CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-42493
5.3 MEDIUM

Dorsett Controls InfoScan is vulnerable due to a leak of possible sensitive information through the response headers and the rendered JavaScript prior to user login.

Aug 8, 2024
CVE-2024-42408
5.3 MEDIUM

The InfoScan client download page can be intercepted with a proxy, to expose filenames located on the system, which could lead to additional information exposure.

Aug 8, 2024
CVE-2024-39287
5.3 MEDIUM

Dorsett Controls Central Server update server has potential information leaks with an unprotected file that contains passwords and API keys.

Aug 8, 2024
CVE-2024-0104
4.2 MEDIUM

NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in the LDAP AAA component, where a user can cause improper access. A …

Aug 8, 2024
CVE-2023-40261
6.8 MEDIUM

Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR17, 4.0.0 SR07, 4.1.0 SR04, 4.2.0 SR04, and 4.3.0 SR02 fails to validate file attributes during the …

Aug 8, 2024
CVE-2023-33206
6.8 MEDIUM

Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR16, 4.0.0 SR06, 4.1.0 SR04, 4.2.0 SR03, and 4.3.0 SR01 fails to validate symlinks during the Pre-Boot …

Aug 8, 2024
CVE-2023-28865
6.6 MEDIUM

Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR15, 4.0.0 SR05, 4.1.0 SR03, and 4.2.0 SR02 fails to validate the directory contents of certain directories …

Aug 8, 2024
CVE-2023-24064
6.8 MEDIUM

Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR4 fails to validate /etc/initab during the Pre-Boot Authorization (PBA) process. This can be exploited by a …

Aug 8, 2024
CVE-2023-24063
6.8 MEDIUM

Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR10 fails to validate /etc/mtab during the Pre-Boot Authorization (PBA) process. This can be exploited by a …

Aug 8, 2024
CVE-2023-24062
6.8 MEDIUM

Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR12, 4.0.0 SR04, 4.1.0 SR02, and 4.2.0 SR01 fails to validate the directory structure of the root …

Aug 8, 2024
CVE-2024-7394
4.8 MEDIUM

Concrete CMS versions 9 through 9.3.2 and below 8.5.18 are vulnerable to Stored XSS in getAttributeSetName(). A rogue administrator could inject malicious code. The Concrete …

Aug 8, 2024
CVE-2024-7480
4.2 MEDIUM

An Improper access control vulnerability was found in Avaya Aura System Manager which could allow a command-line interface (CLI) user with administrative privileges to read …

Aug 8, 2024
CVE-2024-7477
6.5 MEDIUM

A SQL injection vulnerability was found which could allow a command line interface (CLI) user with administrative privileges to execute arbitrary queries against the Avaya …

Aug 8, 2024
CVE-2024-41238
5.3 MEDIUM

A SQL injection vulnerability in /smsa/student_login.php in Kashipara Responsive School Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "username" parameter.

Aug 8, 2024
CVE-2024-42354
5.3 MEDIUM

Shopware is an open commerce platform. The store-API works with regular entities and not expose all fields for the public API; fields need to be …

Aug 8, 2024
CVE-2024-7610
4.3 MEDIUM

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions starting with 15.9 before 17.0.6, 17.1 prior to 17.1.4, and …

Aug 8, 2024
CVE-2024-7554
4.9 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.9 before 17.0.6, all versions starting from 17.1 before 17.1.4, all versions …

Aug 8, 2024
CVE-2024-5423
6.5 MEDIUM

Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0 prior to 17.0.6, starting from 17.1 prior …

Aug 8, 2024
CVE-2024-4207
4.4 MEDIUM

A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 prior 17.0.6, starting from 17.1 prior to 17.1.4, and starting …

Aug 8, 2024
CVE-2024-3958
5.3 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. An issue was …

Aug 8, 2024
CVE-2024-3114
4.3 MEDIUM

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.10 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2, …

Aug 8, 2024
CVE-2024-3035
6.8 MEDIUM

A permission check vulnerability in GitLab CE/EE affecting all versions starting from 8.12 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2 …

Aug 8, 2024
CVE-2024-2800
6.5 MEDIUM

ReDoS flaw in RefMatcher when matching branch names using wildcards in GitLab EE/CE affecting all versions from 11.3 prior to 17.0.6, 17.1 prior to 17.1.4, …

Aug 8, 2024
CVE-2024-6329
5.7 MEDIUM

An issue was discovered in GitLab CE/EE affecting all versions starting from 8.16 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from …

Aug 8, 2024
CVE-2024-4784
4.2 MEDIUM

An issue was discovered in GitLab EE starting from version 16.7 before 17.0.6, version 17.1 before 17.1.4 and 17.2 before 17.2.2 that allowed bypassing the …

Aug 8, 2024
CVE-2024-4210
6.5 MEDIUM

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions starting with 12.6 before 17.0.6, 17.1 prior to 17.1.4, and …

Aug 8, 2024
CVE-2024-42034
6.6 MEDIUM

LaunchAnywhere vulnerability in the account module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Aug 8, 2024
CVE-2024-42033
6.9 MEDIUM

Access control vulnerability in the security verification module mpact: Successful exploitation of this vulnerability will affect integrity and confidentiality.

Aug 8, 2024
CVE-2024-42255
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tpm: Use auth only after NULL check in tpm_buf_check_hmac_response() Dereference auth after NULL check in …

Aug 8, 2024
CVE-2024-42254
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: io_uring: fix error pbuf checking Syz reports a problem, which boils down to NULL vs …

Aug 8, 2024
CVE-2024-42253
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: gpio: pca953x: fix pca953x_irq_bus_sync_unlock race Ensure that `i2c_lock' is held when setting interrupt latch and …

Aug 8, 2024
CVE-2024-42252
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: closures: Change BUG_ON() to WARN_ON() If a BUG_ON() can be hit in the wild, it …

Aug 8, 2024
CVE-2024-42251
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm: page_ref: remove folio_try_get_rcu() The below bug was reported on a non-SMP kernel: [ 275.267158][ …

Aug 8, 2024
CVE-2024-42032
4.4 MEDIUM

Access permission verification vulnerability in the Contacts module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Aug 8, 2024
CVE-2024-42030
6.2 MEDIUM

Access permission verification vulnerability in the content sharing pop-up module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Aug 8, 2024
CVE-2023-7265
4.0 MEDIUM

Permission verification vulnerability in the lock screen module Impact: Successful exploitation of this vulnerability may affect availability

Aug 8, 2024
CVE-2024-6884
5.4 MEDIUM

The Gutenberg Blocks with AI by Kadence WP WordPress plugin before 3.2.39 does not validate and escape some of its block options before outputting them …

Aug 8, 2024
CVE-2024-6824
4.3 MEDIUM

The Premium Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the …

Aug 8, 2024
CVE-2024-6481
4.8 MEDIUM

The Search & Filter Pro WordPress plugin before 2.5.18 does not sanitise and escape some of its settings, which could allow high privilege users such …

Aug 8, 2024
CVE-2024-5226
6.4 MEDIUM

The Fuse Social Floating Sidebar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the file upload functionality in all versions up to, and …

Aug 8, 2024
CVE-2024-6987
4.3 MEDIUM

The Orchid Store theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'orchid_store_activate_plugin' function in all …

Aug 8, 2024
CVE-2024-6869
5.4 MEDIUM

The Falang multilanguage for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in …

Aug 8, 2024
CVE-2024-5668
6.4 MEDIUM

The Lightbox & Modal Popup WordPress Plugin – FooBox plugin for WordPress is vulnerable to DOM-based Stored Cross-Site Scripting via HTML data attributes in all …

Aug 8, 2024
CVE-2024-6552
5.3 MEDIUM

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, …

Aug 8, 2024
CVE-2024-6254
4.3 MEDIUM

The Brizy – Page Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.1. This is due …

Aug 8, 2024
CVE-2024-21302
6.7 MEDIUM

Summary: As of July 8, 2025 Microsoft has completed mitigations to address this vulnerability. See KB5042562: Guidance for blocking rollback of virtualization-based security related updates …

Aug 8, 2024
CVE-2024-6892
6.1 MEDIUM

Attackers can craft a malicious link that once clicked will execute arbitrary JavaScript in the context of the Journyx web application.

Aug 8, 2024
CVE-2024-6706
6.1 MEDIUM

Attackers can craft a malicious prompt that coerces the language model into executing arbitrary JavaScript in the context of the web page.

Aug 7, 2024
CVE-2024-41239
4.8 MEDIUM

A Stored Cross Site Scripting (XSS) vulnerability was found in "/smsa/add_class_submit.php" in Responsive School Management System v3.2.0, which allows remote attackers to execute arbitrary code …

Aug 7, 2024
CVE-2024-41242
6.1 MEDIUM

A Reflected Cross Site Scripting (XSS) vulnerability was found in /smsa/student_login.php in Kashipara Responsive School Management System v3.2.0, which allows remote attackers to execute arbitrary …

Aug 7, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.