CVE Database

59186+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-8823
5.5 MEDIUM

PDF-XChange Editor JB2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. …

Nov 22, 2024
CVE-2024-8822
5.5 MEDIUM

PDF-XChange Editor U3D File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. …

Nov 22, 2024
CVE-2024-8821
5.5 MEDIUM

PDF-XChange Editor U3D File Parsing Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User …

Nov 22, 2024
CVE-2024-8820
5.5 MEDIUM

PDF-XChange Editor U3D File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. …

Nov 22, 2024
CVE-2024-8819
5.5 MEDIUM

PDF-XChange Editor U3D File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. …

Nov 22, 2024
CVE-2024-8816
5.5 MEDIUM

PDF-XChange Editor U3D File Parsing Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of PDF-XChange Editor. User …

Nov 22, 2024
CVE-2024-11619
5.0 MEDIUM

A vulnerability, which was classified as problematic, has been found in macrozheng mall up to 1.0.3. Affected by this issue is some unknown functionality of …

Nov 22, 2024
CVE-2024-11612
6.5 MEDIUM

7-Zip CopyCoder Infinite Loop Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of 7-Zip. Interaction with this library …

Nov 22, 2024
CVE-2024-6247
6.8 MEDIUM

Wyze Cam v3 Wi-Fi SSID OS Command Injection Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations …

Nov 22, 2024
CVE-2024-5512
5.5 MEDIUM

Kofax Power PDF JP2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Kofax …

Nov 22, 2024
CVE-2024-53253
5.3 MEDIUM

Sentry is an error tracking and performance monitoring platform. Version 24.11.0, and only version 24.11.0, is vulnerable to a scenario where a specific error message …

Nov 22, 2024
CVE-2024-47863
6.2 MEDIUM

An issue was discovered in Centreon Web 24.10.x before 24.10.0, 24.04.x before 24.04.8, 23.10.x before 23.10.18, 23.04.x before 23.04.23, and 22.10.x before 22.10.26. A stored …

Nov 22, 2024
CVE-2024-30372
6.3 MEDIUM

Allegra getLinkText Server-Side Template Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Authentication is …

Nov 22, 2024
CVE-2023-52334
6.5 MEDIUM

Allegra downloadAttachmentGlobal Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Allegra. Although authentication is required …

Nov 22, 2024
CVE-2023-51648
6.5 MEDIUM

Allegra getFileContentAsString Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Allegra. Although authentication is required …

Nov 22, 2024
CVE-2023-51647
4.7 MEDIUM

Allegra saveInlineEdit Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Although authentication is …

Nov 22, 2024
CVE-2023-51646
4.7 MEDIUM

Allegra uploadSimpleFile Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Although authentication is …

Nov 22, 2024
CVE-2023-51645
4.7 MEDIUM

Allegra unzipFile Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Although authentication is …

Nov 22, 2024
CVE-2023-51643
4.7 MEDIUM

Allegra uploadFile Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Although authentication is …

Nov 22, 2024
CVE-2023-51642
6.3 MEDIUM

Allegra loadFieldMatch Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Although …

Nov 22, 2024
CVE-2023-51641
6.3 MEDIUM

Allegra renderFieldMatch Deserialization of Unstrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Although …

Nov 22, 2024
CVE-2023-51640
4.7 MEDIUM

Allegra extarctZippedFile Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Allegra. Although authentication is …

Nov 22, 2024
CVE-2024-52998
5.5 MEDIUM

Substance3D - Stager versions 3.0.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Nov 22, 2024
CVE-2024-50657
6.8 MEDIUM

An issue in Owncloud android apk v.4.3.1 allows a physically proximate attacker to escalate privileges via the PassCodeViewModel class, specifically in the checkPassCodeIsValid method

Nov 22, 2024
CVE-2024-37783
5.4 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in Gladinet CentreStack v13.12.9934.54690 allows attackers to inject malicious JavaScript into the web browser of a victim via the …

Nov 22, 2024
CVE-2024-51074
6.7 MEDIUM

Incorrect access control in KIA Seltos vehicle instrument cluster with software and hardware v1.0 allows attackers to arbitrarily change odometer readings in the vehicle by …

Nov 22, 2024
CVE-2024-51073
6.7 MEDIUM

An issue in KIA Seltos vehicle instrument cluster with software and hardware v1.0 allows attackers to control or disrupt CAN communication between the instrument cluster …

Nov 22, 2024
CVE-2024-51072
5.3 MEDIUM

An issue in KIA Seltos vehicle instrument cluster with software and hardware v1.0 allows attackers to cause a Denial of Service (DoS) via ECU reset …

Nov 22, 2024
CVE-2024-50965
5.4 MEDIUM

Cross Site Scripting vulnerability in Public Knowledge Project PKP Platform OJS/OMP/OPS- before v.3.3.0.16 allows an attacker to execute arbitrary code and escalate privileges via a …

Nov 22, 2024
CVE-2024-38646
6.0 MEDIUM

An incorrect permission assignment for critical resource vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow local authenticated attackers …

Nov 22, 2024
CVE-2024-38645
6.5 MEDIUM

A server-side request forgery (SSRF) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote authenticated attackers to read …

Nov 22, 2024
CVE-2024-37050
6.5 MEDIUM

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow …

Nov 22, 2024
CVE-2024-37049
6.5 MEDIUM

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow …

Nov 22, 2024
CVE-2024-37048
4.9 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have …

Nov 22, 2024
CVE-2024-37047
6.5 MEDIUM

A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow …

Nov 22, 2024
CVE-2024-37046
4.9 MEDIUM

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained …

Nov 22, 2024
CVE-2024-37045
4.9 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have …

Nov 22, 2024
CVE-2024-37043
4.9 MEDIUM

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained …

Nov 22, 2024
CVE-2024-37042
4.9 MEDIUM

A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have …

Nov 22, 2024
CVE-2024-32770
6.3 MEDIUM

A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow remote attackers who have gained user access …

Nov 22, 2024
CVE-2024-32769
6.3 MEDIUM

A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow remote attackers who have gained user access …

Nov 22, 2024
CVE-2024-32768
6.3 MEDIUM

A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow remote attackers who have gained user access …

Nov 22, 2024
CVE-2024-32767
6.3 MEDIUM

A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow remote attackers who have gained user access …

Nov 22, 2024
CVE-2021-38134
6.1 MEDIUM

Possible XSS in iManager URL for access Component has been discovered in OpenText™ iManager 3.2.5.0000.

Nov 22, 2024
CVE-2021-38119
6.1 MEDIUM

Possible Reflected Cross-Site Scripting (XSS) Vulnerability in iManager has been discovered in OpenText™ iManager 3.2.4.0000.

Nov 22, 2024
CVE-2021-38118
5.5 MEDIUM

Possible improper input validation Vulnerability in iManager has been discovered in OpenText™ iManager 3.2.4.0000.

Nov 22, 2024
CVE-2024-49054
4.3 MEDIUM

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Nov 22, 2024
CVE-2024-51766
6.5 MEDIUM

A potential security vulnerability has been identified in the HPE NonStop DISK UTIL (T9208) product. This vulnerability could be exploited to cause a denial of …

Nov 22, 2024
CVE-2024-41781
5.1 MEDIUM

IBM PowerVM Platform KeyStore (IBM PowerVM Hypervisor FW950.00 through FW950.90, FW1030.00 through FW1030.60, FW1050.00 through FW1050.20, and FW1060.00 through FW1060.10 functionality can be compromised if …

Nov 22, 2024
CVE-2021-30299
6.7 MEDIUM

Possible out of bound access in audio module due to lack of validation of user provided input.

Nov 22, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.