CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2017-13313
6.5 MEDIUM

In ElementaryStreamQueue::dequeueAccessUnitMPEG4Video of ESQueue.cpp, there is a possible infinite loop leading to resource exhaustion due to an incorrect bounds check. This could lead to remote …

Nov 15, 2024
CVE-2017-13311
6.7 MEDIUM

In the read() function of ProcessStats.java, there is a possible read/write serialization issue leading to a permissions bypass. This could lead to local escalation of …

Nov 15, 2024
CVE-2024-49592
6.7 MEDIUM

Trial installer for McAfee Total Protection (legacy trial installer software) 16.0.53 allows local privilege escalation because of an Uncontrolled Search Path Element. The attacker could …

Nov 15, 2024
CVE-2024-45611
5.7 MEDIUM

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An authenticated user can …

Nov 15, 2024
CVE-2024-45610
6.5 MEDIUM

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An unauthenticated user can …

Nov 15, 2024
CVE-2024-11217
4.9 MEDIUM

A vulnerability was found in the OAuth-server. OAuth-server logs the OAuth2 client secret when the logLevel is Debug higher for OIDC/GitHub/GitLab/Google IDPs login options.

Nov 15, 2024
CVE-2017-13309
5.5 MEDIUM

In readEncryptedData of ConscryptEngine.java, there is a possible plaintext leak due to improperly used crypto. This could lead to local information disclosure with no additional …

Nov 15, 2024
CVE-2024-49536
5.5 MEDIUM

Audition versions 23.6.9, 24.4.6 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage …

Nov 15, 2024
CVE-2024-45609
6.5 MEDIUM

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An unauthenticated user can …

Nov 15, 2024
CVE-2024-3334
4.3 MEDIUM

A security bypass vulnerability exists in the Removable Media Encryption (RME)component of Digital Guardian Windows Agents prior to version 8.2.0. This allows a user to …

Nov 15, 2024
CVE-2024-24459
5.9 MEDIUM

An invalid memory access when handling the ProtocolIE_ID field of S1Setup Request messages in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial of …

Nov 15, 2024
CVE-2024-24458
5.9 MEDIUM

An invalid memory access when handling the ENB Configuration Transfer messages containing invalid PLMN Identities in Athonet vEPC MME v11.4.0 allows attackers to cause a …

Nov 15, 2024
CVE-2024-24457
5.9 MEDIUM

An invalid memory access when handling the ProtocolIE_ID field of E-RAB Setup List Context SURes messages in Athonet vEPC MME v11.4.0 allows attackers to cause …

Nov 15, 2024
CVE-2024-24455
5.9 MEDIUM

An invalid memory access when handling a UE Context Release message containing an invalid UE identifier in Athonet vEPC MME v11.4.0 allows attackers to cause …

Nov 15, 2024
CVE-2024-24454
5.9 MEDIUM

An invalid memory access when handling the ProtocolIE_ID field of E-RAB Modify Request messages in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial …

Nov 15, 2024
CVE-2024-24453
5.9 MEDIUM

An invalid memory access when handling the ProtocolIE_ID field of E-RAB NotToBeModifiedBearerModInd information element in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial …

Nov 15, 2024
CVE-2024-24452
5.9 MEDIUM

An invalid memory access when handling the ProtocolIE_ID field of E-RAB Release Indication messages in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial …

Nov 15, 2024
CVE-2024-51330
4.4 MEDIUM

An issue in UltiMaker Cura v.4.41 and 5.8.1 and before allows a local attacker to execute arbitrary code via Inter-process communication (IPC) mechanism between Cura …

Nov 15, 2024
CVE-2024-51142
5.4 MEDIUM

Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows an attacker to execute arbitrary code via the svkey parameter of the storageapi.php file.

Nov 15, 2024
CVE-2024-51037
5.3 MEDIUM

An issue in kodbox v.1.52.04 and before allows a remote attacker to obtain sensitive information via the captcha feature in the password reset function.

Nov 15, 2024
CVE-2024-45608
6.5 MEDIUM

GLPI is a free asset and IT management software package. An authenticated user can perfom a SQL injection by changing its preferences. Upgrade to 10.0.17.

Nov 15, 2024
CVE-2024-43418
6.5 MEDIUM

GLPI is a free asset and IT management software package. An unauthenticated user can provide a malicious link to a GLPI technician in order to …

Nov 15, 2024
CVE-2024-43417
6.5 MEDIUM

GLPI is a free asset and IT management software package. An unauthenticated user can provide a malicious link to a GLPI technician in order to …

Nov 15, 2024
CVE-2024-41679
6.5 MEDIUM

GLPI is a free asset and IT management software package. An authenticated user can exploit a SQL injection vulnerability from the ticket form. Upgrade to …

Nov 15, 2024
CVE-2024-24446
6.5 MEDIUM

An uninitialized pointer dereference in OpenAirInterface CN5G AMF up to v2.0.0 allows attackers to cause a Denial of Service (DoS) via a crafted InitialContextSetupResponse message …

Nov 15, 2024
CVE-2024-24425
6.5 MEDIUM

Magma v1.8.0 and OAI EPC Federation v1.20 were discovered to contain an out-of-bounds read in the amf_as_establish_req function at /tasks/amf/amf_as.cpp. This vulnerability allows attackers to …

Nov 15, 2024
CVE-2024-23169
4.6 MEDIUM

The web interface in RSA NetWitness 11.7.2.0 allows Cross-Site Scripting (XSS) via the Where textbox on the Reports screen during new rule creation.

Nov 15, 2024
CVE-2024-52514
4.1 MEDIUM

Nextcloud Server is a self hosted personal cloud system. After a user received a share with some files inside being blocked by the files access …

Nov 15, 2024
CVE-2024-52511
6.3 MEDIUM

Nextcloud Tables allows users to to create tables with individual columns. By directly specifying the ID of a table or view, a malicious user could …

Nov 15, 2024
CVE-2024-52510
4.2 MEDIUM

The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. The Desktop client did not stop with an error …

Nov 15, 2024
CVE-2024-50800
5.4 MEDIUM

Cross Site Scripting vulnerability in M2000 Smart4Web before v.5.020241004 allows a remote attacker to execute arbitrary code via the error parameter in URL

Nov 15, 2024
CVE-2024-47759
4.8 MEDIUM

GLPI is a free Asset and IT management software package. An technician can upload a SVG containing a malicious script. The script will then be …

Nov 15, 2024
CVE-2024-41678
6.5 MEDIUM

GLPI is a free asset and IT management software package. An unauthenticated user can provide a malicious link to a GLPI technician in order to …

Nov 15, 2024
CVE-2024-24450
5.3 MEDIUM

Stack-based memcpy buffer overflow in the ngap_handle_pdu_session_resource_setup_response routine in OpenAirInterface CN5G AMF <= 2.0.0 allows a remote attacker with access to the N2 interface to …

Nov 15, 2024
CVE-2024-24449
6.5 MEDIUM

An uninitialized pointer dereference in the NasPdu::NasPdu component of OpenAirInterface CN5G AMF up to v2.0.0 allows attackers to cause a Denial of Service (DoS) via …

Nov 15, 2024
CVE-2024-24447
5.3 MEDIUM

A buffer overflow in the ngap_amf_handle_pdu_session_resource_setup_response function of oai-cn5g-amf up to v2.0.0 allows attackers to cause a Denial of Service (DoS) via a PDU Session …

Nov 15, 2024
CVE-2024-11251
6.3 MEDIUM

A vulnerability was found in erzhongxmu Jeewms up to 20241108. It has been rated as critical. This issue affects some unknown processing of the file …

Nov 15, 2024
CVE-2024-11250
6.3 MEDIUM

A vulnerability was found in code-projects Inventory Management up to 1.0. It has been declared as critical. This vulnerability affects unknown code of the file …

Nov 15, 2024
CVE-2024-52523
4.6 MEDIUM

Nextcloud Server is a self hosted personal cloud system. After setting up a user or administrator defined external storage with fixed credentials, the API returns …

Nov 15, 2024
CVE-2024-52520
5.7 MEDIUM

Nextcloud Server is a self hosted personal cloud system. Due to a pre-flighted HEAD request, the link reference provider could be tricked into downloading bigger …

Nov 15, 2024
CVE-2024-52518
4.4 MEDIUM

Nextcloud Server is a self hosted personal cloud system. After an attacker got access to the session of a user or administrator, the attacker would …

Nov 15, 2024
CVE-2024-52517
4.6 MEDIUM

Nextcloud Server is a self hosted personal cloud system. After storing "Global credentials" on the server, the API returns them and adds them into the …

Nov 15, 2024
CVE-2024-52515
5.7 MEDIUM

Nextcloud Server is a self hosted personal cloud system. After an admin enables the default-disabled SVG preview provider, a malicious user could upload a manipulated …

Nov 15, 2024
CVE-2024-50655
5.4 MEDIUM

emlog pro <=2.3.18 is vulnerable to Cross Site Scripting (XSS), which allows attackers to write malicious JavaScript code in published articles.

Nov 15, 2024
CVE-2022-20633
5.3 MEDIUM

A vulnerability in the web-based management interface of Cisco&nbsp;ECE could allow an unauthenticated, remote attacker to perform a username enumeration attack against an affected device. …

Nov 15, 2024
CVE-2022-20632
6.1 MEDIUM

A vulnerability in the web-based management interface of Cisco&nbsp;ECE could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of the …

Nov 15, 2024
CVE-2021-34753
5.8 MEDIUM

A vulnerability in the payload inspection for Ethernet Industrial Protocol (ENIP) traffic for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker …

Nov 15, 2024
CVE-2021-34752
6.7 MEDIUM

A vulnerability in the CLI of Cisco&nbsp;FTD Software could allow an authenticated, local attacker with administrative privileges to execute arbitrary commands with root privileges on …

Nov 15, 2024
CVE-2021-34751
4.3 MEDIUM

A vulnerability in the administrative web-based GUI configuration manager of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to access sensitive …

Nov 15, 2024
CVE-2021-34750
4.3 MEDIUM

A vulnerability in the administrative web-based GUI configuration manager of Cisco Firepower Management Center Software could allow an authenticated, remote attacker to access sensitive configuration …

Nov 15, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.