CVE Database

5223+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-6936
2.7 LOW

A vulnerability, which was classified as problematic, has been found in formtools.org Form Tools 3.1.1. This issue affects some unknown processing of the file /admin/settings/index.php?page=accounts …

Jul 21, 2024
CVE-2024-6935
2.4 LOW

A vulnerability classified as problematic was found in formtools.org Form Tools 3.1.1. This vulnerability affects unknown code of the file /admin/clients/ of the component User …

Jul 21, 2024
CVE-2024-6934
2.4 LOW

A vulnerability classified as problematic has been found in formtools.org Form Tools 3.1.1. This affects an unknown part of the file /admin/forms/add/step2.php?submission_type=direct. The manipulation of …

Jul 21, 2024
CVE-2024-6932
3.5 LOW

A vulnerability was found in ClassCMS 4.5. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/?action=home&do=shop:index&keyword=&kind=all. …

Jul 20, 2024
CVE-2024-6694
2.7 LOW

The WP Mail SMTP plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 4.0.1. This is due to plugin …

Jul 20, 2024
CVE-2024-6907
3.5 LOW

A vulnerability was found in SourceCodester Record Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file sort.php. …

Jul 19, 2024
CVE-2024-30130
3.7 LOW

HCL Nomad server on Domino is vulnerable to the cache containing sensitive information which could potentially give an attacker the ability to acquire the sensitive …

Jul 19, 2024
CVE-2024-38806
3.9 LOW

Failure to properly synchronize user's permissions in UAA in Cloud Foundry Foundation v40.17.0 https://github.com/cloudfoundry/cf-deployment/releases/tag/v40.17.0 , potentially resulting in users retaining access rights they should not …

Jul 18, 2024
CVE-2024-40640
2.9 LOW

vodozemac is an open source implementation of Olm and Megolm in pure Rust. Versions before 0.7.0 of vodozemac use a non-constant time base64 implementation for …

Jul 17, 2024
CVE-2023-42010
3.1 LOW

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 could disclose sensitive information in the HTTP response using man in the …

Jul 17, 2024
CVE-2024-38870
3.5 LOW

Zohocorp ManageEngine OpManager, OpManager Plus, OpManager MSP and OpManager Enterprise Edition versions before 128104, from 128151 before 128238, from 128247 before 128250 are vulnerable to …

Jul 17, 2024
CVE-2024-30471
3.7 LOW

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache StreamPipes in user self-registration. This allows an attacker to potentially request the creation of multiple accounts with …

Jul 17, 2024
CVE-2024-6807
2.4 LOW

A vulnerability was found in SourceCodester Student Study Center Desk Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality …

Jul 17, 2024
CVE-2024-6595
3.0 LOW

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from …

Jul 17, 2024
CVE-2024-21174
3.1 LOW

Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.23, 21.3-21.14 and 23.4. Difficult to exploit vulnerability allows …

Jul 16, 2024
CVE-2024-21164
2.5 LOW

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.20. Difficult to exploit vulnerability …

Jul 16, 2024
CVE-2024-21151
3.3 LOW

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged …

Jul 16, 2024
CVE-2024-21144
3.7 LOW

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Concurrency). Supported versions that are affected are Oracle Java …

Jul 16, 2024
CVE-2024-21138
3.7 LOW

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are …

Jul 16, 2024
CVE-2024-21131
3.7 LOW

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are …

Jul 16, 2024
CVE-2024-21123
2.3 LOW

Vulnerability in the Oracle Database Core component of Oracle Database Server. Supported versions that are affected are 19.3-19.23. Easily exploitable vulnerability allows high privileged attacker …

Jul 16, 2024
CVE-2024-40455
2.7 LOW

An arbitrary file deletion vulnerability in ThinkSAAS v3.7 allows attackers to delete arbitrary files via a crafted request.

Jul 16, 2024
CVE-2022-48852
3.3 LOW

In the Linux kernel, the following vulnerability has been resolved: drm/vc4: hdmi: Unregister codec device on unbind On bind we will register the HDMI codec …

Jul 16, 2024
CVE-2024-6780
3.3 LOW

Improper permission control in the mobile application (com.android.server.telecom) may lead to user information security risks.

Jul 16, 2024
CVE-2024-40632
3.7 LOW

Linkerd is an open source, ultralight, security-first service mesh for Kubernetes. In affected versions when the application being run by linkerd is susceptible to SSRF, …

Jul 15, 2024
CVE-2024-39919
3.1 LOW

@jmondi/url-to-png is an open source URL to PNG utility featuring parallel rendering using Playwright for screenshots and with storage caching via Local, S3, or CouchDB. …

Jul 15, 2024
CVE-2024-41007
3.3 LOW

In the Linux kernel, the following vulnerability has been resolved: tcp: avoid too many retransmit packets If a TCP socket is using TCP_USER_TIMEOUT, and the …

Jul 15, 2024
CVE-2024-32945
2.6 LOW

Mattermost Mobile Apps versions <=2.16.0 fail to protect against abuse of a globally shared MathJax state which allows an attacker to change the contents of …

Jul 15, 2024
CVE-2023-41093
3.1 LOW

Use After Free vulnerability in Silicon Labs Bluetooth SDK on 32 bit, ARM may allow an attacker with precise timing capabilities to intercept a small …

Jul 12, 2024
CVE-2024-5470
3.8 LOW

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Guest …

Jul 11, 2024
CVE-2024-2880
2.7 LOW

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.5 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from …

Jul 11, 2024
CVE-2024-23194
3.3 LOW

Improper output Neutralization for Logs (CWE-117) in the Command Centre API Diagnostics Endpoint could allow an attacker limited ability to modify Command Centre log files. …

Jul 11, 2024
CVE-2024-6650
2.4 LOW

A vulnerability was found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0 and classified as problematic. Affected by this issue is the function …

Jul 10, 2024
CVE-2024-39886
3.7 LOW

TONE store App version 3.4.2 and earlier contains an issue with unprotected primary channel. Since TONE store App communicates with TONE store website in cleartext, …

Jul 10, 2024
CVE-2024-36452
3.1 LOW

Cross-site request forgery vulnerability exists in ajaxterm module of Webmin versions prior to 2.003. If this vulnerability is exploited, unintended operations may be performed when …

Jul 10, 2024
CVE-2024-22018
2.9 LOW

A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-read flag is used. This flaw arises from an …

Jul 10, 2024
CVE-2024-22477
1.8 LOW

A cross-site scripting vulnerability exists in the admin console OIDC Policy Management Editor. The impact is contained to admin console users only.

Jul 9, 2024
CVE-2024-21832
3.5 LOW

A potential JSON injection attack vector exists in PingFederate REST API data stores using the POST method and a JSON request body.

Jul 9, 2024
CVE-2024-6501
3.1 LOW

A flaw was found in NetworkManager. When a system running NetworkManager with DEBUG logs enabled and an interface eth1 configured with LLDP enabled, a malicious …

Jul 9, 2024
CVE-2024-26015
3.4 LOW

An incorrect parsing of numbers with different radices vulnerability [CWE-1389] in FortiProxy version 7.4.3 and below, version 7.2.10 and below, version 7.0.17 and below and …

Jul 9, 2024
CVE-2024-37996
3.3 LOW

A vulnerability has been identified in JT Open (All versions < V11.5), JT2Go (All versions < V2406.0003), PLM XML SDK (All versions < V7.1.0.014), Teamcenter …

Jul 9, 2024
CVE-2024-37442
3.8 LOW

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Photo Gallery Team Photo Gallery by Ays allows Code Injection.This …

Jul 9, 2024
CVE-2024-37253
2.7 LOW

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in WpDirectoryKit WP Directory Kit allows Code Injection.This issue affects WP …

Jul 9, 2024
CVE-2024-35777
3.5 LOW

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Automattic WooCommerce allows Content Spoofing.This issue affects WooCommerce: from n/a …

Jul 9, 2024
CVE-2024-34692
3.3 LOW

Due to missing verification of file type or content, SAP Enable Now allows an authenticated attacker to upload arbitrary files. These files include executables which …

Jul 9, 2024
CVE-2024-38372
2.0 LOW

Undici is an HTTP/1.1 client, written from scratch for Node.js. Depending on network and process conditions of a `fetch()` request, `response.arrayBuffer()` might include portion of …

Jul 8, 2024
CVE-2024-34602
3.3 LOW

Use of implicit intent for sensitive communication in Samsung Messages prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information. User interaction …

Jul 8, 2024
CVE-2024-6539
3.5 LOW

A vulnerability classified as problematic has been found in heyewei SpringBootCMS up to 2024-05-28. Affected is an unknown function of the file /guestbook of the …

Jul 7, 2024
CVE-2024-37234
3.5 LOW

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Kodezen Limited Academy LMS.This issue affects Academy LMS: from n/a through 2.0.4.

Jul 6, 2024
CVE-2024-40594
2.3 LOW

The OpenAI ChatGPT app before 2024-07-05 for macOS opts out of the sandbox, and stores conversations in cleartext in a location accessible to other apps.

Jul 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.