CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-21879
8.8 HIGH

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability through an url parameter of an authenticated enpoint in Enphase IQ Gateway (formerly …

Aug 12, 2024
CVE-2024-21878
9.8 CRITICAL

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Enphase IQ Gateway (formerly known as Envoy) allows OS Command Injection. This …

Aug 12, 2024
CVE-2024-21877
6.5 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability through a url parameter in Enphase IQ Gateway (formerly known as Envoy) allows …

Aug 12, 2024
CVE-2024-21876
9.1 CRITICAL

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability via a URL parameter in Enphase IQ Gateway (formerly known as Envoy) allows …

Aug 12, 2024
CVE-2024-0115
6.1 MEDIUM

NVIDIA CV-CUDA for Ubuntu 20.04, Ubuntu 22.04, and Jetpack contains a vulnerability in Python APIs where a user may cause an uncontrolled resource consumption issue …

Aug 12, 2024
CVE-2024-0113
7.5 HIGH

NVIDIA Mellanox OS, ONYX, Skyway, and MetroX-3 XCC contain a vulnerability in the web support, where an attacker can cause a CGI path traversal by …

Aug 12, 2024
CVE-2023-50810
6.0 MEDIUM

In certain Sonos products before Sonos S1 Release 11.12 and S2 release 15.9, a vulnerability exists in the U-Boot component of the firmware that allow …

Aug 12, 2024
CVE-2023-50809
7.8 HIGH

In certain Sonos products before S1 Release 11.12 and S2 release 15.9, the mt_7615.ko wireless driver does not properly validate an information element during negotiation …

Aug 12, 2024
CVE-2023-38018
6.3 MEDIUM

IBM Aspera Shares 1.10.0 PL2 does not invalidate session after a password change which could allow an authenticated user to impersonate another user on the …

Aug 12, 2024
CVE-2023-31315
7.5 HIGH

Improper validation in a model specific register (MSR) could allow a malicious program with ring0 access to modify SMM configuration while SMI lock is enabled, …

Aug 12, 2024
CVE-2022-38322

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Aug 12, 2024
CVE-2024-42493
5.3 MEDIUM

Dorsett Controls InfoScan is vulnerable due to a leak of possible sensitive information through the response headers and the rendered JavaScript prior to user login.

Aug 8, 2024
CVE-2024-42408
5.3 MEDIUM

The InfoScan client download page can be intercepted with a proxy, to expose filenames located on the system, which could lead to additional information exposure.

Aug 8, 2024
CVE-2024-41161
7.5 HIGH

Use of hard-coded credentials vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9 and prior, enables an unauthenticated remote attacker …

Aug 8, 2024
CVE-2024-39287
5.3 MEDIUM

Dorsett Controls Central Server update server has potential information leaks with an unprotected file that contains passwords and API keys.

Aug 8, 2024
CVE-2024-37382
7.2 HIGH

An issue discovered in import host feature in Ab Initio Metadata Hub and Authorization Gateway before 4.3.1.1 allows attackers to run arbitrary code via crafted …

Aug 8, 2024
CVE-2024-0104
4.2 MEDIUM

NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in the LDAP AAA component, where a user can cause improper access. A …

Aug 8, 2024
CVE-2023-40261
6.8 MEDIUM

Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR17, 4.0.0 SR07, 4.1.0 SR04, 4.2.0 SR04, and 4.3.0 SR02 fails to validate file attributes during the …

Aug 8, 2024
CVE-2023-33206
6.8 MEDIUM

Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR16, 4.0.0 SR06, 4.1.0 SR04, 4.2.0 SR03, and 4.3.0 SR01 fails to validate symlinks during the Pre-Boot …

Aug 8, 2024
CVE-2023-28865
6.6 MEDIUM

Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR15, 4.0.0 SR05, 4.1.0 SR03, and 4.2.0 SR02 fails to validate the directory contents of certain directories …

Aug 8, 2024
CVE-2023-24064
6.8 MEDIUM

Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR4 fails to validate /etc/initab during the Pre-Boot Authorization (PBA) process. This can be exploited by a …

Aug 8, 2024
CVE-2023-24063
6.8 MEDIUM

Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR10 fails to validate /etc/mtab during the Pre-Boot Authorization (PBA) process. This can be exploited by a …

Aug 8, 2024
CVE-2023-24062
6.8 MEDIUM

Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR12, 4.0.0 SR04, 4.1.0 SR02, and 4.2.0 SR01 fails to validate the directory structure of the root …

Aug 8, 2024
CVE-2024-7394
4.8 MEDIUM

Concrete CMS versions 9 through 9.3.2 and below 8.5.18 are vulnerable to Stored XSS in getAttributeSetName(). A rogue administrator could inject malicious code. The Concrete …

Aug 8, 2024
CVE-2024-42366
9.0 CRITICAL

VRCX is an assistant/companion application for VRChat. In versions prior to 2024.03.23, a CefSharp browser with over-permission and cross-site scripting via overlay notification can be …

Aug 8, 2024
CVE-2024-42365
7.4 HIGH

Asterisk is an open source private branch exchange (PBX) and telephony toolkit. Prior to asterisk versions 18.24.2, 20.9.2, and 21.4.2 and certified-asterisk versions 18.9-cert11 and …

Aug 8, 2024
CVE-2024-0108
8.7 HIGH

NVIDIA Jetson Linux contains a vulnerability in NvGPU where error handling paths in GPU MMU mapping code fail to clean up a failed mapping attempt. …

Aug 8, 2024
CVE-2024-0107
7.8 HIGH

NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A …

Aug 8, 2024
CVE-2024-0102
3.3 LOW

NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvdisasm, where an attacker can cause an out-of-bounds read issue by deceiving a user into …

Aug 8, 2024
CVE-2024-0101
7.5 HIGH

NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in ipfilter, where improper ipfilter definitions could enable an attacker to cause a …

Aug 8, 2024
CVE-2024-7480
4.2 MEDIUM

An Improper access control vulnerability was found in Avaya Aura System Manager which could allow a command-line interface (CLI) user with administrative privileges to read …

Aug 8, 2024
CVE-2024-7477
6.5 MEDIUM

A SQL injection vulnerability was found which could allow a command line interface (CLI) user with administrative privileges to execute arbitrary queries against the Avaya …

Aug 8, 2024
CVE-2024-41238
5.3 MEDIUM

A SQL injection vulnerability in /smsa/student_login.php in Kashipara Responsive School Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "username" parameter.

Aug 8, 2024
CVE-2024-7490
9.8 CRITICAL

Improper Input Validation vulnerability in Microchip Techology Advanced Software Framework example DHCP server can cause remote code execution through a buffer overflow. This vulnerability is …

Aug 8, 2024
CVE-2024-42357
7.3 HIGH

Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, the Shopware application API contains a search functionality which enables users to search …

Aug 8, 2024
CVE-2024-42356
8.3 HIGH

Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, the `context` variable is injected into almost any Twig Template and allows to …

Aug 8, 2024
CVE-2024-42355
8.3 HIGH

Shopware, an open ecommerce platform, has a new Twig Tag `sw_silent_feature_call` which silences deprecation messages while triggered in this tag. Prior to versions 6.6.5.1 and …

Aug 8, 2024
CVE-2024-42354
5.3 MEDIUM

Shopware is an open commerce platform. The store-API works with regular entities and not expose all fields for the public API; fields need to be …

Aug 8, 2024
CVE-2024-41942
7.2 HIGH

JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to versions 4.1.6 and 5.1.0, if a user is granted …

Aug 8, 2024
CVE-2024-7348
8.8 HIGH

Time-of-check Time-of-use (TOCTOU) race condition in pg_dump in PostgreSQL allows an object creator to execute arbitrary SQL functions as the user running pg_dump, which is …

Aug 8, 2024
CVE-2024-3659
7.2 HIGH

Firmware in KAON AR2140 routers, prior to versions 3.2.50 and 4.2.16, is vulnerable to a shell command injection via sending a crafted request to one …

Aug 8, 2024
CVE-2024-7610
4.3 MEDIUM

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions starting with 15.9 before 17.0.6, 17.1 prior to 17.1.4, and …

Aug 8, 2024
CVE-2024-7554
4.9 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.9 before 17.0.6, all versions starting from 17.1 before 17.1.4, all versions …

Aug 8, 2024
CVE-2024-5423
6.5 MEDIUM

Multiple Denial of Service (DoS) conditions has been discovered in GitLab CE/EE affecting all versions starting from 1.0 prior to 17.0.6, starting from 17.1 prior …

Aug 8, 2024
CVE-2024-4207
4.4 MEDIUM

A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 prior 17.0.6, starting from 17.1 prior to 17.1.4, and starting …

Aug 8, 2024
CVE-2024-3958
5.3 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. An issue was …

Aug 8, 2024
CVE-2024-3114
4.3 MEDIUM

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.10 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2, …

Aug 8, 2024
CVE-2024-3035
6.8 MEDIUM

A permission check vulnerability in GitLab CE/EE affecting all versions starting from 8.12 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2 …

Aug 8, 2024
CVE-2024-2800
6.5 MEDIUM

ReDoS flaw in RefMatcher when matching branch names using wildcards in GitLab EE/CE affecting all versions from 11.3 prior to 17.0.6, 17.1 prior to 17.1.4, …

Aug 8, 2024
CVE-2024-6329
5.7 MEDIUM

An issue was discovered in GitLab CE/EE affecting all versions starting from 8.16 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from …

Aug 8, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.