CVE Database

46795+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-6200
8.0 HIGH

HaloITSM versions up to 2.146.1 are affected by a Stored Cross-Site Scripting (XSS) vulnerability. The injected JavaScript code can execute arbitrary action on behalf of …

Aug 6, 2024
CVE-2024-5709
8.8 HIGH

The WPBakery Visual Composer plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.7 via the 'layout_name' parameter. …

Aug 6, 2024
CVE-2024-7505
7.3 HIGH

A vulnerability, which was classified as critical, was found in itsourcecode Bike Delivery System 1.0. Affected is an unknown function of the file contact_us_action.php. The …

Aug 6, 2024
CVE-2024-6781
7.5 HIGH

Path traversal in Calibre <= 7.14.0 allow unauthenticated attackers to achieve arbitrary file read.

Aug 6, 2024
CVE-2024-7498
7.3 HIGH

A vulnerability was found in itsourcecode Airline Reservation System 1.0. It has been classified as critical. Affected is the function login/login2 of the file /admin/login.php …

Aug 6, 2024
CVE-2024-5828
8.6 HIGH

Expression Language Injection vulnerability in Hitachi Tuning Manager on Windows, Linux, Solaris allows Code Injection.This issue affects Hitachi Tuning Manager: before 8.8.7-00.

Aug 6, 2024
CVE-2024-7485
7.2 HIGH

The Traffic Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page' parameter in the 'UserWebStat' AJAX function in all versions up …

Aug 6, 2024
CVE-2024-7484
7.2 HIGH

The CRM Perks Forms plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file validation on the 'handle_uploaded_files' function in versions up …

Aug 6, 2024
CVE-2024-6315
8.8 HIGH

The Blox Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'handleUploadFile' function in all …

Aug 6, 2024
CVE-2023-5000
8.8 HIGH

The Horizontal scrolling announcements plugin for WordPress is vulnerable to SQL Injection via the plugin's 'hsas-shortcode' shortcode in versions up to, and including, 2.4 due …

Aug 6, 2024
CVE-2024-7547
7.8 HIGH

oFono SMS Decoder Stack-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker …

Aug 6, 2024
CVE-2024-7546
7.8 HIGH

oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must …

Aug 6, 2024
CVE-2024-7545
7.8 HIGH

oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must …

Aug 6, 2024
CVE-2024-7544
7.8 HIGH

oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must …

Aug 6, 2024
CVE-2024-7543
7.8 HIGH

oFono SimToolKit Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must …

Aug 6, 2024
CVE-2024-7539
7.8 HIGH

oFono CUSD Stack-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An attacker must …

Aug 6, 2024
CVE-2024-7538
7.8 HIGH

oFono CUSD AT Command Stack-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows local attackers to execute arbitrary code on affected installations of oFono. An …

Aug 6, 2024
CVE-2024-42352
8.6 HIGH

Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. `nuxt/icon` provides an API to allow client side icon …

Aug 5, 2024
CVE-2024-34344
8.8 HIGH

Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. Due to the insufficient validation of the `path` parameter …

Aug 5, 2024
CVE-2024-23657
8.8 HIGH

Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. Nuxt Devtools is missing authentication on the `getTextAssetContent` RPC …

Aug 5, 2024
CVE-2024-41959
7.6 HIGH

mailcow: dockerized is an open source groupware/email suite based on docker. An unauthenticated attacker can inject a JavaScript payload into the API logs. This payload …

Aug 5, 2024
CVE-2024-42010
7.5 HIGH

mod_css_styles in Roundcube through 1.5.7 and 1.6.x through 1.6.7 insufficiently filters Cascading Style Sheets (CSS) token sequences in rendered e-mail messages, allowing a remote attacker …

Aug 5, 2024
CVE-2024-41376
8.8 HIGH

dzzoffice 2.02.1 is vulnerable to Directory Traversal via user/space/about.php.

Aug 5, 2024
CVE-2024-40531
8.8 HIGH

A mass assignment vulnerability exists in Pantera CRM versions 401.152 and 402.072. This flaw allows authenticated users to modify any user attribute, including roles, by …

Aug 5, 2024
CVE-2024-40530
7.5 HIGH

A vulnerability in Pantera CRM versions 401.152 and 402.072 allows unauthorized attackers to bypass IP-based access controls by manipulating the X-Forwarded-For header.

Aug 5, 2024
CVE-2024-21980
7.9 HIGH

Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to potentially overwrite a guest's memory or UMC seed resulting in loss …

Aug 5, 2024
CVE-2024-33034
8.4 HIGH

Memory corruption can occur if VBOs hold outdated or invalid GPU SMMU mappings, especially when the binding and reclaiming of memory buffers are performed at …

Aug 5, 2024
CVE-2024-33028
8.4 HIGH

Memory corruption as fence object may still be accessed in timeline destruct after isync fence is released.

Aug 5, 2024
CVE-2024-33027
8.4 HIGH

Memory corruption can occur when arbitrary user-space app gains kernel level privilege to modify DDR memory by corrupting the GPU page table.

Aug 5, 2024
CVE-2024-33026
7.5 HIGH

Transient DOS while parsing probe response and assoc response frame when received frame length is less than max size of timestamp.

Aug 5, 2024
CVE-2024-33025
7.5 HIGH

Transient DOS while parsing the BSS parameter change count or MLD capabilities fields of the ML IE.

Aug 5, 2024
CVE-2024-33024
7.5 HIGH

Transient DOS while parsing the ML IE when a beacon with length field inside the common info of ML IE greater than the ML IE …

Aug 5, 2024
CVE-2024-33023
8.4 HIGH

Memory corruption while creating a fence to wait on timeline events, and simultaneously signal timeline events.

Aug 5, 2024
CVE-2024-33022
8.4 HIGH

Memory corruption while allocating memory in HGSL driver.

Aug 5, 2024
CVE-2024-33021
8.4 HIGH

Memory corruption while processing IOCTL call to set metainfo.

Aug 5, 2024
CVE-2024-33020
7.5 HIGH

Transient DOS while processing TID-to-link mapping IE elements.

Aug 5, 2024
CVE-2024-33019
7.5 HIGH

Transient DOS while parsing the received TID-to-link mapping action frame.

Aug 5, 2024
CVE-2024-33018
7.5 HIGH

Transient DOS while parsing the received TID-to-link mapping element of the TID-to-link mapping action frame.

Aug 5, 2024
CVE-2024-33015
7.5 HIGH

Transient DOS while parsing SCAN RNR IE when bytes received from AP is such that the size of the last param of IE is less …

Aug 5, 2024
CVE-2024-33014
7.5 HIGH

Transient DOS while parsing ESP IE from beacon/probe response frame.

Aug 5, 2024
CVE-2024-33013
7.5 HIGH

Transient DOS when driver accesses the ML IE memory and offset value is incremented beyond ML IE length.

Aug 5, 2024
CVE-2024-33012
7.5 HIGH

Transient DOS while parsing the multiple MBSSID IEs from the beacon, when the tag length is non-zero value but with end of beacon.

Aug 5, 2024
CVE-2024-33011
7.5 HIGH

Transient DOS while parsing the MBSSID IE from the beacons, when the MBSSID IE length is zero.

Aug 5, 2024
CVE-2024-33010
7.5 HIGH

Transient DOS while parsing fragments of MBSSID IE from beacon frame.

Aug 5, 2024
CVE-2024-23384
8.4 HIGH

Memory corruption when the mapped pages in VBO are still mapped after reclaiming by shrinker.

Aug 5, 2024
CVE-2024-23383
8.4 HIGH

Memory corruption when kernel driver attempts to trigger hardware fences.

Aug 5, 2024
CVE-2024-23382
8.4 HIGH

Memory corruption while processing graphics kernel driver request to create DMA fence.

Aug 5, 2024
CVE-2024-23381
8.4 HIGH

Memory corruption when memory mapped in a VBO is not unmapped by the GPU SMMU.

Aug 5, 2024
CVE-2024-23356
7.8 HIGH

Memory corruption during session sign renewal request calls in HLOS.

Aug 5, 2024
CVE-2024-23355
7.8 HIGH

Memory corruption when keymaster operation imports a shared key.

Aug 5, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.