CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-27385
6.7 MEDIUM

A vulnerability was discovered in the slsi_handle_nan_rx_event_log_ind function in Samsung Mobile Processor Exynos 1380 and Exynos 1480 related to no input validation check on tag_len …

Jul 9, 2024
CVE-2024-40750
5.3 MEDIUM

Linksys Velop Pro 6E 1.0.8 MX6200_1.0.8.215731 and 7 1.0.10.215314 devices send cleartext Wi-Fi passwords over the public Internet during app-based installation.

Jul 9, 2024
CVE-2024-37830
6.1 MEDIUM

An issue in Outline <= v0.76.1 allows attackers to redirect a victim user to a malicious site via intercepting and changing the state cookie.

Jul 9, 2024
CVE-2024-34140
5.5 MEDIUM

Bridge versions 14.0.4, 13.0.7, 14.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Jul 9, 2024
CVE-2024-28068
5.3 MEDIUM

A vulnerability was discovered in SS in Samsung Mobile Processor, Wearable Processor, and Modems with versions Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos …

Jul 9, 2024
CVE-2024-27363
6.0 MEDIUM

A vulnerability was discovered in Samsung Mobile Processor Exynos 850, Exynos 9610, Exynos 980, Exynos 1280, Exynos 1380, Exynos 1330, Exynos W920, and Exynos W930 …

Jul 9, 2024
CVE-2024-27361
5.1 MEDIUM

A vulnerability was discovered in Samsung Mobile Processor Exynos 980, Exynos 990, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, and Exynos 2400 …

Jul 9, 2024
CVE-2024-40038
5.3 MEDIUM

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/userScore_deal.php?mudi=rev

Jul 9, 2024
CVE-2024-40035
5.9 MEDIUM

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/userLevel_deal.php?mudi=add.

Jul 9, 2024
CVE-2024-39899
5.3 MEDIUM

PrivateBin is an online pastebin where the server has zero knowledge of pasted data. In v1.5, PrivateBin introduced the YOURLS server-side proxy. The idea was …

Jul 9, 2024
CVE-2024-39897
4.3 MEDIUM

zot is an OCI image registry. Prior to 2.1.0, the cache driver `GetBlob()` allows read access to any blob without access control check. If a …

Jul 9, 2024
CVE-2024-40742
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the circuit …

Jul 9, 2024
CVE-2024-40741
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the circuit …

Jul 9, 2024
CVE-2024-40740
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name …

Jul 9, 2024
CVE-2024-40739
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name …

Jul 9, 2024
CVE-2024-40738
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name …

Jul 9, 2024
CVE-2024-40737
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name …

Jul 9, 2024
CVE-2024-40736
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name …

Jul 9, 2024
CVE-2024-40735
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name …

Jul 9, 2024
CVE-2024-40734
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name …

Jul 9, 2024
CVE-2024-40733
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name …

Jul 9, 2024
CVE-2024-40732
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name …

Jul 9, 2024
CVE-2024-40731
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name …

Jul 9, 2024
CVE-2024-40730
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name …

Jul 9, 2024
CVE-2024-40729
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name …

Jul 9, 2024
CVE-2024-40728
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name …

Jul 9, 2024
CVE-2024-40727
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name …

Jul 9, 2024
CVE-2024-40726
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name …

Jul 9, 2024
CVE-2024-38972
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in netbox v4.0.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name …

Jul 9, 2024
CVE-2024-38971
5.4 MEDIUM

vaeThink 1.0.2 is vulnerable to stored Cross Site Scripting (XSS) in the system backend.

Jul 9, 2024
CVE-2024-38970
4.9 MEDIUM

vaeThink 1.0.2 is vulnerable to Information Disclosure via the system backend,access management administrator function.

Jul 9, 2024
CVE-2024-31957
6.2 MEDIUM

A vulnerability was discovered in Samsung Mobile Processors Exynos 2200 and Exynos 2400 where they lack a check for the validation of native handles, which …

Jul 9, 2024
CVE-2024-28067
5.3 MEDIUM

A vulnerability in Samsung Exynos Modem 5300 allows a Man-in-the-Middle (MITM) attacker to downgrade the security mode of packets going to the victim, enabling the …

Jul 9, 2024
CVE-2024-27362
4.4 MEDIUM

A vulnerability was discovered in Samsung Mobile Processors Exynos 1280, Exynos 2200, Exynos 1330, Exynos 1380, and Exynos 2400 where they do not properly check …

Jul 9, 2024
CVE-2024-27360
6.0 MEDIUM

A vulnerability was discovered in Samsung Mobile Processors Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, and Exynos W930 …

Jul 9, 2024
CVE-2024-27183
6.1 MEDIUM

XSS vulnerability in DJ-HelpfulArticles component for Joomla.

Jul 9, 2024
CVE-2024-6237
6.5 MEDIUM

A flaw was found in the 389 Directory Server. This flaw allows an unauthenticated user to cause a systematic server crash while sending a specific …

Jul 9, 2024
CVE-2024-5652
6.1 MEDIUM

In Docker Desktop on Windows before v4.31.0 allows a user in the docker-users group to cause a Windows Denial-of-Service through the exec-path Docker daemon config …

Jul 9, 2024
CVE-2024-39118
5.5 MEDIUM

Mommy Heather Advanced Backups up to v3.5.3 allows attackers to write arbitrary files via restoring a crafted back up.

Jul 9, 2024
CVE-2024-38105
6.5 MEDIUM

Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability

Jul 9, 2024
CVE-2024-38102
6.5 MEDIUM

Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability

Jul 9, 2024
CVE-2024-38101
6.5 MEDIUM

Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability

Jul 9, 2024
CVE-2024-38099
5.9 MEDIUM

Windows Remote Desktop Licensing Service Denial of Service Vulnerability

Jul 9, 2024
CVE-2024-38086
6.4 MEDIUM

Azure Kinect SDK Remote Code Execution Vulnerability

Jul 9, 2024
CVE-2024-38065
6.8 MEDIUM

Secure Boot Security Feature Bypass Vulnerability

Jul 9, 2024
CVE-2024-38058
6.8 MEDIUM

BitLocker Security Feature Bypass Vulnerability

Jul 9, 2024
CVE-2024-38056
5.5 MEDIUM

Microsoft Windows Codecs Library Information Disclosure Vulnerability

Jul 9, 2024
CVE-2024-38055
5.5 MEDIUM

Microsoft Windows Codecs Library Information Disclosure Vulnerability

Jul 9, 2024
CVE-2024-38049
6.6 MEDIUM

Windows Distributed Transaction Coordinator Remote Code Execution Vulnerability

Jul 9, 2024
CVE-2024-38048
6.5 MEDIUM

Windows Network Driver Interface Specification (NDIS) Denial of Service Vulnerability

Jul 9, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.