CVE Database

47087+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-29509
8.8 HIGH

Artifex Ghostscript before 10.03.0 has a heap-based overflow when PDFPassword (e.g., for runpdf) has a \000 byte in the middle.

Jul 3, 2024
CVE-2024-29506
8.8 HIGH

Artifex Ghostscript before 10.03.0 has a stack-based buffer overflow in the pdfi_apply_filter() function via a long PDF filter name.

Jul 3, 2024
CVE-2023-52169
8.2 HIGH

The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains an out-of-bounds read that allows an attacker to read beyond the intended buffer. The …

Jul 3, 2024
CVE-2023-52168
8.4 HIGH

The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains a heap-based buffer overflow that allows an attacker to overwrite two bytes at multiple …

Jul 3, 2024
CVE-2024-32937
8.1 HIGH

An os command injection vulnerability exists in the CWMP SelfDefinedTimeZone functionality of Grandstream GXP2135 1.0.9.129, 1.0.11.74 and 1.0.11.79. A specially crafted network packet can lead …

Jul 3, 2024
CVE-2024-5672
7.2 HIGH

A high privileged remote attacker can execute arbitrary system commands via GET requests due to improper neutralization of special elements used in an OS command.

Jul 3, 2024
CVE-2024-6427
7.5 HIGH

Uncontrolled Resource Consumption vulnerability in MESbook 20221021.03 version. An unauthenticated remote attacker can use the "message" parameter to inject a payload with dangerous JavaScript code, …

Jul 3, 2024
CVE-2024-6426
8.1 HIGH

Information exposure vulnerability in MESbook 20221021.03 version, the exploitation of which could allow a local attacker, with user privileges, to access different resources by changing …

Jul 3, 2024
CVE-2024-39830
8.1 HIGH

Mattermost versions 9.8.x <= 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5, when shared channels are enabled, fail to use constant time …

Jul 3, 2024
CVE-2024-38453
7.5 HIGH

The Avalara for Salesforce CPQ app before 7.0 for Salesforce allows attackers to read an API key. NOTE: the current version is 11 as of …

Jul 3, 2024
CVE-2024-2376
8.8 HIGH

The WPQA Builder WordPress plugin before 6.1.1 does not have CSRF checks in some places, which could allow attackers to make logged in users perform …

Jul 3, 2024
CVE-2024-24791
7.5 HIGH

The net/http HTTP/1.1 client mishandled the case where a server responds to a request with an "Expect: 100-continue" header with a non-informational (200 or higher) …

Jul 2, 2024
CVE-2022-30636
7.5 HIGH

httpTokenCacheKey uses path.Base to extract the expected HTTP-01 token value to lookup in the DirCache implementation. On Windows, path.Base acts differently to filepath.Base, since Windows …

Jul 2, 2024
CVE-2022-25480
7.8 HIGH

Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 allows writing …

Jul 2, 2024
CVE-2022-25478
7.8 HIGH

Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 provides read …

Jul 2, 2024
CVE-2024-39894
7.5 HIGH

OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) because of an ObscureKeystrokeTiming logic error. …

Jul 2, 2024
CVE-2024-39206
7.5 HIGH

An issue discovered in MSP360 Backup Agent v7.8.5.15 and v7.9.4.84 allows attackers to obtain network share credentials used in a backup due to enginesettings.list being …

Jul 2, 2024
CVE-2024-5865
7.7 HIGH

Vulnerability in Delinea Centrify PAS v. 21.3 and possibly others. The application is prone to the path traversal vulnerability allowing arbitrary files reading outside the …

Jul 2, 2024
CVE-2024-4467
7.8 HIGH

A flaw was found in the QEMU disk image utility (qemu-img) 'info' command. A specially crafted image file containing a `json:{}` value describing block devices …

Jul 2, 2024
CVE-2024-39323
7.1 HIGH

aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.01 and prior to versions 2022.10.10, 2023.10.6, and 2024.04.6, an improper access control vulnerability …

Jul 2, 2024
CVE-2024-26314
7.8 HIGH

Improper privilege management in Jungo WinDriver 6.0.0 through 16.1.0 allows local attackers to escalate privileges and execute arbitrary code.

Jul 2, 2024
CVE-2024-25088
7.8 HIGH

Improper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges and execute arbitrary code.

Jul 2, 2024
CVE-2024-25086
7.8 HIGH

Improper privilege management in Jungo WinDriver before 12.2.0 allows local attackers to escalate privileges and execute arbitrary code.

Jul 2, 2024
CVE-2024-22106
7.8 HIGH

Improper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges, execute arbitrary code, or cause a Denial of Service (DoS).

Jul 2, 2024
CVE-2024-4897
8.4 HIGH

parisneo/lollms-webui, in its latest version, is vulnerable to remote code execution due to an insecure dependency on llama-cpp-python version llama_cpp_python-0.2.61+cpuavx2-cp311-cp311-manylinux_2_31_x86_64. The vulnerability arises from the …

Jul 2, 2024
CVE-2023-51776
7.8 HIGH

Improper privilege management in Jungo WinDriver before 12.1.0 allows local attackers to escalate privileges and execute arbitrary code.

Jul 2, 2024
CVE-2024-38519
7.8 HIGH

`yt-dlp` and `youtube-dl` are command-line audio/video downloaders. Prior to the fixed versions, `yt-dlp` and `youtube-dl` do not limit the extensions of downloaded files, which could …

Jul 2, 2024
CVE-2024-34122
7.8 HIGH

Acrobat for Edge versions 126.0.2592.68 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read …

Jul 2, 2024
CVE-2024-34595
7.8 HIGH

Improper access control in clickAdapterItem of SystemUI prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities.

Jul 2, 2024
CVE-2024-34593
7.5 HIGH

Improper input validation in parsing and distributing RTCP packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to execute arbitrary code with …

Jul 2, 2024
CVE-2024-34587
7.5 HIGH

Improper input validation in parsing application information from RTCP packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to execute arbitrary code …

Jul 2, 2024
CVE-2024-34585
7.8 HIGH

Improper access control in launchApp of SystemUI prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities.

Jul 2, 2024
CVE-2024-20895
7.7 HIGH

Improper access control in Dar service prior to SMR Jul-2024 Release 1 allows local attackers to bypass restriction for calling SDP features.

Jul 2, 2024
CVE-2024-20891
7.8 HIGH

Improper access control in launchFullscreenIntent of SystemUI prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities.

Jul 2, 2024
CVE-2024-20888
7.8 HIGH

Improper access control in OneUIHome prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities. User interaction is required for triggering this …

Jul 2, 2024
CVE-2024-4836
7.5 HIGH

Web services managed by Edito CMS (Content Management System) in versions from 3.5 through 3.25 leak sensitive data as they allow downloading configuration files by …

Jul 2, 2024
CVE-2024-37185
8.2 HIGH

in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds write.

Jul 2, 2024
CVE-2024-37077
8.2 HIGH

in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds write.

Jul 2, 2024
CVE-2024-37030
8.2 HIGH

in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through use after free.

Jul 2, 2024
CVE-2024-36260
8.2 HIGH

in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds write.

Jul 2, 2024
CVE-2024-36243
8.2 HIGH

in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds read and write.

Jul 2, 2024
CVE-2024-37479
8.5 HIGH

Local File Inclusion vulnerability in LA-Studio LA-Studio Element Kit for Elementor via "LaStudioKit Progress Bar" widget in New Post, specifically in the "progress_type" attribute.This issue …

Jul 2, 2024
CVE-2023-41926
8.8 HIGH

The webserver utilizes basic authentication for its user login to the configuration interface. As encryption is disabled on port 80, it enables potential eavesdropping on …

Jul 2, 2024
CVE-2023-41923
7.2 HIGH

The user management section of the web application permits the creation of user accounts with excessively weak passwords, including single-character passwords.

Jul 2, 2024
CVE-2023-41922
7.2 HIGH

A 'Cross-site Scripting' (XSS) vulnerability, characterized by improper input neutralization during web page generation, has been discovered. This vulnerability allows for Stored XSS attacks to …

Jul 2, 2024
CVE-2024-5767
8.8 HIGH

The sitetweet WordPress plugin through 0.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow …

Jul 2, 2024
CVE-2024-5606
8.8 HIGH

The Quiz and Survey Master (QSM) WordPress plugin before 9.0.2 is vulnerable does not validate and escape the question_id parameter in the qsm_bulk_delete_question_from_database AJAX action, …

Jul 2, 2024
CVE-2024-5349
8.8 HIGH

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.8.1 via the …

Jul 2, 2024
CVE-2024-4679
7.8 HIGH

Incorrect Default Permissions vulnerability in Hitachi JP1/Extensible SNMP Agent for Windows, Hitachi JP1/Extensible SNMP Agent on Windows, Hitachi Job Management Partner1/Extensible SNMP Agent on Windows …

Jul 2, 2024
CVE-2024-37765
8.8 HIGH

Machform up to version 19 is affected by an authenticated Blind SQL injection in the user account settings page.

Jul 1, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.