CVE Database

46624+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-52007
8.6 HIGH

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. XSLT parsing performed by various components are vulnerable to …

Nov 8, 2024
CVE-2024-52002
8.8 HIGH

Combodo iTop is a simple, web based IT Service Management tool. Several url endpoints are subject to a Cross-Site Request Forgery (CSRF) vulnerability. Please refer …

Nov 8, 2024
CVE-2024-35423
7.8 HIGH

vmir e8117 was discovered to contain a heap buffer overflow via the wasm_parse_section_functions function at /src/vmir_wasm_parser.c.

Nov 8, 2024
CVE-2024-35422
7.8 HIGH

vmir e8117 was discovered to contain a heap buffer overflow via the wasm_call function at /src/vmir_wasm_parser.c.

Nov 8, 2024
CVE-2024-27532
7.5 HIGH

wasm-micro-runtime (aka WebAssembly Micro Runtime or WAMR) 06df58f is vulnerable to NULL Pointer Dereference in function `block_type_get_result_types.

Nov 8, 2024
CVE-2024-27530
8.4 HIGH

wasm3 139076a contains a Use-After-Free in ForEachModule.

Nov 8, 2024
CVE-2024-27529
8.4 HIGH

wasm3 139076a contains memory leaks in Read_utf8.

Nov 8, 2024
CVE-2024-27528
8.4 HIGH

wasm3 139076a suffers from Invalid Memory Read, leading to DoS and potential Code Execution.

Nov 8, 2024
CVE-2024-27527
7.5 HIGH

wasm3 139076a is vulnerable to Denial of Service (DoS).

Nov 8, 2024
CVE-2024-50809
8.8 HIGH

The theme.php file in SDCMS 2.8 has a command execution vulnerability that allows for the execution of system commands

Nov 8, 2024
CVE-2024-50808
8.8 HIGH

SeaCms 13.1 is vulnerable to code injection in the notification module of the member message notification module in the backend user module, due to unsafe …

Nov 8, 2024
CVE-2024-51997
8.1 HIGH

Trustee is a set of tools and components for attesting confidential guests and providing secrets to them. The ART (**Attestation Results Token**) token, generated by …

Nov 8, 2024
CVE-2024-51152
7.2 HIGH

File Upload vulnerability in Laravel CMS v.1.4.7 and before allows a remote attacker to execute arbitrary code via the shell.php a component.

Nov 8, 2024
CVE-2024-50634
8.8 HIGH

A vulnerability in a weak JWT token in Watcharr v1.43.0 and below allows attackers to perform privilege escalation using a crafted JWT token. This vulnerability …

Nov 8, 2024
CVE-2024-25431
7.8 HIGH

An issue in bytecodealliance wasm-micro-runtime before v.b3f728c and fixed in commit 06df58f allows a remote attacker to escalate privileges via a crafted file to the …

Nov 8, 2024
CVE-2024-50592
7.0 HIGH

An attacker with local access the to medical office computer can escalate his Windows user privileges to "NT AUTHORITY\SYSTEM" by exploiting a race condition in …

Nov 8, 2024
CVE-2024-50593
7.8 HIGH

An attacker with local access to the medical office computer can access restricted functions of the Elefant Service tool by using a hard-coded "Hotline" password …

Nov 8, 2024
CVE-2024-50591
7.8 HIGH

An attacker with local access the to medical office computer can escalate his Windows user privileges to "NT AUTHORITY\SYSTEM" by exploiting a command injection vulnerability …

Nov 8, 2024
CVE-2024-50590
7.8 HIGH

Attackers with local access to the medical office computer can escalate their Windows user privileges to "NT AUTHORITY\SYSTEM" by overwriting one of two Elefant service …

Nov 8, 2024
CVE-2024-50589
7.5 HIGH

An unauthenticated attacker with access to the local network of the medical office can query an unprotected Fast Healthcare Interoperability Resources (FHIR) API to get …

Nov 8, 2024
CVE-2024-10839
8.5 HIGH

Zohocorp ManageEngine SharePoint Manager Plus versions 4503 and prior are vulnerable to authenticated XML External Entity (XXE) in the Management option.

Nov 8, 2024
CVE-2024-24409
8.8 HIGH

Zohocorp ManageEngine ADManager Plus versions 7203 and prior are vulnerable to Privilege Escalation in the Modify Computers option.

Nov 8, 2024
CVE-2024-10998
7.3 HIGH

A vulnerability was found in 1000 Projects Bookstore Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the …

Nov 8, 2024
CVE-2024-10996
7.3 HIGH

A vulnerability was found in 1000 Projects Bookstore Management System 1.0. It has been classified as critical. This affects an unknown part of the file …

Nov 8, 2024
CVE-2024-10995
7.3 HIGH

A vulnerability was found in Codezips Hospital Appointment System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Nov 8, 2024
CVE-2024-50209
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Add a check for memory allocation __alloc_pbl() can return error when memory allocation fails. …

Nov 8, 2024
CVE-2024-50203
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: bpf, arm64: Fix address emission with tag-based KASAN enabled When BPF_TRAMP_F_CALL_ORIG is enabled, the address …

Nov 8, 2024
CVE-2024-50193
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: x86/entry_32: Clear CPU buffers after register restore in NMI return CPU buffers are currently cleared …

Nov 8, 2024
CVE-2024-50186
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: explicitly clear the sk pointer, when pf->create fails We have recently noticed the exact …

Nov 8, 2024
CVE-2024-50180
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: fbdev: sisfb: Fix strbuf array overflow The values of the variables xres and yres are …

Nov 8, 2024
CVE-2024-21538
7.5 HIGH

Versions of the package cross-spawn before 6.0.6, from 7.0.0 and before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input …

Nov 8, 2024
CVE-2024-10991
7.3 HIGH

A vulnerability, which was classified as critical, has been found in Codezips Hospital Appointment System 1.0. This issue affects some unknown processing of the file …

Nov 8, 2024
CVE-2024-10988
7.3 HIGH

A vulnerability was found in code-projects E-Health Care System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Nov 8, 2024
CVE-2024-8424
7.8 HIGH

Improper Privilege Management vulnerability in WatchGuard EPDR, Panda AD360 and Panda Dome on Windows (PSANHost.exe module) allows arbitrary file delete with SYSTEM permissions. This issue …

Nov 8, 2024
CVE-2024-51998
8.6 HIGH

changedetection.io is a free open source web page change detection tool. The validation for the file URI scheme falls short, and results in an attacker …

Nov 8, 2024
CVE-2024-47072
7.5 HIGH

XStream is a simple library to serialize objects to XML and back again. This vulnerability may allow a remote attacker to terminate the application with …

Nov 8, 2024
CVE-2024-46961
8.1 HIGH

The Inshot com.downloader.privatebrowser (aka Video Downloader - XDownloader) application through 1.3.5 for Android allows an attacker to execute arbitrary JavaScript code via the com.downloader.privatebrowser.activity.PrivateMainActivity component.

Nov 7, 2024
CVE-2024-46960
8.8 HIGH

The ASD com.rocks.video.downloader (aka HD Video Downloader All Format) application through 7.0.129 for Android allows an attacker to execute arbitrary JavaScript code via the com.rocks.video.downloader.MainBrowserActivity …

Nov 7, 2024
CVE-2024-36063
7.5 HIGH

The Goodwy com.goodwy.dialer (aka Right Dialer) application through 5.1.0 for Android enables any application (with no permissions) to place phone calls without user interaction by …

Nov 7, 2024
CVE-2024-10975
7.7 HIGH

Nomad Community and Nomad Enterprise ("Nomad") volume specification is vulnerable to arbitrary cross-namespace volume creation through unauthorized Container Storage Interface (CSI) volume writes. This vulnerability, …

Nov 7, 2024
CVE-2019-20460
8.8 HIGH

An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices. POST requests don't require (anti-)CSRF tokens or other mechanisms for validating that the request …

Nov 7, 2024
CVE-2024-10969
7.3 HIGH

A vulnerability was found in 1000 Projects Bookstore Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

Nov 7, 2024
CVE-2024-10968
7.3 HIGH

A vulnerability was found in 1000 Projects Bookstore Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Nov 7, 2024
CVE-2024-51995
7.1 HIGH

Combodo iTop is a web based IT Service Management tool. An attacker can request any `route` we want as long as we specify an `operation` …

Nov 7, 2024
CVE-2024-51989
7.1 HIGH

Password Pusher is an open source application to communicate sensitive information over the web. A cross-site scripting (XSS) vulnerability was identified in the PasswordPusher application, …

Nov 7, 2024
CVE-2024-51428
7.5 HIGH

An issue in Espressif Esp idf v5.3.0 allows attackers to cause a Denial of Service (DoS) via a crafted data channel packet.

Nov 7, 2024
CVE-2024-45794
8.3 HIGH

devtron is an open source tool integration platform for Kubernetes. In affected versions an authenticated user (with minimum permission) could utilize and exploit SQL Injection …

Nov 7, 2024
CVE-2024-10967
7.3 HIGH

A vulnerability was found in code-projects E-Health Care System 1.0. It has been classified as critical. Affected is an unknown function of the file /Doctor/delete_user_appointment_request.php. …

Nov 7, 2024
CVE-2020-11926
7.5 HIGH

An issue was discovered in Luvion Grand Elite 3 Connect through 2020-02-25. Clients can authenticate themselves to the device using a username and password. These …

Nov 7, 2024
CVE-2020-11921
8.8 HIGH

An issue was discovered in Lush 2 through 2020-02-25. Due to the lack of Bluetooth traffic encryption, it is possible to hijack an ongoing Bluetooth …

Nov 7, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.