CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2018-9353
6.5 MEDIUM

In ihevcd_parse_slice_data of ihevcd_parse_slice.c there is a possible heap buffer out of bound read due to a missing bounds check. This could lead to remote …

Nov 27, 2024
CVE-2018-9352
6.5 MEDIUM

In ihevcd_allocate_dynamic_bufs of ihevcd_api.c there is a possible resource exhaustion due to integer overflow. This could lead to remote denial of service with no additional …

Nov 27, 2024
CVE-2018-9351
6.5 MEDIUM

In ih264e_fmt_conv_420p_to_420sp of ih264e_fmt_conv.c there is a possible out of bound read due to missing bounds check. This could lead to remote denial of service …

Nov 27, 2024
CVE-2024-53859
6.5 MEDIUM

go-gh is a Go module for interacting with the `gh` utility and the GitHub API from the command line. A security vulnerability has been identified …

Nov 27, 2024
CVE-2024-53858
6.5 MEDIUM

The gh cli is GitHub’s official command line tool. A security vulnerability has been identified in the GitHub CLI that could leak authentication tokens when …

Nov 27, 2024
CVE-2024-53260
6.8 MEDIUM

Autolab is a course management service that enables auto-graded programming assignments. A user can modify their first and or last name to include a valid …

Nov 27, 2024
CVE-2018-9350
6.5 MEDIUM

In ih264d_assign_pic_num of ih264d_utils.c there is a possible out of bound read due to missing bounds check. This could lead to a denial of service …

Nov 27, 2024
CVE-2018-9349
6.5 MEDIUM

In mv_err_cost of mcomp.c there is a possible out of bounds read due to missing bounds check. This could lead to denial of service with …

Nov 27, 2024
CVE-2017-13321
5.5 MEDIUM

In SensorService::isDataInjectionEnabled of frameworks/native/services/sensorservice/SensorService.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure …

Nov 27, 2024
CVE-2017-13320
6.5 MEDIUM

In impeg2d_bit_stream_flush() of libmpeg2dec there is a possible OOB read due to a missing bounds check. This could lead to Remote DoS with no additional …

Nov 27, 2024
CVE-2024-54004
4.3 MEDIUM

Jenkins Filesystem List Parameter Plugin 0.0.14 and earlier does not restrict the path used for the File system objects list Parameter, allowing attackers with Item/Configure …

Nov 27, 2024
CVE-2024-51228
6.8 MEDIUM

An issue in TOTOLINK-CX-A3002RU V1.0.4-B20171106.1512 and TOTOLINK-CX-N150RT V2.1.6-B20171121.1002 and TOTOLINK-CX-N300RT V2.1.6-B20170724.1420 and TOTOLINK-CX-N300RT V2.1.8-B20171113.1408 and TOTOLINK-CX-N300RT V2.1.8-B20191010.1107 and TOTOLINK-CX-N302RE V2.0.2-B20170511.1523 allows a remote attacker to …

Nov 27, 2024
CVE-2024-37816
4.2 MEDIUM

Quectel EC25-EUX EC25EUXGAR08A05M1G was discovered to contain a stack overflow.

Nov 27, 2024
CVE-2024-21703
6.4 MEDIUM

This Medium severity Security Misconfiguration vulnerability was introduced in version 8.8.1 of Confluence Data Center and Server for Windows installations. This Security Misconfiguration vulnerability, with …

Nov 27, 2024
CVE-2024-11860
6.5 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Best House Rental Management System 1.0. This affects an unknown part of the file /rental/ajax.php?action=delete_tenant …

Nov 27, 2024
CVE-2024-46055
4.8 MEDIUM

OpenVidReview 1.0 is vulnerable to Cross Site Scripting (XSS) in review names.

Nov 27, 2024
CVE-2024-53635
4.8 MEDIUM

A Reflected Cross Site Scripting (XSS) vulnerability was found in /covid-tms/patient-search-report.php in PHPGurukul COVID 19 Testing Management System v1.0, which allows remote attackers to execute …

Nov 27, 2024
CVE-2024-42326
4.4 MEDIUM

There was discovered a use after free bug in browser.c in the es_browser_get_variant function

Nov 27, 2024
CVE-2024-11009
4.9 MEDIUM

The Internal Linking for SEO traffic & Ranking – Auto internal links (100% automatic) plugin for WordPress is vulnerable to time-based SQL Injection via the …

Nov 27, 2024
CVE-2024-11025
5.4 MEDIUM

An authenticated attacker with low privileges may use a SQL Injection vulnerability in the affected products administration panel to gain read and write access to …

Nov 27, 2024
CVE-2024-10521
4.3 MEDIUM

The WordPress Contact Forms by Cimatti plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.2. This is …

Nov 27, 2024
CVE-2024-10895
6.4 MEDIUM

The Counter Up – Animated Number Counter & Milestone Showcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'lgx-counter' shortcode in …

Nov 27, 2024
CVE-2024-10580
5.3 MEDIUM

The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized form submissions due to a missing capability check on …

Nov 27, 2024
CVE-2024-10175
6.4 MEDIUM

The Pricing Tables For WPBakery Page Builder (formerly Visual Composer) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wdo_pricing_tables shortcode in …

Nov 27, 2024
CVE-2024-11219
5.3 MEDIUM

The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Path Traversal in all versions up …

Nov 27, 2024
CVE-2024-11083
5.3 MEDIUM

The ProfilePress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.15.18 via the WordPress core search feature. …

Nov 27, 2024
CVE-2024-43784
5.7 MEDIUM

lakeFS is an open-source tool that transforms object storage into a Git-like repository. Existing lakeFS users who have issued credentials to users who have been …

Nov 26, 2024
CVE-2024-11743
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in SourceCodester Best House Rental Management System 1.0. Affected is an unknown function of the file …

Nov 26, 2024
CVE-2024-10240
5.3 MEDIUM

An issue has been discovered in GitLab EE affecting all versions starting from 17.3 before 17.3.7, all versions starting from 17.4 before 17.4.4, all versions …

Nov 26, 2024
CVE-2024-8237
6.5 MEDIUM

A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions prior to 12.6 prior to 17.4.5, 17.5 prior to 17.5.3, …

Nov 26, 2024
CVE-2024-8177
5.3 MEDIUM

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.4.5, starting from 17.5 prior to 17.5.3, starting from 17.6 …

Nov 26, 2024
CVE-2024-53844
6.3 MEDIUM

E.D.D.I (Enhanced Dialog Driven Interface) is a middleware to connect and manage LLM API bots. A path traversal vulnerability exists in the backup export functionality …

Nov 26, 2024
CVE-2024-53620
4.8 MEDIUM

A cross-site scripting (XSS) vulnerability in the Article module of SPIP v4.3.3 allows authenticated attackers to execute arbitrary web scripts or HTML via injecting a …

Nov 26, 2024
CVE-2024-53619
6.3 MEDIUM

An authenticated arbitrary file upload vulnerability in the Documents module of SPIP v4.3.3 allows attackers to execute arbitrary code via uploading a crafted PDF file.

Nov 26, 2024
CVE-2024-53267
5.5 MEDIUM

sigstore-java is a sigstore java client for interacting with sigstore infrastructure. sigstore-java has insufficient verification for a situation where a validly-signed but "mismatched" bundle is …

Nov 26, 2024
CVE-2024-11828
4.3 MEDIUM

A denial of service (DoS) condition was discovered in GitLab CE/EE affecting all versions from 13.2.4 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. …

Nov 26, 2024
CVE-2024-11669
6.5 MEDIUM

An issue was discovered in GitLab CE/EE affecting all versions from 16.9.8 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. Certain API endpoints could …

Nov 26, 2024
CVE-2024-11668
4.2 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. Long-lived connections could …

Nov 26, 2024
CVE-2024-51058
6.2 MEDIUM

Local File Inclusion (LFI) vulnerability has been discovered in TCPDF 6.7.5. This vulnerability enables a user to read arbitrary files from the server's file system …

Nov 26, 2024
CVE-2024-10878
6.1 MEDIUM

The Sugar Calendar – Simple Event Management plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without …

Nov 26, 2024
CVE-2024-53365
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability was identified in PHPGURUKUL Vehicle Parking Management System v1.13 in /users/profile.php. This vulnerability allows authenticated users to inject malicious …

Nov 26, 2024
CVE-2024-52337
5.5 MEDIUM

A log spoofing flaw was found in the Tuned package due to improper sanitization of some API arguments. This flaw allows an attacker to pass …

Nov 26, 2024
CVE-2024-36463
6.5 MEDIUM

The implementation of atob in "Zabbix JS" allows to create a string with arbitrary content and use it to access internal properties of objects.

Nov 26, 2024
CVE-2024-9929
4.3 MEDIUM

A vulnerability exists in NSD570 that allows any authenticated user to access all device logs disclosing login information with timestamps.

Nov 26, 2024
CVE-2024-9928
5.3 MEDIUM

A vulnerability exists in NSD570 login panel that does not restrict excessive authentication attempts. If exploited, this could cause account takeover and unauthorized access to …

Nov 26, 2024
CVE-2024-8236
6.4 MEDIUM

The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter of …

Nov 26, 2024
CVE-2024-53976
5.4 MEDIUM

Under certain circumstances, navigating to a webpage would result in the address missing from the location URL bar, making it unclear what the URL was …

Nov 26, 2024
CVE-2024-53975
5.4 MEDIUM

Accessing a non-secure HTTP site that uses a non-existent port may cause the SSL padlock icon in the location URL bar to, misleadingly, appear secure. …

Nov 26, 2024
CVE-2024-11708
6.5 MEDIUM

Missing thread synchronization primitives could have led to a data race on members of the PlaybackParams structure. This vulnerability affects Firefox < 133 and Thunderbird …

Nov 26, 2024
CVE-2024-11706
6.5 MEDIUM

A null pointer dereference may have inadvertently occurred in `pk12util`, and specifically in the `SEC_ASN1DecodeItem_Util` function, when handling malformed or improperly formatted input files. This …

Nov 26, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.