CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-53614
6.5 MEDIUM

A hardcoded decryption key in Thinkware Cloud APK v4.3.46 allows attackers to access sensitive data and execute arbitrary commands with elevated privileges.

Dec 4, 2024
CVE-2024-53140
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: netlink: terminate outstanding dump on socket close Netlink supports iterative dumping of data. It provides …

Dec 4, 2024
CVE-2024-53138
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: kTLS, Fix incorrect page refcounting The kTLS tx handling code is using a mix …

Dec 4, 2024
CVE-2024-53137
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ARM: fix cacheflush with PAN It seems that the cacheflush syscall got broken when PAN …

Dec 4, 2024
CVE-2024-53136
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm: revert "mm: shmem: fix data-race in shmem_getattr()" Revert d949d1d14fa2 ("mm: shmem: fix data-race in …

Dec 4, 2024
CVE-2024-53135
6.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Bury Intel PT virtualization (guest/host mode) behind CONFIG_BROKEN Hide KVM's pt_mode module param …

Dec 4, 2024
CVE-2024-53134
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: pmdomain: imx93-blk-ctrl: correct remove path The check condition should be 'i < bc->onecell_data.num_domains', not 'bc->onecell_data.num_domains' …

Dec 4, 2024
CVE-2024-53132
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/xe/oa: Fix "Missing outer runtime PM protection" warning Fix the following drm_WARN: [953.586396] xe 0000:00:02.0: …

Dec 4, 2024
CVE-2024-53131
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix null-ptr-deref in block_touch_buffer tracepoint Patch series "nilfs2: fix null-ptr-deref bugs on block tracepoints". …

Dec 4, 2024
CVE-2024-53130
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix null-ptr-deref in block_dirty_buffer tracepoint When using the "block:block_dirty_buffer" tracepoint, mark_buffer_dirty() may cause a …

Dec 4, 2024
CVE-2024-53129
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/rockchip: vop: Fix a dereferenced before check warning The 'state' can't be NULL, we should …

Dec 4, 2024
CVE-2024-53128
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sched/task_stack: fix object_is_on_stack() for KASAN tagged pointers When CONFIG_KASAN_SW_TAGS and CONFIG_KASAN_STACK are enabled, the object_is_on_stack() …

Dec 4, 2024
CVE-2024-53127
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Revert "mmc: dw_mmc: Fix IDMAC operation with pages bigger than 4K" The commit 8396c793ffdf ("mmc: …

Dec 4, 2024
CVE-2024-40745
5.4 MEDIUM

Reflected Cross site scripting vulnerability in Convert Forms component for Joomla in versions before 4.4.8.

Dec 4, 2024
CVE-2024-7488
5.3 MEDIUM

Integer Overflow or Wraparound, Improper Validation of Specified Quantity in Input vulnerability in RestApp Inc. Online Ordering System allows Integer Attacks. This issue affects Online …

Dec 4, 2024
CVE-2024-53125
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: sync_linked_regs() must preserve subreg_def Range propagation must not affect subreg_def marks, otherwise the following …

Dec 4, 2024
CVE-2024-12138
6.3 MEDIUM

A vulnerability classified as critical was found in horilla up to 1.2.1. This vulnerability affects the function request_new/get_employee_shift/create_reimbursement/key_result_current_value_update/create_meetings/create_skills. The manipulation leads to deserialization. The attack …

Dec 4, 2024
CVE-2024-11935
6.4 MEDIUM

The Email Address Obfuscation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘class’ parameter in all versions up to, and including, 1.0.1 …

Dec 4, 2024
CVE-2024-8962
6.4 MEDIUM

The WPBITS Addons For Elementor Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, …

Dec 4, 2024
CVE-2024-54157
4.3 MEDIUM

In JetBrains YouTrack before 2024.3.52635 potential ReDoS was possible due to vulnerable RegExp in Ruby syntax detector

Dec 4, 2024
CVE-2024-54156
4.2 MEDIUM

In JetBrains YouTrack before 2024.3.52635 multiple merge functions were vulnerable to prototype pollution attack

Dec 4, 2024
CVE-2024-11854
6.4 MEDIUM

The Listdom – Business Directory and Classified Ads Listings WordPress Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘shortcode’ parameter in …

Dec 4, 2024
CVE-2024-11814
6.1 MEDIUM

The Additional Custom Order Status for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the wfwp_wcos_delete_finished, wfwp_wcos_delete_fallback_finished, wfwp_wcos_delete_fallback_orders_updated, and wfwp_wcos_delete_fallback_status parameters in …

Dec 4, 2024
CVE-2024-5020
6.4 MEDIUM

Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions 1.3.4 to 3.5.7) in various versions due …

Dec 4, 2024
CVE-2024-11880
6.4 MEDIUM

The B Testimonial – testimonial plugin for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'b_testimonial' shortcode in all versions …

Dec 4, 2024
CVE-2024-10787
4.3 MEDIUM

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.4.4 via the 'elementor-template' …

Dec 4, 2024
CVE-2024-11903
6.4 MEDIUM

The WP eCards plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ecard' shortcode in all versions up to, and including, 1.3.904 …

Dec 4, 2024
CVE-2024-11769
6.4 MEDIUM

The Flower Delivery by Florist One plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'flower-delivery' shortcode in all versions up to, …

Dec 4, 2024
CVE-2024-11466
6.1 MEDIUM

The Intro Tour Tutorial DeepPresentation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, …

Dec 4, 2024
CVE-2024-10664
4.3 MEDIUM

The Knowledge Base documentation & wiki plugin – BasePress Docs plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability …

Dec 4, 2024
CVE-2023-6978
6.1 MEDIUM

The WP Job Manager – Company Profiles plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'company' parameter in all versions up to, …

Dec 4, 2024
CVE-2023-52944
4.3 MEDIUM

Incorrect authorization vulnerability in ActionRule webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to perform limited actions on the …

Dec 4, 2024
CVE-2023-52943
4.3 MEDIUM

Incorrect authorization vulnerability in Alert.Setting webapi component in Synology Surveillance Station before 9.2.0-11289 and 9.2.0-9289 allows remote authenticated users to to perform limited actions on …

Dec 4, 2024
CVE-2024-12099
4.3 MEDIUM

The Dollie Hub – Build Your Own WordPress Cloud Platform plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, …

Dec 4, 2024
CVE-2024-10885
6.4 MEDIUM

The SearchIQ – The Search Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'siq_searchbox' shortcode in all versions up to, …

Dec 4, 2024
CVE-2024-11897
6.4 MEDIUM

The Contact Form, Survey & Form Builder – MightyForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mightyforms' shortcode in all …

Dec 4, 2024
CVE-2024-11813
6.1 MEDIUM

The Pulsating Chat Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.1. This is due to …

Dec 4, 2024
CVE-2024-11807
6.1 MEDIUM

The NPS computy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'data1' and 'data2' parameters in all versions up to, and including, …

Dec 4, 2024
CVE-2024-11747
6.4 MEDIUM

The Responsive Videos plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'somryv' shortcode in all versions up to, and including, 2.1 …

Dec 4, 2024
CVE-2024-11093
5.5 MEDIUM

The SG Helper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in version 1.0 due to insufficient input sanitization and …

Dec 4, 2024
CVE-2024-10832
6.1 MEDIUM

The Posti Shipping plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the account_number and secret_key parameters in all versions up to, and including, …

Dec 4, 2024
CVE-2024-10663
4.3 MEDIUM

The Eleblog – Elementor Blog And Magazine Addons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

Dec 4, 2024
CVE-2024-45206
6.5 MEDIUM

A vulnerability in Veeam Service Provider Console has been identified, which allows to perform arbitrary HTTP requests to arbitrary hosts of the network and get …

Dec 4, 2024
CVE-2024-45204
4.3 MEDIUM

A vulnerability exists where a low-privileged user can exploit insufficient permissions in credential handling to leak NTLM hashes of saved credentials. The exploitation involves using …

Dec 4, 2024
CVE-2024-42457
6.5 MEDIUM

A vulnerability in Veeam Backup & Replication allows users with certain operator roles to expose saved credentials by leveraging a combination of methods in a …

Dec 4, 2024
CVE-2024-42451
6.5 MEDIUM

A vulnerability in Veeam Backup & Replication allows low-privileged users to leak all saved credentials in plaintext. This is achieved by calling a series of …

Dec 4, 2024
CVE-2024-11985
4.4 MEDIUM

An improper input validation vulnerability leads to device crashes in certain ASUS router models. Refer to the '12/03/2024 ASUS Router Improper Input Validation' section on …

Dec 4, 2024
CVE-2024-53672
4.7 MEDIUM

A vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploit could …

Dec 3, 2024
CVE-2024-51773
4.8 MEDIUM

A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authenticated remote Attacker to conduct a stored cross-site scripting …

Dec 3, 2024
CVE-2024-51772
6.4 MEDIUM

An authenticated RCE vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. Successful …

Dec 3, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.