CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-8461
5.3 MEDIUM

A vulnerability, which was classified as problematic, was found in D-Link DNS-320 2.02b01. This affects an unknown part of the file /cgi-bin/discovery.cgi of the component …

Sep 5, 2024
CVE-2024-7884
7.5 HIGH

When a canister method is called via ic_cdk::call* , a new Future CallFuture is created and can be awaited by the caller to get the …

Sep 5, 2024
CVE-2024-8460
3.7 LOW

A vulnerability, which was classified as problematic, has been found in D-Link DNS-320 2.02b01. Affected by this issue is some unknown functionality of the file …

Sep 5, 2024
CVE-2024-7605
4.3 MEDIUM

The HelloAsso plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ha_ajax' function in all versions …

Sep 5, 2024
CVE-2024-7381
5.3 MEDIUM

The Geo Controller plugin for WordPress is vulnerable to unauthorized shortcode execution due to missing authorization and capability checks on the ajax__shortcode_cache function in all …

Sep 5, 2024
CVE-2024-7380
4.3 MEDIUM

The Geo Controller plugin for WordPress is vulnerable to unauthorized menu creation/deletion due to missing capability checks on the ajax__geolocate_menu and ajax__geolocate_remove_menu functions in all …

Sep 5, 2024
CVE-2024-5957
6.3 MEDIUM

This vulnerability allows unauthenticated remote attackers to bypass authentication and gain APIs access of the Manager.

Sep 5, 2024
CVE-2024-5956
6.5 MEDIUM

This vulnerability allows unauthenticated remote attackers to bypass authentication and gain partial data access to the vulnerable Trellix IPS Manager with garbage data in response …

Sep 5, 2024
CVE-2022-4529
5.3 MEDIUM

The Security, Antivirus, Firewall – S.A.F plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.3.5. This is due …

Sep 5, 2024
CVE-2022-3556
4.4 MEDIUM

The Cab fare calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the vehicle title setting in versions up to, and including, 1.1.6 …

Sep 5, 2024
CVE-2024-6929
6.4 MEDIUM

The Dynamic Featured Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘dfiFeatured’ parameter in all versions up to, and including, 3.7.0 …

Sep 5, 2024
CVE-2024-6894
6.4 MEDIUM

The RD Station plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.3.2 due to insufficient input sanitization …

Sep 5, 2024
CVE-2024-6332
6.5 MEDIUM

The Booking for Appointments and Events Calendar – Amelia Premium and Lite plugins for WordPress are vulnerable to unauthorized access of data due to a …

Sep 5, 2024
CVE-2024-8363
6.4 MEDIUM

The Share This Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's STI Buttons shortcode in all versions up to, and …

Sep 5, 2024
CVE-2024-5309
5.4 MEDIUM

The Form Vibes – Database Manager for Forms plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a …

Sep 5, 2024
CVE-2024-45107
5.5 MEDIUM

Acrobat Reader versions 20.005.30636, 24.002.20964, 24.001.30123, 24.002.20991 and earlier are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. …

Sep 5, 2024
CVE-2024-6835
5.3 MEDIUM

The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 5.5.6 via the …

Sep 5, 2024
CVE-2024-6846
5.3 MEDIUM

The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not validate access on some REST routes, allowing for an unauthenticated user to purge error and …

Sep 5, 2024
CVE-2024-8178
8.8 HIGH

The ctl_write_buffer and ctl_read_buffer functions allocated memory to be returned to userspace, without initializing it. Malicious software running in a guest VM that exposes virtio_scsi …

Sep 5, 2024
CVE-2024-45063
8.8 HIGH

The function ctl_write_buffer incorrectly set a flag which resulted in a kernel Use-After-Free when a command finished processing. Malicious software running in a guest VM …

Sep 5, 2024
CVE-2024-43110
8.8 HIGH

The ctl_request_sense function could expose up to three bytes of the kernel heap to userspace. Malicious software running in a guest VM that exposes virtio_scsi …

Sep 5, 2024
CVE-2024-43102
10.0 CRITICAL

Concurrent removals of certain anonymous shared memory mappings by using the UMTX_SHM_DESTROY sub-request of UMTX_OP_SHM can lead to decreasing the reference count of the object …

Sep 5, 2024
CVE-2024-42416
8.8 HIGH

The ctl_report_supported_opcodes function did not sufficiently validate a field provided by userspace, allowing an arbitrary write to a limited amount of kernel help memory. Malicious …

Sep 5, 2024
CVE-2024-32668
8.2 HIGH

An insufficient boundary validation in the USB code could lead to an out-of-bounds write on the heap, with data controlled by the caller. A malicious, …

Sep 5, 2024
CVE-2024-45288
8.4 HIGH

A missing null-termination character in the last element of an nvlist array string can lead to writing outside the allocated buffer.

Sep 5, 2024
CVE-2024-45287
7.5 HIGH

A malicious value of size in a structure of packed libnv can cause an integer overflow, leading to the allocation of a smaller buffer than …

Sep 5, 2024
CVE-2024-41928
8.4 HIGH

Malicious software running in a guest VM can exploit the buffer overflow to achieve code execution on the host in the bhyve userspace process, which …

Sep 5, 2024
CVE-2024-7627
8.1 HIGH

The Bit File Manager plugin for WordPress is vulnerable to Remote Code Execution in versions 6.0 to 6.5.5 via the 'checkSyntax' function. This is due …

Sep 5, 2024
CVE-2024-45692
7.5 HIGH

Webmin before 2.202 and Virtualmin before 7.20.2 allow a network traffic loop via spoofed UDP packets on port 10000.

Sep 4, 2024
CVE-2024-45429
6.1 MEDIUM

Cross-site scripting vulnerability exists in Advanced Custom Fields versions 6.3.5 and earlier and Advanced Custom Fields Pro versions 6.3.5 and earlier. If an attacker with …

Sep 4, 2024
CVE-2024-2166
8.8 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Email Security (Real Time Monitor modules) allows Reflected XSS.This issue affects Email …

Sep 4, 2024
CVE-2024-20506
6.1 MEDIUM

A vulnerability in the ClamD service module of Clam AntiVirus (ClamAV) versions 1.4.0, 1.3.2 and prior versions, all 1.2.x versions, 1.0.6 and prior versions, all …

Sep 4, 2024
CVE-2024-20505
4.0 MEDIUM

A vulnerability in the PDF parsing module of Clam AntiVirus (ClamAV) versions 1.4.0, 1.3.2 and prior versions, all 1.2.x versions, 1.0.6 and prior versions, all …

Sep 4, 2024
CVE-2024-45395
3.1 LOW

sigstore-go, a Go library for Sigstore signing and verification, is susceptible to a denial of service attack in versions prior to 0.6.1 when a verifier …

Sep 4, 2024
CVE-2024-45399
4.3 MEDIUM

Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In Indico prior to version 3.3.4, corresponding to Flask-Multipass prior …

Sep 4, 2024
CVE-2024-45172
6.8 MEDIUM

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to missing protection mechanisms, the C-MOR web interface is vulnerable to cross-site …

Sep 4, 2024
CVE-2024-45008
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Input: MT - limit max slots syzbot is reporting too large allocation at input_mt_init_slots(), for …

Sep 4, 2024
CVE-2024-45007
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: char: xillybus: Don't destroy workqueue from work item running on it Triggered by a kref …

Sep 4, 2024
CVE-2024-45006
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: xhci: Fix Panther point NULL pointer deref at full-speed re-enumeration re-enumerating full-speed devices after a …

Sep 4, 2024
CVE-2024-45005
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KVM: s390: fix validity interception issue when gisa is switched off We might run into …

Sep 4, 2024
CVE-2024-45004
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KEYS: trusted: dcp: fix leak of blob encryption key Trusted keys unseal the key blob …

Sep 4, 2024
CVE-2024-45003
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: vfs: Don't evict inode under the inode lru traversing context The inode reclaiming process(See function …

Sep 4, 2024
CVE-2024-45002
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: rtla/osnoise: Prevent NULL dereference in error handling If the "tool->data" allocation fails then there is …

Sep 4, 2024
CVE-2024-45001
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: mana: Fix RX buf alloc_size alignment and atomic op panic The MANA driver's RX …

Sep 4, 2024
CVE-2024-45000
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fs/netfs/fscache_cookie: add missing "n_accesses" check This fixes a NULL pointer dereference bug due to a …

Sep 4, 2024
CVE-2024-44999
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: gtp: pull network headers in gtp_dev_xmit() syzbot/KMSAN reported use of uninit-value in get_dev_xmit() [1] We …

Sep 4, 2024
CVE-2024-44998
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: atm: idt77252: prevent use after free in dequeue_rx() We can't dereference "skb" after calling vcc->push() …

Sep 4, 2024
CVE-2024-44997
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk_wed: fix use-after-free panic in mtk_wed_setup_tc_block_cb() When there are multiple ap interfaces on …

Sep 4, 2024
CVE-2024-44996
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: vsock: fix recursive ->recvmsg calls After a vsock socket has been added to a BPF …

Sep 4, 2024
CVE-2024-44995
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: hns3: fix a deadlock problem when config TC during resetting When config TC during …

Sep 4, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.