CVE Database

4634+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-7738
3.3 LOW

A vulnerability, which was classified as problematic, has been found in yzane vscode-markdown-pdf 1.5.0. Affected by this issue is some unknown functionality of the component …

Aug 13, 2024
CVE-2024-7733
3.5 LOW

A vulnerability, which was classified as problematic, was found in FastCMS up to 0.1.5. Affected is an unknown function of the component New Article Category …

Aug 13, 2024
CVE-2023-31366
3.3 LOW

Improper input validation in AMD μProf could allow an attacker to perform a write to an invalid address, potentially resulting in denial of service.

Aug 13, 2024
CVE-2023-31307
2.3 LOW

Improper validation of array index in Power Management Firmware (PMFW) may allow a privileged attacker to cause an out-of-bounds memory read within PMFW, potentially leading …

Aug 13, 2024
CVE-2023-31305
1.9 LOW

Generation of weak and predictable Initialization Vector (IV) in PMFW (Power Management Firmware) may allow an attacker with privileges to reuse IV values to reverse-engineer …

Aug 13, 2024
CVE-2023-31304
2.3 LOW

Improper input validation in SMU may allow an attacker with privileges and a compromised physical function (PF) to modify the PCIe® lane count and speed, …

Aug 13, 2024
CVE-2023-20518
1.9 LOW

Incomplete cleanup in the ASP may expose the Master Encryption Key (MEK) to a privileged attacker with access to the BIOS menu or UEFI shell …

Aug 13, 2024
CVE-2023-20513
3.3 LOW

An insufficient bounds check in PMFW (Power Management Firmware) may allow an attacker to utilize a malicious VF (virtualization function) to send a malformed message, …

Aug 13, 2024
CVE-2023-20512
1.9 LOW

A hardcoded AES key in PMFW may result in a privileged attacker gaining access to the key, potentially resulting in internal debug information leakage.

Aug 13, 2024
CVE-2021-46772
3.9 LOW

Insufficient input validation in the ABL may allow a privileged attacker with access to the BIOS menu or UEFI shell to tamper with the structure …

Aug 13, 2024
CVE-2021-26387
3.9 LOW

Insufficient access controls in ASP kernel may allow a privileged attacker with access to AMD signing keys and the BIOS menu or UEFI shell to …

Aug 13, 2024
CVE-2022-45862
3.7 LOW

An insufficient session expiration vulnerability [CWE-613] vulnerability in FortiOS 7.2.5 and below, 7.0 all versions, 6.4 all versions; FortiProxy 7.2 all versions, 7.0 all versions; …

Aug 13, 2024
CVE-2024-41731
3.1 LOW

SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker to upload malicious code over the network, that could be executed by the application. On successful …

Aug 13, 2024
CVE-2024-28166
3.7 LOW

SAP BusinessObjects Business Intelligence Platform allows an authenticated attacker to upload malicious code over the network, that could be executed by the application. On successful …

Aug 13, 2024
CVE-2024-7686
3.5 LOW

A vulnerability, which was classified as problematic, was found in SourceCodester Kortex Lite Advocate Office Management System 1.0. This affects an unknown part of the …

Aug 12, 2024
CVE-2024-7685
3.5 LOW

A vulnerability, which was classified as problematic, has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0. Affected by this issue is some …

Aug 12, 2024
CVE-2024-7684
3.5 LOW

A vulnerability classified as problematic was found in SourceCodester Kortex Lite Advocate Office Management System 1.0. Affected by this vulnerability is an unknown functionality of …

Aug 12, 2024
CVE-2024-7683
3.5 LOW

A vulnerability classified as problematic has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0. Affected is an unknown function of the file …

Aug 12, 2024
CVE-2024-7678
3.5 LOW

A vulnerability was found in SourceCodester Car Driving School Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown …

Aug 12, 2024
CVE-2024-7677
3.5 LOW

A vulnerability was found in SourceCodester Car Driving School Management System 1.0. It has been declared as problematic. Affected by this vulnerability is the function …

Aug 12, 2024
CVE-2024-7660
3.5 LOW

A vulnerability has been found in SourceCodester File Manager App 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the …

Aug 12, 2024
CVE-2024-7659
3.7 LOW

A vulnerability, which was classified as problematic, was found in projectsend up to r1605. Affected is the function generate_random_string of the file includes/functions.php of the …

Aug 12, 2024
CVE-2024-7657
3.5 LOW

A vulnerability classified as problematic was found in Gila CMS 1.10.9. This vulnerability affects unknown code of the file /cm/update_rows/page?id=2 of the component HTTP POST …

Aug 12, 2024
CVE-2024-7644
3.5 LOW

A vulnerability was found in SourceCodester Leads Manager Tool 1.0. It has been classified as problematic. This affects an unknown part of the file /endpoint/add-leads.php …

Aug 12, 2024
CVE-2024-6692
3.3 LOW

The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

Aug 12, 2024
CVE-2024-5445
3.8 LOW

Ecosystem Agent version 4 < 4.1.5.2597 and Ecosystem Agent version 5 < 5.1.4.2473 did not properly validate SSL/TLS certificates, which could allow a malicious actor …

Aug 12, 2024
CVE-2024-43167
2.8 LOW

DISPUTE NOTE: this issue does not pose a security risk as it (according to analysis by the original software developer, NLnet Labs) falls within the …

Aug 12, 2024
CVE-2024-22123
2.7 LOW

Setting SMS media allows to set GSM modem file. Later this file is used as Linux device. But due everything is a file for Linux, …

Aug 12, 2024
CVE-2024-22122
3.0 LOW

Zabbix allows to configure SMS notifications. AT command injection occurs on "Zabbix Server" because there is no validation of "Number" field on Web nor on …

Aug 12, 2024
CVE-2024-0102
3.3 LOW

NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvdisasm, where an attacker can cause an out-of-bounds read issue by deceiving a user into …

Aug 8, 2024
CVE-2024-42036
2.5 LOW

Access permission verification vulnerability in the Notepad module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Aug 8, 2024
CVE-2024-42249
3.3 LOW

In the Linux kernel, the following vulnerability has been resolved: spi: don't unoptimize message in spi_async() Calling spi_maybe_unoptimize_message() in spi_async() is wrong because the message …

Aug 7, 2024
CVE-2024-42233
3.3 LOW

In the Linux kernel, the following vulnerability has been resolved: filemap: replace pte_offset_map() with pte_offset_map_nolock() The vmf->ptl in filemap_fault_recheck_pte_none() is still set from handle_pte_fault(). But …

Aug 7, 2024
CVE-2024-6996
3.1 LOW

Race in Frames in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform …

Aug 6, 2024
CVE-2024-7551
2.7 LOW

A vulnerability was found in juzaweb CMS up to 3.4.2. It has been classified as problematic. Affected is an unknown function of the file /admin-cp/theme/editor/default …

Aug 6, 2024
CVE-2024-7542
3.3 LOW

oFono AT CMGR Command Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of oFono. An attacker …

Aug 6, 2024
CVE-2024-7541
3.3 LOW

oFono AT CMT Command Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of oFono. An attacker …

Aug 6, 2024
CVE-2024-7540
3.3 LOW

oFono AT CMGL Command Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of oFono. An attacker …

Aug 6, 2024
CVE-2024-41811
3.9 LOW

ipl/web is a set of common web components for php projects. Some of the recent development by Icinga is, under certain circumstances, susceptible to cross …

Aug 5, 2024
CVE-2024-42350
3.0 LOW

Biscuit is an authorization token with decentralized verification, offline attenuation and strong security policy enforcement based on a logic language. Third-party blocks can be generated …

Aug 5, 2024
CVE-2024-41960
3.8 LOW

mailcow: dockerized is an open source groupware/email suite based on docker. An authenticated admin user can inject a JavaScript payload into the Relay Hosts configuration. …

Aug 5, 2024
CVE-2024-40096
3.3 LOW

The com.cascadialabs.who (aka Who - Caller ID, Spam Block) application 15.0 for Android places sensitive information in the system log.

Aug 5, 2024
CVE-2024-7466
2.4 LOW

A vulnerability has been found in PMWeb 7.2.00 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Web Application …

Aug 5, 2024
CVE-2024-7453
2.4 LOW

A vulnerability was found in FastAdmin 1.5.0.20240328. It has been declared as problematic. This vulnerability affects unknown code of the file /[admins_url].php/general/attachment/edit/ids/4?dialog=1 of the component …

Aug 4, 2024
CVE-2024-7368
3.5 LOW

A vulnerability has been found in SourceCodester Simple Realtime Quiz System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /ajax.php?action=save_quiz. …

Aug 1, 2024
CVE-2024-41949
3.0 LOW

biscuit-rust is the Rust implementation of Biscuit, an authentication and authorization token for microservices architectures. Third-party blocks can be generated without transferring the whole token …

Aug 1, 2024
CVE-2024-41948
3.0 LOW

biscuit-java is the java implementation of Biscuit, an authentication and authorization token for microservices architectures. Third-party blocks can be generated without transferring the whole token …

Aug 1, 2024
CVE-2024-7359
3.5 LOW

A vulnerability was found in SourceCodester Tracking Monitoring Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality …

Aug 1, 2024
CVE-2024-23600
2.7 LOW

Improper Input Validation of query search results for private field data in PingIDM (Query Filter module) allows for a potentially efficient brute forcing approach leading …

Aug 1, 2024
CVE-2024-41926
2.7 LOW

Mattermost versions 9.9.x <= 9.9.0 and 9.5.x <= 9.5.6 fail to validate the source of sync messages and only allow the correct remote IDs, which …

Aug 1, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.