CVE Database

5223+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-27457
2.5 LOW

Improper check for unusual or exceptional conditions in Intel(R) TDX Module firmware before version 1.5.06 may allow a privileged user to potentially enable information disclosure …

Oct 8, 2024
CVE-2024-47780
3.1 LOW

TYPO3 is a free and open source Content Management Framework. Backend users could see items in the backend page tree without having access if the …

Oct 8, 2024
CVE-2024-47951
3.5 LOW

In JetBrains TeamCity before 2024.07.3 stored XSS was possible via server global settings

Oct 8, 2024
CVE-2024-47950
3.5 LOW

In JetBrains TeamCity before 2024.07.3 stored XSS was possible in Backup configuration settings

Oct 8, 2024
CVE-2024-33506
3.3 LOW

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiManager 7.4.2 and below, 7.2.5 and below, 7.0.12 and below allows a remote …

Oct 8, 2024
CVE-2024-8518
3.3 LOW

CWE-20: Improper Input Validation vulnerability exists that could cause a crash of the Zelio Soft 2 application when a specially crafted project file is loaded …

Oct 8, 2024
CVE-2024-45476
3.3 LOW

A vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versions < V14.3.0.12), Teamcenter Visualization V2312 (All versions …

Oct 8, 2024
CVE-2024-34671
3.3 LOW

Use of implicit intent for sensitive communication in translation혻in Samsung Internet prior to version 26.0.3.1 allows local attackers to get sensitive information. User interaction is …

Oct 8, 2024
CVE-2024-9026
3.3 LOW

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using PHP-FPM SAPI and it is configured to catch workers output through …

Oct 8, 2024
CVE-2024-8925
3.1 LOW

In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, erroneous parsing of multipart form data contained in an HTTP POST request could …

Oct 8, 2024
CVE-2024-45382
3.3 LOW

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS through out-of-bounds write.

Oct 8, 2024
CVE-2024-43697
3.3 LOW

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS through improper input.

Oct 8, 2024
CVE-2024-43696
3.3 LOW

in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS by memory leak.

Oct 8, 2024
CVE-2024-47814
3.9 LOW

Vim is an open source, command line text editor. A use-after-free was found in Vim < 9.1.0764. When closing a buffer (visible in a window) …

Oct 7, 2024
CVE-2024-9554
3.7 LOW

A vulnerability classified as problematic was found in Sovell Smart Canteen System up to 3.0.7303.30513. Affected by this vulnerability is the function Check_ET_CheckPwdz201 of the …

Oct 6, 2024
CVE-2024-41511
3.9 LOW

A Path Traversal (Local File Inclusion) vulnerability in "BinaryFileRedirector.ashx" in CADClick v1.11.0 and before allows remote attackers to retrieve arbitrary local files via the "path" …

Oct 4, 2024
CVE-2024-9513
3.7 LOW

A vulnerability was found in Netadmin Software NetAdmin IAM up to 3.5 and classified as problematic. Affected by this issue is some unknown functionality of …

Oct 4, 2024
CVE-2024-0125
3.3 LOW

NVIDIA CUDA Toolkit for Windows and Linux contains a vulnerability in the nvdisam command line tool, where a user can cause a NULL pointer dereference …

Oct 3, 2024
CVE-2024-0124
3.3 LOW

NVIDIA CUDA Toolkit for Windows and Linux contains a vulnerability in the nvdisam command line tool, where a user can cause nvdisasm to read freed …

Oct 3, 2024
CVE-2024-0123
3.3 LOW

NVIDIA CUDA toolkit for Windows and Linux contains a vulnerability in the nvdisasm command line tool where an attacker may cause an improper validation in …

Oct 3, 2024
CVE-2024-24122
3.3 LOW

A remote code execution vulnerability in the project management of Wanxing Technology's Yitu project which allows an attacker to use the exp.adpx file as a …

Oct 2, 2024
CVE-2024-47612
3.5 LOW

DataDump is a MediaWiki extension that provides dumps of wikis. Several interface messages are unescaped (more specifically, (datadump-table-column-queued), (datadump-table-column-in-progress), (datadump-table-column-completed), (datadump-table-column-failed)). If these messages are …

Oct 2, 2024
CVE-2024-47526
3.5 LOW

LibreNMS is an open-source, PHP/MySQL/SNMP-based network monitoring system. A Self Cross-Site Scripting (Self-XSS) vulnerability in the "Alert Templates" feature allows users to inject arbitrary JavaScript …

Oct 1, 2024
CVE-2024-9411
3.5 LOW

A vulnerability classified as problematic has been found in OFCMS 1.1.2. This affects the function add of the file /admin/system/dict/add.json?sqlid=system.dict.save. The manipulation of the argument …

Oct 1, 2024
CVE-2024-30132
3.7 LOW

HCL Nomad server on Domino did not configure certain HTTP Security headers by default which could allow an attacker to obtain sensitive information via unspecified …

Oct 1, 2024
CVE-2024-28808
2.7 LOW

An issue was discovered in Infinera hiT 7300 5.60.50. Hidden functionality in the web interface allows a remote authenticated attacker to access reserved information by …

Sep 30, 2024
CVE-2024-28811
3.3 LOW

An issue was discovered in Infinera hiT 7300 5.60.50. A web application allows a remote privileged attacker to execute applications contained in a specific OS …

Sep 30, 2024
CVE-2024-42496
2.4 LOW

Smart-tab Android app installed April 2023 or earlier contains an issue with plaintext storage of a password. If this vulnerability is exploited, an attacker with …

Sep 30, 2024
CVE-2024-9323
3.5 LOW

A vulnerability was found in SourceCodester Inventory Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of …

Sep 29, 2024
CVE-2024-9320
3.5 LOW

A vulnerability has been found in SourceCodester Online Timesheet App 1.0 and classified as problematic. This vulnerability affects unknown code of the file /endpoint/add-timesheet.php of …

Sep 29, 2024
CVE-2024-9299
3.5 LOW

A vulnerability classified as problematic has been found in SourceCodester Online Railway Reservation System 1.0. This affects an unknown part of the file /?page=reserve. The …

Sep 28, 2024
CVE-2024-9291
3.5 LOW

A vulnerability classified as problematic has been found in kalvinGit kvf-admin up to f12a94dc1ebb7d1c51ee978a85e4c7ed75c620ff. Affected is an unknown function of the file /ueditor/upload?configPath=ueditor/config.json&action=uploadfile of the …

Sep 27, 2024
CVE-2024-45744
3.0 LOW

TopQuadrant TopBraid EDG stores external credentials insecurely. An authenticated attacker with file system access can read edg-setup.properites and obtain the secret to decrypt external passwords …

Sep 27, 2024
CVE-2024-9283
3.3 LOW

A vulnerability classified as problematic has been found in RelaxedJS ReLaXed up to 0.2.2. Affected is an unknown function of the component Pug to PDF …

Sep 27, 2024
CVE-2024-9279
2.4 LOW

A vulnerability, which was classified as problematic, was found in funnyzpc Mee-Admin up to 1.6. This affects an unknown part of the file /mee/index of …

Sep 27, 2024
CVE-2024-9277
3.5 LOW

A vulnerability classified as problematic was found in Langflow up to 1.0.18. Affected by this vulnerability is an unknown functionality of the file \src\backend\base\langflow\interface\utils.py of …

Sep 27, 2024
CVE-2024-9276
3.5 LOW

A vulnerability classified as problematic has been found in TMsoft MyAuth Gateway 3. Affected is an unknown function of the file /index.php. The manipulation of …

Sep 27, 2024
CVE-2024-8974
2.6 LOW

Information disclosure in Gitlab EE/CE affecting all versions from 15.6 prior to 17.2.8, 17.3 prior to 17.3.4, and 17.4 prior to 17.4.1 in specific conditions …

Sep 26, 2024
CVE-2024-4099
3.1 LOW

An issue has been discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.2.8, from 17.3 prior to 17.3.4, and from 17.4 …

Sep 26, 2024
CVE-2024-9203
2.5 LOW

A vulnerability, which was classified as problematic, has been found in Enpass Password Manager up to 6.9.5 on Windows. This issue affects some unknown processing. …

Sep 26, 2024
CVE-2024-47145
3.1 LOW

Mattermost versions 9.5.x <= 9.5.8 fail to properly authorize access to archived channels when viewing archived channels is disabled, which allows an attacker to view …

Sep 26, 2024
CVE-2024-47003
3.1 LOW

Mattermost versions 9.11.x <= 9.11.0 and 9.5.x <= 9.5.8 fail to validate that the message of the permalink post is a string, which allows an …

Sep 26, 2024
CVE-2024-45843
3.1 LOW

Mattermost versions 9.5.x <= 9.5.8 fail to include the metadata endpoints of Oracle Cloud and Alibaba in the SSRF denylist, which allows an attacker to …

Sep 26, 2024
CVE-2023-25189
3.3 LOW

BTS is affected by information disclosure vulnerability where mobile network operator personnel connected over BTS Web Element Manager, regardless of the access privileges, having a …

Sep 25, 2024
CVE-2024-8350
2.7 LOW

The Uncanny Groups for LearnDash plugin for WordPress is vulnerable to user group add due to a missing capability check on the /wp-json/ulgm_management/v1/add_user/ REST API …

Sep 25, 2024
CVE-2024-45599
3.8 LOW

Cursor is an artificial intelligence code editor. Prior to version 0.41.0, if a user on macOS has granted Cursor access to the camera or microphone, …

Sep 25, 2024
CVE-2023-5359
3.7 LOW

The W3 Total Cache plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.7.5 via Google OAuth API secrets …

Sep 25, 2024
CVE-2022-43845
3.7 LOW

IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A …

Sep 25, 2024
CVE-2024-8263
2.7 LOW

An improper privilege management vulnerability allowed arbitrary workflows to be committed using an improperly scoped PAT through the use of nested tags. This vulnerability affected …

Sep 23, 2024
CVE-2024-9092
3.5 LOW

A vulnerability was found in SourceCodester Profile Registration without Reload Refresh 1.0. It has been rated as problematic. Affected by this issue is some unknown …

Sep 23, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.