CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-7754
6.3 MEDIUM

A vulnerability was found in SourceCodester Clinics Patient Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the …

Aug 14, 2024
CVE-2024-7753
5.3 MEDIUM

A vulnerability was found in SourceCodester Clinics Patient Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file …

Aug 14, 2024
CVE-2024-7751
6.3 MEDIUM

A vulnerability was found in SourceCodester Clinics Patient Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Aug 13, 2024
CVE-2024-7750
6.3 MEDIUM

A vulnerability has been found in SourceCodester Clinics Patient Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Aug 13, 2024
CVE-2024-7748
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Accounts Manager App 1.0. This issue affects some unknown processing of the file …

Aug 13, 2024
CVE-2024-7741
5.3 MEDIUM

A vulnerability was found in wanglongcn ltcms 1.0.20 and classified as critical. This issue affects the function downloadFile of the file /api/file/downloadfile of the component …

Aug 13, 2024
CVE-2024-42368
6.5 MEDIUM

OpenTelemetry, also known as OTel, is a vendor-neutral open source Observability framework for instrumenting, generating, collecting, and exporting telemetry data such as traces, metrics, and …

Aug 13, 2024
CVE-2024-7739
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in yzane vscode-markdown-pdf 1.5.0. This affects an unknown part. The manipulation leads to cross site scripting. …

Aug 13, 2024
CVE-2024-38223
6.8 MEDIUM

Windows Initial Machine Configuration Elevation of Privilege Vulnerability

Aug 13, 2024
CVE-2024-38214
6.5 MEDIUM

Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

Aug 13, 2024
CVE-2024-38213
6.5 MEDIUM KEV

Windows Mark of the Web Security Feature Bypass Vulnerability

Aug 13, 2024
CVE-2024-38197
6.5 MEDIUM

Microsoft Teams for iOS Spoofing Vulnerability

Aug 13, 2024
CVE-2024-38173
6.7 MEDIUM

Microsoft Outlook Remote Code Execution Vulnerability

Aug 13, 2024
CVE-2024-38167
6.5 MEDIUM

.NET and Visual Studio Information Disclosure Vulnerability

Aug 13, 2024
CVE-2024-38165
6.5 MEDIUM

Windows Compressed Folder Tampering Vulnerability

Aug 13, 2024
CVE-2024-38161
6.8 MEDIUM

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

Aug 13, 2024
CVE-2024-38155
5.5 MEDIUM

Security Center Broker Information Disclosure Vulnerability

Aug 13, 2024
CVE-2024-38151
5.5 MEDIUM

Windows Kernel Information Disclosure Vulnerability

Aug 13, 2024
CVE-2024-38143
4.2 MEDIUM

Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability

Aug 13, 2024
CVE-2024-38123
4.4 MEDIUM

Windows Bluetooth Driver Information Disclosure Vulnerability

Aug 13, 2024
CVE-2024-38122
5.5 MEDIUM

Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability

Aug 13, 2024
CVE-2024-38118
5.5 MEDIUM

Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability

Aug 13, 2024
CVE-2024-41711
6.8 MEDIUM

A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an …

Aug 13, 2024
CVE-2024-41614
4.8 MEDIUM

symphonycms <=2.7.10 is vulnerable to Cross Site Scripting (XSS) in the Comment component for articles.

Aug 13, 2024
CVE-2024-41613
5.4 MEDIUM

A Cross Site Scripting (XSS) vulnerability in Symphony CMS 2.7.10 allows remote attackers to inject arbitrary web script or HTML by editing note.

Aug 13, 2024
CVE-2024-21981
5.7 MEDIUM

Improper key usage control in AMD Secure Processor (ASP) may allow an attacker with local access who has gained arbitrary code execution privilege in ASP …

Aug 13, 2024
CVE-2023-31356
4.4 MEDIUM

Incomplete system memory cleanup in SEV firmware could allow a privileged attacker to corrupt guest private memory, potentially resulting in a loss of data integrity.

Aug 13, 2024
CVE-2023-31339
4.8 MEDIUM

Improper input validation in ARM® Trusted Firmware used in AMD’s Zynq™ UltraScale+™) MPSoC/RFSoC may allow a privileged attacker to perform out of bound reads, potentially …

Aug 13, 2024
CVE-2023-31310
5.0 MEDIUM

Improper input validation in Power Management Firmware (PMFW) may allow an attacker with privileges to send a malformed input for the "set temperature input selection" …

Aug 13, 2024
CVE-2023-20591
6.5 MEDIUM

Improper re-initialization of IOMMU during the DRTM event may permit an untrusted platform configuration to persist, allowing an attacker to read or modify hypervisor memory, …

Aug 13, 2024
CVE-2023-20584
5.3 MEDIUM

IOMMU improperly handles certain special address ranges with invalid device table entries (DTEs), which may allow an attacker with privileges and a compromised Hypervisor to …

Aug 13, 2024
CVE-2023-20510
4.7 MEDIUM

An insufficient DRAM address validation in PMFW may allow a privileged attacker to read from an invalid DRAM address to SRAM, potentially resulting in data …

Aug 13, 2024
CVE-2023-20509
5.2 MEDIUM

An insufficient DRAM address validation in PMFW may allow a privileged attacker to perform a DMA read from an invalid DRAM address to SRAM, potentially …

Aug 13, 2024
CVE-2021-46746
5.2 MEDIUM

Lack of stack protection exploit mechanisms in ASP Secure OS Trusted Execution Environment (TEE) may allow a privileged attacker with access to AMD signing keys …

Aug 13, 2024
CVE-2021-26367
5.7 MEDIUM

A malicious attacker in x86 can misconfigure the Trusted Memory Regions (TMRs), which may allow the attacker to set an arbitrary address range for the …

Aug 13, 2024
CVE-2024-36505
5.1 MEDIUM

An improper access control vulnerability [CWE-284] in FortiOS 7.4.0 through 7.4.3, 7.2.5 through 7.2.7, 7.0.12 through 7.0.14 and 6.4.x may allow an attacker who has …

Aug 13, 2024
CVE-2024-21757
6.1 MEDIUM

A unverified password change in Fortinet FortiManager versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, as well as Fortinet FortiAnalyzer …

Aug 13, 2024
CVE-2023-26211
6.8 MEDIUM

An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSOAR 7.3.0 through 7.3.2 allows an authenticated, remote attacker to inject arbitrary …

Aug 13, 2024
CVE-2022-27486
6.6 MEDIUM

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiDDoS version 5.5.0 through 5.5.1, 5.4.2 through 5.4.0, 5.3.0 …

Aug 13, 2024
CVE-2024-6384
5.3 MEDIUM

"Hot" backup files may be downloaded by underprivileged users, if they are capable of acquiring a unique backup identifier. This issue affects MongoDB Enterprise Server …

Aug 13, 2024
CVE-2024-42740
6.8 MEDIUM

In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setLedCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.

Aug 13, 2024
CVE-2024-3913
5.9 MEDIUM

An unauthenticated remote attacker can use this vulnerability to change the device configuration due to a file writeable for short time after system startup.

Aug 13, 2024
CVE-2024-38501
6.1 MEDIUM

An unauthenticated remote attacker may use a HTML injection vulnerability with limited length to inject malicious HTML code and gain low-privileged access on the affected …

Aug 13, 2024
CVE-2024-43165
6.5 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rashid87 WPSection allows PHP Local File Inclusion.This issue affects WPSection: from n/a …

Aug 13, 2024
CVE-2024-43138
6.5 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in MagePeople Team Event Manager for WooCommerce allows PHP Local File Inclusion.This issue …

Aug 13, 2024
CVE-2024-43129
6.5 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPDeveloper BetterDocs allows PHP Local File Inclusion.This issue affects BetterDocs: from n/a …

Aug 13, 2024
CVE-2024-43128
6.5 MEDIUM

Improper Control of Generation of Code ('Code Injection') vulnerability in WC Product Table WooCommerce Product Table Lite allows Code Injection.This issue affects WooCommerce Product Table …

Aug 13, 2024
CVE-2024-41774
4.8 MEDIUM

IBM Common Licensing 9.0 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI …

Aug 13, 2024
CVE-2024-39642
6.5 MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in ThimPress LearnPress allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects LearnPress: from n/a through 4.2.6.8.2.

Aug 13, 2024
CVE-2024-38760
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in David Maucher Send Users Email allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects …

Aug 13, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.