CVE Database

4634+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-39837
3.8 LOW

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly restrict channel creation which allows a malicious remote to create arbitrary channels, when shared …

Aug 1, 2024
CVE-2024-29977
2.7 LOW

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly validate synced reactions, when shared channels are enabled, which allows a malicious remote to …

Aug 1, 2024
CVE-2024-38489
3.1 LOW

Dell iDRAC Service Module version 5.3.0.0 and prior contains Out of bound write Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting in …

Aug 1, 2024
CVE-2024-7343
3.5 LOW

A vulnerability was found in Baidu UEditor 1.4.2. It has been declared as problematic. This vulnerability affects unknown code of the file /ueditor142/php/controller.php?action=catchimage. The manipulation …

Aug 1, 2024
CVE-2024-7342
3.5 LOW

A vulnerability was found in Baidu UEditor 1.4.3.3. It has been classified as problematic. This affects an unknown part of the file /ueditor/php/controller.php?action=uploadfile&encode=utf-8. The manipulation …

Aug 1, 2024
CVE-2022-4003
2.7 LOW

A denial-of-service vulnerability could allow an authenticated user to trigger an internal service restart via a specially crafted API request.

Jul 31, 2024
CVE-2024-37135
3.3 LOW

DM5500 5.16.0.0, contains an information disclosure vulnerability. A local attacker with high privileges could potentially exploit this vulnerability, leading to the disclosure of certain user …

Jul 31, 2024
CVE-2024-31203
3.3 LOW

A “CWE-121: Stack-based Buffer Overflow” in the wd210std.dll dynamic library packaged with the ThermoscanIP installer allows a local attacker to possibly trigger a Denial-of-Service (DoS) …

Jul 31, 2024
CVE-2024-7310
3.5 LOW

A vulnerability was found in SourceCodester Record Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file sort_user.php. …

Jul 31, 2024
CVE-2024-7309
3.5 LOW

A vulnerability was found in SourceCodester Record Management System 1.0. It has been classified as problematic. This affects an unknown part of the file entry.php. …

Jul 31, 2024
CVE-2024-7303
3.5 LOW

A vulnerability was found in itsourcecode Online Blood Bank Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of …

Jul 31, 2024
CVE-2024-7300
3.5 LOW

A vulnerability classified as problematic has been found in Bolt CMS 3.7.1. Affected is an unknown function of the file /bolt/editcontent/showcases of the component Showcase …

Jul 31, 2024
CVE-2024-7299
3.5 LOW

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Bolt CMS 3.7.1. It has been rated as problematic. This issue affects some unknown processing …

Jul 31, 2024
CVE-2024-7285
3.5 LOW

A vulnerability has been found in SourceCodester Establishment Billing Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /admin/ajax.php?action=save_settings. …

Jul 31, 2024
CVE-2024-7284
3.5 LOW

A vulnerability, which was classified as problematic, was found in SourceCodester Lot Reservation Management System 1.0. This affects an unknown part of the file /admin/ajax.php?action=save_settings. …

Jul 31, 2024
CVE-2024-41945
3.1 LOW

fuels-ts is a library for interacting with Fuel v2. The typescript SDK has no awareness of to-be-spent transactions causing some transactions to fail or silently …

Jul 30, 2024
CVE-2024-5250
3.5 LOW

In versions of Akana API Platform prior to 2024.1.0 overly verbose errors can be found in SAML integrations

Jul 30, 2024
CVE-2022-33167
3.7 LOW

IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure …

Jul 30, 2024
CVE-2024-7225
3.5 LOW

A vulnerability was found in SourceCodester Insurance Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /Script/admin/core/update_policy …

Jul 30, 2024
CVE-2024-42155
1.9 LOW

In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Wipe copies of protected- and secure-keys Although the clear-key of neither protected- nor secure-keys …

Jul 30, 2024
CVE-2024-7218
3.5 LOW

A flaw has been found in SourceCodester/Campcodes School Log Management System 1.0. Affected is an unknown function of the file /admin/ajax.php?action=save_student. Executing manipulation of the …

Jul 30, 2024
CVE-2024-7216
2.6 LOW

A vulnerability was found in TOTOLINK LR1200 9.3.1cu.2832. It has been classified as problematic. This affects an unknown part of the file /etc/shadow.sample. The manipulation …

Jul 30, 2024
CVE-2024-40832
3.3 LOW

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.6. An app may be able to view a contact's phone …

Jul 29, 2024
CVE-2024-40822
2.4 LOW

This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and …

Jul 29, 2024
CVE-2024-40798
3.3 LOW

This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, macOS Monterey 12.7.6, macOS Sonoma …

Jul 29, 2024
CVE-2024-40795
3.3 LOW

This issue was addressed with improved data protection. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, watchOS 10.6. …

Jul 29, 2024
CVE-2024-40778
3.3 LOW

An authentication issue was addressed with improved state management. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS …

Jul 29, 2024
CVE-2024-27862
2.4 LOW

A logic issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.6. Enabling Lockdown Mode while setting up a Mac …

Jul 29, 2024
CVE-2023-42957
3.3 LOW

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, watchOS 10. An app …

Jul 29, 2024
CVE-2023-42949
3.3 LOW

This issue was addressed with improved data protection. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, watchOS 10, tvOS 17. …

Jul 29, 2024
CVE-2023-42948
3.3 LOW

This issue was addressed through improved state management. This issue is fixed in macOS Sonoma 14. A Wi-Fi password may not be deleted when activating …

Jul 29, 2024
CVE-2023-42925
3.3 LOW

The issue was addressed with improved restriction of data container access. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. An …

Jul 29, 2024
CVE-2024-6620
3.5 LOW

Honeywell PC42t, PC42tp, and PC42d Printers, T10.19.020016 to T10.20.060398, contain a cross-site scripting vulnerability. A(n) attacker could potentially inject malicious code which may lead to …

Jul 29, 2024
CVE-2024-41027
3.3 LOW

In the Linux kernel, the following vulnerability has been resolved: Fix userfaultfd_api to return EINVAL as expected Currently if we request a feature that is …

Jul 29, 2024
CVE-2024-7200
3.5 LOW

A vulnerability, which was classified as problematic, has been found in SourceCodester Complaints Report Management System 1.0. This issue affects some unknown processing of the …

Jul 29, 2024
CVE-2024-7170
3.5 LOW

A vulnerability was found in TOTOLINK A3000RU 5.9c.5185. It has been rated as problematic. This issue affects some unknown processing of the file /web_cste/cgi-bin/product.ini. The …

Jul 28, 2024
CVE-2024-7163
3.5 LOW

A vulnerability, which was classified as problematic, was found in SeaCMS 12.9. This affects an unknown part of the file /js/player/dmplayer/player/index.php. The manipulation of the …

Jul 28, 2024
CVE-2024-7162
3.5 LOW

A vulnerability, which was classified as problematic, has been found in SeaCMS 12.9/13.0. Affected by this issue is some unknown functionality of the file js/player/dmplayer/admin/post.php?act=setting. …

Jul 28, 2024
CVE-2024-7155
2.5 LOW

A vulnerability has been found in TOTOLINK A3300R 17.0.0cu.557_B20221024 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /etc/shadow.sample. …

Jul 28, 2024
CVE-2024-4786
2.8 LOW

An improper validation vulnerability was reported in the Lenovo Tab K10 that could allow a specially crafted application to keep the device on.

Jul 26, 2024
CVE-2024-27358
3.3 LOW

An issue was discovered in WithSecure Elements Agent through 23.x for macOS and WithSecure Elements Client Security through 23.x for macOS. Local users can block …

Jul 26, 2024
CVE-2024-41686
3.3 LOW

This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to improper implementation of password policies. A local attacker could exploit this by creating password that do …

Jul 26, 2024
CVE-2024-4811
2.2 LOW

In affected versions of Octopus Server under certain conditions, a user with specific role assignments can access restricted project artifacts.

Jul 25, 2024
CVE-2024-7060
2.6 LOW

An information disclosure vulnerability in GitLab CE/EE in project/group exports affecting all versions from 15.4 prior to 17.0.5, 17.1 prior to 17.1.3, and 17.2 prior …

Jul 24, 2024
CVE-2024-0231
2.7 LOW

A resource misdirection vulnerability in GitLab CE/EE versions 12.0 prior to 17.0.5, 17.1 prior to 17.1.3, and 17.2 prior to 17.2.1 allows an attacker to …

Jul 24, 2024
CVE-2024-37533
2.4 LOW

IBM InfoSphere Information Server 11.7 could disclose sensitive user information to another user with physical access to the machine. IBM X-Force ID: 294727.

Jul 24, 2024
CVE-2024-7068
3.5 LOW

A vulnerability classified as problematic has been found in SourceCodester Insurance Management System 1.0. This affects an unknown part of the file /Script/admin/core/update_sub_category. The manipulation …

Jul 24, 2024
CVE-2024-3454
3.5 LOW

An implementation issue in the Connectivity Standards Alliance Matter 1.2 protocol as used in the connectedhomeip SDK allows a third party to disclose information about …

Jul 24, 2024
CVE-2024-41663
3.5 LOW

Canarytokens help track activity and actions on a network. A Cross-Site Scripting vulnerability was identified in the "Cloned Website" Canarytoken, whereby the Canarytoken's creator can …

Jul 23, 2024
CVE-2024-41839
3.5 LOW

Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Input Validation vulnerability that could lead to a security feature bypass. A low-privileged …

Jul 23, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.