CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-50141
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ACPI: PRM: Find EFI_MEMORY_RUNTIME block for PRM handler and context PRMT needs to find the …

Nov 7, 2024
CVE-2024-50140
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: sched/core: Disable page allocation in task_tick_mm_cid() With KASAN and PREEMPT_RT enabled, calling task_work_add() in task_tick_mm_cid() …

Nov 7, 2024
CVE-2024-50139
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Fix shift-out-of-bounds bug Fix a shift-out-of-bounds bug reported by UBSAN when running VM …

Nov 7, 2024
CVE-2023-1932
6.1 MEDIUM

A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. …

Nov 7, 2024
CVE-2024-30141
4.7 MEDIUM

HCL BigFix Compliance is vulnerable to the generation of error messages containing sensitive information. Detailed error messages can provide enticement information or expose information about …

Nov 7, 2024
CVE-2024-30140
5.4 MEDIUM

HCL BigFix Compliance is affected by unvalidated redirects and forwards. The HOST header can be manipulated by an attacker and as a result, it can …

Nov 7, 2024
CVE-2024-10027
4.8 MEDIUM

The WP Booking Calendar WordPress plugin before 10.6.3 does not sanitise and escape some of its Widgets settings, which could allow high privilege users such …

Nov 7, 2024
CVE-2024-10947
4.7 MEDIUM

A vulnerability classified as critical was found in Guangzhou Tuchuang Computer Software Development Interlib Library Cluster Automation Management System up to 2.0.1. This vulnerability affects …

Nov 7, 2024
CVE-2024-10946
4.7 MEDIUM

A vulnerability classified as critical has been found in Guangzhou Tuchuang Computer Software Development Interlib Library Cluster Automation Management System up to 2.0.1. This affects …

Nov 7, 2024
CVE-2024-51409
6.5 MEDIUM

Buffer Overflow vulnerability in Tenda O3 v.1.0.0.5 allows a remote attacker to cause a denial of service via a network packet in a fixed format …

Nov 6, 2024
CVE-2024-10941
6.5 MEDIUM

A malicious website could have included an iframe with an malformed URI resulting in a non-exploitable browser crash. This vulnerability affects Firefox < 126.

Nov 6, 2024
CVE-2024-51988
6.5 MEDIUM

RabbitMQ is a feature rich, multi-protocol messaging and streaming broker. In affected versions queue deletion via the HTTP API was not verifying the `configure` permission …

Nov 6, 2024
CVE-2024-51751
6.5 MEDIUM

Gradio is an open-source Python package designed to enable quick builds of a demo or web application. If File or UploadButton components are used as …

Nov 6, 2024
CVE-2024-50637
5.4 MEDIUM

UnoPim 0.1.3 and below is vulnerable to Cross Site Scripting (XSS) in the Create User function. This allows attackers to perform XSS via an SVG …

Nov 6, 2024
CVE-2024-20540
5.4 MEDIUM

A vulnerability in the web-based management interface of Cisco Unified Contact Center Management Portal (Unified CCMP) could allow an authenticated, remote attacker with low privileges …

Nov 6, 2024
CVE-2024-20539
4.8 MEDIUM

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct a stored XSS attack against a user …

Nov 6, 2024
CVE-2024-20538
6.1 MEDIUM

A vulnerability in the web-based management interface of Cisco ISE could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of …

Nov 6, 2024
CVE-2024-20537
6.5 MEDIUM

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to bypass the authorization mechanisms for specific administrative functions. …

Nov 6, 2024
CVE-2024-20534
4.8 MEDIUM

A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 6800, 7800, and 8800 Series, and Cisco Video Phone 8875 …

Nov 6, 2024
CVE-2024-20533
4.8 MEDIUM

A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 6800, 7800, and 8800 Series, and Cisco Video Phone 8875 …

Nov 6, 2024
CVE-2024-20532
5.5 MEDIUM

A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read and delete arbitrary files on an affected device. To …

Nov 6, 2024
CVE-2024-20531
5.5 MEDIUM

A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system of an …

Nov 6, 2024
CVE-2024-20530
6.1 MEDIUM

A vulnerability in the web-based management interface of Cisco ISE could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of …

Nov 6, 2024
CVE-2024-20529
5.5 MEDIUM

A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read and delete arbitrary files on an affected device. To …

Nov 6, 2024
CVE-2024-20527
5.5 MEDIUM

A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read and delete arbitrary files on an affected device. To …

Nov 6, 2024
CVE-2024-20525
6.1 MEDIUM

A vulnerability in the web-based management interface of Cisco ISE could allow an unauthenticated, remote attacker to conduct an XSS attack against a user of …

Nov 6, 2024
CVE-2024-20514
5.4 MEDIUM

A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, low-privileged, remote attacker …

Nov 6, 2024
CVE-2024-20511
6.1 MEDIUM

A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) …

Nov 6, 2024
CVE-2024-20507
4.3 MEDIUM

A vulnerability in the logging subsystem of Cisco Meeting Management could allow an authenticated, remote attacker to view sensitive information in clear text on an …

Nov 6, 2024
CVE-2024-20504
5.4 MEDIUM

A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager, Secure Email Gateway, and Secure Web Appliance …

Nov 6, 2024
CVE-2024-20487
4.3 MEDIUM

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct a stored XSS attack against a user …

Nov 6, 2024
CVE-2024-20476
4.3 MEDIUM

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to bypass the authorization mechanisms for specific file management …

Nov 6, 2024
CVE-2024-20457
6.5 MEDIUM

A vulnerability in the logging component of Cisco Unified Communications Manager IM &amp; Presence Service (Unified CM IM&amp;P) could allow an authenticated, remote attacker to …

Nov 6, 2024
CVE-2024-20445
5.3 MEDIUM

A vulnerability in the web UI of Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 could …

Nov 6, 2024
CVE-2024-20371
5.3 MEDIUM

A vulnerability in the access control list (ACL) programming of Cisco Nexus 3550-F Switches could allow an unauthenticated, remote attacker to send traffic that should …

Nov 6, 2024
CVE-2024-10318
5.4 MEDIUM

A session fixation issue was discovered in the NGINX OpenID Connect reference implementation, where a nonce was not checked at login time. This flaw allows …

Nov 6, 2024
CVE-2024-10919
6.3 MEDIUM

A vulnerability has been found in didi Super-Jacoco 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /cov/triggerUnitCover. …

Nov 6, 2024
CVE-2024-35146
5.4 MEDIUM

IBM Maximo Application Suite - Monitor Component 8.10.11, 8.11.8, and 9.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary …

Nov 6, 2024
CVE-2024-10916
5.3 MEDIUM

A vulnerability classified as problematic has been found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. This affects an unknown part of the …

Nov 6, 2024
CVE-2024-10186
6.4 MEDIUM

The Event post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's events_cal shortcode in all versions up to, and including, 5.9.6 …

Nov 6, 2024
CVE-2024-8323
6.4 MEDIUM

The Pricing Tables WordPress Plugin – Easy Pricing Tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘fontFamily’ attribute in all versions …

Nov 6, 2024
CVE-2024-10168
6.4 MEDIUM

The Active Products Tables for WooCommerce. Use constructor to create tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's woot_button shortcode …

Nov 6, 2024
CVE-2024-10715
6.4 MEDIUM

The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Map block in all versions up to, and …

Nov 6, 2024
CVE-2024-9902
6.3 MEDIUM

A flaw was found in Ansible. The ansible-core `user` module can allow an unprivileged user to silently create or replace the contents of any file …

Nov 6, 2024
CVE-2024-9681
6.5 MEDIUM

When curl is asked to use HSTS, the expiry time for a subdomain might overwrite a parent domain's cache entry, making it end sooner or …

Nov 6, 2024
CVE-2024-52043
5.3 MEDIUM

Generation of Error Message Containing Sensitive Information in HumHub GmbH & Co. KG - HumHub on Linux allows: Excavation (user enumeration).This issue affects all released …

Nov 6, 2024
CVE-2024-6626
5.3 MEDIUM

The EleForms – All In One Form Integration including DB for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a …

Nov 6, 2024
CVE-2024-10543
4.3 MEDIUM

The Tumult Hype Animations plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the hypeanimations_getcontent function in …

Nov 6, 2024
CVE-2024-10535
5.3 MEDIUM

The Video Gallery for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the remove_unused_thumbnails() function …

Nov 6, 2024
CVE-2024-9934
6.1 MEDIUM

The Wp-ImageZoom WordPress plugin through 1.1.0 does not sanitise and escape some parameters before outputting them back in a page, leading to a Reflected Cross-Site …

Nov 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.