CVE Database

46624+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-47906
7.8 HIGH

Excessive binary privileges in Ivanti Connect Secure before version 22.7R2.3 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.2 (Not Applicable to 9.1Rx) …

Nov 12, 2024
CVE-2024-51564
7.5 HIGH

A guest can trigger an infinite loop in the hda audio driver.

Nov 12, 2024
CVE-2024-50386
8.5 HIGH

Account users in Apache CloudStack by default are allowed to register templates to be downloaded directly to the primary storage for deploying instances. Due to …

Nov 12, 2024
CVE-2024-45289
7.5 HIGH

The fetch(3) library uses environment variables for passing certain information, including the revocation file pathname. The environment variable name used by fetch(1) to pass the …

Nov 12, 2024
CVE-2024-42442
7.2 HIGH

APTIOV contains a vulnerability in the BIOS where a user or attacker may cause an improper restriction of operations within the bounds of a memory …

Nov 12, 2024
CVE-2024-37365
7.3 HIGH

A remote code execution vulnerability exists in the affected product. The vulnerability allows users to save projects within the public directory allowing anyone with local …

Nov 12, 2024
CVE-2024-33658
7.8 HIGH

APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Restriction of Operations within the Bounds of a Memory Buffer by local. …

Nov 12, 2024
CVE-2024-2315
7.1 HIGH

APTIOV contains a vulnerability in BIOS where may cause Improper Access Control by a local attacker. Successful exploitation of this vulnerability may lead to unexpected …

Nov 12, 2024
CVE-2024-50572
7.2 HIGH

A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V8.2), SCALANCE …

Nov 12, 2024
CVE-2024-50557
7.2 HIGH

A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V8.2), SCALANCE …

Nov 12, 2024
CVE-2024-50310
7.5 HIGH

A vulnerability has been identified in SIMATIC CP 1543-1 V4.0 (6GK7543-1AX10-0XE0) (All versions >= V4.0.44 < V4.0.50). Affected devices do not properly handle authorization. This …

Nov 12, 2024
CVE-2024-47942
7.3 HIGH

A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 9). The affected applications suffer from a DLL hijacking vulnerability. This …

Nov 12, 2024
CVE-2024-47941
7.8 HIGH

A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 9). The affected applications contain an out of bounds read past …

Nov 12, 2024
CVE-2024-47940
7.8 HIGH

A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 9). The affected applications contain an out of bounds read past …

Nov 12, 2024
CVE-2024-47808
8.4 HIGH

A vulnerability has been identified in SINEC NMS (All versions < V3.0 SP1). The affected application contains a database function, that does not properly restrict …

Nov 12, 2024
CVE-2024-47783
7.8 HIGH

A vulnerability has been identified in SIPORT (All versions < V3.4.0). The affected application improperly assigns file permissions to installation folders. This could allow a …

Nov 12, 2024
CVE-2024-29119
7.8 HIGH

A vulnerability has been identified in Spectrum Power 7 (All versions < V24Q3). The affected product contains several root-owned SUID binaries that could allow an …

Nov 12, 2024
CVE-2023-32736
7.3 HIGH

A vulnerability has been identified in SIMATIC S7-PLCSIM V16 (All versions), SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 Safety V16 (All versions), SIMATIC STEP …

Nov 12, 2024
CVE-2024-45827
8.0 HIGH

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Mesh Wi-Fi router RP562B firmware version v1.0.2 and earlier. …

Nov 12, 2024
CVE-2024-49560
7.8 HIGH

Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) a command injection vulnerability. A low privileged attacker with local access could potentially exploit this …

Nov 12, 2024
CVE-2024-49558
7.8 HIGH

Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) an Improper Privilege Management vulnerability. A low privileged attacker with local access could potentially exploit …

Nov 12, 2024
CVE-2024-49557
7.8 HIGH

Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low …

Nov 12, 2024
CVE-2024-48837
7.8 HIGH

Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) an Execution with Unnecessary Privileges vulnerability. A low privileged attacker with local access could potentially …

Nov 12, 2024
CVE-2024-11100
7.3 HIGH

A vulnerability was found in 1000 Projects Beauty Parlour Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown …

Nov 12, 2024
CVE-2024-11099
7.3 HIGH

A vulnerability was found in code-projects Job Recruitment 1.0 and classified as critical. This issue affects some unknown processing of the file /login.php. The manipulation …

Nov 12, 2024
CVE-2024-47590
8.8 HIGH

An unauthenticated attacker can create a malicious link which they can make publicly available. When an authenticated victim clicks on this malicious link, input data …

Nov 12, 2024
CVE-2024-25253
7.5 HIGH

Driver Booster v10.6 was discovered to contain a buffer overflow via the Host parameter under the Customize proxy module.

Nov 11, 2024
CVE-2024-46966
8.1 HIGH

The Ikhgur mn.ikhgur.khotoch (aka Video Downloader Pro & Browser) application through 1.0.42 for Android allows an attacker to execute arbitrary JavaScript code via the mn.ikhgur.khotoch.MainActivity …

Nov 11, 2024
CVE-2024-46964
8.1 HIGH

The com.video.downloader.all (aka All Video Downloader) application through 11.28 for Android allows an attacker to execute arbitrary JavaScript code via the com.video.downloader.all.StartActivity component.

Nov 11, 2024
CVE-2024-46963
8.1 HIGH

The com.superfast.video.downloader (aka Super Unlimited Video Downloader - All in One) application through 5.1.9 for Android allows an attacker to execute arbitrary JavaScript code via …

Nov 11, 2024
CVE-2024-52532
7.5 HIGH

GNOME libsoup before 3.6.1 has an infinite loop, and memory consumption. during the reading of certain patterns of WebSocket data from clients.

Nov 11, 2024
CVE-2024-52530
7.5 HIGH

GNOME libsoup before 3.6.0 allows HTTP request smuggling in some configurations because '\0' characters at the end of header names are ignored, i.e., a "Transfer-Encoding\0: …

Nov 11, 2024
CVE-2024-51487
8.1 HIGH

Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing fails to properly validate CSRF tokens when activating …

Nov 11, 2024
CVE-2024-51485
8.1 HIGH

Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing fails to properly validate CSRF tokens when activating …

Nov 11, 2024
CVE-2024-51484
8.1 HIGH

Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing fails to properly validate CSRF tokens when activating …

Nov 11, 2024
CVE-2024-51186
8.0 HIGH

D-Link DIR-820L 1.05b03 was discovered to contain a remote code execution (RCE) vulnerability via the ping_addr parameter in the ping_v4 and ping_v6 functions.

Nov 11, 2024
CVE-2024-48322
8.1 HIGH

UsersController.php in Run.codes 1.5.2 and older has a reset password race condition vulnerability.

Nov 11, 2024
CVE-2024-11077
7.3 HIGH

A vulnerability, which was classified as critical, was found in code-projects Job Recruitment 1.0. Affected is an unknown function of the file /index.php. The manipulation …

Nov 11, 2024
CVE-2024-47131
7.8 HIGH

If an attacker tricks a valid user into running Delta Electronics DIAScreen with a file containing malicious code, a stack-based buffer overflow in BACnetObjectInfo can …

Nov 11, 2024
CVE-2024-39605
7.8 HIGH

If an attacker tricks a valid user into running Delta Electronics DIAScreen with a file containing malicious code, a stack-based buffer overflow in BACnetParameter can …

Nov 11, 2024
CVE-2024-39354
7.8 HIGH

If an attacker tricks a valid user into running Delta Electronics DIAScreen with a file containing malicious code, a stack-based buffer overflow in CEtherIPTagItem can …

Nov 11, 2024
CVE-2024-11067
7.5 HIGH

The D-Link DSL6740C modem has a Path Traversal Vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files. Additionally, since the …

Nov 11, 2024
CVE-2024-11066
7.2 HIGH

The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute arbitrary system commands through the …

Nov 11, 2024
CVE-2024-11065
7.2 HIGH

The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute arbitrary system commands through a …

Nov 11, 2024
CVE-2024-11064
7.2 HIGH

The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute arbitrary system commands through a …

Nov 11, 2024
CVE-2024-11063
7.2 HIGH

The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute arbitrary system commands through a …

Nov 11, 2024
CVE-2024-11062
7.2 HIGH

The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute arbitrary system commands through a …

Nov 11, 2024
CVE-2024-11017
8.8 HIGH

Webopac from Grand Vice info does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload and execute webshells, which could …

Nov 11, 2024
CVE-2024-51882
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopalkumar315 Gboy Custom Google Map gboy-custom-google-map allows Blind SQL Injection.This issue …

Nov 11, 2024
CVE-2024-51845
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in richteam Share Buttons – Social Media rich-web-share-button allows Blind SQL Injection.This …

Nov 11, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.