CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-43112
6.1 MEDIUM

Long pressing on a download link could potentially provide a means for cross-site scripting This vulnerability affects Firefox for iOS < 129.

Aug 6, 2024
CVE-2024-43111
6.1 MEDIUM

Long pressing on a download link could potentially allow Javascript commands to be executed within the browser This vulnerability affects Firefox for iOS < 129.

Aug 6, 2024
CVE-2024-41616
9.8 CRITICAL

D-Link DIR-300 REVA FIRMWARE v1.06B05_WW contains hardcoded credentials in the Telnet service.

Aug 6, 2024
CVE-2024-41333
6.1 MEDIUM

A reflected cross-site scripting (XSS) vulnerability in Phpgurukul Tourism Management System v2.0 allows attackers to execute arbitrary code in the context of a user's browser …

Aug 6, 2024
CVE-2024-39751
4.3 MEDIUM

IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. …

Aug 6, 2024
CVE-2024-39228
9.8 CRITICAL

GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S1300 v4.3.13, and XE3000/X3000 v4.4 were discovered to contain a shell injection vulnerability via the …

Aug 6, 2024
CVE-2024-39226
9.8 CRITICAL

GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S1300 v4.3.13, and XE3000/X3000 v4.4 were discovered to contain a vulnerability can be exploited to …

Aug 6, 2024
CVE-2024-39225
9.8 CRITICAL

GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S1300 v4.3.13, and XE3000/X3000 v4.4 were discovered to contain a remote code execution (RCE) vulnerability.

Aug 6, 2024
CVE-2024-23483
7.0 HIGH

An Improper Input Validation vulnerability in Zscaler Client Connector on MacOS allows OS Command Injection. This issue affects Zscaler Client Connector on MacOS <4.2.

Aug 6, 2024
CVE-2024-23464
7.2 HIGH

In certain cases, Zscaler Internet Access (ZIA) can be disabled by PowerShell commands with admin rights. This affects Zscaler Client Connector on Windows <4.2.1

Aug 6, 2024
CVE-2024-23460
6.4 MEDIUM

The Zscaler Updater process does not validate the digital signature of the installer before execution, allowing arbitrary code to be locally executed. This affects Zscaler …

Aug 6, 2024
CVE-2024-23458
7.3 HIGH

While copying individual autoupdater log files, reparse point check was missing which could result into crafted attacks, potentially leading to a local privilege escalation. This …

Aug 6, 2024
CVE-2024-23456
7.8 HIGH

Anti-tampering can be disabled under certain conditions without signature validation. This affects Zscaler Client Connector <4.2.0.190 with anti-tampering enabled.

Aug 6, 2024
CVE-2023-28806
5.7 MEDIUM

An Improper Validation of signature in Zscaler Client Connector on Windows allows an authenticated user to disable anti-tampering. This issue affects Client Connector on Windows …

Aug 6, 2024
CVE-2024-7552
6.3 MEDIUM

A vulnerability was found in DataGear up to 5.0.0. It has been declared as critical. Affected by this vulnerability is the function evaluateVariableExpression of the …

Aug 6, 2024
CVE-2024-36424
5.5 MEDIUM

K7RKScan.sys in K7 Ultimate Security before 17.0.2019 allows local users to cause a denial of service (BSOD) because of a NULL pointer dereference.

Aug 6, 2024
CVE-2024-41913
8.8 HIGH

A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware flaw does not properly sanitize User input.

Aug 6, 2024
CVE-2024-41911
5.4 MEDIUM

A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The flaw does not properly neutralize input during a …

Aug 6, 2024
CVE-2024-41910
6.1 MEDIUM

A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware contained multiple XSS vulnerabilities in the version …

Aug 6, 2024
CVE-2024-41226
7.8 HIGH

A CSV injection vulnerability in Automation Anywhere Automation 360 version 21094 allows attackers to execute arbitrary code via a crafted payload. NOTE: Automation Anywhere disputes …

Aug 6, 2024
CVE-2024-40101
6.1 MEDIUM

A Reflected Cross-site scripting (XSS) vulnerability exists in '/search' in microweber 2.0.15 and earlier allowing unauthenticated remote attackers to inject arbitrary web script or HTML …

Aug 6, 2024
CVE-2024-33897
9.1 CRITICAL

A compromised HMS Networks Cosy+ device could be used to request a Certificate Signing Request from Talk2m for another device, resulting in an availability issue. …

Aug 6, 2024
CVE-2024-30170
9.1 CRITICAL

PrivX before 34.0 allows data exfiltration and denial of service via the REST API. This is fixed in minor versions 33.1, 32.3, 31.3, and later, …

Aug 6, 2024
CVE-2023-40819
6.1 MEDIUM

ID4Portais in version < V.2022.837.002a returns message parameter unsanitized in the response, resulting in a HTML Injection vulnerability.

Aug 6, 2024
CVE-2024-7551
2.7 LOW

A vulnerability was found in juzaweb CMS up to 3.4.2. It has been classified as problematic. Affected is an unknown function of the file /admin-cp/theme/editor/default …

Aug 6, 2024
CVE-2024-7531
6.5 MEDIUM

Calling `PK11_Encrypt()` in NSS using CKM_CHACHA20 and the same buffer for input and output can result in plaintext on an Intel Sandy Bridge processor. In …

Aug 6, 2024
CVE-2024-7530
8.8 HIGH

Incorrect garbage collection interaction could have led to a use-after-free. This vulnerability affects Firefox < 129.

Aug 6, 2024
CVE-2024-7529
6.5 MEDIUM

The date picker could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. This vulnerability …

Aug 6, 2024
CVE-2024-7528
8.8 HIGH

Incorrect garbage collection interaction in IndexedDB could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < …

Aug 6, 2024
CVE-2024-7527
8.8 HIGH

Unexpected marking work at the start of sweeping could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox …

Aug 6, 2024
CVE-2024-7526
6.5 MEDIUM

ANGLE failed to initialize parameters which lead to reading from uninitialized memory. This could be leveraged to leak sensitive data from memory. This vulnerability affects …

Aug 6, 2024
CVE-2024-7525
8.1 HIGH

It was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and modify the response body …

Aug 6, 2024
CVE-2024-7524
6.1 MEDIUM

Firefox adds web-compatibility shims in place of some tracking scripts blocked by Enhanced Tracking Protection. On a site protected by Content Security Policy in "strict-dynamic" …

Aug 6, 2024
CVE-2024-7523
8.1 HIGH

A select option could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. *This issue …

Aug 6, 2024
CVE-2024-7522
8.8 HIGH

Editor code failed to check an attribute value. This could have led to an out-of-bounds read. This vulnerability affects Firefox < 129, Firefox ESR < …

Aug 6, 2024
CVE-2024-7521
8.8 HIGH

Incomplete WebAssembly exception handing could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird …

Aug 6, 2024
CVE-2024-7520
8.8 HIGH

A type confusion bug in WebAssembly could be leveraged by an attacker to potentially achieve code execution. This vulnerability affects Firefox < 129, Firefox ESR …

Aug 6, 2024
CVE-2024-7519
9.6 CRITICAL

Insufficient checks when processing graphics shared memory could have led to memory corruption. This could be leveraged by an attacker to perform a sandbox escape. …

Aug 6, 2024
CVE-2024-7518
6.5 MEDIUM

Select options could obscure the fullscreen notification dialog. This could be used by a malicious site to perform a spoofing attack. This vulnerability affects Firefox …

Aug 6, 2024
CVE-2024-6359
6.4 MEDIUM

Privilege escalation vulnerability identified in OpenText ArcSight Intelligence.

Aug 6, 2024
CVE-2024-6358
6.3 MEDIUM

Incorrect Authorization vulnerability identified in OpenText ArcSight Intelligence.

Aug 6, 2024
CVE-2024-6357
6.3 MEDIUM

Insecure Direct Object Reference vulnerability identified in OpenText ArcSight Intelligence.

Aug 6, 2024
CVE-2024-43114
7.5 HIGH

In JetBrains TeamCity before 2024.07.1 possible privilege escalation due to incorrect directory permissions

Aug 6, 2024
CVE-2024-33994
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a …

Aug 6, 2024
CVE-2024-33993
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a …

Aug 6, 2024
CVE-2024-33992
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to …

Aug 6, 2024
CVE-2024-33991
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to …

Aug 6, 2024
CVE-2024-33990
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted javascript payload …

Aug 6, 2024
CVE-2024-33989
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted javascript payload …

Aug 6, 2024
CVE-2024-33988
7.1 HIGH

Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL …

Aug 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.