CVE Database

46542+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-11977
7.3 HIGH

The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up …

Dec 21, 2024
CVE-2023-31279
8.1 HIGH

The AirVantage platform is vulnerable to an unauthorized attacker registering previously unregistered devices on the AirVantage platform when the owner has not disabled the AirVantage …

Dec 21, 2024
CVE-2020-13712
7.8 HIGH

A command injection is possible through the user interface, allowing arbitrary command execution as the root user. oMG2000 running MGOS 3.15.1 or earlier is affected. …

Dec 20, 2024
CVE-2024-56359
8.1 HIGH

grist-core is a spreadsheet hosting server. A user visiting a malicious document and clicking on a link in a HyperLink cell using a control modifier …

Dec 20, 2024
CVE-2024-56358
8.1 HIGH

grist-core is a spreadsheet hosting server. A user visiting a malicious document and previewing an attachment could have their account compromised, because JavaScript in an …

Dec 20, 2024
CVE-2024-56357
8.1 HIGH

grist-core is a spreadsheet hosting server. A user visiting a malicious document or submitting a malicious form could have their account compromised, because it was …

Dec 20, 2024
CVE-2024-56335
7.6 HIGH

vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. In affected versions an attacker is capable of updating or deleting …

Dec 20, 2024
CVE-2024-56334
7.8 HIGH

systeminformation is a System and OS information library for node.js. In affected versions SSIDs are not sanitized when before they are passed as a parameter …

Dec 20, 2024
CVE-2024-37758
8.8 HIGH

Improper access control in the endpoint /RoleMenuMapping/AddRoleMenu of Digiteam v4.21.0.0 allows authenticated attackers to escalate privileges.

Dec 20, 2024
CVE-2024-12677
7.8 HIGH

Delta Electronics DTM Soft deserializes objects, which could allow an attacker to execute arbitrary code.

Dec 20, 2024
CVE-2024-55470
7.5 HIGH

Oqtane Framework 6.0.0 is vulnerable to Incorrect Access Control. By manipulating the entityid parameter, attackers can bypass passcode validation and successfully log into the application …

Dec 20, 2024
CVE-2024-40695
8.0 HIGH

IBM Cognos Analytics 11.2.0 through 11.2.4 FP4 and 12.0.0 through 12.0.4 could be vulnerable to malicious file upload by not validating the content of the …

Dec 20, 2024
CVE-2024-21549
8.6 HIGH

Versions of the package spatie/browsershot before 5.0.3 are vulnerable to Improper Input Validation due to improper URL validation through the setUrl method. An attacker can …

Dec 20, 2024
CVE-2024-44195
7.5 HIGH

A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.1. An app may be able to read arbitrary files.

Dec 20, 2024
CVE-2023-42867
7.8 HIGH

This issue was addressed with improved validation of the process entitlement and Team ID. This issue is fixed in GarageBand 10.4.9. An app may be …

Dec 20, 2024
CVE-2022-34159
7.5 HIGH

Huawei printers have an input verification vulnerability. Successful exploitation of this vulnerability may cause device service exceptions. (Vulnerability ID: HWPSIRT-2022-80078) This vulnerability has been assigned …

Dec 20, 2024
CVE-2022-32204
7.5 HIGH

There is an improper input verification vulnerability in Huawei printer product. Successful exploitation of this vulnerability may cause service abnormal. (Vulnerability ID: HWPSIRT-2022-87185) This vulnerability …

Dec 20, 2024
CVE-2022-32144
8.6 HIGH

There is an insufficient input verification vulnerability in Huawei product. Successful exploitation of this vulnerability may lead to service abnormal. (Vulnerability ID: HWPSIRT-2022-76192) This vulnerability …

Dec 20, 2024
CVE-2024-54538
7.5 HIGH

A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS …

Dec 20, 2024
CVE-2024-12831
7.8 HIGH

Arista NG Firewall uvm_login Incorrect Authorization Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Arista NG Firewall. An …

Dec 20, 2024
CVE-2024-12830
7.3 HIGH

Arista NG Firewall custom_handler Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Arista NG …

Dec 20, 2024
CVE-2024-12829
8.8 HIGH

Arista NG Firewall ExecManagerImpl Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Arista NG …

Dec 20, 2024
CVE-2024-54663
7.5 HIGH

An issue was discovered in the Webmail Classic UI in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A Local File Inclusion (LFI) vulnerability exists …

Dec 19, 2024
CVE-2024-12700
8.8 HIGH

There is an unrestricted file upload vulnerability where it is possible for an authenticated user (low privileged) to upload an jsp shell and execute code …

Dec 19, 2024
CVE-2024-12729
8.8 HIGH

A post-auth code injection vulnerability in the User Portal allows authenticated users to execute code remotely in Sophos Firewall older than version 21.0 MR1 (21.0.1).

Dec 19, 2024
CVE-2024-12672
7.3 HIGH

A third-party vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the boundaries of allocated memory in a …

Dec 19, 2024
CVE-2024-12175
7.8 HIGH

Another “use after free” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and …

Dec 19, 2024
CVE-2024-11364
7.3 HIGH

Another “uninitialized variable” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force …

Dec 19, 2024
CVE-2024-11157
7.3 HIGH

A third-party vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the boundaries of allocated memory in a …

Dec 19, 2024
CVE-2024-53991
7.5 HIGH

Discourse is an open source platform for community discussion. This vulnerability only impacts Discourse instances configured to use `FileStore::LocalStore` which means uploads and backups are …

Dec 19, 2024
CVE-2024-12111
8.0 HIGH

In a specific scenario a LDAP user can abuse the authentication process using injection attack in OpenText Privileged Access Manager that allows authentication bypass. This …

Dec 19, 2024
CVE-2024-56200
8.6 HIGH

Altair is a fork of Misskey v12. Affected versions lack of request validation and lack of authentication in the image proxy for compressing and resizing …

Dec 19, 2024
CVE-2024-55196
7.5 HIGH

Insufficiently Protected Credentials in the Mail Server Configuration in GoPhish v0.12.1 allows an attacker to access cleartext passwords for the configured IMAP and SMTP servers.

Dec 19, 2024
CVE-2024-38819
7.5 HIGH

Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests …

Dec 19, 2024
CVE-2024-12792
7.3 HIGH

A vulnerability classified as critical was found in Codezips E-Commerce Site 1.0. Affected by this vulnerability is an unknown functionality of the file newadmin.php. The …

Dec 19, 2024
CVE-2024-12791
7.3 HIGH

A vulnerability was found in Codezips E-Commerce Site 1.0. It has been rated as critical. This issue affects some unknown processing of the file signin.php. …

Dec 19, 2024
CVE-2023-7005
7.5 HIGH

A specially crafted message can be sent to the TTLock App that downgrades the encryption protocol used for communication, and can be utilized to compromise …

Dec 19, 2024
CVE-2024-12788
7.3 HIGH

A vulnerability was found in Codezips Technical Discussion Forum 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Dec 19, 2024
CVE-2024-55082
7.5 HIGH

A Server-Side Request Forgery (SSRF) in the endpoint http://{your-server}/url-to-pdf of Stirling-PDF 0.35.1 allows attackers to access sensitive information via a crafted request.

Dec 19, 2024
CVE-2024-12787
7.3 HIGH

A vulnerability has been found in 1000 Projects Attendance Tracking Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality …

Dec 19, 2024
CVE-2024-54790
7.5 HIGH

A SQL Injection vulnerability was found in /index.php in PHPGurukul Pre-School Enrollment System v1.0, which allows remote attackers to execute arbitrary code via the visittime …

Dec 19, 2024
CVE-2024-47093
8.8 HIGH

Improper neutralization of input in Nagvis before version 1.9.42 which can lead to XSS

Dec 19, 2024
CVE-2024-25131
8.8 HIGH

A flaw was found in the MustGather.managed.openshift.io Custom Defined Resource (CRD) of OpenShift Dedicated. A non-privileged user on the cluster can create a MustGather object …

Dec 19, 2024
CVE-2024-12786
7.8 HIGH

A vulnerability, which was classified as critical, was found in X1a0He Adobe Downloader up to 1.3.1 on macOS. Affected is the function shouldAcceptNewConnection of the …

Dec 19, 2024
CVE-2024-12782
7.3 HIGH

A vulnerability has been found in Fujifilm Business Innovation Apeos C3070, Apeos C5570 and Apeos C6580 up to 24.8.28 and classified as critical. This vulnerability …

Dec 19, 2024
CVE-2021-32589
8.1 HIGH

A Use After Free (CWE-416) vulnerability in FortiManager version 7.0.0, version 6.4.5 and below, version 6.2.7 and below, version 6.0.10 and below, version 5.6.10 and …

Dec 19, 2024
CVE-2021-26115
7.8 HIGH

An OS command injection (CWE-78) vulnerability in FortiWAN version 4.5.7 and below Command Line Interface may allow a local, authenticated and unprivileged attacker to escalate …

Dec 19, 2024
CVE-2020-15934
8.8 HIGH

An execution with unnecessary privileges vulnerability in the VCM engine of FortiClient for Linux versions 6.2.7 and below, version 6.4.0. may allow local users to …

Dec 19, 2024
CVE-2024-12569
7.8 HIGH

Disclosure of sensitive information in a Milestone XProtect Device Pack driver’s log file for third-party cameras, allows an attacker to read camera credentials stored in …

Dec 19, 2024
CVE-2024-4230
7.8 HIGH

External Control of File Name or Path vulnerability in Edgecross Basic Software for Windows versions 1.00 and later and Edgecross Basic Software for Developers versions …

Dec 19, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.