CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2022-49034
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sh: cpuinfo: Fix a warning for CONFIG_CPUMASK_OFFSTACK When CONFIG_CPUMASK_OFFSTACK and CONFIG_DEBUG_PER_CPU_MAPS are selected, cpu_max_bits_warn() generates …

Dec 27, 2024
CVE-2020-9253
6.3 MEDIUM

There is a stack overflow vulnerability in some Huawei smart phone. An attacker can craft specific packet to exploit this vulnerability. Due to insufficient verification, …

Dec 27, 2024
CVE-2020-9211
6.4 MEDIUM

There is an out-of-bound read and write vulnerability in Huawei smartphone. A module dose not verify the input sufficiently. Attackers can exploit this vulnerability by …

Dec 27, 2024
CVE-2020-9210
6.8 MEDIUM

There is an insufficient integrity vulnerability in Huawei products. A module does not perform sufficient integrity check in a specific scenario. Attackers can exploit the …

Dec 27, 2024
CVE-2020-9086
4.3 MEDIUM

There is a buffer error vulnerability in some Huawei product. An unauthenticated attacker may send special UPNP message to the affected products. Due to insufficient …

Dec 27, 2024
CVE-2020-9085
5.3 MEDIUM

There is a NULL pointer dereference vulnerability in some Huawei products. An attacker may send specially crafted POST messages to the affected products. Due to …

Dec 27, 2024
CVE-2024-12981
6.3 MEDIUM

A vulnerability was found in CodeAstro Car Rental System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Dec 27, 2024
CVE-2024-11921
4.8 MEDIUM

The GiveWP WordPress plugin before 3.19.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Dec 27, 2024
CVE-2024-11842
4.3 MEDIUM

The DN Shipping by Weight for WooCommerce WordPress plugin before 1.2 does not have CSRF check in place when updating its settings, which could allow …

Dec 27, 2024
CVE-2024-11645
4.8 MEDIUM

The float block WordPress plugin through 1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Dec 27, 2024
CVE-2024-11644
5.9 MEDIUM

The WP-SVG WordPress plugin through 0.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the …

Dec 27, 2024
CVE-2024-11605
4.8 MEDIUM

The wp-publications WordPress plugin through 1.2 does not escape filenames before outputting them back in the page, which could allow high privilege users such as …

Dec 27, 2024
CVE-2024-12980
4.3 MEDIUM

A vulnerability was found in code-projects Job Recruitment 1.0. It has been classified as problematic. Affected is the function fln_update of the file /_parse/_all_edits.php. The …

Dec 27, 2024
CVE-2024-12979
4.3 MEDIUM

A vulnerability was found in code-projects Job Recruitment 1.0 and classified as problematic. This issue affects the function cn_update of the file /_parse/_all_edits.php. The manipulation …

Dec 27, 2024
CVE-2024-9774
6.5 MEDIUM

A vulnerability was found in python-sql where unary operators do not escape non-Expression.

Dec 27, 2024
CVE-2024-12977
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in PHPGurukul Complaint Management System 1.0. This affects an unknown part of the file /admin/state.php. The …

Dec 27, 2024
CVE-2024-45805
4.3 MEDIUM

OpenCTI is an open-source cyber threat intelligence platform. Before 6.3.0, general users can access information that can only be accessed by users with access privileges …

Dec 26, 2024
CVE-2024-56510
5.3 MEDIUM

@marp-team/marp-core is the core for Marp, which is the ecosystem to write your presentation with plain Markdown. Marp Core from v3.0.2 to v3.9.0 and v4.0.0, …

Dec 26, 2024
CVE-2024-12908
6.9 MEDIUM

Delinea addressed a reported case on Secret Server v11.7.31 (protocol handler version 6.0.3.26) where, within the protocol handler function, URI's were compared before normalization and …

Dec 26, 2024
CVE-2024-12956
6.3 MEDIUM

A vulnerability was found in 1000 Projects Portfolio Management System MCA 1.0 and classified as critical. This issue affects some unknown processing of the file …

Dec 26, 2024
CVE-2024-12955
4.3 MEDIUM

A vulnerability has been found in PHPGurukul Blood Bank & Donor Management System 2.4 and classified as problematic. This vulnerability affects unknown code of the …

Dec 26, 2024
CVE-2024-12954
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in 1000 Projects Portfolio Management System MCA 1.0. This affects an unknown part of the file …

Dec 26, 2024
CVE-2024-12953
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in 1000 Projects Portfolio Management System MCA 1.0. Affected by this issue is some unknown …

Dec 26, 2024
CVE-2024-12952
6.3 MEDIUM

A vulnerability classified as critical was found in melMass comfy_mtb up to 0.1.4. Affected by this vulnerability is the function run_command of the file comfy_mtb/endpoint.py …

Dec 26, 2024
CVE-2024-12951
6.3 MEDIUM

A vulnerability classified as critical has been found in 1000 Projects Portfolio Management System MCA 1.0. Affected is an unknown function of the file /add_personal_details.php. …

Dec 26, 2024
CVE-2024-8994
6.2 MEDIUM

Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.

Dec 26, 2024
CVE-2024-8993
6.2 MEDIUM

Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.

Dec 26, 2024
CVE-2024-8992
4.0 MEDIUM

Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.

Dec 26, 2024
CVE-2024-47155
5.5 MEDIUM

Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.

Dec 26, 2024
CVE-2024-47154
5.5 MEDIUM

Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.

Dec 26, 2024
CVE-2024-47153
6.2 MEDIUM

Some Honor products are affected by information leak vulnerability, successful exploitation could cause the information leak.

Dec 26, 2024
CVE-2024-47148
4.0 MEDIUM

Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.

Dec 26, 2024
CVE-2024-12950
6.3 MEDIUM

A vulnerability was found in code-projects/projectworlds Travel Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file …

Dec 26, 2024
CVE-2024-12949
6.3 MEDIUM

A vulnerability was found in code-projects Travel Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /package.php. …

Dec 26, 2024
CVE-2024-47151
6.3 MEDIUM

Some Honor products are affected by file writing vulnerability, successful exploitation could cause code execution

Dec 26, 2024
CVE-2024-12948
6.3 MEDIUM

A vulnerability was found in code-projects Travel Management System 1.0. It has been classified as critical. This affects an unknown part of the file /detail.php. …

Dec 26, 2024
CVE-2024-12947
6.3 MEDIUM

A vulnerability was found in Codezips Hospital Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Dec 26, 2024
CVE-2024-12941
6.3 MEDIUM

A vulnerability was found in CodeAstro Blood Donor Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /pages/deletedannounce.php. …

Dec 26, 2024
CVE-2024-12939
6.3 MEDIUM

A vulnerability was found in code-projects Job Recruitment 1.0. It has been rated as critical. This issue affects the function add_edu of the file /_parse/_all_edits.php. …

Dec 26, 2024
CVE-2024-12938
6.3 MEDIUM

A vulnerability has been found in code-projects Simple Admin Panel 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Dec 26, 2024
CVE-2024-12937
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in code-projects Simple Admin Panel 1.0. Affected is an unknown function of the file addVariationController.php. The …

Dec 26, 2024
CVE-2024-11223
4.7 MEDIUM

The WPForms WordPress plugin before 1.9.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

Dec 26, 2024
CVE-2024-10903
4.7 MEDIUM

The Broken Link Checker WordPress plugin before 2.4.2 does not validate a the link URLs before making a request to them, which could allow admin …

Dec 26, 2024
CVE-2024-12936
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in code-projects Simple Admin Panel 1.0. This issue affects some unknown processing of the file …

Dec 26, 2024
CVE-2024-12935
6.3 MEDIUM

A vulnerability classified as critical was found in code-projects Simple Admin Panel 1.0. This vulnerability affects unknown code of the file editItemForm.php. The manipulation of …

Dec 26, 2024
CVE-2024-12934
6.3 MEDIUM

A vulnerability classified as critical has been found in code-projects Simple Admin Panel 1.0. This affects an unknown part of the file updateItemController.php. The manipulation …

Dec 26, 2024
CVE-2024-12931
6.3 MEDIUM

A vulnerability was found in code-projects Simple Admin Panel 1.0. It has been classified as critical. Affected is an unknown function of the file /addCatController.php. …

Dec 26, 2024
CVE-2024-12929
6.3 MEDIUM

A vulnerability has been found in code-projects Student Management System 1.0.00 and classified as critical. This vulnerability affects unknown code of the file /addCatController.php. The …

Dec 26, 2024
CVE-2024-12928
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in code-projects Simple Admin Panel 1.0. This affects an unknown part. The manipulation of the argument …

Dec 26, 2024
CVE-2024-12926
6.3 MEDIUM

A vulnerability classified as critical was found in Codezips Project Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/forms/advanced.php. …

Dec 25, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.