CVE Database

46624+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-51996
7.5 HIGH

Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. When consuming a persisted remember-me cookie, Symfony does not check …

Nov 13, 2024
CVE-2024-45594
7.7 HIGH

Decidim is a participatory democracy framework. The meeting embeds feature used in the online or hybrid meetings is subject to potential XSS attack through a …

Nov 13, 2024
CVE-2024-7295
7.1 HIGH

In Progress® Telerik® Report Server versions prior to 2024 Q4 (10.3.24.1112), the encryption of local asset data used an older algorithm which may allow a …

Nov 13, 2024
CVE-2024-52306
7.6 HIGH

FileManager provides a Backpack admin interface for files and folder. Prior to 3.0.9, deserialization of untrusted data from the mimes parameter could lead to remote …

Nov 13, 2024
CVE-2024-52299
7.5 HIGH

macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. Any user with view right on XWiki.PDFViewerService can access any attachment stored in the …

Nov 13, 2024
CVE-2024-52298
7.5 HIGH

macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. The PDF Viewer macro allows an attacker to view any attachment using the "Delegate …

Nov 13, 2024
CVE-2024-52293
7.2 HIGH

Craft is a content management system (CMS). Prior to 4.12.2 and 5.4.3, Craft is missing normalizePath in the function FileHelper::absolutePath could lead to Remote Code …

Nov 13, 2024
CVE-2024-50972
7.2 HIGH

A SQL injection vulnerability in printtool.php of Itsourcecode Construction Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the borrow_id parameter.

Nov 13, 2024
CVE-2024-50971
7.2 HIGH

A SQL injection vulnerability in print.php of Itsourcecode Construction Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the map_id parameter.

Nov 13, 2024
CVE-2024-50970
8.8 HIGH

A SQL injection vulnerability in orderview1.php of Itsourcecode Online Furniture Shopping Project 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

Nov 13, 2024
CVE-2024-10013
7.8 HIGH

In Progress Telerik UI for WinForms versions prior to 2024 Q4 (2024.4.1113), a code execution attack is possible through an insecure deserialization vulnerability.

Nov 13, 2024
CVE-2024-10012
7.8 HIGH

In Progress Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1111), a code execution attack is possible through an insecure deserialization vulnerability.

Nov 13, 2024
CVE-2024-50854
8.8 HIGH

Tenda G3 v3.0 v15.11.0.20 was discovered to contain a stack overflow via the formSetPortMapping function.

Nov 13, 2024
CVE-2024-50853
8.8 HIGH

Tenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSetDebugCfg function.

Nov 13, 2024
CVE-2024-50852
8.8 HIGH

Tenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSetUSBPartitionUmount function.

Nov 13, 2024
CVE-2024-48989
7.5 HIGH

A vulnerability in the PROFINET stack implementation of the IndraDrive (all versions) of Bosch Rexroth allows an attacker to cause a denial of service, rendering …

Nov 13, 2024
CVE-2024-47574
7.8 HIGH

A authentication bypass using an alternate path or channel in Fortinet FortiClientWindows version 7.4.0, versions 7.2.4 through 7.2.0, versions 7.0.12 through 7.0.0, and 6.4.10 through …

Nov 13, 2024
CVE-2024-4741
7.5 HIGH

Issue summary: Calling the OpenSSL API function SSL_free_buffers may cause memory to be accessed that was previously freed in some situations Impact summary: A use …

Nov 13, 2024
CVE-2024-9409
7.5 HIGH

CWE-400: An Uncontrolled Resource Consumption vulnerability exists that could cause the device to become unresponsive resulting in communication loss when a large amount of IGMP …

Nov 13, 2024
CVE-2024-8938
8.1 HIGH

CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause a potential arbitrary code execution after a successful …

Nov 13, 2024
CVE-2024-8935
7.5 HIGH

CWE-290: Authentication Bypass by Spoofing vulnerability exists that could cause a denial of service and loss of confidentiality and integrity of controllers when conducting a …

Nov 13, 2024
CVE-2024-21541
7.3 HIGH

Versions of the package dom-iterator before 1.0.1 are vulnerable to Arbitrary Code Execution due to use of the Function constructor without complete input sanitization. Function …

Nov 13, 2024
CVE-2024-10800
8.8 HIGH

The WordPress User Extra Fields plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the ajax_save_fields() function in all …

Nov 13, 2024
CVE-2024-8933
7.5 HIGH

CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause retrieval of password hash that could lead to …

Nov 13, 2024
CVE-2024-10828
8.1 HIGH

The Advanced Order Export For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.5.5 via deserialization …

Nov 13, 2024
CVE-2024-10816
7.5 HIGH

The LUNA RADIO PLAYER plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.24.01.24 via the js/fallback.php file. This …

Nov 13, 2024
CVE-2024-10174
7.3 HIGH

The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to Insecure Direct …

Nov 13, 2024
CVE-2024-39709
7.8 HIGH

Incorrect file permissions in Ivanti Connect Secure before version 22.6R2 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1 (Not Applicable to 9.1Rx) …

Nov 13, 2024
CVE-2024-38655
7.2 HIGH

Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.9 and Ivanti Policy Secure before version 22.7R1.1 and 9.1R18.9 allows a remote authenticated attacker …

Nov 13, 2024
CVE-2024-38649
7.5 HIGH

An out-of-bounds write in IPsec of Ivanti Connect Secure before version 22.7R2.1(Not Applicable to 9.1Rx) allows a remote unauthenticated attacker to cause a denial of …

Nov 13, 2024
CVE-2024-37400
7.5 HIGH

An out of bounds read in Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to trigger an infinite loop, causing a denial …

Nov 13, 2024
CVE-2024-37398
7.8 HIGH

Insufficient validation in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.

Nov 13, 2024
CVE-2024-37376
7.2 HIGH

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges …

Nov 13, 2024
CVE-2024-34787
7.8 HIGH

Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a local unauthenticated attacker to achieve code …

Nov 13, 2024
CVE-2024-34784
7.2 HIGH

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges …

Nov 13, 2024
CVE-2024-34782
7.2 HIGH

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges …

Nov 13, 2024
CVE-2024-34781
7.2 HIGH

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges …

Nov 13, 2024
CVE-2024-34780
7.2 HIGH

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges …

Nov 13, 2024
CVE-2024-32847
7.2 HIGH

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges …

Nov 13, 2024
CVE-2024-32844
7.2 HIGH

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges …

Nov 13, 2024
CVE-2024-32841
7.2 HIGH

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges …

Nov 13, 2024
CVE-2024-32839
7.2 HIGH

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges …

Nov 13, 2024
CVE-2024-10629
8.8 HIGH

The GPX Viewer plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check and file type validation in the gpxv_file_upload() …

Nov 13, 2024
CVE-2024-28726
8.0 HIGH

An issue in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker to execute arbitrary …

Nov 12, 2024
CVE-2021-27702
7.3 HIGH

Sercomm Router Etisalat Model S3- AC2100 is affected by Incorrect Access Control via the diagnostic utility in the router dashboard.

Nov 12, 2024
CVE-2021-27700
7.6 HIGH

SOCIFI Socifi Guest wifi as SAAS wifi portal is affected by Insecure Permissions. Any authorized customer with partner mode can switch to another customer dashboard …

Nov 12, 2024
CVE-2024-51179
7.5 HIGH

An issue in Open 5GS v.2.7.1 allows a remote attacker to cause a denial of service via the Network Function Virtualizations (NFVs) such as the …

Nov 12, 2024
CVE-2024-51094
8.0 HIGH

An issue in Snipe-IT v.7.0.13 build 15514 allows a low-privileged attacker to modify their profile name and inject a malicious payload into the "Name" field. …

Nov 12, 2024
CVE-2024-51093
8.7 HIGH

Stored Cross-Site Scripting (XSS) vulnerability in Snipe-IT - v7.0.13 allows an attacker to upload a malicious XML file containing JavaScript code. This can lead to …

Nov 12, 2024
CVE-2024-49509
7.8 HIGH

InDesign Desktop versions ID18.5.3, ID19.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Nov 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.