CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-33880
5.3 MEDIUM

An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. It discloses full pathnames via Virto.SharePoint.FileDownloader/Api/Download.ashx?action=archive.

Jun 24, 2024
CVE-2024-33879
9.8 CRITICAL

An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileDownloader/Api/Download.ashx isCompleted method allows arbitrary file download and deletion via …

Jun 24, 2024
CVE-2024-6287
7.5 HIGH

Incorrect Calculation vulnerability in Renesas arm-trusted-firmware allows Local Execution of Code. When checking whether a new image invades/overlaps with a previously loaded image the code …

Jun 24, 2024
CVE-2024-6285
7.5 HIGH

Integer Underflow (Wrap or Wraparound) vulnerability in Renesas arm-trusted-firmware. An integer underflow in image range check calculations could lead to bypassing address restrictions and loading …

Jun 24, 2024
CVE-2024-33687
7.5 HIGH

Insufficient verification of data authenticity issue exists in NJ Series CPU Unit all versions and NX Series CPU Unit all versions. If a user program …

Jun 24, 2024
CVE-2024-4748
8.8 HIGH

The CRUDDIY project is vulnerable to shell command injection via sending a crafted POST request to the application server. The exploitation risk is limited since …

Jun 24, 2024
CVE-2024-39292
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: um: Add winch to winch_handlers before registering winch IRQ Registering a winch IRQ is racy, …

Jun 24, 2024
CVE-2024-39291
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix buffer size in gfx_v9_4_3_init_ cp_compute_microcode() and rlc_microcode() The function gfx_v9_4_3_init_microcode in gfx_v9_4_3.c was …

Jun 24, 2024
CVE-2024-38667
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: riscv: prevent pt_regs corruption for secondary idle threads Top of the kernel thread stack should …

Jun 24, 2024
CVE-2024-38664
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm: zynqmp_dpsub: Always register bridge We must always register the DRM bridge, since zynqmp_dp_hpd_work_func calls …

Jun 24, 2024
CVE-2024-38663
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: blk-cgroup: fix list corruption from resetting io stat Since commit 3b8cc6298724 ("blk-cgroup: Optimize blkcg_rstat_flush()"), each …

Jun 24, 2024
CVE-2024-38384
8.4 HIGH

In the Linux kernel, the following vulnerability has been resolved: blk-cgroup: fix list corruption from reorder of WRITE ->lqueued __blkcg_rstat_flush() can be run anytime, especially …

Jun 24, 2024
CVE-2024-37825
5.4 MEDIUM

An issue in EnvisionWare Computer Access & Reservation Control SelfCheck v1.0 (fixed in OneStop 3.2.0.27184 Hotfix May 2024) allows unauthenticated attackers on the same network …

Jun 24, 2024
CVE-2024-37026
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/xe: Only use reserved BCS instances for usm migrate exec queue The GuC context scheduling …

Jun 24, 2024
CVE-2024-37021
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fpga: manager: add owner module and take its refcount The current implementation of the fpga …

Jun 24, 2024
CVE-2024-36479
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fpga: bridge: add owner module and take its refcount The current implementation of the fpga …

Jun 24, 2024
CVE-2024-35247
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fpga: region: add owner module and take its refcount The current implementation of the fpga …

Jun 24, 2024
CVE-2024-34030
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: PCI: of_property: Return error for int_map allocation failure Return -ENOMEM from of_pci_prop_intr_map() if kcalloc() fails …

Jun 24, 2024
CVE-2024-34027
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: f2fs: compress: fix to cover {reserve,release}_compress_blocks() w/ cp_rwsem lock It needs to cover {reserve,release}_compress_blocks() w/ …

Jun 24, 2024
CVE-2024-33847
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: f2fs: compress: don't allow unaligned truncation on released compress inode f2fs image may be corrupted …

Jun 24, 2024
CVE-2024-33278
9.8 CRITICAL

Buffer Overflow vulnerability in ASUS router RT-AX88U with firmware versions v3.0.0.4.388_24198 allows a remote attacker to execute arbitrary code via the connection_state_machine due to improper …

Jun 24, 2024
CVE-2024-32936
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: ti: j721e-csi2rx: Fix races while restarting DMA After the frame is submitted to DMA, …

Jun 24, 2024
CVE-2024-5862
7.5 HIGH

Improper Restriction of Excessive Authentication Attempts vulnerability in Mia Technology Inc. Mia-Med Health Aplication allows Interface Manipulation.This issue affects Mia-Med Health Aplication: before 1.0.14.

Jun 24, 2024
CVE-2024-4839
3.3 LOW

A Cross-Site Request Forgery (CSRF) vulnerability exists in the 'Servers Configurations' function of the parisneo/lollms-webui, versions 9.6 to the latest. The affected functions include Elastic …

Jun 24, 2024
CVE-2024-3264
5.3 MEDIUM

Use of a Broken or Risky Cryptographic Algorithm vulnerability in Mia Technology Inc. Mia-Med Health Aplication allows Signature Spoofing by Improper Validation.This issue affects Mia-Med …

Jun 24, 2024
CVE-2024-37233
4.3 MEDIUM

Improper Authentication vulnerability in Play.Ht allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Play.Ht: from n/a through 3.6.4.

Jun 24, 2024
CVE-2024-37231
8.6 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salon Booking System Salon booking system allows File Manipulation.This issue affects Salon …

Jun 24, 2024
CVE-2024-37228
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.38.

Jun 24, 2024
CVE-2024-37111
7.5 HIGH

Missing Authorization vulnerability in Membership Software WishList Member X.This issue affects WishList Member X: from n/a before 3.26.7.

Jun 24, 2024
CVE-2024-37109
9.9 CRITICAL

Improper Control of Generation of Code ('Code Injection') vulnerability in Membership Software WishList Member X allows Code Injection.This issue affects WishList Member X: from n/a …

Jun 24, 2024
CVE-2024-37107
8.8 HIGH

Improper Privilege Management vulnerability in Membership Software WishList Member X allows Privilege Escalation.This issue affects WishList Member X: from n/a before 3.26.7.

Jun 24, 2024
CVE-2024-37092
8.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in StylemixThemes Consulting Elementor Widgets allows PHP Local File Inclusion.This issue affects Consulting …

Jun 24, 2024
CVE-2024-37091
9.9 CRITICAL

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in StylemixThemes Consulting Elementor Widgets, StylemixThemes Masterstudy Elementor Widgets allows OS Command Injection.This …

Jun 24, 2024
CVE-2024-37089
9.0 CRITICAL

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in StylemixThemes Consulting Elementor Widgets allows PHP Local File Inclusion.This issue affects Consulting …

Jun 24, 2024
CVE-2024-36038
6.3 MEDIUM

Zoho ManageEngine ITOM products versions from 128234 to 128248 are affected by the stored cross-site scripting vulnerability in the proxy server option.

Jun 24, 2024
CVE-2024-6160

SQL Injection vulnerability in MegaBIP software allows attacker to disclose the contents of the database, obtain session cookies or modify the content of pages. This …

Jun 24, 2024
CVE-2024-29868
9.1 CRITICAL

Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) vulnerability in Apache StreamPipes user self-registration and password recovery mechanism. This allows an attacker to guess the …

Jun 24, 2024
CVE-2024-5683
9.8 CRITICAL

Improper Control of Generation of Code ('Code Injection') vulnerability in Next4Biz CRM & BPM Software Business Process Manangement (BPM) allows Remote Code Inclusion.This issue affects …

Jun 24, 2024
CVE-2024-4754
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Next4Biz CRM & BPM Software Business Process Manangement (BPM) allows Stored XSS.This issue …

Jun 24, 2024
CVE-2024-36497
9.1 CRITICAL

The decrypted configuration file contains the password in cleartext which is used to configure WINSelect. It can be used to remove the existing restrictions and …

Jun 24, 2024
CVE-2024-36496
7.5 HIGH

The configuration file is encrypted with a static key derived from a static five-character password which allows an attacker to decrypt this file. The application …

Jun 24, 2024
CVE-2024-36495
7.7 HIGH

The application Faronics WINSelect (Standard + Enterprise) saves its configuration in an encrypted file on the file system which "Everyone" has read and write access …

Jun 24, 2024
CVE-2024-27136
6.1 MEDIUM

XSS in Upload page in Apache JSPWiki 2.12.1 and priors allows the attacker to execute javascript in the victim's browser and get some sensitive information …

Jun 24, 2024
CVE-2024-24554
8.2 HIGH

Bludit uses predictable methods in combination with the MD5 hashing algorithm to generate sensitive tokens such as the API token and the user token. This …

Jun 24, 2024
CVE-2024-4460

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 24, 2024
CVE-2024-24553
7.5 HIGH

Bludit uses the SHA-1 hashing algorithm to compute password hashes. Thus, attackers could determine cleartext passwords with brute-force attacks due to the inherent speed of …

Jun 24, 2024
CVE-2024-24552
8.8 HIGH

A session fixation vulnerability in Bludit allows an attacker to bypass the server's authentication if they can trick an administrator or any other user into …

Jun 24, 2024
CVE-2024-24551
8.8 HIGH

A security vulnerability has been identified in Bludit, allowing authenticated attackers to execute arbitrary code through the Image API. This vulnerability arises from improper handling …

Jun 24, 2024
CVE-2024-24550
8.1 HIGH

A security vulnerability has been identified in Bludit, allowing attackers with knowledge of the API token to upload arbitrary files through the File API which …

Jun 24, 2024
CVE-2024-4900
6.1 MEDIUM

The SEOPress WordPress plugin before 7.8 does not validate and escape one of its Post settings, which could allow contributor and above role to perform …

Jun 24, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.