CVE Database

46795+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-46831
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: microchip: vcap: Fix use-after-free error in kunit test This is a clear use-after-free error. …

Sep 27, 2024
CVE-2024-46830
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Acquire kvm->srcu when handling KVM_SET_VCPU_EVENTS Grab kvm->srcu when processing KVM_SET_VCPU_EVENTS, as KVM will …

Sep 27, 2024
CVE-2024-46828
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: sched: sch_cake: fix bulk flow accounting logic for host fairness In sch_cake, we keep track …

Sep 27, 2024
CVE-2024-46821
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amd/pm: Fix negative array index read Avoid using the negative values for clk_idex as an …

Sep 27, 2024
CVE-2024-46820
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn: remove irq disabling in vcn 5 suspend We do not directly enable/disable VCN IRQ …

Sep 27, 2024
CVE-2024-46818
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Check gpio_id before used as array index [WHY & HOW] GPIO_ID_UNKNOWN (-1) is not …

Sep 27, 2024
CVE-2024-46815
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Check num_valid_sets before accessing reader_wm_sets[] [WHY & HOW] num_valid_sets needs to be checked to …

Sep 27, 2024
CVE-2024-46814
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Check msg_id before processing transcation [WHY & HOW] HDCP_MESSAGE_ID_INVALID (-1) is not a valid …

Sep 27, 2024
CVE-2024-46813
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Check link_index before accessing dc->links[] [WHY & HOW] dc->links[] has max size of MAX_LINKS …

Sep 27, 2024
CVE-2024-46812
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Skip inactive planes within ModeSupportAndSystemConfiguration [Why] Coverity reports Memory - illegal accesses. [How] Skip …

Sep 27, 2024
CVE-2024-46811
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix index may exceed array range within fpu_update_bw_bounding_box [Why] Coverity reports OVERRUN warning. soc.num_states …

Sep 27, 2024
CVE-2024-46804
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Add array index check for hdcp ddc access [Why] Coverity reports OVERRUN warning. Do …

Sep 27, 2024
CVE-2024-46441
8.8 HIGH

An arbitrary file upload vulnerability in YPay 1.2.0 allows attackers to execute arbitrary code via a ZIP archive to themePutFile in app/common/util/Upload.php (called from app/admin/controller/ypay/Home.php). …

Sep 27, 2024
CVE-2024-8644
7.5 HIGH

Cleartext Storage of Sensitive Information in a Cookie vulnerability in Oceanic Software ValeApp allows Protocol Manipulation, : JSON Hijacking (aka JavaScript Hijacking).This issue affects ValeApp: …

Sep 27, 2024
CVE-2024-8609
7.5 HIGH

Insertion of Sensitive Information into Log File vulnerability in Oceanic Software ValeApp allows Query System for Information.This issue affects ValeApp: before v2.0.0.

Sep 27, 2024
CVE-2024-6931
7.2 HIGH

The The Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via RSVP name field in all versions up to, and including, 6.6.3 …

Sep 27, 2024
CVE-2024-38861
7.4 HIGH

Improper Certificate Validation in Checkmk Exchange plugin MikroTik allows attackers in MitM position to intercept traffic. This issue affects MikroTik: from 2.0.0 through 2.5.5, from …

Sep 27, 2024
CVE-2024-39432
8.3 HIGH

In UMTS RLC driver, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of …

Sep 27, 2024
CVE-2024-39431
8.3 HIGH

In UMTS RLC driver, there is a possible out of bounds write due to a missing bounds check. This could lead to remote denial of …

Sep 27, 2024
CVE-2024-9029
7.5 HIGH

A flaw was found in the freeimage library. Processing a crafted image can cause a buffer over-read of 1 byte in the read_iptc_profile function in …

Sep 27, 2024
CVE-2024-9130
7.2 HIGH

The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter in all versions up …

Sep 27, 2024
CVE-2024-8922
8.8 HIGH

The Product Enquiry for WooCommerce, WooCommerce product catalog plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.2.33.32 …

Sep 27, 2024
CVE-2024-7714
7.5 HIGH

The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 lacks sufficient access controls allowing an unauthenticated user to disconnect the …

Sep 27, 2024
CVE-2024-7713
7.5 HIGH

The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 discloses the Open AI API Key, allowing unauthenticated users to obtain …

Sep 27, 2024
CVE-2024-47175
8.6 HIGH

CUPS is a standards-based, open-source printing system, and `libppd` can be used for legacy PPD file support. The `libppd` function `ppdCreatePPDFromIPP2` does not sanitize IPP …

Sep 26, 2024
CVE-2024-47076
8.6 HIGH

CUPS is a standards-based, open-source printing system, and `libcupsfilters` contains the code of the filters of the former `cups-filters` package as library functions to be …

Sep 26, 2024
CVE-2024-40508
7.3 HIGH

Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMConference.asmx function.

Sep 26, 2024
CVE-2024-40507
7.3 HIGH

Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMPersonnel.asmx function.

Sep 26, 2024
CVE-2024-40506
7.3 HIGH

Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMHospitality.asmx function.

Sep 26, 2024
CVE-2024-7594
7.5 HIGH

Vault’s SSH secrets engine did not require the valid_principals list to contain a value by default. If the valid_principals and default_user fields of the SSH …

Sep 26, 2024
CVE-2024-47180
8.8 HIGH

Shields.io is a service for concise, consistent, and legible badges in SVG and raster format. Shields.io and users self-hosting their own instance of shields using …

Sep 26, 2024
CVE-2024-47179
8.8 HIGH

RSSHub is an RSS network. Prior to commit 64e00e7, RSSHub's `docker-test-cont.yml` workflow is vulnerable to Artifact Poisoning, which could have lead to a full repository …

Sep 26, 2024
CVE-2024-47169
8.8 HIGH

Agnai is an artificial-intelligence-agnostic multi-user, mult-bot roleplaying chat system. A vulnerability in versions prior to 1.0.330 permits attackers to upload arbitrary files to attacker-chosen locations …

Sep 26, 2024
CVE-2024-47130
8.8 HIGH

The goTenna Pro App allows unauthenticated attackers to remotely update the local public keys used for P2P and group messages. It is advised to update …

Sep 26, 2024
CVE-2024-47125
8.1 HIGH

The goTenna Pro App does not authenticate public keys which allows an unauthenticated attacker to manipulate messages. It is advised to update your app to …

Sep 26, 2024
CVE-2024-39577
7.1 HIGH

Dell SmartFabric OS10 Software, versions 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low …

Sep 26, 2024
CVE-2024-45982
8.8 HIGH

A host header injection vulnerability in scheduleR v0.0.18 allows attackers to obtain the password reset token via user interaction with a crafted password reset link. …

Sep 26, 2024
CVE-2024-45981
8.8 HIGH

A host header injection vulnerability in BookReviewLibrary 1.0 allows attackers to obtain the password reset token via user interaction with a crafted password reset link.

Sep 26, 2024
CVE-2024-45980
8.8 HIGH

A host header injection vulnerability in MEANStore 1.0 allows attackers to obtain the password reset token via user interaction with a crafted password reset link. …

Sep 26, 2024
CVE-2024-45979
8.8 HIGH

A host header injection vulnerability in Lines Police CAD 1.0 allows attackers to obtain the password reset token via user interaction with a crafted password …

Sep 26, 2024
CVE-2024-44860
7.5 HIGH

An information disclosure vulnerability in the /Letter/PrintQr/ endpoint of Solvait v24.4.2 allows attackers to access sensitive data via a crafted request.

Sep 26, 2024
CVE-2024-37125
7.5 HIGH

Dell SmartFabric OS10 Software, versions 10.5.6.x, 10.5.5.x, 10.5.4.x,10.5.3.x, contains an Uncontrolled Resource Consumption vulnerability. A remote unauthenticated host could potentially exploit this vulnerability leading to …

Sep 26, 2024
CVE-2024-43191
7.2 HIGH

IBM ManageIQ could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted yaml file request.

Sep 26, 2024
CVE-2024-41605
8.4 HIGH

In Foxit PDF Reader before 2024.3, and PDF Editor before 2024.3 and 13.x before 13.1.4, an attacker can replace an update file with a Trojan …

Sep 26, 2024
CVE-2024-46330
7.4 HIGH

VONETS VAP11G-300 v3.3.23.6.9 was discovered to contain a command injection vulnerability via the iptablesWebsFilterRun object.

Sep 26, 2024
CVE-2024-46329
8.0 HIGH

VONETS VAP11G-300 v3.3.23.6.9 was discovered to contain a command injection vulnerability via the SystemCommand object.

Sep 26, 2024
CVE-2024-46328
8.0 HIGH

VONETS VAP11G-300 v3.3.23.6.9 was discovered to contain hardcoded credentials for several different privileged accounts, including root.

Sep 26, 2024
CVE-2024-7107
7.5 HIGH

Files or Directories Accessible to External Parties vulnerability in National Keep Cyber Security Services CyberMath allows Collect Data from Common Resource Locations.This issue affects CyberMath: …

Sep 26, 2024
CVE-2024-8704
7.2 HIGH

The Advanced File Manager plugin for WordPress is vulnerable to Local JavaScript File Inclusion in all versions up to, and including, 5.2.8 via the 'fma_locale' …

Sep 26, 2024
CVE-2024-8126
7.5 HIGH

The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads via the 'class_fma_connector.php' file in all versions up to, and including, 5.2.8. …

Sep 26, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.