CVE Database

46542+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-48457
7.5 HIGH

An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi 11AC Router NC63 3.0.0.3327 and …

Jan 6, 2025
CVE-2024-48456
7.5 HIGH

An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi 11AC Router NC63 3.0.0.3327 and …

Jan 6, 2025
CVE-2024-46981
7.0 HIGH

Redis is an open source, in-memory database that persists on disk. An authenticated user may use a specially crafted Lua script to manipulate the garbage …

Jan 6, 2025
CVE-2021-27285
8.4 HIGH

An issue was discovered in Inspur ClusterEngine v4.0 that allows attackers to gain escalated Local privileges and execute arbitrary commands via /opt/tsce4/torque6/bin/getJobsByShell.

Jan 6, 2025
CVE-2024-55076
8.1 HIGH

Grocy through 4.3.0 has no CSRF protection, as demonstrated by changing the Administrator's password.

Jan 6, 2025
CVE-2024-55074
8.8 HIGH

The edit profile function of Grocy through 4.3.0 allows stored XSS and resultant privilege escalation by uploading a crafted HTML or SVG file, a different …

Jan 6, 2025
CVE-2024-55407
7.8 HIGH

An issue in the DeviceloControl function of ITE Tech. Inc ITE IO Access v1.0.0.0 allows attackers to perform arbitrary port read and write actions via …

Jan 6, 2025
CVE-2024-55629
7.5 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.8, TCP streams with TCP urgent data (out …

Jan 6, 2025
CVE-2024-55628
7.5 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.8, DNS resource name compression can lead …

Jan 6, 2025
CVE-2025-21618
7.5 HIGH

NiceGUI is an easy-to-use, Python-based UI framework. Prior to 2.9.1, authenticating with NiceGUI logged in the user for all browsers, including browsers in incognito mode. …

Jan 6, 2025
CVE-2025-21614
7.5 HIGH

go-git is a highly extensible git implementation library written in pure Go. A denial of service (DoS) vulnerability was discovered in go-git versions prior to …

Jan 6, 2025
CVE-2024-56766
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: mtd: rawnand: fix double free in atmel_pmecc_create_user() The "user" pointer was converted from being allocated …

Jan 6, 2025
CVE-2024-56765
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: powerpc/pseries/vas: Add close() callback in vas_vm_ops struct The mapping VMA address is saved in VAS …

Jan 6, 2025
CVE-2024-56764
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ublk: detach gendisk from ublk device if add_disk() fails Inside ublk_abort_requests(), gendisk is grabbed for …

Jan 6, 2025
CVE-2024-56759
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix use-after-free when COWing tree bock and tracing is enabled When a COWing a …

Jan 6, 2025
CVE-2024-55605
7.5 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.8, a large input buffer to the to_lowercase, …

Jan 6, 2025
CVE-2023-6605
7.2 HIGH

A flaw was found in FFmpeg's DASH playlist support. This vulnerability allows arbitrary HTTP GET requests to be made on behalf of the machine running …

Jan 6, 2025
CVE-2025-21612
8.6 HIGH

TabberNeue is a MediaWiki extension that allows the wiki to create tabs. Prior to 2.7.2, TabberTransclude.php doesn't escape the user-supplied page name when outputting, so …

Jan 6, 2025
CVE-2025-21611
8.8 HIGH

tgstation-server is a production scale tool for BYOND server management. Prior to 6.12.3, roles used to authorize API methods were incorrectly OR'd instead of AND'ed …

Jan 6, 2025
CVE-2024-8474
7.5 HIGH

OpenVPN Connect before version 3.5.0 can contain the configuration profile's clear-text private key which is logged in the application log, which an unauthorized actor can …

Jan 6, 2025
CVE-2024-45558
7.5 HIGH

Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE …

Jan 6, 2025
CVE-2024-45555
8.4 HIGH

Memory corruption can occur if an already verified IFS2 image is overwritten, bypassing boot verification. This allows unauthorized programs to be injected into security-sensitive images, …

Jan 6, 2025
CVE-2024-45553
7.8 HIGH

Memory corruption can occur when process-specific maps are added to the global list. If a map is removed from the global list while another thread …

Jan 6, 2025
CVE-2024-45550
7.8 HIGH

Memory corruption occurs when invoking any IOCTL-calling application that executes all MCDM driver IOCTL calls.

Jan 6, 2025
CVE-2024-45548
7.8 HIGH

Memory corruption while processing FIPS encryption or decryption validation functionality IOCTL call.

Jan 6, 2025
CVE-2024-45547
7.8 HIGH

Memory corruption while processing IOCTL call invoked from user-space to verify non extension FIPS encryption and decryption functionality.

Jan 6, 2025
CVE-2024-45546
7.8 HIGH

Memory corruption while processing FIPS encryption or decryption IOCTL call invoked from user-space.

Jan 6, 2025
CVE-2024-45542
7.8 HIGH

Memory corruption when IOCTL call is invoked from user-space to write board data to WLAN driver.

Jan 6, 2025
CVE-2024-45541
7.8 HIGH

Memory corruption when IOCTL call is invoked from user-space to read board data.

Jan 6, 2025
CVE-2024-43064
7.5 HIGH

Uncontrolled resource consumption when a driver, an application or a SMMU client tries to access the global registers through SMMU.

Jan 6, 2025
CVE-2024-21464
8.4 HIGH

Memory corruption while processing IPA statistics, when there are no active clients registered.

Jan 6, 2025
CVE-2024-20154
8.8 HIGH

In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution, if a …

Jan 6, 2025
CVE-2024-20153
7.5 HIGH

In wlan STA, there is a possible way to trick a client to connect to an AP with spoofed SSID. This could lead to remote …

Jan 6, 2025
CVE-2024-20150
7.5 HIGH

In Modem, there is a possible system crash due to a logic error. This could lead to remote denial of service with no additional execution …

Jan 6, 2025
CVE-2024-20149
7.5 HIGH

In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution …

Jan 6, 2025
CVE-2024-20146
8.1 HIGH

In wlan STA driver, there is a possible out of bounds write due to improper input validation. This could lead to remote (proximal/adjacent) code execution …

Jan 6, 2025
CVE-2025-0233
7.3 HIGH

A vulnerability was found in Codezips Project Management System 1.0. It has been classified as critical. This affects an unknown part of the file /pages/forms/course.php. …

Jan 5, 2025
CVE-2024-41767
7.3 HIGH

IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could …

Jan 4, 2025
CVE-2024-41766
7.5 HIGH

IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 could allow a remote attacker to cause a denial of service using a complex regular expression.

Jan 4, 2025
CVE-2025-0210
7.3 HIGH

A vulnerability has been found in Campcodes School Faculty Scheduling System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Jan 4, 2025
CVE-2024-10957
8.8 HIGH

The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to PHP Object Injection in all versions from 1.23.8 to 1.24.11 via deserialization …

Jan 4, 2025
CVE-2025-0207
7.3 HIGH

A vulnerability, which was classified as critical, has been found in code-projects Online Shoe Store 1.0. Affected by this issue is some unknown functionality of …

Jan 4, 2025
CVE-2024-10932
8.8 HIGH

The Backup Migration plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.6 via deserialization of untrusted input …

Jan 4, 2025
CVE-2025-22390
7.5 HIGH

An issue was discovered in Optimizely EPiServer.CMS.Core before 12.32.0. A medium-severity vulnerability exists in the CMS due to insufficient enforcement of password complexity requirements. The …

Jan 4, 2025
CVE-2025-22389
8.0 HIGH

An issue was discovered in Optimizely EPiServer.CMS.Core before 12.32.0. A medium-severity vulnerability exists in the CMS, where the application does not properly validate uploaded files. …

Jan 4, 2025
CVE-2025-22387
7.5 HIGH

An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue exists in requests for resources where the session token is submitted as …

Jan 4, 2025
CVE-2025-22386
7.3 HIGH

An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity session issue exists in the Commerce B2B application, affecting the longevity of active …

Jan 4, 2025
CVE-2025-22384
7.5 HIGH

An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue concerning business logic exists in the Commerce B2B application, which allows storefront …

Jan 4, 2025
CVE-2024-11733
7.3 HIGH

The The WordPress Popular Posts plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 7.1.0. This is due …

Jan 3, 2025
CVE-2024-13129
8.8 HIGH

A vulnerability was found in Roxy-WI up to 8.1.3. It has been declared as critical. Affected by this vulnerability is the function action_service of the …

Jan 3, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.