CVE Database

46795+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-39809
7.5 HIGH

The Central Manager user session refresh token does not expire when a user logs out. Note: Software versions which have reached End of Technical Support …

Aug 14, 2024
CVE-2024-39792
7.5 HIGH

When the NGINX Plus is configured to use the MQTT pre-read module, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions …

Aug 14, 2024
CVE-2024-39778
7.5 HIGH

When a stateless virtual server is configured on BIG-IP system with a High-Speed Bridge (HSB), undisclosed requests can cause TMM to terminate. Note: Software versions …

Aug 14, 2024
CVE-2024-39426
7.8 HIGH

Acrobat Reader versions 20.005.30636, 24.002.20965, 24.002.20964, 24.001.30123 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in …

Aug 14, 2024
CVE-2024-39425
7.0 HIGH

Acrobat Reader versions 20.005.30636, 24.002.20965, 24.002.20964, 24.001.30123 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could lead to privilege escalation. …

Aug 14, 2024
CVE-2024-39424
7.8 HIGH

Acrobat Reader versions 20.005.30636, 24.002.20965, 24.002.20964, 24.001.30123 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in …

Aug 14, 2024
CVE-2024-39423
7.8 HIGH

Acrobat Reader versions 20.005.30636, 24.002.20965, 24.002.20964, 24.001.30123 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the …

Aug 14, 2024
CVE-2024-39422
7.8 HIGH

Acrobat Reader versions 20.005.30636, 24.002.20965, 24.002.20964, 24.001.30123 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in …

Aug 14, 2024
CVE-2024-39420
7.0 HIGH

Acrobat Reader versions 20.005.30636, 24.002.21005, 24.001.30159, 20.005.30655, 24.002.20965, 24.002.20964, 24.001.30123, 24.003.20054 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could …

Aug 14, 2024
CVE-2024-39394
7.8 HIGH

InDesign Desktop versions ID19.4, ID18.5.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Aug 14, 2024
CVE-2024-39393
7.8 HIGH

InDesign Desktop versions ID19.4, ID18.5.2 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read …

Aug 14, 2024
CVE-2024-39391
7.8 HIGH

InDesign Desktop versions ID19.4, ID18.5.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Aug 14, 2024
CVE-2024-39390
7.8 HIGH

InDesign Desktop versions ID19.4, ID18.5.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Aug 14, 2024
CVE-2024-39389
7.8 HIGH

InDesign Desktop versions ID19.4, ID18.5.2 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

Aug 14, 2024
CVE-2024-39388
7.8 HIGH

Substance3D - Stager versions 3.0.2 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

Aug 14, 2024
CVE-2024-39386
7.8 HIGH

Bridge versions 13.0.8, 14.1.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the …

Aug 14, 2024
CVE-2024-39383
7.8 HIGH

Acrobat Reader versions 20.005.30636, 24.002.20965, 24.002.20964, 24.001.30123 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in …

Aug 14, 2024
CVE-2024-34133
7.8 HIGH

Illustrator versions 28.5, 27.9.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the …

Aug 14, 2024
CVE-2024-34124
7.8 HIGH

Dimension versions 3.4.11 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current …

Aug 14, 2024
CVE-2024-34117
7.8 HIGH

Photoshop Desktop versions 24.7.3, 25.9.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

Aug 14, 2024
CVE-2024-20789
7.8 HIGH

Dimension versions 3.4.11 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the …

Aug 14, 2024
CVE-2024-34163
7.5 HIGH

Improper input validation in firmware for some Intel(R) NUC may allow a privileged user to potentially enableescalation of privilege via local access.

Aug 14, 2024
CVE-2024-28947
8.2 HIGH

Improper input validation in kernel mode driver for some Intel(R) Server Board S2600ST Family firmware before version 02.01.0017 may allow a privileged user to potentially …

Aug 14, 2024
CVE-2024-26022
7.8 HIGH

Improper access control in some Intel(R) UEFI Integrator Tools on Aptio V for Intel(R) NUC may allow an authenticated user to potentially enable escalation of …

Aug 14, 2024
CVE-2024-25576
7.9 HIGH

improper access control in firmware for some Intel(R) FPGA products before version 24.1 may allow a privileged user to enable escalation of privilege via local …

Aug 14, 2024
CVE-2024-24986
8.8 HIGH

Improper access control in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to …

Aug 14, 2024
CVE-2024-24853
7.2 HIGH

Incorrect behavior order in transition between executive monitor and SMI transfer monitor (STM) in some Intel(R) Processor may allow a privileged user to potentially enable …

Aug 14, 2024
CVE-2024-23981
8.8 HIGH

Wrap-around error in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially …

Aug 14, 2024
CVE-2024-23497
8.8 HIGH

Out-of-bounds write in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially …

Aug 14, 2024
CVE-2024-21810
8.8 HIGH

Improper input validation in the Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user …

Aug 14, 2024
CVE-2024-21807
8.8 HIGH

Improper initialization in the Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to …

Aug 14, 2024
CVE-2024-21801
7.1 HIGH

Insufficient control flow management in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable denial of service via …

Aug 14, 2024
CVE-2023-49141
7.8 HIGH

Improper isolation in some Intel(R) Processors stream cache mechanism may allow an authenticated user to potentially enable escalation of privilege via local access.

Aug 14, 2024
CVE-2023-42667
7.8 HIGH

Improper isolation in the Intel(R) Core(TM) Ultra Processor stream cache mechanism may allow an authenticated user to potentially enable escalation of privilege via local access.

Aug 14, 2024
CVE-2024-39403
7.6 HIGH

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged …

Aug 14, 2024
CVE-2024-39402
8.4 HIGH

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command …

Aug 14, 2024
CVE-2024-39401
8.4 HIGH

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command …

Aug 14, 2024
CVE-2024-39400
8.1 HIGH

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. This vulnerability could allow an admin attacker …

Aug 14, 2024
CVE-2024-39399
7.7 HIGH

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability …

Aug 14, 2024
CVE-2024-39398
7.4 HIGH

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Restriction of Excessive Authentication Attempts vulnerability that could result in a …

Aug 14, 2024
CVE-2024-4389
8.8 HIGH

The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the uploadFile …

Aug 14, 2024
CVE-2024-41864
7.8 HIGH

Substance3D - Designer versions 13.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Aug 14, 2024
CVE-2024-41858
7.8 HIGH

InCopy versions 18.5.2, 19.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context …

Aug 14, 2024
CVE-2024-7729
7.5 HIGH

The CAYIN Technology CMS lacks proper access control, allowing unauthenticated remote attackers to download arbitrary CGI files.

Aug 14, 2024
CVE-2024-7728
7.2 HIGH

The specific CGI of the CAYIN Technology CMS does not properly validate user input, allowing a remote attacker with administrator privileges to inject OS commands …

Aug 14, 2024
CVE-2024-38653
7.5 HIGH

XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on the server.

Aug 14, 2024
CVE-2024-37399
7.5 HIGH

A NULL pointer dereference in WLAvalancheService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to crash the service, resulting in a DoS.

Aug 14, 2024
CVE-2024-37373
7.2 HIGH

Improper input validation in the Central Filestore in Ivanti Avalanche 6.3.1 allows a remote authenticated attacker with admin rights to achieve RCE.

Aug 14, 2024
CVE-2024-36136
7.5 HIGH

An off-by-one error in WLInfoRailService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to crash the service, resulting in a DoS.

Aug 14, 2024
CVE-2024-38163
7.8 HIGH

Windows Update Stack Elevation of Privilege Vulnerability

Aug 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.