CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-39400
8.1 HIGH

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. This vulnerability could allow an admin attacker …

Aug 14, 2024
CVE-2024-39399
7.7 HIGH

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability …

Aug 14, 2024
CVE-2024-39398
7.4 HIGH

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Restriction of Excessive Authentication Attempts vulnerability that could result in a …

Aug 14, 2024
CVE-2024-39397
9.0 CRITICAL

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in …

Aug 14, 2024
CVE-2024-6532
6.4 MEDIUM

The Sheet to Table Live Sync for Google Sheet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's STWT_Sheet_Table shortcode in all …

Aug 14, 2024
CVE-2024-38483
5.8 MEDIUM

Dell BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, …

Aug 14, 2024
CVE-2024-4389
8.8 HIGH

The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the uploadFile …

Aug 14, 2024
CVE-2024-41864
7.8 HIGH

Substance3D - Designer versions 13.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

Aug 14, 2024
CVE-2024-41863
5.5 MEDIUM

Substance3D - Sampler versions 4.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Aug 14, 2024
CVE-2024-41862
5.5 MEDIUM

Substance3D - Sampler versions 4.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Aug 14, 2024
CVE-2024-41861
5.5 MEDIUM

Substance3D - Sampler versions 4.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Aug 14, 2024
CVE-2024-41860
5.5 MEDIUM

Substance3D - Sampler versions 4.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Aug 14, 2024
CVE-2024-41858
7.8 HIGH

InCopy versions 18.5.2, 19.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context …

Aug 14, 2024
CVE-2024-7732
9.8 CRITICAL

Dr.ID Access Control System from SECOM does not properly validate a specific page parameter, allowing unauthenticated remote attackers to inject SQL commands to read, modify, …

Aug 14, 2024
CVE-2024-7731
9.8 CRITICAL

Dr.ID Access Control System from SECOM does not properly validate a specific page parameter, allowing unauthenticated remote attackers to inject SQL commands to read, modify, …

Aug 14, 2024
CVE-2024-7588
6.4 MEDIUM

The Gutenberg Blocks, Page Builder – ComboBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Accordion block in all versions up …

Aug 14, 2024
CVE-2024-7729
7.5 HIGH

The CAYIN Technology CMS lacks proper access control, allowing unauthenticated remote attackers to download arbitrary CGI files.

Aug 14, 2024
CVE-2024-7728
7.2 HIGH

The specific CGI of the CAYIN Technology CMS does not properly validate user input, allowing a remote attacker with administrator privileges to inject OS commands …

Aug 14, 2024
CVE-2024-38653
7.5 HIGH

XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on the server.

Aug 14, 2024
CVE-2024-38652
9.1 CRITICAL

Path traversal in the skin management component of Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to achieve denial of service via arbitrary file deletion.

Aug 14, 2024
CVE-2024-37399
7.5 HIGH

A NULL pointer dereference in WLAvalancheService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to crash the service, resulting in a DoS.

Aug 14, 2024
CVE-2024-37373
7.2 HIGH

Improper input validation in the Central Filestore in Ivanti Avalanche 6.3.1 allows a remote authenticated attacker with admin rights to achieve RCE.

Aug 14, 2024
CVE-2024-36136
7.5 HIGH

An off-by-one error in WLInfoRailService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to crash the service, resulting in a DoS.

Aug 14, 2024
CVE-2024-20083
9.8 CRITICAL

In venc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with …

Aug 14, 2024
CVE-2024-20082
9.8 CRITICAL

In Modem, there is a possible memory corruption due to a missing bounds check. This could lead to remote code execution with no additional execution …

Aug 14, 2024
CVE-2024-7754
6.3 MEDIUM

A vulnerability was found in SourceCodester Clinics Patient Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the …

Aug 14, 2024
CVE-2024-7753
5.3 MEDIUM

A vulnerability was found in SourceCodester Clinics Patient Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file …

Aug 14, 2024
CVE-2024-7752
3.5 LOW

A vulnerability was found in SourceCodester Clinics Patient Management System 1.0. It has been classified as problematic. This affects an unknown part of the file …

Aug 14, 2024
CVE-2024-38163
7.8 HIGH

Windows Update Stack Elevation of Privilege Vulnerability

Aug 14, 2024
CVE-2024-7751
6.3 MEDIUM

A vulnerability was found in SourceCodester Clinics Patient Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Aug 13, 2024
CVE-2024-7750
6.3 MEDIUM

A vulnerability has been found in SourceCodester Clinics Patient Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Aug 13, 2024
CVE-2024-28986
9.8 CRITICAL KEV

SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to …

Aug 13, 2024
CVE-2024-7749
3.5 LOW

A vulnerability, which was classified as problematic, was found in SourceCodester Accounts Manager App 1.0. Affected is an unknown function of the file /endpoint/add-account.php. The …

Aug 13, 2024
CVE-2024-7748
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Accounts Manager App 1.0. This issue affects some unknown processing of the file …

Aug 13, 2024
CVE-2024-7743
7.3 HIGH

A vulnerability was found in wanglongcn ltcms 1.0.20. It has been declared as critical. Affected by this vulnerability is the function downloadUrl of the file …

Aug 13, 2024
CVE-2024-7742
7.3 HIGH

A vulnerability was found in wanglongcn ltcms 1.0.20. It has been classified as critical. Affected is the function multiDownload of the file /api/file/multiDownload of the …

Aug 13, 2024
CVE-2024-7741
5.3 MEDIUM

A vulnerability was found in wanglongcn ltcms 1.0.20 and classified as critical. This issue affects the function downloadFile of the file /api/file/downloadfile of the component …

Aug 13, 2024
CVE-2024-7740
7.3 HIGH

A vulnerability has been found in wanglongcn ltcms 1.0.20 and classified as critical. This vulnerability affects the function download of the file /api/test/download of the …

Aug 13, 2024
CVE-2024-42368
6.5 MEDIUM

OpenTelemetry, also known as OTel, is a vendor-neutral open source Observability framework for instrumenting, generating, collecting, and exporting telemetry data such as traces, metrics, and …

Aug 13, 2024
CVE-2024-7739
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in yzane vscode-markdown-pdf 1.5.0. This affects an unknown part. The manipulation leads to cross site scripting. …

Aug 13, 2024
CVE-2024-7738
3.3 LOW

A vulnerability, which was classified as problematic, has been found in yzane vscode-markdown-pdf 1.5.0. Affected by this issue is some unknown functionality of the component …

Aug 13, 2024
CVE-2024-7593
9.8 CRITICAL KEV

Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the …

Aug 13, 2024
CVE-2024-7570
8.3 HIGH

Improper certificate validation in Ivanti ITSM on-prem and Neurons for ITSM Versions 2023.4 and earlier allows a remote attacker in a MITM position to craft …

Aug 13, 2024
CVE-2024-7569
9.6 CRITICAL

An information disclosure vulnerability in Ivanti ITSM on-prem and Neurons for ITSM versions 2023.4 and earlier allows an unauthenticated attacker to obtain the OIDC client …

Aug 13, 2024
CVE-2024-7733
3.5 LOW

A vulnerability, which was classified as problematic, was found in FastCMS up to 0.1.5. Affected is an unknown function of the component New Article Category …

Aug 13, 2024
CVE-2024-7567

A denial-of-service vulnerability exists via the CIP/Modbus port in the Rockwell Automation Micro850/870 (2080 -L50E/2080 -L70E). If exploited, the CIP/Modbus communication may be disrupted for …

Aug 13, 2024
CVE-2024-6079

A vulnerability exists in the Rockwell Automation Emulate3D™, which could be leveraged to execute a DLL Hijacking attack. The application loads shared libraries, which are …

Aug 13, 2024
CVE-2024-38223
6.8 MEDIUM

Windows Initial Machine Configuration Elevation of Privilege Vulnerability

Aug 13, 2024
CVE-2024-38215
7.8 HIGH

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

Aug 13, 2024
CVE-2024-38214
6.5 MEDIUM

Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

Aug 13, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.