CVE Database

46795+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-5556
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in reports module.

Aug 23, 2024
CVE-2024-5490
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in aggregate reports option.

Aug 23, 2024
CVE-2024-5467
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injection in account lockout report.

Aug 23, 2024
CVE-2024-5466
8.8 HIGH

Zohocorp ManageEngine OpManager and Remote Monitoring and Management versions 128329 and below are vulnerable to the authenticated remote code execution in the deploy agent option.

Aug 23, 2024
CVE-2024-36517
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in alerts module.

Aug 23, 2024
CVE-2024-36516
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in dashboard. Note: This vulnerability is different from another vulnerability (CVE-2024-36515), …

Aug 23, 2024
CVE-2024-36515
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in dashboard. Note: This vulnerability is different from another vulnerability (CVE-2024-36516), …

Aug 23, 2024
CVE-2024-36514
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in file summary option.

Aug 23, 2024
CVE-2024-43883
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: usb: vhci-hcd: Do not drop references before new references are gained At a few places …

Aug 23, 2024
CVE-2024-7986
7.5 HIGH

A vulnerability exists in the Rockwell Automation ThinManager® ThinServer that allows a threat actor to disclose sensitive information. A threat actor can exploit this vulnerability …

Aug 23, 2024
CVE-2024-7258
8.8 HIGH

The WooCommerce Google Feed Manager plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'wppfm_removeFeedFile' function …

Aug 23, 2024
CVE-2024-7559
8.8 HIGH

The File Manager Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and capability checks in the mk_file_folder_manager …

Aug 23, 2024
CVE-2024-43477
7.5 HIGH

Improper access control in Decentralized Identity Services resulted in a vulnerability that allows an unauthenticated attacker to disable Verifiable ID's on another tenant.

Aug 23, 2024
CVE-2024-8086
7.3 HIGH

A vulnerability has been found in SourceCodester E-Commerce System 1.0 and classified as critical. This vulnerability affects unknown code of the file /ecommerce/admin/login.php of the …

Aug 22, 2024
CVE-2024-38210
7.8 HIGH

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Aug 22, 2024
CVE-2024-38209
7.8 HIGH

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Aug 22, 2024
CVE-2024-8081
7.3 HIGH

A vulnerability classified as critical was found in itsourcecode Payroll Management System 1.0. Affected by this vulnerability is an unknown functionality of the file login.php. …

Aug 22, 2024
CVE-2024-8079
8.8 HIGH

A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.862_B20230228. It has been rated as critical. This issue affects the function exportOvpn. The manipulation leads to …

Aug 22, 2024
CVE-2024-8078
8.8 HIGH

A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.862_B20230228. It has been declared as critical. This vulnerability affects the function setTracerouteCfg. The manipulation leads to …

Aug 22, 2024
CVE-2023-7260
7.5 HIGH

Path Traversal vulnerability discovered in OpenText™ CX-E Voice, affecting all version through 22.4. The vulnerability could allow arbitrarily access files on the system.

Aug 22, 2024
CVE-2024-8076
8.8 HIGH

A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.862_B20230228 and classified as critical. Affected by this issue is the function setDiagnosisCfg. The manipulation leads to …

Aug 22, 2024
CVE-2024-45201
8.8 HIGH

An issue was discovered in llama_index before 0.10.38. download/integration.py includes an exec call for import {cls_name}.

Aug 22, 2024
CVE-2024-42599
8.8 HIGH

SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_files.php imposes restrictions on edited files, attackers can still …

Aug 22, 2024
CVE-2024-42418
7.5 HIGH

Avtec Outpost uses a default cryptographic key that can be used to decrypt sensitive information.

Aug 22, 2024
CVE-2024-39776
7.5 HIGH

Avtec Outpost stores sensitive information in an insecure location without proper access controls in place.

Aug 22, 2024
CVE-2024-39717
7.2 HIGH KEV

The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user …

Aug 22, 2024
CVE-2024-42767
7.2 HIGH

Kashipara Hotel Management System v1.0 is vulnerable to Unrestricted File Upload RCE via /admin/add_room_controller.php.

Aug 22, 2024
CVE-2024-42776
7.2 HIGH

Kashipara Hotel Management System v1.0 is vulnerable to Incorrect Access Control via /admin/users.php.

Aug 22, 2024
CVE-2024-42774
7.5 HIGH

An Incorrect Access Control vulnerability was found in /admin/delete_room.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to delete valid hotel room …

Aug 22, 2024
CVE-2024-42772
7.5 HIGH

An Incorrect Access Control vulnerability was found in /admin/rooms.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to view valid hotel room …

Aug 22, 2024
CVE-2024-42490
7.5 HIGH

authentik is an open-source Identity Provider. Several API endpoints can be accessed by users without correct authentication/authorization. The main API endpoints affected by this are …

Aug 22, 2024
CVE-2024-36444
8.1 HIGH

cgi-bin/fdmcgiwebv2.cgi on Swissphone DiCal-RED 4009 devices allows an unauthenticated attacker to gain access to device logs.

Aug 22, 2024
CVE-2024-36442
8.8 HIGH

cgi-bin/fdmcgiwebv2.cgi on Swissphone DiCal-RED 4009 devices allows an authenticated attacker to gain access to arbitrary files on the device's file system.

Aug 22, 2024
CVE-2024-36443
7.6 HIGH

Swissphone DiCal-RED 4009 devices allow a remote attacker to gain read access to almost the whole file system via anonymous FTP.

Aug 22, 2024
CVE-2022-48943
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: make apf token non-zero to fix bug In current async pagefault logic, when …

Aug 22, 2024
CVE-2022-48927
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: iio: adc: tsc2046: fix memory corruption by preventing array overflow On one side we have …

Aug 22, 2024
CVE-2022-48926
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: rndis: add spinlock for rndis response list There's no lock for rndis response …

Aug 22, 2024
CVE-2024-7384
7.5 HIGH

The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing …

Aug 22, 2024
CVE-2024-39576
8.8 HIGH

Dell Power Manager (DPM), versions 3.15.0 and prior, contains an Incorrect Privilege Assignment vulnerability. A low privileged attacker with local access could potentially exploit this …

Aug 22, 2024
CVE-2022-48925
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: RDMA/cma: Do not change route.addr.src_addr outside state checks If the state is not idle then …

Aug 22, 2024
CVE-2022-48919
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: cifs: fix double free race when mount fails in cifs_get_root() When cifs_get_root() fails during cifs_smb3_do_mount() …

Aug 22, 2024
CVE-2022-48913
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: blktrace: fix use after free for struct blk_trace When tracing the whole disk, 'dropped' and …

Aug 22, 2024
CVE-2022-48912
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: netfilter: fix use-after-free in __nf_register_net_hook() We must not dereference @new_hooks after nf_hook_mutex has been released, …

Aug 22, 2024
CVE-2024-43033
8.8 HIGH

JPress through 5.1.1 on Windows has an arbitrary file upload vulnerability that could cause arbitrary code execution via ::$DATA to AttachmentController, such as a .jsp::$DATA …

Aug 22, 2024
CVE-2024-7980
7.8 HIGH

Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to perform privilege escalation via a crafted symbolic …

Aug 21, 2024
CVE-2024-7979
7.8 HIGH

Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to perform privilege escalation via a crafted symbolic …

Aug 21, 2024
CVE-2024-7977
7.8 HIGH

Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to perform privilege escalation via a malicious file. …

Aug 21, 2024
CVE-2024-7974
8.8 HIGH

Insufficient data validation in V8 API in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted Chrome …

Aug 21, 2024
CVE-2024-7973
8.8 HIGH

Heap buffer overflow in PDFium in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform an out of bounds memory read via a …

Aug 21, 2024
CVE-2024-7972
8.8 HIGH

Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially perform out of bounds memory access via a crafted …

Aug 21, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.