CVE Database

46795+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-23353
7.5 HIGH

Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI.

Aug 5, 2024
CVE-2024-23352
7.5 HIGH

Transient DOS when NAS receives ODAC criteria of length 1 and type 1 in registration accept OTA.

Aug 5, 2024
CVE-2024-21481
8.4 HIGH

Memory corruption when preparing a shared memory notification for a memparcel in Resource Manager.

Aug 5, 2024
CVE-2024-21479
7.5 HIGH

Transient DOS during music playback of ALAC content.

Aug 5, 2024
CVE-2024-7409
7.5 HIGH

A flaw was found in the QEMU NBD Server. This vulnerability allows a denial of service (DoS) attack via improper synchronization during socket closure when …

Aug 5, 2024
CVE-2024-7383
7.4 HIGH

A flaw was found in libnbd. The client did not always correctly verify the NBD server's certificate when using TLS to connect to an NBD …

Aug 5, 2024
CVE-2024-6472
7.8 HIGH

Certificate Validation user interface in LibreOffice allows potential vulnerability. Signed macros are scripts that have been digitally signed by the developer using a cryptographic signature. …

Aug 5, 2024
CVE-2024-4607
7.8 HIGH

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel …

Aug 5, 2024
CVE-2024-2937
7.8 HIGH

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel …

Aug 5, 2024
CVE-2024-36448
7.3 HIGH

** UNSUPPORTED WHEN ASSIGNED ** Server-Side Request Forgery (SSRF) vulnerability in Apache IoTDB Workbench. This issue affects Apache IoTDB Workbench: from 0.13.0. As this project …

Aug 5, 2024
CVE-2024-2232
8.1 HIGH

The lacks CSRF checks allowing a user to invite any user to any group (including private groups)

Aug 5, 2024
CVE-2024-6117
8.8 HIGH

A Unrestricted upload of file with dangerous type vulnerability in meeting management function in Hamastar MeetingHub Paperless Meetings 2021 allows remote authenticated users to perform …

Aug 5, 2024
CVE-2024-41720
8.0 HIGH

Incorrect permission assignment for critical resource issue exists in ZWX-2000CSW2-HN firmware versions prior to Ver.0.3.15, which may allow a network-adjacent authenticated attacker to alter the …

Aug 5, 2024
CVE-2024-39838
8.8 HIGH

ZWX-2000CSW2-HN firmware versions prior to Ver.0.3.15 uses hard-coded credentials, which may allow a network-adjacent attacker with an administrative privilege to alter the configuration of the …

Aug 5, 2024
CVE-2024-39713
8.6 HIGH

A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1.

Aug 5, 2024
CVE-2024-7465
8.8 HIGH

A vulnerability, which was classified as critical, was found in TOTOLINK CP450 4.1.0cu.747_B20191224. Affected is the function loginauth of the file /cgi-bin/cstecgi.cgi. The manipulation of …

Aug 5, 2024
CVE-2024-7463
8.8 HIGH

A vulnerability classified as critical was found in TOTOLINK CP900 6.3c.566. This vulnerability affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi. The manipulation of the …

Aug 5, 2024
CVE-2024-7462
8.8 HIGH

A vulnerability classified as critical has been found in TOTOLINK N350RT 9.3.5u.6139_B20201216. This affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the …

Aug 5, 2024
CVE-2024-7461
7.3 HIGH

A vulnerability was found in ForIP Tecnologia Administração PABX 1.x. It has been rated as critical. Affected by this issue is some unknown functionality of …

Aug 5, 2024
CVE-2024-7449
7.3 HIGH

A vulnerability, which was classified as critical, was found in itsourcecode Placement Management System 1.0. Affected is an unknown function of the file login.php. The …

Aug 4, 2024
CVE-2024-6331
7.5 HIGH

stitionai/devika main branch as of commit cdfb782b0e634b773b10963c8034dc9207ba1f9f is vulnerable to Local File Read (LFI) by Prompt Injection. The integration of Google Gimini 1.0 Pro with …

Aug 4, 2024
CVE-2024-7444
7.3 HIGH

A vulnerability classified as critical was found in itsourcecode Ticket Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the file login.php …

Aug 3, 2024
CVE-2024-7441
8.8 HIGH

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Vivotek SD9364 VVTK-0103f. It has been declared as critical. This vulnerability affects the function read …

Aug 3, 2024
CVE-2024-7439
8.8 HIGH

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Vivotek CC8160 VVTK-0100d and classified as critical. Affected by this issue is the function read …

Aug 3, 2024
CVE-2024-7031
7.5 HIGH

The File Manager Pro – Filester plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'njt_fs_saveSettingRestrictions' …

Aug 3, 2024
CVE-2024-7291
7.2 HIGH

The JetFormBuilder plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.3.4.1. This is due to improper restriction on …

Aug 3, 2024
CVE-2024-6477
7.5 HIGH

The UsersWP WordPress plugin before 1.2.12 uses predictable filenames when an admin generates an export, which could allow unauthenticated attackers to download them and retrieve …

Aug 3, 2024
CVE-2024-3056
7.7 HIGH

A flaw was found in Podman. This issue may allow an attacker to create a specially crafted container that, when configured to share the same …

Aug 2, 2024
CVE-2024-38891
7.5 HIGH

An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Sniffing Network Traffic …

Aug 2, 2024
CVE-2024-28298
8.8 HIGH

SQL injection vulnerability in BM SOFT BMPlanning 1.0.0.1 allows authenticated users to execute arbitrary SQL commands via the SEC_IDF, LIE_IDF, PLANF_IDF, CLI_IDF, DOS_IDF, and possibly …

Aug 2, 2024
CVE-2024-28297
7.5 HIGH

SQL injection vulnerability in AzureSoft MyHorus 4.3.5 allows authenticated users to execute arbitrary SQL commands via unspecified vectors.

Aug 2, 2024
CVE-2024-38885
7.5 HIGH

An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform unauthorized access using known …

Aug 2, 2024
CVE-2024-38884
7.8 HIGH

An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a local attacker to perform an Authentication Bypass attack …

Aug 2, 2024
CVE-2024-38881
7.5 HIGH

An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Rainbow Table Password …

Aug 2, 2024
CVE-2024-33896
7.2 HIGH

Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to code injection due to improper parameter blacklisting. This …

Aug 2, 2024
CVE-2024-33894
8.8 HIGH

Insecure Permission vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are executing several processes with elevated privileges.

Aug 2, 2024
CVE-2024-33892
7.5 HIGH

Insecure Permissions vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are susceptible to leaking information through cookies. …

Aug 2, 2024
CVE-2024-41518
7.5 HIGH

An Incorrect Access Control vulnerability in "/admin/programm/<program_id>/export/statistics" in Feripro <= v2.2.3 allows remote attackers to export an XLSX file with information about registrations and participants.

Aug 2, 2024
CVE-2024-41310
7.5 HIGH

AndServer 2.1.12 is vulnerable to Directory Traversal.

Aug 2, 2024
CVE-2024-7029
8.8 HIGH

Commands can be injected over the network and executed without authentication.

Aug 2, 2024
CVE-2024-41127
8.3 HIGH

Monkeytype is a minimalistic and customizable typing test. Monkeytype is vulnerable to Poisoned Pipeline Execution through Code Injection in its ci-failure-comment.yml GitHub Workflow, enabling attackers …

Aug 2, 2024
CVE-2024-38890
8.4 HIGH

An issue in Horizon Business Services Inc. Caterease Software 16.0.1.1663 through 24.0.1.2405 and possibly later versions allows a local attacker to perform an Authentication Bypass …

Aug 2, 2024
CVE-2024-40721
8.8 HIGH

The specific API in TCBServiSign Windows Version from CHANGING Information Technology does not properly validate server-side input. When a user visits a spoofed website, unauthenticated …

Aug 2, 2024
CVE-2024-40720
8.8 HIGH

The specific API in TCBServiSign Windows Version from CHANGING Information Technology does not properly validate server-side input. When a user visits a spoofed website, unauthenticated …

Aug 2, 2024
CVE-2024-38879
7.5 HIGH

A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 R8.2 SP3 (All versions), Omnivise T3000 R8.2 SP4 (All versions). …

Aug 2, 2024
CVE-2024-38878
7.2 HIGH

A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 R8.2 SP3 (All versions), Omnivise T3000 R8.2 SP4 (All versions). …

Aug 2, 2024
CVE-2024-38877
8.2 HIGH

A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 Domain Controller R9.2 (All versions), Omnivise T3000 Network Intrusion Detection …

Aug 2, 2024
CVE-2024-38876
7.8 HIGH

A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 Domain Controller R9.2 (All versions), Omnivise T3000 Product Data Management …

Aug 2, 2024
CVE-2024-27181
8.8 HIGH

In Apache Linkis <= 1.5.0, Privilege Escalation in Basic management services where the attacking user is a trusted account allows access to Linkis's Token information. …

Aug 2, 2024
CVE-2024-38776
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Martin Gibson WP GoToWebinar allows Cross-Site Scripting (XSS).This issue affects WP GoToWebinar: from n/a through 15.7.

Aug 2, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.