CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-7552
6.3 MEDIUM

A vulnerability was found in DataGear up to 5.0.0. It has been declared as critical. Affected by this vulnerability is the function evaluateVariableExpression of the …

Aug 6, 2024
CVE-2024-36424
5.5 MEDIUM

K7RKScan.sys in K7 Ultimate Security before 17.0.2019 allows local users to cause a denial of service (BSOD) because of a NULL pointer dereference.

Aug 6, 2024
CVE-2024-41913
8.8 HIGH

A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware flaw does not properly sanitize User input.

Aug 6, 2024
CVE-2024-41911
5.4 MEDIUM

A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The flaw does not properly neutralize input during a …

Aug 6, 2024
CVE-2024-41910
6.1 MEDIUM

A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware contained multiple XSS vulnerabilities in the version …

Aug 6, 2024
CVE-2024-41226
7.8 HIGH

A CSV injection vulnerability in Automation Anywhere Automation 360 version 21094 allows attackers to execute arbitrary code via a crafted payload. NOTE: Automation Anywhere disputes …

Aug 6, 2024
CVE-2024-40101
6.1 MEDIUM

A Reflected Cross-site scripting (XSS) vulnerability exists in '/search' in microweber 2.0.15 and earlier allowing unauthenticated remote attackers to inject arbitrary web script or HTML …

Aug 6, 2024
CVE-2024-33897
9.1 CRITICAL

A compromised HMS Networks Cosy+ device could be used to request a Certificate Signing Request from Talk2m for another device, resulting in an availability issue. …

Aug 6, 2024
CVE-2024-30170
9.1 CRITICAL

PrivX before 34.0 allows data exfiltration and denial of service via the REST API. This is fixed in minor versions 33.1, 32.3, 31.3, and later, …

Aug 6, 2024
CVE-2023-40819
6.1 MEDIUM

ID4Portais in version < V.2022.837.002a returns message parameter unsanitized in the response, resulting in a HTML Injection vulnerability.

Aug 6, 2024
CVE-2024-7551
2.7 LOW

A vulnerability was found in juzaweb CMS up to 3.4.2. It has been classified as problematic. Affected is an unknown function of the file /admin-cp/theme/editor/default …

Aug 6, 2024
CVE-2024-7531
6.5 MEDIUM

Calling `PK11_Encrypt()` in NSS using CKM_CHACHA20 and the same buffer for input and output can result in plaintext on an Intel Sandy Bridge processor. In …

Aug 6, 2024
CVE-2024-7530
8.8 HIGH

Incorrect garbage collection interaction could have led to a use-after-free. This vulnerability affects Firefox < 129.

Aug 6, 2024
CVE-2024-7529
6.5 MEDIUM

The date picker could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. This vulnerability …

Aug 6, 2024
CVE-2024-7528
8.8 HIGH

Incorrect garbage collection interaction in IndexedDB could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < …

Aug 6, 2024
CVE-2024-7527
8.8 HIGH

Unexpected marking work at the start of sweeping could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox …

Aug 6, 2024
CVE-2024-7526
6.5 MEDIUM

ANGLE failed to initialize parameters which lead to reading from uninitialized memory. This could be leveraged to leak sensitive data from memory. This vulnerability affects …

Aug 6, 2024
CVE-2024-7525
8.1 HIGH

It was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and modify the response body …

Aug 6, 2024
CVE-2024-7524
6.1 MEDIUM

Firefox adds web-compatibility shims in place of some tracking scripts blocked by Enhanced Tracking Protection. On a site protected by Content Security Policy in "strict-dynamic" …

Aug 6, 2024
CVE-2024-7523
8.1 HIGH

A select option could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. *This issue …

Aug 6, 2024
CVE-2024-7522
8.8 HIGH

Editor code failed to check an attribute value. This could have led to an out-of-bounds read. This vulnerability affects Firefox < 129, Firefox ESR < …

Aug 6, 2024
CVE-2024-7521
8.8 HIGH

Incomplete WebAssembly exception handing could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird …

Aug 6, 2024
CVE-2024-7520
8.8 HIGH

A type confusion bug in WebAssembly could be leveraged by an attacker to potentially achieve code execution. This vulnerability affects Firefox < 129, Firefox ESR …

Aug 6, 2024
CVE-2024-7519
9.6 CRITICAL

Insufficient checks when processing graphics shared memory could have led to memory corruption. This could be leveraged by an attacker to perform a sandbox escape. …

Aug 6, 2024
CVE-2024-7518
6.5 MEDIUM

Select options could obscure the fullscreen notification dialog. This could be used by a malicious site to perform a spoofing attack. This vulnerability affects Firefox …

Aug 6, 2024
CVE-2024-6359
6.4 MEDIUM

Privilege escalation vulnerability identified in OpenText ArcSight Intelligence.

Aug 6, 2024
CVE-2024-6358
6.3 MEDIUM

Incorrect Authorization vulnerability identified in OpenText ArcSight Intelligence.

Aug 6, 2024
CVE-2024-6357
6.3 MEDIUM

Insecure Direct Object Reference vulnerability identified in OpenText ArcSight Intelligence.

Aug 6, 2024
CVE-2024-43114
7.5 HIGH

In JetBrains TeamCity before 2024.07.1 possible privilege escalation due to incorrect directory permissions

Aug 6, 2024
CVE-2024-33994
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a …

Aug 6, 2024
CVE-2024-33993
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a …

Aug 6, 2024
CVE-2024-33992
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to …

Aug 6, 2024
CVE-2024-33991
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to …

Aug 6, 2024
CVE-2024-33990
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted javascript payload …

Aug 6, 2024
CVE-2024-33989
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted javascript payload …

Aug 6, 2024
CVE-2024-33988
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL …

Aug 6, 2024
CVE-2024-33987
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL …

Aug 6, 2024
CVE-2024-33986
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL …

Aug 6, 2024
CVE-2024-33985
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL …

Aug 6, 2024
CVE-2024-33984
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL …

Aug 6, 2024
CVE-2024-33983
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL …

Aug 6, 2024
CVE-2024-33982
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL …

Aug 6, 2024
CVE-2024-33974
9.8 CRITICAL

SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted …

Aug 6, 2024
CVE-2024-33973
9.8 CRITICAL

SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted …

Aug 6, 2024
CVE-2024-33972
9.8 CRITICAL

SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted …

Aug 6, 2024
CVE-2024-33971
9.8 CRITICAL

SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted …

Aug 6, 2024
CVE-2024-33970
9.8 CRITICAL

SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted …

Aug 6, 2024
CVE-2024-33969
9.8 CRITICAL

SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted …

Aug 6, 2024
CVE-2024-33968
9.8 CRITICAL

SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted …

Aug 6, 2024
CVE-2024-33967
9.8 CRITICAL

SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted …

Aug 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.