CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-4188

Unprotected Transport of Credentials vulnerability in OpenText™ Documentum™ Server could allow Credential Stuffing.This issue affects Documentum™ Server: from 16.7 through 23.4.

Jul 30, 2024
CVE-2024-41109
6.3 MEDIUM

Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. Navigating to `/admin/index/statistics` with a logged in Pimcore user exposes information about the Pimcore …

Jul 30, 2024
CVE-2024-39320
6.1 MEDIUM

Discourse is an open source discussion platform. Prior to 3.2.5 and 3.3.0.beta5, the vulnerability allows an attacker to inject iframes from any domain, bypassing the …

Jul 30, 2024
CVE-2024-37299
4.9 MEDIUM

Discourse is an open source discussion platform. Prior to 3.2.5 and 3.3.0.beta5, crafting requests to submit very long tag group names can reduce the availability …

Jul 30, 2024
CVE-2024-37165
6.3 MEDIUM

Discourse is an open source discussion platform. Prior to 3.2.3 and 3.3.0.beta3, improperly sanitized Onebox data could lead to an XSS vulnerability in some situations. …

Jul 30, 2024
CVE-2024-38909
9.8 CRITICAL

Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrary attacker to expose …

Jul 30, 2024
CVE-2024-23091
7.5 HIGH

Weak password hashing using MD5 in funzioni.php in HotelDruid before 1.32 allows an attacker to obtain plaintext passwords from hash values.

Jul 30, 2024
CVE-2024-6699
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mikafon Electronic Inc. Mikafon MA7 allows SQL Injection.This issue affects Mikafon …

Jul 30, 2024
CVE-2024-7127
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation vulnerability in Stackposts Social Marketing Tool allows Cross-site Scripting (XSS) attack. By submitting the payload in the …

Jul 30, 2024
CVE-2024-41702
9.8 CRITICAL

SiberianCMS - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Jul 30, 2024
CVE-2024-41701
5.3 MEDIUM

AccuPOS - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Jul 30, 2024
CVE-2024-7226
4.3 MEDIUM

A vulnerability was found in SourceCodester Medicine Tracker System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /classes/Users.php?f=save_user …

Jul 30, 2024
CVE-2024-7225
3.5 LOW

A vulnerability was found in SourceCodester Insurance Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /Script/admin/core/update_policy …

Jul 30, 2024
CVE-2024-41924
7.2 HIGH

Acceptance of extraneous untrusted data with trusted data vulnerability exists in EC-CUBE 4 series. If this vulnerability is exploited, an attacker who obtained the administrative …

Jul 30, 2024
CVE-2024-41696
7.5 HIGH

Priority PRI WEB Portal Add-On for Priority ERP on prem - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Jul 30, 2024
CVE-2024-41695
7.5 HIGH

Cybonet - CWE-22: Improper Limitation of a Pathname to a Restricted Directory

Jul 30, 2024
CVE-2024-41694
5.3 MEDIUM

Cybonet - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Jul 30, 2024
CVE-2024-41693
6.1 MEDIUM

Mashov - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

Jul 30, 2024
CVE-2024-41141
6.1 MEDIUM

Stored cross-site scripting vulnerability exists in EC-CUBE Web API Plugin. When there are multiple users using OAuth Management feature and one of them inputs some …

Jul 30, 2024
CVE-2024-40895
6.4 MEDIUM

FFRI AMC versions 3.4.0 to 3.5.3 and some OEM products that implement/bundle FFRI AMC versions 3.4.0 to 3.5.3 allow a remote unauthenticated attacker to execute …

Jul 30, 2024
CVE-2024-38432
5.5 MEDIUM

Matrix Tafnit v8 - CWE-646: Reliance on File Name or Extension of Externally-Supplied File

Jul 30, 2024
CVE-2024-38431
5.3 MEDIUM

Matrix Tafnit v8 - CWE-204: Observable Response Discrepancy

Jul 30, 2024
CVE-2024-38430
5.4 MEDIUM

Matrix - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Jul 30, 2024
CVE-2024-38429
7.5 HIGH

Matrix Tafnit v8 - CWE-552: Files or Directories Accessible to External Parties

Jul 30, 2024
CVE-2023-48396
9.1 CRITICAL

Web Authentication vulnerability in Apache SeaTunnel. Since the jwt key is hardcoded in the application, an attacker can forge any token to log in any …

Jul 30, 2024
CVE-2024-7224
6.3 MEDIUM

A vulnerability was found in SourceCodester Lot Reservation Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Jul 30, 2024
CVE-2024-7223
6.3 MEDIUM

A vulnerability has been found in SourceCodester Lot Reservation Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Jul 30, 2024
CVE-2024-42231
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: zoned: fix calc_available_free_space() for zoned mode calc_available_free_space() returns the total size of metadata (or …

Jul 30, 2024
CVE-2024-42230
4.4 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: powerpc/pseries: Fix scv instruction crash with kexec kexec on pseries disables AIL (reloc_on_exc), required for …

Jul 30, 2024
CVE-2024-42229
4.1 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: crypto: aead,cipher - zeroize key buffer after use I.G 9.7.B for FIPS 140-3 specifies that …

Jul 30, 2024
CVE-2024-42228
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Using uninitialized value *size when calling amdgpu_vce_cs_reloc Initialize the size before calling amdgpu_vce_cs_reloc, such …

Jul 30, 2024
CVE-2024-42227
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix overlapping copy within dml_core_mode_programming [WHY] &mode_lib->mp.Watermark and &locals->Watermark are the same address. memcpy …

Jul 30, 2024
CVE-2024-42226

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 30, 2024
CVE-2024-42225
7.5 HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: replace skb_put with skb_put_zero Avoid potentially reusing uninitialized data

Jul 30, 2024
CVE-2024-42224
6.1 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: dsa: mv88e6xxx: Correct check for empty list Since commit a3c53be55c95 ("net: dsa: mv88e6xxx: Support …

Jul 30, 2024
CVE-2024-42223
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: dvb-frontends: tda10048: Fix integer overflow state->xtal_hz can be up to 16M, so it can …

Jul 30, 2024
CVE-2024-42162
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: gve: Account for stopped queues when reading NIC stats We now account for the fact …

Jul 30, 2024
CVE-2024-42161
6.3 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: Avoid uninitialized value in BPF_CORE_READ_BITFIELD [Changes from V1: - Use a default branch in …

Jul 30, 2024
CVE-2024-42160
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: f2fs: check validation of fault attrs in f2fs_build_fault_attr() - It missed to check validation of …

Jul 30, 2024
CVE-2024-42159
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: scsi: mpi3mr: Sanitise num_phys Information is stored in mr_sas_port->phy_mask, values larger then size of this …

Jul 30, 2024
CVE-2024-42158
4.1 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Use kfree_sensitive() to fix Coccinelle warnings Replace memzero_explicit() and kfree() with kfree_sensitive() to fix …

Jul 30, 2024
CVE-2024-42157
4.1 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Wipe sensitive data on failure Wipe sensitive data from stack also if the copy_to_user() …

Jul 30, 2024
CVE-2024-42156
4.1 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Wipe copies of clear-key structures on failure Wipe all sensitive data from stack for …

Jul 30, 2024
CVE-2024-42155
1.9 LOW

In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Wipe copies of protected- and secure-keys Although the clear-key of neither protected- nor secure-keys …

Jul 30, 2024
CVE-2024-42154
4.4 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tcp_metrics: validate source addr length I don't see anything checking that TCP_METRICS_ATTR_SADDR_IPV4 is at least …

Jul 30, 2024
CVE-2024-42153
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: i2c: pnx: Fix potential deadlock warning from del_timer_sync() call in isr When del_timer_sync() is called …

Jul 30, 2024
CVE-2024-42152
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nvmet: fix a possible leak when destroy a ctrl during qp establishment In nvmet_sq_destroy we …

Jul 30, 2024
CVE-2024-42151
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bpf: mark bpf_dummy_struct_ops.test_1 parameter as nullable Test case dummy_st_ops/dummy_init_ret_value passes NULL as the first parameter …

Jul 30, 2024
CVE-2024-42150
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: txgbe: remove separate irq request for MSI and INTx When using MSI or INTx …

Jul 30, 2024
CVE-2024-42149
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fs: don't misleadingly warn during thaw operations The block device may have been frozen before …

Jul 30, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.