CVE Database

46795+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-46741
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: Fix double free of 'buf' in error path smatch warning: drivers/misc/fastrpc.c:1926 fastrpc_req_mmap() error: …

Sep 18, 2024
CVE-2024-46740
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: binder: fix UAF caused by offsets overwrite Binder objects are processed and copied individually into …

Sep 18, 2024
CVE-2024-46738
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: VMCI: Fix use-after-free when removing resource in vmci_resource_remove() When removing a resource from vmci_resource_table in …

Sep 18, 2024
CVE-2024-46736
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double put of @cfile in smb2_rename_path() If smb2_set_path_attr() is called with a …

Sep 18, 2024
CVE-2024-47001
8.8 HIGH

Hidden functionality issue in multiple digital video recorders provided by TAKENAKA ENGINEERING CO., LTD. allows a remote authenticated attacker to execute an arbitrary OS command …

Sep 18, 2024
CVE-2024-46731
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amd/pm: fix the Out-of-bounds read warning using index i - 1U may beyond element index …

Sep 18, 2024
CVE-2024-46729
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix incorrect size calculation for loop [WHY] fe_clk_en has size of 5 but sizeof(fe_clk_en) …

Sep 18, 2024
CVE-2024-46725
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix out-of-bounds write warning Check the ring type value to fix the out-of-bounds write …

Sep 18, 2024
CVE-2024-46724
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix out-of-bounds read of df_v1_7_channel_number Check the fb_channel_number range to avoid the array out-of-bounds …

Sep 18, 2024
CVE-2024-46723
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix ucode out-of-bounds read warning Clear warning that read ucode[] may out-of-bounds.

Sep 18, 2024
CVE-2024-46722
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix mc_data out-of-bounds read warning Clear warning that read mc_data[i-1] may out-of-bounds.

Sep 18, 2024
CVE-2024-43778
8.8 HIGH

OS command injection vulnerability in multiple digital video recorders provided by TAKENAKA ENGINEERING CO., LTD. allows a remote authenticated attacker to execute an arbitrary OS …

Sep 18, 2024
CVE-2024-41929
8.8 HIGH

Improper authentication vulnerability in multiple digital video recorders provided by TAKENAKA ENGINEERING CO., LTD. allows a remote authenticated attacker to execute an arbitrary OS command …

Sep 18, 2024
CVE-2024-42404
8.8 HIGH

SQL injection vulnerability in Welcart e-Commerce prior to 2.11.2 allows an attacker who can login to the product to obtain or alter the information stored …

Sep 18, 2024
CVE-2024-45679
8.4 HIGH

Heap-based buffer overflow vulnerability in Assimp versions prior to 5.4.3 allows a local attacker to execute arbitrary code by importing a specially crafted file into …

Sep 18, 2024
CVE-2024-44003
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in spicethemes Spice Starter Sites spice-starter-sites allows Reflected XSS.This issue affects Spice Starter Sites: …

Sep 18, 2024
CVE-2024-44002
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Team Showcase team allows Reflected XSS.This issue affects Team Showcase: from n/a …

Sep 18, 2024
CVE-2024-43975
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in highwarden Super Store Finder superstorefinder-wp.This issue affects Super Store Finder: from n/a through …

Sep 18, 2024
CVE-2024-43971
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart.This issue affects Sunshine Photo Cart: from n/a through …

Sep 18, 2024
CVE-2024-43970
7.1 HIGH

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SureCart allows Reflected XSS.This issue affects SureCart: from n/a through 2.29.3.

Sep 18, 2024
CVE-2024-44064
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LikeBtn Like Button Rating likebtn-like-button.This issue affects Like Button Rating: from n/a through …

Sep 17, 2024
CVE-2024-44009
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WC Lovers WCFM Marketplace wc-multivendor-marketplace allows Reflected XSS.This issue affects WCFM Marketplace: from …

Sep 17, 2024
CVE-2024-44007
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT Templates – Elementor & Gutenberg templates skt-templates allows Reflected XSS.This issue …

Sep 17, 2024
CVE-2024-43969
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Spiffy Plugins Spiffy Calendar allows SQL Injection.This issue affects Spiffy Calendar: …

Sep 17, 2024
CVE-2024-46982
7.5 HIGH

Next.js is a React framework for building full-stack web applications. By sending a crafted HTTP request, it is possible to poison the cache of a …

Sep 17, 2024
CVE-2024-8957
7.2 HIGH KEV

PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an OS command injection issue. The camera does not sufficiently validate the ntp_addr configuration value which may …

Sep 17, 2024
CVE-2024-8905
8.8 HIGH

Inappropriate implementation in V8 in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page. (Chromium …

Sep 17, 2024
CVE-2024-8904
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 129.0.6668.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Sep 17, 2024
CVE-2024-45606
7.1 HIGH

Sentry is a developer-first error tracking and performance monitoring platform. An authenticated user can mute alert rules from arbitrary organizations and projects with a know …

Sep 17, 2024
CVE-2024-45398
8.3 HIGH

Contao is an Open Source CMS. In affected versions a back end user with access to the file manager can upload malicious files and execute …

Sep 17, 2024
CVE-2024-8948
7.3 HIGH

A vulnerability was found in MicroPython 1.23.0. It has been rated as critical. Affected by this issue is the function mpz_as_bytes of the file py/objint.c. …

Sep 17, 2024
CVE-2024-8946
7.3 HIGH

A vulnerability was found in MicroPython 1.23.0. It has been classified as critical. Affected is the function mp_vfs_umount of the file extmod/vfs.c of the component …

Sep 17, 2024
CVE-2024-8900
7.5 HIGH

An attacker could write data to the user's clipboard, bypassing the user prompt, during a certain sequence of navigational events. This vulnerability affects Firefox < …

Sep 17, 2024
CVE-2024-43460
8.1 HIGH

Improper authorization in Dynamics 365 Business Central resulted in a vulnerability that allows an authenticated attacker to elevate privileges over a network.

Sep 17, 2024
CVE-2024-8944
7.3 HIGH

A vulnerability, which was classified as critical, was found in code-projects Hospital Management System 1.0. This affects an unknown part of the file check_availability.php. The …

Sep 17, 2024
CVE-2024-45682
8.8 HIGH

There is a command injection vulnerability that may allow an attacker to inject malicious input on the device's operating system.

Sep 17, 2024
CVE-2024-42503
7.2 HIGH

Authenticated command execution vulnerability exist in the ArubaOS command line interface (CLI). Successful exploitation of this vulnerabilities result in the ability to run arbitrary commands …

Sep 17, 2024
CVE-2024-42502
7.2 HIGH

Authenticated command injection vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability result in the ability to inject shell commands on …

Sep 17, 2024
CVE-2024-42501
7.2 HIGH

An authenticated Path Traversal vulnerabilities exists in the ArubaOS. Successful exploitation of this vulnerability allows an attacker to install unsigned packages on the underlying operating …

Sep 17, 2024
CVE-2024-38813
7.5 HIGH KEV

The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to …

Sep 17, 2024
CVE-2024-8768
7.5 HIGH

A flaw was found in the vLLM library. A completions API request with an empty prompt will crash the vLLM API server, resulting in a …

Sep 17, 2024
CVE-2024-7788
7.8 HIGH

Improper Digital Signature Invalidation vulnerability in Zip Repair Mode of The Document Foundation LibreOffice allows Signature forgery vulnerability in LibreOfficeThis issue affects LibreOffice: from 24.2 …

Sep 17, 2024
CVE-2021-27916
8.1 HIGH

Prior to the patched version, logged in users of Mautic are vulnerable to Relative Path Traversal/Arbitrary File Deletion. Regardless of the level of access the …

Sep 17, 2024
CVE-2024-47049
8.2 HIGH

The czim/file-handling package before 1.5.0 and 2.x before 2.3.0 (used with PHP Composer) does not properly validate URLs within makeFromUrl and makeFromAny, leading to SSRF, …

Sep 17, 2024
CVE-2024-47047
7.5 HIGH

An issue was discovered in the powermail extension through 12.4.0 for TYPO3. It fails to validate the mail parameter of the createAction, resulting in Insecure …

Sep 17, 2024
CVE-2024-22303
8.8 HIGH

Incorrect Privilege Assignment vulnerability in favethemes Houzez allows Privilege Escalation.This issue affects Houzez: from n/a through 3.2.4.

Sep 17, 2024
CVE-2024-21743
8.8 HIGH

Privilege Escalation vulnerability in favethemes Houzez Login Register houzez-login-register.This issue affects Houzez Login Register: from n/a through 3.2.5.

Sep 17, 2024
CVE-2021-27915
7.6 HIGH

Prior to the patched version, there is an XSS vulnerability in the description fields within the Mautic application which could be exploited by a logged …

Sep 17, 2024
CVE-2024-46362
8.8 HIGH

FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/create_directory

Sep 17, 2024
CVE-2024-46085
8.8 HIGH

FrogCMS V0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/plugin/file_manager/rename

Sep 17, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.