CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-52548
6.7 MEDIUM

An attacker who can execute arbitrary Operating Systems commands, can bypass code signing enforcements in the kernel, and execute arbitrary native code. This vulnerability has …

Dec 3, 2024
CVE-2024-52546
5.3 MEDIUM

An unauthenticated attacker can perform a null pointer dereference in the DHIP Service (UDP port 37810). This vulnerability has been resolved in firmware version 2.800.0000000.8.R.20241111.

Dec 3, 2024
CVE-2024-52545
6.5 MEDIUM

An unauthenticated attacker can perform an out of bounds heap read in the IQ Service (TCP port 9876). This vulnerability has been resolved in firmware …

Dec 3, 2024
CVE-2024-45676
4.3 MEDIUM

IBM Cognos Controller 11.0.0 and 11.0.1 could allow an authenticated user to upload insecure files, due to insufficient file type distinction.

Dec 3, 2024
CVE-2024-41776
6.5 MEDIUM

IBM Cognos Controller 11.0.0 and 11.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from …

Dec 3, 2024
CVE-2024-41775
5.9 MEDIUM

IBM Cognos Controller 11.0.0 and 11.0.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

Dec 3, 2024
CVE-2024-25020
5.5 MEDIUM

IBM Cognos Controller 11.0.0 and 11.0.1 is vulnerable to malicious file upload by allowing unrestricted filetype attachments in the Journal entry page. Attackers can make …

Dec 3, 2024
CVE-2024-53867
4.3 MEDIUM

Synapse is an open-source Matrix homeserver. The Sliding Sync feature on Synapse versions between 1.113.0rc1 and 1.120.0 can leak partial room state changes to users …

Dec 3, 2024
CVE-2024-52815
5.3 MEDIUM

Synapse is an open-source Matrix homeserver. Synapse versions before 1.120.1 fail to properly validate invites received over federation. This vulnerability allows a malicious server to …

Dec 3, 2024
CVE-2024-37303
5.3 MEDIUM

Synapse is an open-source Matrix homeserver. Synapse before version 1.106 allows, by design, unauthenticated remote participants to trigger a download and caching of remote media …

Dec 3, 2024
CVE-2024-25036
4.3 MEDIUM

IBM Cognos Controller 11.0.0 and 11.0.1 could allow an authenticated user with local access to bypass security allowing users to circumvent restrictions imposed on input …

Dec 3, 2024
CVE-2024-25035
5.3 MEDIUM

IBM Cognos Controller 11.0.0 and 11.0.1 exposes server details that could allow an attacker to obtain information of the application environment to conduct further attacks.

Dec 3, 2024
CVE-2024-25019
5.5 MEDIUM

IBM Cognos Controller 11.0.0 and 11.0.1 could be vulnerable to malicious file upload by not validating the type of file uploaded to Journal entry attachments. …

Dec 3, 2024
CVE-2021-29892
5.9 MEDIUM

IBM Cognos Controller 11.0.0 and 11.0.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport …

Dec 3, 2024
CVE-2024-53257
4.9 MEDIUM

Vitess is a database clustering system for horizontal scaling of MySQL. The /debug/querylogz and /debug/env pages for vtgate and vttablet do not properly escape user …

Dec 3, 2024
CVE-2024-11200
6.1 MEDIUM

The Goodlayers Core plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘font-family’ parameter in all versions up to, and including, 2.0.7 due …

Dec 3, 2024
CVE-2024-9978
5.5 MEDIUM

in OpenHarmony v4.1.1 and prior versions allow a local attacker cause information leak through out-of-bounds Read.

Dec 3, 2024
CVE-2024-12082
5.5 MEDIUM

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.

Dec 3, 2024
CVE-2024-11326
6.1 MEDIUM

The Campaign Monitor Forms by Optin Cat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping …

Dec 3, 2024
CVE-2024-12062
4.3 MEDIUM

The Charity Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.3.3 via the 'nacharity_elementor_template' shortcode …

Dec 3, 2024
CVE-2024-11782
6.4 MEDIUM

The WP Mailster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mst_subscribe' shortcode in all versions up to, and including, 1.8.17.0 …

Dec 3, 2024
CVE-2024-11325
5.2 MEDIUM

The AWeber Forms by Optin Cat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on …

Dec 3, 2024
CVE-2024-11866
6.4 MEDIUM

The BMLT Tabbed Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bmlt_tabbed_map' shortcode in all versions up to, and including, …

Dec 3, 2024
CVE-2024-11844
4.3 MEDIUM

The IdeaPush plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the idea_push_taxonomy_save_routine function in all versions …

Dec 3, 2024
CVE-2024-11898
6.4 MEDIUM

The Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more plugin for WordPress is vulnerable to Stored Cross-Site …

Dec 3, 2024
CVE-2024-11853
6.4 MEDIUM

The jAlbum Bridge plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ar’ parameter in all versions up to, and including, 2.0.16 due …

Dec 3, 2024
CVE-2024-11805
6.1 MEDIUM

The Quick License Manager – WooCommerce Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'submit_qlm_products' parameter in all versions up to, …

Dec 3, 2024
CVE-2024-11732
6.5 MEDIUM

The BP Profile Shortcodes Extra plugin for WordPress is vulnerable to time-based SQL Injection via the ‘tab’ parameter in all versions up to, and including, …

Dec 3, 2024
CVE-2024-11707
6.1 MEDIUM

The My auctions allegro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 3.6.17 …

Dec 3, 2024
CVE-2024-11461
6.1 MEDIUM

The Form Data Collector plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 2.2.3 …

Dec 3, 2024
CVE-2024-11453
6.4 MEDIUM

The WordPress Pinterest Plugin – Make a Popup, User Profile, Masonry and Gallery Layout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Dec 3, 2024
CVE-2024-9058
6.4 MEDIUM

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Dec 3, 2024
CVE-2024-49421
4.3 MEDIUM

Path traversal in Quick Share Agent prior to version 3.5.14.47 in Android 12, 3.5.19.41 in Android 13, and 3.5.19.42 in Android 14 allows adjacent attackers …

Dec 3, 2024
CVE-2024-49419
4.3 MEDIUM

Insufficient verification of url authenticity in GamingHub prior to version 6.1.03.4 in Korea, 7.1.02.4 in Global allows remote attackers to load an arbitrary URL in …

Dec 3, 2024
CVE-2024-49418
6.5 MEDIUM

Insufficient verification of url authenticity in GamingHub prior to version 6.1.03.4 in Korea, 7.1.02.4 in Global allows remote attackers to enable JavaScript in its webview.

Dec 3, 2024
CVE-2024-49416
4.0 MEDIUM

Use of implicit intent for sensitive communication in SmartThings prior to version 1.8.21 allows local attackers to get sensitive information.

Dec 3, 2024
CVE-2024-49412
5.5 MEDIUM

Improper input validation in Settings prior to SMR Dec-2024 Release 1 allows local attackers to broadcast signal for discovering Bluetooth on Galaxy Watch.

Dec 3, 2024
CVE-2024-49411
4.3 MEDIUM

Path Traversal in ThemeCenter prior to SMR Dec-2024 Release 1 allows physical attackers to copy apk files to arbitrary path with ThemeCenter privilege.

Dec 3, 2024
CVE-2024-49410
5.9 MEDIUM

Out-of-bounds write in libswmfextractor.so prior to SMR Dec-2024 Release 1 allows local attackers to execute arbitrary code.

Dec 3, 2024
CVE-2024-10893
4.8 MEDIUM

The WP Booking Calendar WordPress plugin before 10.6.5 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Dec 3, 2024
CVE-2024-10484
6.4 MEDIUM

The Spectra – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Team' widget in all versions up to, …

Dec 3, 2024
CVE-2024-9694
6.4 MEDIUM

The CMSMasters Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.14.7 due …

Dec 3, 2024
CVE-2024-9197
4.9 MEDIUM

A post-authentication buffer overflow vulnerability in the parameter "action" of the CGI program in Zyxel VMG3625-T50B firmware versions through V5.50(ABPM.9.2)C0 could allow an authenticated attacker …

Dec 3, 2024
CVE-2018-9449
5.5 MEDIUM

In process_service_search_attr_rsp of sdp_discovery.cc, there is a possible out of bound read due to a missing bounds check. This could lead to local information disclosure …

Dec 3, 2024
CVE-2018-9441
5.5 MEDIUM

In sdp_copy_raw_data of sdp_discovery.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure …

Dec 3, 2024
CVE-2024-53988
6.1 MEDIUM

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with …

Dec 2, 2024
CVE-2024-53987
6.1 MEDIUM

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with …

Dec 2, 2024
CVE-2024-53986
6.1 MEDIUM

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with …

Dec 2, 2024
CVE-2024-53985
6.1 MEDIUM

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. There is a possible XSS vulnerability with certain configurations of Rails::HTML::Sanitizer 1.6.0 when used with …

Dec 2, 2024
CVE-2018-9435
5.5 MEDIUM

In gatt_process_error_rsp of gatt_cl.cc, there is a possible out of bound read due to a missing bounds check. This could lead to local information disclosure …

Dec 2, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.