CVE Database

39885+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-34974
8.8 HIGH

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands …

Sep 6, 2024
CVE-2024-8509
7.5 HIGH

A vulnerability was found in Forklift Controller. There is no verification against the authorization header except to ensure it uses bearer authentication. Without an Authorization …

Sep 6, 2024
CVE-2024-45294
8.6 HIGH

The HL7 FHIR Core Artifacts repository provides the java core object handling code, with utilities (including validator), for the Fast Healthcare Interoperability Resources (FHIR) specification. …

Sep 6, 2024
CVE-2024-44408
7.5 HIGH

D-Link DIR-823G v1.0.2B05_20181207 is vulnerable to Information Disclosure. The device allows unauthorized configuration file downloads, and the downloaded configuration files contain plaintext user passwords.

Sep 6, 2024
CVE-2024-8428
8.8 HIGH

The ForumWP – Forum & Discussion Board Plugin plugin for WordPress is vulnerable to Privilege Escalation via Insecure Direct Object Reference in all versions up …

Sep 6, 2024
CVE-2024-6445
7.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in DataFlowX Technology DataDiodeX allows Path Traversal.This issue affects DataDiodeX: from v3.0.0 before …

Sep 6, 2024
CVE-2024-45300
7.5 HIGH

alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5, a race condition allows the user …

Sep 6, 2024
CVE-2024-44739
8.8 HIGH

Sourcecodester Simple Forum Website v1.0 has a SQL injection vulnerability in /php-sqlite-forum/?page=manage_user&id=.

Sep 6, 2024
CVE-2024-1744
7.5 HIGH

Authorization Bypass Through User-Controlled Key, Missing Authorization vulnerability in Ariva Computer Accord ORS allows Retrieve Embedded Sensitive Data.This issue affects Accord ORS: before 7.3.2.1.

Sep 6, 2024
CVE-2023-52916
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: media: aspeed: Fix memory overwrite if timing is 1600x900 When capturing 1600x900, system could crash …

Sep 6, 2024
CVE-2024-7349
7.2 HIGH

The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to blind SQL Injection via the 'order' parameter in …

Sep 6, 2024
CVE-2024-39585
7.9 HIGH

Dell SmartFabric OS10 Software, version(s) 10.5.5.4 through 10.5.5.10 and 10.5.6.x, contain(s) an Use of Hard-coded Password vulnerability. A low privileged attacker with remote access could …

Sep 6, 2024
CVE-2024-38486
7.5 HIGH

Dell SmartFabric OS10 Software, version(s) 10.5.5.4 through 10.5.5.10 and 10.5.6.x , contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. …

Sep 6, 2024
CVE-2024-8480
8.8 HIGH

The Image Optimizer, Resizer and CDN – Sirv plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on …

Sep 6, 2024
CVE-2024-8247
8.8 HIGH

The Newsletters plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.9.9.2. This is due to the plugin not …

Sep 6, 2024
CVE-2024-45401
7.5 HIGH

stripe-cli is a command-line tool for the payment processor Stripe. A vulnerability exists in stripe-cli starting in version 1.11.1 and prior to version 1.21.3 where …

Sep 5, 2024
CVE-2024-45392
7.7 HIGH

SuiteCRM is an open-source customer relationship management (CRM) system. Prior to version 7.14.5 and 8.6.2, insufficient access control checks allow a threat actor to delete …

Sep 5, 2024
CVE-2024-45175
8.8 HIGH

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Sensitive information is stored in cleartext. It was found out that sensitive information, for example …

Sep 5, 2024
CVE-2024-45171
8.8 HIGH

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper user input validation, it is possible to upload dangerous files, for instance …

Sep 5, 2024
CVE-2024-45178
7.1 HIGH

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper user input validation, it is possible to download arbitrary files from the …

Sep 5, 2024
CVE-2024-45173
8.8 HIGH

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper privilege management concerning sudo privileges, C-MOR is vulnerable to a privilege escalation …

Sep 5, 2024
CVE-2024-44587
8.8 HIGH

itsourcecode Alton Management System 1.0 is vulnerable to SQL Injection in /noncombo_save.php via the "menu" parameter.

Sep 5, 2024
CVE-2024-7884
7.5 HIGH

When a canister method is called via ic_cdk::call* , a new Future CallFuture is created and can be awaited by the caller to get the …

Sep 5, 2024
CVE-2024-8178
8.8 HIGH

The ctl_write_buffer and ctl_read_buffer functions allocated memory to be returned to userspace, without initializing it. Malicious software running in a guest VM that exposes virtio_scsi …

Sep 5, 2024
CVE-2024-45063
8.8 HIGH

The function ctl_write_buffer incorrectly set a flag which resulted in a kernel Use-After-Free when a command finished processing. Malicious software running in a guest VM …

Sep 5, 2024
CVE-2024-43110
8.8 HIGH

The ctl_request_sense function could expose up to three bytes of the kernel heap to userspace. Malicious software running in a guest VM that exposes virtio_scsi …

Sep 5, 2024
CVE-2024-42416
8.8 HIGH

The ctl_report_supported_opcodes function did not sufficiently validate a field provided by userspace, allowing an arbitrary write to a limited amount of kernel help memory. Malicious …

Sep 5, 2024
CVE-2024-32668
8.2 HIGH

An insufficient boundary validation in the USB code could lead to an out-of-bounds write on the heap, with data controlled by the caller. A malicious, …

Sep 5, 2024
CVE-2024-45288
8.4 HIGH

A missing null-termination character in the last element of an nvlist array string can lead to writing outside the allocated buffer.

Sep 5, 2024
CVE-2024-45287
7.5 HIGH

A malicious value of size in a structure of packed libnv can cause an integer overflow, leading to the allocation of a smaller buffer than …

Sep 5, 2024
CVE-2024-41928
8.4 HIGH

Malicious software running in a guest VM can exploit the buffer overflow to achieve code execution on the host in the bhyve userspace process, which …

Sep 5, 2024
CVE-2024-7627
8.1 HIGH

The Bit File Manager plugin for WordPress is vulnerable to Remote Code Execution in versions 6.0 to 6.5.5 via the 'checkSyntax' function. This is due …

Sep 5, 2024
CVE-2024-45692
7.5 HIGH

Webmin before 2.202 and Virtualmin before 7.20.2 allow a network traffic loop via spoofed UDP packets on port 10000.

Sep 4, 2024
CVE-2024-2166
8.8 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Email Security (Real Time Monitor modules) allows Reflected XSS.This issue affects Email …

Sep 4, 2024
CVE-2024-44999
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: gtp: pull network headers in gtp_dev_xmit() syzbot/KMSAN reported use of uninit-value in get_dev_xmit() [1] We …

Sep 4, 2024
CVE-2024-44998
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: atm: idt77252: prevent use after free in dequeue_rx() We can't dereference "skb" after calling vcc->push() …

Sep 4, 2024
CVE-2024-44997
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk_wed: fix use-after-free panic in mtk_wed_setup_tc_block_cb() When there are multiple ap interfaces on …

Sep 4, 2024
CVE-2024-44993
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Fix out-of-bounds read in `v3d_csd_job_run()` When enabling UBSAN on Raspberry Pi 5, we get …

Sep 4, 2024
CVE-2024-44987
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ipv6: prevent UAF in ip6_send_skb() syzbot reported an UAF in ip6_send_skb() [1] After ip6_local_out() has …

Sep 4, 2024
CVE-2024-44986
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ipv6: fix possible UAF in ip6_finish_output2() If skb_expand_head() returns NULL, skb has been freed and …

Sep 4, 2024
CVE-2024-44985
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ipv6: prevent possible UAF in ip6_xmit() If skb_expand_head() returns NULL, skb has been freed and …

Sep 4, 2024
CVE-2024-44983
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: validate vlan header Ensure there is sufficient room to access the protocol field …

Sep 4, 2024
CVE-2024-44978
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/xe: Free job before xe_exec_queue_put Free job depends on job->vm being valid, the last xe_exec_queue_put …

Sep 4, 2024
CVE-2024-44977
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Validate TA binary size Add TA binary size validation to avoid OOB write. (cherry …

Sep 4, 2024
CVE-2024-44974
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: avoid possible UaF when selecting endp select_local_address() and select_signal_address() both select an endpoint …

Sep 4, 2024
CVE-2024-44967
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/mgag200: Bind I2C lifetime to DRM device Managed cleanup with devm_add_action_or_reset() will release the I2C …

Sep 4, 2024
CVE-2024-44964
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: idpf: fix memory leaks and crashes while performing a soft reset The second tagged commit …

Sep 4, 2024
CVE-2024-44951
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: serial: sc16is7xx: fix TX fifo corruption Sometimes, when a packet is received on channel A …

Sep 4, 2024
CVE-2024-44949
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: parisc: fix a possible DMA corruption ARCH_DMA_MINALIGN was defined as 16 - this is too …

Sep 4, 2024
CVE-2024-45174
8.1 HIGH

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to improper validation of user-supplied data, different functionalities of the C-MOR web …

Sep 4, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.