CVE Database

40083+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-5085
8.1 HIGH

The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, …

May 23, 2024
CVE-2024-4471
8.0 HIGH

The 140+ Widgets | Best Addons For Elementor – FREE for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.4.3.1 …

May 23, 2024
CVE-2024-35224
7.6 HIGH

OpenProject is the leading open source project management software. OpenProject utilizes `tablesorter` inside of the Cost Report feature. This dependency, when misconfigured, can lead to …

May 23, 2024
CVE-2024-34060
8.8 HIGH

IrisEVTXModule is an interface module for Evtx2Splunk and Iris in order to ingest Microsoft EVTX log files. The `iris-evtx-module` is a pipeline plugin of `iris-web` …

May 23, 2024
CVE-2024-26139
8.3 HIGH

OpenCTI is an open source platform allowing organizations to manage their cyber threat intelligence knowledge and observables. Due to lack of certain security controls on …

May 23, 2024
CVE-2024-4779
8.8 HIGH

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to SQL Injection via the ‘data[post_ids][0]’ parameter in all versions up …

May 23, 2024
CVE-2024-35186
8.8 HIGH

gitoxide is a pure Rust implementation of Git. During checkout, `gix-worktree-state` does not verify that paths point to locations in the working tree. A specially …

May 23, 2024
CVE-2024-30280
7.8 HIGH

Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read …

May 23, 2024
CVE-2024-30279
7.8 HIGH

Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

May 23, 2024
CVE-2024-4835
8.0 HIGH

A XSS condition exists within GitLab in versions 15.11 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1. By leveraging this condition, an attacker can …

May 23, 2024
CVE-2024-36012
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: msft: fix slab-use-after-free in msft_do_close() Tying the msft->data lifetime to hdev by freeing it …

May 23, 2024
CVE-2024-2038
7.5 HIGH

The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, …

May 23, 2024
CVE-2024-4388
7.5 HIGH

This does not validate a path generated with user input when downloading files, allowing unauthenticated user to download arbitrary files from the server

May 23, 2024
CVE-2024-4347
7.2 HIGH

The WP Fastest Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.2.6 via the specificDeleteCache function. This …

May 23, 2024
CVE-2024-3594
8.7 HIGH

The IDonate WordPress plugin through 1.9.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

May 23, 2024
CVE-2024-4662
8.8 HIGH

The Oxygen Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.8.2 via post metadata. This is …

May 23, 2024
CVE-2024-4978
8.4 HIGH KEV

Justice AV Solutions Viewer Setup 8.3.7.250-1 contains a malicious binary when executed and is signed with an unexpected authenticode signature. A remote, privileged threat actor …

May 23, 2024
CVE-2024-29853
7.8 HIGH

An authentication bypass vulnerability in Veeam Agent for Microsoft Windows allows for local privilege escalation.

May 22, 2024
CVE-2024-29851
7.2 HIGH

Veeam Backup Enterprise Manager allows high-privileged users to steal NTLM hash of Enterprise manager service account.

May 22, 2024
CVE-2024-29850
8.8 HIGH

Veeam Backup Enterprise Manager allows account takeover via NTLM relay.

May 22, 2024
CVE-2024-4454
7.8 HIGH

WithSecure Elements Endpoint Protection Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of WithSecure Elements Endpoint …

May 22, 2024
CVE-2024-4453
7.8 HIGH

GStreamer EXIF Metadata Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction …

May 22, 2024
CVE-2024-27264
7.4 HIGH

IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated privileges due to an unqualified library call. …

May 22, 2024
CVE-2023-51636
7.8 HIGH

Avira Prime Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Avira Prime. An attacker must …

May 22, 2024
CVE-2024-20360
8.8 HIGH

A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks …

May 22, 2024
CVE-2024-36077
8.8 HIGH

Qlik Sense Enterprise for Windows before 14.187.4 allows a remote attacker to elevate their privilege due to improper validation. The attacker can elevate their privilege …

May 22, 2024
CVE-2024-5160
8.8 HIGH

Heap buffer overflow in Dawn in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to perform an out of bounds memory write via a …

May 22, 2024
CVE-2024-5159
8.8 HIGH

Heap buffer overflow in ANGLE in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to perform an out of bounds memory read via a …

May 22, 2024
CVE-2024-5158
8.1 HIGH

Type Confusion in V8 in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to potentially perform arbitrary read/write via a crafted HTML page. (Chromium …

May 22, 2024
CVE-2024-5157
8.8 HIGH

Use after free in Scheduling in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted …

May 22, 2024
CVE-2024-34448
8.8 HIGH

Ghost before 5.82.0 allows CSV Injection during a member CSV export.

May 22, 2024
CVE-2024-33228
8.4 HIGH

An issue in the component segwindrvx64.sys of Insyde Software Corp SEG Windows Driver v100.00.07.02 allows attackers to escalate privileges and execute arbitrary code via sending …

May 22, 2024
CVE-2024-33227
8.8 HIGH

An issue in the component ddcdrv.sys of Nicomsoft WinI2C/DDC v3.7.4.0 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.

May 22, 2024
CVE-2024-33225
7.8 HIGH

An issue in the component RTKVHD64.sys of Realtek Semiconductor Corp Realtek(r) High Definition Audio Function Driver v6.0.9549.1 allows attackers to escalate privileges and execute arbitrary …

May 22, 2024
CVE-2024-33224
8.4 HIGH

An issue in the component rtkio64.sys of Realtek Semiconductor Corp Realtek lO Driver v1.008.0823.2017 allows attackers to escalate privileges and execute arbitrary code via sending …

May 22, 2024
CVE-2024-33223
8.8 HIGH

An issue in the component IOMap64.sys of ASUSTeK Computer Inc ASUS GPU TweakII v1.4.5.2 allows attackers to escalate privileges and execute arbitrary code via sending …

May 22, 2024
CVE-2024-33222
8.4 HIGH

An issue in the component ATSZIO64.sys of ASUSTeK Computer Inc ASUS ATSZIO Driver v0.2.1.7 allows attackers to escalate privileges and execute arbitrary code via sending …

May 22, 2024
CVE-2024-33221
7.8 HIGH

An issue in the component AsusBSItf.sys of ASUSTeK Computer Inc ASUS BIOS Flash Driver v3.2.12.0 allows attackers to escalate privileges and execute arbitrary code via …

May 22, 2024
CVE-2024-33220
8.8 HIGH

An issue in the component AslO3_64.sys of ASUSTeK Computer Inc AISuite3 v3.03.36 3.03.36 allows attackers to escalate privileges and execute arbitrary code via sending crafted …

May 22, 2024
CVE-2024-33219
7.8 HIGH

An issue in the component AsIO64.sys of ASUSTeK Computer Inc ASUS SABERTOOTH X99 Driver v1.0.1.0 allows attackers to escalate privileges and execute arbitrary code via …

May 22, 2024
CVE-2024-33218
7.8 HIGH

An issue in the component AsUpIO64.sys of ASUSTeK Computer Inc ASUS USB 3.0 Boost Storage Driver 5.30.20.0 allows attackers to escalate privileges and execute arbitrary …

May 22, 2024
CVE-2024-35559
8.8 HIGH

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoMove_deal.php?mudi=rev&nohrefStr=close.

May 22, 2024
CVE-2024-35558
8.8 HIGH

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ca_deal.php?mudi=rev&nohrefStr=close.

May 22, 2024
CVE-2024-35556
8.8 HIGH

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/vpsSys_deal.php?mudi=infoSet.

May 22, 2024
CVE-2024-35553
8.3 HIGH

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoMove_deal.php?mudi=add&nohrefStr=close.

May 22, 2024
CVE-2024-35552
8.8 HIGH

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoMove_deal.php?mudi=del&dataType=logo&dataTypeCN.

May 22, 2024
CVE-2024-5031
8.5 HIGH

The Memberpress plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 1.11.29 via the 'mepr-user-file' shortcode. This …

May 22, 2024
CVE-2021-47497
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: nvmem: Fix shift-out-of-bound (UBSAN) with byte size cells If a cell has 'nbits' equal to …

May 22, 2024
CVE-2021-47496
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net/tls: Fix flipped sign in tls_err_abort() calls sk->sk_err appears to expect a positive value, a …

May 22, 2024
CVE-2021-47489
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix even more out of bound writes from debugfs CVE-2021-42327 was fixed by: commit …

May 22, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.