CVE Database

39885+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-5760
7.8 HIGH

The Samsung Universal Print Driver for Windows is potentially vulnerable to escalation of privilege allowing the creation of a reverse shell in the tool. This …

Sep 11, 2024
CVE-2024-45026
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: s390/dasd: fix error recovery leading to data corruption on ESE devices Extent Space Efficient (ESE) …

Sep 11, 2024
CVE-2024-45023
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: md/raid1: Fix data corruption for degraded array with slow disk read_balance() will avoid reading from …

Sep 11, 2024
CVE-2024-39378
7.8 HIGH

Audition versions 24.4.1, 23.6.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the …

Sep 11, 2024
CVE-2024-8306
7.8 HIGH

CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentiality, integrity and availability of the workstation when non-admin authenticated user tries …

Sep 11, 2024
CVE-2024-8642
8.1 HIGH

In Eclipse Dataspace Components, from version 0.5.0 and before version 0.9.0, the ConsumerPullTransferTokenValidationApiController does not check for token validity (expiry, not-before, issuance date), which can …

Sep 11, 2024
CVE-2024-8639
8.8 HIGH

Use after free in Autofill in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a crafted …

Sep 11, 2024
CVE-2024-8638
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium …

Sep 11, 2024
CVE-2024-8637
8.8 HIGH

Use after free in Media Router in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a …

Sep 11, 2024
CVE-2024-8636
8.8 HIGH

Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Sep 11, 2024
CVE-2024-7609
7.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Vidco Software VOC TESTER allows Path Traversal.This issue affects VOC TESTER: before …

Sep 11, 2024
CVE-2024-45788
7.5 HIGH

This vulnerability exists in Reedos aiM-Star version 2.0.1 due to missing rate limiting on OTP requests in certain API endpoints. An authenticated remote attacker could …

Sep 11, 2024
CVE-2024-45327
7.5 HIGH

An improper authorization vulnerability [CWE-285] in FortiSOAR version 7.4.0 through 7.4.3, 7.3.0 through 7.3.2, 7.2.0 through 7.2.2, 7.0.0 through 7.0.3 change password endpoint may allow …

Sep 11, 2024
CVE-2024-7626
8.1 HIGH

The WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) plugin for WordPress is vulnerable to arbitrary file movement and reading due to …

Sep 11, 2024
CVE-2024-43690
8.0 HIGH

Inclusion of Functionality from Untrusted Control Sphere(CWE-829) in the Command Centre Server and Workstations may allow an attacker to perform Remote Code Execution (RCE). This …

Sep 11, 2024
CVE-2024-21529
8.2 HIGH

Versions of the package dset before 3.1.4 are vulnerable to Prototype Pollution via the dset function due improper user input sanitization. This vulnerability allows the …

Sep 11, 2024
CVE-2024-8253
8.8 HIGH

The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to privilege escalation in all versions 2.2.87 to 2.2.90. This is due to the …

Sep 11, 2024
CVE-2024-40662
7.8 HIGH

In scheme of Uri.java, there is a possible way to craft a malformed Uri object due to improper input validation. This could lead to local …

Sep 11, 2024
CVE-2024-40658
7.8 HIGH

In getConfig of SoftVideoDecoderOMXComponent.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of …

Sep 11, 2024
CVE-2024-40657
7.8 HIGH

In addPreferencesForType of AccountTypePreferenceLoader.java, there is a possible way to disable apps for other users due to a confused deputy. This could lead to local …

Sep 11, 2024
CVE-2024-40655
7.8 HIGH

In bindAndGetCallIdentification of CallScreeningServiceHelper.java, there is a possible way to maintain a while-in-use permission in the background due to a permissions bypass. This could lead …

Sep 11, 2024
CVE-2024-40654
7.8 HIGH

In multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional …

Sep 11, 2024
CVE-2024-40652
7.8 HIGH

In onCreate of SettingsHomepageActivity.java, there is a possible way to access the Settings app while the device is provisioning due to a missing permission check. …

Sep 11, 2024
CVE-2024-40650
7.8 HIGH

In wifi_item_edit_content of styles.xml , there is a possible FRP bypass due to Missing check for FRP state. This could lead to local escalation of …

Sep 11, 2024
CVE-2024-31336
7.8 HIGH

In PVRSRVBridgeRGXKickTA3D2 of server_rgxta3d_bridge.c, there is a possible arbitrary code execution due to improper input validation. This could lead to local escalation of privilege in …

Sep 11, 2024
CVE-2024-23716
7.0 HIGH

In DevmemIntPFNotify of devicemem_server.c, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege in the kernel …

Sep 11, 2024
CVE-2024-8191
7.8 HIGH

SQL injection in the management console of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote …

Sep 10, 2024
CVE-2024-8190
7.2 HIGH KEV

An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to obtain remote code …

Sep 10, 2024
CVE-2024-8012
7.8 HIGH

An authentication bypass weakness in the message broker service of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their …

Sep 10, 2024
CVE-2024-44107
8.8 HIGH

DLL hijacking in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges and achieve …

Sep 10, 2024
CVE-2024-44106
8.8 HIGH

Insufficient server-side controls in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges.

Sep 10, 2024
CVE-2024-44105
8.2 HIGH

Cleartext transmission of sensitive information in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to obtain OS …

Sep 10, 2024
CVE-2024-44104
8.8 HIGH

An incorrectly implemented authentication scheme that is subjected to a spoofing attack in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows …

Sep 10, 2024
CVE-2024-44103
8.8 HIGH

DLL hijacking in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges.

Sep 10, 2024
CVE-2024-8504
8.8 HIGH

An attacker with authenticated access to VICIdial as an "agent" can execute arbitrary shell commands as the "root" user. This attack can be chained with …

Sep 10, 2024
CVE-2024-8232
7.5 HIGH

SpiderControl SCADA Web Server has a vulnerability that could allow an attacker to upload specially crafted malicious files without authentication.

Sep 10, 2024
CVE-2024-45596
7.4 HIGH

Directus is a real-time API and App dashboard for managing SQL database content. An unauthenticated user can access credentials of last authenticated user via OpenID …

Sep 10, 2024
CVE-2024-44871
7.2 HIGH

An arbitrary file upload vulnerability in the component /admin/index.php of moziloCMS v3.0 allows attackers to execute arbitrary code via uploading a crafted file.

Sep 10, 2024
CVE-2024-44667
8.0 HIGH

Shenzhen Haichangxing Technology Co., Ltd HCX H822 4G LTE Router M7628NNxISPxUIv2_v1.0.1557.15.35_P0 is vulnerable to Incorrect Access Control. Unauthenticated factory mode reset and command injection leads …

Sep 10, 2024
CVE-2024-43495
7.3 HIGH

Windows libarchive Remote Code Execution Vulnerability

Sep 10, 2024
CVE-2024-43492
7.8 HIGH

Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability

Sep 10, 2024
CVE-2024-43479
8.5 HIGH

Microsoft Power Automate Desktop Remote Code Execution Vulnerability

Sep 10, 2024
CVE-2024-43476
7.6 HIGH

Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

Sep 10, 2024
CVE-2024-43475
7.3 HIGH

Microsoft Windows Admin Center Information Disclosure Vulnerability

Sep 10, 2024
CVE-2024-43474
7.6 HIGH

Microsoft SQL Server Information Disclosure Vulnerability

Sep 10, 2024
CVE-2024-43470
7.3 HIGH

Azure Network Watcher VM Agent Elevation of Privilege Vulnerability

Sep 10, 2024
CVE-2024-43469
8.8 HIGH

Azure CycleCloud Remote Code Execution Vulnerability

Sep 10, 2024
CVE-2024-43467
7.5 HIGH

Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability

Sep 10, 2024
CVE-2024-43465
7.8 HIGH

Microsoft Excel Elevation of Privilege Vulnerability

Sep 10, 2024
CVE-2024-43464
7.2 HIGH

Microsoft SharePoint Server Remote Code Execution Vulnerability

Sep 10, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.