CVE Database

39885+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-37928
8.6 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in NooTheme Jobmonster allows File Manipulation.This issue affects Jobmonster: from n/a through 4.7.0.

Jul 12, 2024
CVE-2024-37564
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PayPlus LTD PayPlus Payment Gateway.This issue affects PayPlus Payment Gateway: from …

Jul 12, 2024
CVE-2024-37560
8.0 HIGH

Improper Privilege Management vulnerability in IqbalRony WP User Switch allows Privilege Escalation.This issue affects WP User Switch: from n/a through 1.1.0.

Jul 12, 2024
CVE-2024-37213
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in guru-aliexpress AliNext ali2woo-lite allows Cross Site Request Forgery.This issue affects AliNext: from n/a through <= 3.4.6.

Jul 12, 2024
CVE-2024-35773
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in WPJohnny, zerOneIT Comment Reply Email allows Cross-Site Scripting (XSS).This issue affects Comment Reply Email: from n/a through 1.3.

Jul 12, 2024
CVE-2024-5325
8.8 HIGH

The Form Vibes plugin for WordPress is vulnerable to SQL Injection via the ‘fv_export_data’ parameter in all versions up to, and including, 1.4.10 due to …

Jul 12, 2024
CVE-2024-41003
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix reg_set_min_max corruption of fake_reg Juan reported that after doing some changes to buzzer …

Jul 12, 2024
CVE-2024-41000
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: block/ioctl: prefer different overflow check Running syzkaller with the newly reintroduced signed integer overflow sanitizer …

Jul 12, 2024
CVE-2024-40996
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: bpf: Avoid splat in pskb_pull_reason syzkaller builds (CONFIG_DEBUG_NET=y) frequently trigger a debug hint in pskb_may_pull. …

Jul 12, 2024
CVE-2024-40994
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ptp: fix integer overflow in max_vclocks_store On 32bit systems, the "4 * max" multiply can …

Jul 12, 2024
CVE-2024-40989
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Disassociate vcpus from redistributor region on teardown When tearing down a redistributor region, …

Jul 12, 2024
CVE-2024-40978
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: scsi: qedi: Fix crash while reading debugfs attribute The qedi_dbg_do_not_recover_cmd_read() function invokes sprintf() directly on …

Jul 12, 2024
CVE-2024-40974
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: powerpc/pseries: Enforce hcall result buffer validity and size plpar_hcall(), plpar_hcall9(), and related functions expect callers …

Jul 12, 2024
CVE-2024-40958
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: netns: Make get_net_ns() handle zero refcount net Syzkaller hit a warning: refcount_t: addition on 0; …

Jul 12, 2024
CVE-2024-40956
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: Fix possible Use-After-Free in irq_process_work_list Use list_for_each_entry_safe() to allow iterating through the list …

Jul 12, 2024
CVE-2024-40954
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: do not leave a dangling sk pointer, when socket creation fails It is possible …

Jul 12, 2024
CVE-2024-40940
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix tainted pointer delete is case of flow rules creation fail In case of …

Jul 12, 2024
CVE-2024-40939
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: wwan: iosm: Fix tainted pointer delete is case of region creation fail In case …

Jul 12, 2024
CVE-2024-40935
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: cachefiles: flush all requests after setting CACHEFILES_DEAD In ondemand mode, when the daemon is processing …

Jul 12, 2024
CVE-2024-40929
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: check n_ssids before accessing the ssids In some versions of cfg80211, the …

Jul 12, 2024
CVE-2024-40927
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: xhci: Handle TD clearing for multiple streams case When multiple streams are in use, multiple …

Jul 12, 2024
CVE-2024-40920
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: bridge: mst: fix suspicious rcu usage in br_mst_set_state I converted br_mst_set_state to RCU to …

Jul 12, 2024
CVE-2024-40913
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: cachefiles: defer exposing anon_fd until after copy_to_user() succeeds After installing the anonymous fd, we can …

Jul 12, 2024
CVE-2024-40909
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix a potential use-after-free in bpf_link_free() After commit 1a80dbcb2dba, bpf_link can be freed by …

Jul 12, 2024
CVE-2024-40906
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Always stop health timer during driver removal Currently, if teardown_hca fails to execute during …

Jul 12, 2024
CVE-2024-40903
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: usb: typec: tcpm: fix use-after-free case in tcpm_register_source_caps There could be a potential use-after-free case …

Jul 12, 2024
CVE-2024-40902
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: jfs: xattr: fix buffer overflow for invalid xattr When an xattr size is not what …

Jul 12, 2024
CVE-2024-40901
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: scsi: mpt3sas: Avoid test/set_bit() operating in non-allocated memory There is a potential out-of-bounds access when …

Jul 12, 2024
CVE-2024-40900
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: cachefiles: remove requests from xarray during flushing requests Even with CACHEFILES_DEAD set, we can still …

Jul 12, 2024
CVE-2024-40899
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: cachefiles: fix slab-use-after-free in cachefiles_ondemand_get_fd() We got the following issue in a fuzz test of …

Jul 12, 2024
CVE-2024-39510
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: cachefiles: fix slab-use-after-free in cachefiles_ondemand_daemon_read() We got the following issue in a fuzz test of …

Jul 12, 2024
CVE-2024-39503
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: Fix race between namespace cleanup and gc in the list:set type Lion Ackermann …

Jul 12, 2024
CVE-2024-39502
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ionic: fix use after netif_napi_del() When queues are started, netif_napi_add() and napi_enable() are called. If …

Jul 12, 2024
CVE-2024-39499
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: vmci: prevent speculation leaks by sanitizing event in event_deliver() Coverity spotted that event_msg is controlled …

Jul 12, 2024
CVE-2024-39496
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: btrfs: zoned: fix use-after-free due to race with dev replace While loading a zone's info …

Jul 12, 2024
CVE-2024-39495
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: greybus: Fix use-after-free bug in gb_interface_release due to race condition. In gb_interface_create, &intf->mode_switch_completion is bound …

Jul 12, 2024
CVE-2024-39494
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ima: Fix use-after-free on a dentry's dname.name ->d_name.name can change on rename and the earlier …

Jul 12, 2024
CVE-2024-39340
8.8 HIGH

The authentication system of Securepoint UTM mishandles OTP keys. This allows the bypassing of second-factor verification (when OTP is enabled) in both the administration web …

Jul 12, 2024
CVE-2024-6353
8.8 HIGH

The Wallet for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'search[value]' parameter in all versions up to, and including, 1.5.4 due …

Jul 12, 2024
CVE-2024-6024
8.8 HIGH

The ContentLock WordPress plugin through 1.0.3 does not have CSRF check in place when deleting groups or emails, which could allow attackers to make a …

Jul 12, 2024
CVE-2024-6023
8.8 HIGH

The ContentLock WordPress plugin through 1.0.3 does not have CSRF check in place when adding emails, which could allow attackers to make a logged in …

Jul 12, 2024
CVE-2024-6022
8.8 HIGH

The ContentLock WordPress plugin through 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged …

Jul 12, 2024
CVE-2024-6677
7.8 HIGH

Privilege escalation in uberAgent

Jul 12, 2024
CVE-2024-6468
7.5 HIGH

Vault and Vault Enterprise did not properly handle requests originating from unauthorized IP addresses when the TCP listener option, proxy_protocol_behavior, was set to deny_unauthorized. When …

Jul 11, 2024
CVE-2024-39552
7.5 HIGH

An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows a network …

Jul 11, 2024
CVE-2024-39551
7.5 HIGH

An Uncontrolled Resource Consumption vulnerability in the H.323 ALG (Application Layer Gateway) of Juniper Networks Junos OS on SRX Series and MX Series with SPC3 …

Jul 11, 2024
CVE-2024-39549
7.5 HIGH

A Missing Release of Memory after Effective Lifetime vulnerability in the routing process daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows …

Jul 11, 2024
CVE-2024-39548
7.5 HIGH

An Uncontrolled Resource Consumption vulnerability in the aftmand process of Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to consume memory resources, resulting …

Jul 11, 2024
CVE-2024-39546
7.3 HIGH

A Missing Authorization vulnerability in the Socket Intercept (SI) command file interface of Juniper Networks Junos OS Evolved allows an authenticated, low-privilege local attacker to …

Jul 11, 2024
CVE-2024-39545
7.5 HIGH

An Improper Check for Unusual or Exceptional Conditions vulnerability in the the IKE daemon (iked) of Juniper Networks Junos OS on SRX Series, MX Series …

Jul 11, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.