CVE Database

46624+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-9935
7.5 HIGH

The PDF Generator Addon for Elementor Page Builder plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.0.0 via …

Nov 16, 2024
CVE-2024-9849
8.8 HIGH

The Real3D Flipbook Lite – 3D FlipBook, PDF Viewer, PDF Embedder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type …

Nov 16, 2024
CVE-2024-9839
7.3 HIGH

The The Uix Slideshow plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.6.5. This is due to …

Nov 16, 2024
CVE-2024-9192
8.8 HIGH

The WordPress Video Robot - The Ultimate Video Importer plugin for WordPress is vulnerable to privilege escalation due to insufficient validation on user meta that …

Nov 16, 2024
CVE-2024-9500
7.8 HIGH

A maliciously crafted DLL file when placed in temporary files and folders that are leveraged by the Autodesk Installer could lead to escalation of privileges …

Nov 15, 2024
CVE-2017-13314
7.8 HIGH

In setAllowOnlyVpnForUids of NetworkManagementService.java, there is a possible security settings bypass due to a missing permission check. This could lead to local escalation of privilege …

Nov 15, 2024
CVE-2017-13312
7.8 HIGH

In createFromParcel of MediaCas.java, there is a possible parcel read/write mismatch due to improper input validation. This could lead to local escalation of privilege where …

Nov 15, 2024
CVE-2017-13310
7.8 HIGH

In createFromParcel of ViewPager.java, there is a possible read/write serialization issue leading to a permissions bypass. This could lead to local escalation of privilege where …

Nov 15, 2024
CVE-2024-49060
8.8 HIGH

Azure Stack HCI Elevation of Privilege Vulnerability

Nov 15, 2024
CVE-2024-44759
7.5 HIGH

An arbitrary file download vulnerability in the component /Doc/DownloadFile of NUS-M9 ERP Management Software v3.0.0 allows attackers to download arbitrary files and access sensitive information …

Nov 15, 2024
CVE-2024-11258
7.3 HIGH

A vulnerability classified as critical was found in 1000 Projects Beauty Parlour Management System 1.0. This vulnerability affects unknown code of the file /admin/index.php. The …

Nov 15, 2024
CVE-2024-11257
7.3 HIGH

A vulnerability classified as critical has been found in 1000 Projects Beauty Parlour Management System 1.0. This affects an unknown part of the file /admin/forgot-password.php. …

Nov 15, 2024
CVE-2024-11256
7.3 HIGH

A vulnerability was found in 1000 Projects Portfolio Management System MCA 1.0 and classified as critical. This issue affects some unknown processing of the file …

Nov 15, 2024
CVE-2024-51141
7.8 HIGH

An issue in TOTOLINK Bluetooth Wireless Adapter A600UB allows a local attacker to execute arbitrary code via the WifiAutoInstallDriver.exe and MSASN1.dll components.

Nov 15, 2024
CVE-2024-45969
7.5 HIGH

NULL pointer dereference in the MMS Client in MZ Automation LibIEC1850 before commit 7afa40390b26ad1f4cf93deaa0052fe7e357ef33 allows a malicious server to Cause a Denial-of-Service via the MMS …

Nov 15, 2024
CVE-2024-24431
7.5 HIGH

A reachable assertion in the ogs_nas_emm_decode function of Open5GS v2.7.0 allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet with …

Nov 15, 2024
CVE-2024-24426
7.5 HIGH

Reachable assertions in the NGAP_FIND_PROTOCOLIE_BY_ID function of OpenAirInterface Magma v1.8.0 and OAI EPC Federation v1.2.0 allow attackers to cause a Denial of Service (DoS) via …

Nov 15, 2024
CVE-2024-52508
8.2 HIGH

Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. When a user is trying to set up a mail account with an …

Nov 15, 2024
CVE-2024-46467
7.8 HIGH

By default, dedicated folders of ZONEPOINT for Windows up to 2024.1 can be accessed by other users to misuse technical files and make them perform …

Nov 15, 2024
CVE-2024-46466
7.8 HIGH

By default, dedicated folders of ZONECENTRAL for Windows up to 2024.3 or up to Q.2021.2 (ANSSI qualification submission) can be accessed by other users to …

Nov 15, 2024
CVE-2024-46465
7.8 HIGH

By default, dedicated folders of CRYHOD for Windows up to 2024.3 can be accessed by other users to misuse technical files and make them perform …

Nov 15, 2024
CVE-2024-46463
7.8 HIGH

By default, dedicated folders of ORIZON for Windows up to 2024.3 can be accessed by other users to misuse technical files and make them perform …

Nov 15, 2024
CVE-2024-46462
7.8 HIGH

By default, dedicated folders of ZEDMAIL for Windows up to 2024.3 can be accessed by other users to misuse technical files and make them perform …

Nov 15, 2024
CVE-2024-40638
8.1 HIGH

GLPI is a free asset and IT management software package. An authenticated user can exploit multiple SQL injection vulnerabilities. One of them can be used …

Nov 15, 2024
CVE-2024-50654
7.5 HIGH

lilishop <=4.2.4 is vulnerable to Incorrect Access Control, which can allow attackers to obtain coupons beyond the quantity limit by capturing and sending the data …

Nov 15, 2024
CVE-2024-50653
7.5 HIGH

CRMEB <=5.4.0 is vulnerable to Incorrect Access Control. Users can bypass the front-end restriction of only being able to claim coupons once by capturing packets …

Nov 15, 2024
CVE-2024-44625
8.8 HIGH

Gogs <=0.13.0 is vulnerable to Directory Traversal via the editFilePost function of internal/route/repo/editor.go.

Nov 15, 2024
CVE-2024-39726
8.2 HIGH

IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A …

Nov 15, 2024
CVE-2024-11248
8.8 HIGH

A vulnerability was found in Tenda AC10 16.03.10.13 and classified as critical. Affected by this issue is the function formSetRebootTimer of the file /goform/SetSysAutoRebbotCfg. The …

Nov 15, 2024
CVE-2024-50650
7.5 HIGH

python_book V1.0 is vulnerable to Incorrect Access Control, which allows attackers to obtain sensitive information of users with different IDs by modifying the ID parameter.

Nov 15, 2024
CVE-2024-50647
7.5 HIGH

The python_food ordering system V1.0 has an unauthorized vulnerability that leads to the leakage of sensitive user information. Attackers can access it through https://ip:port/api/myapp/index/user/info?id=1 And …

Nov 15, 2024
CVE-2024-49754
7.5 HIGH

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Stored Cross-Site Scripting (XSS) vulnerability in the API-Access page allows authenticated users to inject arbitrary JavaScript …

Nov 15, 2024
CVE-2024-41784
7.5 HIGH

IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, and 6.1.0.0 could allow a remote attacker to traverse directories on the system. An attacker could send …

Nov 15, 2024
CVE-2022-20853
7.4 HIGH

A vulnerability in the REST API of Cisco&nbsp;Expressway Series and Cisco&nbsp;TelePresence VCS could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) …

Nov 15, 2024
CVE-2022-20814
7.4 HIGH

A vulnerability in the certificate validation of Cisco&nbsp;Expressway-C and Cisco&nbsp;TelePresence VCS could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data.&nbsp;&nbsp;The vulnerability …

Nov 15, 2024
CVE-2022-20685
7.5 HIGH

A vulnerability in the Modbus preprocessor of the Snort detection engine could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition …

Nov 15, 2024
CVE-2022-20655
8.8 HIGH

A vulnerability in the implementation of the CLI on a device that is running ConfD could allow an authenticated, local attacker to perform a command …

Nov 15, 2024
CVE-2022-20649
8.1 HIGH

A vulnerability in Cisco&nbsp;RCM for Cisco&nbsp;StarOS Software could allow an unauthenticated, remote attacker to perform remote code execution on the application with root-level privileges&nbsp;in the …

Nov 15, 2024
CVE-2024-50986
7.3 HIGH

An issue in Clementine v.1.3.1 allows a local attacker to execute arbitrary code via a crafted DLL file.

Nov 15, 2024
CVE-2024-11241
7.3 HIGH

A vulnerability was found in code-projects Job Recruitment 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the …

Nov 15, 2024
CVE-2023-20125
8.6 HIGH

A vulnerability in the local interface of Cisco BroadWorks Network Server could allow an unauthenticated, remote attacker to exhaust system resources, causing a denial of …

Nov 15, 2024
CVE-2024-11237
7.5 HIGH

A vulnerability, which was classified as critical, has been found in TP-Link VN020 F3v(T) TT_V6.2.1021. Affected by this issue is some unknown functionality of the …

Nov 15, 2024
CVE-2021-3742
8.8 HIGH

A Server-Side Request Forgery (SSRF) vulnerability was discovered in chatwoot/chatwoot, affecting all versions prior to 2.5.0. The vulnerability allows an attacker to upload an SVG …

Nov 15, 2024
CVE-2024-8979
8.0 HIGH

The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in …

Nov 15, 2024
CVE-2024-10311
7.5 HIGH

The External Database Based Actions plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 0.1. This is due to a …

Nov 15, 2024
CVE-2024-45784
7.5 HIGH

Apache Airflow versions before 2.10.3 contain a vulnerability that could expose sensitive configuration variables in task logs. This vulnerability allows DAG authors to unintentionally or …

Nov 15, 2024
CVE-2024-10793
7.2 HIGH

The WP Activity Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user_id parameter in all versions up to, and including, 5.2.1 …

Nov 15, 2024
CVE-2024-10260
7.2 HIGH

The Tripetto plugin for WordPress is vulnerable to Stored Cross-Site Scripting via File uploads in all versions up to, and including, 8.0.11 due to insufficient …

Nov 15, 2024
CVE-2024-52308
8.0 HIGH

The GitHub CLI version 2.6.1 and earlier are vulnerable to remote code execution through a malicious codespace SSH server when using `gh codespace ssh` or …

Nov 14, 2024
CVE-2024-49778
8.8 HIGH

A heap-based buffer overflow in tsMuxer version nightly-2024-05-12-02-01-18 allows attackers to cause Denial of Service (DoS) and Code Execution via a crafted MOV video file.

Nov 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.