CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-37306
7.1 HIGH

Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. Starting in version 2.2.0 and prior to version 2.14.3, …

Jun 13, 2024
CVE-2024-37164
7.1 HIGH

Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. CVAT allows users to supply custom endpoint URLs for …

Jun 13, 2024
CVE-2024-37131
7.5 HIGH

SCG Policy Manager, all versions, contains an overly permissive Cross-Origin Resource Policy (CORP) vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to …

Jun 13, 2024
CVE-2024-29168
5.4 MEDIUM

Dell SCG, versions prior to 5.22.00.00, contain a SQL Injection Vulnerability in the SCG UI for an internal assets REST API. A remote authenticated attacker …

Jun 13, 2024
CVE-2024-28969
4.3 MEDIUM

Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an internal update REST API (if enabled by …

Jun 13, 2024
CVE-2024-28968
5.4 MEDIUM

Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for internal email and collection settings REST APIs (if …

Jun 13, 2024
CVE-2024-28967
5.4 MEDIUM

Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an internal maintenance REST API (if enabled by …

Jun 13, 2024
CVE-2024-28966
5.4 MEDIUM

Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an internal update REST API (if enabled by …

Jun 13, 2024
CVE-2024-28965
5.4 MEDIUM

Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an internal enable REST API (if enabled by …

Jun 13, 2024
CVE-2021-4237

Rejected reason: reserved but not needed

Jun 13, 2024
CVE-2024-37849
9.8 CRITICAL

A SQL Injection vulnerability in itsourcecode Billing System 1.0 allows a local attacker to execute arbitrary code in process.php via the username parameter.

Jun 13, 2024
CVE-2024-37309
5.3 MEDIUM

CrateDB is a distributed SQL database. A high-risk vulnerability has been identified in versions prior to 5.7.2 where the TLS endpoint (port 4200) permits client-initiated …

Jun 13, 2024
CVE-2024-37308
5.4 MEDIUM

The Cooked Pro recipe plugin for WordPress is vulnerable to Persistent Cross-Site Scripting (XSS) via the `_recipe_settings[post_title]` parameter in versions up to, and including, 1.7.15.4 …

Jun 13, 2024
CVE-2024-36647
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in Church CRM v5.8.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into …

Jun 13, 2024
CVE-2024-25052
4.4 MEDIUM

IBM Jazz Reporting Service 7.0.3 stores user credentials in plain clear text which can be read by an admin user. IBM X-Force ID: 283363.

Jun 13, 2024
CVE-2024-22333
3.3 LOW

IBM Maximo Asset Management 7.6.1.3 and IBM Maximo Application Suite 8.10 and 8.11 allows web pages to be stored locally which can be read by …

Jun 13, 2024
CVE-2024-36396
8.8 HIGH

Verint - CWE-434: Unrestricted Upload of File with Dangerous Type

Jun 13, 2024
CVE-2024-36395
6.1 MEDIUM

Verint - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

Jun 13, 2024
CVE-2024-32860
7.5 HIGH

Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit …

Jun 13, 2024
CVE-2024-32859
7.5 HIGH

Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit …

Jun 13, 2024
CVE-2024-32858
7.5 HIGH

Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit …

Jun 13, 2024
CVE-2024-34130
5.5 MEDIUM

Acrobat Mobile Sign Android versions 24.4.2.33155 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker …

Jun 13, 2024
CVE-2024-34129
7.5 HIGH

Acrobat Mobile Sign Android versions 24.4.2.33155 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that …

Jun 13, 2024
CVE-2024-34116
7.1 HIGH

Creative Cloud Desktop versions 6.1.0.587 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in a security feature bypass. An …

Jun 13, 2024
CVE-2024-34115
7.8 HIGH

Substance3D - Stager versions 2.1.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Jun 13, 2024
CVE-2024-34113
5.5 MEDIUM

ColdFusion versions 2023u7, 2021u13 and earlier are affected by a Weak Cryptography for Passwords vulnerability that could result in a security feature bypass. This vulnerability …

Jun 13, 2024
CVE-2024-34112
7.5 HIGH

ColdFusion versions 2023u7, 2021u13 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could …

Jun 13, 2024
CVE-2024-32856
5.1 MEDIUM

Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit …

Jun 13, 2024
CVE-2024-30472
7.5 HIGH

Telemetry Dashboard v1.0.0.8 for Dell ThinOS 2402 contains a sensitive information disclosure vulnerability. An unauthenticated user with local access to the device could exploit this …

Jun 13, 2024
CVE-2024-30300
9.8 CRITICAL

Adobe Framemaker Publishing Server versions 2020.3, 2022.2 and earlier are affected by an Information Exposure vulnerability (CWE-200) that could lead to privilege escalation. An attacker …

Jun 13, 2024
CVE-2024-30299
10.0 CRITICAL

Adobe Framemaker Publishing Server versions 2020.3, 2022.2 and earlier are affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could …

Jun 13, 2024
CVE-2024-20753
7.8 HIGH

Photoshop Desktop versions 24.7.3, 25.7 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read …

Jun 13, 2024
CVE-2024-5927

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 13, 2024
CVE-2024-30278
5.5 MEDIUM

Media Encoder versions 23.6.5, 24.3 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker …

Jun 13, 2024
CVE-2024-4371
9.0 CRITICAL

The CoDesigner WooCommerce Builder for Elementor – Customize Checkout, Shop, Email, Products & More plugin for WordPress is vulnerable to PHP Object Injection in all …

Jun 13, 2024
CVE-2024-4176
4.1 MEDIUM

An Cross site scripting vulnerability in the EDR XConsole before this release allowed an attacker to potentially leverage an XSS/HTML-Injection using command line variables. A …

Jun 13, 2024
CVE-2024-3073
2.7 LOW

The Easy WP SMTP by SendLayer – WordPress SMTP and Email Log Plugin plugin for WordPress is vulnerable to information exposure in all versions up …

Jun 13, 2024
CVE-2024-34111
6.5 MEDIUM

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system …

Jun 13, 2024
CVE-2024-34110
7.2 HIGH

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in …

Jun 13, 2024
CVE-2024-34109
7.2 HIGH

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in …

Jun 13, 2024
CVE-2024-34108
9.1 CRITICAL

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in …

Jun 13, 2024
CVE-2024-34107
5.3 MEDIUM

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. …

Jun 13, 2024
CVE-2024-34106
5.3 MEDIUM

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. An …

Jun 13, 2024
CVE-2024-34105
4.8 MEDIUM

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an admin …

Jun 13, 2024
CVE-2024-34104
8.2 HIGH

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. An …

Jun 13, 2024
CVE-2024-34103
8.1 HIGH

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could …

Jun 13, 2024
CVE-2024-34102
9.8 CRITICAL KEV

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result …

Jun 13, 2024
CVE-2024-30285
5.5 MEDIUM

Audition versions 24.2, 23.6.4 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service condition. An attacker could …

Jun 13, 2024
CVE-2024-30276
5.5 MEDIUM

Audition versions 24.2, 23.6.4 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Jun 13, 2024
CVE-2024-1565
6.4 MEDIUM

The EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor plugin for WordPress is vulnerable …

Jun 13, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.