CVE Database

59325+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-20787
5.5 MEDIUM

Substance3D - Painter versions 10.0.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Oct 9, 2024
CVE-2024-9451
6.4 MEDIUM

The Embed PDF Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'height' and 'width' parameters in all versions up to, and …

Oct 9, 2024
CVE-2024-9449
6.4 MEDIUM

The Auto iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' parameter in all versions up to, and including, 1.7 due …

Oct 9, 2024
CVE-2024-39440
6.2 MEDIUM

In DRM service, there is a possible system crash due to null pointer dereference. This could lead to local denial of service with System execution …

Oct 9, 2024
CVE-2024-39439
6.2 MEDIUM

In DRM service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service …

Oct 9, 2024
CVE-2024-39438
6.5 MEDIUM

In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution …

Oct 9, 2024
CVE-2024-39437
6.5 MEDIUM

In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution …

Oct 9, 2024
CVE-2024-39436
6.5 MEDIUM

In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution …

Oct 9, 2024
CVE-2024-5968
4.8 MEDIUM

The Photo Gallery by 10Web WordPress plugin before 1.8.28 does not properly sanitise and escape some of its Gallery settings, which could allow high privilege …

Oct 9, 2024
CVE-2023-45872
6.5 MEDIUM

An issue was discovered in Qt before 6.2.11 and 6.3.x through 6.6.x before 6.6.1. When a QML image refers to an image whose content is …

Oct 9, 2024
CVE-2023-45361
6.1 MEDIUM

An issue was discovered in VectorComponentUserLinks.php in the Vector Skin component in MediaWiki before 1.39.5 and 1.40.x before 1.40.1. vector-intro-page MalformedTitleException is uncaught if it …

Oct 9, 2024
CVE-2023-45359
6.5 MEDIUM

An issue was discovered in the Vector Skin component for MediaWiki before 1.39.5 and 1.40.x before 1.40.1. vector-toc-toggle-button-label is not escaped, but should be, because …

Oct 9, 2024
CVE-2024-42934
5.0 MEDIUM

OpenIPMI before 2.0.36 has an out-of-bounds array access (for authentication type) in the ipmi_sim simulator, resulting in denial of service or (with very low probability) …

Oct 9, 2024
CVE-2024-7963
6.4 MEDIUM

The CMSMasters Content Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's multiple shortcodes in all versions up to, and including, …

Oct 9, 2024
CVE-2024-36814
4.9 MEDIUM

An arbitrary file read vulnerability in Adguard Home before v0.107.52 allows authenticated attackers to access arbitrary files as root on the underlying Operating System via …

Oct 8, 2024
CVE-2024-47822
4.2 MEDIUM

Directus is a real-time API and App dashboard for managing SQL database content. Access tokens from query strings are not redacted and are potentially exposed …

Oct 8, 2024
CVE-2024-46410
4.8 MEDIUM

PublicCMS V4.0.202406.d was discovered to contain a cross-site scripting (XSS) vulnerability via a crafted script to the Category Managment feature

Oct 8, 2024
CVE-2024-43614
5.5 MEDIUM

Relative path traversal in Microsoft Defender for Endpoint allows an authorized attacker to perform spoofing locally.

Oct 8, 2024
CVE-2024-43612
6.9 MEDIUM

Power BI Report Server Spoofing Vulnerability

Oct 8, 2024
CVE-2024-43609
6.5 MEDIUM

Microsoft Office Spoofing Vulnerability

Oct 8, 2024
CVE-2024-43604
5.7 MEDIUM

Outlook for Android Elevation of Privilege Vulnerability

Oct 8, 2024
CVE-2024-43603
5.5 MEDIUM

Visual Studio Collector Service Denial of Service Vulnerability

Oct 8, 2024
CVE-2024-43585
5.5 MEDIUM

Code Integrity Guard Security Feature Bypass Vulnerability

Oct 8, 2024
CVE-2024-43573
6.5 MEDIUM KEV

Windows MSHTML Platform Spoofing Vulnerability

Oct 8, 2024
CVE-2024-43571
5.6 MEDIUM

Sudo for Windows Spoofing Vulnerability

Oct 8, 2024
CVE-2024-43570
6.4 MEDIUM

Windows Kernel Elevation of Privilege Vulnerability

Oct 8, 2024
CVE-2024-43561
6.5 MEDIUM

Windows Mobile Broadband Driver Denial of Service Vulnerability

Oct 8, 2024
CVE-2024-43559
6.5 MEDIUM

Windows Mobile Broadband Driver Denial of Service Vulnerability

Oct 8, 2024
CVE-2024-43558
6.5 MEDIUM

Windows Mobile Broadband Driver Denial of Service Vulnerability

Oct 8, 2024
CVE-2024-43557
6.5 MEDIUM

Windows Mobile Broadband Driver Denial of Service Vulnerability

Oct 8, 2024
CVE-2024-43555
6.5 MEDIUM

Windows Mobile Broadband Driver Denial of Service Vulnerability

Oct 8, 2024
CVE-2024-43554
5.5 MEDIUM

Windows Kernel-Mode Driver Information Disclosure Vulnerability

Oct 8, 2024
CVE-2024-43547
6.5 MEDIUM

Windows Kerberos Information Disclosure Vulnerability

Oct 8, 2024
CVE-2024-43546
5.6 MEDIUM

Windows Cryptographic Information Disclosure Vulnerability

Oct 8, 2024
CVE-2024-43543
6.8 MEDIUM

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

Oct 8, 2024
CVE-2024-43542
6.5 MEDIUM

Windows Mobile Broadband Driver Denial of Service Vulnerability

Oct 8, 2024
CVE-2024-43540
6.5 MEDIUM

Windows Mobile Broadband Driver Denial of Service Vulnerability

Oct 8, 2024
CVE-2024-43538
6.5 MEDIUM

Windows Mobile Broadband Driver Denial of Service Vulnerability

Oct 8, 2024
CVE-2024-43537
6.5 MEDIUM

Windows Mobile Broadband Driver Denial of Service Vulnerability

Oct 8, 2024
CVE-2024-43536
6.8 MEDIUM

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

Oct 8, 2024
CVE-2024-43534
6.5 MEDIUM

Windows Graphics Component Information Disclosure Vulnerability

Oct 8, 2024
CVE-2024-43526
6.8 MEDIUM

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

Oct 8, 2024
CVE-2024-43525
6.8 MEDIUM

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

Oct 8, 2024
CVE-2024-43524
6.8 MEDIUM

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

Oct 8, 2024
CVE-2024-43523
6.8 MEDIUM

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

Oct 8, 2024
CVE-2024-43520
5.0 MEDIUM

Windows Kernel Denial of Service Vulnerability

Oct 8, 2024
CVE-2024-43513
6.4 MEDIUM

BitLocker Security Feature Bypass Vulnerability

Oct 8, 2024
CVE-2024-43512
6.5 MEDIUM

Windows Standards-Based Storage Management Service Denial of Service Vulnerability

Oct 8, 2024
CVE-2024-43508
5.5 MEDIUM

Windows Graphics Component Information Disclosure Vulnerability

Oct 8, 2024
CVE-2024-43500
5.5 MEDIUM

Windows Resilient File System (ReFS) Information Disclosure Vulnerability

Oct 8, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.