CVE Database

4634+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-9596
3.7 LOW

An issue has been discovered in GitLab EE affecting all versions starting from 16.6 prior to 17.2.9, from 17.3 prior to 17.3.5, and from 17.4 …

Oct 10, 2024
CVE-2024-45149
2.7 LOW

Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. …

Oct 10, 2024
CVE-2024-45135
2.7 LOW

Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. …

Oct 10, 2024
CVE-2024-45134
2.7 LOW

Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Information Exposure vulnerability that could result in a security feature bypass. An …

Oct 10, 2024
CVE-2024-45133
2.7 LOW

Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Information Exposure vulnerability that could result in a security feature bypass. An …

Oct 10, 2024
CVE-2024-45120
3.1 LOW

Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could lead to a security …

Oct 10, 2024
CVE-2024-30118
3.5 LOW

HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user to obtain sensitive information they are not entitled to because of …

Oct 9, 2024
CVE-2024-7038
2.7 LOW

An information disclosure vulnerability exists in open-webui version 0.3.8. The vulnerability is related to the embedding model update feature under admin settings. When a user …

Oct 9, 2024
CVE-2024-47813
2.9 LOW

Wasmtime is an open source runtime for WebAssembly. Under certain concurrent event orderings, a `wasmtime::Engine`'s internal type registry was susceptible to double-unregistration bugs due to …

Oct 9, 2024
CVE-2024-39586
2.9 LOW

Dell AppSync Server, version 4.3 through 4.6, contains an XML External Entity Injection vulnerability. An adjacent high privileged attacker could potentially exploit this vulnerability, leading …

Oct 9, 2024
CVE-2023-36325
3.7 LOW

i2p before 2.3.0 (Java) allows de-anonymizing the public IPv4 and IPv6 addresses of i2p hidden services (aka eepsites) via a correlation attack across the IPv4 …

Oct 9, 2024
CVE-2024-27457
2.5 LOW

Improper check for unusual or exceptional conditions in Intel(R) TDX Module firmware before version 1.5.06 may allow a privileged user to potentially enable information disclosure …

Oct 8, 2024
CVE-2024-47780
3.1 LOW

TYPO3 is a free and open source Content Management Framework. Backend users could see items in the backend page tree without having access if the …

Oct 8, 2024
CVE-2024-47951
3.5 LOW

In JetBrains TeamCity before 2024.07.3 stored XSS was possible via server global settings

Oct 8, 2024
CVE-2024-47950
3.5 LOW

In JetBrains TeamCity before 2024.07.3 stored XSS was possible in Backup configuration settings

Oct 8, 2024
CVE-2024-33506
3.3 LOW

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiManager 7.4.2 and below, 7.2.5 and below, 7.0.12 and below allows a remote …

Oct 8, 2024
CVE-2024-8518
3.3 LOW

CWE-20: Improper Input Validation vulnerability exists that could cause a crash of the Zelio Soft 2 application when a specially crafted project file is loaded …

Oct 8, 2024
CVE-2024-45476
3.3 LOW

A vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versions < V14.3.0.12), Teamcenter Visualization V2312 (All versions …

Oct 8, 2024
CVE-2024-34671
3.3 LOW

Use of implicit intent for sensitive communication in translation혻in Samsung Internet prior to version 26.0.3.1 allows local attackers to get sensitive information. User interaction is …

Oct 8, 2024
CVE-2024-9026
3.3 LOW

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using PHP-FPM SAPI and it is configured to catch workers output through …

Oct 8, 2024
CVE-2024-8925
3.1 LOW

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, erroneous parsing of multipart form data contained in an HTTP POST request could …

Oct 8, 2024
CVE-2024-45382
3.3 LOW

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS through out-of-bounds write.

Oct 8, 2024
CVE-2024-43697
3.3 LOW

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS through improper input.

Oct 8, 2024
CVE-2024-43696
3.3 LOW

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS by memory leak.

Oct 8, 2024
CVE-2024-47814
3.9 LOW

Vim is an open source, command line text editor. A use-after-free was found in Vim < 9.1.0764. When closing a buffer (visible in a window) …

Oct 7, 2024
CVE-2024-9554
3.7 LOW

A vulnerability classified as problematic was found in Sovell Smart Canteen System up to 3.0.7303.30513. Affected by this vulnerability is the function Check_ET_CheckPwdz201 of the …

Oct 6, 2024
CVE-2024-41511
3.9 LOW

A Path Traversal (Local File Inclusion) vulnerability in "BinaryFileRedirector.ashx" in CADClick v1.11.0 and before allows remote attackers to retrieve arbitrary local files via the "path" …

Oct 4, 2024
CVE-2024-9513
3.7 LOW

A vulnerability was found in Netadmin Software NetAdmin IAM up to 3.5 and classified as problematic. Affected by this issue is some unknown functionality of …

Oct 4, 2024
CVE-2024-0125
3.3 LOW

NVIDIA CUDA Toolkit for Windows and Linux contains a vulnerability in the nvdisam command line tool, where a user can cause a NULL pointer dereference …

Oct 3, 2024
CVE-2024-0124
3.3 LOW

NVIDIA CUDA Toolkit for Windows and Linux contains a vulnerability in the nvdisam command line tool, where a user can cause nvdisasm to read freed …

Oct 3, 2024
CVE-2024-0123
3.3 LOW

NVIDIA CUDA toolkit for Windows and Linux contains a vulnerability in the nvdisasm command line tool where an attacker may cause an improper validation in …

Oct 3, 2024
CVE-2024-24122
3.3 LOW

A remote code execution vulnerability in the project management of Wanxing Technology's Yitu project which allows an attacker to use the exp.adpx file as a …

Oct 2, 2024
CVE-2024-47612
3.5 LOW

DataDump is a MediaWiki extension that provides dumps of wikis. Several interface messages are unescaped (more specifically, (datadump-table-column-queued), (datadump-table-column-in-progress), (datadump-table-column-completed), (datadump-table-column-failed)). If these messages are …

Oct 2, 2024
CVE-2024-47526
3.5 LOW

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Self Cross-Site Scripting (Self-XSS) vulnerability in the "Alert Templates" feature allows users to inject arbitrary JavaScript …

Oct 1, 2024
CVE-2024-9411
3.5 LOW

A vulnerability classified as problematic has been found in OFCMS 1.1.2. This affects the function add of the file /admin/system/dict/add.json?sqlid=system.dict.save. The manipulation of the argument …

Oct 1, 2024
CVE-2024-30132
3.7 LOW

HCL Nomad server on Domino did not configure certain HTTP Security headers by default which could allow an attacker to obtain sensitive information via unspecified …

Oct 1, 2024
CVE-2024-28808
2.7 LOW

An issue was discovered in Infinera hiT 7300 5.60.50. Hidden functionality in the web interface allows a remote authenticated attacker to access reserved information by …

Sep 30, 2024
CVE-2024-28811
3.3 LOW

An issue was discovered in Infinera hiT 7300 5.60.50. A web application allows a remote privileged attacker to execute applications contained in a specific OS …

Sep 30, 2024
CVE-2024-42496
2.4 LOW

Smart-tab Android app installed April 2023 or earlier contains an issue with plaintext storage of a password. If this vulnerability is exploited, an attacker with …

Sep 30, 2024
CVE-2024-9323
3.5 LOW

A vulnerability was found in SourceCodester Inventory Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of …

Sep 29, 2024
CVE-2024-9320
3.5 LOW

A vulnerability has been found in SourceCodester Online Timesheet App 1.0 and classified as problematic. This vulnerability affects unknown code of the file /endpoint/add-timesheet.php of …

Sep 29, 2024
CVE-2024-9299
3.5 LOW

A vulnerability classified as problematic has been found in SourceCodester Online Railway Reservation System 1.0. This affects an unknown part of the file /?page=reserve. The …

Sep 28, 2024
CVE-2024-9291
3.5 LOW

A vulnerability classified as problematic has been found in kalvinGit kvf-admin up to f12a94dc1ebb7d1c51ee978a85e4c7ed75c620ff. Affected is an unknown function of the file /ueditor/upload?configPath=ueditor/config.json&action=uploadfile of the …

Sep 27, 2024
CVE-2024-45744
3.0 LOW

TopQuadrant TopBraid EDG stores external credentials insecurely. An authenticated attacker with file system access can read edg-setup.properites and obtain the secret to decrypt external passwords …

Sep 27, 2024
CVE-2024-9283
3.3 LOW

A vulnerability classified as problematic has been found in RelaxedJS ReLaXed up to 0.2.2. Affected is an unknown function of the component Pug to PDF …

Sep 27, 2024
CVE-2024-9279
2.4 LOW

A vulnerability, which was classified as problematic, was found in funnyzpc Mee-Admin up to 1.6. This affects an unknown part of the file /mee/index of …

Sep 27, 2024
CVE-2024-9277
3.5 LOW

A vulnerability classified as problematic was found in Langflow up to 1.0.18. Affected by this vulnerability is an unknown functionality of the file \src\backend\base\langflow\interface\utils.py of …

Sep 27, 2024
CVE-2024-9276
3.5 LOW

A vulnerability classified as problematic has been found in TMsoft MyAuth Gateway 3. Affected is an unknown function of the file /index.php. The manipulation of …

Sep 27, 2024
CVE-2024-8974
2.6 LOW

Information disclosure in Gitlab EE/CE affecting all versions from 15.6 prior to 17.2.8, 17.3 prior to 17.3.4, and 17.4 prior to 17.4.1 in specific conditions …

Sep 26, 2024
CVE-2024-4099
3.1 LOW

An issue has been discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.2.8, from 17.3 prior to 17.3.4, and from 17.4 …

Sep 26, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.