CVE Database

46624+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2020-11919
8.0 HIGH

An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. There is no CSRF protection.

Nov 7, 2024
CVE-2019-20459
8.4 HIGH

An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices. With the SNMPv1 public community, all values can be read, and with the epson …

Nov 7, 2024
CVE-2019-20458
8.8 HIGH

An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices. By default, the device comes (and functions) without a password. The user is at …

Nov 7, 2024
CVE-2024-48953
7.5 HIGH

An issue was discovered in Logpoint before 7.5.0. Endpoints for creating, editing, or deleting third-party authentication modules lacked proper authorization checks. This allowed unauthenticated users …

Nov 7, 2024
CVE-2024-48951
7.5 HIGH

An issue was discovered in Logpoint before 7.5.0. Server-Side Request Forgery (SSRF) on SOAR can be used to leak Logpoint's API Token leading to authentication …

Nov 7, 2024
CVE-2024-48950
7.5 HIGH

An issue was discovered in Logpoint before 7.5.0. An endpoint used by Distributed Logpoint Setup was exposed, allowing unauthenticated attackers to bypass CSRF protections and …

Nov 7, 2024
CVE-2024-40715
7.7 HIGH

A vulnerability in Veeam Backup & Replication Enterprise Manager has been identified, which allows attackers to perform authentication bypass. Attackers must be able to perform …

Nov 7, 2024
CVE-2024-10963
7.4 HIGH

A flaw was found in pam_access, where certain rules in its configuration file are mistakenly treated as hostnames. This vulnerability allows attackers to trick the …

Nov 7, 2024
CVE-2024-10668
7.5 HIGH

There exists an auth bypass in Google Quickshare where an attacker can upload an unknown file type to a victim. The root cause of the …

Nov 7, 2024
CVE-2024-43440
7.5 HIGH

A flaw was found in moodle. A local file may include risks when restoring block backups.

Nov 7, 2024
CVE-2024-43438
7.5 HIGH

A flaw was found in Feedback. Bulk messaging in the activity's non-respondents report did not verify message recipients belonging to the set of users returned …

Nov 7, 2024
CVE-2024-43436
7.2 HIGH

A SQL injection risk flaw was found in the XMLDB editor tool available to site administrators.

Nov 7, 2024
CVE-2024-43434
8.1 HIGH

The bulk message sending feature in Moodle's Feedback module's non-respondents report had an incorrect CSRF token check, leading to a CSRF vulnerability.

Nov 7, 2024
CVE-2024-43431
7.5 HIGH

A vulnerability was found in Moodle. Insufficient capability checks made it possible to delete badges that a user does not have permission to access.

Nov 7, 2024
CVE-2024-43428
7.7 HIGH

To address a cache poisoning risk in Moodle, additional validation for local storage was required.

Nov 7, 2024
CVE-2024-43426
7.5 HIGH

A flaw was found in pdfTeX. Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is …

Nov 7, 2024
CVE-2024-43425
8.1 HIGH

A flaw was found in Moodle. Additional restrictions are required to avoid a remote code execution risk in calculated question types. Note: This requires the …

Nov 7, 2024
CVE-2024-24914
8.0 HIGH

Authenticated Gaia users can inject code or commands by global variables through special HTTP requests. A Security fix that mitigates this vulnerability is available.

Nov 7, 2024
CVE-2024-50164
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix overloading of MEM_UNINIT's meaning Lonial reported an issue in the BPF verifier where …

Nov 7, 2024
CVE-2024-50159
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: firmware: arm_scmi: Fix the double free in scmi_debugfs_common_setup() Clang static checker(scan-build) throws below warning: | …

Nov 7, 2024
CVE-2024-50158
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Fix out of bound check Driver exports pacing stats only on GenP5 and P7 …

Nov 7, 2024
CVE-2024-50155
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: netdevsim: use cond_resched() in nsim_dev_trap_report_work() I am still seeing many syzbot reports hinting that syzbot …

Nov 7, 2024
CVE-2024-50154
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: tcp/dccp: Don't use timer_pending() in reqsk_queue_unlink(). Martin KaFai Lau reported use-after-free [0] in reqsk_timer_handler(). """ …

Nov 7, 2024
CVE-2024-50151
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix OOBs when building SMB2_IOCTL request When using encryption, either enforced by the …

Nov 7, 2024
CVE-2024-50150
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: usb: typec: altmode should keep reference to parent The altmode device release refers to its …

Nov 7, 2024
CVE-2024-50143
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: udf: fix uninit-value use in udf_get_fileshortad Check for overflow when computing alen in udf_current_aext to …

Nov 7, 2024
CVE-2024-10203
7.0 HIGH

Zohocorp ManageEngine EndPoint Central versions 11.3.2416.21 and below, 11.3.2428.9 and below are vulnerable to Arbitrary File Deletion in the agent installed machines.

Nov 7, 2024
CVE-2023-1973
7.5 HIGH

A flaw was found in Undertow package. Using the FormAuthenticationMechanism, a malicious user could trigger a Denial of Service by sending crafted requests, leading the …

Nov 7, 2024
CVE-2024-38286
8.6 HIGH

Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from …

Nov 7, 2024
CVE-2024-48325
8.1 HIGH

Portabilis i-Educar 2.8.0 is vulnerable to SQL Injection in the "getDocuments" function of the "InstituicaoDocumentacaoController" class. The "instituicao_id" parameter in "/module/Api/InstituicaoDocumentacao?oper=get&resource=getDocuments&instituicao_id" is not properly sanitized, …

Nov 6, 2024
CVE-2024-50340
7.3 HIGH

symfony/runtime is a module for the Symphony PHP framework which enables decoupling PHP applications from global state. When the `register_argv_argc` php directive is set to …

Nov 6, 2024
CVE-2024-20536
8.8 HIGH

A vulnerability in a REST API endpoint and web-based management interface of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, remote attacker with …

Nov 6, 2024
CVE-2024-20484
7.5 HIGH

A vulnerability in the External Agent Assignment Service (EAAS) feature of Cisco Enterprise Chat and Email (ECE) could allow an unauthenticated, remote attacker to cause …

Nov 6, 2024
CVE-2024-10827
8.8 HIGH

Use after free in Serial in Google Chrome prior to 130.0.6723.116 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Nov 6, 2024
CVE-2024-10826
8.8 HIGH

Use after free in Family Experiences in Google Chrome on Android prior to 130.0.6723.116 allowed a remote attacker to potentially exploit heap corruption via a …

Nov 6, 2024
CVE-2024-6861
7.5 HIGH

A disclosure of sensitive information flaw was found in foreman via the GraphQL API. If the introspection feature is enabled, it is possible for attackers …

Nov 6, 2024
CVE-2024-10082
8.7 HIGH

CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Authentication method confusion allows logging in as …

Nov 6, 2024
CVE-2024-10915
8.1 HIGH

A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been rated as critical. Affected by this issue is …

Nov 6, 2024
CVE-2024-10914
8.1 HIGH

A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been declared as critical. Affected by this vulnerability is …

Nov 6, 2024
CVE-2020-11859
7.6 HIGH

Improper Input Validation vulnerability in OpenText iManager allows Cross-Site Scripting (XSS). This issue affects iManager before 3.2.3

Nov 6, 2024
CVE-2024-9946
8.1 HIGH

The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to authentication bypass in all versions up to, …

Nov 6, 2024
CVE-2024-10020
8.1 HIGH

The Heateor Social Login WordPress plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.1.35. This is due to …

Nov 6, 2024
CVE-2024-10028
7.5 HIGH

The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up …

Nov 6, 2024
CVE-2024-47463
7.2 HIGH

An arbitrary file creation vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. Successful exploitation of this vulnerability could allow an authenticated remote …

Nov 5, 2024
CVE-2024-47462
7.2 HIGH

An arbitrary file creation vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. Successful exploitation of this vulnerability could allow an authenticated remote …

Nov 5, 2024
CVE-2024-47461
7.2 HIGH

An authenticated command injection vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. A successful exploitation of this vulnerability results in the ability …

Nov 5, 2024
CVE-2024-51116
8.8 HIGH

Tenda AC6 v2.0 V15.03.06.50 was discovered to contain a buffer overflow in the function 'formSetPPTPServer'.

Nov 5, 2024
CVE-2024-7995
7.8 HIGH

A maliciously crafted binary file when downloaded could lead to escalation of privileges to NT AUTHORITY/SYSTEM due to an untrusted search path being utilized in …

Nov 5, 2024
CVE-2024-51382
8.4 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in JATOS v3.9.3 allows an attacker to reset the administrator's password. This critical security flaw can result in unauthorized access …

Nov 5, 2024
CVE-2024-51381
8.4 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in JATOS v3.9.3 that allows attackers to perform actions reserved for administrators, including creating admin accounts. This critical flaw can …

Nov 5, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.