CVE Database

46795+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-40464
8.8 HIGH

An issue in beego v.2.2.0 and before allows a remote attacker to escalate privileges via the sendMail function located in beego/core/logs/smtp.go file

Jul 31, 2024
CVE-2023-1577
7.8 HIGH

A path hijacking vulnerability was reported in Lenovo Driver Manager prior to version 3.1.1307.1308 that could allow a local user to execute code with elevated …

Jul 31, 2024
CVE-2022-4002
7.2 HIGH

A command injection vulnerability could allow an authenticated user to execute operating system commands as root via a specially crafted API request.

Jul 31, 2024
CVE-2022-4001
7.3 HIGH

An authentication bypass vulnerability could allow an attacker to access API functions without authentication.

Jul 31, 2024
CVE-2019-6198
7.8 HIGH

A vulnerability was reported in Lenovo PC Manager prior to version 2.8.90.11211 that could allow a local attacker to escalate privileges.

Jul 31, 2024
CVE-2019-6197
7.8 HIGH

A vulnerability was reported in Lenovo PC Manager prior to version 2.8.90.11211 that could allow a local attacker to escalate privileges.

Jul 31, 2024
CVE-2024-7325
7.8 HIGH

A vulnerability was found in IObit Driver Booster 11.0.0.0. It has been rated as critical. Affected by this issue is some unknown functionality in the …

Jul 31, 2024
CVE-2024-41630
7.6 HIGH

Stack-based buffer overflow vulnerability in Tenda AC18 V15.03.3.10_EN allows a remote attacker to execute arbitrary code via the ssid parameter at ip/goform/fast_setting_wifi_set.

Jul 31, 2024
CVE-2024-41108
7.5 HIGH

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. The hostinfo page has missing/improper access control since only the host's mac address is required to …

Jul 31, 2024
CVE-2024-40645
8.8 HIGH

FOG is a cloning/imaging/rescue suite/inventory management system. An improperly restricted file upload feature allows authenticated users to execute arbitrary code on the fogproject server. The …

Jul 31, 2024
CVE-2024-7324
7.8 HIGH

A vulnerability was found in IObit iTop Data Recovery Pro 4.4.0.687. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Jul 31, 2024
CVE-2024-6975
8.8 HIGH

Cato Networks Windows SDP Client Local Privilege Escalation via openssl configuration file. This issue affects SDP Client before 5.10.34.

Jul 31, 2024
CVE-2024-6974
8.8 HIGH

Cato Networks Windows SDP Client Local Privilege Escalation via self-upgradeThis issue affects SDP Client: before 5.10.34.

Jul 31, 2024
CVE-2024-6973
7.5 HIGH

Remote Code Execution in Cato Windows SDP client via crafted URLs. This issue affects Windows SDP Client before 5.10.34.

Jul 31, 2024
CVE-2024-41950
7.5 HIGH

Haystack is an end-to-end LLM framework that allows you to build applications powered by LLMs, Transformer models, vector search and more. Haystack clients that let …

Jul 31, 2024
CVE-2024-7340
8.8 HIGH

The Weave server API allows remote users to fetch files from a specific directory, but due to a lack of input validation, it is possible …

Jul 31, 2024
CVE-2024-3083
8.3 HIGH

A “CWE-352: Cross-Site Request Forgery (CSRF)” can be exploited by remote attackers to perform state-changing operations with administrative privileges by luring authenticated victims into visiting …

Jul 31, 2024
CVE-2024-31202
7.8 HIGH

A “CWE-732: Incorrect Permission Assignment for Critical Resource” in the ThermoscanIP installation folder allows a local attacker to perform a Local Privilege Escalation.

Jul 31, 2024
CVE-2024-31199
8.8 HIGH

A “CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')” allows malicious users to permanently inject arbitrary Javascript code.

Jul 31, 2024
CVE-2024-7320
7.3 HIGH

A vulnerability classified as critical has been found in itsourcecode Online Blood Bank Management System 1.0. This affects an unknown part of the file /admin/index.php …

Jul 31, 2024
CVE-2024-7311
7.3 HIGH

A vulnerability was found in code-projects Online Bus Reservation Site 1.0. It has been rated as critical. This issue affects some unknown processing of the …

Jul 31, 2024
CVE-2024-37142
7.3 HIGH

Dell Peripheral Manager, versions prior to 1.7.6, contain an uncontrolled search path element vulnerability. An attacker could potentially exploit this vulnerability through preloading malicious DLL …

Jul 31, 2024
CVE-2024-37127
7.8 HIGH

Dell Peripheral Manager, versions prior to 1.7.6, contain an uncontrolled search path element vulnerability. An attacker could potentially exploit this vulnerability through preloading malicious DLL …

Jul 31, 2024
CVE-2024-32857
7.3 HIGH

Dell Peripheral Manager, versions prior to 1.7.6, contain an uncontrolled search path element vulnerability. An attacker could potentially exploit this vulnerability through preloading malicious DLL …

Jul 31, 2024
CVE-2024-6770
7.2 HIGH

The Lifetime free Drag & Drop Contact Form Builder for WordPress VForm plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up …

Jul 31, 2024
CVE-2024-42381
8.3 HIGH

os/linux/elf.rb in Homebrew brew before 4.2.20 uses ldd to load ELF files obtained from untrusted sources, which allows attackers to achieve code execution via an …

Jul 31, 2024
CVE-2024-7286
7.3 HIGH

A vulnerability was found in SourceCodester Establishment Billing Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/ajax.php?action=login …

Jul 31, 2024
CVE-2024-39950
8.6 HIGH

A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities to initiate device initialization.

Jul 31, 2024
CVE-2024-39949
7.5 HIGH

A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities, causing the device to crash.

Jul 31, 2024
CVE-2024-39948
7.5 HIGH

A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities, causing the device to crash.

Jul 31, 2024
CVE-2024-39944
7.5 HIGH

A vulnerability has been found in Dahua products.Attackers can send carefully crafted data packets to the interface with vulnerabilities, causing the device to crash.

Jul 31, 2024
CVE-2024-7279
7.3 HIGH

A vulnerability was found in SourceCodester Lot Reservation Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file …

Jul 31, 2024
CVE-2024-6255
8.2 HIGH

A vulnerability in the JSON file handling of gaizhenbiao/chuanhuchatgpt version 20240410 allows any user to delete any JSON file on the server, including critical configuration …

Jul 31, 2024
CVE-2023-33976
7.5 HIGH

TensorFlow is an end-to-end open source platform for machine learning. `array_ops.upper_bound` causes a segfault when not given a rank 2 tensor. The fix will be …

Jul 30, 2024
CVE-2024-7297
8.8 HIGH

Langflow versions prior to 1.0.13 suffer from a Privilege Escalation vulnerability, allowing a remote and low privileged attacker to gain super admin privileges by performing …

Jul 30, 2024
CVE-2024-41915
7.2 HIGH

A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass …

Jul 30, 2024
CVE-2024-41802
8.1 HIGH

Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the API routes inside the CMS responsible for Filtering DataSets. This …

Jul 30, 2024
CVE-2024-23091
7.5 HIGH

Weak password hashing using MD5 in funzioni.php in HotelDruid before 1.32 allows an attacker to obtain plaintext passwords from hash values.

Jul 30, 2024
CVE-2024-41924
7.2 HIGH

Acceptance of extraneous untrusted data with trusted data vulnerability exists in EC-CUBE 4 series. If this vulnerability is exploited, an attacker who obtained the administrative …

Jul 30, 2024
CVE-2024-41696
7.5 HIGH

Priority PRI WEB Portal Add-On for Priority ERP on prem - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Jul 30, 2024
CVE-2024-41695
7.5 HIGH

Cybonet - CWE-22: Improper Limitation of a Pathname to a Restricted Directory

Jul 30, 2024
CVE-2024-38429
7.5 HIGH

Matrix Tafnit v8 - CWE-552: Files or Directories Accessible to External Parties

Jul 30, 2024
CVE-2024-42228
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Using uninitialized value *size when calling amdgpu_vce_cs_reloc Initialize the size before calling amdgpu_vce_cs_reloc, such …

Jul 30, 2024
CVE-2024-42225
7.5 HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: replace skb_put with skb_put_zero Avoid potentially reusing uninitialized data

Jul 30, 2024
CVE-2024-42162
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: gve: Account for stopped queues when reading NIC stats We now account for the fact …

Jul 30, 2024
CVE-2024-42160
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: f2fs: check validation of fault attrs in f2fs_build_fault_attr() - It missed to check validation of …

Jul 30, 2024
CVE-2024-42159
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: scsi: mpi3mr: Sanitise num_phys Information is stored in mr_sas_port->phy_mask, values larger then size of this …

Jul 30, 2024
CVE-2024-42148
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: bnx2x: Fix multiple UBSAN array-index-out-of-bounds Fix UBSAN warnings that occur when using a system with …

Jul 30, 2024
CVE-2024-42147
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/debugfs - Fix debugfs uninit process issue During the zip probe process, the debugfs …

Jul 30, 2024
CVE-2024-42138
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: mlxsw: core_linecards: Fix double memory deallocation in case of invalid INI file In case of …

Jul 30, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.