CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-54502
6.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.6, macOS Sequoia 15.2, tvOS …

Dec 12, 2024
CVE-2024-54501
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, macOS Sonoma 14.7.2, …

Dec 12, 2024
CVE-2024-54500
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, macOS Sonoma 14.7.2, …

Dec 12, 2024
CVE-2024-54495
5.5 MEDIUM

The issue was addressed with improved permissions logic. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2. An app may be able to …

Dec 12, 2024
CVE-2024-54494
5.9 MEDIUM

A race condition was addressed with additional validation. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, macOS Sonoma …

Dec 12, 2024
CVE-2024-54492
5.9 MEDIUM

This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, …

Dec 12, 2024
CVE-2024-54490
5.5 MEDIUM

This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Sequoia 15.2. A local attacker may gain access to user's Keychain …

Dec 12, 2024
CVE-2024-54486
6.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2, macOS Sonoma 14.7.2, …

Dec 12, 2024
CVE-2024-54484
5.5 MEDIUM

The issue was resolved by sanitizing logging. This issue is fixed in macOS Sequoia 15.2. An app may be able to access user-sensitive data.

Dec 12, 2024
CVE-2024-54477
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An app may be …

Dec 12, 2024
CVE-2024-54476
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An app may be …

Dec 12, 2024
CVE-2024-54474
5.5 MEDIUM

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An app may be …

Dec 12, 2024
CVE-2024-54471
5.5 MEDIUM

This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. A malicious application …

Dec 12, 2024
CVE-2024-54466
5.3 MEDIUM

An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An encrypted …

Dec 12, 2024
CVE-2024-53274
6.1 MEDIUM

Habitica is an open-source habit-building program. Versions prior to 5.28.5 are vulnerable to reflected cross-site scripting. The `register` function in `home.vue` containsa reflected XSS vulnerability …

Dec 12, 2024
CVE-2024-53273
6.1 MEDIUM

Habitica is an open-source habit-building program. Versions prior to 5.28.5 are vulnerable to reflected cross-site scripting. The `register` function in `RegisterLoginReset.vue` contains a reflected XSS …

Dec 12, 2024
CVE-2024-53272
6.1 MEDIUM

Habitica is an open-source habit-building program. Versions prior to 5.28.5 are vulnerable to reflected cross-site scripting. The `login` and `social media` function in `RegisterLoginReset.vue` contains …

Dec 12, 2024
CVE-2024-44300
5.5 MEDIUM

A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An app …

Dec 12, 2024
CVE-2024-44248
6.5 MEDIUM

This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. A user with …

Dec 12, 2024
CVE-2024-44246
5.3 MEDIUM

The issue was addressed with improved routing of Safari-originated requests. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS …

Dec 12, 2024
CVE-2024-44243
5.5 MEDIUM

A configuration issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.3. An app may be able to …

Dec 12, 2024
CVE-2024-44220
5.5 MEDIUM

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2. Parsing a maliciously crafted video file …

Dec 12, 2024
CVE-2024-44212
5.3 MEDIUM

A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, …

Dec 12, 2024
CVE-2024-44201
5.5 MEDIUM

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.1 and iPadOS 18.1, iPadOS 17.7.3, macOS Sequoia 15.1, macOS Sonoma …

Dec 12, 2024
CVE-2024-41146
4.6 MEDIUM

Use of Multiple Resources with Duplicate Identifier (CWE-694) in the Controller 6000 and Controller 7000 Platforms could allow an attacker with physical access to HBUS …

Dec 12, 2024
CVE-2024-12492
6.3 MEDIUM

A vulnerability was found in code-projects Farmacia 1.0. It has been rated as critical. This issue affects some unknown processing of the file /visualizar-usuario.php. The …

Dec 12, 2024
CVE-2024-12490
6.3 MEDIUM

A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0. It has been declared as critical. This vulnerability affects unknown code of …

Dec 12, 2024
CVE-2024-50339
5.3 MEDIUM

GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.17, an unauthenticated user can retrieve all …

Dec 12, 2024
CVE-2024-49111
6.6 MEDIUM

Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability

Dec 12, 2024
CVE-2024-49110
6.8 MEDIUM

Windows Mobile Broadband Driver Elevation of Privilege Vulnerability

Dec 12, 2024
CVE-2024-49109
6.6 MEDIUM

Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability

Dec 12, 2024
CVE-2024-49103
4.3 MEDIUM

Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability

Dec 12, 2024
CVE-2024-49101
6.6 MEDIUM

Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability

Dec 12, 2024
CVE-2024-49099
4.3 MEDIUM

Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability

Dec 12, 2024
CVE-2024-49098
4.3 MEDIUM

Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability

Dec 12, 2024
CVE-2024-49094
6.6 MEDIUM

Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability

Dec 12, 2024
CVE-2024-49092
6.8 MEDIUM

Windows Mobile Broadband Driver Elevation of Privilege Vulnerability

Dec 12, 2024
CVE-2024-49087
4.6 MEDIUM

Windows Mobile Broadband Driver Information Disclosure Vulnerability

Dec 12, 2024
CVE-2024-49083
6.8 MEDIUM

Windows Mobile Broadband Driver Elevation of Privilege Vulnerability

Dec 12, 2024
CVE-2024-49082
6.8 MEDIUM

Windows File Explorer Information Disclosure Vulnerability

Dec 12, 2024
CVE-2024-49081
6.6 MEDIUM

Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability

Dec 12, 2024
CVE-2024-49078
6.8 MEDIUM

Windows Mobile Broadband Driver Elevation of Privilege Vulnerability

Dec 12, 2024
CVE-2024-49077
6.8 MEDIUM

Windows Mobile Broadband Driver Elevation of Privilege Vulnerability

Dec 12, 2024
CVE-2024-49073
6.8 MEDIUM

Windows Mobile Broadband Driver Elevation of Privilege Vulnerability

Dec 12, 2024
CVE-2024-49065
5.5 MEDIUM

Microsoft Office Remote Code Execution Vulnerability

Dec 12, 2024
CVE-2024-49064
6.5 MEDIUM

Microsoft SharePoint Information Disclosure Vulnerability

Dec 12, 2024
CVE-2024-49062
6.5 MEDIUM

Microsoft SharePoint Information Disclosure Vulnerability

Dec 12, 2024
CVE-2024-12489
6.3 MEDIUM

A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0. It has been classified as critical. This affects an unknown part of …

Dec 12, 2024
CVE-2024-12488
6.3 MEDIUM

A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0 and classified as critical. Affected by this issue is some unknown functionality …

Dec 12, 2024
CVE-2024-12487
6.3 MEDIUM

A vulnerability has been found in code-projects Online Class and Exam Scheduling System 1.0 and classified as critical. Affected by this vulnerability is an unknown …

Dec 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.