CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-43534
6.5 MEDIUM

Windows Graphics Component Information Disclosure Vulnerability

Oct 8, 2024
CVE-2024-43526
6.8 MEDIUM

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

Oct 8, 2024
CVE-2024-43525
6.8 MEDIUM

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

Oct 8, 2024
CVE-2024-43524
6.8 MEDIUM

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

Oct 8, 2024
CVE-2024-43523
6.8 MEDIUM

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

Oct 8, 2024
CVE-2024-43520
5.0 MEDIUM

Windows Kernel Denial of Service Vulnerability

Oct 8, 2024
CVE-2024-43513
6.4 MEDIUM

BitLocker Security Feature Bypass Vulnerability

Oct 8, 2024
CVE-2024-43512
6.5 MEDIUM

Windows Standards-Based Storage Management Service Denial of Service Vulnerability

Oct 8, 2024
CVE-2024-43508
5.5 MEDIUM

Windows Graphics Component Information Disclosure Vulnerability

Oct 8, 2024
CVE-2024-43500
5.5 MEDIUM

Windows Resilient File System (ReFS) Information Disclosure Vulnerability

Oct 8, 2024
CVE-2024-43481
6.5 MEDIUM

Power BI Report Server Spoofing Vulnerability

Oct 8, 2024
CVE-2024-43480
6.6 MEDIUM

Azure Service Fabric for Linux Remote Code Execution Vulnerability

Oct 8, 2024
CVE-2024-43456
4.8 MEDIUM

Windows Remote Desktop Services Tampering Vulnerability

Oct 8, 2024
CVE-2024-37983
6.7 MEDIUM

Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability

Oct 8, 2024
CVE-2024-37982
6.7 MEDIUM

Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability

Oct 8, 2024
CVE-2024-37979
6.7 MEDIUM

Windows Kernel Elevation of Privilege Vulnerability

Oct 8, 2024
CVE-2024-37976
6.7 MEDIUM

Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability

Oct 8, 2024
CVE-2024-35215
6.2 MEDIUM

NULL pointer dereference in IP socket options processing of the Networking Stack in QNX Software Development Platform (SDP) version(s) 7.1 and 7.0 could allow an …

Oct 8, 2024
CVE-2024-9622
5.3 MEDIUM

A vulnerability was found in the resteasy-netty4 library arising from improper handling of HTTP requests using smuggling techniques. When an HTTP smuggling request with an …

Oct 8, 2024
CVE-2024-9621
5.3 MEDIUM

A vulnerability was found in Quarkus CXF. Passwords and other secrets may appear in the application log in spite of the user configuring them to …

Oct 8, 2024
CVE-2024-9620
5.3 MEDIUM

A flaw was found in Event-Driven Automation (EDA) in Ansible Automation Platform (AAP), which lacks encryption of sensitive information. An attacker with network access could …

Oct 8, 2024
CVE-2024-9379
6.5 MEDIUM KEV

SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL …

Oct 8, 2024
CVE-2024-47949
4.9 MEDIUM

In JetBrains TeamCity before 2024.07.3 path traversal allowed backup file write to arbitrary location

Oct 8, 2024
CVE-2024-47948
4.9 MEDIUM

In JetBrains TeamCity before 2024.07.3 path traversal leading to information disclosure was possible via server backups

Oct 8, 2024
CVE-2024-47161
4.3 MEDIUM

In JetBrains TeamCity before 2024.07.3 password could be exposed via Sonar runner REST API

Oct 8, 2024
CVE-2024-45231
5.3 MEDIUM

An issue was discovered in Django v5.1.1, v5.0.9, and v4.2.16. The django.contrib.auth.forms.PasswordResetForm class, when used in a view implementing password reset flows, allows remote attackers …

Oct 8, 2024
CVE-2024-8482
6.4 MEDIUM

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and …

Oct 8, 2024
CVE-2024-8431
4.3 MEDIUM

The Photo Gallery, Images, Slider in Rbs Image Gallery plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check …

Oct 8, 2024
CVE-2024-9207
6.1 MEDIUM

The BuddyPress Docs plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in …

Oct 8, 2024
CVE-2024-8488
4.4 MEDIUM

The Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Survey fields in all versions up to, and including, 4.9.7 due to …

Oct 8, 2024
CVE-2024-8629
6.1 MEDIUM

The WooCommerce Multilingual & Multicurrency with WPML plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping …

Oct 8, 2024
CVE-2024-8433
6.4 MEDIUM

The Easy Mega Menu Plugin for WordPress – ThemeHunk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘themehunk_megamenu_bg_image' parameter in all versions …

Oct 8, 2024
CVE-2024-3506
6.7 MEDIUM

A possible buffer overflow in selected cameras' drivers from XProtect Device Pack can allow an attacker with access to internal network to execute commands on …

Oct 8, 2024
CVE-2024-47565
4.3 MEDIUM

A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate that user input complies with …

Oct 8, 2024
CVE-2024-47563
5.3 MEDIUM

A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate a file path that is …

Oct 8, 2024
CVE-2024-47196
6.7 MEDIUM

A vulnerability has been identified in ModelSim (All versions < V2025.2), Questa (All versions < V2025.2). vsimk.exe in affected applications allows a specific tcl file …

Oct 8, 2024
CVE-2024-47195
6.7 MEDIUM

A vulnerability has been identified in ModelSim (All versions < V2024.3), Questa (All versions < V2024.3). gdb.exe in affected applications allows a specific executable file …

Oct 8, 2024
CVE-2024-47194
6.7 MEDIUM

A vulnerability has been identified in ModelSim (All versions < V2024.3), Questa (All versions < V2024.3). vish2.exe in affected applications allows a specific DLL file …

Oct 8, 2024
CVE-2024-46887
5.3 MEDIUM

The web server of affected devices do not properly authenticate user request to the '/ClientArea/RuntimeInfoData.mwsl' endpoint. This could allow an unauthenticated remote attacker to gain …

Oct 8, 2024
CVE-2024-46886
4.7 MEDIUM

The web server of affected devices does not properly validate input that is used for a user redirection. This could allow an attacker to make …

Oct 8, 2024
CVE-2022-4534
5.3 MEDIUM

The Limit Login Attempts (Spam Protection) plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 5.3. This is due …

Oct 8, 2024
CVE-2024-8964
6.4 MEDIUM

The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up …

Oct 8, 2024
CVE-2024-34672
5.5 MEDIUM

Improper input validation in SamsungVideoPlayer prior to versions 7.3.29.1 in Android 12, 7.3.36.1 in Android 13, and 7.3.41.230 in Android 14 allows local attackers to …

Oct 8, 2024
CVE-2024-34670
4.0 MEDIUM

Use of implicit intent for sensitive communication in Sound Assistant prior to version 6.1.0.9 allows local attackers to get sensitive information.

Oct 8, 2024
CVE-2024-34664
4.1 MEDIUM

Improper check for exception conditions in Knox Guard prior to SMR Oct-2024 Release 1 allows physical attackers to bypass Knox Guard in a multi-user environment.

Oct 8, 2024
CVE-2024-34663
5.3 MEDIUM

Integer overflow in libSEF.quram.so prior to SMR Oct-2024 Release 1 allows local attackers to write out-of-bounds memory.

Oct 8, 2024
CVE-2024-34662
6.2 MEDIUM

Improper access control in ActivityManager prior to SMR Oct-2024 Release 1 in select Android 12, 13 and SMR Sep-2024 Release 1 in select Android 14 …

Oct 8, 2024
CVE-2024-9292
6.4 MEDIUM

The Bridge Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'formforall' shortcode in versions up to, and including, 3.2.0 due to insufficient …

Oct 8, 2024
CVE-2024-9021
5.4 MEDIUM

In the process of testing the Relevanssi WordPress plugin before 4.23.1, a vulnerability was found that allows you to implement Stored XSS on behalf of …

Oct 8, 2024
CVE-2024-8983
4.8 MEDIUM

Custom Twitter Feeds WordPress plugin before 2.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Oct 8, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.