CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-41989
7.5 HIGH

An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The floatformat template filter is subject to significant memory consumption when given …

Aug 7, 2024
CVE-2024-7579
6.3 MEDIUM

A vulnerability was found in Alien Technology ALR-F800 up to 19.10.24.00. It has been declared as critical. Affected by this vulnerability is the function popen …

Aug 7, 2024
CVE-2024-43199
7.8 HIGH

Nagios NDOUtils before 2.1.4 allows privilege escalation from nagios to root because certain executable files are owned by the nagios user.

Aug 7, 2024
CVE-2024-43045
6.3 MEDIUM

Jenkins 2.470 and earlier, LTS 2.452.3 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to access …

Aug 7, 2024
CVE-2024-43044
8.8 HIGH

Jenkins 2.470 and earlier, LTS 2.452.3 and earlier allows agent processes to read arbitrary files from the Jenkins controller file system by using the `ClassLoaderProxy#fetchJar` …

Aug 7, 2024
CVE-2024-7578
7.3 HIGH

A vulnerability was found in Alien Technology ALR-F800 up to 19.10.24.00. It has been classified as critical. Affected is an unknown function of the file …

Aug 7, 2024
CVE-2024-7355
4.9 MEDIUM

The Organization chart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title_input’ and 'node_description' parameter in all versions up to, and including, …

Aug 7, 2024
CVE-2024-7353
5.4 MEDIUM

The Accept Stripe Payments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's accept_stripe_payment_ng shortcode in all versions up to, and including, …

Aug 7, 2024
CVE-2024-7267
6.5 MEDIUM

Exposure of Sensitive Information vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP allows logged-in user to retrieve information about IP …

Aug 7, 2024
CVE-2024-7266
4.3 MEDIUM

Incorrect User Management vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP allows logged-in user to list all users in the …

Aug 7, 2024
CVE-2024-7265
8.8 HIGH

Incorrect User Management vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP allows logged-in user to change the password of any …

Aug 7, 2024
CVE-2024-6522
8.5 HIGH

The Modern Events Calendar plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 7.12.1 via the 'mec_fes_form' AJAX …

Aug 7, 2024
CVE-2024-7553
7.3 HIGH

Incorrect validation of files loaded from a local untrusted directory may allow local privilege escalation if the underlying operating systems is Windows. This may result …

Aug 7, 2024
CVE-2024-5290
8.8 HIGH

An issue was discovered in Ubuntu wpa_supplicant that resulted in loading of arbitrary shared objects, which allows a local unprivileged attacker to escalate privileges to …

Aug 7, 2024
CVE-2024-42222
4.3 MEDIUM

In Apache CloudStack 4.19.1.0, a regression in the network listing API allows unauthorised list access of network details for domain admin and normal user accounts. …

Aug 7, 2024
CVE-2024-42062
7.2 HIGH

CloudStack account-users by default use username and password based authentication for API and UI access. Account-users can generate and register randomised API and secret keys …

Aug 7, 2024
CVE-2024-6494
6.1 MEDIUM

The WordPress File Upload WordPress plugin before 4.24.8 does not properly sanitize and escape certain parameters, which could allow unauthenticated users to execute stored cross-site …

Aug 7, 2024
CVE-2024-3973
4.8 MEDIUM

The House Manager WordPress plugin through 1.0.8.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Aug 7, 2024
CVE-2024-37403
5.5 MEDIUM

Ivanti Docs@Work for Android, before 2.26.0 is affected by the 'Dirty Stream' vulnerability. The application fails to properly sanitize file names, resulting in a path …

Aug 7, 2024
CVE-2024-36132
7.5 HIGH

Insufficient verification of authentication controls in EPMM prior to 12.1.0.1 allows a remote attacker to bypass authentication and access sensitive resources.

Aug 7, 2024
CVE-2024-36131
8.8 HIGH

An insecure deserialization vulnerability in web component of EPMM prior to 12.1.0.1 allows an authenticated remote attacker to execute arbitrary commands on the underlying operating …

Aug 7, 2024
CVE-2024-36130
9.8 CRITICAL

An insufficient authorization vulnerability in web component of EPMM prior to 12.1.0.1 allows an unauthorized attacker within the network to execute arbitrary commands on the …

Aug 7, 2024
CVE-2024-34788
6.5 MEDIUM

An improper authentication vulnerability in web component of EPMM prior to 12.1.0.1 allows a remote malicious user to access potentially sensitive information

Aug 7, 2024
CVE-2024-34636
4.0 MEDIUM

Use of implicit intent for sensitive communication in Samsung Email prior to version 6.1.94.2 allows local attackers to get sensitive information.

Aug 7, 2024
CVE-2024-34635
4.0 MEDIUM

Out-of-bounds read in parsing textbox object in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.

Aug 7, 2024
CVE-2024-34634
4.0 MEDIUM

Out-of-bounds read in parsing connected object list in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.

Aug 7, 2024
CVE-2024-34633
4.0 MEDIUM

Out-of-bounds read in parsing object header in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.

Aug 7, 2024
CVE-2024-34632
4.0 MEDIUM

Out-of-bounds read in uuid parsing in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.

Aug 7, 2024
CVE-2024-34631
5.5 MEDIUM

Out-of-bounds read in applying new binary in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

Aug 7, 2024
CVE-2024-34630
5.5 MEDIUM

Out-of-bounds read in applying own binary with textbox in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

Aug 7, 2024
CVE-2024-34629
5.5 MEDIUM

Out-of-bounds read in applying binary with text common object in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

Aug 7, 2024
CVE-2024-34628
5.5 MEDIUM

Out-of-bounds read in applying binary with path in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

Aug 7, 2024
CVE-2024-34627
5.5 MEDIUM

Out-of-bounds read in parsing implemention in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

Aug 7, 2024
CVE-2024-34626
5.5 MEDIUM

Out-of-bounds read in applying own binary in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

Aug 7, 2024
CVE-2024-34625
5.5 MEDIUM

Out-of-bounds read in applying connection point in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

Aug 7, 2024
CVE-2024-34624
5.5 MEDIUM

Out-of-bounds read in applying paragraphs in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

Aug 7, 2024
CVE-2024-34623
7.8 HIGH

Out-of-bounds write in applying connected information in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially execute arbitrary code with Samsung Notes privilege.

Aug 7, 2024
CVE-2024-34622
7.8 HIGH

Out-of-bounds write in appending paragraph in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially execute arbitrary code with Samsung Notes privilege.

Aug 7, 2024
CVE-2024-34621
5.5 MEDIUM

Out-of-bounds read in applying binary with data in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

Aug 7, 2024
CVE-2024-34620
8.4 HIGH

Improper privilege management in SumeNNService prior to SMR Aug-2024 Release 1 allows local attackers to start privileged service.

Aug 7, 2024
CVE-2024-34619
7.5 HIGH

Improper input validation in librtp.so prior to SMR Aug-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required …

Aug 7, 2024
CVE-2024-34618
4.0 MEDIUM

Improper access control in System property prior to SMR Aug-2024 Release 1 allows local attackers to access cell related information.

Aug 7, 2024
CVE-2024-34617
4.0 MEDIUM

Improper handling of insufficient permission in Telephony prior to SMR Aug-2024 Release 1 allows local attackers to configure default Message application.

Aug 7, 2024
CVE-2024-34616
5.1 MEDIUM

Improper handling of insufficient permission in KnoxDualDARPolicy prior to SMR Aug-2024 Release 1 allows local attackers to access sensitive data.

Aug 7, 2024
CVE-2024-34615
5.1 MEDIUM

Out-of-bound write in libsmat.so prior to SMR Aug-2024 Release 1 allows local attackers to cause memory corruption.

Aug 7, 2024
CVE-2024-34614
7.3 HIGH

Out-of-bound write in libsmat.so prior to SMR Aug-2024 Release 1 allows local attackers to execute arbitrary code.

Aug 7, 2024
CVE-2024-34613
4.0 MEDIUM

Improper access control in Galaxy Watch prior to SMR Aug-2024 Release 1 allows local attackers to access sensitive information of Galaxy watch.

Aug 7, 2024
CVE-2024-34612
7.3 HIGH

Out-of-bound write in libcodec2secmp4vdec.so prior to SMR Aug-2024 Release 1 allows local attackers to execute arbitrary code.

Aug 7, 2024
CVE-2024-34611
5.1 MEDIUM

Improper access control in KnoxService prior to SMR Aug-2024 Release 1 allows local attackers to get sensitive information.

Aug 7, 2024
CVE-2024-34610
5.1 MEDIUM

Improper access control in ExtControlDeviceService prior to SMR Aug-2024 Release 1 allows local attackers to access protected data.

Aug 7, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.