CVE Database

47087+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-40070
8.8 HIGH

Improper access control in some Intel(R) Power Gadget software for macOS all versions may allow an authenticated user to potentially enable escalation of privilege via …

May 16, 2024
CVE-2023-38654
8.2 HIGH

Improper input validation for some some Intel(R) PROSet/Wireless WiFi software for Windows before version 23.20 may allow an unauthenticated user to potentially enable denial of …

May 16, 2024
CVE-2023-38581
8.8 HIGH

Buffer overflow in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation of privilege via local access.

May 16, 2024
CVE-2023-28402
7.2 HIGH

Improper input validation in some Intel(R) BIOS Guard firmware may allow a privileged user to potentially enable escalation of privilege via local access.

May 16, 2024
CVE-2023-27504
7.2 HIGH

Improper conditions check in some Intel(R) BIOS Guard firmware may allow a privileged user to potentially enable escalation of privilege via local access.

May 16, 2024
CVE-2023-24460
8.2 HIGH

Incorrect default permissions in some Intel(R) GPA software installers before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local …

May 16, 2024
CVE-2022-37410
7.0 HIGH

Improper access control for some Intel(R) Thunderbolt driver software before version 89 may allow an authenticated user to potentially enable escalation of privilege via local …

May 16, 2024
CVE-2022-37341
7.2 HIGH

Improper access control in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user to potentially enable escalation of …

May 16, 2024
CVE-2024-4733
7.5 HIGH

The ShiftController Employee Shift Scheduling plugin is vulnerable to PHP Object Injection via deserialization of untrusted input via the `hc3_session`-cookie in versions up to, and …

May 16, 2024
CVE-2024-3286
7.5 HIGH

A buffer overflow vulnerability was identified in some Lenovo printers that could allow an unauthenticated user to trigger a device restart by sending a specially …

May 16, 2024
CVE-2024-1417
7.8 HIGH

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in WatchGuard AuthPoint Password Manager on MacOS allows an a adversary with local …

May 16, 2024
CVE-2024-27260
8.4 HIGH

IBM AIX could 7.2, 7.3, VIOS 3.1, and VIOS 4.1 allow a non-privileged local user to exploit a vulnerability in the invscout command to execute …

May 16, 2024
CVE-2024-4956
7.5 HIGH

Path Traversal in Sonatype Nexus Repository 3 allows an unauthenticated attacker to read system files. Fixed in version 3.68.1.

May 16, 2024
CVE-2024-34905
7.5 HIGH

FlyFish v3.0.0 was discovered to contain a buffer overflow via the password parameter on the login page. This vulnerability allows attackers to cause a Denial …

May 16, 2024
CVE-2024-31142
7.5 HIGH

Because of a logical error in XSA-407 (Branch Type Confusion), the mitigation is not applied properly when it is intended to be used. XSA-434 (Speculative …

May 16, 2024
CVE-2024-20389
7.8 HIGH

A vulnerability in the ConfD CLI and the Cisco Crosswork Network Services Orchestrator CLI could allow an authenticated, low-privileged, local attacker to read and write …

May 16, 2024
CVE-2024-20326
7.8 HIGH

A vulnerability in the ConfD CLI and the Cisco Crosswork Network Services Orchestrator CLI could allow an authenticated, low-privileged, local attacker to read and write …

May 16, 2024
CVE-2024-30314
7.8 HIGH

Dreamweaver Desktop versions 21.3 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that …

May 16, 2024
CVE-2024-30292
7.8 HIGH

Adobe Framemaker versions 2020.5, 2022.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

May 16, 2024
CVE-2024-30291
7.8 HIGH

Adobe Framemaker versions 2020.5, 2022.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

May 16, 2024
CVE-2024-30290
7.8 HIGH

Adobe Framemaker versions 2020.5, 2022.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

May 16, 2024
CVE-2024-30289
7.8 HIGH

Adobe Framemaker versions 2020.5, 2022.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

May 16, 2024
CVE-2024-30288
7.8 HIGH

Adobe Framemaker versions 2020.5, 2022.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context …

May 16, 2024
CVE-2024-4838
7.5 HIGH

The ConvertPlus plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.5.26 via deserialization of untrusted input from …

May 16, 2024
CVE-2024-4352
8.8 HIGH

The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability …

May 16, 2024
CVE-2024-4351
8.8 HIGH

The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability …

May 16, 2024
CVE-2024-4222
7.3 HIGH

The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability …

May 16, 2024
CVE-2024-4322
7.5 HIGH

A path traversal vulnerability exists in the parisneo/lollms-webui application, specifically within the `/list_personalities` endpoint. By manipulating the `category` parameter, an attacker can traverse the directory …

May 16, 2024
CVE-2024-4321
7.5 HIGH

A Local File Inclusion (LFI) vulnerability exists in the gaizhenbiao/chuanhuchatgpt application, specifically within the functionality for uploading chat history. The vulnerability arises due to improper …

May 16, 2024
CVE-2024-4181
8.8 HIGH

A command injection vulnerability exists in the RunGptLLM class of the llama_index library, version 0.9.47, used by the RunGpt framework from JinaAI to connect to …

May 16, 2024
CVE-2024-3848
7.5 HIGH

A path traversal vulnerability exists in mlflow/mlflow version 2.11.0, identified as a bypass for the previously addressed CVE-2023-6909. The vulnerability arises from the application's handling …

May 16, 2024
CVE-2024-3435
8.4 HIGH

A path traversal vulnerability exists in the 'save_settings' endpoint of the parisneo/lollms-webui application, affecting versions up to the latest release before 9.5. The vulnerability arises …

May 16, 2024
CVE-2024-3403
7.5 HIGH

imartinez/privategpt version 0.2.0 is vulnerable to a local file inclusion vulnerability that allows attackers to read arbitrary files from the filesystem. By manipulating file upload …

May 16, 2024
CVE-2024-3126
8.4 HIGH

A command injection vulnerability exists in the 'run_xtts_api_server' function of the parisneo/lollms-webui application, specifically within the 'lollms_xtts.py' script. The vulnerability arises due to the improper …

May 16, 2024
CVE-2024-30307
7.8 HIGH

Substance3D - Painter versions 9.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

May 16, 2024
CVE-2024-30297
7.8 HIGH

Animate versions 24.0.2, 23.0.5 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the …

May 16, 2024
CVE-2024-30296
7.8 HIGH

Animate versions 24.0.2, 23.0.5 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the …

May 16, 2024
CVE-2024-30295
7.8 HIGH

Animate versions 24.0.2, 23.0.5 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in arbitrary code execution in the context of …

May 16, 2024
CVE-2024-30294
7.8 HIGH

Animate versions 24.0.2, 23.0.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of …

May 16, 2024
CVE-2024-30293
7.8 HIGH

Animate versions 24.0.2, 23.0.5 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of …

May 16, 2024
CVE-2024-30282
7.8 HIGH

Animate versions 24.0.2, 23.0.5 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the …

May 16, 2024
CVE-2024-30275
7.8 HIGH

Adobe Aero Desktop versions 23.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

May 16, 2024
CVE-2024-30274
7.8 HIGH

Substance3D - Painter versions 9.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

May 16, 2024
CVE-2024-20792
7.8 HIGH

Illustrator versions 28.4, 27.9.3 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of …

May 16, 2024
CVE-2024-20791
7.8 HIGH

Illustrator versions 28.4, 27.9.3 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past …

May 16, 2024
CVE-2024-4966
7.3 HIGH

A vulnerability was found in SourceCodester SchoolWebTech 1.0. It has been classified as critical. Affected is an unknown function of the file /improve/home.php. The manipulation …

May 16, 2024
CVE-2024-4844
7.5 HIGH

Hardcoded credentials vulnerability in Trellix ePolicy Orchestrator (ePO) on Premise prior to 5.10 Service Pack 1 Update 2 allows an attacker with admin privileges on …

May 16, 2024
CVE-2024-4318
8.8 HIGH

The Tutor LMS plugin for WordPress is vulnerable to time-based SQL Injection via the ‘question_id’ parameter in versions up to, and including, 2.7.0 due to …

May 16, 2024
CVE-2024-3643
8.8 HIGH

The Newsletter Popup WordPress plugin through 1.2 does not have CSRF check when deleting list, which could allow attackers to make logged in admins perform …

May 16, 2024
CVE-2024-4927
7.3 HIGH

A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

May 16, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.