CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-7585
8.8 HIGH

A vulnerability has been found in Tenda i22 1.0.0.3(4687) and classified as critical. Affected by this vulnerability is the function formApPortalWebAuth of the file /goform/apPortalAuth. …

Aug 7, 2024
CVE-2024-7584
8.8 HIGH

A vulnerability, which was classified as critical, was found in Tenda i22 1.0.0.3(4687). Affected is the function formApPortalPhoneAuth of the file /goform/apPortalPhoneAuth. The manipulation of …

Aug 7, 2024
CVE-2024-7143
8.3 HIGH

A flaw was found in the Pulp package. When a role-based access control (RBAC) object in Pulp is set to assign permissions on its creation, …

Aug 7, 2024
CVE-2024-7061
5.5 MEDIUM

Okta Verify for Windows is vulnerable to privilege escalation through DLL hijacking. The vulnerability is fixed in Okta Verify for Windows version 5.0.2. To remediate …

Aug 7, 2024
CVE-2024-41250
5.3 MEDIUM

An Incorrect Access Control vulnerability was found in /smsa/view_students.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view STUDENT details.

Aug 7, 2024
CVE-2024-41245
5.3 MEDIUM

An Incorrect Access Control vulnerability was found in /smsa/view_teachers.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view TEACHER details.

Aug 7, 2024
CVE-2024-41244
5.3 MEDIUM

An Incorrect Access Control vulnerability was found in /smsa/view_class.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view CLASS details.

Aug 7, 2024
CVE-2024-41243
5.3 MEDIUM

An Incorrect Access Control vulnerability was found in /smsa/view_marks.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view MARKS details.

Aug 7, 2024
CVE-2024-20479
4.8 MEDIUM

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct an XSS attack against a user of …

Aug 7, 2024
CVE-2024-20454
9.8 CRITICAL

Multiple vulnerabilities in the web-based management interface of Cisco Small Business SPA300 Series IP Phones and Cisco Small Business SPA500 Series IP Phones could allow …

Aug 7, 2024
CVE-2024-20451
7.5 HIGH

Multiple vulnerabilities in the web-based management interface of Cisco Small Business SPA300 Series IP Phones and Cisco Small Business SPA500 Series IP Phones could allow …

Aug 7, 2024
CVE-2024-20450
9.8 CRITICAL

Multiple vulnerabilities in the web-based management interface of Cisco Small Business SPA300 Series IP Phones and Cisco Small Business SPA500 Series IP Phones could allow …

Aug 7, 2024
CVE-2024-20443
5.4 MEDIUM

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct an XSS attack against a user of …

Aug 7, 2024
CVE-2024-7583
8.8 HIGH

A vulnerability, which was classified as critical, has been found in Tenda i22 1.0.0.3(4687). This issue affects the function formApPortalOneKeyAuth of the file /goform/apPortalOneKeyAuth. The …

Aug 7, 2024
CVE-2024-7582
8.8 HIGH

A vulnerability classified as critical was found in Tenda i22 1.0.0.3(4687). This vulnerability affects the function formApPortalAccessCodeAuth of the file /goform/apPortalAccessCodeAuth. The manipulation of the …

Aug 7, 2024
CVE-2024-42250
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: cachefiles: add missing lock protection when polling Add missing lock protection in poll routine when …

Aug 7, 2024
CVE-2024-42249
3.3 LOW

In the Linux kernel, the following vulnerability has been resolved: spi: don't unoptimize message in spi_async() Calling spi_maybe_unoptimize_message() in spi_async() is wrong because the message …

Aug 7, 2024
CVE-2024-42248
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tty: serial: ma35d1: Add a NULL check for of_node The pdev->dev.of_node can be NULL if …

Aug 7, 2024
CVE-2024-42247
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: wireguard: allowedips: avoid unaligned 64-bit memory accesses On the parisc platform, the kernel issues kernel …

Aug 7, 2024
CVE-2024-42246
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net, sunrpc: Remap EPERM in case of connection failure in xs_tcp_setup_socket When using a BPF …

Aug 7, 2024
CVE-2024-42245
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Revert "sched/fair: Make sure to try to detach at least one movable task" This reverts …

Aug 7, 2024
CVE-2024-42244
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: USB: serial: mos7840: fix crash on resume Since commit c49cfa917025 ("USB: serial: use generic method …

Aug 7, 2024
CVE-2024-42243
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/filemap: make MAX_PAGECACHE_ORDER acceptable to xarray Patch series "mm/filemap: Limit page cache size to that …

Aug 7, 2024
CVE-2024-42242
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mmc: sdhci: Fix max_seg_size for 64KiB PAGE_SIZE blk_queue_max_segment_size() ensured: if (max_size < PAGE_SIZE) max_size = …

Aug 7, 2024
CVE-2024-42241
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/shmem: disable PMD-sized page cache if needed For shmem files, it's possible that PMD-sized page …

Aug 7, 2024
CVE-2024-42240
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: x86/bhi: Avoid warning in #DB handler due to BHI mitigation When BHI mitigation is enabled, …

Aug 7, 2024
CVE-2024-42239
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: Fail bpf_timer_cancel when callback is being cancelled Given a schedule: timer1 cb timer2 cb …

Aug 7, 2024
CVE-2024-42238
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: firmware: cs_dsp: Return error if block header overflows file Return an error from cs_dsp_power_up() if …

Aug 7, 2024
CVE-2024-42237
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: firmware: cs_dsp: Validate payload length before processing block Move the payload length check in cs_dsp_load() …

Aug 7, 2024
CVE-2024-42236
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: configfs: Prevent OOB read/write in usb_string_copy() Userspace provided string 's' could trivially have …

Aug 7, 2024
CVE-2024-42235
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: s390/mm: Add NULL pointer check to crst_table_free() base_crst_free() crst_table_free() used to work with NULL pointers …

Aug 7, 2024
CVE-2024-42234
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm: fix crashes from deferred split racing folio migration Even on 6.10-rc6, I've been seeing …

Aug 7, 2024
CVE-2024-42233
3.3 LOW

In the Linux kernel, the following vulnerability has been resolved: filemap: replace pte_offset_map() with pte_offset_map_nolock() The vmf->ptl in filemap_fault_recheck_pte_none() is still set from handle_pte_fault(). But …

Aug 7, 2024
CVE-2024-42232
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: libceph: fix race between delayed_work() and ceph_monc_stop() The way the delayed work is handled in …

Aug 7, 2024
CVE-2024-41432
5.3 MEDIUM

An IP Spoofing vulnerability has been discovered in Likeshop up to 2.5.7.20210811. This issue allows an attacker to replace their real IP address with any …

Aug 7, 2024
CVE-2024-41309
7.8 HIGH

An issue in the Hardware info module of IT Solutions Enjay CRM OS v1.0 allows attackers to escape the restricted terminal environment and gain root-level …

Aug 7, 2024
CVE-2024-41308
7.8 HIGH

An issue in the Ping feature of IT Solutions Enjay CRM OS v1.0 allows attackers to escape the restricted terminal environment and gain root-level privileges …

Aug 7, 2024
CVE-2024-41252
6.5 MEDIUM

An Incorrect Access Control vulnerability was found in /smsa/admin_student_register_approval.php and /smsa/admin_student_register_approval_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view …

Aug 7, 2024
CVE-2024-41251
6.5 MEDIUM

An Incorrect Access Control vulnerability was found in /smsa/admin_teacher_register_approval.php and /smsa/admin_teacher_register_approval_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view …

Aug 7, 2024
CVE-2024-41249
5.3 MEDIUM

An Incorrect Access Control vulnerability was found in /smsa/view_subject.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view SUBJECT details.

Aug 7, 2024
CVE-2024-41248
5.3 MEDIUM

An Incorrect Access Control vulnerability was found in /smsa/add_subject.php and /smsa/add_subject_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to add …

Aug 7, 2024
CVE-2024-41247
5.3 MEDIUM

An Incorrect Access Control vulnerability was found in /smsa/add_class.php and /smsa/add_class_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to add …

Aug 7, 2024
CVE-2024-41246
5.3 MEDIUM

An Incorrect Access Control vulnerability was found in /smsa/admin_dashboard.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view administrator dashboard.

Aug 7, 2024
CVE-2024-34480
9.8 CRITICAL

SourceCodester Computer Laboratory Management System 1.0 allows admin/category/view_category.php id SQL Injection.

Aug 7, 2024
CVE-2024-34479
9.8 CRITICAL

SourceCodester Computer Laboratory Management System 1.0 allows classes/Master.php id SQL Injection.

Aug 7, 2024
CVE-2024-7581
8.8 HIGH

A vulnerability classified as critical has been found in Tenda A301 15.13.08.12. This affects the function formWifiBasicSet of the file /goform/WifiBasicSet. The manipulation of the …

Aug 7, 2024
CVE-2024-7580
6.3 MEDIUM

A vulnerability was found in Alien Technology ALR-F800 up to 19.10.24.00. It has been rated as critical. Affected by this issue is some unknown functionality …

Aug 7, 2024
CVE-2024-42005
7.3 HIGH

An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. QuerySet.values() and values_list() methods on models with a JSONField are subject to …

Aug 7, 2024
CVE-2024-41991
7.5 HIGH

An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize and urlizetrunc template filters, and the AdminURLFieldWidget widget, are subject …

Aug 7, 2024
CVE-2024-41990
7.5 HIGH

An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize() and urlizetrunc() template filters are subject to a potential denial-of-service …

Aug 7, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.