CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-6984
8.8 HIGH

An issue was discovered in Juju that resulted in the leak of the sensitive context ID, which allows a local unprivileged attacker to access other …

Jul 29, 2024
CVE-2024-6576
7.3 HIGH

Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Privilege Escalation.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.12, from 2023.1.0 before …

Jul 29, 2024
CVE-2024-41022
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix signedness bug in sdma_v4_0_process_trap_irq() The "instance" variable needs to be signed for the …

Jul 29, 2024
CVE-2024-41021
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: s390/mm: Fix VM_FAULT_HWPOISON handling in do_exception() There is no support for HWPOISON, MEMORY_FAILURE, or ARCH_HAS_COPY_MC …

Jul 29, 2024
CVE-2024-41020
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: filelock: Fix fcntl/close race recovery compat path When I wrote commit 3cad1bc01041 ("filelock: Remove locks …

Jul 29, 2024
CVE-2024-40576
4.7 MEDIUM

Cross Site Scripting vulnerability in Best House Rental Management System 1.0 allows a remote attacker to execute arbitrary code via the "House No" and "Description" …

Jul 29, 2024
CVE-2024-7200
3.5 LOW

A vulnerability, which was classified as problematic, has been found in SourceCodester Complaints Report Management System 1.0. This issue affects some unknown processing of the …

Jul 29, 2024
CVE-2024-7199
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Complaints Report Management System 1.0. This vulnerability affects unknown code of the file /admin/manage_user.php. The manipulation …

Jul 29, 2024
CVE-2024-6881
5.4 MEDIUM

Stored XSS in M-Files Hubshare versions before 5.0.6.0 allows an authenticated attacker to execute arbitrary JavaScript in user's browser session

Jul 29, 2024
CVE-2024-6124
5.4 MEDIUM

Reflected XSS in M-Files Hubshare before version 5.0.6.0 allows an attacker to execute arbitrary JavaScript code in the context of the victim's browser session

Jul 29, 2024
CVE-2024-7198
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Complaints Report Management System 1.0. This affects an unknown part of the file /admin/manage_station.php. The …

Jul 29, 2024
CVE-2024-7197
6.3 MEDIUM

A vulnerability was found in SourceCodester Complaints Report Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

Jul 29, 2024
CVE-2024-7196
7.3 HIGH

A vulnerability was found in SourceCodester Complaints Report Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Jul 29, 2024
CVE-2024-7195
6.3 MEDIUM

A vulnerability was found in itsourcecode Society Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/check_admin.php. …

Jul 29, 2024
CVE-2024-6761

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 29, 2024
CVE-2024-4848

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 29, 2024
CVE-2024-7194
6.3 MEDIUM

A vulnerability was found in itsourcecode Society Management System 1.0 and classified as critical. This issue affects some unknown processing of the file check_student.php. The …

Jul 29, 2024
CVE-2024-7193
5.3 MEDIUM

A vulnerability has been found in Mp3tag up to 3.26d and classified as problematic. This vulnerability affects unknown code in the library tak_deco_lib.dll of the …

Jul 29, 2024
CVE-2024-7192
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in itsourcecode Society Management System 1.0. This affects an unknown part of the file /admin/student.php. The …

Jul 29, 2024
CVE-2024-7191
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in itsourcecode Society Management System 1.0. Affected by this issue is some unknown functionality of …

Jul 29, 2024
CVE-2024-41881
8.8 HIGH

SDoP versions prior to 1.11 fails to handle appropriately some parameters inside the input data, resulting in a stack-based buffer overflow vulnerability. When a user …

Jul 29, 2024
CVE-2024-41726
7.5 HIGH

Path traversal vulnerability exists in SKYSEA Client View Ver.3.013.00 to Ver.19.210.04e. If this vulnerability is exploited, an arbitrary executable file may be executed by a …

Jul 29, 2024
CVE-2024-41143
7.8 HIGH

Origin validation error vulnerability exists in SKYSEA Client View Ver.3.013.00 to Ver.19.210.04e. If this vulnerability is exploited, an arbitrary process may be executed with SYSTEM …

Jul 29, 2024
CVE-2024-41139
7.8 HIGH

Incorrect privilege assignment vulnerability exists in SKYSEA Client View Ver.6.010.06 to Ver.19.210.04e. If a user who can log in to the PC where the product's …

Jul 29, 2024
CVE-2024-7190
6.3 MEDIUM

A vulnerability classified as critical was found in itsourcecode Society Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/get_price.php. …

Jul 29, 2024
CVE-2024-7189
6.3 MEDIUM

A vulnerability classified as critical has been found in itsourcecode Online Food Ordering System 1.0. Affected is an unknown function of the file editproduct.php. The …

Jul 29, 2024
CVE-2024-7188
7.3 HIGH

A vulnerability was found in Bylancer Quicklancer 2.4. It has been rated as critical. This issue affects some unknown processing of the file /listing of …

Jul 29, 2024
CVE-2024-7187
8.8 HIGH

A vulnerability was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. It has been declared as critical. This vulnerability affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi. The …

Jul 29, 2024
CVE-2024-41091
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: tun: add missing verification for short frame The cited commit missed to check against the …

Jul 29, 2024
CVE-2024-41090
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: tap: add missing verification for short frame The cited commit missed to check against the …

Jul 29, 2024
CVE-2024-41019
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Validate ff offset This adds sanity checks for ff offset. There is a check …

Jul 29, 2024
CVE-2024-41018
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Add a check for attr_names and oatbl Added out-of-bound checking for *ane (ATTR_NAME_ENTRY).

Jul 29, 2024
CVE-2024-41017
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: jfs: don't walk off the end of ealist Add a check before visiting the members …

Jul 29, 2024
CVE-2024-41016
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ocfs2: strict bound check before memcmp in ocfs2_xattr_find_entry() xattr in ocfs2 maybe 'non-indexed', which saved …

Jul 29, 2024
CVE-2024-41015
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ocfs2: add bounds checking to ocfs2_check_dir_entry() This adds sanity checks for ocfs2_dir_entry to make sure …

Jul 29, 2024
CVE-2024-41014
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: xfs: add bounds checking to xlog_recover_process_data There is a lack of verification of the space …

Jul 29, 2024
CVE-2024-41013
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: xfs: don't walk off the end of a directory data block This adds sanity checks …

Jul 29, 2024
CVE-2024-7186
8.8 HIGH

A vulnerability was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. It has been classified as critical. This affects the function setWiFiAclAddConfig of the file /cgi-bin/cstecgi.cgi. The manipulation …

Jul 29, 2024
CVE-2024-7185
8.8 HIGH

A vulnerability was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102 and classified as critical. Affected by this issue is the function setWebWlanIdx of the file /cgi-bin/cstecgi.cgi. The …

Jul 29, 2024
CVE-2024-6487
5.9 MEDIUM

The Inline Related Posts WordPress plugin before 3.8.0 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Jul 29, 2024
CVE-2024-6366
9.1 CRITICAL

The User Profile Builder WordPress plugin before 3.11.8 does not have proper authorisation, allowing unauthenticated users to upload media files via the async upload functionality …

Jul 29, 2024
CVE-2024-6362
4.6 MEDIUM

The Ultimate Blocks WordPress plugin before 3.2.0 does not validate and escape some of its post-grid block attributes before outputting them back in a page/post …

Jul 29, 2024
CVE-2024-5883
4.7 MEDIUM

The Ultimate Classified Listings WordPress plugin before 1.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Jul 29, 2024
CVE-2024-5882
7.5 HIGH

The Ultimate Classified Listings WordPress plugin before 1.3 does not validate the `ucl_page` and `layout` parameters allowing unauthenticated users to access PHP files on the …

Jul 29, 2024
CVE-2024-5285
5.5 MEDIUM

The wp-affiliate-platform WordPress plugin before 6.5.2 does not have CSRF check in place when deleting affiliates, which could allow attackers to make a logged in …

Jul 29, 2024
CVE-2024-4483
5.4 MEDIUM

The Email Encoder WordPress plugin before 2.2.2 does not escape the WP_Email_Encoder_Bundle_options[protection_text] parameter before outputting it back in an attribute in an admin page, leading …

Jul 29, 2024
CVE-2024-41637
8.3 HIGH

RaspAP before 3.1.5 allows an attacker to escalate privileges: the www-data user has write access to the restapi.service file and also possesses Sudo privileges to …

Jul 29, 2024
CVE-2024-37381
8.0 HIGH

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2024 flat allows an authenticated attacker within the same network to execute arbitrary code.

Jul 29, 2024
CVE-2024-7184
8.8 HIGH

A vulnerability has been found in TOTOLINK A3600R 4.1.2cu.5182_B20201102 and classified as critical. Affected by this vulnerability is the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi. …

Jul 29, 2024
CVE-2024-7183
8.8 HIGH

A vulnerability, which was classified as critical, was found in TOTOLINK A3600R 4.1.2cu.5182_B20201102. Affected is the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. The manipulation of …

Jul 29, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.