CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-8198
8.8 HIGH

Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.113 allowed a remote attacker who had compromised the renderer process to potentially exploit heap …

Aug 28, 2024
CVE-2024-8194
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 128.0.6613.113 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Aug 28, 2024
CVE-2024-8193
8.8 HIGH

Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.113 allowed a remote attacker who had compromised the renderer process to potentially exploit heap …

Aug 28, 2024
CVE-2024-45059
8.8 HIGH

i-Educar is free, fully online school management software that can be used by school secretaries, teachers, coordinators, and area managers. A SQL Injection vulnerability was …

Aug 28, 2024
CVE-2024-45058
8.1 HIGH

i-Educar is free, fully online school management software that can be used by school secretaries, teachers, coordinators, and area managers. Prior to the 2.9 branch, …

Aug 28, 2024
CVE-2024-45057
6.1 MEDIUM

i-Educar is free, fully online school management software that can be used by school secretaries, teachers, coordinators, and area managers. A Reflected Cross-Site Scripting (XSS) …

Aug 28, 2024
CVE-2024-45048
8.8 HIGH

PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Affected versions are subject to a bypassing of a filter which allows for …

Aug 28, 2024
CVE-2024-45046
5.4 MEDIUM

PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In affected versions `\PhpOffice\PhpSpreadsheet\Writer\Html` doesn't sanitize spreadsheet styling information such as font names, …

Aug 28, 2024
CVE-2024-45054
2.8 LOW

Hwameistor is an HA local storage system for cloud-native stateful workloads. This ClusterRole has * verbs of * resources. If a malicious user can access …

Aug 28, 2024
CVE-2024-45043
5.3 MEDIUM

The OpenTelemetry Collector module AWS firehose receiver is for ingesting AWS Kinesis Data Firehose delivery stream messages and parsing the records received based on the …

Aug 28, 2024
CVE-2024-44760
7.5 HIGH

Incorrect access control in the component /servlet/SnoopServlet of Shenzhou News Union Enterprise Management System v5.0 through v18.8 allows attackers to access sensitive information regarding the …

Aug 28, 2024
CVE-2024-43805
7.6 HIGH

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. This vulnerability depends on user interaction by opening a …

Aug 28, 2024
CVE-2024-42793
8.0 HIGH

A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System v1.0 via a crafted request to the /music/ajax.php?action=save_user page.

Aug 28, 2024
CVE-2024-34195
9.8 CRITICAL

TOTOLINK AC1200 Wireless Router A3002R Firmware V1.1.1-B20200824 is vulnerable to Buffer Overflow. In the boa server program's CGI handling function formWlEncrypt, there is a lack …

Aug 28, 2024
CVE-2024-44761
9.8 CRITICAL

An issue in EQ Enterprise Management System before v2.0.0 allows attackers to execute a directory traversal via crafted requests.

Aug 28, 2024
CVE-2024-44915
5.5 MEDIUM

An issue in the component EXR!ReadEXR+0x4eef0 of Irfanview v4.67.1.0 allows attackers to cause an access violation via a crafted EXR file. This vulnerability can lead …

Aug 28, 2024
CVE-2024-44914
5.5 MEDIUM

An issue in the component EXR!ReadEXR+0x3df50 of Irfanview v4.67.1.0 allows attackers to cause an access violation via a crafted EXR file. This vulnerability can lead …

Aug 28, 2024
CVE-2024-44913
5.5 MEDIUM

An issue in the component EXR!ReadEXR+0x40ef1 of Irfanview v4.67.1.0 allows attackers to cause an access violation via a crafted EXR file. This vulnerability can lead …

Aug 28, 2024
CVE-2024-42905
9.8 CRITICAL

Beijing Digital China Cloud Technology Co., Ltd. DCME-320 v.7.4.12.60 has a command execution vulnerability, which can be exploited to obtain device administrator privileges via the …

Aug 28, 2024
CVE-2024-41236
7.2 HIGH

A SQL injection vulnerability in /smsa/admin_login.php in Kashipara Responsive School Management System v3.2.0 allows an attacker to execute arbitrary SQL commands via the "username" parameter …

Aug 28, 2024
CVE-2024-7745
6.5 MEDIUM

In WS_FTP Server versions before 8.8.8 (2022.0.8), a Missing Critical Step in Multi-Factor Authentication of the Web Transfer Module allows users to skip the second-factor …

Aug 28, 2024
CVE-2024-7744
6.5 MEDIUM

In WS_FTP Server versions before 8.8.8 (2022.0.8), an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the Web Transfer Module …

Aug 28, 2024
CVE-2024-6053
4.3 MEDIUM

Improper access control in the clipboard synchronization feature in TeamViewer Full Client prior version 15.57 and TeamViewer Meeting prior version 15.55.3 can lead to unintentional …

Aug 28, 2024
CVE-2024-41565
4.3 MEDIUM

JustEnoughItems (JEI) 19.5.0.33 and before contains an Improper Validation of Specified Index, Position, or Offset in Input vulnerability. The specific issue is a failure to …

Aug 28, 2024
CVE-2024-41564
4.3 MEDIUM

EMI v.1.1.10 and before, fixed in v.1.1.11, contains an Improper Validation of Specified Index, Position, or Offset in Input vulnerability. The specific issue is a …

Aug 28, 2024
CVE-2024-20478
6.5 MEDIUM

A vulnerability in the software upgrade component of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Network Controller, formerly Cisco Cloud APIC, could allow an …

Aug 28, 2024
CVE-2024-20446
8.6 HIGH

A vulnerability in the DHCPv6 relay agent of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition …

Aug 28, 2024
CVE-2024-20413
6.7 MEDIUM

A vulnerability in Cisco NX-OS Software could allow an authenticated, local attacker with privileges to access the Bash shell to elevate privileges to network-admin on …

Aug 28, 2024
CVE-2024-20411
6.7 MEDIUM

A vulnerability in Cisco NX-OS Software could allow an authenticated, local attacker with privileges to access the Bash shell to execute arbitrary code as root on …

Aug 28, 2024
CVE-2024-20289
4.4 MEDIUM

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, low-privileged, local attacker to execute arbitrary commands on the underlying operating system …

Aug 28, 2024
CVE-2024-20286
5.3 MEDIUM

A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local attacker to escape the Python sandbox and gain unauthorized …

Aug 28, 2024
CVE-2024-20285
5.3 MEDIUM

A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local attacker to escape the Python sandbox and gain unauthorized …

Aug 28, 2024
CVE-2024-20284
5.3 MEDIUM

A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local attacker to escape the Python sandbox and gain unauthorized …

Aug 28, 2024
CVE-2024-20279
4.3 MEDIUM

A vulnerability in the restricted security domain implementation of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to modify the behavior …

Aug 28, 2024
CVE-2024-42900
6.1 MEDIUM

Ruoyi v4.7.9 and before was discovered to contain a cross-site scripting (XSS) vulnerability via the sql parameter of the createTable() function at /tool/gen/create.

Aug 28, 2024
CVE-2024-42698
4.3 MEDIUM

Roughly Enough Items (REI) v.16.0.729 and before contains an Improper Validation of Specified Index, Position, or Offset in Input vulnerability. The specific issue is a …

Aug 28, 2024
CVE-2024-34198
9.8 CRITICAL

TOTOLINK AC1200 Wireless Router A3002RU V2.1.1-B20230720.1011 is vulnerable to Buffer Overflow. The formWlEncrypt CGI handler in the boa program fails to limit the length of …

Aug 28, 2024
CVE-2024-8195
5.3 MEDIUM

The Permalink Manager Lite plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'debug_data', 'debug_query', and …

Aug 28, 2024
CVE-2024-7447
5.3 MEDIUM

The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free plugin for WordPress is vulnerable to unauthorized modification …

Aug 28, 2024
CVE-2024-6450
6.1 MEDIUM

HyperView Geoportal Toolkit in versions lower than 8.5.0 is vulnerable to Reflected Cross-Site Scripting (XSS). An unauthenticated attacker might trick somebody into using a crafted …

Aug 28, 2024
CVE-2024-6449
6.5 MEDIUM

HyperView Geoportal Toolkit in versions lower than 8.5.0 does not restrict cross-domain requests when fetching remote content pointed by one of GET request parameters. An …

Aug 28, 2024
CVE-2024-7269
5.4 MEDIUM

Improper Neutralization of Input During Web Page Generation vulnerability in "Update of Personal Details" form in ConnX ESP HR Management allows Stored XSS attack. An …

Aug 28, 2024
CVE-2024-5546
8.3 HIGH

Zohocorp ManageEngine Password Manager Pro versions before 12431 and ManageEngine PAM360 versions before 7001 are affected by authenticated SQL Injection vulnerability via a global search …

Aug 28, 2024
CVE-2024-44943
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm: gup: stop abusing try_grab_folio A kernel warning was reported when pinning folio in CMA …

Aug 28, 2024
CVE-2023-26324
8.8 HIGH

A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit …

Aug 28, 2024
CVE-2023-26323
7.6 HIGH

A code execution vulnerability exists in the Xiaomi App market product. The vulnerability is caused by unsafe configuration and can be exploited by attackers to …

Aug 28, 2024
CVE-2023-26322
8.8 HIGH

A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit …

Aug 28, 2024
CVE-2023-26321
6.3 MEDIUM

A path traversal vulnerability exists in the Xiaomi File Manager application product(international version). The vulnerability is caused by unfiltered special characters and can be exploited …

Aug 28, 2024
CVE-2024-6312
6.5 MEDIUM

The Funnelforms Free plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 3.7.3.2 via the 'af2DeleteFontFile' function. This …

Aug 28, 2024
CVE-2024-6311
7.2 HIGH

The Funnelforms Free plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'af2_add_font' function in all versions …

Aug 28, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.