CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2022-25480
7.8 HIGH

Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 allows writing …

Jul 2, 2024
CVE-2022-25479
5.5 MEDIUM

Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 allows for …

Jul 2, 2024
CVE-2022-25478
7.8 HIGH

Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 provides read …

Jul 2, 2024
CVE-2022-25477
5.5 MEDIUM

Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 leaks driver …

Jul 2, 2024
CVE-2024-6382
6.4 MEDIUM

Incorrect handling of certain string inputs may result in MongoDB Rust driver constructing unintended server commands. This may cause unexpected application behavior including data modification. …

Jul 2, 2024
CVE-2024-6381
4.0 MEDIUM

The bson_strfreev function in the MongoDB C driver library may be susceptible to an integer overflow where the function will try to free memory at …

Jul 2, 2024
CVE-2024-39894
7.5 HIGH

OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) because of an ObscureKeystrokeTiming logic error. …

Jul 2, 2024
CVE-2024-39891
5.3 MEDIUM KEV

In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to certain phone-number data, …

Jul 2, 2024
CVE-2024-39206
7.5 HIGH

An issue discovered in MSP360 Backup Agent v7.8.5.15 and v7.9.4.84 allows attackers to obtain network share credentials used in a backup due to enginesettings.list being …

Jul 2, 2024
CVE-2023-39324

Rejected reason: reserved but not needed

Jul 2, 2024
CVE-2022-41730

Rejected reason: reserved but not needed

Jul 2, 2024
CVE-2022-41729

Rejected reason: reserved but not needed

Jul 2, 2024
CVE-2022-41728

Rejected reason: reserved but not needed

Jul 2, 2024
CVE-2022-41726

Rejected reason: reserved but not needed

Jul 2, 2024
CVE-2022-41718

Rejected reason: reserved but not needed

Jul 2, 2024
CVE-2022-3428

Rejected reason: reserved but not needed

Jul 2, 2024
CVE-2022-32191

Rejected reason: reserved but not needed

Jul 2, 2024
CVE-2022-32147

Rejected reason: reserved but not needed

Jul 2, 2024
CVE-2024-5866
5.0 MEDIUM

Vulnerability in Delinea Centrify PAS v. 21.3 and possibly others. The application is prone to the path traversal vulnerability allowing listing of arbitrary directory outside …

Jul 2, 2024
CVE-2024-5865
7.7 HIGH

Vulnerability in Delinea Centrify PAS v. 21.3 and possibly others. The application is prone to the path traversal vulnerability allowing arbitrary files reading outside the …

Jul 2, 2024
CVE-2024-4467
7.8 HIGH

A flaw was found in the QEMU disk image utility (qemu-img) 'info' command. A specially crafted image file containing a `json:{}` value describing block devices …

Jul 2, 2024
CVE-2024-3826

In versions of Akana in versions prior to and including 2022.1.3 validation is broken when using the SAML Single Sign-On (SSO) functionality.

Jul 2, 2024
CVE-2024-39323
7.1 HIGH

aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.01 and prior to versions 2022.10.10, 2023.10.6, and 2024.04.6, an improper access control vulnerability …

Jul 2, 2024
CVE-2024-39316
6.5 MEDIUM

Rack is a modular Ruby web server interface. Starting in version 3.1.0 and prior to version 3.1.5, Regular Expression Denial of Service (ReDoS) vulnerability exists …

Jul 2, 2024
CVE-2024-26314
7.8 HIGH

Improper privilege management in Jungo WinDriver 6.0.0 through 16.1.0 allows local attackers to escalate privileges and execute arbitrary code.

Jul 2, 2024
CVE-2024-25088
7.8 HIGH

Improper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges and execute arbitrary code.

Jul 2, 2024
CVE-2024-25087
5.5 MEDIUM

Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.7.0 allows local attackers to cause a Windows blue screen error.

Jul 2, 2024
CVE-2024-25086
7.8 HIGH

Improper privilege management in Jungo WinDriver before 12.2.0 allows local attackers to escalate privileges and execute arbitrary code.

Jul 2, 2024
CVE-2024-22106
7.8 HIGH

Improper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges, execute arbitrary code, or cause a Denial of Service (DoS).

Jul 2, 2024
CVE-2024-22105
5.5 MEDIUM

Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.5.1 allows local attackers to cause a Windows blue screen error.

Jul 2, 2024
CVE-2024-4897
8.4 HIGH

parisneo/lollms-webui, in its latest version, is vulnerable to remote code execution due to an insecure dependency on llama-cpp-python version llama_cpp_python-0.2.61+cpuavx2-cp311-cp311-manylinux_2_31_x86_64. The vulnerability arises from the …

Jul 2, 2024
CVE-2024-32932
6.8 MEDIUM

Under certain circumstances the web interface users credentials may be recovered by an authenticated user.

Jul 2, 2024
CVE-2024-22104
5.5 MEDIUM

Out-of-Bounds Write vulnerability in Jungo WinDriver before 12.5.1 allows local attackers to cause a Windows blue screen error and Denial of Service (DoS).

Jul 2, 2024
CVE-2024-22103
5.5 MEDIUM

Out-of-Bounds Write vulnerability in Jungo WinDriver before 12.6.0 allows local attackers to cause a Windows blue screen error and Denial of Service (DoS).

Jul 2, 2024
CVE-2024-22102
5.5 MEDIUM

Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.6.0 allows local attackers to cause a Windows blue screen error.

Jul 2, 2024
CVE-2023-51778
5.5 MEDIUM

Out-of-Bounds Write vulnerability in Jungo WinDriver before 12.1.0 allows local attackers to cause a Windows blue screen error and Denial of Service (DoS).

Jul 2, 2024
CVE-2023-51777
5.5 MEDIUM

Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.1.0 allows local attackers to cause a Windows blue screen error.

Jul 2, 2024
CVE-2023-51776
7.8 HIGH

Improper privilege management in Jungo WinDriver before 12.1.0 allows local attackers to escalate privileges and execute arbitrary code.

Jul 2, 2024
CVE-2024-39143
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in ResidenceCMS 2.10.1 that allows a low-privilege user to create malicious property content with HTML inside which acts …

Jul 2, 2024
CVE-2024-38519
7.8 HIGH

`yt-dlp` and `youtube-dl` are command-line audio/video downloaders. Prior to the fixed versions, `yt-dlp` and `youtube-dl` do not limit the extensions of downloaded files, which could …

Jul 2, 2024
CVE-2024-36404
9.8 CRITICAL

GeoTools is an open source Java library that provides tools for geospatial data. Prior to versions 31.2, 30.4, and 29.6, Remote Code Execution (RCE) is …

Jul 2, 2024
CVE-2024-34122
7.8 HIGH

Acrobat for Edge versions 126.0.2592.68 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read …

Jul 2, 2024
CVE-2024-32757
6.8 MEDIUM

Under certain circumstances unnecessary user details are provided within system logs

Jul 2, 2024
CVE-2024-32756
6.8 MEDIUM

Under certain circumstances the Linux users credentials may be recovered by an authenticated user.

Jul 2, 2024
CVE-2024-32755
9.1 CRITICAL

Under certain circumstances the web interface will accept characters unrelated to the expected input.

Jul 2, 2024
CVE-2024-39119
5.4 MEDIUM

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/info_deal.php?mudi=rev&nohrefStr=close.

Jul 2, 2024
CVE-2024-6441
6.3 MEDIUM

A vulnerability was found in ORIPA up to 1.72. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the …

Jul 2, 2024
CVE-2024-6440
6.3 MEDIUM

A vulnerability was found in SourceCodester Home Owners Collection Management System 1.0. It has been classified as critical. Affected is an unknown function of the …

Jul 2, 2024
CVE-2024-6439
6.3 MEDIUM

A vulnerability was found in SourceCodester Home Owners Collection Management System 1.0 and classified as critical. This issue affects some unknown processing of the file …

Jul 2, 2024
CVE-2024-6438
6.3 MEDIUM

A vulnerability has been found in Hitout Carsale 1.0 and classified as critical. This vulnerability affects unknown code of the file OrderController.java. The manipulation of …

Jul 2, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.