CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-40524
9.8 CRITICAL

Directory Traversal vulnerability in xmind2testcase v.1.5 allows a remote attacker to execute arbitrary code via the webtool\application.py component.

Jul 15, 2024
CVE-2024-4143
9.8 CRITICAL

A potential security vulnerability has been identified in certain HP PC products using AMI BIOS, which might allow arbitrary code execution. AMI has released firmware …

Jul 15, 2024
CVE-2024-40632
3.7 LOW

Linkerd is an open source, ultralight, security-first service mesh for Kubernetes. In affected versions when the application being run by linkerd is susceptible to SSRF, …

Jul 15, 2024
CVE-2024-4224
5.4 MEDIUM

An authenticated stored cross-site scripting (XSS) exists in the TP-Link TL-SG1016DE affecting version TL-SG1016DE(UN) V7.6_1.0.0 Build 20230616, which could allow an adversary to run JavaScript …

Jul 15, 2024
CVE-2024-40630
4.3 MEDIUM

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation via a format-agnostic API …

Jul 15, 2024
CVE-2024-40627
5.8 MEDIUM

Fastapi OPA is an opensource fastapi middleware which includes auth flow. HTTP `OPTIONS` requests are always allowed by `OpaMiddleware`, even when they lack authentication, and …

Jul 15, 2024
CVE-2024-40624
9.8 CRITICAL

TorrentPier is an open source BitTorrent Public/Private tracker engine, written in php. In `torrentpier/library/includes/functions.php`, `get_tracks()` uses the unsafe native PHP serialization format to deserialize user-controlled …

Jul 15, 2024
CVE-2024-39919
3.1 LOW

@jmondi/url-to-png is an open source URL to PNG utility featuring parallel rendering using Playwright for screenshots and with storage caching via Local, S3, or CouchDB. …

Jul 15, 2024
CVE-2024-39918
4.3 MEDIUM

@jmondi/url-to-png is an open source URL to PNG utility featuring parallel rendering using Playwright for screenshots and with storage caching via Local, S3, or CouchDB. …

Jul 15, 2024
CVE-2024-39915
9.9 CRITICAL

Thruk is a multibackend monitoring webinterface for Naemon, Nagios, Icinga and Shinken using the Livestatus API. This authenticated RCE in Thruk allows authorized users with …

Jul 15, 2024
CVE-2024-39912
5.3 MEDIUM

web-auth/webauthn-lib is an open source set of PHP libraries and a Symfony bundle to allow developers to integrate that authentication mechanism into their web applications. …

Jul 15, 2024
CVE-2024-38360
4.9 MEDIUM

Discourse is an open source platform for community discussion. In affected versions by creating replacement words with an almost unlimited number of characters, a moderator …

Jul 15, 2024
CVE-2024-40631
8.1 HIGH

Plate media is an open source, rich-text editor for React. Editors that use `MediaEmbedElement` and pass custom `urlParsers` to the `useMediaState` hook may be vulnerable …

Jul 15, 2024
CVE-2024-37386
4.2 MEDIUM

An issue was discovered in Stormshield Network Security (SNS) 4.0.0 through 4.3.25, 4.4.0 through 4.7.5, and 4.8.0. Certain manipulations allow restarting in single-user mode despite …

Jul 15, 2024
CVE-2024-36438
7.3 HIGH

eLinkSmart Hidden Smart Cabinet Lock 2024-05-22 has Incorrect Access Control and fails to perform an authorization check which can lead to card duplication and other …

Jul 15, 2024
CVE-2024-36434
7.5 HIGH

An SMM callout vulnerability was discovered in Supermicro X11DPH-T, X11DPH-Tq, and X11DPH-i motherboards with BIOS firmware before 4.4.

Jul 15, 2024
CVE-2024-36433
7.5 HIGH

An arbitrary memory write vulnerability was discovered in Supermicro X11DPH-T, X11DPH-Tq, and X11DPH-i motherboards with BIOS firmware before 4.4.

Jul 15, 2024
CVE-2024-36432
7.5 HIGH

An arbitrary memory write vulnerability was discovered in Supermicro X11DPG-HGX2, X11PDG-QT, X11PDG-OT, and X11PDG-SN motherboards with BIOS firmware before 4.4.

Jul 15, 2024
CVE-2024-31946
4.2 MEDIUM

An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.41, 3.10.0 through 3.11.29, 4.0 through 4.3.24, and 4.4.0 through 4.7.4. A user who …

Jul 15, 2024
CVE-2024-40416
9.8 CRITICAL

A vulnerability in /goform/SetVirtualServerCfg in the sub_6320C function in Tenda AX1806 1.0.0.1 firmware leads to stack-based buffer overflow.

Jul 15, 2024
CVE-2024-40415
9.8 CRITICAL

A vulnerability in /goform/SetStaticRouteCfg in the sub_519F4 function in Tenda AX1806 1.0.0.1 firmware leads to stack-based buffer overflow.

Jul 15, 2024
CVE-2024-39827
5.5 MEDIUM

Improper input validation in the installer for Zoom Workplace Desktop App for Windows before version 6.0.10 may allow an authenticated user to conduct a denial …

Jul 15, 2024
CVE-2024-39826
6.8 MEDIUM

Race condition in Team Chat for some Zoom Workplace Apps and SDKs for Windows may allow an authenticated user to conduct information disclosure via network …

Jul 15, 2024
CVE-2024-39821
6.6 MEDIUM

Race condition in the installer for Zoom Workplace App for Windows and Zoom Rooms App for Windows may allow an authenticated user to conduct a …

Jul 15, 2024
CVE-2024-39820
6.6 MEDIUM

Uncontrolled search path element in the installer for Zoom Workplace Desktop App for macOS before version 6.0.10 may allow an authenticated user to conduct a …

Jul 15, 2024
CVE-2024-39819
6.7 MEDIUM

Integrity check in the installer for some Zoom Workplace Apps and SDKs for Windows may allow an authenticated user to conduct a privilege escalation via …

Jul 15, 2024
CVE-2024-37016
6.8 MEDIUM

Mengshen Wireless Door Alarm M70 2024-05-24 allows Authentication Bypass via a Capture-Replay approach.

Jul 15, 2024
CVE-2024-27241
5.3 MEDIUM

Improper input validation in some Zoom Apps and SDKs may allow an authenticated user to conduct a denial of service via network access.

Jul 15, 2024
CVE-2024-27240
7.1 HIGH

Improper input validation in the installer for some Zoom Apps for Windows may allow an authenticated user to conduct a privilege escalation via local access.

Jul 15, 2024
CVE-2024-27238
7.1 HIGH

Race condition in the installer for some Zoom Apps and SDKs for Windows before version 6.0.0 may allow an authenticated user to conduct a privilege …

Jul 15, 2024
CVE-2024-40414
9.8 CRITICAL

A vulnerability in /goform/SetNetControlList in the sub_656BC function in Tenda AX1806 1.0.0.1 firmware leads to stack-based buffer overflow.

Jul 15, 2024
CVE-2024-40560
7.3 HIGH

Tmall_demo before v2024.07.03 was discovered to contain a SQL injection vulnerability.

Jul 15, 2024
CVE-2024-40555
5.3 MEDIUM

Tmall_demo v2024.07.03 was discovered to contain an arbitrary file upload vulnerability.

Jul 15, 2024
CVE-2024-40554
7.5 HIGH

An access control issue in Tmall_demo v2024.07.03 allows attackers to obtain sensitive information.

Jul 15, 2024
CVE-2024-40553
4.9 MEDIUM

Tmall_demo v2024.07.03 was discovered to contain an arbitrary file upload via the component uploadUserHeadImage.

Jul 15, 2024
CVE-2024-6716

Rejected reason: Invalid security issue.

Jul 15, 2024
CVE-2024-38496

The vulnerability allows a malicious low-privileged PAM user to access information about other PAM users and their group memberships.

Jul 15, 2024
CVE-2024-38495

A specific authentication strategy allows a malicious attacker to learn ids of all PAM users defined in its database.

Jul 15, 2024
CVE-2024-6689
7.8 HIGH

Local Privilege Escalation in MSI-Installer in baramundi Management Agent v23.1.172.0 on Windows allows a local unprivileged user to escalate privileges to SYSTEM.

Jul 15, 2024
CVE-2024-38494

This vulnerability allows a high-privileged authenticated PAM user to achieve remote command execution on the affected PAM system by sending a specially crafted HTTP request.

Jul 15, 2024
CVE-2024-38493
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability exists in the PAM UI web interface. A remote attacker able to convince a PAM user to click on …

Jul 15, 2024
CVE-2024-38492

This vulnerability allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by uploading a specially crafted PAM upgrade file.

Jul 15, 2024
CVE-2024-38491

The vulnerability allows an unauthenticated attacker to read arbitrary information from the database.

Jul 15, 2024
CVE-2024-36458

The vulnerability allows a malicious low-privileged PAM user to perform server upgrade related actions.

Jul 15, 2024
CVE-2024-36457

The vulnerability allows an attacker to bypass the authentication requirements for a specific PAM endpoint.

Jul 15, 2024
CVE-2024-36456

This vulnerability allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by uploading a specially crafted PAM upgrade file.

Jul 15, 2024
CVE-2024-36455

An improper input validation allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by sending a specially crafted HTTP request.

Jul 15, 2024
CVE-2024-6746
4.3 MEDIUM

A vulnerability classified as problematic was found in NaiboWang EasySpider 0.6.2 on Windows. Affected by this vulnerability is an unknown functionality of the file \EasySpider\resources\app\server.js …

Jul 15, 2024
CVE-2024-5402
7.8 HIGH

Unquoted Search Path or Element vulnerability in ABB Mint Workbench. A local attacker who successfully exploited this vulnerability could gain elevated privileges by inserting an …

Jul 15, 2024
CVE-2024-6745
7.3 HIGH

A vulnerability classified as critical has been found in code-projects Simple Ticket Booking 1.0. Affected is an unknown function of the file adminauthenticate.php of the …

Jul 15, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.