CVE Database

39885+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-6508
8.0 HIGH

An insufficient entropy vulnerability was found in the Openshift Console. In the authorization code type and implicit grant type, the OAuth2 protocol is vulnerable to …

Aug 21, 2024
CVE-2024-38305
7.3 HIGH

Dell SupportAssist for Home PCs Installer exe version 4.0.3 contains a privilege escalation vulnerability in the installer. A local low-privileged authenticated attacker could potentially exploit …

Aug 21, 2024
CVE-2024-43882
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: exec: Fix ToCToU between perm check and set-uid/gid usage When opening a file for exec …

Aug 21, 2024
CVE-2024-43881
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: change DMA direction while mapping reinjected packets For fragmented packets, ath12k reassembles each …

Aug 21, 2024
CVE-2024-43878
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: xfrm: Fix input error path memory access When there is a misconfiguration of input state …

Aug 21, 2024
CVE-2024-43877
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: media: pci: ivtv: Add check for DMA map result In case DMA fails, 'dma->SG_length' is …

Aug 21, 2024
CVE-2024-43873
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: vhost/vsock: always initialize seqpacket_allow There are two issues around seqpacket_allow: 1. seqpacket_allow is not initialized …

Aug 21, 2024
CVE-2024-22281
7.5 HIGH

** UNSUPPORTED WHEN ASSIGNED ** The Apache Helix Front (UI) component contained a hard-coded secret, allowing an attacker to spoof sessions by generating their own …

Aug 20, 2024
CVE-2024-43403
8.8 HIGH

Kanister is a data protection workflow management tool. The kanister has a deployment called default-kanister-operator, which is bound with a ClusterRole called edit via ClusterRoleBinding. …

Aug 20, 2024
CVE-2024-42363
8.8 HIGH

Prior to 3385, the user-controlled role parameter enters the application in the Kubernetes::RoleVerificationsController. The role parameter flows into the RoleConfigFile initializer and then into the …

Aug 20, 2024
CVE-2024-42362
8.8 HIGH

Hertzbeat is an open source, real-time monitoring system. Hertzbeat has an authenticated (user role) RCE via unsafe deserialization in /api/monitors/import. This vulnerability is fixed in …

Aug 20, 2024
CVE-2024-42361
7.5 HIGH

Hertzbeat is an open source, real-time monitoring system. Hertzbeat 1.6.0 and earlier declares a /api/monitor/{monitorId}/metric/{metricFull} endpoint to download job metrics. In the process, it executes …

Aug 20, 2024
CVE-2024-41657
8.1 HIGH

Casdoor is a UI-first Identity and Access Management (IAM) / Single-Sign-On (SSO) platform. In Casdoor 1.577.0 and earlier, a logic vulnerability exists in the beego …

Aug 20, 2024
CVE-2024-41659
8.1 HIGH

memos is a privacy-first, lightweight note-taking service. A CORS misconfiguration exists in memos 0.20.1 and earlier where an arbitrary origin is reflected with Access-Control-Allow-Credentials set …

Aug 20, 2024
CVE-2024-31842
8.8 HIGH

An issue was discovered in Italtel Embrace 1.6.4. The web application inserts the access token of an authenticated user inside GET requests. The query string …

Aug 20, 2024
CVE-2024-42619
8.8 HIGH

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/domain_management.php?id=0&list=whitelist&remove=pligg.com

Aug 20, 2024
CVE-2024-42612
8.8 HIGH

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/domain_management.php?whitelist_add

Aug 20, 2024
CVE-2024-27187
7.5 HIGH

Improper Access Controls allows backend users to overwrite their username when disallowed.

Aug 20, 2024
CVE-2024-43406
8.8 HIGH

LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. A user could utilize and exploit SQL …

Aug 20, 2024
CVE-2024-42662
7.5 HIGH

An issue in apollocongif apollo v.2.2.0 allows a remote attacker to obtain sensitive information via a crafted request.

Aug 20, 2024
CVE-2024-42621
8.8 HIGH

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_editor.php

Aug 20, 2024
CVE-2024-42618
8.8 HIGH

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /module.php?module=karma

Aug 20, 2024
CVE-2024-42617
8.8 HIGH

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_config.php?action=save&var_id=32

Aug 20, 2024
CVE-2024-42616
8.8 HIGH

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_widgets.php?action=remove&widget=Statistics

Aug 20, 2024
CVE-2024-42613
8.8 HIGH

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_widgets.php?action=install&widget=akismet

Aug 20, 2024
CVE-2024-42611
8.8 HIGH

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/admin_page.php?link_id=1&mode=delete

Aug 20, 2024
CVE-2024-42610
8.8 HIGH

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=files

Aug 20, 2024
CVE-2024-42609
8.8 HIGH

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=avatars

Aug 20, 2024
CVE-2024-42607
8.8 HIGH

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=database

Aug 20, 2024
CVE-2024-42606
8.8 HIGH

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_log.php?clear=1

Aug 20, 2024
CVE-2024-42605
8.8 HIGH

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/edit_page.php?link_id=1

Aug 20, 2024
CVE-2024-42604
8.8 HIGH

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_group.php?mode=delete&group_id=3

Aug 20, 2024
CVE-2024-42603
8.8 HIGH

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/admin_backup.php?dobackup=clearall

Aug 20, 2024
CVE-2024-39690
8.4 HIGH

Capsule is a multi-tenancy and policy-based framework for Kubernetes. In Capsule v0.7.0 and earlier, the tenant-owner can patch any arbitrary namespace that has not been …

Aug 20, 2024
CVE-2024-8005
7.3 HIGH

A vulnerability was found in demozx gf_cms 1.0/1.0.1. It has been classified as critical. This affects the function init of the file internal/logic/auth/auth.go of the …

Aug 20, 2024
CVE-2024-6379
7.7 HIGH

A reflected Cross-site Scripting (XSS) vulnerability affecting 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in …

Aug 20, 2024
CVE-2024-6378
8.7 HIGH

A reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary …

Aug 20, 2024
CVE-2024-6377
8.1 HIGH

An URL redirection to untrusted site (open redirect) vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to …

Aug 20, 2024
CVE-2024-42608
8.8 HIGH

Pligg CMS v2.0.2 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/submit_page.php.

Aug 20, 2024
CVE-2024-42006
7.5 HIGH

Keyfactor AWS Orchestrator through 2.0 allows Information Disclosure.

Aug 20, 2024
CVE-2024-34458
7.5 HIGH

Keyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection which could result in information disclosure.

Aug 20, 2024
CVE-2024-6918
7.5 HIGH

CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists that could cause a crash of the Accutech Manager when receiving a …

Aug 20, 2024
CVE-2024-42586
8.8 HIGH

A Cross-Site Request Forgery (CSRF) in the component categorie.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.

Aug 20, 2024
CVE-2024-42585
8.8 HIGH

A Cross-Site Request Forgery (CSRF) in the component delete_media.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.

Aug 20, 2024
CVE-2024-42584
8.8 HIGH

A Cross-Site Request Forgery (CSRF) in the component delete_product.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.

Aug 20, 2024
CVE-2024-42583
8.8 HIGH

A Cross-Site Request Forgery (CSRF) in the component delete_user.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.

Aug 20, 2024
CVE-2024-42582
8.8 HIGH

A Cross-Site Request Forgery (CSRF) in the component delete_categorie.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.

Aug 20, 2024
CVE-2024-42581
8.8 HIGH

A Cross-Site Request Forgery (CSRF) in the component delete_group.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.

Aug 20, 2024
CVE-2024-42580
8.8 HIGH

A Cross-Site Request Forgery (CSRF) in the component edit_group.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.

Aug 20, 2024
CVE-2024-42579
8.8 HIGH

A Cross-Site Request Forgery (CSRF) in the component add_group.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.

Aug 20, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.