CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-41241
6.1 MEDIUM

A Reflected Cross Site Scripting (XSS) vulnerability was found in " /smsa/admin_login.php" in Kashipara Responsive School Management System v3.2.0, which allows remote attackers to execute …

Aug 7, 2024
CVE-2024-41240
6.1 MEDIUM

A Reflected Cross Site Scripting (XSS) vulnerability was found in " /smsa/teacher_login.php" in Kashipara Responsive School Management System v3.2.0, which allows remote attackers to execute …

Aug 7, 2024
CVE-2024-7061
5.5 MEDIUM

Okta Verify for Windows is vulnerable to privilege escalation through DLL hijacking. The vulnerability is fixed in Okta Verify for Windows version 5.0.2. To remediate …

Aug 7, 2024
CVE-2024-41250
5.3 MEDIUM

An Incorrect Access Control vulnerability was found in /smsa/view_students.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view STUDENT details.

Aug 7, 2024
CVE-2024-41245
5.3 MEDIUM

An Incorrect Access Control vulnerability was found in /smsa/view_teachers.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view TEACHER details.

Aug 7, 2024
CVE-2024-41244
5.3 MEDIUM

An Incorrect Access Control vulnerability was found in /smsa/view_class.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view CLASS details.

Aug 7, 2024
CVE-2024-41243
5.3 MEDIUM

An Incorrect Access Control vulnerability was found in /smsa/view_marks.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view MARKS details.

Aug 7, 2024
CVE-2024-20479
4.8 MEDIUM

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct an XSS attack against a user of …

Aug 7, 2024
CVE-2024-20443
5.4 MEDIUM

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct an XSS attack against a user of …

Aug 7, 2024
CVE-2024-42250
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: cachefiles: add missing lock protection when polling Add missing lock protection in poll routine when …

Aug 7, 2024
CVE-2024-42248
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tty: serial: ma35d1: Add a NULL check for of_node The pdev->dev.of_node can be NULL if …

Aug 7, 2024
CVE-2024-42247
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wireguard: allowedips: avoid unaligned 64-bit memory accesses On the parisc platform, the kernel issues kernel …

Aug 7, 2024
CVE-2024-42246
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net, sunrpc: Remap EPERM in case of connection failure in xs_tcp_setup_socket When using a BPF …

Aug 7, 2024
CVE-2024-42245
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Revert "sched/fair: Make sure to try to detach at least one movable task" This reverts …

Aug 7, 2024
CVE-2024-42244
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: USB: serial: mos7840: fix crash on resume Since commit c49cfa917025 ("USB: serial: use generic method …

Aug 7, 2024
CVE-2024-42243
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/filemap: make MAX_PAGECACHE_ORDER acceptable to xarray Patch series "mm/filemap: Limit page cache size to that …

Aug 7, 2024
CVE-2024-42242
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mmc: sdhci: Fix max_seg_size for 64KiB PAGE_SIZE blk_queue_max_segment_size() ensured: if (max_size < PAGE_SIZE) max_size = …

Aug 7, 2024
CVE-2024-42241
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/shmem: disable PMD-sized page cache if needed For shmem files, it's possible that PMD-sized page …

Aug 7, 2024
CVE-2024-42240
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: x86/bhi: Avoid warning in #DB handler due to BHI mitigation When BHI mitigation is enabled, …

Aug 7, 2024
CVE-2024-42239
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: Fail bpf_timer_cancel when callback is being cancelled Given a schedule: timer1 cb timer2 cb …

Aug 7, 2024
CVE-2024-42238
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: firmware: cs_dsp: Return error if block header overflows file Return an error from cs_dsp_power_up() if …

Aug 7, 2024
CVE-2024-42237
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: firmware: cs_dsp: Validate payload length before processing block Move the payload length check in cs_dsp_load() …

Aug 7, 2024
CVE-2024-42236
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: configfs: Prevent OOB read/write in usb_string_copy() Userspace provided string 's' could trivially have …

Aug 7, 2024
CVE-2024-42235
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: s390/mm: Add NULL pointer check to crst_table_free() base_crst_free() crst_table_free() used to work with NULL pointers …

Aug 7, 2024
CVE-2024-42234
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm: fix crashes from deferred split racing folio migration Even on 6.10-rc6, I've been seeing …

Aug 7, 2024
CVE-2024-42232
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: libceph: fix race between delayed_work() and ceph_monc_stop() The way the delayed work is handled in …

Aug 7, 2024
CVE-2024-41432
5.3 MEDIUM

An IP Spoofing vulnerability has been discovered in Likeshop up to 2.5.7.20210811. This issue allows an attacker to replace their real IP address with any …

Aug 7, 2024
CVE-2024-41252
6.5 MEDIUM

An Incorrect Access Control vulnerability was found in /smsa/admin_student_register_approval.php and /smsa/admin_student_register_approval_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view …

Aug 7, 2024
CVE-2024-41251
6.5 MEDIUM

An Incorrect Access Control vulnerability was found in /smsa/admin_teacher_register_approval.php and /smsa/admin_teacher_register_approval_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view …

Aug 7, 2024
CVE-2024-41249
5.3 MEDIUM

An Incorrect Access Control vulnerability was found in /smsa/view_subject.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view SUBJECT details.

Aug 7, 2024
CVE-2024-41248
5.3 MEDIUM

An Incorrect Access Control vulnerability was found in /smsa/add_subject.php and /smsa/add_subject_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to add …

Aug 7, 2024
CVE-2024-41247
5.3 MEDIUM

An Incorrect Access Control vulnerability was found in /smsa/add_class.php and /smsa/add_class_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to add …

Aug 7, 2024
CVE-2024-41246
5.3 MEDIUM

An Incorrect Access Control vulnerability was found in /smsa/admin_dashboard.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view administrator dashboard.

Aug 7, 2024
CVE-2024-7580
6.3 MEDIUM

A vulnerability was found in Alien Technology ALR-F800 up to 19.10.24.00. It has been rated as critical. Affected by this issue is some unknown functionality …

Aug 7, 2024
CVE-2024-7579
6.3 MEDIUM

A vulnerability was found in Alien Technology ALR-F800 up to 19.10.24.00. It has been declared as critical. Affected by this vulnerability is the function popen …

Aug 7, 2024
CVE-2024-43045
6.3 MEDIUM

Jenkins 2.470 and earlier, LTS 2.452.3 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to access …

Aug 7, 2024
CVE-2024-7355
4.9 MEDIUM

The Organization chart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title_input’ and 'node_description' parameter in all versions up to, and including, …

Aug 7, 2024
CVE-2024-7353
5.4 MEDIUM

The Accept Stripe Payments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's accept_stripe_payment_ng shortcode in all versions up to, and including, …

Aug 7, 2024
CVE-2024-7267
6.5 MEDIUM

Exposure of Sensitive Information vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP allows logged-in user to retrieve information about IP …

Aug 7, 2024
CVE-2024-7266
4.3 MEDIUM

Incorrect User Management vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP allows logged-in user to list all users in the …

Aug 7, 2024
CVE-2024-42222
4.3 MEDIUM

In Apache CloudStack 4.19.1.0, a regression in the network listing API allows unauthorised list access of network details for domain admin and normal user accounts. …

Aug 7, 2024
CVE-2024-6494
6.1 MEDIUM

The WordPress File Upload WordPress plugin before 4.24.8 does not properly sanitize and escape certain parameters, which could allow unauthenticated users to execute stored cross-site …

Aug 7, 2024
CVE-2024-3973
4.8 MEDIUM

The House Manager WordPress plugin through 1.0.8.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Aug 7, 2024
CVE-2024-37403
5.5 MEDIUM

Ivanti Docs@Work for Android, before 2.26.0 is affected by the 'Dirty Stream' vulnerability. The application fails to properly sanitize file names, resulting in a path …

Aug 7, 2024
CVE-2024-34788
6.5 MEDIUM

An improper authentication vulnerability in web component of EPMM prior to 12.1.0.1 allows a remote malicious user to access potentially sensitive information

Aug 7, 2024
CVE-2024-34636
4.0 MEDIUM

Use of implicit intent for sensitive communication in Samsung Email prior to version 6.1.94.2 allows local attackers to get sensitive information.

Aug 7, 2024
CVE-2024-34635
4.0 MEDIUM

Out-of-bounds read in parsing textbox object in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.

Aug 7, 2024
CVE-2024-34634
4.0 MEDIUM

Out-of-bounds read in parsing connected object list in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.

Aug 7, 2024
CVE-2024-34633
4.0 MEDIUM

Out-of-bounds read in parsing object header in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.

Aug 7, 2024
CVE-2024-34632
4.0 MEDIUM

Out-of-bounds read in uuid parsing in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.

Aug 7, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.