CVE Database

46795+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-44985
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ipv6: prevent possible UAF in ip6_xmit() If skb_expand_head() returns NULL, skb has been freed and …

Sep 4, 2024
CVE-2024-44983
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: validate vlan header Ensure there is sufficient room to access the protocol field …

Sep 4, 2024
CVE-2024-44978
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/xe: Free job before xe_exec_queue_put Free job depends on job->vm being valid, the last xe_exec_queue_put …

Sep 4, 2024
CVE-2024-44977
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Validate TA binary size Add TA binary size validation to avoid OOB write. (cherry …

Sep 4, 2024
CVE-2024-44974
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: avoid possible UaF when selecting endp select_local_address() and select_signal_address() both select an endpoint …

Sep 4, 2024
CVE-2024-44967
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/mgag200: Bind I2C lifetime to DRM device Managed cleanup with devm_add_action_or_reset() will release the I2C …

Sep 4, 2024
CVE-2024-44964
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: idpf: fix memory leaks and crashes while performing a soft reset The second tagged commit …

Sep 4, 2024
CVE-2024-44951
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: serial: sc16is7xx: fix TX fifo corruption Sometimes, when a packet is received on channel A …

Sep 4, 2024
CVE-2024-44949
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: parisc: fix a possible DMA corruption ARCH_DMA_MINALIGN was defined as 16 - this is too …

Sep 4, 2024
CVE-2024-45174
8.1 HIGH

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to improper validation of user-supplied data, different functionalities of the C-MOR web …

Sep 4, 2024
CVE-2024-45170
8.1 HIGH

An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper or missing access control, low privileged users can use administrative functions of …

Sep 4, 2024
CVE-2024-20440
7.5 HIGH

A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive information. This vulnerability is due to excessive verbosity in …

Sep 4, 2024
CVE-2024-8391
7.5 HIGH

In Eclipse Vert.x version 4.3.0 to 4.5.9, the gRPC server does not limit the maximum length of message payload (Maven GAV: io.vertx:vertx-grpc-server and io.vertx:vertx-grpc-client). This …

Sep 4, 2024
CVE-2024-45075
8.8 HIGH

IBM webMethods Integration 10.15 could allow an authenticated user to create scheduler tasks that would allow them to escalate their privileges to administrator due to …

Sep 4, 2024
CVE-2024-45050
7.1 HIGH

Ringer server is the server code for the Ringer messaging app. Prior to version 1.3.1, there is an issue with the messages loading route where …

Sep 4, 2024
CVE-2024-44859
8.0 HIGH

Tenda FH1201 v1.2.0.14 has a stack buffer overflow vulnerability in `formWrlExtraGet`.

Sep 4, 2024
CVE-2024-44817
8.8 HIGH

SQL Injection vulnerability in ZZCMS v.2023 and before allows a remote attacker to obtain sensitive information via the id parameter in the adv2.php component.

Sep 4, 2024
CVE-2024-43405
7.4 HIGH

Nuclei is a vulnerability scanner powered by YAML based templates. Starting in version 3.0.0 and prior to version 3.3.2, a vulnerability in Nuclei's template signature …

Sep 4, 2024
CVE-2024-43402
8.1 HIGH

Rust is a programming language. The fix for CVE-2024-24576, where `std::process::Command` incorrectly escaped arguments when invoking batch files on Windows, was incomplete. Prior to Rust …

Sep 4, 2024
CVE-2024-8418
7.5 HIGH

A flaw was found in Aardvark-dns, which is vulnerable to a Denial of Service attack due to the serial processing of TCP DNS queries. An …

Sep 4, 2024
CVE-2024-45506
7.5 HIGH

HAProxy 2.9.x before 2.9.10, 3.0.x before 3.0.4, and 3.1.x through 3.1-dev6 allows a remote denial of service for HTTP/2 zero-copy forwarding (h2_send loop) under a …

Sep 4, 2024
CVE-2024-7834
7.8 HIGH

A local privilege escalation is caused by Overwolf loading and executing certain dynamic link library files from a user-writeable folder in SYSTEM context on launch. …

Sep 4, 2024
CVE-2024-45195
7.5 HIGH KEV

Direct Request ('Forced Browsing') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes …

Sep 4, 2024
CVE-2024-8104
8.8 HIGH

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.0.8 via …

Sep 4, 2024
CVE-2024-8102
8.8 HIGH

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due …

Sep 4, 2024
CVE-2024-34660
7.3 HIGH

Heap-based out-of-bounds write in Samsung Notes prior to version 4.4.21.62 allows local attackers to execute arbitrary code.

Sep 4, 2024
CVE-2024-34659
7.5 HIGH

Exposure of sensitive information in GroupSharing prior to version 13.6.13.3 allows remote attackers can force the victim to join the group.

Sep 4, 2024
CVE-2024-34657
8.6 HIGH

Stack-based out-of-bounds write in Samsung Notes prior to version 4.4.21.62 allows remote attackers to execute arbitrary code.

Sep 4, 2024
CVE-2024-34656
7.3 HIGH

Path traversal in Samsung Notes prior to version 4.4.21.62 allows local attackers to execute arbitrary code.

Sep 4, 2024
CVE-2024-39921
7.5 HIGH

Observable timing discrepancy issue exists in IPCOM EX2 Series V01L02NF0001 to V01L06NF0401, V01L20NF0001 to V01L20NF0401, V02L20NF0001 to V02L21NF0301, and IPCOM VE2 Series V01L04NF0001 to V01L06NF0112. …

Sep 4, 2024
CVE-2024-41716
8.1 HIGH

Cleartext storage of sensitive information vulnerability exists in WindLDR and WindO/I-NV4. If this vulnerability is exploited, an attacker who obtained the product's project file may …

Sep 4, 2024
CVE-2024-8362
8.8 HIGH

Use after free in WebAudio in Google Chrome prior to 128.0.6613.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Sep 3, 2024
CVE-2024-7970
8.8 HIGH

Out of bounds write in V8 in Google Chrome prior to 128.0.6613.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

Sep 3, 2024
CVE-2024-45394
8.8 HIGH

Authenticator is a browser extension that generates two-step verification codes. In versions 7.0.0 and below, encryption keys for user data were stored encrypted at-rest using …

Sep 3, 2024
CVE-2024-45391
7.5 HIGH

Tina is an open-source content management system (CMS). Sites building with Tina CMS's command line interface (CLI) prior to version 1.6.2 that use a search …

Sep 3, 2024
CVE-2024-45390
7.3 HIGH

@blakeembrey/template is a string template library. Prior to version 1.2.0, it is possible to inject and run code within the template if the attacker has …

Sep 3, 2024
CVE-2024-45307
8.8 HIGH

SudoBot, a Discord moderation bot, is vulnerable to privilege escalation and exploit of the `-config` command in versions prior to 9.26.7. Anyone is theoretically able …

Sep 3, 2024
CVE-2024-41436
7.5 HIGH

ClickHouse v24.3.3.102 was discovered to contain a buffer overflow via the component DB::evaluateConstantExpressionImpl.

Sep 3, 2024
CVE-2024-41435
7.5 HIGH

YugabyteDB v2.21.1.0 was discovered to contain a buffer overflow via the "insert into" parameter.

Sep 3, 2024
CVE-2024-42902
8.8 HIGH

An issue in the js_localize.php function of LimeSurvey v6.6.2 and before allows attackers to execute arbitrary code via injecting a crafted payload into the lng …

Sep 3, 2024
CVE-2024-38456
7.8 HIGH

HIGH-LEIT V05.08.01.03 and HIGH-LEIT V04.25.00.00 to 4.25.01.01 for Windows from Vivavis contain an insecure file and folder permissions vulnerability in prunsrv.exe. A regular user (non-admin) …

Sep 3, 2024
CVE-2023-49233
8.8 HIGH

Insufficient access checks in Visual Planning Admin Center 8 before v.1 Build 240207 allow attackers in possession of a non-administrative Visual Planning account to utilize …

Sep 3, 2024
CVE-2024-6119
7.5 HIGH

Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination …

Sep 3, 2024
CVE-2024-42991
8.1 HIGH

MCMS v5.4.1 has front-end file upload vulnerability which can lead to remote command execution.

Sep 3, 2024
CVE-2024-7654
8.3 HIGH

An ActiveMQ Discovery service was reachable by default from an OpenEdge Management installation when an OEE/OEM auto-discovery feature was activated. Unauthorized access to the discovery …

Sep 3, 2024
CVE-2024-7346
7.2 HIGH

Host name validation for TLS certificates is bypassed when the installed OpenEdge default certificates are used to perform the TLS handshake for a networked connection. …

Sep 3, 2024
CVE-2024-7345
8.3 HIGH

Local ABL Client bypass of the required PASOE security checks may allow an attacker to commit unauthorized code injection into Multi-Session Agents on supported OpenEdge …

Sep 3, 2024
CVE-2024-8383
7.5 HIGH

Firefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that the browser does not support. It …

Sep 3, 2024
CVE-2024-8382
8.8 HIGH

Internal browser event interfaces were exposed to web content when privileged EventHandler listener callbacks ran for those events. Web content that tried to use those …

Sep 3, 2024
CVE-2024-6232
7.5 HIGH

There is a MEDIUM severity vulnerability affecting CPython. Regular expressions that allowed excessive backtracking during tarfile.TarFile header parsing are vulnerable to ReDoS via specifically-crafted tar …

Sep 3, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.