CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-4784
4.2 MEDIUM

An issue was discovered in GitLab EE starting from version 16.7 before 17.0.6, version 17.1 before 17.1.4 and 17.2 before 17.2.2 that allowed bypassing the …

Aug 8, 2024
CVE-2024-4210
6.5 MEDIUM

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions starting with 12.6 before 17.0.6, 17.1 prior to 17.1.4, and …

Aug 8, 2024
CVE-2024-42038
8.8 HIGH

Vulnerability of PIN enhancement failures in the screen lock module Impact: Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.

Aug 8, 2024
CVE-2024-42037
9.3 CRITICAL

Vulnerability of uncaught exceptions in the Graphics module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Aug 8, 2024
CVE-2024-42036
2.5 LOW

Access permission verification vulnerability in the Notepad module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Aug 8, 2024
CVE-2024-42035
8.4 HIGH

Permission control vulnerability in the App Multiplier module Impact:Successful exploitation of this vulnerability may affect functionality and confidentiality.

Aug 8, 2024
CVE-2024-42034
6.6 MEDIUM

LaunchAnywhere vulnerability in the account module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Aug 8, 2024
CVE-2024-42033
6.9 MEDIUM

Access control vulnerability in the security verification module mpact: Successful exploitation of this vulnerability will affect integrity and confidentiality.

Aug 8, 2024
CVE-2024-42257
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ext4: use memtostr_pad() for s_volume_name As with the other strings in struct ext4_super_block, s_volume_name is …

Aug 8, 2024
CVE-2024-42256
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: cifs: Fix server re-repick on subrequest retry When a subrequest is marked for needing retry, …

Aug 8, 2024
CVE-2024-42255
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tpm: Use auth only after NULL check in tpm_buf_check_hmac_response() Dereference auth after NULL check in …

Aug 8, 2024
CVE-2024-42254
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: io_uring: fix error pbuf checking Syz reports a problem, which boils down to NULL vs …

Aug 8, 2024
CVE-2024-42253
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: gpio: pca953x: fix pca953x_irq_bus_sync_unlock race Ensure that `i2c_lock' is held when setting interrupt latch and …

Aug 8, 2024
CVE-2024-42252
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: closures: Change BUG_ON() to WARN_ON() If a BUG_ON() can be hit in the wild, it …

Aug 8, 2024
CVE-2024-42251
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm: page_ref: remove folio_try_get_rcu() The below bug was reported on a non-SMP kernel: [ 275.267158][ …

Aug 8, 2024
CVE-2024-42032
4.4 MEDIUM

Access permission verification vulnerability in the Contacts module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Aug 8, 2024
CVE-2024-42031
7.5 HIGH

Access permission verification vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Aug 8, 2024
CVE-2024-42030
6.2 MEDIUM

Access permission verification vulnerability in the content sharing pop-up module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Aug 8, 2024
CVE-2024-22069
7.1 HIGH

There is a permission and access control vulnerability of ZTE's ZXV10 XT802/ET301 product.Attackers with common permissions can log in the terminal web and change the …

Aug 8, 2024
CVE-2023-7265
4.0 MEDIUM

Permission verification vulnerability in the lock screen module Impact: Successful exploitation of this vulnerability may affect availability

Aug 8, 2024
CVE-2024-7548
8.8 HIGH

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the 'order' parameter in all versions up to, and …

Aug 8, 2024
CVE-2024-7150
8.8 HIGH

The Slider by 10Web – Responsive Image Slider plugin for WordPress is vulnerable to time-based SQL Injection via the 'id' parameter in all versions up …

Aug 8, 2024
CVE-2024-6884
5.4 MEDIUM

The Gutenberg Blocks with AI by Kadence WP WordPress plugin before 3.2.39 does not validate and escape some of its block options before outputting them …

Aug 8, 2024
CVE-2024-6824
4.3 MEDIUM

The Premium Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the …

Aug 8, 2024
CVE-2024-6481
4.8 MEDIUM

The Search & Filter Pro WordPress plugin before 2.5.18 does not sanitise and escape some of its settings, which could allow high privilege users such …

Aug 8, 2024
CVE-2024-5226
6.4 MEDIUM

The Fuse Social Floating Sidebar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the file upload functionality in all versions up to, and …

Aug 8, 2024
CVE-2024-6987
4.3 MEDIUM

The Orchid Store theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'orchid_store_activate_plugin' function in all …

Aug 8, 2024
CVE-2024-6869
5.4 MEDIUM

The Falang multilanguage for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in …

Aug 8, 2024
CVE-2024-5668
6.4 MEDIUM

The Lightbox & Modal Popup WordPress Plugin – FooBox plugin for WordPress is vulnerable to DOM-based Stored Cross-Site Scripting via HTML data attributes in all …

Aug 8, 2024
CVE-2024-6552
5.3 MEDIUM

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, …

Aug 8, 2024
CVE-2024-6254
4.3 MEDIUM

The Brizy – Page Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.1. This is due …

Aug 8, 2024
CVE-2024-7492
8.8 HIGH

The MainWP Child Reports plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2. This is due to …

Aug 8, 2024
CVE-2024-7350
9.8 CRITICAL

The Appointment Booking Calendar Plugin and Online Scheduling Plugin – BookingPress plugin for WordPress is vulnerable to authentication bypass in versions 1.1.6 to 1.1.7. This …

Aug 8, 2024
CVE-2024-7561
8.8 HIGH

The The Next theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.0 via deserialization of untrusted input …

Aug 8, 2024
CVE-2024-7560
7.2 HIGH

The News Flash theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.0 via deserialization of untrusted input …

Aug 8, 2024
CVE-2024-7486
8.8 HIGH

The MultiPurpose theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.2.0 via deserialization of untrusted input through …

Aug 8, 2024
CVE-2024-38202
7.3 HIGH

Summary Microsoft was notified that an elevation of privilege vulnerability exists in Windows Update, potentially enabling an attacker with basic user privileges to reintroduce previously …

Aug 8, 2024
CVE-2024-21302
6.7 MEDIUM

Summary: As of July 8, 2025 Microsoft has completed mitigations to address this vulnerability. See KB5042562: Guidance for blocking rollback of virtualization-based security related updates …

Aug 8, 2024
CVE-2024-6893
7.5 HIGH

The "soap_cgi.pyc" API handler allows the XML body of SOAP requests to contain references to external entities. This allows an unauthenticated attacker to read local …

Aug 8, 2024
CVE-2024-6892
6.1 MEDIUM

Attackers can craft a malicious link that once clicked will execute arbitrary JavaScript in the context of the Journyx web application.

Aug 8, 2024
CVE-2024-6891
8.8 HIGH

Attackers with a valid username and password can exploit a python code injection vulnerability during the natural login flow.

Aug 8, 2024
CVE-2024-6890
8.8 HIGH

Password reset tokens are generated using an insecure source of randomness. Attackers who know the username of the Journyx installation user can bruteforce the password …

Aug 7, 2024
CVE-2024-6707
8.8 HIGH

Attacker controlled files can be uploaded to arbitrary locations on the web server's filesystem by abusing a path traversal vulnerability.

Aug 7, 2024
CVE-2024-6706
6.1 MEDIUM

Attackers can craft a malicious prompt that coerces the language model into executing arbitrary JavaScript in the context of the web page.

Aug 7, 2024
CVE-2024-41912
9.8 CRITICAL

A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware flaw does not properly implement access controls.

Aug 7, 2024
CVE-2024-41239
4.8 MEDIUM

A Stored Cross Site Scripting (XSS) vulnerability was found in "/smsa/add_class_submit.php" in Responsive School Management System v3.2.0, which allows remote attackers to execute arbitrary code …

Aug 7, 2024
CVE-2024-41237
9.8 CRITICAL

A SQL injection vulnerability in /smsa/teacher_login.php in Kashipara Responsive School Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "username" parameter.

Aug 7, 2024
CVE-2024-41242
6.1 MEDIUM

A Reflected Cross Site Scripting (XSS) vulnerability was found in /smsa/student_login.php in Kashipara Responsive School Management System v3.2.0, which allows remote attackers to execute arbitrary …

Aug 7, 2024
CVE-2024-41241
6.1 MEDIUM

A Reflected Cross Site Scripting (XSS) vulnerability was found in " /smsa/admin_login.php" in Kashipara Responsive School Management System v3.2.0, which allows remote attackers to execute …

Aug 7, 2024
CVE-2024-41240
6.1 MEDIUM

A Reflected Cross Site Scripting (XSS) vulnerability was found in " /smsa/teacher_login.php" in Kashipara Responsive School Management System v3.2.0, which allows remote attackers to execute …

Aug 7, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.