CVE Database

4634+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-9203
2.5 LOW

A vulnerability, which was classified as problematic, has been found in Enpass Password Manager up to 6.9.5 on Windows. This issue affects some unknown processing. …

Sep 26, 2024
CVE-2024-47145
3.1 LOW

Mattermost versions 9.5.x <= 9.5.8 fail to properly authorize access to archived channels when viewing archived channels is disabled, which allows an attacker to view …

Sep 26, 2024
CVE-2024-47003
3.1 LOW

Mattermost versions 9.11.x <= 9.11.0 and 9.5.x <= 9.5.8 fail to validate that the message of the permalink post is a string, which allows an …

Sep 26, 2024
CVE-2024-45843
3.1 LOW

Mattermost versions 9.5.x <= 9.5.8 fail to include the metadata endpoints of Oracle Cloud and Alibaba in the SSRF denylist, which allows an attacker to …

Sep 26, 2024
CVE-2023-25189
3.3 LOW

BTS is affected by information disclosure vulnerability where mobile network operator personnel connected over BTS Web Element Manager, regardless of the access privileges, having a …

Sep 25, 2024
CVE-2024-8350
2.7 LOW

The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to user group add due to a missing capability check on the /wp-json/ulgm_management/v1/add_user/ REST API …

Sep 25, 2024
CVE-2024-45599
3.8 LOW

Cursor is an artificial intelligence code editor. Prior to version 0.41.0, if a user on macOS has granted Cursor access to the camera or microphone, …

Sep 25, 2024
CVE-2023-5359
3.7 LOW

The W3 Total Cache plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.5 via Google OAuth API secrets …

Sep 25, 2024
CVE-2022-43845
3.7 LOW

IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A …

Sep 25, 2024
CVE-2024-8263
2.7 LOW

An improper privilege management vulnerability allowed arbitrary workflows to be committed using an improperly scoped PAT through the use of nested tags. This vulnerability affected …

Sep 23, 2024
CVE-2024-9092
3.5 LOW

A vulnerability was found in SourceCodester Profile Registration without Reload Refresh 1.0. It has been rated as problematic. Affected by this issue is some unknown …

Sep 23, 2024
CVE-2024-45453
3.7 LOW

Authentication Bypass by Spoofing vulnerability in Peter Hardy-vanDoorn Maintenance Redirect jf3-maintenance-mode.This issue affects Maintenance Redirect: from n/a through <= 2.0.1.

Sep 23, 2024
CVE-2024-9089
3.5 LOW

A vulnerability was found in SourceCodester Modern Loan Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file update_loan_record.php. …

Sep 23, 2024
CVE-2024-9084
3.5 LOW

A vulnerability classified as problematic was found in code-projects Blood Bank System 1.0. This vulnerability affects unknown code of the file bbms.php. The manipulation of …

Sep 22, 2024
CVE-2024-9083
2.4 LOW

A vulnerability classified as problematic has been found in SourceCodester Employee Management System 1.0. This affects an unknown part of the file /Admin/add-admin.php. The manipulation …

Sep 22, 2024
CVE-2024-9077
3.5 LOW

A vulnerability classified as problematic has been found in dingfangzu up to 29d67d9044f6f93378e6eb6ff92272217ff7225c. Affected is an unknown function of the file scripts/order.js of the component …

Sep 22, 2024
CVE-2024-9075
2.6 LOW

A vulnerability was found in Stirling-Tools Stirling-PDF up to 0.28.3. It has been declared as problematic. This vulnerability affects unknown code of the component Markdown-to-PDF. …

Sep 21, 2024
CVE-2024-9048
3.1 LOW

A vulnerability was found in y_project RuoYi up to 4.7.9. It has been declared as problematic. Affected by this vulnerability is the function SysUserServiceImpl of …

Sep 21, 2024
CVE-2024-8612
3.8 LOW

A flaw was found in QEMU, in the virtio-scsi, virtio-blk, and virtio-crypto devices. The size for virtqueue_push as set in virtio_scsi_complete_req / virtio_blk_req_complete / virito_crypto_req_complete …

Sep 20, 2024
CVE-2024-9040
2.3 LOW

A vulnerability, which was classified as problematic, was found in code-projects Blood Bank Management System 1.0. This affects an unknown part of the component Password …

Sep 20, 2024
CVE-2024-9033
3.5 LOW

A vulnerability has been found in SourceCodester Best House Rental Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality …

Sep 20, 2024
CVE-2024-9031
3.5 LOW

A vulnerability, which was classified as problematic, has been found in CodeCanyon CRMGo SaaS up to 7.2. This issue affects some unknown processing of the …

Sep 20, 2024
CVE-2024-9030
3.5 LOW

A vulnerability classified as problematic was found in CodeCanyon CRMGo SaaS 7.2. This vulnerability affects unknown code of the file /deal/{note_id}/note. The manipulation of the …

Sep 20, 2024
CVE-2024-9007
3.5 LOW

A vulnerability classified as problematic has been found in jeanmarc77 123solar 1.8.4.5. This affects an unknown part of the file /detailed.php. The manipulation of the …

Sep 19, 2024
CVE-2024-47058
2.9 LOW

With access to edit a Mautic form, the attacker can add Cross-Site Scripting stored in the html filed. This could be used to steal sensitive …

Sep 18, 2024
CVE-2024-46989
3.7 LOW

spicedb is an Open Source, Google Zanzibar-inspired permissions database to enable fine-grained authorization for customer applications. Multiple caveats over the same indirect subject type on …

Sep 18, 2024
CVE-2024-46794
3.3 LOW

In the Linux kernel, the following vulnerability has been resolved: x86/tdx: Fix data leak in mmio_read() The mmio_read() function makes a TDVMCALL to retrieve MMIO …

Sep 18, 2024
CVE-2024-46792
3.3 LOW

In the Linux kernel, the following vulnerability has been resolved: riscv: misaligned: Restrict user access to kernel memory raw_copy_{to,from}_user() do not call access_ok(), so this …

Sep 18, 2024
CVE-2024-8951
3.5 LOW

A vulnerability classified as problematic was found in SourceCodester Resort Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the file manage_fee.php. …

Sep 17, 2024
CVE-2024-44180
2.4 LOW

The issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18. An attacker with physical access may be able …

Sep 17, 2024
CVE-2024-44139
2.4 LOW

The issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18. An attacker with physical access may be able …

Sep 17, 2024
CVE-2024-40838
3.3 LOW

A privacy issue was addressed by moving sensitive data to a protected location. This issue is fixed in macOS Sequoia 15. A malicious app may …

Sep 17, 2024
CVE-2024-40830
3.3 LOW

This issue was addressed with improved data protection. This issue is fixed in iOS 18 and iPadOS 18. An app may be able to enumerate …

Sep 17, 2024
CVE-2024-40791
3.3 LOW

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 …

Sep 17, 2024
CVE-2024-6685
3.1 LOW

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.7 prior to 17.1.7, 17.2 prior to 17.2.5, and 17.3 prior to 17.3.2, …

Sep 16, 2024
CVE-2024-36261
3.5 LOW

Improper access control in Intel(R) RAID Web Console software all versions may allow an authenticated user to potentially enable denial of service via adjacent access.

Sep 16, 2024
CVE-2024-28170
3.3 LOW

Improper access control in Intel(R) RAID Web Console all versions may allow an authenticated user to potentially enable information disclosure via local access.

Sep 16, 2024
CVE-2023-25546
2.5 LOW

Out-of-bounds read in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable denial of service via local access.

Sep 16, 2024
CVE-2024-45835
2.5 LOW

Mattermost Desktop App versions <=5.8.0 fail to sufficiently configure Electron Fuses which allows an attacker to gather Chromium cookies or abuse other misconfigurations via remote/local …

Sep 16, 2024
CVE-2024-39772
3.7 LOW

Mattermost Desktop App versions <=5.8.0 fail to safeguard screen capture functionality which allows an attacker to silently capture high-quality screenshots via JavaScript APIs.

Sep 16, 2024
CVE-2024-46970
3.3 LOW

In JetBrains IntelliJ IDEA before 2024.1 hTML injection via the project name was possible

Sep 16, 2024
CVE-2024-8867
3.5 LOW

A vulnerability was found in Perfex CRM 3.1.6. It has been declared as problematic. This vulnerability affects unknown code of the file application/controllers/Clients.php of the …

Sep 15, 2024
CVE-2024-8865
3.5 LOW

A vulnerability was found in composiohq composio up to 0.5.8 and classified as problematic. Affected by this issue is the function path of the file …

Sep 15, 2024
CVE-2024-8863
3.5 LOW

A vulnerability, which was classified as problematic, was found in aimhubio aim up to 3.24. Affected is the function dangerouslySetInnerHTML of the file textbox.tsx of …

Sep 14, 2024
CVE-2024-8783
3.5 LOW

A vulnerability classified as problematic has been found in OpenTibiaBR MyAAC up to 0.8.16. Affected is an unknown function of the file system/pages/forum/new_post.php of the …

Sep 13, 2024
CVE-2024-36066
3.1 LOW

The CMP CLI client in KeyFactor EJBCA before 8.3.1 has only 6 octets of salt, and is thus not compliant with the security requirements of …

Sep 12, 2024
CVE-2024-6446
3.5 LOW

An issue has been discovered in GitLab affecting all versions starting from 17.1 to 17.1.7, 17.2 prior to 17.2.5 and 17.3 prior to 17.3.2. A …

Sep 12, 2024
CVE-2024-8708
3.5 LOW

A vulnerability was found in SourceCodester Best House Rental Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of …

Sep 12, 2024
CVE-2024-8694
3.8 LOW

A vulnerability, which was classified as problematic, was found in JFinalCMS up to 20240903. This affects the function update of the file /admin/template/update of the …

Sep 11, 2024
CVE-2024-8693
2.4 LOW

A vulnerability, which was classified as problematic, has been found in Kaon CG3000 1.01.43. Affected by this issue is some unknown functionality of the component …

Sep 11, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.