CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-43638
6.8 MEDIUM

Windows USB Video Class System Driver Elevation of Privilege Vulnerability

Nov 12, 2024
CVE-2024-43637
6.8 MEDIUM

Windows USB Video Class System Driver Elevation of Privilege Vulnerability

Nov 12, 2024
CVE-2024-43634
6.8 MEDIUM

Windows USB Video Class System Driver Elevation of Privilege Vulnerability

Nov 12, 2024
CVE-2024-43633
6.5 MEDIUM

Windows Hyper-V Denial of Service Vulnerability

Nov 12, 2024
CVE-2024-43631
6.7 MEDIUM

Windows Secure Kernel Mode Elevation of Privilege Vulnerability

Nov 12, 2024
CVE-2024-43451
6.5 MEDIUM KEV

NTLM Hash Disclosure Spoofing Vulnerability

Nov 12, 2024
CVE-2024-43449
6.8 MEDIUM

Windows USB Video Class System Driver Elevation of Privilege Vulnerability

Nov 12, 2024
CVE-2024-38264
5.9 MEDIUM

Microsoft Virtual Hard Disk (VHDX) Denial of Service Vulnerability

Nov 12, 2024
CVE-2024-38203
6.2 MEDIUM

Windows Package Library Manager Information Disclosure Vulnerability

Nov 12, 2024
CVE-2024-21949
5.5 MEDIUM

Improper validation of user input in the NPU driver could allow an attacker to provide a buffer with unexpected size, potentially leading to system crash.

Nov 12, 2024
CVE-2024-9999
6.5 MEDIUM

In WS_FTP Server versions before 8.8.9 (2022.0.9), an Incorrect Implementation of Authentication Algorithm in the Web Transfer Module allows users to skip the second-factor verification …

Nov 12, 2024
CVE-2024-9843
5.0 MEDIUM

A buffer over-read in Ivanti Secure Access Client before 22.7R4 allows a local unauthenticated attacker to cause a denial of service.

Nov 12, 2024
CVE-2024-51750
5.0 MEDIUM

Element is a Matrix web client built using the Matrix React SDK. A malicious homeserver can send invalid messages over federation which can prevent Element …

Nov 12, 2024
CVE-2024-49527
5.5 MEDIUM

Animate versions 23.0.7, 24.0.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage …

Nov 12, 2024
CVE-2024-30133
5.3 MEDIUM

HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a control flow vulnerability. The application does not sufficiently manage its control flow during execution, creating …

Nov 12, 2024
CVE-2024-11004
6.1 MEDIUM

Reflected XSS in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allows a remote unauthenticated attacker to obtain admin privileges. …

Nov 12, 2024
CVE-2024-52296
6.5 MEDIUM

libosdp is an implementation of IEC 60839-11-5 OSDP (Open Supervised Device Protocol) and provides a C library with support for C++, Rust and Python3. At …

Nov 12, 2024
CVE-2024-47909
4.9 MEDIUM

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin …

Nov 12, 2024
CVE-2024-47905
4.9 MEDIUM

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin …

Nov 12, 2024
CVE-2024-47535
5.5 MEDIUM

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. An unsafe reading of environment file …

Nov 12, 2024
CVE-2024-10971
4.3 MEDIUM

Improper access control in the Password History feature in Devolutions DVLS 2024.3.6 and earlier allows a malicious authenticated user to obtain sensitive data via faulty …

Nov 12, 2024
CVE-2024-51566
6.5 MEDIUM

The NVMe driver queue processing is vulernable to guest-induced infinite loops.

Nov 12, 2024
CVE-2024-51565
6.5 MEDIUM

The hda driver is vulnerable to a buffer over-read from a guest-controlled value.

Nov 12, 2024
CVE-2024-51563
6.5 MEDIUM

The virtio_vq_recordon function is subject to a time-of-check to time-of-use (TOCTOU) race condition.

Nov 12, 2024
CVE-2024-51562
6.5 MEDIUM

The NVMe driver function nvme_opc_get_log_page is vulnerable to a buffer over-read from a guest-controlled value.

Nov 12, 2024
CVE-2024-39281
5.3 MEDIUM

The command ctl_persistent_reserve_out allows the caller to specify an arbitrary size which will be passed to the kernel's memory allocator.

Nov 12, 2024
CVE-2024-33660
4.3 MEDIUM

An exploit is possible where an actor with physical access can manipulate SPI flash without being detected.

Nov 12, 2024
CVE-2024-11127
6.3 MEDIUM

A vulnerability was found in code-projects Job Recruitment up to 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Nov 12, 2024
CVE-2024-11125
4.3 MEDIUM

A vulnerability was found in GetSimpleCMS 3.3.16 and classified as problematic. This issue affects some unknown processing of the file /admin/profile.php. The manipulation leads to …

Nov 12, 2024
CVE-2024-11124
4.7 MEDIUM

A vulnerability has been found in TimGeyssens UIOMatic 5 and classified as critical. This vulnerability affects unknown code of the file /src/UIOMatic/wwwroot/backoffice/resources/uioMaticObject.r. The manipulation leads …

Nov 12, 2024
CVE-2024-50561
4.3 MEDIUM

A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V8.2), SCALANCE …

Nov 12, 2024
CVE-2024-50559
4.3 MEDIUM

A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V8.2), SCALANCE …

Nov 12, 2024
CVE-2024-50558
4.3 MEDIUM

A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V8.2), SCALANCE …

Nov 12, 2024
CVE-2024-50313
5.3 MEDIUM

A vulnerability has been identified in Mendix Runtime V10 (All versions < V10.16.0 only if the basic authentication mechanism is used by the application), Mendix …

Nov 12, 2024
CVE-2024-46894
6.3 MEDIUM

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly validate authorization of a …

Nov 12, 2024
CVE-2024-46892
4.9 MEDIUM

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly invalidate sessions when the …

Nov 12, 2024
CVE-2024-46891
5.3 MEDIUM

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly restrict the size of …

Nov 12, 2024
CVE-2024-46889
5.3 MEDIUM

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application uses hard-coded cryptographic key material to obfuscate …

Nov 12, 2024
CVE-2024-36140
6.8 MEDIUM

A vulnerability has been identified in OZW672 (All versions < V5.2), OZW772 (All versions < V5.2). The user accounts tab of affected devices is vulnerable …

Nov 12, 2024
CVE-2024-11123
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in 上海灵当信息科技有限公司 Lingdang CRM up to 8.6.4.3. This affects an unknown part of the file /crm/data/pdf.php. …

Nov 12, 2024
CVE-2024-11122
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in 上海灵当信息科技有限公司 Lingdang CRM up to 8.6.4.3. Affected by this issue is some unknown functionality …

Nov 12, 2024
CVE-2024-11121
6.3 MEDIUM

A vulnerability classified as critical was found in 上海灵当信息科技有限公司 Lingdang CRM up to 8.6.4.3. Affected by this vulnerability is an unknown functionality of the file …

Nov 12, 2024
CVE-2024-10323
6.4 MEDIUM

The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and …

Nov 12, 2024
CVE-2024-10179
6.4 MEDIUM

The Slickstream: Engagement and Conversions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's slick-grid shortcode in all versions up to, and …

Nov 12, 2024
CVE-2024-9836
5.9 MEDIUM

The RSS Feed Widget WordPress plugin before 3.0.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post …

Nov 12, 2024
CVE-2024-9835
4.8 MEDIUM

The RSS Feed Widget WordPress plugin before 3.0.1 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to …

Nov 12, 2024
CVE-2024-9357
6.1 MEDIUM

The xili-tidy-tags plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'action' parameter in all versions up to, and including, 1.12.04 due to …

Nov 12, 2024
CVE-2024-29075
4.6 MEDIUM

Active debug code vulnerability exists in Mesh Wi-Fi router RP562B firmware version v1.0.2 and earlier. If this vulnerability is exploited, a network-adjacent authenticated attacker may …

Nov 12, 2024
CVE-2024-10790
5.4 MEDIUM

The Admin and Site Enhancements (ASE) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and …

Nov 12, 2024
CVE-2024-11101
4.7 MEDIUM

A vulnerability was found in 1000 Projects Beauty Parlour Management System 1.0. It has been classified as critical. Affected is an unknown function of the …

Nov 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.