CVE Database

46542+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-4229
7.8 HIGH

Incorrect Default Permissions vulnerability in Edgecross Basic Software for Windows versions 1.00 and later and Edgecross Basic Software for Developers versions 1.00 and later allows …

Dec 19, 2024
CVE-2021-26093
7.3 HIGH

An access of uninitialized pointer (CWE-824) vulnerability in FortiWLC versions 8.6.0, 8.5.3 and earlier may allow a local and authenticated attacker to crash the access …

Dec 19, 2024
CVE-2024-11740
7.3 HIGH

The The Download Manager plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.3.03. This is due to …

Dec 19, 2024
CVE-2024-11984
8.8 HIGH

A unrestricted upload of file with dangerous type vulnerability in epaper draft function in Corporate Training Management System before 10.13 allows remote authenticated users to …

Dec 19, 2024
CVE-2024-51532
7.1 HIGH

Dell PowerStore contains an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability. A low privileged attacker with local access could potentially exploit …

Dec 19, 2024
CVE-2024-35141
7.8 HIGH

IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to execution of unnecessary privileges.

Dec 19, 2024
CVE-2023-23354
7.3 HIGH

A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have …

Dec 19, 2024
CVE-2022-27595
7.8 HIGH

An insecure library loading vulnerability has been reported to affect QVPN Device Client. If exploited, the vulnerability could allow local attackers who have gained user …

Dec 19, 2024
CVE-2022-44520
7.8 HIGH

Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary …

Dec 19, 2024
CVE-2022-44518
7.8 HIGH

Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary …

Dec 19, 2024
CVE-2022-44514
7.8 HIGH

Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary …

Dec 19, 2024
CVE-2022-44513
7.8 HIGH

Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by an out-of-bounds write vulnerability that could result in …

Dec 19, 2024
CVE-2022-44512
7.8 HIGH

Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by an out-of-bounds write vulnerability that could result in …

Dec 19, 2024
CVE-2024-56319
7.5 HIGH

In Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0 before e3277eb, unlimited user label appends in a userlabel cluster can lead to a denial of …

Dec 18, 2024
CVE-2024-56318
7.5 HIGH

In raw\TCP.cpp in Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0 before 27ca6ec, there is a NULL pointer dereference in TCPBase::ProcessSingleMessage via TCP packets with …

Dec 18, 2024
CVE-2024-56317
7.5 HIGH

In Matter (aka connectedhomeip or Project CHIP) through 1.4.0.0, the WriteAcl function deletes all existing ACL entries first, and then attempts to recreate them based …

Dec 18, 2024
CVE-2024-56116
8.8 HIGH

A Cross-Site Request Forgery vulnerability in Amiro.CMS before 7.8.4 allows remote attackers to create an administrator account.

Dec 18, 2024
CVE-2024-55506
8.8 HIGH

An IDOR vulnerability in CodeAstro's Complaint Management System v1.0 (version with 0 updates) enables an attacker to execute arbitrary code and obtain sensitive information via …

Dec 18, 2024
CVE-2024-53580
7.5 HIGH

iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function.

Dec 18, 2024
CVE-2024-43106
7.1 HIGH

A library injection vulnerability exists in Microsoft Excel 16.83 for macOS. A specially crafted library can leverage Excel's access privileges, leading to a permission bypass. …

Dec 18, 2024
CVE-2024-42220
7.1 HIGH

A library injection vulnerability exists in Microsoft Outlook 16.83.3 for macOS. A specially crafted library can leverage Outlook's access privileges, leading to a permission bypass. …

Dec 18, 2024
CVE-2024-42004
7.1 HIGH

A library injection vulnerability exists in Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to …

Dec 18, 2024
CVE-2024-41165
7.1 HIGH

A library injection vulnerability exists in Microsoft Word 16.83 for macOS. A specially crafted library can leverage Word's access privileges, leading to a permission bypass. …

Dec 18, 2024
CVE-2024-41159
7.1 HIGH

A library injection vulnerability exists in Microsoft OneNote 16.83 for macOS. A specially crafted library can leverage OneNote's access privileges, leading to a permission bypass. …

Dec 18, 2024
CVE-2024-41145
7.1 HIGH

A library injection vulnerability exists in the WebView.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage …

Dec 18, 2024
CVE-2024-41138
7.1 HIGH

A library injection vulnerability exists in the com.microsoft.teams2.modulehost.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage …

Dec 18, 2024
CVE-2024-39804
7.1 HIGH

A library injection vulnerability exists in Microsoft PowerPoint 16.83 for macOS. A specially crafted library can leverage PowerPoint's access privileges, leading to a permission bypass. …

Dec 18, 2024
CVE-2024-55505
8.8 HIGH

An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the mess-view.php component.

Dec 18, 2024
CVE-2024-12695
8.8 HIGH

Out of bounds write in V8 in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to execute arbitrary code inside a sandbox via a …

Dec 18, 2024
CVE-2024-12694
8.8 HIGH

Use after free in Compositing in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Dec 18, 2024
CVE-2024-12693
8.8 HIGH

Out of bounds memory access in V8 in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to execute arbitrary code inside a sandbox via …

Dec 18, 2024
CVE-2024-12692
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 131.0.6778.204 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Dec 18, 2024
CVE-2024-53271
7.1 HIGH

Envoy is a cloud-native high-performance edge/middle/service proxy. In affected versions envoy does not properly handle http 1.1 non-101 1xx responses. This can lead to downstream …

Dec 18, 2024
CVE-2024-53270
7.5 HIGH

Envoy is a cloud-native high-performance edge/middle/service proxy. In affected versions `sendOverloadError` is going to assume the active request exists when `envoy.load_shed_points.http1_server_abort_dispatch` is configured. If `active_request` …

Dec 18, 2024
CVE-2024-49363
7.4 HIGH

Misskey is an open source, federated social media platform. In affected versions FileServerService (media proxy) in github.com/misskey-dev/misskey 2024.10.1 or earlier did not detect proxy loops, …

Dec 18, 2024
CVE-2024-36694
7.2 HIGH

OpenCart 4.0.2.3 is vulnerable to Server-Side Template Injection (SSTI) via the Theme Editor Function.

Dec 18, 2024
CVE-2024-12741
7.8 HIGH

A deserialization of untrusted data vulnerability exists in NI DAQExpress that may result in remote code execution. Successful exploitation requires an attacker to get a …

Dec 18, 2024
CVE-2024-56055
8.5 HIGH

Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS wplms_plugin allows Path Traversal.This issue affects WPLMS: from n/a through < 1.9.9.5.2.

Dec 18, 2024
CVE-2024-56053
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS wplms_plugin allows SQL Injection.This issue affects WPLMS: from n/a …

Dec 18, 2024
CVE-2024-56051
8.5 HIGH

Improper Control of Generation of Code ('Code Injection') vulnerability in VibeThemes WPLMS wplms_plugin allows Code Injection.This issue affects WPLMS: from n/a through < 1.9.9.5.

Dec 18, 2024
CVE-2024-56049
8.5 HIGH

Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS wplms_plugin allows Path Traversal.This issue affects WPLMS: from n/a through < 1.9.9.5.2.

Dec 18, 2024
CVE-2024-56048
8.8 HIGH

Missing Authorization vulnerability in VibeThemes WPLMS wplms_plugin allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPLMS: from n/a through <= 1.9.9.

Dec 18, 2024
CVE-2024-56047
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VibeThemes WPLMS wplms_plugin allows SQL Injection.This issue affects WPLMS: from n/a …

Dec 18, 2024
CVE-2024-55953
8.1 HIGH

DataEase is an open source business analytics tool. Authenticated users can read and deserialize arbitrary files through the background JDBC connection. When constructing the jdbc …

Dec 18, 2024
CVE-2024-55952
8.8 HIGH

DataEase is an open source business analytics tool. Authenticated users can remotely execute code through the backend JDBC connection. When constructing the jdbc connection string, …

Dec 18, 2024
CVE-2024-54381
7.1 HIGH

Missing Authorization vulnerability in Dotstore Advance Menu Manager advance-menu-manager.This issue affects Advance Menu Manager: from n/a through <= 3.1.1.

Dec 18, 2024
CVE-2024-49202
7.6 HIGH

Keyfactor Command before 12.5.0 has Incorrect Access Control: access tokens are over permissioned, aka 64099. The fixed versions are 11.5.1.1, 11.5.2.1, 11.5.3.1, 11.5.4.5, 11.5.6.1, 11.6.0, …

Dec 18, 2024
CVE-2024-47040
7.8 HIGH

There is a possible UAF due to a logic error in the code. This could lead to local escalation of privilege with no additional execution …

Dec 18, 2024
CVE-2024-47038
7.8 HIGH

In dhd_prot_flowrings_pool_release of dhd_msgbuf.c, there is a possible outcof bounds write due to a missing bounds check. This could lead to localcescalation of privilege with …

Dec 18, 2024
CVE-2024-55088
8.8 HIGH

GetSimple CMS CE 3.3.19 is vulnerable to Server-Side Request Forgery (SSRF) in the backend plugin module.

Dec 18, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.