CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-48010
6.5 MEDIUM

Dell PowerProtect DD, versions prior to 8.1.0.0, 7.13.1.10, 7.10.1.40, and 7.7.5.50, contains an access control vulnerability. A remote high privileged attacker could potentially exploit this …

Nov 8, 2024
CVE-2024-45759
6.8 MEDIUM

Dell PowerProtect Data Domain, versions prior to 8.1.0.0, 7.13.1.10, 7.10.1.40, and 7.7.5.50, contains an escalation of privilege vulnerability. A local low privileged attacker could potentially …

Nov 8, 2024
CVE-2024-51987
5.4 MEDIUM

Duende.AccessTokenManagement.OpenIdConnect is a set of .NET libraries that manage OAuth and OpenId Connect access tokens. HTTP Clients created by `AddUserAccessTokenHttpClient` may use a different user's …

Nov 8, 2024
CVE-2024-8810
6.5 MEDIUM

A GitHub App installed in organizations could upgrade some permissions from read to write access without approval from an organization administrator. An attacker would require …

Nov 7, 2024
CVE-2024-51434
6.1 MEDIUM

Inconsistent <plaintext> tag parsing allows for XSS in Froala WYSIWYG editor 4.3.0 and earlier.

Nov 7, 2024
CVE-2024-49524
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute …

Nov 7, 2024
CVE-2024-49523
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject …

Nov 7, 2024
CVE-2024-36064
6.2 MEDIUM

The NLL com.nll.cb (aka ACR Phone) application through 0.330-playStore-NoAccessibility-arm8 for Android allows any installed application (with no permissions) to place phone calls without user interaction …

Nov 7, 2024
CVE-2024-36062
4.0 MEDIUM

The com.callassistant.android (aka AI Call Assistant & Screener) application 1.174 for Android enables any installed application (with no permissions) to place phone calls without user …

Nov 7, 2024
CVE-2024-10824
6.5 MEDIUM

An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed unauthorized internal users to access sensitive secret scanning alert data intended only for …

Nov 7, 2024
CVE-2024-50599
6.1 MEDIUM

A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Zimbra Collaboration Suite (ZCS) 8.8.15, affecting one of the webmail calendar endpoints. This arises from …

Nov 7, 2024
CVE-2019-20472
6.2 MEDIUM

An issue was discovered on One2Track 2019-12-08 devices. Any SIM card used with the device cannot have a PIN configured. If a PIN is configured, …

Nov 7, 2024
CVE-2019-20469
4.6 MEDIUM

An issue was discovered on One2Track 2019-12-08 devices. Confidential information is needlessly stored on the smartwatch. Audio files are stored in .amr format, in the …

Nov 7, 2024
CVE-2019-20462
5.3 MEDIUM

An issue was discovered on Alecto IVM-100 2019-11-12 devices. The device comes with a serial interface at the board level. By attaching to this serial …

Nov 7, 2024
CVE-2024-51994
5.4 MEDIUM

Combodo iTop is a web based IT Service Management tool. In affected versions uploading a text file containing some java script in the portal will …

Nov 7, 2024
CVE-2024-48290
4.3 MEDIUM

An issue in the Bluetooth Low Energy implementation of Realtek RTL8762E BLE SDK v1.4.0 allows attackers to cause a Denial of Service (DoS) via supplying …

Nov 7, 2024
CVE-2024-10966
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in TOTOLINK X18 9.1.0cu.2024_B20220329. Affected by this issue is some unknown functionality of the file …

Nov 7, 2024
CVE-2020-11918
5.4 MEDIUM

An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. When a backup file is created through the web interface, information on all users, including passwords, can …

Nov 7, 2024
CVE-2020-11917
4.3 MEDIUM

An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. It uses a default SSID value, which makes it easier for remote attackers to discover the physical …

Nov 7, 2024
CVE-2020-11916
6.3 MEDIUM

An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. The password for the root user is hashed using an old and deprecated hashing technique. Because of …

Nov 7, 2024
CVE-2024-48954
6.4 MEDIUM

An issue was discovered in Logpoint before 7.5.0. Unvalidated input during the EventHub Collector setup by an authenticated user leads to Remote Code execution.

Nov 7, 2024
CVE-2024-48952
6.4 MEDIUM

An issue was discovered in Logpoint before 7.5.0. SOAR uses a static JWT secret key to generate tokens that allow access to SOAR API endpoints …

Nov 7, 2024
CVE-2024-10965
4.3 MEDIUM

A vulnerability classified as problematic was found in emqx neuron up to 2.10.0. Affected by this vulnerability is an unknown functionality of the file /api/v2/schema …

Nov 7, 2024
CVE-2024-10964
6.3 MEDIUM

A vulnerability classified as critical has been found in emqx neuron up to 2.10.0. Affected is the function handle_add_plugin in the library cmd.library of the …

Nov 7, 2024
CVE-2024-8378
4.8 MEDIUM

The Safe SVG WordPress plugin before 2.2.6 has its sanitisation code is only running for paths that call wp_handle_upload, but not for example for code …

Nov 7, 2024
CVE-2024-9926
4.3 MEDIUM

The Jetpack WordPress plugin does not have proper authorisation in one of its REST endpoint, allowing any authenticated users, such as subscriber to read arbitrary …

Nov 7, 2024
CVE-2024-8442
6.4 MEDIUM

The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Nov 7, 2024
CVE-2024-50172
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Fix a possible memory leak In bnxt_re_setup_chip_ctx() when bnxt_qplib_map_db_bar() fails driver is not freeing …

Nov 7, 2024
CVE-2024-50171
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: systemport: fix potential memory leak in bcm_sysport_xmit() The bcm_sysport_xmit() returns NETDEV_TX_OK without freeing skb …

Nov 7, 2024
CVE-2024-50170
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: bcmasp: fix potential memory leak in bcmasp_xmit() The bcmasp_xmit() returns NETDEV_TX_OK without freeing skb …

Nov 7, 2024
CVE-2024-50169
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: vsock: Update rx_bytes on read_skb() Make sure virtio_transport_inc_rx_pkt() and virtio_transport_dec_rx_pkt() calls are balanced (i.e. virtio_vsock_sock::rx_bytes …

Nov 7, 2024
CVE-2024-50168
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/sun3_82586: fix potential memory leak in sun3_82586_send_packet() The sun3_82586_send_packet() returns NETDEV_TX_OK without freeing skb in …

Nov 7, 2024
CVE-2024-50167
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: be2net: fix potential memory leak in be_xmit() The be_xmit() returns NETDEV_TX_OK without freeing skb in …

Nov 7, 2024
CVE-2024-50166
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fsl/fman: Fix refcount handling of fman-related devices In mac_probe() there are multiple calls to of_find_device_by_node(), …

Nov 7, 2024
CVE-2024-50165
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: Preserve param->string when parsing mount options In bpf_parse_param(), keep the value of param->string intact …

Nov 7, 2024
CVE-2024-50163
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: Make sure internal and UAPI bpf_redirect flags don't overlap The bpf_redirect_info is shared between …

Nov 7, 2024
CVE-2024-50162
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: devmap: provide rxq after redirect rxq contains a pointer to the device from where …

Nov 7, 2024
CVE-2024-50161
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: Check the remaining info_cnt before repeating btf fields When trying to repeat the btf …

Nov 7, 2024
CVE-2024-50160
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ALSA: hda/cs8409: Fix possible NULL dereference If snd_hda_gen_add_kctl fails to allocate memory and returns NULL, …

Nov 7, 2024
CVE-2024-50157
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Avoid CPU lockups due fifo occupancy check loop Driver waits indefinitely for the fifo …

Nov 7, 2024
CVE-2024-50156
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/msm: Avoid NULL dereference in msm_disp_state_print_regs() If the allocation in msm_disp_state_dump_regs() failed then `block->state` can …

Nov 7, 2024
CVE-2024-50153
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: target: core: Fix null-ptr-deref in target_alloc_device() There is a null-ptr-deref issue reported by KASAN: …

Nov 7, 2024
CVE-2024-50152
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix possible double free in smb2_set_ea() Clang static checker(scan-build) warning: fs/smb/client/smb2ops.c:1304:2: Attempt to …

Nov 7, 2024
CVE-2024-50149
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/xe: Don't free job in TDR Freeing job in TDR is not safe as TDR …

Nov 7, 2024
CVE-2024-50148
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: bnep: fix wild-memory-access in proto_unregister There's issue as follows: KASAN: maybe wild-memory-access in range …

Nov 7, 2024
CVE-2024-50147
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix command bitmask initialization Command bitmask have a dedicated bit for MANAGE_PAGES command, this …

Nov 7, 2024
CVE-2024-50146
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Don't call cleanup on profile rollback failure When profile rollback fails in mlx5e_netdev_change_profile, the …

Nov 7, 2024
CVE-2024-50145
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: octeon_ep: Add SKB allocation failures handling in __octep_oq_process_rx() build_skb() returns NULL in case of a …

Nov 7, 2024
CVE-2024-50144
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/xe: fix unbalanced rpm put() with fence_fini() Currently we can call fence_fini() twice if something …

Nov 7, 2024
CVE-2024-50142
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: xfrm: validate new SA's prefixlen using SA family when sel.family is unset This expands the …

Nov 7, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.