CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-7139
6.5 MEDIUM

Due to an unchecked buffer length, a specially crafted L2CAP packet can cause a buffer overflow. This buffer overflow triggers an assert, which results in …

Dec 19, 2024
CVE-2024-7138
6.5 MEDIUM

An assert may be triggered, causing a temporary denial of service when a peer device sends a specially crafted malformed L2CAP packet. If a watchdog …

Dec 19, 2024
CVE-2024-7137
6.5 MEDIUM

The L2CAP receive data buffer for L2CAP packets is restricted to packet sizes smaller than the maximum supported packet size. Receiving a packet that exceeds …

Dec 19, 2024
CVE-2024-52794
6.8 MEDIUM

Discourse is an open source platform for community discussion. Users clicking on the lightbox thumbnails could be affected. This problem is patched in the latest …

Dec 19, 2024
CVE-2024-49765
5.3 MEDIUM

Discourse is an open source platform for community discussion. Sites that are using discourse connect but still have local logins enabled could allow attackers to …

Dec 19, 2024
CVE-2024-56159
5.3 MEDIUM

Astro is a web framework for content-driven websites. A bug in the build process allows any unauthenticated user to read parts of the server source …

Dec 19, 2024
CVE-2020-6923
5.7 MEDIUM

The HP Linux Imaging and Printing (HPLIP) software may potentially be affected by memory buffer overflow.

Dec 19, 2024
CVE-2024-52897
6.2 MEDIUM

IBM MQ 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a remote attacker to obtain sensitive information when …

Dec 19, 2024
CVE-2024-51471
5.3 MEDIUM

IBM MQ Appliance 9.3 LTS, 9.3 CD, and 9.4 LTS web console could allow an authenticated user to cause a denial-of-service when trace is enabled …

Dec 19, 2024
CVE-2024-49336
6.5 MEDIUM

IBM Security Guardium 11.5 and 12.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the …

Dec 19, 2024
CVE-2024-12794
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Codezips E-Commerce Site 1.0. This affects an unknown part of the file /admin/editorder.php. The manipulation …

Dec 19, 2024
CVE-2024-12793
4.3 MEDIUM

A vulnerability, which was classified as problematic, has been found in PbootCMS up to 5.2.3. Affected by this issue is some unknown functionality of the …

Dec 19, 2024
CVE-2024-52896
6.2 MEDIUM

IBM MQ 9.2 LTS, 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a remote attacker to obtain sensitive information when …

Dec 19, 2024
CVE-2024-12789
6.3 MEDIUM

A vulnerability was found in PbootCMS up to 3.2.3. It has been classified as critical. This affects an unknown part of the file apps/home/controller/IndexController.php. The …

Dec 19, 2024
CVE-2024-12785
6.3 MEDIUM

A vulnerability was found in itsourcecode Vehicle Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Dec 19, 2024
CVE-2024-12784
6.3 MEDIUM

A vulnerability was found in itsourcecode Vehicle Management System 1.0. It has been classified as critical. Affected is an unknown function of the file editbill.php. …

Dec 19, 2024
CVE-2024-45819
5.5 MEDIUM

PVH guests have their ACPI tables constructed by the toolstack. The construction involves building the tables in local memory, which are then copied into guest …

Dec 19, 2024
CVE-2024-45818
6.5 MEDIUM

The hypervisor contains code to accelerate VGA memory accesses for HVM guests, when the (virtual) VGA is in "standard" mode. Locking involved there has an …

Dec 19, 2024
CVE-2024-37962
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Agency Dominion Inc. Fusion fusion.This issue affects Fusion: from n/a through <= 1.6.1.

Dec 19, 2024
CVE-2024-12331
4.3 MEDIUM

The File Manager Pro – Filester plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ajax_install_plugin' …

Dec 19, 2024
CVE-2020-12820
5.4 MEDIUM

Under non-default configuration, a stack-based buffer overflow in FortiOS version 6.0.10 and below, version 5.6.12 and below may allow a remote attacker authenticated to the …

Dec 19, 2024
CVE-2020-12819
5.4 MEDIUM

A heap-based buffer overflow vulnerability in the processing of Link Control Protocol messages in FortiGate versions 5.6.12, 6.0.10, 6.2.4 and 6.4.1 and earlier may allow …

Dec 19, 2024
CVE-2024-12560
4.3 MEDIUM

The Button Block – Get fully customizable & multi-functional buttons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and …

Dec 19, 2024
CVE-2024-11768
5.3 MEDIUM

The Download Manager plugin for WordPress is vulnerable to unauthorized download of password-protected content due to improper password validation on the checkFilePassword function in all …

Dec 19, 2024
CVE-2024-12121
5.4 MEDIUM

The Broken Link Checker | Finder plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 2.5.0 via …

Dec 19, 2024
CVE-2024-10548
6.5 MEDIUM

The WP Project Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.15 via the Project Task …

Dec 19, 2024
CVE-2023-30443
5.3 MEDIUM

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted …

Dec 19, 2024
CVE-2023-23357
4.8 MEDIUM

A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have …

Dec 19, 2024
CVE-2023-23356
5.5 MEDIUM

A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained …

Dec 19, 2024
CVE-2022-27600
6.8 MEDIUM

An uncontrolled resource consumption vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers to launch …

Dec 19, 2024
CVE-2022-33954
4.6 MEDIUM

IBM Robotic Process Automation 21.0.1, 21.0.2, and 21.0.3 could allow a user with psychical access to the system to obtain sensitive information due to insufficiently …

Dec 19, 2024
CVE-2021-39081
5.9 MEDIUM

IBM Cognos Analytics Mobile for Android 1.1.14 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

Dec 19, 2024
CVE-2024-55603
6.5 MEDIUM

Kanboard is project management software that focuses on the Kanban methodology. In affected versions sessions are still usable even though their lifetime has exceeded. Kanboard …

Dec 19, 2024
CVE-2023-21586
5.5 MEDIUM

Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a NULL Pointer Dereference vulnerability. An unauthenticated attacker …

Dec 19, 2024
CVE-2022-44519
5.5 MEDIUM

Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability that could lead to disclosure …

Dec 19, 2024
CVE-2022-44517
5.5 MEDIUM

Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted …

Dec 19, 2024
CVE-2022-44516
5.5 MEDIUM

Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted …

Dec 19, 2024
CVE-2022-44515
5.5 MEDIUM

Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted …

Dec 19, 2024
CVE-2021-29827
5.2 MEDIUM

IBM InfoSphere Information Server 11.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a …

Dec 19, 2024
CVE-2021-20553
5.4 MEDIUM

IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the …

Dec 19, 2024
CVE-2024-56115
6.1 MEDIUM

A vulnerability in Amiro.CMS before 7.8.4 exists due to the failure to take measures to neutralize special elements. It allows remote attackers to conduct a …

Dec 18, 2024
CVE-2024-55239
5.4 MEDIUM

A reflected Cross-Site Scripting vulnerability in the standard documentation upload functionality in Portabilis i-Educar 2.9 allows attacker to craft malicious urls with arbitrary javascript in …

Dec 18, 2024
CVE-2024-37649
4.6 MEDIUM

Insecure Permissions vulnerability in SecureSTATION v.2.5.5.3116-S50-SMA-B20160811A and before allows a physically proximate attacker to obtain sensitive information via the modification of user credentials.

Dec 18, 2024
CVE-2022-40733
5.0 MEDIUM

An access violation vulnerability exists in the DirectComposition functionality win32kbase.sys driver version 10.0.22000.593 as part of Windows 11 version 22000.593 and version 10.0.20348.643 as part …

Dec 18, 2024
CVE-2022-40732
5.0 MEDIUM

An access violation vulnerability exists in the DirectComposition functionality win32kbase.sys driver version 10.0.22000.593 as part of Windows 11 version 22000.593 and version 10.0.20348.643 as part …

Dec 18, 2024
CVE-2024-55232
5.4 MEDIUM

An IDOR vulnerability in the manage-notes.php module in PHPGurukul Online Notes Sharing Management System v1.0 allows unauthorized users to delete notes belonging to other accounts …

Dec 18, 2024
CVE-2024-55231
4.3 MEDIUM

An IDOR vulnerability in the edit-notes.php module of PHPGurukul Online Notes Sharing Management System v1.0 allows unauthorized users to modify notes belonging to other accounts …

Dec 18, 2024
CVE-2024-56140
5.9 MEDIUM

Astro is a web framework for content-driven websites. In affected versions a bug in Astro’s CSRF-protection middleware allows requests to bypass CSRF checks. When the …

Dec 18, 2024
CVE-2024-45338
5.3 MEDIUM

An attacker can craft an input to the Parse functions that would be processed non-linearly with respect to its length, resulting in extremely slow parsing. …

Dec 18, 2024
CVE-2024-12686
6.6 MEDIUM KEV

A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative privileges to inject …

Dec 18, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.