CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-39514
6.5 MEDIUM

An Improper Check or Handling of Exceptional Conditions vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos and Junos OS Evolved allows an …

Jul 10, 2024
CVE-2024-39513
5.5 MEDIUM

An Improper Input Validation vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved allows a local, low-privileged attacker to cause a …

Jul 10, 2024
CVE-2024-39512
6.6 MEDIUM

An Improper Physical Access Control vulnerability in the console port control of Juniper Networks Junos OS Evolved allows an attacker with physical access to the …

Jul 10, 2024
CVE-2024-39511
5.5 MEDIUM

An Improper Input Validation vulnerability in the 802.1X Authentication (dot1x) Daemon of Juniper Networks Junos OS allows a local, low-privileged attacker with access to the …

Jul 10, 2024
CVE-2024-6664

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

Jul 10, 2024
CVE-2024-6663

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

Jul 10, 2024
CVE-2024-6286
7.8 HIGH

Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows

Jul 10, 2024
CVE-2024-6236
7.5 HIGH

Denial of Service in NetScaler Console (formerly NetScaler ADM), NetScaler Agent, and NetScaler SDX

Jul 10, 2024
CVE-2024-6151
7.8 HIGH

Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Virtual Delivery Agent for Windows used by Citrix Virtual Apps and Desktops and …

Jul 10, 2024
CVE-2024-6150
4.3 MEDIUM

A non-admin user can cause short-term disruption in Target VM availability in Citrix Provisioning

Jul 10, 2024
CVE-2024-6149
6.1 MEDIUM

Redirection of users to a vulnerable URL in Citrix Workspace app for HTML5

Jul 10, 2024
CVE-2024-6148
8.8 HIGH

Bypass of GACS Policy Configuration settings in Citrix Workspace app for HTML5

Jul 10, 2024
CVE-2024-39693
7.5 HIGH

Next.js is a React framework. A Denial of Service (DoS) condition was identified in Next.js. Exploitation of the bug can trigger a crash, affecting the …

Jul 10, 2024
CVE-2024-38354
8.1 HIGH

CodiMD allows realtime collaborative markdown notes on all platforms. The notebook feature of Hackmd.io permits the rendering of iframe `HTML` tags with an improperly sanitized …

Jul 10, 2024
CVE-2024-38353
5.3 MEDIUM

CodiMD allows realtime collaborative markdown notes on all platforms. CodiMD before 2.5.4 is missing authentication and access control vulnerability allowing an unauthenticated attacker to gain …

Jul 10, 2024
CVE-2024-37310
9.0 CRITICAL

EVerest is an EV charging software stack. An integer overflow in the "v2g_incoming_v2gtp" function in the v2g_server.cpp implementation can allow a remote attacker to overflow …

Jul 10, 2024
CVE-2024-37149
7.2 HIGH

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An authenticated technician user …

Jul 10, 2024
CVE-2024-37148
8.1 HIGH

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An authenticated user can …

Jul 10, 2024
CVE-2024-25077
9.8 CRITICAL

An issue was discovered on Renesas SmartBond DA14691, DA14695, DA14697, and DA14699 devices. The Nonce used for on-the-fly decryption of flash images is stored in …

Jul 10, 2024
CVE-2024-25076
6.8 MEDIUM

An issue was discovered on Renesas SmartBond DA14691, DA14695, DA14697, and DA14699 devices. The bootrom function responsible for validating the Flash Product Header directly uses …

Jul 10, 2024
CVE-2024-6649
4.3 MEDIUM

A vulnerability has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0 and classified as problematic. Affected by this vulnerability is the …

Jul 10, 2024
CVE-2024-6235
8.8 HIGH

Sensitive information disclosure in NetScaler Console

Jul 10, 2024
CVE-2024-5913
6.1 MEDIUM

An improper input validation vulnerability in Palo Alto Networks PAN-OS software enables an attacker with the ability to tamper with the physical file system to …

Jul 10, 2024
CVE-2024-5912

An improper file signature check in Palo Alto Networks Cortex XDR agent may allow an attacker to bypass the Cortex XDR agent's executable blocking capabilities …

Jul 10, 2024
CVE-2024-5911
4.9 MEDIUM

An arbitrary file upload vulnerability in Palo Alto Networks Panorama software enables an authenticated read-write administrator with access to the web interface to disrupt system …

Jul 10, 2024
CVE-2024-5910
9.8 CRITICAL KEV

Missing authentication for a critical function in Palo Alto Networks Expedition can lead to an Expedition admin account takeover for attackers with network access to …

Jul 10, 2024
CVE-2024-5492
6.1 MEDIUM

Open redirect vulnerability allows a remote unauthenticated attacker to redirect users to arbitrary websites in NetScaler ADC and NetScaler Gateway

Jul 10, 2024
CVE-2024-5491
7.5 HIGH

Denial of Service in NetScaler ADC and NetScaler Gateway in NetScaler

Jul 10, 2024
CVE-2024-37147
4.3 MEDIUM

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An authenticated user can …

Jul 10, 2024
CVE-2024-32469
7.1 HIGH

Decidim is a participatory democracy framework. The pagination feature used in searches and filters is subject to potential XSS attack through a malformed URL using …

Jul 10, 2024
CVE-2024-27095
5.4 MEDIUM

Decidim is a participatory democracy framework. The admin panel is subject to potential XSS attach in case the attacker manages to modify some records being …

Jul 10, 2024
CVE-2024-27090
5.3 MEDIUM

Decidim is a participatory democracy framework, written in Ruby on Rails, originally developed for the Barcelona City government online and offline participation website. If an …

Jul 10, 2024
CVE-2024-6647
4.7 MEDIUM

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in Croogo up to 4.0.7. This affects an unknown part of the …

Jul 10, 2024
CVE-2024-6646
5.3 MEDIUM

A vulnerability was found in Netgear WN604 up to 20240710. It has been rated as problematic. Affected by this issue is some unknown functionality of …

Jul 10, 2024
CVE-2024-6630

Rejected reason: **REJECT** This CVE ID was issued in error and is a duplicate. Please use CVE-2024-6500 instead.

Jul 10, 2024
CVE-2024-37770
9.1 CRITICAL

14Finger v1.1 was discovered to contain a remote command execution (RCE) vulnerability in the fingerprint function. This vulnerability allows attackers to execute arbitrary commands via …

Jul 10, 2024
CVE-2024-37504
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ninja Team FileBird Document Library.This issue affects FileBird Document Library: from n/a through 2.0.6.

Jul 10, 2024
CVE-2024-37498
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Pauple Table & Contact Form 7 Database – Tablesome.This issue affects Table & Contact Form …

Jul 10, 2024
CVE-2024-37270
5.3 MEDIUM

Insertion of Sensitive Information into Log File vulnerability in TrustedLogin TrustedLogin Vendor.This issue affects TrustedLogin Vendor: from n/a before 1.1.1.

Jul 10, 2024
CVE-2024-37205
5.3 MEDIUM

Insertion of Sensitive Information into Log File vulnerability in SERVIT Software Solutions.This issue affects affiliate-toolkit: from n/a through 3.4.4.

Jul 10, 2024
CVE-2024-37115
7.5 HIGH

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Automattic Newspack Blocks.This issue affects Newspack Blocks: from n/a through 3.0.8.

Jul 10, 2024
CVE-2024-37113
9.8 CRITICAL

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Membership Software WishList Member X.This issue affects WishList Member X: from n/a before 3.26.7.

Jul 10, 2024
CVE-2024-37110
7.5 HIGH

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Membership Software WishList Member X.This issue affects WishList Member X: from n/a before 3.26.7.

Jul 10, 2024
CVE-2024-32759

Under certain circumstances the Software House C●CURE 9000 installer will utilize weak credentials.

Jul 10, 2024
CVE-2024-6645
6.3 MEDIUM

A vulnerability was found in WuKongOpenSource Wukong_nocode up to 20230807. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Jul 10, 2024
CVE-2024-6644
6.3 MEDIUM

A vulnerability was found in zmops ArgusDBM up to 0.1.0. It has been classified as critical. Affected is the function getDefaultClassLoader of the file CalculateAlarm.java …

Jul 10, 2024
CVE-2024-5217
9.8 CRITICAL KEV

ServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and earlier Now Platform releases. This vulnerability could enable an …

Jul 10, 2024
CVE-2024-5178
4.9 MEDIUM

ServiceNow has addressed a sensitive file read vulnerability that was identified in the Washington DC, Vancouver, and Utah Now Platform releases. This vulnerability could allow …

Jul 10, 2024
CVE-2024-4879
9.8 CRITICAL KEV

ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platform releases. This vulnerability could enable an unauthenticated user …

Jul 10, 2024
CVE-2024-3325
7.2 HIGH

Vulnerability in Jaspersoft JasperReport Servers.This issue affects JasperReport Servers: from 8.0.4 through 9.0.0.

Jul 10, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.