CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-10577
6.1 MEDIUM

The 胖鼠采集(Fat Rat Collect) 微信知乎简书腾讯新闻列表分页采集, 还有自动采集、自动发布、自动标签、等多项功能。开源插件 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to missing escaping on a URL in all versions …

Nov 13, 2024
CVE-2024-10038
6.1 MEDIUM

The WP-Strava plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.12.1 due to insufficient …

Nov 13, 2024
CVE-2024-28731
4.3 MEDIUM

Cross Site Request Forgery vulnerability in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker …

Nov 12, 2024
CVE-2024-28730
5.4 MEDIUM

Cross Site Scripting vulnerability in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker to …

Nov 12, 2024
CVE-2024-28728
6.6 MEDIUM

Cross Site Scripting vulnerability in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker to …

Nov 12, 2024
CVE-2021-27704
6.5 MEDIUM

Appspace 6.2.4 is affected by Incorrect Access Control via the Appspace Web Portal password reset page.

Nov 12, 2024
CVE-2021-27703
5.4 MEDIUM

Sercomm Model Etisalat Model S3- AC2100 is affected by Cross Site Scripting (XSS) via the firmware update page.

Nov 12, 2024
CVE-2021-27701
4.7 MEDIUM

SOCIFI Socifi Guest wifi as SAAS is affected by Cross Site Request Forgery (CSRF) via the Socifi wifi portal. The application does not contain a …

Nov 12, 2024
CVE-2024-48075
5.3 MEDIUM

A Heap buffer overflow in the server-site handshake implementation in Real Time Logic SharkSSL from 09/09/24 and earlier allows a remote attacker to trigger a …

Nov 12, 2024
CVE-2024-49512
5.5 MEDIUM

InDesign Desktop versions ID18.5.3, ID19.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Nov 12, 2024
CVE-2024-49511
5.5 MEDIUM

InDesign Desktop versions ID18.5.3, ID19.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Nov 12, 2024
CVE-2024-49510
5.5 MEDIUM

InDesign Desktop versions ID18.5.3, ID19.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Nov 12, 2024
CVE-2024-11117
4.3 MEDIUM

Inappropriate implementation in FileSystem in Google Chrome prior to 131.0.6778.69 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. (Chromium security …

Nov 12, 2024
CVE-2024-11116
4.3 MEDIUM

Inappropriate implementation in Blink in Google Chrome prior to 131.0.6778.69 allowed a remote attacker who convinced a user to engage in specific UI gestures to …

Nov 12, 2024
CVE-2024-11111
4.3 MEDIUM

Inappropriate implementation in Autofill in Google Chrome prior to 131.0.6778.69 allowed a remote attacker who convinced a user to engage in specific UI gestures to …

Nov 12, 2024
CVE-2024-11110
6.5 MEDIUM

Inappropriate implementation in Extensions in Google Chrome prior to 131.0.6778.69 allowed a remote attacker to bypass site isolation via a crafted Chrome Extension. (Chromium security …

Nov 12, 2024
CVE-2024-47440
5.5 MEDIUM

Substance3D - Painter versions 10.1.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Nov 12, 2024
CVE-2024-47439
5.5 MEDIUM

Substance3D - Painter versions 10.1.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could …

Nov 12, 2024
CVE-2024-47438
5.5 MEDIUM

Substance3D - Painter versions 10.1.0 and earlier are affected by a Write-what-where Condition vulnerability that could lead to a memory leak. This vulnerability allows an …

Nov 12, 2024
CVE-2024-47437
5.5 MEDIUM

Substance3D - Painter versions 10.1.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Nov 12, 2024
CVE-2024-47436
5.5 MEDIUM

Substance3D - Painter versions 10.1.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Nov 12, 2024
CVE-2024-47435
5.5 MEDIUM

Substance3D - Painter versions 10.1.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Nov 12, 2024
CVE-2024-2207
6.0 MEDIUM

Potential vulnerabilities have been identified in the audio package for certain HP PC products using the Sound Research SECOMN64 driver, which might allow escalation of …

Nov 12, 2024
CVE-2024-51722
6.4 MEDIUM

A local privilege escalation vulnerability in the SecuSUITE Server (System Configuration) of SecuSUITE versions 5.0.420 and earlier could allow a successful attacker that had gained …

Nov 12, 2024
CVE-2024-47458
5.5 MEDIUM

Bridge versions 13.0.9, 14.1.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit …

Nov 12, 2024
CVE-2024-47457
5.5 MEDIUM

Illustrator versions 28.7.1 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this …

Nov 12, 2024
CVE-2024-47456
5.5 MEDIUM

Illustrator versions 28.7.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this …

Nov 12, 2024
CVE-2024-47455
5.5 MEDIUM

Illustrator versions 28.7.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this …

Nov 12, 2024
CVE-2024-47454
5.5 MEDIUM

Illustrator versions 28.7.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this …

Nov 12, 2024
CVE-2024-47453
5.5 MEDIUM

Illustrator versions 28.7.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this …

Nov 12, 2024
CVE-2024-47449
5.5 MEDIUM

Audition versions 23.6.9, 24.4.6 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage …

Nov 12, 2024
CVE-2024-47446
5.5 MEDIUM

After Effects versions 23.6.9, 24.6.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Nov 12, 2024
CVE-2024-47445
5.5 MEDIUM

After Effects versions 23.6.9, 24.6.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Nov 12, 2024
CVE-2024-47444
5.5 MEDIUM

After Effects versions 23.6.9, 24.6.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Nov 12, 2024
CVE-2024-45147
5.5 MEDIUM

Bridge versions 13.0.9, 14.1.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage …

Nov 12, 2024
CVE-2024-36509
4.2 MEDIUM

An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiWeb version 7.6.0, version 7.4.3 and below, version 7.2.10 and below, …

Nov 12, 2024
CVE-2024-33510
4.3 MEDIUM

An improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability [CWE-74] in FortiOS version 7.4.3 and below, version 7.2.8 and …

Nov 12, 2024
CVE-2024-33505
5.6 MEDIUM

A heap-based buffer overflow in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiManager version 7.4.0 through 7.4.2, …

Nov 12, 2024
CVE-2024-32118
6.7 MEDIUM

Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before …

Nov 12, 2024
CVE-2024-32117
4.9 MEDIUM

An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.4.0 through 7.4.2 and below 7.2.5, FortiAnalyzer …

Nov 12, 2024
CVE-2024-32116
5.1 MEDIUM

Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 and …

Nov 12, 2024
CVE-2024-31496
6.7 MEDIUM

A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 and …

Nov 12, 2024
CVE-2024-26011
5.3 MEDIUM

A missing authentication for critical function in Fortinet FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.14, FortiPAM version 1.2.0, …

Nov 12, 2024
CVE-2023-47543
5.4 MEDIUM

An authorization bypass through user-controlled key vulnerability [CWE-639] in Fortinet FortiPortal version 7.0.0 through 7.0.3 allows an authenticated attacker to interact with ressources of other …

Nov 12, 2024
CVE-2023-44255
4.1 MEDIUM

An exposure of sensitive information to an unauthorized actor [CWE-200] in Fortinet FortiManager before 7.4.2, FortiAnalyzer before 7.4.2 and FortiAnalyzer-BigData before 7.2.5 may allow a …

Nov 12, 2024
CVE-2024-51720
4.8 MEDIUM

An insufficient entropy vulnerability in the SecuSUITE Secure Client Authentication (SCA) Server of SecuSUITE versions 5.0.420 and earlier could allow an attacker to potentially enroll …

Nov 12, 2024
CVE-2024-49044
6.7 MEDIUM

Visual Studio Elevation of Privilege Vulnerability

Nov 12, 2024
CVE-2024-43646
6.7 MEDIUM

Windows Secure Kernel Mode Elevation of Privilege Vulnerability

Nov 12, 2024
CVE-2024-43645
6.7 MEDIUM

Windows Defender Application Control (WDAC) Security Feature Bypass Vulnerability

Nov 12, 2024
CVE-2024-43643
6.8 MEDIUM

Windows USB Video Class System Driver Elevation of Privilege Vulnerability

Nov 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.