CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-43891
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tracing: Have format file honor EVENT_FILE_FL_FREED When eventfs was introduced, special care had to be …

Aug 26, 2024
CVE-2024-43890
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tracing: Fix overflow in get_free_elt() "tracing_map->next_elt" in get_free_elt() is at risk of overflowing. Once it …

Aug 26, 2024
CVE-2024-43889
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: padata: Fix possible divide-by-0 panic in padata_mt_helper() We are hit with a not easily reproducible …

Aug 26, 2024
CVE-2024-43888
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: mm: list_lru: fix UAF for memory cgroup The mem_cgroup_from_slab_obj() is supposed to be called under …

Aug 26, 2024
CVE-2024-43887
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/tcp: Disable TCP-AO static key after RCU grace period The lifetime of TCP-AO static_key is …

Aug 26, 2024
CVE-2024-43886
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Add null check in resource_log_pipe_topology_update [WHY] When switching from "Extend" to "Second Display Only" …

Aug 26, 2024
CVE-2024-43885

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 26, 2024
CVE-2024-8161
9.8 CRITICAL

SQL injection vulnerability in ATISolutions CIGES affecting versions lower than 2.15.5. This vulnerability allows a remote attacker to send a specially crafted SQL query to …

Aug 26, 2024
CVE-2024-43444
8.2 HIGH

Passwords of agents and customers are displayed in plain text in the OTRS admin log module if certain configurations regarding the authentication sources match and …

Aug 26, 2024
CVE-2024-43443
4.9 MEDIUM

Improper Neutralization of Input done by an attacker with admin privileges ('Cross-site Scripting') in Process Management modules of OTRS and ((OTRS)) Community Edition allows Cross-Site …

Aug 26, 2024
CVE-2024-43442
4.9 MEDIUM

Improper Neutralization of Input done by an attacker with admin privileges ('Cross-site Scripting') in OTRS (System Configuration modules) and ((OTRS)) Community Edition allows Cross-Site Scripting …

Aug 26, 2024
CVE-2024-43884
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: Add error handling to pair_device() hci_conn_params_add() never checks for a NULL value and …

Aug 26, 2024
CVE-2024-45256
9.8 CRITICAL

An arbitrary file write issue in the exfiltration endpoint in BYOB (Build Your Own Botnet) 2.0 allows attackers to overwrite SQLite databases and bypass authentication …

Aug 26, 2024
CVE-2024-45241
7.5 HIGH

A traversal vulnerability in GeneralDocs.aspx in CentralSquare CryWolf (False Alarm Management) through 2024-08-09 allows unauthenticated attackers to read files outside of the working web directory …

Aug 26, 2024
CVE-2024-7313
6.1 MEDIUM

The Shield Security WordPress plugin before 20.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Aug 26, 2024
CVE-2024-6879
4.7 MEDIUM

The Quiz and Survey Master (QSM) WordPress plugin before 9.1.1 fails to validate and escape certain Quiz fields before displaying them on a page or …

Aug 26, 2024
CVE-2024-41996
7.5 HIGH

Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the …

Aug 26, 2024
CVE-2024-8073
9.8 CRITICAL

Improper Input Validation vulnerability in Hillstone Networks Hillstone Networks Web Application Firewall on 5.5R6 allows Command Injection.This issue affects Hillstone Networks Web Application Firewall: from …

Aug 26, 2024
CVE-2024-8155
4.7 MEDIUM

A vulnerability classified as critical was found in ContiNew Admin 3.2.0. Affected by this vulnerability is the function top.continew.starter.extension.crud.controller.BaseController#tree of the file /api/system/dept/tree?sort=parentId%2Casc&sort=sort%2Casc. The manipulation …

Aug 25, 2024
CVE-2024-8154
3.5 LOW

A vulnerability classified as problematic has been found in SourceCodester QR Code Bookmark System 1.0. Affected is an unknown function of the file /endpoint/update-bookmark.php of …

Aug 25, 2024
CVE-2024-8153
3.5 LOW

A vulnerability was found in SourceCodester QR Code Bookmark System 1.0. It has been rated as problematic. This issue affects some unknown processing of the …

Aug 25, 2024
CVE-2024-8152
3.5 LOW

A vulnerability was found in SourceCodester QR Code Bookmark System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file …

Aug 25, 2024
CVE-2024-8158
6.5 MEDIUM

A bug in the 9p authentication implementation within lib9p allows an attacker with an existing valid user within the configured auth server to impersonate any …

Aug 25, 2024
CVE-2024-8151
3.5 LOW

A vulnerability was found in SourceCodester Interactive Map with Marker 1.0. It has been classified as problematic. This affects an unknown part of the file …

Aug 25, 2024
CVE-2024-8150
4.7 MEDIUM

A vulnerability was found in ContiNew Admin 3.2.0 and classified as critical. Affected by this issue is the function top.continew.starter.extension.crud.controller.BaseController#page of the file /api/system/user?deptId=1&page=1&size=10. The …

Aug 25, 2024
CVE-2024-45258
9.8 CRITICAL

The req package before 3.43.4 for Go may send an unintended request when a malformed URL is provided, because cleanHost in http.go intentionally uses a …

Aug 25, 2024
CVE-2023-48957
5.3 MEDIUM

PureVPN Linux client 2.0.2-Productions fails to properly handle DNS queries, allowing them to bypass the VPN tunnel and be sent directly to the ISP or …

Aug 25, 2024
CVE-2024-8011
5.5 MEDIUM

Logitech Options+ on MacOS prior 1.72 allows a local attacker to inject dynamic library within Options+ runtime and abuse permissions granted by the user to …

Aug 25, 2024
CVE-2024-8147
6.3 MEDIUM

A vulnerability was found in code-projects Pharmacy Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /index.php?action=editPharmacist. The …

Aug 25, 2024
CVE-2024-8146
6.3 MEDIUM

A vulnerability has been found in code-projects Pharmacy Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /index.php?action=editSalesman. The …

Aug 25, 2024
CVE-2024-42340
8.3 HIGH

CyberArk - CWE-602: Client-Side Enforcement of Server-Side Security

Aug 25, 2024
CVE-2024-42339
4.3 MEDIUM

CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Aug 25, 2024
CVE-2024-42338
4.3 MEDIUM

CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Aug 25, 2024
CVE-2024-42337
4.3 MEDIUM

CyberArk - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Aug 25, 2024
CVE-2024-8145
2.4 LOW

A vulnerability, which was classified as problematic, has been found in ClassCMS 4.8. Affected by this issue is some unknown functionality of the file /index.php/admin …

Aug 25, 2024
CVE-2024-8144
3.5 LOW

A vulnerability classified as problematic was found in ClassCMS 4.8. Affected by this vulnerability is an unknown functionality of the file /index.php/admin of the component …

Aug 25, 2024
CVE-2024-8142
3.5 LOW

A vulnerability was found in SourceCodester Daily Calories Monitoring Tool 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file …

Aug 25, 2024
CVE-2024-8141
3.5 LOW

A vulnerability was found in SourceCodester Daily Calories Monitoring Tool 1.0. It has been classified as problematic. This affects an unknown part of the file …

Aug 25, 2024
CVE-2024-8140
3.5 LOW

A vulnerability was found in SourceCodester Task Progress Tracker 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file …

Aug 25, 2024
CVE-2024-45244
5.3 MEDIUM

Hyperledger Fabric through 3.0.0 and 2.5.x through 2.5.9 do not verify that a request has a timestamp within the expected time window.

Aug 25, 2024
CVE-2024-8139
6.3 MEDIUM

A vulnerability has been found in itsourcecode E-Commerce Website 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file …

Aug 25, 2024
CVE-2024-8138
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in code-projects Pharmacy Management System 1.0. Affected is the function editManager of the file /index.php?action=editManager of …

Aug 25, 2024
CVE-2024-8137
3.5 LOW

A vulnerability has been found in SourceCodester Record Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file search_user.php. The …

Aug 24, 2024
CVE-2024-45240
7.4 HIGH

The TikTok (aka com.zhiliaoapp.musically) application before 34.5.5 for Android allows the takeover of Lynxview JavaScript interfaces via deeplink traversal (in the application's exposed WebView). (On …

Aug 24, 2024
CVE-2024-45239
7.5 HIGH

An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) …

Aug 24, 2024
CVE-2024-45238
7.5 HIGH

An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) …

Aug 24, 2024
CVE-2024-45237
9.8 CRITICAL

An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) …

Aug 24, 2024
CVE-2024-45236
7.5 HIGH

An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) …

Aug 24, 2024
CVE-2024-45235
7.5 HIGH

An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) …

Aug 24, 2024
CVE-2024-45234
7.5 HIGH

An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) …

Aug 24, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.