CVE Database

46542+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-13044
7.8 HIGH

Ashlar-Vellum Cobalt AR File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum …

Dec 30, 2024
CVE-2024-13043
7.8 HIGH

Panda Security Dome Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Panda Security Dome. An …

Dec 30, 2024
CVE-2024-12753
7.3 HIGH

Foxit PDF Reader Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Foxit PDF Reader. An …

Dec 30, 2024
CVE-2024-12752
7.8 HIGH

Foxit PDF Reader AcroForm Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF …

Dec 30, 2024
CVE-2024-12751
7.8 HIGH

Foxit PDF Reader AcroForm Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF …

Dec 30, 2024
CVE-2024-11944
8.8 HIGH

iXsystems TrueNAS CORE tarfile.extractall Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of iXsystems TrueNAS …

Dec 30, 2024
CVE-2024-56800
7.4 HIGH

Firecrawl is a web scraper that allows users to extract the content of a webpage for a large language model. Versions prior to 1.1.1 contain …

Dec 30, 2024
CVE-2024-12836
7.8 HIGH

Delta Electronics DRASimuCAD STP File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Dec 30, 2024
CVE-2024-12835
7.8 HIGH

Delta Electronics DRASimuCAD ICS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Dec 30, 2024
CVE-2024-12834
7.8 HIGH

Delta Electronics DRASimuCAD STP File Parsing Type Confusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Dec 30, 2024
CVE-2024-12828
8.8 HIGH

Webmin CGI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Webmin. Authentication is required …

Dec 30, 2024
CVE-2024-54181
7.2 HIGH

IBM WebSphere Automation 1.7.5 could allow a remote privileged user, who has authorized access to the swagger UI, to execute arbitrary code. Using specially crafted …

Dec 30, 2024
CVE-2024-47925
7.5 HIGH

Tecnick TCExam – Multiple CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Dec 30, 2024
CVE-2024-47924
7.5 HIGH

Boa web server – CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Dec 30, 2024
CVE-2024-47922
7.5 HIGH

Priority – CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Dec 30, 2024
CVE-2024-47921
8.4 HIGH

Smadar SPS – CWE-327: Use of a Broken or Risky Cryptographic Algorithm

Dec 30, 2024
CVE-2024-47920
7.5 HIGH

Tiki Wiki CMS – CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Dec 30, 2024
CVE-2024-47917
7.5 HIGH

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Dec 30, 2024
CVE-2024-22063
7.6 HIGH

The ZENIC ONE R58 products by ZTE Corporation have a command injection vulnerability. An authenticated attacker can exploit this vulnerability to tamper with messages, inject …

Dec 30, 2024
CVE-2024-13038
7.3 HIGH

A vulnerability was found in CodeAstro Simple Loan Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Dec 30, 2024
CVE-2024-13030
7.3 HIGH

A vulnerability was found in D-Link DIR-823G 1.0.2B05_20181207. It has been rated as critical. This issue affects the function SetAutoRebootSettings/SetClientInfo/SetDMZSettings/SetFirewallSettings/SetParentsControlInfo/SetQoSSettings/SetVirtualServerSettings of the file /HNAP1/ of …

Dec 30, 2024
CVE-2024-56740
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: nfs/localio: must clear res.replen in nfs_local_read_done Otherwise memory corruption can occur due to NFSv3 LOCALIO …

Dec 29, 2024
CVE-2024-56721
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: x86/CPU/AMD: Terminate the erratum_1386_microcode array The erratum_1386_microcode array requires an empty entry at the end. …

Dec 29, 2024
CVE-2024-13006
7.3 HIGH

A vulnerability, which was classified as critical, has been found in 1000 Projects Human Resource Management System 1.0. This issue affects some unknown processing of …

Dec 29, 2024
CVE-2024-56737
8.8 HIGH

GNU GRUB (aka GRUB2) through 2.12 has a heap-based buffer overflow in fs/hfs.c via crafted sblock data in an HFS filesystem.

Dec 29, 2024
CVE-2024-13004
7.3 HIGH

A vulnerability classified as critical has been found in PHPGurukul Complaint Management System 1.0. This affects an unknown part of the file /admin/category.php. The manipulation …

Dec 29, 2024
CVE-2018-25107
7.5 HIGH

The Crypt::Random::Source package before 0.13 for Perl has a fallback to the built-in rand() function, which is not a secure source of random bits.

Dec 29, 2024
CVE-2024-13002
7.3 HIGH

A vulnerability was found in 1000 Projects Bookstore Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Dec 29, 2024
CVE-2024-56708
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: EDAC/igen6: Avoid segmentation fault on module unload The segmentation fault happens because: During modprobe: 1. …

Dec 28, 2024
CVE-2024-56704
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: 9p/xen: fix release of IRQ Kernel logs indicate an IRQ was double-freed. Pass correct device …

Dec 28, 2024
CVE-2024-56699
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: s390/pci: Fix potential double remove of hotplug slot In commit 6ee600bfbe0f ("s390/pci: remove hotplug slot …

Dec 28, 2024
CVE-2024-56695
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Use dynamic allocation for CU occupancy array in 'kfd_get_cu_occupancy()' The `kfd_get_cu_occupancy` function previously declared …

Dec 28, 2024
CVE-2024-56693
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: brd: defer automatic disk creation until module initialization succeeds My colleague Wupeng found the following …

Dec 28, 2024
CVE-2024-56684
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: mailbox: mtk-cmdq: fix wrong use of sizeof in cmdq_get_clocks() It should be size of the …

Dec 28, 2024
CVE-2024-56678
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: powerpc/mm/fault: Fix kfence page fault reporting copy_from_kernel_nofault() can be called when doing read of /proc/kcore. …

Dec 28, 2024
CVE-2023-7266
7.5 HIGH

Some Huawei home routers have a connection hijacking vulnerability. Successful exploitation of this vulnerability may cause DoS or information leakage.(Vulnerability ID:HWPSIRT-2023-76605) This vulnerability has been …

Dec 28, 2024
CVE-2023-7263
7.3 HIGH

Some Huawei home music system products have a path traversal vulnerability. Successful exploitation of this vulnerability may cause unauthorized file deletion or file permission change.(Vulnerability …

Dec 28, 2024
CVE-2021-37000
7.7 HIGH

Some Huawei wearables have a permission management vulnerability.

Dec 28, 2024
CVE-2021-22484
7.5 HIGH

Some Huawei wearables have a vulnerability of not verifying the actual data size when reading data. Successful exploitation of this vulnerability may cause a server …

Dec 28, 2024
CVE-2024-46973
7.8 HIGH

Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger use-after-free kernel exceptions.

Dec 28, 2024
CVE-2024-46972
7.8 HIGH

Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger use-after-free kernel exceptions.

Dec 28, 2024
CVE-2024-43705
7.8 HIGH

Software installed and run as a non-privileged user can trigger the GPU kernel driver to write to arbitrary read-only system files that have been mapped …

Dec 28, 2024
CVE-2024-50714
7.5 HIGH

A Server-Side Request Forgery (SSRF) in smarts-srl.com Smart Agent v.1.1.0 allows a remote attacker to obtain sensitive information via a crafted script to the /FB/getFbVideoSource.php …

Dec 27, 2024
CVE-2024-50715
7.5 HIGH

An issue in smarts-srl.com Smart Agent v.1.1.0 allows a remote attacker to obtain sensitive information via command injection through a vulnerable unsanitized parameter defined in …

Dec 27, 2024
CVE-2024-56732
8.8 HIGH

HarfBuzz is a text shaping engine. Starting with 8.5.0 through 10.0.1, there is a heap-based buffer overflow in the hb_cairo_glyphs_from_buffer function.

Dec 27, 2024
CVE-2024-54453
7.5 HIGH

An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35, 7.10.x through 7.10.0.18, and 7.11.x through 7.11.0.15. A path traversal vulnerability in the DocServlet servlet …

Dec 27, 2024
CVE-2024-39025
7.5 HIGH

Incorrect access control in the /users endpoint of Cpacker MemGPT v0.3.17 allows attackers to access sensitive data.

Dec 27, 2024
CVE-2024-50945
7.5 HIGH

An improper access control vulnerability exists in SimplCommerce at commit 230310c8d7a0408569b292c5a805c459d47a1d8f, allowing users to submit reviews without verifying if they have purchased the product.

Dec 27, 2024
CVE-2024-12988
7.3 HIGH

A vulnerability has been found in Netgear R6900P and R7000P 1.3.3.154 and classified as critical. Affected by this vulnerability is the function sub_16C4C of the …

Dec 27, 2024
CVE-2024-56509
8.6 HIGH

changedetection.io is a free open source web page change detection, website watcher, restock monitor and notification service. Improper input validation in the application can allow …

Dec 27, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.