CVE Database

4634+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-10768
3.5 LOW

A vulnerability classified as problematic was found in PHPGurukul Online Shopping Portal 2.0. This vulnerability affects unknown code of the file /admin/assets/plugins/DataTables/media/unit_testing/templates/two_tables.php. The manipulation of …

Nov 4, 2024
CVE-2024-10757
3.5 LOW

A vulnerability, which was classified as problematic, has been found in PHPGurukul Online Shopping Portal 2.0. Affected by this issue is some unknown functionality of …

Nov 4, 2024
CVE-2024-10756
3.5 LOW

A vulnerability classified as problematic was found in PHPGurukul Online Shopping Portal 2.0. Affected by this vulnerability is an unknown functionality of the file /admin/assets/plugins/DataTables/media/unit_testing/templates/html_table.php. …

Nov 4, 2024
CVE-2024-10755
3.5 LOW

A vulnerability classified as problematic has been found in PHPGurukul Online Shopping Portal 2.0. Affected is an unknown function of the file /admin/assets/plugins/DataTables/media/unit_testing/templates/empty_table.php. The manipulation …

Nov 4, 2024
CVE-2024-10754
3.5 LOW

A vulnerability was found in PHPGurukul Online Shopping Portal 2.0. It has been rated as problematic. This issue affects some unknown processing of the file …

Nov 4, 2024
CVE-2024-10753
3.5 LOW

A vulnerability was found in PHPGurukul Online Shopping Portal 2.0. It has been declared as problematic. This vulnerability affects unknown code of the file admin/assets/plugins/DataTables/media/unit_testing/templates/dom_data_two_headers.php. …

Nov 4, 2024
CVE-2024-10748
2.5 LOW

A vulnerability, which was classified as problematic, has been found in Cosmote Greece What's Up App 4.47.3 on Android. This issue affects some unknown processing …

Nov 4, 2024
CVE-2024-10747
3.5 LOW

A vulnerability classified as problematic was found in PHPGurukul Online Shopping Portal 2.0. This vulnerability affects unknown code of the file /admin/assets/plugins/DataTables/media/unit_testing/templates/dom_data_th.php. The manipulation of …

Nov 4, 2024
CVE-2024-10746
3.5 LOW

A vulnerability classified as problematic has been found in PHPGurukul Online Shopping Portal 2.0. This affects an unknown part of the file /admin/assets/plugins/DataTables/media/unit_testing/templates/dom_data.php. The manipulation …

Nov 4, 2024
CVE-2024-10745
3.5 LOW

A vulnerability was found in PHPGurukul Online Shopping Portal 2.0. It has been rated as problematic. Affected by this issue is some unknown functionality of …

Nov 3, 2024
CVE-2024-10744
3.5 LOW

A vulnerability was found in PHPGurukul Online Shopping Portal 2.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of …

Nov 3, 2024
CVE-2024-10743
3.5 LOW

A vulnerability was found in PHPGurukul Online Shopping Portal 2.0. It has been classified as problematic. Affected is an unknown function of the file /shopping/admin/assets/plugins/DataTables/examples/examples_support/editable_ajax.php. …

Nov 3, 2024
CVE-2024-10701
3.5 LOW

A vulnerability was found in PHPGurukul Car Rental Portal 1.0. It has been rated as problematic. This issue affects some unknown processing of the file …

Nov 2, 2024
CVE-2024-7883
3.7 LOW

When using Arm Cortex-M Security Extensions (CMSE), Secure stack contents can be leaked to Non-secure state via floating-point registers when a Secure to Non-secure function …

Oct 31, 2024
CVE-2024-33623
3.7 LOW

A denial of service vulnerability exists in the Web Application functionality of LevelOne WBR-6012 R0.40e6. A specially crafted HTTP request can lead to a reboot. …

Oct 30, 2024
CVE-2024-10503
3.5 LOW

A vulnerability was found in Klokan MapTiler tileserver-gl 2.3.1 and classified as problematic. This issue affects some unknown processing of the component URL Handler. The …

Oct 30, 2024
CVE-2024-10228
3.8 LOW

The Vagrant VMWare Utility Windows installer targeted a custom location with a non-protected path that could be modified by an unprivileged user, introducing potential for …

Oct 29, 2024
CVE-2024-10452
2.2 LOW

Organization admins can delete pending invites created in an organization they are not part of.

Oct 29, 2024
CVE-2024-48921
2.7 LOW

Kyverno is a policy engine designed for Kubernetes. A kyverno ClusterPolicy, ie. "disallow-privileged-containers," can be overridden by the creation of a PolicyException in a random …

Oct 29, 2024
CVE-2024-41156
2.7 LOW

Profile files from TRO600 series radios are extracted in plain-text and encrypted file formats. Profile files provide potential attackers valuable configuration information about the Tropos …

Oct 29, 2024
CVE-2024-10479
2.4 LOW

A vulnerability, which was classified as problematic, was found in LinZhaoguan pb-cms up to 2.0.1. Affected is an unknown function of the file /admin#themes of …

Oct 29, 2024
CVE-2024-10478
2.4 LOW

A vulnerability, which was classified as problematic, has been found in LinZhaoguan pb-cms up to 2.0.1. This issue affects some unknown processing of the file …

Oct 29, 2024
CVE-2024-10477
2.4 LOW

A vulnerability classified as problematic was found in LinZhaoguan pb-cms up to 2.0.1. This vulnerability affects unknown code of the file /admin#permissions of the component …

Oct 29, 2024
CVE-2024-30106
3.5 LOW

HCL Connections is vulnerable to an information disclosure vulnerability, due to an IBM WebSphere Application Server error, which could allow a user to obtain sensitive …

Oct 28, 2024
CVE-2024-44265
2.4 LOW

The issue was addressed by restricting options offered on a locked device. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura …

Oct 28, 2024
CVE-2024-44251
2.4 LOW

This issue was addressed through improved state management. This issue is fixed in iOS 18.1 and iPadOS 18.1. An attacker may be able to view …

Oct 28, 2024
CVE-2024-44222
3.3 LOW

This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. An …

Oct 28, 2024
CVE-2024-44123
2.3 LOW

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. A malicious app with …

Oct 28, 2024
CVE-2024-40853
3.3 LOW

This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18 and iPadOS 18. An attacker may …

Oct 28, 2024
CVE-2024-40851
2.4 LOW

This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.1 and iPadOS 18.1. An attacker with …

Oct 28, 2024
CVE-2024-40792
3.3 LOW

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. A malicious app may be able to change network …

Oct 28, 2024
CVE-2024-27849
3.3 LOW

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15. An app may be …

Oct 28, 2024
CVE-2024-49755
3.1 LOW

Duende IdentityServer is an OpenID Connect and OAuth 2.x framework for ASP.NET Core. IdentityServer's local API authentication handler performs insufficient validation of the cnf claim …

Oct 28, 2024
CVE-2024-10214
3.5 LOW

Mattermost versions 9.11.X <= 9.11.1, 9.5.x <= 9.5.9 icorrectly issues two sessions when using desktop SSO - one in the browser and one in desktop …

Oct 28, 2024
CVE-2024-8013
2.2 LOW

A bug in query analysis of certain complex self-referential $lookup subpipelines may result in literal values in expressions for encrypted fields to be sent to …

Oct 28, 2024
CVE-2024-23843
2.2 LOW

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Genians Genian NAC V5.0, Genians Genian NAC LTS V5.0.This issue affects …

Oct 28, 2024
CVE-2024-10433
3.5 LOW

A vulnerability was found in Project Worlds Simple Web-Based Chat Application 1.0 and classified as problematic. Affected by this issue is some unknown functionality of …

Oct 28, 2024
CVE-2024-50610
3.6 LOW

GSL (GNU Scientific Library) through 2.8 has an integer signedness error in gsl_siman_solve_many in siman/siman.c. When params.n_tries is negative, incorrect memory allocation occurs.

Oct 27, 2024
CVE-2024-10419
3.5 LOW

A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality …

Oct 27, 2024
CVE-2024-10414
2.4 LOW

A vulnerability, which was classified as problematic, was found in PHPGurukul Vehicle Record System 1.0. This affects an unknown part of the file /admin/edit-brand.php. The …

Oct 27, 2024
CVE-2024-10412
3.5 LOW

A vulnerability was found in Poco-z Guns-Medical 1.0. It has been declared as problematic. Affected by this vulnerability is the function upload of the file …

Oct 27, 2024
CVE-2024-47483
2.9 LOW

Dell Data Lakehouse, version(s) 1.0.0.0 and 1.1.0.0, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. An unauthenticated attacker …

Oct 25, 2024
CVE-2024-10348
3.5 LOW

A vulnerability was found in SourceCodester Best House Rental Management System 1.0. It has been classified as problematic. This affects an unknown part of the …

Oct 24, 2024
CVE-2023-50355
3.6 LOW

HCL Sametime is impacted by the error messages containing sensitive information. An attacker can use this information to launch another, more focused attack.

Oct 23, 2024
CVE-2024-10276
3.5 LOW

A vulnerability has been found in Telestream Sentry 6.0.9 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /?page=reports …

Oct 23, 2024
CVE-2024-43173
3.7 LOW

IBM Concert 1.0.0 and 1.0.1 vulnerable to attacks that rely on the use of cookies without the SameSite attribute.

Oct 22, 2024
CVE-2024-50057
3.3 LOW

In the Linux kernel, the following vulnerability has been resolved: usb: typec: tipd: Free IRQ only if it was requested before In polling mode, if …

Oct 21, 2024
CVE-2024-50044
3.3 LOW

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: FIX possible deadlock in rfcomm_sk_state_change rfcomm_sk_state_change attempts to use sock_lock so it must …

Oct 21, 2024
CVE-2024-47738
3.3 LOW

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: don't use rate mask for offchannel TX either Like the commit ab9177d83c04 ("wifi: …

Oct 21, 2024
CVE-2024-10199
2.4 LOW

A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of …

Oct 21, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.