CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-47663
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: staging: iio: frequency: ad9834: Validate frequency parameter value In ad9834_write_frequency() clk_get_rate() can return 0. In …

Oct 9, 2024
CVE-2024-47662
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Remove register from DCN35 DMCUB diagnostic collection [Why] These registers should not be read …

Oct 9, 2024
CVE-2024-47661
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Avoid overflow from uint32_t to uint8_t [WHAT & HOW] dmub_rb_cmd's ramping_boundary has size of …

Oct 9, 2024
CVE-2024-47660
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fsnotify: clear PARENT_WATCHED flags lazily In some setups directories can have many (usually negative) dentries. …

Oct 9, 2024
CVE-2024-47658
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: crypto: stm32/cryp - call finalize with bh disabled The finalize operation in interrupt mode produce …

Oct 9, 2024
CVE-2024-46870
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Disable DMCUB timeout for DCN35 [Why] DMCUB can intermittently take longer than expected to …

Oct 9, 2024
CVE-2024-46237
5.4 MEDIUM

PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) via the patname, pataddress, and medhis parameters in doctor/add-patient.php and doctor/edit-patient.php.

Oct 9, 2024
CVE-2024-47420
5.5 MEDIUM

Animate versions 23.0.7, 24.0.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage …

Oct 9, 2024
CVE-2024-47419
5.5 MEDIUM

Animate versions 23.0.7, 24.0.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage …

Oct 9, 2024
CVE-2024-45145
5.5 MEDIUM

Lightroom Desktop versions 7.4.1, 13.5, 12.5.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker …

Oct 9, 2024
CVE-2024-20787
5.5 MEDIUM

Substance3D - Painter versions 10.0.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Oct 9, 2024
CVE-2024-9451
6.4 MEDIUM

The Embed PDF Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'height' and 'width' parameters in all versions up to, and …

Oct 9, 2024
CVE-2024-9449
6.4 MEDIUM

The Auto iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' parameter in all versions up to, and including, 1.7 due …

Oct 9, 2024
CVE-2024-39440
6.2 MEDIUM

In DRM service, there is a possible system crash due to null pointer dereference. This could lead to local denial of service with System execution …

Oct 9, 2024
CVE-2024-39439
6.2 MEDIUM

In DRM service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Oct 9, 2024
CVE-2024-39438
6.5 MEDIUM

In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution …

Oct 9, 2024
CVE-2024-39437
6.5 MEDIUM

In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution …

Oct 9, 2024
CVE-2024-39436
6.5 MEDIUM

In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution …

Oct 9, 2024
CVE-2024-5968
4.8 MEDIUM

The Photo Gallery by 10Web WordPress plugin before 1.8.28 does not properly sanitise and escape some of its Gallery settings, which could allow high privilege …

Oct 9, 2024
CVE-2023-45872
6.5 MEDIUM

An issue was discovered in Qt before 6.2.11 and 6.3.x through 6.6.x before 6.6.1. When a QML image refers to an image whose content is …

Oct 9, 2024
CVE-2023-45361
6.1 MEDIUM

An issue was discovered in VectorComponentUserLinks.php in the Vector Skin component in MediaWiki before 1.39.5 and 1.40.x before 1.40.1. vector-intro-page MalformedTitleException is uncaught if it …

Oct 9, 2024
CVE-2023-45359
6.5 MEDIUM

An issue was discovered in the Vector Skin component for MediaWiki before 1.39.5 and 1.40.x before 1.40.1. vector-toc-toggle-button-label is not escaped, but should be, because …

Oct 9, 2024
CVE-2024-42934
5.0 MEDIUM

OpenIPMI before 2.0.36 has an out-of-bounds array access (for authentication type) in the ipmi_sim simulator, resulting in denial of service or (with very low probability) …

Oct 9, 2024
CVE-2024-7963
6.4 MEDIUM

The CMSMasters Content Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's multiple shortcodes in all versions up to, and including, …

Oct 9, 2024
CVE-2024-36814
4.9 MEDIUM

An arbitrary file read vulnerability in Adguard Home before v0.107.52 allows authenticated attackers to access arbitrary files as root on the underlying Operating System via …

Oct 8, 2024
CVE-2024-47822
4.2 MEDIUM

Directus is a real-time API and App dashboard for managing SQL database content. Access tokens from query strings are not redacted and are potentially exposed …

Oct 8, 2024
CVE-2024-46410
4.8 MEDIUM

PublicCMS V4.0.202406.d was discovered to contain a cross-site scripting (XSS) vulnerability via a crafted script to the Category Managment feature

Oct 8, 2024
CVE-2024-43614
5.5 MEDIUM

Relative path traversal in Microsoft Defender for Endpoint allows an authorized attacker to perform spoofing locally.

Oct 8, 2024
CVE-2024-43612
6.9 MEDIUM

Power BI Report Server Spoofing Vulnerability

Oct 8, 2024
CVE-2024-43609
6.5 MEDIUM

Microsoft Office Spoofing Vulnerability

Oct 8, 2024
CVE-2024-43604
5.7 MEDIUM

Outlook for Android Elevation of Privilege Vulnerability

Oct 8, 2024
CVE-2024-43603
5.5 MEDIUM

Visual Studio Collector Service Denial of Service Vulnerability

Oct 8, 2024
CVE-2024-43585
5.5 MEDIUM

Code Integrity Guard Security Feature Bypass Vulnerability

Oct 8, 2024
CVE-2024-43573
6.5 MEDIUM KEV

Windows MSHTML Platform Spoofing Vulnerability

Oct 8, 2024
CVE-2024-43571
5.6 MEDIUM

Sudo for Windows Spoofing Vulnerability

Oct 8, 2024
CVE-2024-43570
6.4 MEDIUM

Windows Kernel Elevation of Privilege Vulnerability

Oct 8, 2024
CVE-2024-43561
6.5 MEDIUM

Windows Mobile Broadband Driver Denial of Service Vulnerability

Oct 8, 2024
CVE-2024-43559
6.5 MEDIUM

Windows Mobile Broadband Driver Denial of Service Vulnerability

Oct 8, 2024
CVE-2024-43558
6.5 MEDIUM

Windows Mobile Broadband Driver Denial of Service Vulnerability

Oct 8, 2024
CVE-2024-43557
6.5 MEDIUM

Windows Mobile Broadband Driver Denial of Service Vulnerability

Oct 8, 2024
CVE-2024-43555
6.5 MEDIUM

Windows Mobile Broadband Driver Denial of Service Vulnerability

Oct 8, 2024
CVE-2024-43554
5.5 MEDIUM

Windows Kernel-Mode Driver Information Disclosure Vulnerability

Oct 8, 2024
CVE-2024-43547
6.5 MEDIUM

Windows Kerberos Information Disclosure Vulnerability

Oct 8, 2024
CVE-2024-43546
5.6 MEDIUM

Windows Cryptographic Information Disclosure Vulnerability

Oct 8, 2024
CVE-2024-43543
6.8 MEDIUM

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

Oct 8, 2024
CVE-2024-43542
6.5 MEDIUM

Windows Mobile Broadband Driver Denial of Service Vulnerability

Oct 8, 2024
CVE-2024-43540
6.5 MEDIUM

Windows Mobile Broadband Driver Denial of Service Vulnerability

Oct 8, 2024
CVE-2024-43538
6.5 MEDIUM

Windows Mobile Broadband Driver Denial of Service Vulnerability

Oct 8, 2024
CVE-2024-43537
6.5 MEDIUM

Windows Mobile Broadband Driver Denial of Service Vulnerability

Oct 8, 2024
CVE-2024-43536
6.8 MEDIUM

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

Oct 8, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.