CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-45192
5.3 MEDIUM

An issue was discovered in Matrix libolm through 3.2.16. Cache-timing attacks can occur due to use of base64 when decoding group session keys. This refers …

Aug 22, 2024
CVE-2024-45191
5.3 MEDIUM

An issue was discovered in Matrix libolm through 3.2.16. The AES implementation is vulnerable to cache-timing attacks due to use of S-boxes. This is related …

Aug 22, 2024
CVE-2024-43780
4.3 MEDIUM

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.0, 9.8.x <= 9.8.2 fail to enforce permissions which allows a guest user with read access to …

Aug 22, 2024
CVE-2024-42771
4.8 MEDIUM

A Stored Cross Site Scripting (XSS) vulnerability was found in " /admin/edit_room_controller.php" of the Kashipara Hotel Management System v1.0, which allows remote attackers to execute …

Aug 22, 2024
CVE-2024-42770
4.7 MEDIUM

A Stored Cross Site Scripting (XSS) vulnerability was found in "/core/signup_user.php" of Kashipara Hotel Management System v1.0, which allows remote attackers to execute arbitrary code …

Aug 22, 2024
CVE-2024-42769
6.1 MEDIUM

A Reflected Cross Site Scripting (XSS) vulnerability was found in "/core/signup_user.php " of Kashipara Hotel Management System v1.0, which allows remote attackers to execute arbitrary …

Aug 22, 2024
CVE-2024-42497
6.0 MEDIUM

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to properly enforce permissions which allows a user with systems …

Aug 22, 2024
CVE-2024-42490
7.5 HIGH

authentik is an open-source Identity Provider. Several API endpoints can be accessed by users without correct authentication/authorization. The main API endpoints affected by this are …

Aug 22, 2024
CVE-2024-40884
2.7 LOW

Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to properly enforce permissions which allows a team admin user without "Add Team Members" permission to …

Aug 22, 2024
CVE-2024-3127
4.3 MEDIUM

An issue has been discovered in GitLab EE affecting all versions starting from 12.5 before 17.1.6, all versions starting from 17.2 before 17.2.4, all versions …

Aug 22, 2024
CVE-2024-36441
5.4 MEDIUM

Swissphone DiCal-RED 4009 devices allow an unauthenticated attacker use a port-2101 TCP connection to gain access to operation messages that are received by the device.

Aug 22, 2024
CVE-2023-6452
9.6 CRITICAL

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Web Security (Transaction Viewer) allows Stored XSS. The Forcepoint Web Security portal …

Aug 22, 2024
CVE-2024-43787
5.0 MEDIUM

Hono is a Web application framework that provides support for any JavaScript runtime. Hono CSRF middleware can be bypassed using crafted Content-Type header. MIME types …

Aug 22, 2024
CVE-2024-43785
2.5 LOW

gitoxide An idiomatic, lean, fast & safe pure Rust implementation of Git. gitoxide-core, which provides most underlying functionality of the gix and ein commands, does …

Aug 22, 2024
CVE-2024-43398
5.9 MEDIUM

REXML is an XML toolkit for Ruby. The REXML gem before 3.3.6 has a DoS vulnerability when it parses an XML that has many deep …

Aug 22, 2024
CVE-2024-36445
9.8 CRITICAL

Swissphone DiCal-RED 4009 devices allow a remote attacker to gain a root shell via TELNET without authentication.

Aug 22, 2024
CVE-2024-36444
8.1 HIGH

cgi-bin/fdmcgiwebv2.cgi on Swissphone DiCal-RED 4009 devices allows an unauthenticated attacker to gain access to device logs.

Aug 22, 2024
CVE-2024-36442
8.8 HIGH

cgi-bin/fdmcgiwebv2.cgi on Swissphone DiCal-RED 4009 devices allows an authenticated attacker to gain access to arbitrary files on the device's file system.

Aug 22, 2024
CVE-2024-36440
6.8 MEDIUM

An issue was discovered on Swissphone DiCal-RED 4009 devices. An attacker with access to the file /etc/deviceconfig may recover the administrative device password via password-cracking …

Aug 22, 2024
CVE-2024-36439
9.4 CRITICAL

Swissphone DiCal-RED 4009 devices allow a remote attacker to gain access to the administrative web interface via the device password's hash value, without knowing the …

Aug 22, 2024
CVE-2024-36443
7.6 HIGH

Swissphone DiCal-RED 4009 devices allow a remote attacker to gain read access to almost the whole file system via anonymous FTP.

Aug 22, 2024
CVE-2024-43331
5.3 MEDIUM

Missing Authorization vulnerability in VeronaLabs WP SMS.This issue affects WP SMS: from n/a through 6.9.3.

Aug 22, 2024
CVE-2024-7848
4.3 MEDIUM

The User Private Files – WordPress File Sharing Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and …

Aug 22, 2024
CVE-2024-39746
5.9 MEDIUM

IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 could allow a remote attacker to obtain sensitive information, caused by the failure to properly …

Aug 22, 2024
CVE-2024-39745
5.9 MEDIUM

IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive …

Aug 22, 2024
CVE-2024-39744
4.3 MEDIUM

IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and …

Aug 22, 2024
CVE-2024-35151
6.5 MEDIUM

IBM OpenPages with Watson 8.3 and 9.0 could allow authenticated users access to sensitive information through improper authorization controls on APIs.

Aug 22, 2024
CVE-2024-7778
6.4 MEDIUM

The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, …

Aug 22, 2024
CVE-2024-6870
6.4 MEDIUM

The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via file uploads in all versions up to, and including, 2.4.7 …

Aug 22, 2024
CVE-2024-8072
5.3 MEDIUM

Mage AI allows remote unauthenticated attackers to leak the terminal server command history of arbitrary users

Aug 22, 2024
CVE-2024-8071
4.7 MEDIUM

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to restrict which roles can promote a user as …

Aug 22, 2024
CVE-2024-43813
4.3 MEDIUM

Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to enforce proper access controls which allows any authenticated user, including guests, to mark any channel …

Aug 22, 2024
CVE-2024-42411
5.3 MEDIUM

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to restrict the input in POST /api/v4/users which allows a …

Aug 22, 2024
CVE-2024-40886
4.6 MEDIUM

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2 fail to sanitize user inputs in the frontend that are used …

Aug 22, 2024
CVE-2024-39836
4.8 MEDIUM

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to ensure that remote/synthetic users cannot create sessions or …

Aug 22, 2024
CVE-2024-39810
4.9 MEDIUM

Mattermost versions 9.5.x <= 9.5.7 and 9.10.x <= 9.10.0 fail to time limit and size limit the CA path file in the ElasticSearch configuration which …

Aug 22, 2024
CVE-2024-32939
4.3 MEDIUM

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2, when shared channels are enabled, fail to redact remote users' original …

Aug 22, 2024
CVE-2024-45169
9.8 CRITICAL

An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Due to improper input validation, improper deserialization, and improper restriction of …

Aug 22, 2024
CVE-2024-45168
9.1 CRITICAL

An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Data is transferred over a raw socket without any authentication mechanism. …

Aug 22, 2024
CVE-2024-45167
9.8 CRITICAL

An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Due to improper input validation, improper deserialization, and improper restriction of …

Aug 22, 2024
CVE-2024-45166
9.8 CRITICAL

An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Due to improper input validation, improper deserialization, and improper restriction of …

Aug 22, 2024
CVE-2024-45165
5.3 MEDIUM

An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Data is sent between client and server with encryption. However, the …

Aug 22, 2024
CVE-2024-45163
9.1 CRITICAL

The Mirai botnet through 2024-08-19 mishandles simultaneous TCP connections to the CNC (command and control) server. Unauthenticated sessions remain open, causing resource consumption. For example, …

Aug 22, 2024
CVE-2022-48943
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: make apf token non-zero to fix bug In current async pagefault logic, when …

Aug 22, 2024
CVE-2022-48942
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: hwmon: Handle failure to register sensor with thermal zone correctly If an attempt is made …

Aug 22, 2024
CVE-2022-48941
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ice: fix concurrent reset and removal of VFs Commit c503e63200c6 ("ice: Stop processing VF messages …

Aug 22, 2024
CVE-2022-48940
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix crash due to incorrect copy_map_value When both bpf_spin_lock and bpf_timer are present in …

Aug 22, 2024
CVE-2022-48939
3.3 LOW

In the Linux kernel, the following vulnerability has been resolved: bpf: Add schedule points in batch ops syzbot reported various soft lockups caused by bpf …

Aug 22, 2024
CVE-2022-48938
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: CDC-NCM: avoid overflow in sanity checking A broken device may give an extreme offset like …

Aug 22, 2024
CVE-2022-48937
3.3 LOW

In the Linux kernel, the following vulnerability has been resolved: io_uring: add a schedule point in io_add_buffers() Looping ~65535 times doing kmalloc() calls can trigger …

Aug 22, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.