CVE Database

46624+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-52566
7.8 HIGH

A vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versions < V14.3.0.12), Teamcenter Visualization V2312 (All versions …

Nov 18, 2024
CVE-2024-52565
7.8 HIGH

A vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versions < V14.3.0.12), Teamcenter Visualization V2312 (All versions …

Nov 18, 2024
CVE-2024-52424
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in sureshdsk wp-login customizer wp-login-customizer allows Stored XSS.This issue affects wp-login customizer: from n/a through <= 1.0.

Nov 18, 2024
CVE-2021-1285
7.4 HIGH

Multiple Cisco&nbsp;products are affected by a vulnerability in the Ethernet Frame Decoder of the Snort detection engine that could allow an unauthenticated, adjacent attacker to …

Nov 18, 2024
CVE-2020-27124
8.6 HIGH

A vulnerability in the SSL/TLS handler of Cisco&nbsp;Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause the affected device to reload …

Nov 18, 2024
CVE-2020-26074
7.8 HIGH

A vulnerability in system file transfer functions of Cisco&nbsp;SD-WAN vManage Software could allow an authenticated, local attacker to gain escalated privileges on the underlying operating …

Nov 18, 2024
CVE-2020-26073
7.5 HIGH

A vulnerability in the application data endpoints of Cisco&nbsp;SD-WAN vManage Software could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability …

Nov 18, 2024
CVE-2020-26071
8.4 HIGH

A vulnerability in the CLI of Cisco&nbsp;SD-WAN Software could allow an authenticated, local attacker to create or overwrite arbitrary files on an affected device, which …

Nov 18, 2024
CVE-2024-52436
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal Post SMTP post-smtp allows Blind SQL Injection.This issue affects …

Nov 18, 2024
CVE-2024-52435
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjada WPDM – Premium Packages wpdm-premium-packages.This issue affects WPDM – Premium …

Nov 18, 2024
CVE-2024-52428
8.1 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Peter Ads Booster by Ads Pro free-wp-booster-by-ads-pro allows PHP …

Nov 18, 2024
CVE-2024-28058
7.5 HIGH

In RSA NetWitness (NW) Platform before 12.5.1, even when an administrator revokes the access of a specific user with an active session, an internal threat …

Nov 18, 2024
CVE-2024-11318
7.5 HIGH

An IDOR (Insecure Direct Object Reference) vulnerability has been discovered in AbsysNet, affecting version 2.3.1. This vulnerability could allow a remote attacker to obtain the …

Nov 18, 2024
CVE-2024-3370
8.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Egebilgi Software Website Template allows SQL Injection.This issue affects Website Template: …

Nov 18, 2024
CVE-2024-42386
8.2 HIGH

Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation …

Nov 18, 2024
CVE-2024-42384
7.5 HIGH

Integer Overflow or Wraparound vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault …

Nov 18, 2024
CVE-2024-41974
7.1 HIGH

A low privileged remote attacker may modify the BACNet service properties due to incorrect permission assignment for critical resources which may lead to a DoS …

Nov 18, 2024
CVE-2024-41973
8.1 HIGH

A low privileged remote attacker can specify an arbitrary file on the filesystem which may lead to an arbitrary file writes with root privileges.

Nov 18, 2024
CVE-2024-41971
8.1 HIGH

A low privileged remote attacker can overwrite an arbitrary file on the filesystem leading to a DoS and data loss.

Nov 18, 2024
CVE-2023-39179
7.5 HIGH

A flaw was found within the handling of SMB2 read requests in the kernel ksmbd module. The issue results from the lack of proper validation …

Nov 18, 2024
CVE-2024-48962
8.8 HIGH

Improper Control of Generation of Code ('Code Injection'), Cross-Site Request Forgery (CSRF), : Improper Neutralization of Special Elements Used in a Template Engine vulnerability in …

Nov 18, 2024
CVE-2024-45791
7.5 HIGH

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache HertzBeat. This issue affects Apache HertzBeat: before 1.6.1. Users are recommended to upgrade to …

Nov 18, 2024
CVE-2024-45505
8.8 HIGH

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache HertzBeat (incubating). This vulnerability can only be exploited by authorized attackers. …

Nov 18, 2024
CVE-2024-41969
8.8 HIGH

A low privileged remote attacker may modify the configuration of the CODESYS V3 service through a missing authentication vulnerability which could lead to full system …

Nov 18, 2024
CVE-2024-41967
8.1 HIGH

A low privileged remote attacker may modify the boot mode configuration setup of the device, leading to modification of the firmware upgrade process or a …

Nov 18, 2024
CVE-2024-41151
8.8 HIGH

Deserialization of Untrusted Data vulnerability in Apache HertzBeat. This vulnerability can only be exploited by authorized attackers. This issue affects Apache HertzBeat: before 1.6.1. Users …

Nov 18, 2024
CVE-2024-49574
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8123 are vulnerable to SQL Injection in the reports module.

Nov 18, 2024
CVE-2024-52946
8.8 HIGH

An issue was discovered in LemonLDAP::NG before 2.20.1. An Improper Check during session refresh allows an authenticated user to raise their authentication level if the …

Nov 18, 2024
CVE-2024-52945
7.8 HIGH

An issue was discovered in Veritas NetBackup before 10.5. This only applies to NetBackup components running on a Windows Operating System. If a user executes …

Nov 18, 2024
CVE-2024-11310
7.5 HIGH

The DVC from TRCore has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.

Nov 18, 2024
CVE-2024-11309
7.5 HIGH

The DVC from TRCore has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.

Nov 18, 2024
CVE-2024-52940
7.5 HIGH

AnyDesk through 8.1.0 on Windows, when Allow Direct Connections is enabled, inadvertently exposes a public IP address within network traffic. The attacker must know the …

Nov 18, 2024
CVE-2024-43704
8.4 HIGH

Software installed and run as a non-privileged user may conduct improper GPU system calls to gain access to the graphics buffers of a parent process.

Nov 18, 2024
CVE-2024-52920
7.5 HIGH

Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (infinite loop) via a malformed GETDATA message.

Nov 18, 2024
CVE-2024-52916
7.5 HIGH

Bitcoin Core before 0.15.0 allows a denial of service (OOM kill of a daemon process) via a flood of minimum difficulty headers.

Nov 18, 2024
CVE-2024-52915
7.5 HIGH

Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (memory consumption) via a crafted INV message.

Nov 18, 2024
CVE-2024-52914
7.5 HIGH

In Bitcoin Core before 0.18.0, a node could be stalled for hours when processing the orphans of a crafted unconfirmed transaction.

Nov 18, 2024
CVE-2024-52912
7.5 HIGH

Bitcoin Core before 0.21.0 allows a network split that is resultant from an integer overflow (calculating the time offset for newly connecting peers) and an …

Nov 18, 2024
CVE-2019-25220
7.5 HIGH

Bitcoin Core before 24.0.1 allows remote attackers to cause a denial of service (daemon crash) via a flood of low-difficulty header chains (aka a "Chain …

Nov 18, 2024
CVE-2024-0793
7.7 HIGH

A flaw was found in kube-controller-manager. This issue occurs when the initial application of a HPA config YAML lacking a .spec.behavior.scaleUp block causes a denial …

Nov 17, 2024
CVE-2023-4639
7.4 HIGH

A flaw was found in Undertow, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct …

Nov 17, 2024
CVE-2020-25720
7.5 HIGH

A vulnerability was found in Samba where a delegated administrator with permission to create objects in Active Directory can write to all attributes of the …

Nov 17, 2024
CVE-2024-52876
7.5 HIGH

Holy Stone Remote ID Module HSRID01, firmware distributed with the Drone Go2 mobile application before 1.1.8, allows unauthenticated "remote power off" actions (in broadcast mode) …

Nov 17, 2024
CVE-2024-52872
7.5 HIGH

In Flagsmith before 2.134.1, the get_document endpoint is not correctly protected by permissions.

Nov 17, 2024
CVE-2024-52871
7.5 HIGH

In Flagsmith before 2.134.1, it is possible to bypass the ALLOW_REGISTRATION_WITHOUT_INVITE setting.

Nov 17, 2024
CVE-2024-52867
8.1 HIGH

guix-daemon in GNU Guix before 5ab3c4c allows privilege escalation because build outputs are accessible by local users before file metadata concerns (e.g., for setuid and …

Nov 17, 2024
CVE-2024-52415
8.8 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in skipstorm SK WP Settings Backup sk-wp-settings-backup allows Object Injection.This issue affects SK WP Settings Backup: from n/a through <= …

Nov 16, 2024
CVE-2024-9887
7.2 HIGH

The Login using WordPress Users ( WP as SAML IDP ) plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in …

Nov 16, 2024
CVE-2024-10645
7.5 HIGH

The Blogger 301 Redirect plugin for WordPress is vulnerable to blind time-based SQL Injection via the ‘br’ parameter in all versions up to, and including, …

Nov 16, 2024
CVE-2024-10728
8.8 HIGH

The Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing capability …

Nov 16, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.