CVE Database

5223+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-12667
3.7 LOW

A vulnerability was found in InvoicePlane up to 1.6.1 and classified as problematic. Affected by this issue is some unknown functionality of the file /invoices/view. …

Dec 16, 2024
CVE-2024-12665
3.5 LOW

A vulnerability, which was classified as problematic, was found in ruifang-tech Rebuild 3.8.5. Affected is an unknown function of the component Task Comment Attachment Upload. …

Dec 16, 2024
CVE-2024-12664
3.5 LOW

A vulnerability, which was classified as problematic, has been found in ruifang-tech Rebuild 3.8.5. This issue affects some unknown processing of the component Project Task …

Dec 16, 2024
CVE-2024-12663
3.7 LOW

A vulnerability classified as problematic was found in funnyzpc Mee-Admin up to 1.6. This vulnerability affects unknown code of the file /mee/login of the component …

Dec 16, 2024
CVE-2024-56082
3.5 LOW

ChatBar.tsx in Lumos before 1.0.17 parses raw HTML in Markdown because the markdown-to-jsx package is used without disableParsingRawHTML set to true.

Dec 15, 2024
CVE-2023-41695
3.5 LOW

Missing Authorization vulnerability in Adnan Analytify wp-analytify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Analytify: from n/a through <= 5.1.0.

Dec 13, 2024
CVE-2022-45819
3.5 LOW

Missing Authorization vulnerability in Popup Maker Popup Maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Popup Maker: from n/a through 1.17.1.

Dec 13, 2024
CVE-2021-32007
3.5 LOW

This issue affects: Secomea GateManager Version 9.5 and all prior versions. Protection Mechanism Failure vulnerability in web server of Secomea GateManager to potentially leak information …

Dec 13, 2024
CVE-2024-12300
3.7 LOW

The AR for WordPress plugin for WordPress is vulnerable to unauthorized double extension file upload due to a missing capability check on the set_ar_featured_image() function …

Dec 13, 2024
CVE-2024-10043
3.1 LOW

An issue has been discovered in GitLab EE affecting all versions starting from 14.3 before 17.4.6, all versions starting from 17.5 before 17.5.4 all versions …

Dec 12, 2024
CVE-2024-54493
3.3 LOW

This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.2. Privacy indicators for microphone access may be attributed incorrectly.

Dec 12, 2024
CVE-2024-54491
3.3 LOW

The issue was resolved by sanitizing logging. This issue is fixed in macOS Sequoia 15.2. A malicious application may be able to determine a user's …

Dec 12, 2024
CVE-2024-54485
2.4 LOW

The issue was addressed by adding additional logic. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2. An attacker …

Dec 12, 2024
CVE-2024-44290
3.3 LOW

This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, watchOS 11.1. …

Dec 12, 2024
CVE-2024-44200
3.3 LOW

This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1. An app …

Dec 12, 2024
CVE-2024-12536
3.5 LOW

A vulnerability, which was classified as problematic, has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0. Affected by this issue is some …

Dec 12, 2024
CVE-2024-12503
2.4 LOW

A vulnerability classified as problematic was found in ClassCMS 4.8. Affected by this vulnerability is an unknown functionality of the file /index.php/admin of the component …

Dec 12, 2024
CVE-2024-12483
3.7 LOW

A vulnerability classified as problematic has been found in Dromara UJCMS up to 9.6.3. This affects an unknown part of the file /users/id of the …

Dec 12, 2024
CVE-2023-23472
3.1 LOW

IBM InfoSphere DataStage Flow Designer (InfoSphere Information Server 11.7) could allow an authenticated user to obtain sensitive information that could aid in further attacks against …

Dec 11, 2024
CVE-2024-11053
3.4 LOW

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host …

Dec 11, 2024
CVE-2023-37395
2.5 LOW

IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information due to improper encryption of certain data.

Dec 11, 2024
CVE-2024-52831
3.5 LOW

Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass. A low-privileged …

Dec 10, 2024
CVE-2024-43755
3.5 LOW

Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass. A low-privileged …

Dec 10, 2024
CVE-2024-55550
2.7 LOW KEV

Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A …

Dec 10, 2024
CVE-2024-53245
3.1 LOW

In Splunk Enterprise versions below 9.3.0, 9.2.4, and 9.1.7 and Splunk Cloud Platform versions below 9.1.2312.206, a low-privileged user that does not hold the “admin“ …

Dec 10, 2024
CVE-2024-47577
2.7 LOW

Webservice API endpoints for Assisted Service Module within SAP Commerce Cloud has information disclosure vulnerability. When an authorized agent searches for customer to manage their …

Dec 10, 2024
CVE-2024-47576
3.3 LOW

SAP Product Lifecycle Costing Client (versions below 4.7.1) application loads on demand a DLL that is available with Windows OS. This DLL is loaded from …

Dec 10, 2024
CVE-2024-12174
2.7 LOW

An Improper Certificate Validation vulnerability exists in Tenable Security Center where an authenticated, privileged attacker could intercept email messages sent from Security Center via a …

Dec 9, 2024
CVE-2023-28168
3.7 LOW

Missing Authorization vulnerability in Jerod Santo WordPress Console allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress Console: from n/a through 0.3.9.

Dec 9, 2024
CVE-2023-24375
3.5 LOW

Missing Authorization vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress …

Dec 9, 2024
CVE-2023-23825
3.1 LOW

Missing Authorization vulnerability in Brainstorm Force Spectra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Spectra: from n/a through 2.3.0.

Dec 9, 2024
CVE-2023-23814
3.8 LOW

Missing Authorization vulnerability in CodePeople CP Multi View Event Calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CP Multi View Event Calendar …

Dec 9, 2024
CVE-2024-46901
3.1 LOW

Insufficient validation of filenames against control characters in Apache Subversion repositories served via mod_dav_svn allows authenticated users with commit access to commit a corrupted revision, …

Dec 9, 2024
CVE-2024-12359
3.5 LOW

A vulnerability was found in code-projects Admin Dashboard 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /vendor_management.php. The …

Dec 9, 2024
CVE-2024-12355
3.3 LOW

A vulnerability has been found in SourceCodester Phone Contact Manager System 1.0 and classified as problematic. Affected by this vulnerability is the function ContactBook::adding of …

Dec 9, 2024
CVE-2024-12353
3.3 LOW

A vulnerability, which was classified as problematic, has been found in SourceCodester Phone Contact Manager System 1.0. This issue affects the function UserInterface::MenuDisplayStart of the …

Dec 9, 2024
CVE-2024-12348
3.5 LOW

A vulnerability was found in Guizhou Xiaoma Technology jpress 5.1.2. It has been classified as problematic. Affected is the function AttachmentUtils.isUnSafe of the file /commons/attachment/upload …

Dec 9, 2024
CVE-2024-12346
3.5 LOW

A vulnerability has been found in Talentera up to 20241128 and classified as problematic. This vulnerability affects unknown code of the file /app/control/byt_cv_manager. The manipulation …

Dec 9, 2024
CVE-2024-6219
3.8 LOW

Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust store with its restrictions not …

Dec 6, 2024
CVE-2024-6156
3.8 LOW

Mark Laing discovered that LXD's PKI mode, until version 5.21.2, could be bypassed if the client's certificate was present in the trust store.

Dec 6, 2024
CVE-2024-12232
3.5 LOW

A vulnerability has been found in code-projects Simple CRUD Functionality 1.0 and classified as problematic. This vulnerability affects unknown code of the file /index.php. The …

Dec 5, 2024
CVE-2024-42195
3.1 LOW

HCL DevOps Deploy / HCL Launch is vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web …

Dec 5, 2024
CVE-2024-54014
3.6 LOW

Improper authorization in handler for custom URL scheme issue in 'Skylark' App for Android 6.2.13 and earlier and 'Skylark' App for iOS 6.2.13 and earlier …

Dec 5, 2024
CVE-2024-12183
3.5 LOW

A vulnerability, which was classified as problematic, was found in DedeCMS 5.7.116. This affects the function RemoveXSS of the file /plus/carbuyaction.php of the component HTTP …

Dec 4, 2024
CVE-2024-12182
3.5 LOW

A vulnerability, which was classified as problematic, has been found in DedeCMS 5.7.116. Affected by this issue is some unknown functionality of the file /member/soft_add.php. …

Dec 4, 2024
CVE-2024-12181
3.5 LOW

A vulnerability classified as problematic was found in DedeCMS 5.7.116. Affected by this vulnerability is an unknown functionality of the file /member/uploads_add.php of the component …

Dec 4, 2024
CVE-2024-12180
3.5 LOW

A vulnerability classified as problematic has been found in DedeCMS 5.7.116. Affected is an unknown function of the file /member/article_add.php. The manipulation of the argument …

Dec 4, 2024
CVE-2024-38829
3.7 LOW

A vulnerability in Spring LDAP allows data exposure for case sensitive comparisons.This issue affects Spring LDAP: from 2.4.0 through 2.4.3, from 3.0.0 through 3.0.9, from …

Dec 4, 2024
CVE-2024-54158
3.5 LOW

In JetBrains YouTrack before 2024.3.52635 potential spoofing attack was possible via lack of Punycode encoding

Dec 4, 2024
CVE-2024-54155
3.7 LOW

In JetBrains YouTrack before 2024.3.51866 improper access control allowed listing of project names during app import without authentication

Dec 4, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.