CVE Database

4634+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-44575
3.7 LOW

RELY-PCIe v22.2.1 to v23.1.0 does not set the Secure attribute for sensitive cookies in HTTPS sessions, which could cause the user agent to send those …

Sep 11, 2024
CVE-2024-1656
2.6 LOW

Affected versions of Octopus Server had a weak content security policy.

Sep 11, 2024
CVE-2024-36511
3.7 LOW

An improperly implemented security check for standard vulnerability [CWE-358] in FortiADC Web Application Firewall (WAF) 7.4.0 through 7.4.4, 7.2 all versions, 7.1 all versions, 7.0 …

Sep 10, 2024
CVE-2024-8443
2.9 LOW

A heap-based buffer overflow vulnerability was found in the libopensc OpenPGP driver. A crafted USB device or smart card with malicious responses to the APDUs …

Sep 10, 2024
CVE-2024-37995
2.7 LOW

A vulnerability has been identified in SIMATIC Reader RF610R CMIIT (6GT2811-6BC10-2AA0) (All versions < V4.2), SIMATIC Reader RF610R ETSI (6GT2811-6BC10-0AA0) (All versions < V4.2), SIMATIC …

Sep 10, 2024
CVE-2024-42425
3.8 LOW

Dell Precision Rack, 14G Intel BIOS versions prior to 2.22.2, contains an Access of Memory Location After End of Buffer vulnerability. A low privileged attacker …

Sep 10, 2024
CVE-2024-39582
2.3 LOW

Dell PowerScale InsightIQ, version 5.0, contain a Use of hard coded Credentials vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, …

Sep 10, 2024
CVE-2024-45284
2.4 LOW

An authenticated attacker with high privilege can use functions of SLCM transactions to which access should be restricted. This may result in an escalation of …

Sep 10, 2024
CVE-2024-41728
2.7 LOW

Due to missing authorization check, SAP NetWeaver Application Server for ABAP and ABAP Platform allows an attacker logged in as a developer to read objects …

Sep 10, 2024
CVE-2024-44114
2.0 LOW

SAP NetWeaver Application Server for ABAP and ABAP Platform allow users with high privileges to execute a program that reveals data over the network. This …

Sep 10, 2024
CVE-2024-8610
3.5 LOW

A vulnerability classified as problematic has been found in SourceCodester Best House Rental Management System 1.0. Affected is an unknown function of the file /index.php?page=tenants …

Sep 9, 2024
CVE-2024-8042
2.4 LOW

Rapid7 Insight Platform versions between November 2019 and August 14, 2024 suffer from missing authorization issues whereby an attacker can intercept local requests to set …

Sep 9, 2024
CVE-2024-8583
3.5 LOW

A vulnerability was found in SourceCodester Online Bank Management System and Online Bank Management System - 1.0. It has been classified as problematic. This affects …

Sep 8, 2024
CVE-2024-8582
3.5 LOW

A vulnerability was found in SourceCodester Food Ordering Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the …

Sep 8, 2024
CVE-2024-8572
3.5 LOW

A vulnerability was found in Gouniverse GoLang CMS 1.4.0. It has been declared as problematic. This vulnerability affects the function PageRenderHtmlByAlias of the file FrontendHandler.go. …

Sep 8, 2024
CVE-2024-8571
3.5 LOW

A vulnerability was found in erjemin roll_cms up to 1484fe2c4e0805946a7bcf46218509fcb34883a9. It has been classified as problematic. This affects an unknown part of the file roll_cms/roll_cms/views.py. …

Sep 8, 2024
CVE-2024-8563
3.5 LOW

A vulnerability was found in SourceCodester PHP CRUD 1.0. It has been classified as problematic. This affects an unknown part of the file /endpoint/update.php. The …

Sep 7, 2024
CVE-2024-8562
3.5 LOW

A vulnerability was found in SourceCodester PHP CRUD 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /endpoint/Add.php. …

Sep 7, 2024
CVE-2024-36137
3.3 LOW

A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-write flag is used. Node.js Permission Model do not …

Sep 7, 2024
CVE-2024-8554
3.5 LOW

A vulnerability was found in SourceCodester Clinics Patient Management System 2.0 and classified as problematic. This issue affects some unknown processing of the file /users.php. …

Sep 7, 2024
CVE-2024-32771
2.6 LOW

An improper restriction of excessive authentication attempts vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow local …

Sep 6, 2024
CVE-2024-27125
3.5 LOW

A cross-site scripting (XSS) vulnerability has been reported to affect Helpdesk. If exploited, the vulnerability could allow authenticated administrators to inject malicious code via a …

Sep 6, 2024
CVE-2024-6792
3.5 LOW

The WP ULike WordPress plugin before 4.7.2.1 does not properly sanitize user display names when rendering on a public page.

Sep 6, 2024
CVE-2024-8462
3.7 LOW

A vulnerability was found in Windmill 1.380.0. It has been classified as problematic. Affected is an unknown function of the file backend/windmill-api/src/users.rs of the component …

Sep 5, 2024
CVE-2024-8460
3.7 LOW

A vulnerability, which was classified as problematic, has been found in D-Link DNS-320 2.02b01. Affected by this issue is some unknown functionality of the file …

Sep 5, 2024
CVE-2024-45395
3.1 LOW

sigstore-go, a Go library for Sigstore signing and verification, is susceptible to a denial of service attack in versions prior to 0.6.1 when a verifier …

Sep 4, 2024
CVE-2024-8417
3.1 LOW

A vulnerability was found in 云课网络科技有限公司 Yunke Online School System up to 1.5.5. It has been declared as problematic. This vulnerability affects unknown code of …

Sep 4, 2024
CVE-2024-45314
3.6 LOW

Flask-AppBuilder is an application development framework. Prior to version 4.5.1, the auth DB login form default cache directives allows browser to locally store sensitive data. …

Sep 4, 2024
CVE-2024-8411
3.5 LOW

A vulnerability was determined in ABCD ABCD2 up to 2.2.0-beta-1. Impacted is an unknown function of the file /buscar_integrada.php. Executing a manipulation of the argument …

Sep 4, 2024
CVE-2024-8407
3.5 LOW

A vulnerability was found in alwindoss akademy up to 35caccea888ed63d5489e211c99edff1f62efdba. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of …

Sep 4, 2024
CVE-2024-34649
2.4 LOW

Improper access control in new Dex Mode in multitasking framework prior to SMR Sep-2024 Release 1 allows physical attackers to temporarily access an unlocked screen.

Sep 4, 2024
CVE-2024-34640
3.3 LOW

Improper access control vulnerability in BGProtectManager prior to SMR Sep-2024 Release 1 allows local attackers to bypass restriction of process expiration.

Sep 4, 2024
CVE-2024-45620
3.9 LOW

A vulnerability was found in the pkcs15-init tool in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the …

Sep 3, 2024
CVE-2024-45618
3.9 LOW

A vulnerability was found in pkcs15-init in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with …

Sep 3, 2024
CVE-2024-45617
3.9 LOW

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which …

Sep 3, 2024
CVE-2024-45616
3.9 LOW

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which …

Sep 3, 2024
CVE-2024-45615
3.9 LOW

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. The problem is missing initialization of variables expected to be initialized (as …

Sep 3, 2024
CVE-2024-45310
3.6 LOW

runc is a CLI tool for spawning and running containers according to the OCI specification. runc 1.1.13 and earlier, as well as 1.2.0-rc2 and earlier, …

Sep 3, 2024
CVE-2024-43413
3.5 LOW

Xibo is an open source digital signage platform with a web content management system (CMS). Prior to version 4.1.0, a cross-site scripting vulnerability in Xibo …

Sep 3, 2024
CVE-2024-45305
2.5 LOW

gix-path is a crate of the gitoxide project dealing with git paths and their conversions. `gix-path` executes `git` to find the path of a configuration …

Sep 2, 2024
CVE-2023-7279
2.6 LOW

A vulnerability has been found in Secure Systems Engineering Connaisseur up to 3.3.0 and classified as problematic. This vulnerability affects unknown code of the file …

Sep 2, 2024
CVE-2024-28044
3.3 LOW

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause crash through integer overflow.

Sep 2, 2024
CVE-2024-8370
3.5 LOW

A vulnerability classified as problematic was found in Grocy up to 4.2.0. This vulnerability affects unknown code of the file /api/files/recipepictures/ of the component SVG …

Sep 1, 2024
CVE-2024-8367
3.5 LOW

A vulnerability was found in HM Courts & Tribunals Service Probate Back Office up to c1afe0cdb2b2766d9e24872c4e827f8b82a6cd31. It has been classified as problematic. Affected is an …

Sep 1, 2024
CVE-2024-0109
3.3 LOW

NVIDIA CUDA Toolkit contains a vulnerability in command `cuobjdump` where a user may cause a crash by passing in a malformed ELF file. A successful …

Aug 31, 2024
CVE-2024-44918
3.5 LOW

A cross-site scripting (XSS) vulnerability in the component admin_datarelate.php of SeaCMS v12.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

Aug 30, 2024
CVE-2024-8337
3.5 LOW

A vulnerability, which was classified as problematic, has been found in SourceCodester Contact Manager with Export to VCF 1.0. Affected by this issue is some …

Aug 30, 2024
CVE-2024-39300
3.7 LOW

Missing authentication vulnerability exists in Telnet function of WAB-I1750-PS v1.5.10 and earlier. When Telnet function of the product is enabled, a remote attacker may login …

Aug 30, 2024
CVE-2024-2502
2.0 LOW

An application can be configured to block boot attempts after consecutive tamper resets are detected, which may not occur as expected. This is possible because …

Aug 29, 2024
CVE-2024-43944
3.7 LOW

Authentication Bypass by Spoofing vulnerability in ilyasine Maintenance & Coming Soon Redirect Animation maintenance-coming-soon-redirect-animation allows Identity Spoofing.This issue affects Maintenance & Coming Soon Redirect Animation: …

Aug 29, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.