this …

Jan 11, 2025
CVE-2024-52319
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: mm: use aligned address in clear_gigantic_page() In current kernel, hugetlb_no_page() calls folio_zero_user() with the fault …

Jan 11, 2025
CVE-2024-51729
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: mm: use aligned address in copy_user_gigantic_page() In current kernel, hugetlb_wp() calls copy_user_large_folio() with the fault …

Jan 11, 2025
CVE-2024-50051
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: spi: mpc52xx: Add cancel_work_sync before module remove If we remove the module which will call …

Jan 11, 2025
CVE-2024-41935
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to shrink read extent node in batches We use rwlock to protect core …

Jan 11, 2025
CVE-2024-41149
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: block: avoid to reuse `hctx` not removed from cpuhp callback list If the 'hctx' isn't …

Jan 11, 2025
CVE-2025-0103
8.8 HIGH

An SQL injection vulnerability in Palo Alto Networks Expedition enables an authenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, …

Jan 11, 2025
CVE-2024-42169
7.1 HIGH

HCL MyXalytics is affected by insecure direct object references. It occurs due to missing access control checks, which fail to verify whether a user should …

Jan 11, 2025
CVE-2024-42168
8.9 HIGH

HCL MyXalytics is affected by out-of-band resource load (HTTP) vulnerability. An attacker can deploy a web server that returns malicious content, and then induce the …

Jan 11, 2025
CVE-2024-12627
7.5 HIGH

The Coupon X: Discount Pop Up, Promo Code Pop Ups, Announcement Pop Up, WooCommerce Popups plugin for WordPress is vulnerable to PHP Object Injection in …

Jan 11, 2025
CVE-2024-12404
7.5 HIGH

The CF Internal Link Shortcode plugin for WordPress is vulnerable to SQL Injection via the 'post_title' parameter in all versions up to, and including, 1.1.0 …

Jan 11, 2025
CVE-2024-9188
8.8 HIGH

Specially constructed queries cause cross platform scripting leaking administrator tokens

Jan 10, 2025
CVE-2024-9134
8.3 HIGH

Multiple SQL Injection vulnerabilities exist in the reporting application. A user with advanced report application access rights can exploit the SQL injection, allowing them to …

Jan 10, 2025
CVE-2024-9132
8.1 HIGH

The administrator is able to configure an insecure captive portal script

Jan 10, 2025
CVE-2024-9131
7.2 HIGH

A user with administrator privileges can perform command injection

Jan 10, 2025
CVE-2024-47520
7.6 HIGH

A user with advanced report application access rights can perform actions for which they are not authorized

Jan 10, 2025
CVE-2024-47519
8.3 HIGH

Backup uploads to ETM subject to man-in-the-middle interception

Jan 10, 2025
CVE-2024-54996
8.8 HIGH

MonicaHQ v4.1.2 was discovered to contain multiple authenticated Client-Side Injection vulnerabilities via the title and description parameters at /people/ID/reminders/create.

Jan 10, 2025
CVE-2024-57228
8.0 HIGH

Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the iface parameter in the vif_disable function.

Jan 10, 2025
CVE-2024-57227
8.0 HIGH

Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pbc_wps function.

Jan 10, 2025
CVE-2024-57226
8.0 HIGH

Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the iface parameter in the vif_enable function.

Jan 10, 2025
CVE-2024-57211
8.0 HIGH

TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the modifyOne parameter in the enable_wsh function.

Jan 10, 2025
CVE-2024-54848
7.4 HIGH

Improper handling and storage of certificates in CP Plus CP-VNR-3104 B3223P22C02424 allow attackers to decrypt communications or execute a man-in-the-middle attacks.

Jan 10, 2025
CVE-2025-22598
8.3 HIGH

WeGIA is a web manager for charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the cadastrarSocio.php endpoint of the WeGIA application. This …

Jan 10, 2025
CVE-2025-22597
8.3 HIGH

WeGIA is a web manager for charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the CobrancaController.php endpoint of the WeGIA application. This …

Jan 10, 2025
CVE-2024-46210
7.2 HIGH

An arbitrary file upload vulnerability in the MediaPool module of Redaxo CMS v5.17.1 allows attackers to execute arbitrary code via uploading a crafted file.

Jan 10, 2025
CVE-2024-25371
7.5 HIGH

Gramine before a390e33e16ed374a40de2344562a937f289be2e1 suffers from an Interface vulnerability due to mismatching SW signals vs HW exceptions.

Jan 10, 2025
CVE-2025-21380
8.8 HIGH

Improper access control in Azure SaaS Resources allows an authorized attacker to disclose information over a network.

Jan 9, 2025
CVE-2025-21385
8.8 HIGH

A Server-Side Request Forgery (SSRF) vulnerability in Microsoft Purview allows an authorized attacker to disclose information over a network.

Jan 9, 2025
CVE-2024-51229
8.8 HIGH

Cross Site Scripting vulnerability in LinZhaoguan pb-cms v.2.0 allows a remote attacker to execute arbitrary code via the theme management function.

Jan 9, 2025
CVE-2024-46464
7.8 HIGH

In PRIMX ZED Enterprise up to 2024.3, technical files stored in local folders with common user access can be manipulated to render the host computer …

Jan 9, 2025
CVE-2024-13311
7.3 HIGH

Vulnerability in Drupal Allow All File Extensions for file fields.This issue affects Allow All File Extensions for file fields: *.*.

Jan 9, 2025
CVE-2024-13291
7.3 HIGH

Incorrect Authorization vulnerability in Drupal Basic HTTP Authentication allows Forceful Browsing.This issue affects Basic HTTP Authentication: from 7.X-1.0 before 7.X-1.4.

Jan 9, 2025
CVE-2024-56113
7.5 HIGH

Smart Toilet Lab - Motius 1.3.11 is running with debug mode turned on (DEBUG = True) and exposing sensitive information defined in Django settings file …

Jan 9, 2025
CVE-2024-54887
8.0 HIGH

TP-Link TL-WR940N V3 and V4 with firmware 3.16.9 and earlier contain a buffer overflow via the dnsserver1 and dnsserver2 parameters at /userRpm/Wan6to4TunnelCfgRpm.htm. This vulnerability allows …

Jan 9, 2025
CVE-2024-13284
8.8 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Drupal Gutenberg allows Cross Site Request Forgery.This issue affects Gutenberg: from 0.0.0 before 2.13.0, from 3.0.0 before 3.0.5.

Jan 9, 2025
CVE-2024-13282
8.8 HIGH

Incorrect Authorization vulnerability in Drupal Block permissions allows Forceful Browsing.This issue affects Block permissions: from 1.0.0 before 1.2.0.

Jan 9, 2025
CVE-2024-13276
7.5 HIGH

Insertion of Sensitive Information Into Sent Data vulnerability in Drupal File Entity (fieldable files) allows Forceful Browsing.This issue affects File Entity (fieldable files): from 7.X-* …

Jan 9, 2025
CVE-2024-13267
7.5 HIGH

Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno TinCan Question Type allows PHP Local File Inclusion.This issue affects …

Jan 9, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.