CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-20087
6.7 MEDIUM

In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Sep 2, 2024
CVE-2024-20086
6.7 MEDIUM

In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Sep 2, 2024
CVE-2024-20085
4.4 MEDIUM

In power, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System …

Sep 2, 2024
CVE-2024-20084
4.4 MEDIUM

In power, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System …

Sep 2, 2024
CVE-2024-45522
9.8 CRITICAL

Linen before cd37c3e does not verify that the domain is linen.dev or www.linen.dev when resetting a password. This occurs in create in apps/web/pages/api/forgot-password/index.ts.

Sep 2, 2024
CVE-2024-45270
4.3 MEDIUM

WordPress plugin "Carousel Slider" provided by Sayful Islam contains a cross-site request forgery vulnerability on Hero image selection feature. While logged in to the WordPress …

Sep 2, 2024
CVE-2024-45269
4.3 MEDIUM

WordPress plugin "Carousel Slider" provided by Sayful Islam contains a cross-site request forgery vulnerability on Carousel image selection feature. While logged in to the WordPress …

Sep 2, 2024
CVE-2024-8370
3.5 LOW

A vulnerability classified as problematic was found in Grocy up to 4.2.0. This vulnerability affects unknown code of the file /api/files/recipepictures/ of the component SVG …

Sep 1, 2024
CVE-2024-45509
6.5 MEDIUM

In MISP through 2.4.196, app/Controller/BookmarksController.php does not properly restrict access to bookmarks data in the case where the user is not an org admin.

Sep 1, 2024
CVE-2024-45508
9.8 CRITICAL

HTMLDOC before 1.9.19 has an out-of-bounds write in parse_paragraph in ps-pdf.cxx because of an attempt to strip leading whitespace from a whitespace-only node.

Sep 1, 2024
CVE-2024-5053
4.2 MEDIUM

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to unauthorized Malichimp …

Sep 1, 2024
CVE-2024-8368
7.3 HIGH

A vulnerability was found in code-projects Hospital Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Sep 1, 2024
CVE-2024-8367
3.5 LOW

A vulnerability was found in HM Courts & Tribunals Service Probate Back Office up to c1afe0cdb2b2766d9e24872c4e827f8b82a6cd31. It has been classified as problematic. Affected is an …

Sep 1, 2024
CVE-2024-8366
4.3 MEDIUM

A vulnerability was found in code-projects Pharmacy Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /index.php?id=userProfileEdit …

Aug 31, 2024
CVE-2024-44946
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: kcm: Serialise kcm_sendmsg() for the same socket. syzkaller reported UAF in kcm_release(). [0] The scenario …

Aug 31, 2024
CVE-2022-4539
5.3 MEDIUM

The Web Application Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.1.2. This is due to insufficient …

Aug 31, 2024
CVE-2024-8108
6.4 MEDIUM

The Share This Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alignment' parameter in all versions up to, and including, 2.01 …

Aug 31, 2024
CVE-2024-7717
8.8 HIGH

The WP Events Manager plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter in all versions up to, and including, 2.1.11 …

Aug 31, 2024
CVE-2024-0111
4.4 MEDIUM

NVIDIA CUDA Toolkit contains a vulnerability in command 'cuobjdump' where a user may cause a crash or produce incorrect output by passing a malformed ELF …

Aug 31, 2024
CVE-2024-0110
4.4 MEDIUM

NVIDIA CUDA Toolkit contains a vulnerability in command `cuobjdump` where a user may cause an out-of-bound write by passing in a malformed ELF file. A …

Aug 31, 2024
CVE-2024-0109
3.3 LOW

NVIDIA CUDA Toolkit contains a vulnerability in command `cuobjdump` where a user may cause a crash by passing in a malformed ELF file. A successful …

Aug 31, 2024
CVE-2022-4536
5.3 MEDIUM

The IP Vault – WP Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 1.1. This is due …

Aug 31, 2024
CVE-2022-4100
5.3 MEDIUM

The WP Cerber Security plugin for WordPress is vulnerable to IP Protection bypass in versions up to, and including 9.4 due to the plugin improperly …

Aug 31, 2024
CVE-2024-8276
6.4 MEDIUM

The WPZOOM Portfolio Lite – Filterable Portfolio Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ attribute within the 'wp:wpzoom-blocks' Gutenberg …

Aug 31, 2024
CVE-2024-39579
6.7 MEDIUM

Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contains an incorrect privilege assignment vulnerability. A local high privileged attacker could potentially exploit this vulnerability to gain …

Aug 31, 2024
CVE-2024-39578
6.3 MEDIUM

Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.1 contains a UNIX symbolic link (symlink) following vulnerability. A local high privileged attacker could potentially exploit this vulnerability, …

Aug 31, 2024
CVE-2024-44945
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink: Initialise extack before use in ACKs Add missing extack initialisation when ACKing BATCH_BEGIN …

Aug 31, 2024
CVE-2024-5212
6.1 MEDIUM

The tagDiv Composer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘envato_code[]’ parameter in all versions up to, and including, 5.0 due …

Aug 31, 2024
CVE-2024-3886
6.1 MEDIUM

The tagDiv Composer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘envato_code[]’ parameter in all versions up to, and including, 5.0 due …

Aug 31, 2024
CVE-2024-7435
8.8 HIGH

The Attire theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.0.6 via deserialization of untrusted input. This …

Aug 31, 2024
CVE-2024-39747
8.1 HIGH

IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 uses default credentials for potentially critical functionality.

Aug 31, 2024
CVE-2024-8006
4.4 MEDIUM

Remote packet capture support is disabled by default in libpcap. When a user builds libpcap with remote packet capture support enabled, one of the functions …

Aug 31, 2024
CVE-2024-45304
5.3 MEDIUM

Cairo-Contracts are OpenZeppelin Contracts written in Cairo for Starknet, a decentralized ZK Rollup. This vulnerability can lead to unauthorized ownership transfer, contrary to the original …

Aug 31, 2024
CVE-2023-7256
4.4 MEDIUM

In affected libpcap versions during the setup of a remote packet capture the internal function sock_initaddress() calls getaddrinfo() and possibly freeaddrinfo(), but does not clearly …

Aug 31, 2024
CVE-2024-6586
7.3 HIGH

Lightdash version 0.1024.6 allows users with the necessary permissions, such as Administrator or Editor, to create and share dashboards. A dashboard that contains HTML elements …

Aug 30, 2024
CVE-2024-6585
5.4 MEDIUM

Multiple stored cross-site scripting (“XSS”) vulnerabilities in the markdown dashboard and dashboard comment functionality of Lightdash version 0.1024.6 allows remote authenticated threat actors to inject …

Aug 30, 2024
CVE-2024-8348
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Computer Laboratory Management System 1.0. Affected by this issue is the function delete_category …

Aug 30, 2024
CVE-2024-8347
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Computer Laboratory Management System 1.0. Affected by this vulnerability is the function delete_record of the file …

Aug 30, 2024
CVE-2024-8285
5.9 MEDIUM

A flaw was found in Kroxylicious. When establishing the connection with the upstream Kafka server using a TLS secured connection, Kroxylicious fails to properly verify …

Aug 30, 2024
CVE-2024-44684
6.1 MEDIUM

TpMeCMS 1.3.3.2 is vulnerable to Cross Site Scripting (XSS) in /h.php/page?ref=addtabs via the "Title," "Images," and "Content" fields.

Aug 30, 2024
CVE-2024-44683
6.1 MEDIUM

Seacms v13 is vulnerable to Cross Site Scripting (XSS) via admin-video.php.

Aug 30, 2024
CVE-2024-44682
6.1 MEDIUM

ShopXO 6.2 is vulnerable to Cross Site Scripting (XSS) in the backend that allows attackers to execute code by changing POST parameters.

Aug 30, 2024
CVE-2024-8346
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Computer Laboratory Management System 1.0. Affected is the function update_settings_info of the file /classes/SystemSettings.php?f=update_settings. The …

Aug 30, 2024
CVE-2024-42379

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 30, 2024
CVE-2024-38868
7.6 HIGH

Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability while isolating the devices.This issue affects Endpoint Central: before 11.3.2406.08 and before 11.3.2400.15

Aug 30, 2024
CVE-2024-21658
4.3 MEDIUM

discourse-calendar is a discourse plugin which adds the ability to create a dynamic calendar in the first post of a topic. The limit on region …

Aug 30, 2024
CVE-2024-8345
6.3 MEDIUM

A vulnerability was found in SourceCodester Music Gallery Site 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Aug 30, 2024
CVE-2024-8344
6.3 MEDIUM

A vulnerability has been found in Campcodes Supplier Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Aug 30, 2024
CVE-2024-8235
6.2 MEDIUM

A flaw was found in libvirt. A refactor of the code fetching the list of interfaces for multiple APIs introduced a corner case on platforms …

Aug 30, 2024
CVE-2024-6204
8.3 HIGH

Zohocorp ManageEngine Exchange Reporter Plus versions before 5715 are vulnerable to SQL Injection in the reports module.

Aug 30, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.