CVE Database

46624+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-45148
8.8 HIGH

Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Authentication vulnerability that could result in a security feature bypass. A …

Oct 10, 2024
CVE-2024-45117
7.6 HIGH

Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. …

Oct 10, 2024
CVE-2024-45116
8.1 HIGH

Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by a Cross-Site Scripting (XSS) vulnerability that could be exploited to execute arbitrary code. …

Oct 10, 2024
CVE-2024-9781
7.8 HIGH

AppleTalk and RELOAD Framing dissector crash in Wireshark 4.4.0 and 4.2.0 to 4.2.7 allows denial of service via packet injection or crafted capture file

Oct 10, 2024
CVE-2024-9780
7.8 HIGH

ITS dissector crash in Wireshark 4.4.0 allows denial of service via packet injection or crafted capture file

Oct 10, 2024
CVE-2024-9156
7.5 HIGH

The TI WooCommerce Wishlist WordPress plugin through 2.8.2 is vulnerable to SQL Injection due to insufficient escaping on the user supplied parameter and lack of …

Oct 10, 2024
CVE-2024-9022
7.2 HIGH

The TS Poll – Survey, Versus Poll, Image Poll, Video Poll plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter in all …

Oct 10, 2024
CVE-2024-9581
7.3 HIGH

The Shortcodes AnyWhere plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.0.1. This is due to the …

Oct 10, 2024
CVE-2024-9522
8.8 HIGH

The WP Users Masquerade plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.0. This is due to incorrect authentication …

Oct 10, 2024
CVE-2024-9519
7.2 HIGH

The UserPlus plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the 'save_metabox_form' function in versions up …

Oct 10, 2024
CVE-2024-48958
7.8 HIGH

execute_filter_delta in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a crafted archive file because src can move beyond dst.

Oct 10, 2024
CVE-2024-48957
7.8 HIGH

execute_filter_audio in archive_read_support_format_rar.c in libarchive before 3.7.5 allows out-of-bounds access via a crafted archive file because src can move beyond dst.

Oct 10, 2024
CVE-2024-7037
7.2 HIGH

In version v0.3.8 of open-webui/open-webui, the endpoint /api/pipelines/upload is vulnerable to arbitrary file write and delete due to unsanitized file.filename concatenation with CACHE_DIR. This vulnerability …

Oct 9, 2024
CVE-2024-39525
7.5 HIGH

An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated …

Oct 9, 2024
CVE-2024-39516
7.5 HIGH

An Out-of-Bounds Read vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker sending …

Oct 9, 2024
CVE-2024-39515
7.5 HIGH

An Improper Validation of Consistency within Input vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an …

Oct 9, 2024
CVE-2024-3656
8.1 HIGH

A flaw was found in Keycloak. Certain endpoints in Keycloak's admin REST API allow low-privilege users to access administrative functionalities. This flaw allows users to …

Oct 9, 2024
CVE-2024-9473
7.8 HIGH

A privilege escalation vulnerability in the Palo Alto Networks GlobalProtect app on Windows allows a locally authenticated non-administrative Windows user to escalate their privileges to …

Oct 9, 2024
CVE-2024-9468
7.5 HIGH

A memory corruption vulnerability in Palo Alto Networks PAN-OS software allows an unauthenticated attacker to crash PAN-OS due to a crafted packet through the data …

Oct 9, 2024
CVE-2024-9463
7.5 HIGH KEV

An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in …

Oct 9, 2024
CVE-2024-46307
7.5 HIGH

A loop hole in the payment logic of Sparkshop v1.16 allows attackers to arbitrarily modify the number of products.

Oct 9, 2024
CVE-2024-43610
7.4 HIGH

Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view sensitive information through network attack vector

Oct 9, 2024
CVE-2024-46316
8.0 HIGH

DrayTek Vigor3900 v1.5.1.6 was discovered to contain a command injection vulnerability via the sub_2C920 function at /cgi-bin/mainfunction.cgi. This vulnerability allows attackers to execute arbitrary commands …

Oct 9, 2024
CVE-2024-46304
7.5 HIGH

A NULL pointer dereference in libcoap v4.3.5-rc2 and below allows a remote attacker to cause a denial of service via the coap_handle_request_put_block function in src/coap_block.c.

Oct 9, 2024
CVE-2024-46292
7.5 HIGH

A buffer overflow in modsecurity v3.0.12 allows attackers to cause a Denial of Service (DoS) via a crafted input inserted into the name parameter. NOTE: …

Oct 9, 2024
CVE-2024-9675
7.8 HIGH

A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are within our cache directory, allowing a …

Oct 9, 2024
CVE-2024-8048
7.8 HIGH

In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible using object injection via insecure expression evaluation.

Oct 9, 2024
CVE-2024-8014
8.8 HIGH

In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a code execution attack is possible through object injection via an insecure type resolution vulnerability.

Oct 9, 2024
CVE-2024-7840
7.8 HIGH

In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a command injection attack is possible through improper neutralization of hyperlink elements.

Oct 9, 2024
CVE-2024-7294
7.5 HIGH

In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), an HTTP DoS attack is possible on anonymous endpoints without rate limiting.

Oct 9, 2024
CVE-2024-7293
7.5 HIGH

In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a password brute forcing attack is possible through weak password requirements.

Oct 9, 2024
CVE-2024-7292
7.5 HIGH

In Progress® Telerik® Report Server versions prior to 2024 Q3 (10.2.24.806), a credential stuffing attack is possible through improper restriction of excessive login attempts.

Oct 9, 2024
CVE-2024-47670
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ocfs2: add bounds checking to ocfs2_xattr_find_entry() Add a paranoia check to make sure it doesn't …

Oct 9, 2024
CVE-2024-47425
7.8 HIGH

Adobe Framemaker versions 2020.6, 2022.4 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in …

Oct 9, 2024
CVE-2024-47424
7.8 HIGH

Adobe Framemaker versions 2020.6, 2022.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the …

Oct 9, 2024
CVE-2024-47423
7.8 HIGH

Adobe Framemaker versions 2020.6, 2022.4 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code …

Oct 9, 2024
CVE-2024-47422
7.8 HIGH

Adobe Framemaker versions 2020.6, 2022.4 and earlier are affected by an Untrusted Search Path vulnerability that could lead to arbitrary code execution. An attacker could …

Oct 9, 2024
CVE-2024-47421
7.8 HIGH

Adobe Framemaker versions 2020.6, 2022.4 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read …

Oct 9, 2024
CVE-2024-45137
7.8 HIGH

InDesign Desktop versions 19.4, 18.5.3 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code …

Oct 9, 2024
CVE-2024-45136
7.8 HIGH

InCopy versions 19.4, 18.5.3 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution …

Oct 9, 2024
CVE-2024-47659
8.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: smack: tcp: ipv4, fix incorrect labeling Currently, Smack mirrors the label of incoming tcp/ipv4 connections: …

Oct 9, 2024
CVE-2024-46871
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Correct the defined value for AMDGPU_DMUB_NOTIFICATION_MAX [Why & How] It actually exposes '6' types …

Oct 9, 2024
CVE-2024-45152
7.8 HIGH

Substance3D - Stager versions 3.0.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Oct 9, 2024
CVE-2024-45144
7.8 HIGH

Substance3D - Stager versions 3.0.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Oct 9, 2024
CVE-2024-45143
7.8 HIGH

Substance3D - Stager versions 3.0.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Oct 9, 2024
CVE-2024-45142
7.8 HIGH

Substance3D - Stager versions 3.0.3 and earlier are affected by a Write-what-where Condition vulnerability that could allow an attacker to execute arbitrary code in the …

Oct 9, 2024
CVE-2024-45141
7.8 HIGH

Substance3D - Stager versions 3.0.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Oct 9, 2024
CVE-2024-45140
7.8 HIGH

Substance3D - Stager versions 3.0.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Oct 9, 2024
CVE-2024-45139
7.8 HIGH

Substance3D - Stager versions 3.0.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Oct 9, 2024
CVE-2024-45138
7.8 HIGH

Substance3D - Stager versions 3.0.3 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

Oct 9, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.