CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-5496
8.8 HIGH

Use after free in Media Session in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to execute arbitrary code inside a sandbox via a …

May 30, 2024
CVE-2024-5495
8.8 HIGH

Use after free in Dawn in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

May 30, 2024
CVE-2024-5494
8.8 HIGH

Use after free in Dawn in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

May 30, 2024
CVE-2024-5493
8.8 HIGH

Heap buffer overflow in WebRTC in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

May 30, 2024
CVE-2024-36119
1.8 LOW

Statamic is a, Laravel + Git powered CMS designed for building websites. In affected versions users registering via the `user:register_form` tag will have their password …

May 30, 2024
CVE-2024-1298
6.0 MEDIUM

EDK2 contains a vulnerability when S3 sleep is activated where an Attacker may cause a Division-By-Zero due to a UNIT32 overflow via local access. A …

May 30, 2024
CVE-2024-5271
7.8 HIGH

Fuji Electric Monitouch V-SFT is vulnerable to an out-of-bounds write because of a type confusion, which could result in arbitrary code execution.

May 30, 2024
CVE-2024-35189
6.5 MEDIUM

Fides is an open-source privacy engineering platform. The Fides webserver has a number of endpoints that retrieve `ConnectionConfiguration` records and their associated `secrets` which _can_ …

May 30, 2024
CVE-2024-34171
7.8 HIGH

Fuji Electric Monitouch V-SFT is vulnerable to a stack-based buffer overflow, which could allow an attacker to execute arbitrary code.

May 30, 2024
CVE-2024-32877
4.2 MEDIUM

Yii 2 is a PHP application framework. During internal penetration testing of a product based on Yii2, users discovered a Cross-site Scripting (XSS) vulnerability within …

May 30, 2024
CVE-2024-35228
5.5 MEDIUM

Wagtail is an open source content management system built on Django. Due to an improperly applied permission check in the `wagtail.contrib.settings` module, a user with …

May 30, 2024
CVE-2024-35469
9.8 CRITICAL

A SQL injection vulnerability in /hrm/user/ in SourceCodester Human Resource Management System 1.0 allows attackers to execute arbitrary SQL commands via the password parameter.

May 30, 2024
CVE-2024-35468
5.4 MEDIUM

A SQL injection vulnerability in /hrm/index.php in SourceCodester Human Resource Management System 1.0 allows attackers to execute arbitrary SQL commands via the password parameter.

May 30, 2024
CVE-2024-35433
8.1 HIGH

ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Incorrect Access Control. An authenticated user, without the permissions of managing users, can create a new admin user.

May 30, 2024
CVE-2024-2422
8.8 HIGH

LenelS2 NetBox access control and event monitoring system was discovered to contain an authenticated RCE in versions prior to and including 5.6.1, which allows an …

May 30, 2024
CVE-2024-2421
9.8 CRITICAL

LenelS2 NetBox access control and event monitoring system was discovered to contain an unauthenticated RCE in versions prior to and including 5.6.1, which allows an …

May 30, 2024
CVE-2024-2420
9.8 CRITICAL

LenelS2 NetBox access control and event monitoring system was discovered to contain Hardcoded Credentials in versions prior to and including 5.6.1 which allows an attacker …

May 30, 2024
CVE-2024-5537

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

May 30, 2024
CVE-2024-36118
3.5 LOW

MeterSphere is a test management and interface testing tool. In affected versions users without workspace permissions can view functional test cases of other workspaces beyond …

May 30, 2024
CVE-2024-35431
7.5 HIGH

ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via photoBase64. An unauthenticated user can download local files from the server. NOTE: Third parties have …

May 30, 2024
CVE-2024-35429
6.5 MEDIUM

ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via eventRecord.

May 30, 2024
CVE-2024-35428
7.1 HIGH

ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via BaseMediaFile. An authenticated user can delete local files from the server which can lead to …

May 30, 2024
CVE-2024-35359
9.8 CRITICAL

A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Master.php?f=view_item. Manipulating the argument …

May 30, 2024
CVE-2024-35353
9.8 CRITICAL

A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /classes/Users.php?f=save. Manipulating the argument …

May 30, 2024
CVE-2024-35352
6.1 MEDIUM

A vulnerability has been discovered in Diño Physics School Assistant version 2.3. This vulnerability impacts unidentified code within the file /classes/Users.php?f=save. Manipulating the parameter middlename …

May 30, 2024
CVE-2024-35351
5.4 MEDIUM

A vulnerability has been discovered in Diño Physics School Assistant version 2.3. This vulnerability impacts unidentified code within the file /classes/SystemSettings.php?f=update_settings. Manipulating the parameter name …

May 30, 2024
CVE-2024-35350
9.8 CRITICAL

A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /admin/?page=borrow/view_borrow. Manipulating the argument …

May 30, 2024
CVE-2024-35349
9.8 CRITICAL

A vulnerability has been discovered in Diño Physics School Assistant version 2.3. The vulnerability impacts an unidentified code within the file /admin/category/view_category.php. Manipulating the argument …

May 30, 2024
CVE-2024-5519
7.3 HIGH

A vulnerability classified as critical was found in ItsourceCode Learning Management System Project In PHP 1.0. This vulnerability affects unknown code of the file login.php. …

May 30, 2024
CVE-2024-5518
6.3 MEDIUM

A vulnerability classified as critical has been found in itsourcecode Online Discussion Forum 1.0. This affects an unknown part of the file change_profile_picture.php. The manipulation …

May 30, 2024
CVE-2024-3301
8.5 HIGH

An unsafe .NET object deserialization vulnerability in DELMIA Apriso Release 2019 through Release 2024 could lead to post-authentication remote code execution.

May 30, 2024
CVE-2024-3300
9.0 CRITICAL

An unsafe .NET object deserialization vulnerability in DELMIA Apriso Release 2019 through Release 2024 could lead to pre-authentication remote code execution.

May 30, 2024
CVE-2024-36959
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: pinctrl: devicetree: fix refcount leak in pinctrl_dt_to_map() If we fail to allocate propname buffer, we …

May 30, 2024
CVE-2024-36958
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix nfsd4_encode_fattr4() crasher Ensure that args.acl is initialized early. It is used in an …

May 30, 2024
CVE-2024-36957
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: octeontx2-af: avoid off-by-one read from userspace We try to access count + 1 byte from …

May 30, 2024
CVE-2024-36956
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: thermal/debugfs: Free all thermal zone debug memory on zone removal Because thermal_debug_tz_remove() does not free …

May 30, 2024
CVE-2024-36955
7.7 HIGH

In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: intel-sdw-acpi: fix usage of device_get_named_child_node() The documentation for device_get_named_child_node() mentions this important point: …

May 30, 2024
CVE-2024-36954
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tipc: fix a possible memleak in tipc_buf_append __skb_linearize() doesn't free the skb when it fails, …

May 30, 2024
CVE-2024-36953
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-v2: Check for non-NULL vCPU in vgic_v2_parse_attr() vgic_v2_parse_attr() is responsible for finding the …

May 30, 2024
CVE-2024-36952
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Move NPIV's transport unregistration to after resource clean up There are cases after …

May 30, 2024
CVE-2024-36951
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: range check cp bad op exception interrupts Due to a CP interrupt bug, bad …

May 30, 2024
CVE-2024-36950
4.4 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: firewire: ohci: mask bus reset interrupts between ISR and bottom half In the FireWire OHCI …

May 30, 2024
CVE-2024-36949
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: amd/amdkfd: sync all devices to wait all processes being evicted If there are more than …

May 30, 2024
CVE-2024-36948
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/xe/xe_migrate: Cast to output precision before multiplying operands Addressing potential overflow in result of multiplication …

May 30, 2024
CVE-2024-36947
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: qibfs: fix dentry leak simple_recursive_removal() drops the pinning references to all positives in subtree. For …

May 30, 2024
CVE-2024-36946
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: phonet: fix rtm_phonet_notify() skb allocation fill_route() stores three components in the skb: - struct rtmsg …

May 30, 2024
CVE-2024-36945
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/smc: fix neighbour and rtable leak in smc_ib_find_route() In smc_ib_find_route(), the neighbour found by neigh_lookup() …

May 30, 2024
CVE-2024-36944
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Reapply "drm/qxl: simplify qxl_fence_wait" This reverts commit 07ed11afb68d94eadd4ffc082b97c2331307c5ea. Stephen Rostedt reports: "I went to run …

May 30, 2024
CVE-2024-36943
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fs/proc/task_mmu: fix loss of young/dirty bits during pagemap scan make_uffd_wp_pte() was previously doing: pte = …

May 30, 2024
CVE-2024-36942

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

May 30, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.