CVE Database

46795+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-38126
7.5 HIGH

Windows Network Address Translation (NAT) Denial of Service Vulnerability

Aug 13, 2024
CVE-2024-38125
7.8 HIGH

Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability

Aug 13, 2024
CVE-2024-38121
8.8 HIGH

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

Aug 13, 2024
CVE-2024-38120
8.8 HIGH

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

Aug 13, 2024
CVE-2024-38117
7.8 HIGH

NTFS Elevation of Privilege Vulnerability

Aug 13, 2024
CVE-2024-38116
8.8 HIGH

Windows IP Routing Management Snapin Remote Code Execution Vulnerability

Aug 13, 2024
CVE-2024-38115
8.8 HIGH

Windows IP Routing Management Snapin Remote Code Execution Vulnerability

Aug 13, 2024
CVE-2024-38114
8.8 HIGH

Windows IP Routing Management Snapin Remote Code Execution Vulnerability

Aug 13, 2024
CVE-2024-38107
7.8 HIGH KEV

Windows Power Dependency Coordinator Elevation of Privilege Vulnerability

Aug 13, 2024
CVE-2024-38106
7.0 HIGH KEV

Windows Kernel Elevation of Privilege Vulnerability

Aug 13, 2024
CVE-2024-38098
7.8 HIGH

Azure Connected Machine Agent Elevation of Privilege Vulnerability

Aug 13, 2024
CVE-2024-38084
7.8 HIGH

Microsoft OfficePlus Elevation of Privilege Vulnerability

Aug 13, 2024
CVE-2024-37968
7.5 HIGH

Windows DNS Spoofing Vulnerability

Aug 13, 2024
CVE-2024-29995
8.1 HIGH

Windows Kerberos Elevation of Privilege Vulnerability

Aug 13, 2024
CVE-2024-37015
7.4 HIGH

An issue was discovered in Ada Web Server 20.0. When configured to use SSL (which is not the default setting), the SSL/TLS used to establish …

Aug 13, 2024
CVE-2024-36446
8.8 HIGH

The provisioning manager component of Mitel MiVoice MX-ONE through 7.6 SP1 could allow an authenticated attacker to conduct an authentication bypass attack due to improper …

Aug 13, 2024
CVE-2023-31349
7.3 HIGH

Incorrect default permissions in the AMD μProf installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

Aug 13, 2024
CVE-2023-31348
7.3 HIGH

A DLL hijacking vulnerability in AMD μProf could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

Aug 13, 2024
CVE-2023-31341
7.3 HIGH

Insufficient validation of the Input Output Control (IOCTL) input buffer in AMD μProf may allow an authenticated attacker to cause an out-of-bounds write, potentially causing …

Aug 13, 2024
CVE-2023-20578
7.5 HIGH

A TOCTOU (Time-Of-Check-Time-Of-Use) in SMM may allow an attacker with ring0 privileges and access to the BIOS menu or UEFI shell to modify the communications …

Aug 13, 2024
CVE-2022-23815
7.5 HIGH

Improper bounds checking in APCB firmware may allow an attacker to perform an out of bounds write, corrupting the APCB entry, potentially leading to arbitrary …

Aug 13, 2024
CVE-2021-26344
7.2 HIGH

An out of bounds memory write when processing the AMD PSP1 Configuration Block (APCB) could allow an attacker with access the ability to modify the …

Aug 13, 2024
CVE-2024-6788
8.6 HIGH

A remote unauthenticated attacker can use the firmware update feature on the LAN interface of the device to reset the password for the predefined, low-privileged …

Aug 13, 2024
CVE-2024-42739
8.8 HIGH

In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setAccessDeviceCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.

Aug 13, 2024
CVE-2024-42738
8.8 HIGH

In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setDmzCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.

Aug 13, 2024
CVE-2024-42737
8.8 HIGH

In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in delBlacklist. Authenticated Attackers can send malicious packet to execute arbitrary commands.

Aug 13, 2024
CVE-2024-42736
7.8 HIGH

In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in addBlacklist. Authenticated Attackers can send malicious packet to execute arbitrary commands.

Aug 13, 2024
CVE-2024-5849
7.1 HIGH

An unauthenticated remote attacker may use a reflected XSS vulnerability to obtain information from a user or reboot the affected device once.

Aug 13, 2024
CVE-2024-38502
7.1 HIGH

An unauthenticated remote attacker may use stored XSS vulnerability to obtain information from a user or reboot the affected device once.

Aug 13, 2024
CVE-2024-43140
7.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in G5Theme Ultimate Bootstrap Elements for Elementor allows PHP Local File Inclusion.This issue …

Aug 13, 2024
CVE-2024-35124
7.5 HIGH

A vulnerability in the combination of the OpenBMC's FW1050.00 through FW1050.10, FW1030.00 through FW1030.50, and FW1020.00 through FW1020.60 default password and session management allow an …

Aug 13, 2024
CVE-2024-43135
7.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themewinter WPCafe allows PHP Local File Inclusion.This issue affects WPCafe: from n/a …

Aug 13, 2024
CVE-2024-43131
7.5 HIGH

Incorrect Authorization vulnerability in WPWeb Docket (WooCommerce Collections / Wishlist / Watchlist) allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Docket (WooCommerce Collections …

Aug 13, 2024
CVE-2024-40697
7.5 HIGH

IBM Common Licensing 9.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. …

Aug 13, 2024
CVE-2024-39651
8.6 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPWeb WooCommerce PDF Vouchers allows File Manipulation.This issue affects WooCommerce PDF Vouchers: …

Aug 13, 2024
CVE-2024-38787
7.5 HIGH

Insertion of Sensitive Information Into Sent Data vulnerability in Javier Carazo Import and export users and customers import-users-from-csv-with-meta.This issue affects Import and export users and …

Aug 13, 2024
CVE-2024-38747
7.5 HIGH

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HitPay Payment Solutions Pte Ltd HitPay Payment Gateway for WooCommerce allows Accessing Functionality Not Properly …

Aug 13, 2024
CVE-2024-38724
7.1 HIGH

Cross-Site Request Forgery (CSRF), Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Muhammad Rehman Contact Form 7 Summary and …

Aug 13, 2024
CVE-2024-38699
7.5 HIGH

Missing Authorization vulnerability in WP Swings Wallet System for WooCommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Wallet System for WooCommerce: from …

Aug 13, 2024
CVE-2024-37935
7.5 HIGH

Missing Authorization vulnerability in anhvnit Woocommerce OpenPos allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Woocommerce OpenPos: from n/a through 6.4.4.

Aug 13, 2024
CVE-2024-41977
7.1 HIGH

A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.1), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V8.1), SCALANCE …

Aug 13, 2024
CVE-2024-41976
7.2 HIGH

A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.1), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V8.1), SCALANCE …

Aug 13, 2024
CVE-2024-41939
8.8 HIGH

A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application does not properly enforce authorization checks. This could allow an …

Aug 13, 2024
CVE-2024-41908
7.8 HIGH

A vulnerability has been identified in NX (All versions < V2406.3000). The affected applications contains an out of bounds read vulnerability while parsing specially crafted …

Aug 13, 2024
CVE-2024-41904
7.5 HIGH

A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V2.0). The affected application do not properly enforce restriction of excessive authentication …

Aug 13, 2024
CVE-2024-36398
7.8 HIGH

A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application executes a subset of its services as `NT AUTHORITY\SYSTEM`. This …

Aug 13, 2024
CVE-2024-6823
8.8 HIGH

The Media Library Assistant plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation involving the mla-inline-edit-upload-scripts AJAX action in …

Aug 13, 2024
CVE-2024-42374
8.2 HIGH

BEx Web Java Runtime Export Web Service does not sufficiently validate an XML document accepted from an untrusted source. An attacker can retrieve information from …

Aug 13, 2024
CVE-2024-33003
7.4 HIGH

Some OCC API endpoints in SAP Commerce Cloud allows Personally Identifiable Information (PII) data, such as passwords, email addresses, mobile numbers, coupon codes, and voucher …

Aug 13, 2024
CVE-2024-7707
8.8 HIGH

A vulnerability was found in Tenda FH1206 02.03.01.35 and classified as critical. Affected by this issue is the function formSafeEmailFilter of the file /goform/SafeEmailFilter of …

Aug 13, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.