CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-1577
7.8 HIGH

A path hijacking vulnerability was reported in Lenovo Driver Manager prior to version 3.1.1307.1308 that could allow a local user to execute code with elevated …

Jul 31, 2024
CVE-2022-4003
2.7 LOW

A denial-of-service vulnerability could allow an authenticated user to trigger an internal service restart via a specially crafted API request.

Jul 31, 2024
CVE-2022-4002
7.2 HIGH

A command injection vulnerability could allow an authenticated user to execute operating system commands as root via a specially crafted API request.

Jul 31, 2024
CVE-2022-4001
7.3 HIGH

An authentication bypass vulnerability could allow an attacker to access API functions without authentication.

Jul 31, 2024
CVE-2019-6198
7.8 HIGH

A vulnerability was reported in Lenovo PC Manager prior to version 2.8.90.11211 that could allow a local attacker to escalate privileges.

Jul 31, 2024
CVE-2019-6197
7.8 HIGH

A vulnerability was reported in Lenovo PC Manager prior to version 2.8.90.11211 that could allow a local attacker to escalate privileges.

Jul 31, 2024
CVE-2017-3772
5.5 MEDIUM

A vulnerability was reported in Lenovo PC Manager versions prior to 2.6.40.3154 that could allow an attacker to cause a system reboot.

Jul 31, 2024
CVE-2024-7325
7.8 HIGH

A vulnerability was found in IObit Driver Booster 11.0.0.0. It has been rated as critical. Affected by this issue is some unknown functionality in the …

Jul 31, 2024
CVE-2024-41955
5.2 MEDIUM

Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mobile. An open redirect vulnerability exist in MobSF …

Jul 31, 2024
CVE-2024-41954
5.3 MEDIUM

FOG is a cloning/imaging/rescue suite/inventory management system. The application stores plaintext service account credentials in the "/opt/fog/.fogsettings" file. This file is by default readable by …

Jul 31, 2024
CVE-2024-41951
4.4 MEDIUM

Pheonix App is a Python application designed to streamline various tasks, from managing files to playing mini-games. The issue is that the map of encoding/decoding …

Jul 31, 2024
CVE-2024-41660
9.8 CRITICAL

slpd-lite is a unicast SLP UDP server. Any OpenBMC system that includes the slpd-lite package is impacted. Installing this package is the default when building …

Jul 31, 2024
CVE-2024-41630
7.6 HIGH

Stack-based buffer overflow vulnerability in Tenda AC18 V15.03.3.10_EN allows a remote attacker to execute arbitrary code via the ssid parameter at ip/goform/fast_setting_wifi_set.

Jul 31, 2024
CVE-2024-41108
7.5 HIGH

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. The hostinfo page has missing/improper access control since only the host's mac address is required to …

Jul 31, 2024
CVE-2024-40645
8.8 HIGH

FOG is a cloning/imaging/rescue suite/inventory management system. An improperly restricted file upload feature allows authenticated users to execute arbitrary code on the fogproject server. The …

Jul 31, 2024
CVE-2023-28149
6.1 MEDIUM

An issue was discovered in the IhisiServiceSmm module in Insyde InsydeH2O with kernel 5.2 before 05.28.42, 5.3 before 05.37.42, 5.4 before 05.45.39, 5.5 before 05.53.39, …

Jul 31, 2024
CVE-2024-7324
7.8 HIGH

A vulnerability was found in IObit iTop Data Recovery Pro 4.4.0.687. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Jul 31, 2024
CVE-2024-23444
4.9 MEDIUM

It was discovered by Elastic engineering that when elasticsearch-certutil CLI tool is used with the csr option in order to create a new Certificate Signing …

Jul 31, 2024
CVE-2024-6978
5.6 MEDIUM

Cato Networks Windows SDP Client Local root certificates can be installed by low-privileged users.This issue affects SDP Client: before 5.10.28.

Jul 31, 2024
CVE-2024-6977
6.5 MEDIUM

A vulnerability in Cato Networks SDP Client on Windows allows the insertion of sensitive information into the log file, which can lead to an account …

Jul 31, 2024
CVE-2024-6975
8.8 HIGH

Cato Networks Windows SDP Client Local Privilege Escalation via openssl configuration file. This issue affects SDP Client before 5.10.34.

Jul 31, 2024
CVE-2024-6974
8.8 HIGH

Cato Networks Windows SDP Client Local Privilege Escalation via self-upgradeThis issue affects SDP Client: before 5.10.34.

Jul 31, 2024
CVE-2024-6973
7.5 HIGH

Remote Code Execution in Cato Windows SDP client via crafted URLs. This issue affects Windows SDP Client before 5.10.34.

Jul 31, 2024
CVE-2024-41953
4.3 MEDIUM

Zitadel is an open source identity management system. ZITADEL uses HTML for emails and renders certain information such as usernames dynamically. That information can be …

Jul 31, 2024
CVE-2024-41952
5.3 MEDIUM

Zitadel is an open source identity management system. ZITADEL administrators can enable a setting called "Ignoring unknown usernames" which helps mitigate attacks that try to …

Jul 31, 2024
CVE-2024-41950
7.5 HIGH

Haystack is an end-to-end LLM framework that allows you to build applications powered by LLMs, Transformer models, vector search and more. Haystack clients that let …

Jul 31, 2024
CVE-2024-41947
9.0 CRITICAL

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. By creating a conflict when another user with …

Jul 31, 2024
CVE-2024-39694
4.7 MEDIUM

Duende IdentityServer is an OpenID Connect and OAuth 2.x framework for ASP.NET Core. It is possible for an attacker to craft malicious Urls that certain …

Jul 31, 2024
CVE-2024-39318
5.4 MEDIUM

The Ibexa Admin UI Bundle contains all the necessary parts to run the Ibexa DXP Back Office interface. The file upload widget is vulnerable to …

Jul 31, 2024
CVE-2024-37901
9.9 CRITICAL

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit right on any page …

Jul 31, 2024
CVE-2024-37900
6.4 MEDIUM

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When uploading an attachment with a malicious filename, …

Jul 31, 2024
CVE-2024-37898
4.3 MEDIUM

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When a user has view but not edit …

Jul 31, 2024
CVE-2024-7340
8.8 HIGH

The Weave server API allows remote users to fetch files from a specific directory, but due to a lack of input validation, it is possible …

Jul 31, 2024
CVE-2024-3083
8.3 HIGH

A “CWE-352: Cross-Site Request Forgery (CSRF)” can be exploited by remote attackers to perform state-changing operations with administrative privileges by luring authenticated victims into visiting …

Jul 31, 2024
CVE-2024-3082
4.2 MEDIUM

A “CWE-256: Plaintext Storage of a Password” affecting the administrative account allows an attacker with physical access to the machine to retrieve the password in …

Jul 31, 2024
CVE-2024-37135
3.3 LOW

DM5500 5.16.0.0, contains an information disclosure vulnerability. A local attacker with high privileges could potentially exploit this vulnerability, leading to the disclosure of certain user …

Jul 31, 2024
CVE-2024-31203
3.3 LOW

A “CWE-121: Stack-based Buffer Overflow” in the wd210std.dll dynamic library packaged with the ThermoscanIP installer allows a local attacker to possibly trigger a Denial-of-Service (DoS) …

Jul 31, 2024
CVE-2024-31202
7.8 HIGH

A “CWE-732: Incorrect Permission Assignment for Critical Resource” in the ThermoscanIP installation folder allows a local attacker to perform a Local Privilege Escalation.

Jul 31, 2024
CVE-2024-31201
6.5 MEDIUM

A “CWE-428: Unquoted Search Path or Element” affects the ThermoscanIP_Scrutation service. Such misconfiguration could be abused in scenarios where incorrect permissions were assigned to the …

Jul 31, 2024
CVE-2024-31200
4.2 MEDIUM

A “CWE-201: Insertion of Sensitive Information Into Sent Data” affecting the administrative account allows an attacker with physical access to the machine to retrieve the …

Jul 31, 2024
CVE-2024-31199
8.8 HIGH

A “CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')” allows malicious users to permanently inject arbitrary Javascript code.

Jul 31, 2024
CVE-2024-6208
6.4 MEDIUM

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_all_packages' shortcode in all versions up to, and including, 3.2.97 …

Jul 31, 2024
CVE-2024-39379
5.5 MEDIUM

Acrobat for Edge versions 126.0.2592.81 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Jul 31, 2024
CVE-2024-7321
4.3 MEDIUM

A vulnerability classified as problematic was found in itsourcecode Online Blood Bank Management System 1.0. This vulnerability affects unknown code of the file signup.php of …

Jul 31, 2024
CVE-2024-7320
7.3 HIGH

A vulnerability classified as critical has been found in itsourcecode Online Blood Bank Management System 1.0. This affects an unknown part of the file /admin/index.php …

Jul 31, 2024
CVE-2024-7311
7.3 HIGH

A vulnerability was found in code-projects Online Bus Reservation Site 1.0. It has been rated as critical. This issue affects some unknown processing of the …

Jul 31, 2024
CVE-2024-7135
6.5 MEDIUM

The Tainacan plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_file' function in all versions …

Jul 31, 2024
CVE-2024-6725
4.9 MEDIUM

The Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

Jul 31, 2024
CVE-2024-7310
3.5 LOW

A vulnerability was found in SourceCodester Record Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file sort_user.php. …

Jul 31, 2024
CVE-2024-7309
3.5 LOW

A vulnerability was found in SourceCodester Record Management System 1.0. It has been classified as problematic. This affects an unknown part of the file entry.php. …

Jul 31, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.