CVE Database

39885+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-8169
7.3 HIGH

A vulnerability was found in code-projects Online Quiz Site 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Aug 26, 2024
CVE-2024-8168
7.3 HIGH

A vulnerability was found in code-projects Online Bus Reservation Site 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Aug 26, 2024
CVE-2024-8167
7.3 HIGH

A vulnerability was found in code-projects Job Portal 1.0. It has been classified as critical. Affected is an unknown function of the file /forget.php. The …

Aug 26, 2024
CVE-2024-7987
7.8 HIGH

A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™ that allows a threat actor to execute arbitrary code with System privileges. To …

Aug 26, 2024
CVE-2024-43966
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stark Digital WP Testimonial Widget.This issue affects WP Testimonial Widget: from …

Aug 26, 2024
CVE-2024-44942
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to do sanity check on F2FS_INLINE_DATA flag in inode during GC syzbot reports …

Aug 26, 2024
CVE-2024-44941
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to cover read extent cache access with lock syzbot reports a f2fs bug …

Aug 26, 2024
CVE-2024-44940
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: fou: remove warn in gue_gro_receive on unsupported protocol Drop the WARN_ON_ONCE inn gue_gro_receive if the …

Aug 26, 2024
CVE-2024-41879
7.8 HIGH

Acrobat Reader versions 127.0.2651.105 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the …

Aug 26, 2024
CVE-2024-44934
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: bridge: mcast: wait for previous gc cycles when removing port syzbot hit a use-after-free[1] …

Aug 26, 2024
CVE-2024-44932
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: idpf: fix UAFs when destroying the queues The second tagged commit started sometimes (very rarely, …

Aug 26, 2024
CVE-2024-43900
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: media: xc2028: avoid use-after-free in load_firmware_cb() syzkaller reported use-after-free in load_firmware_cb() [1]. The reason is …

Aug 26, 2024
CVE-2024-43888
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: mm: list_lru: fix UAF for memory cgroup The mem_cgroup_from_slab_obj() is supposed to be called under …

Aug 26, 2024
CVE-2024-43444
8.2 HIGH

Passwords of agents and customers are displayed in plain text in the OTRS admin log module if certain configurations regarding the authentication sources match and …

Aug 26, 2024
CVE-2024-45241
7.5 HIGH

A traversal vulnerability in GeneralDocs.aspx in CentralSquare CryWolf (False Alarm Management) through 2024-08-09 allows unauthenticated attackers to read files outside of the working web directory …

Aug 26, 2024
CVE-2024-41996
7.5 HIGH

Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the …

Aug 26, 2024
CVE-2024-42340
8.3 HIGH

CyberArk - CWE-602: Client-Side Enforcement of Server-Side Security

Aug 25, 2024
CVE-2024-45240
7.4 HIGH

The TikTok (aka com.zhiliaoapp.musically) application before 34.5.5 for Android allows the takeover of Lynxview JavaScript interfaces via deeplink traversal (in the application's exposed WebView). (On …

Aug 24, 2024
CVE-2024-45239
7.5 HIGH

An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) …

Aug 24, 2024
CVE-2024-45238
7.5 HIGH

An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) …

Aug 24, 2024
CVE-2024-45236
7.5 HIGH

An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) …

Aug 24, 2024
CVE-2024-45235
7.5 HIGH

An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) …

Aug 24, 2024
CVE-2024-45234
7.5 HIGH

An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) …

Aug 24, 2024
CVE-2024-7656
8.8 HIGH

The Image Hotspot by DevVN plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.2.5 via deserialization of …

Aug 24, 2024
CVE-2024-7351
7.2 HIGH

The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.12.3 via deserialization of untrusted …

Aug 24, 2024
CVE-2024-45187
7.1 HIGH

Guest users in the Mage AI framework that remain logged in after their accounts are deleted, are mistakenly given high privileges and specifically given access …

Aug 23, 2024
CVE-2024-42845
8.0 HIGH

An eval Injection vulnerability in the component invesalius/reader/dicom.py of InVesalius 3.1.99991 through 3.1.99998 allows attackers to execute arbitrary code via loading a crafted DICOM file.

Aug 23, 2024
CVE-2024-44390
8.8 HIGH

Tenda FH1206 V1.2.0.8(8155)_EN contains a Buffer Overflow vulnerability via the function formWrlsafeset.

Aug 23, 2024
CVE-2024-39841
8.8 HIGH

A SQL Injection vulnerability exists in the service configuration functionality in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before …

Aug 23, 2024
CVE-2024-44386
7.3 HIGH

Tenda FH1206 V1.2.0.8(8155)_EN contains a Buffer Overflow vulnerability via the function fromSetIpBind.

Aug 23, 2024
CVE-2024-42756
8.8 HIGH

An issue in Netgear DGN1000WW v.1.1.00.45 allows a remote attacker to execute arbitrary code via the Diagnostics page

Aug 23, 2024
CVE-2024-42636
7.2 HIGH

DedeCMS V5.7.115 has a command execution vulnerability via file_manage_view.php?fmdo=newfile&activepath.

Aug 23, 2024
CVE-2024-42523
7.2 HIGH

publiccms V4.0.202302.e and before is vulnerable to Any File Upload via publiccms/admin/cmsTemplate/saveMetaData

Aug 23, 2024
CVE-2024-43791
7.8 HIGH

RequestStore provides per-request global storage for Rack. The files published as part of request_store 1.3.2 have 0666 permissions, meaning that they are world-writable, which allows …

Aug 23, 2024
CVE-2024-43782
7.7 HIGH

This openedx-translations repository contains translation files from Open edX repositories to be kept in sync with Transifex. Before moving to pulling translations from the openedx-translations …

Aug 23, 2024
CVE-2024-42915
8.0 HIGH

A host header injection vulnerability in Staff Appraisal System v1.0 allows attackers to obtain the password reset token via user interaction with a crafted password …

Aug 23, 2024
CVE-2024-42040
8.1 HIGH

Buffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from its initial commit in 2002 (3861aa5) up to today on any platform allows an attacker …

Aug 23, 2024
CVE-2024-38869
8.3 HIGH

Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability in remote office deploy configurations.This issue affects Endpoint Central: before 11.3.2416.04 and before 11.3.2400.25.

Aug 23, 2024
CVE-2024-37311
8.2 HIGH

Collabora Online is a collaborative online office suite based on LibreOffice. In affected versions of Collabora Online, https connections from coolwsd to other hosts may …

Aug 23, 2024
CVE-2024-5586
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injection in extranet lockouts report option.

Aug 23, 2024
CVE-2024-5556
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in reports module.

Aug 23, 2024
CVE-2024-5490
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in aggregate reports option.

Aug 23, 2024
CVE-2024-5467
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injection in account lockout report.

Aug 23, 2024
CVE-2024-5466
8.8 HIGH

Zohocorp ManageEngine OpManager and Remote Monitoring and Management versions 128329 and below are vulnerable to the authenticated remote code execution in the deploy agent option.

Aug 23, 2024
CVE-2024-36517
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in alerts module.

Aug 23, 2024
CVE-2024-36516
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in dashboard. Note: This vulnerability is different from another vulnerability (CVE-2024-36515), …

Aug 23, 2024
CVE-2024-36515
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in dashboard. Note: This vulnerability is different from another vulnerability (CVE-2024-36516), …

Aug 23, 2024
CVE-2024-36514
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in file summary option.

Aug 23, 2024
CVE-2024-43883
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: usb: vhci-hcd: Do not drop references before new references are gained At a few places …

Aug 23, 2024
CVE-2024-7986
7.5 HIGH

A vulnerability exists in the Rockwell Automation ThinManager® ThinServer that allows a threat actor to disclose sensitive information. A threat actor can exploit this vulnerability …

Aug 23, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.