CVE Database

46624+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-38403
7.5 HIGH

Transient DOS while parsing BTM ML IE when per STA profile is not included.

Nov 4, 2024
CVE-2024-33068
7.5 HIGH

Transient DOS while parsing fragments of MBSSID IE from beacon frame.

Nov 4, 2024
CVE-2024-23385
7.5 HIGH

Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.

Nov 4, 2024
CVE-2024-10758
7.3 HIGH

A vulnerability, which was classified as critical, was found in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. This affects an unknown part of the file …

Nov 4, 2024
CVE-2024-20104
8.4 HIGH

In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Nov 4, 2024
CVE-2024-10752
7.3 HIGH

A vulnerability was found in Codezips Pet Shop Management System 1.0. It has been classified as critical. This affects an unknown part of the file …

Nov 4, 2024
CVE-2024-10741
7.3 HIGH

A vulnerability has been found in code-projects E-Health Care System 1.0 and classified as critical. This vulnerability affects unknown code of the file /Users/registration.php. The …

Nov 3, 2024
CVE-2024-10739
7.3 HIGH

A vulnerability, which was classified as critical, has been found in code-projects E-Health Care System 1.0. Affected by this issue is some unknown functionality of …

Nov 3, 2024
CVE-2024-10737
7.3 HIGH

A vulnerability classified as critical has been found in Codezips Free Exam Hall Seating Management System 1.0. Affected is an unknown function of the file …

Nov 3, 2024
CVE-2024-10736
7.3 HIGH

A vulnerability was found in Codezips Free Exam Hall Seating Management System 1.0. It has been rated as critical. This issue affects some unknown processing …

Nov 3, 2024
CVE-2024-10733
7.3 HIGH

A vulnerability was found in code-projects Restaurant Order System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Nov 3, 2024
CVE-2024-10702
7.3 HIGH

A vulnerability classified as critical has been found in code-projects Simple Car Rental System 1.0. Affected is an unknown function of the file /signup.php. The …

Nov 2, 2024
CVE-2024-10699
7.3 HIGH

A vulnerability was found in code-projects Wazifa System 1.0. It has been classified as critical. This affects an unknown part of the file /controllers/logincontrol.php. The …

Nov 2, 2024
CVE-2024-10698
8.8 HIGH

A vulnerability was found in Tenda AC6 15.03.05.19 and classified as critical. Affected by this issue is the function formSetDeviceName of the file /goform/SetOnlineDevName. The …

Nov 2, 2024
CVE-2024-51774
8.1 HIGH

qBittorrent before 5.0.1 proceeds with use of https URLs even after certificate validation errors.

Nov 2, 2024
CVE-2024-9191
7.1 HIGH

The Okta Device Access features, provided by the Okta Verify agent for Windows, provides access to the OktaDeviceAccessPipe, which enables attackers in a compromised device …

Nov 1, 2024
CVE-2024-48353
7.5 HIGH

Yealink Meeting Server before V26.0.0.67 allows attackers to obtain static key information from a front-end JS file and decrypt the plaintext passwords based on the …

Nov 1, 2024
CVE-2024-51492
8.8 HIGH

Zusam is a free and open-source way to self-host private forums. Prior to version 0.5.6, specially crafted SVG files uploaded to the service as images …

Nov 1, 2024
CVE-2024-51248
8.8 HIGH

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the modifyrow function.

Nov 1, 2024
CVE-2024-51247
8.8 HIGH

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPPo function.

Nov 1, 2024
CVE-2024-51245
8.8 HIGH

In DrayTek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the rename_table function.

Nov 1, 2024
CVE-2024-51244
8.8 HIGH

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doIPSec function.

Nov 1, 2024
CVE-2024-48352
7.5 HIGH

Yealink Meeting Server before V26.0.0.67 is vulnerable to sensitive data exposure in the server response via sending HTTP request with enterprise ID.

Nov 1, 2024
CVE-2024-48217
8.8 HIGH

An Insecure Direct Object Reference (IDOR) in the dashboard of SiSMART v7.4.0 allows attackers to execute a horizontal-privilege escalation.

Nov 1, 2024
CVE-2024-40490
7.5 HIGH

An issue in Sourcebans++ before v.1.8.0 allows a remote attacker to obtain sensitive information via a crafted XAJAX call to the Forgot Password function.

Nov 1, 2024
CVE-2024-22733
7.5 HIGH

TP Link MR200 V4 Firmware version 210201 was discovered to contain a null-pointer-dereference in the web administration panel on /cgi/login via the sign, Action or …

Nov 1, 2024
CVE-2024-10662
8.8 HIGH

A vulnerability was found in Tenda AC15 15.03.05.19 and classified as critical. This issue affects the function formSetDeviceName of the file /goform/SetOnlineDevName. The manipulation of …

Nov 1, 2024
CVE-2024-10661
8.8 HIGH

A vulnerability has been found in Tenda AC15 15.03.05.19 and classified as critical. This vulnerability affects the function SetDlnaCfg of the file /goform/SetDlnaCfg. The manipulation …

Nov 1, 2024
CVE-2024-47314
7.1 HIGH

Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Photo Cart: from n/a through …

Nov 1, 2024
CVE-2024-43982
8.8 HIGH

Missing Authorization vulnerability in Geek Code Lab Login As Users allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Login As Users: from n/a …

Nov 1, 2024
CVE-2024-43235
7.1 HIGH

Missing Authorization vulnerability in MetaBox.Io Meta Box – WordPress Custom Fields Framework allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Meta Box – …

Nov 1, 2024
CVE-2024-43212
7.5 HIGH

Missing Authorization vulnerability in MagePeople Team WpTravelly allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WpTravelly: from n/a through 1.7.7.

Nov 1, 2024
CVE-2024-43158
7.5 HIGH

Missing Authorization vulnerability in masteriyo Masteriyo - LMS learning-management-system.This issue affects Masteriyo - LMS: from n/a through <= 1.11.4.

Nov 1, 2024
CVE-2024-39664
7.3 HIGH

Missing Authorization vulnerability in YMC Filter & Grids allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Filter & Grids: from n/a through 2.8.33.

Nov 1, 2024
CVE-2024-39650
7.3 HIGH

Missing Authorization vulnerability in WPWeb Elite WooCommerce PDF Vouchers allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WooCommerce PDF Vouchers: from n/a through …

Nov 1, 2024
CVE-2024-38744
8.3 HIGH

Missing Authorization vulnerability in Upqode Plum: Spin Wheel & Email Pop-up allows Accessing Functionality Not Properly Constrained by ACLs, Stored XSS.This issue affects Plum: Spin …

Nov 1, 2024
CVE-2024-38726
7.5 HIGH

Missing Authorization vulnerability in PickPlugins Product Designer allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Product Designer: from n/a through 1.0.33.

Nov 1, 2024
CVE-2024-38721
7.1 HIGH

Missing Authorization vulnerability in spider-themes EazyDocs allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects EazyDocs: from n/a through 2.5.0.

Nov 1, 2024
CVE-2024-37470
8.2 HIGH

Missing Authorization vulnerability in WofficeIO Woffice Core allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Woffice Core: from n/a through 5.4.8.

Nov 1, 2024
CVE-2024-37423
8.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Automattic Newspack Blocks allows Path Traversal.This issue affects Newspack Blocks: from n/a …

Nov 1, 2024
CVE-2024-37277
7.5 HIGH

Authorization Bypass Through User-Controlled Key vulnerability in Paid Memberships Pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Paid Memberships Pro: from n/a …

Nov 1, 2024
CVE-2024-37232
8.8 HIGH

Missing Authorization vulnerability in Hercules Design Hercules Core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hercules Core: from n/a through 6.5.

Nov 1, 2024
CVE-2024-37108
7.7 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WishList Products WishList Member X allows Path Traversal.This issue affects WishList Member …

Nov 1, 2024
CVE-2024-37106
8.2 HIGH

Missing Authorization vulnerability in WishList Products WishList Member X allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WishList Member X: from n/a through …

Nov 1, 2024
CVE-2024-27524
7.1 HIGH

Cross Site Scripting vulnerability in Chamilo LMS v.1.11.26 allows a remote attacker to escalate privileges via a crafted script to the filename parameter of the …

Nov 1, 2024
CVE-2024-48270
7.5 HIGH

An issue in the component /logins of oasys v1.1 allows attackers to access sensitive information via a burst attack.

Nov 1, 2024
CVE-2024-37094
8.2 HIGH

Missing Authorization vulnerability in StylemixThemes MasterStudy LMS allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MasterStudy LMS: from n/a through 3.2.12.

Nov 1, 2024
CVE-2024-10653
7.2 HIGH

IDExpert from CHANGING Information Technology does not properly validate a specific parameter in the administrator interface, allowing remote attackers with administrative privileges to inject and …

Nov 1, 2024
CVE-2024-0106
8.7 HIGH

NVIDIA ConnectX Host Firmware for the BlueField Data Processing Unit (DPU) contains a vulnerability where an attacker may cause an improper handling of insufficient privileges …

Nov 1, 2024
CVE-2024-0105
8.9 HIGH

NVIDIA ConnectX Firmware contains a vulnerability where an attacker may cause an improper handling of insufficient privileges issue. A successful exploit of this vulnerability may …

Nov 1, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.