CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-4884
9.8 CRITICAL

In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold. The Apm.UI.Areas.APM.Controllers.CommunityController allows execution of commands with iisapppool\nmconsole privileges.

Jun 25, 2024
CVE-2024-4883
9.8 CRITICAL

In WhatsUp Gold versions released before 2023.1.3, a Remote Code Execution issue exists in Progress WhatsUp Gold. This vulnerability allows an unauthenticated attacker to achieve …

Jun 25, 2024
CVE-2024-4498
7.7 HIGH

A Path Traversal and Remote File Inclusion (RFI) vulnerability exists in the parisneo/lollms-webui application, affecting versions v9.7 to the latest. The vulnerability arises from insufficient …

Jun 25, 2024
CVE-2024-37894
6.3 MEDIUM

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to an Out-of-bounds Write error when assigning ESI variables, Squid …

Jun 25, 2024
CVE-2024-37167
4.3 MEDIUM

Tuleap is an Open Source Suite to improve management of software developments and collaboration. Users are able to see backlog items that they should not …

Jun 25, 2024
CVE-2024-37820
5.4 MEDIUM

A nil pointer dereference in PingCAP TiDB v8.2.0-alpha-216-gfe5858b allows attackers to crash the application via expression.inferCollation.

Jun 25, 2024
CVE-2024-36819
5.4 MEDIUM

MAP-OS 4.45.0 and earlier is vulnerable to Cross-Site Scripting (XSS). This vulnerability allows malicious users to insert a malicious payload into the "Client Name" input. …

Jun 25, 2024
CVE-2024-6308
7.3 HIGH

A vulnerability was found in itsourcecode Simple Online Hotel Reservation System 1.0. It has been declared as critical. This vulnerability affects unknown code of the …

Jun 25, 2024
CVE-2024-6257
8.4 HIGH

HashiCorp’s go-getter library can be coerced into executing Git update on an existing maliciously modified Git Configuration, potentially leading to arbitrary code execution.

Jun 25, 2024
CVE-2024-6238
7.4 HIGH

pgAdmin <= 8.8 has an installation Directory permission issue. Because of this issue, attackers can gain unauthorised access to the installation directory on the Debian …

Jun 25, 2024
CVE-2024-5990
7.5 HIGH

Due to an improper input validation, an unauthenticated threat actor can send a malicious message to a monitor thread within Rockwell Automation ThinServer™ and cause …

Jun 25, 2024
CVE-2024-5989
9.8 CRITICAL

Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke SQL injection into the program and cause a …

Jun 25, 2024
CVE-2024-5988
9.8 CRITICAL

Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke a local or remote executable and cause a …

Jun 25, 2024
CVE-2024-0171
5.3 MEDIUM

Dell PowerEdge Server BIOS contains an TOCTOU race condition vulnerability. A local low privileged attacker could potentially exploit this vulnerability to gain access to otherwise …

Jun 25, 2024
CVE-2024-5806
9.1 CRITICAL

Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.11, from 2023.1.0 before …

Jun 25, 2024
CVE-2024-5805
9.1 CRITICAL

Improper Authentication vulnerability in Progress MOVEit Gateway (SFTP modules) allows Authentication Bypass.This issue affects MOVEit Gateway: 2024.0.0.

Jun 25, 2024
CVE-2024-39471
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: add error handle to avoid out-of-bounds if the sdma_v4_0_irq_id_to_seq return -EINVAL, the process should …

Jun 25, 2024
CVE-2024-39470
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: eventfs: Fix a possible null pointer dereference in eventfs_find_events() In function eventfs_find_events,there is a potential …

Jun 25, 2024
CVE-2024-39469
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix nilfs_empty_dir() misjudgment and long loop on I/O errors The error handling in nilfs_empty_dir() …

Jun 25, 2024
CVE-2024-39468
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix deadlock in smb2_find_smb_tcon() Unlock cifs_tcp_ses_lock before calling cifs_put_smb_ses() to avoid such deadlock.

Jun 25, 2024
CVE-2024-39467
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to do sanity check on i_xattr_nid in sanity_check_inode() syzbot reports a kernel bug …

Jun 25, 2024
CVE-2024-39466
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: thermal/drivers/qcom/lmh: Check for SCM availability at probe Up until now, the necessary scm availability check …

Jun 25, 2024
CVE-2024-39465
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: mgb4: Fix double debugfs remove Fixes an error where debugfs_remove_recursive() is called first on …

Jun 25, 2024
CVE-2024-39464
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: v4l: async: Fix notifier list entry init struct v4l2_async_notifier has several list_head members, but …

Jun 25, 2024
CVE-2024-39463
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: 9p: add missing locking around taking dentry fid list Fix a use-after-free on dentry's d_fsdata …

Jun 25, 2024
CVE-2024-39462
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: clk: bcm: dvp: Assign ->num before accessing ->hws Commit f316cdff8d67 ("clk: Annotate struct clk_hw_onecell_data with …

Jun 25, 2024
CVE-2024-39461
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: clk: bcm: rpi: Assign ->num before accessing ->hws Commit f316cdff8d67 ("clk: Annotate struct clk_hw_onecell_data with …

Jun 25, 2024
CVE-2024-39371
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: io_uring: check for non-NULL file pointer in io_file_can_poll() In earlier kernels, it was possible to …

Jun 25, 2024
CVE-2024-39362

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 25, 2024
CVE-2024-39301
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/9p: fix uninit-value in p9_client_rpc() Syzbot with the help of KMSAN reported the following error: …

Jun 25, 2024
CVE-2024-39298
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/memory-failure: fix handling of dissolved but not taken off from buddy pages When I did …

Jun 25, 2024
CVE-2024-39296
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bonding: fix oops during rmmod "rmmod bonding" causes an oops ever since commit cc317ea3d927 ("bonding: …

Jun 25, 2024
CVE-2024-39293
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Revert "xsk: Support redirect to any socket bound to the same umem" This reverts commit …

Jun 25, 2024
CVE-2024-39276
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ext4: fix mb_cache_entry's e_refcnt leak in ext4_xattr_block_cache_find() Syzbot reports a warning as follows: ============================================ WARNING: …

Jun 25, 2024
CVE-2024-38661
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: s390/ap: Fix crash in AP internal function modify_bitmap() A system crash like this Failing address: …

Jun 25, 2024
CVE-2024-38385
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: genirq/irqdesc: Prevent use-after-free in irq_find_at_or_after() irq_find_at_or_after() dereferences the interrupt descriptor which is returned by mt_find() …

Jun 25, 2024
CVE-2024-38306
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: protect folio::private when attaching extent buffer folios [BUG] Since v6.8 there are rare kernel …

Jun 25, 2024
CVE-2024-37354
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix crash on racing fsync and size-extending write into prealloc We have been seeing …

Jun 25, 2024
CVE-2024-37087
5.3 MEDIUM

The vCenter Server contains a denial-of-service vulnerability. A malicious actor with network access to vCenter Server may create a denial-of-service condition.

Jun 25, 2024
CVE-2024-37086
6.8 MEDIUM

VMware ESXi contains an out-of-bounds read vulnerability. A malicious actor with local administrative privileges on a virtual machine with an existing snapshot may trigger an …

Jun 25, 2024
CVE-2024-37085
6.8 MEDIUM KEV

VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that …

Jun 25, 2024
CVE-2024-37078
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix potential kernel bug due to lack of writeback flag waiting Destructive writes to …

Jun 25, 2024
CVE-2023-37541
3.5 LOW

HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios.

Jun 25, 2024
CVE-2022-48772
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: lgdt3306a: Add a check against null-pointer-def The driver should check whether the client provides …

Jun 25, 2024
CVE-2021-4440
8.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: x86/xen: Drop USERGS_SYSRET64 paravirt call commit afd30525a659ac0ae0904f0cb4a2ca75522c3123 upstream. USERGS_SYSRET64 is used to return from a …

Jun 25, 2024
CVE-2024-5451
6.4 MEDIUM

The The7 — Website and eCommerce Builder for WordPress theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' attribute within the plugin's …

Jun 25, 2024
CVE-2024-38952
7.5 HIGH

PX4-Autopilot v1.14.3 was discovered to contain a buffer overflow via the topic_name parameter at /logger/logged_topics.cpp.

Jun 25, 2024
CVE-2024-38951
6.5 MEDIUM

A buffer overflow in PX4-Autopilot v1.12.3 allows attackers to cause a Denial of Service (DoS) via a crafted MavLink message.

Jun 25, 2024
CVE-2024-32111
5.0 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Automattic WordPress allows Relative Path Traversal.This issue affects WordPress: from 6.5 through …

Jun 25, 2024
CVE-2024-21827
7.2 HIGH

A leftover debug code vulnerability exists in the cli_server debug functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.4.1 Build 20240117 Rel.57421. A specially crafted …

Jun 25, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.