CVE Database

46795+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-9198
7.6 HIGH

Vulnerability in Clibo Manager v1.1.9.1 that could allow an attacker to execute an stored Cross-Site Scripting (stored XSS ) by uploading a malicious .svg image …

Sep 26, 2024
CVE-2022-4541
7.2 HIGH

The WordPress Visitors plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a spoofed HTTP Header value in versions up to, and including, 1.0 …

Sep 26, 2024
CVE-2024-47197
7.5 HIGH

Exposure of Sensitive Information to an Unauthorized Actor, Insecure Storage of Sensitive Information vulnerability in Maven Archetype Plugin. This issue affects Maven Archetype Plugin: from …

Sep 26, 2024
CVE-2024-7781
8.1 HIGH

The Jupiter X Core plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.7.5. This is due to improper …

Sep 26, 2024
CVE-2024-47045
7.8 HIGH

Privilege chaining issue exists in the installer of e-Tax software(common program). If this vulnerability is exploited, a malicious DLL prepared by an attacker may be …

Sep 26, 2024
CVE-2023-52946
8.2 HIGH

Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in vss service component in Synology Drive Client before 3.5.0-16084 allows remote attackers to …

Sep 26, 2024
CVE-2022-49038
7.8 HIGH

Inclusion of functionality from untrusted control sphere vulnerability in OpenSSL DLL component in Synology Drive Client before 3.3.0-15082 allows local users to execute arbitrary code …

Sep 26, 2024
CVE-2024-8404
7.8 HIGH

An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print enabled. To exploit this vulnerability, an attacker must first …

Sep 26, 2024
CVE-2024-47083
7.5 HIGH

Power Platform Terraform Provider allows managing environments and other resources within Power Platform. Versions prior to 3.0.0 have an issue in the Power Platform Terraform …

Sep 25, 2024
CVE-2024-46489
8.8 HIGH

A remote command execution (RCE) vulnerability in promptr v6.0.7 allows attackers to execute arbitrary commands via a crafted URL.

Sep 25, 2024
CVE-2024-45750
7.3 HIGH

An issue in TheGreenBow Windows Standard VPN Client 6.87.108 (and older), Windows Enterprise VPN Client 6.87.109 (and older), Windows Enterprise VPN Client 7.5.007 (and older), …

Sep 25, 2024
CVE-2024-8996
7.3 HIGH

Unquoted Search Path or Element vulnerability in Grafana Agent (Flow mode) on Windows allows Privilege Escalation from Local User to SYSTEM This issue affects Agent …

Sep 25, 2024
CVE-2024-8975
7.3 HIGH

Unquoted Search Path or Element vulnerability in Grafana Alloy on Windows allows Privilege Escalation from Local User to SYSTEM This issue affects Alloy: before 1.3.3, …

Sep 25, 2024
CVE-2024-44678
8.0 HIGH

Gigastone TR1 Travel Router R101 v1.0.2 is vulnerable to Command Injection. This allows an authenticated attacker to execute arbitrary commands on the device by sending …

Sep 25, 2024
CVE-2024-41708
7.5 HIGH

An issue was discovered in AdaCore ada_web_services 20.0 allows an attacker to escalate privileges and steal sessions via the Random_String() function in the src/core/aws-utils.adb module.

Sep 25, 2024
CVE-2024-20480
8.6 HIGH

A vulnerability in the DHCP Snooping feature of Cisco IOS XE Software on Software-Defined Access (SD-Access) fabric edge nodes could allow an unauthenticated, remote attacker …

Sep 25, 2024
CVE-2024-20467
8.6 HIGH

A vulnerability in the implementation of the IPv4 fragmentation reassembly code in Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a …

Sep 25, 2024
CVE-2024-20464
8.6 HIGH

A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of …

Sep 25, 2024
CVE-2024-20455
8.6 HIGH

A vulnerability in the process that classifies traffic that is going to the Unified Threat Defense (UTD) component of Cisco IOS XE Software in controller …

Sep 25, 2024
CVE-2024-20437
8.1 HIGH

A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform a cross-site request forgery (CSRF) …

Sep 25, 2024
CVE-2024-20436
8.6 HIGH

A vulnerability in the HTTP Server feature of Cisco IOS XE Software when the Telephony Service feature is enabled could allow an unauthenticated, remote attacker …

Sep 25, 2024
CVE-2024-20433
8.6 HIGH

A vulnerability in the Resource Reservation Protocol (RSVP) feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to …

Sep 25, 2024
CVE-2024-20350
7.5 HIGH

A vulnerability in the SSH server of Cisco Catalyst Center, formerly Cisco DNA Center, could allow an unauthenticated, remote attacker to impersonate a Cisco Catalyst …

Sep 25, 2024
CVE-2024-47078
8.1 HIGH

Meshtastic is an open source, off-grid, decentralized, mesh network. Meshtastic uses MQTT to communicate over an internet connection to a shared or private MQTT Server. …

Sep 25, 2024
CVE-2024-44825
7.5 HIGH

Directory Traversal vulnerability in Centro de Tecnologia da Informaco Renato Archer InVesalius3 v3.1.99995 allows attackers to write arbitrary files unto the system via a crafted …

Sep 25, 2024
CVE-2024-46461
8.0 HIGH

VLC media player 3.0.20 and earlier is vulnerable to denial of service through an integer overflow which could be triggered with a maliciously crafted mms …

Sep 25, 2024
CVE-2024-43959
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Testimonials super-testimonial allows Reflected XSS.This issue affects Testimonials: from n/a through <= …

Sep 25, 2024
CVE-2024-30128
8.6 HIGH

HCL Nomad server on Domino is affected by an open proxy vulnerability in which an unauthenticated attacker can mask their original source IP address. This …

Sep 25, 2024
CVE-2024-22893
7.5 HIGH

OpenSlides 4.0.15 verifies passwords by comparing password hashes using a function with content-dependent runtime. This can allow attackers to obtain information about the password hash …

Sep 25, 2024
CVE-2024-22892
7.5 HIGH

OpenSlides 4.0.15 was discovered to be using a weak hashing algorithm to store passwords.

Sep 25, 2024
CVE-2024-8316
7.8 HIGH

In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a code execution attack is possible through an insecure deserialization vulnerability.

Sep 25, 2024
CVE-2024-7679
7.8 HIGH

In Progress Telerik UI for WinForms versions prior to 2024 Q3 (2024.3.924), a command injection attack is possible through improper neutralization of hyperlink elements.

Sep 25, 2024
CVE-2024-7576
7.8 HIGH

In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a code execution attack is possible through an insecure deserialization vulnerability.

Sep 25, 2024
CVE-2024-7575
7.8 HIGH

In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a command injection attack is possible through improper neutralization of hyperlink elements.

Sep 25, 2024
CVE-2024-6594
7.5 HIGH

Improper Handling of Exceptional Conditions vulnerability in the WatchGuard Single Sign-On Client on Windows causes the client to crash while handling malformed commands. An attacker …

Sep 25, 2024
CVE-2024-7481
8.8 HIGH

Improper verification of cryptographic signature during installation of a Printer driver via the TeamViewer_service.exe component of TeamViewer Remote Clients prior version 15.58.4 for Windows allows …

Sep 25, 2024
CVE-2024-7479
8.8 HIGH

Improper verification of cryptographic signature during installation of a VPN driver via the TeamViewer_service.exe component of TeamViewer Remote Clients prior version 15.58.4 for Windows allows …

Sep 25, 2024
CVE-2024-45817
7.3 HIGH

In x86's APIC (Advanced Programmable Interrupt Controller) architecture, error conditions are reported in a status register. Furthermore, the OS can opt to receive an interrupt …

Sep 25, 2024
CVE-2024-31146
7.5 HIGH

When multiple devices share resources and one of them is to be passed through to a guest, security of the entire system and of respective …

Sep 25, 2024
CVE-2024-31145
7.5 HIGH

Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Memory Region Reporting, "RMRR") for Intel VT-d or Unity Mapping …

Sep 25, 2024
CVE-2024-8175
7.5 HIGH

An unauthenticated remote attacker can causes the CODESYS web server to access invalid memory which results in a DoS.

Sep 25, 2024
CVE-2024-8290
8.8 HIGH

The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all …

Sep 25, 2024
CVE-2024-8484
7.5 HIGH

The REST API TO MiniProgram plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the /wp-json/watch-life-net/v1/comment/getcomments REST API endpoint in all …

Sep 25, 2024
CVE-2024-8481
7.3 HIGH

The The Special Text Boxes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 6.2.4. This is due …

Sep 25, 2024
CVE-2024-8349
7.2 HIGH

The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.1.0.1. This is due to …

Sep 25, 2024
CVE-2024-7617
7.2 HIGH

The Contact Form to Any API plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Contact Form 7 form fields in all versions up …

Sep 25, 2024
CVE-2024-9123
8.8 HIGH

Integer overflow in Skia in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to perform an out of bounds memory write via a crafted …

Sep 25, 2024
CVE-2024-9122
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to perform out of bounds memory access via a crafted HTML …

Sep 25, 2024
CVE-2024-9121
8.8 HIGH

Inappropriate implementation in V8 in Google Chrome prior to 129.0.6668.70 allowed a remote attacker to potentially perform out of bounds memory access via a crafted …

Sep 25, 2024
CVE-2024-9120
8.8 HIGH

Use after free in Dawn in Google Chrome on Windows prior to 129.0.6668.70 allowed a remote attacker to potentially exploit heap corruption via a crafted …

Sep 25, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.