CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-6558
6.3 MEDIUM

HMS Industrial Networks Anybus-CompactCom 30 products are vulnerable to a XSS attack caused by the lack of input sanitation checks. As a consequence, it is …

Jul 25, 2024
CVE-2024-41808
8.8 HIGH

The OpenObserve open-source observability platform provides the ability to filter logs in a dashboard by the values uploaded in a given log. However, all versions …

Jul 25, 2024
CVE-2024-40324
5.4 MEDIUM

A CRLF injection vulnerability in E-Staff v5.1 allows attackers to insert Carriage Return (CR) and Line Feed (LF) characters into input fields, leading to HTTP …

Jul 25, 2024
CVE-2024-38289
9.8 CRITICAL

A boolean-based SQL injection issue in the Virtual Meeting Password (VMP) endpoint in R-HUB TurboMeeting through 8.x allows unauthenticated remote attackers to extract hashed passwords …

Jul 25, 2024
CVE-2024-38288
7.2 HIGH

A command-injection issue in the Certificate Signing Request (CSR) functionality in R-HUB TurboMeeting through 8.x allows authenticated attackers with administrator privileges to execute arbitrary commands …

Jul 25, 2024
CVE-2024-38287
9.8 CRITICAL

The password-reset mechanism in the Forgot Password functionality in R-HUB TurboMeeting through 8.x allows unauthenticated remote attackers to force the application into resetting the administrator's …

Jul 25, 2024
CVE-2024-29069
4.8 MEDIUM

In snapd versions prior to 2.62, snapd failed to properly check the destination of symbolic links when extracting a snap. The snap format is a …

Jul 25, 2024
CVE-2024-29068
5.8 MEDIUM

In snapd versions prior to 2.62, snapd failed to properly check the file type when extracting a snap. The snap format is a squashfs file-system …

Jul 25, 2024
CVE-2024-40318
7.2 HIGH

An arbitrary file upload vulnerability in Webkul Qloapps v1.6.0.0 allows attackers to execute arbitrary code via uploading a crafted file.

Jul 25, 2024
CVE-2024-1724
6.3 MEDIUM

In snapd versions prior to 2.62, when using AppArmor for enforcement of sandbox permissions, snapd failed to restrict writes to the $HOME/bin path. In Ubuntu, …

Jul 25, 2024
CVE-2024-40873
4.5 MEDIUM

There is a cross-site scripting vulnerability in the Secure Access administrative console of Absolute Secure Access prior to version 13.07. Attackers with system administrator permissions …

Jul 25, 2024
CVE-2024-28772
6.8 MEDIUM

IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary …

Jul 25, 2024
CVE-2022-32759
5.3 MEDIUM

IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 uses insufficient session expiration which could allow an unauthorized user to obtain sensitive …

Jul 25, 2024
CVE-2024-7007
9.8 CRITICAL

Positron Broadcast Signal Processor TRA7005 v1.20 is vulnerable to an authentication bypass exploit that could allow an attacker to have unauthorized access to protected areas …

Jul 25, 2024
CVE-2024-41801
4.7 MEDIUM

OpenProject is open source project management software. Prior to version 14.3.0, using a forged HOST header in the default configuration of packaged installations and using …

Jul 25, 2024
CVE-2024-41800
4.8 MEDIUM

Craft is a content management system (CMS). Craft CMS 5 allows reuse of TOTP tokens multiple times within the validity period. An attacker is able …

Jul 25, 2024
CVE-2024-40872
8.4 HIGH

There is an elevation of privilege vulnerability in server and client components of Absolute Secure Access prior to version 13.07. Attackers with local access and …

Jul 25, 2024
CVE-2024-36542
8.8 HIGH

Insecure permissions in kuma v2.7.0 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.

Jul 25, 2024
CVE-2024-7101
7.3 HIGH

A vulnerability, which was classified as critical, has been found in ForIP Tecnologia Administração PABX 1.x. This issue affects some unknown processing of the file …

Jul 25, 2024
CVE-2024-41806
5.3 MEDIUM

The Open edX Platform is a learning management platform. Instructors can upload csv files containing learner information to create cohorts in the instructor dashboard. These …

Jul 25, 2024
CVE-2024-36111
6.3 MEDIUM

KubePi is a K8s panel. Starting in version 1.6.3 and prior to version 1.8.0, there is a defect in the KubePi JWT token verification. The …

Jul 25, 2024
CVE-2024-39674
6.2 MEDIUM

Plaintext vulnerability in the Gallery search module. Impact: Successful exploitation of this vulnerability will affect availability.

Jul 25, 2024
CVE-2024-39673
6.8 MEDIUM

Vulnerability of serialisation/deserialisation mismatch in the iAware module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jul 25, 2024
CVE-2024-39672
8.4 HIGH

Memory request logic vulnerability in the memory module. Impact: Successful exploitation of this vulnerability will affect integrity and availability.

Jul 25, 2024
CVE-2024-39671
9.3 CRITICAL

Access control vulnerability in the security verification module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jul 25, 2024
CVE-2024-39670
6.2 MEDIUM

Privilege escalation vulnerability in the account synchronisation module. Impact: Successful exploitation of this vulnerability will affect availability.

Jul 25, 2024
CVE-2023-7271
5.5 MEDIUM

Privilege escalation vulnerability in the NMS module Impact: Successful exploitation of this vulnerability will affect availability.

Jul 25, 2024
CVE-2024-6589
8.8 HIGH

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.2.6.8.2 via the …

Jul 25, 2024
CVE-2024-37084
9.8 CRITICAL

In Spring Cloud Data Flow versions prior to 2.11.4, a malicious user who has access to the Skipper server api can use a crafted upload …

Jul 25, 2024
CVE-2024-41707
4.8 MEDIUM

An issue was discovered in Archer Platform 6 before 2024.06. Authenticated users can achieve HTML content injection. A remote authenticated malicious Archer user could potentially …

Jul 25, 2024
CVE-2024-41706
7.3 HIGH

A stored XSS issue was discovered in Archer Platform 6 before version 2024.06. A remote authenticated malicious Archer user could potentially exploit this to store …

Jul 25, 2024
CVE-2024-41705
7.1 HIGH

A stored XSS issue was discovered in Archer Platform 6.8 before 2024.06. A remote authenticated malicious Archer user could potentially exploit this to store malicious …

Jul 25, 2024
CVE-2024-6972
6.5 MEDIUM

In affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed in the task log in clear-text.

Jul 25, 2024
CVE-2024-4811
2.2 LOW

In affected versions of Octopus Server under certain conditions, a user with specific role assignments can access restricted project artifacts.

Jul 25, 2024
CVE-2024-7057
4.3 MEDIUM

An information disclosure vulnerability in GitLab CE/EE affecting all versions starting from 16.7 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from …

Jul 25, 2024
CVE-2024-7047
7.7 HIGH

A cross site scripting vulnerability exists in GitLab CE/EE affecting all versions from 16.6 prior to 17.0.5, 17.1 prior to 17.1.3, 17.2 prior to 17.2.1 …

Jul 25, 2024
CVE-2024-7091
4.1 MEDIUM

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.6 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from …

Jul 24, 2024
CVE-2024-7060
2.6 LOW

An information disclosure vulnerability in GitLab CE/EE in project/group exports affecting all versions from 15.4 prior to 17.0.5, 17.1 prior to 17.1.3, and 17.2 prior …

Jul 24, 2024
CVE-2024-5067
4.4 MEDIUM

An issue was discovered in GitLab EE affecting all versions starting from 16.11 prior to 17.0.5, starting from 17.1 prior to 17.1.3, and starting from …

Jul 24, 2024
CVE-2024-0231
2.7 LOW

A resource misdirection vulnerability in GitLab CE/EE versions 12.0 prior to 17.0.5, 17.1 prior to 17.1.3, and 17.2 prior to 17.2.1 allows an attacker to …

Jul 24, 2024
CVE-2024-7081
6.3 MEDIUM

A vulnerability was found in itsourcecode Tailoring Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Jul 24, 2024
CVE-2024-41466
7.5 HIGH

Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the page parameter at ip/goform/NatStaticSetting.

Jul 24, 2024
CVE-2024-41465
7.5 HIGH

Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the funcpara1 parameter at ip/goform/setcfm.

Jul 24, 2024
CVE-2024-41464
7.5 HIGH

Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the mitInterface parameter in ip/goform/RouteStatic

Jul 24, 2024
CVE-2024-41463
7.5 HIGH

Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the entrys parameter at ip/goform/addressNat.

Jul 24, 2024
CVE-2024-41462
7.5 HIGH

Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the page parameter at ip/goform/DhcpListClient.

Jul 24, 2024
CVE-2024-41461
9.8 CRITICAL

Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the list1 parameter at ip/goform/DhcpListClient.

Jul 24, 2024
CVE-2024-41460
9.8 CRITICAL

Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the entrys parameter at ip/goform/RouteStatic.

Jul 24, 2024
CVE-2024-41459
9.8 CRITICAL

Tenda FH1201 v1.2.0.14 was discovered to contain a stack-based buffer overflow vulnerability via the PPPOEPassword parameter at ip/goform/QuickIndex.

Jul 24, 2024
CVE-2024-41136
6.8 MEDIUM

An authenticated command injection vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateways Command Line Interface. Successful exploitation of this vulnerability results in the …

Jul 24, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.