CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-7252
7.8 HIGH

Comodo Internet Security Pro cmdagent Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Internet …

Jul 29, 2024
CVE-2024-7251
7.8 HIGH

Comodo Internet Security Pro cmdagent Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Internet …

Jul 29, 2024
CVE-2024-7250
7.8 HIGH

Comodo Internet Security Pro cmdagent Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Internet …

Jul 29, 2024
CVE-2024-7249
7.8 HIGH

Comodo Firewall Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Firewall. An attacker must …

Jul 29, 2024
CVE-2024-7248
7.8 HIGH

Comodo Internet Security Pro Directory Traversal Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Internet Security …

Jul 29, 2024
CVE-2024-3219

The “socket” module provides a pure-Python fallback to the socket.socketpair() function for platforms that don’t support AF_UNIX, such as Windows. This pure-Python implementation uses AF_INET …

Jul 29, 2024
CVE-2023-42959
7.0 HIGH

A race condition was addressed with improved state handling. This issue is fixed in macOS Sonoma 14. An app may be able to execute arbitrary …

Jul 29, 2024
CVE-2023-42958
7.8 HIGH

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.4. An app may be able to gain elevated privileges.

Jul 29, 2024
CVE-2023-42957
3.3 LOW

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, watchOS 10. An app …

Jul 29, 2024
CVE-2023-42949
3.3 LOW

This issue was addressed with improved data protection. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, watchOS 10, tvOS 17. …

Jul 29, 2024
CVE-2023-42948
3.3 LOW

This issue was addressed through improved state management. This issue is fixed in macOS Sonoma 14. A Wi-Fi password may not be deleted when activating …

Jul 29, 2024
CVE-2023-42943
5.5 MEDIUM

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma 14. An app may be …

Jul 29, 2024
CVE-2023-42925
3.3 LOW

The issue was addressed with improved restriction of data container access. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. An …

Jul 29, 2024
CVE-2023-42918
6.3 MEDIUM

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14. A sandboxed process may be able to circumvent sandbox …

Jul 29, 2024
CVE-2023-40398
8.8 HIGH

This issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.4, macOS Big Sur 11.7.5, macOS Ventura 13.3, iOS 16.4 and …

Jul 29, 2024
CVE-2023-40396
7.8 HIGH

The issue was addressed with improved memory handling. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, watchOS 10, tvOS 17. …

Jul 29, 2024
CVE-2019-6185

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 29, 2024
CVE-2019-6174

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 29, 2024
CVE-2019-6164

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 29, 2024
CVE-2019-6162

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 29, 2024
CVE-2017-3769

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 29, 2024
CVE-2017-3766

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 29, 2024
CVE-2017-3755

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 29, 2024
CVE-2024-6620
3.5 LOW

Honeywell PC42t, PC42tp, and PC42d Printers, T10.19.020016 to T10.20.060398, contain a cross-site scripting vulnerability. A(n) attacker could potentially inject malicious code which may lead to …

Jul 29, 2024
CVE-2022-4038

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 29, 2024
CVE-2022-48185

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 29, 2024
CVE-2019-19761

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 29, 2024
CVE-2019-19760

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 29, 2024
CVE-2019-19759

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 29, 2024
CVE-2024-6578
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in aimhubio/aim version 3.19.3. The vulnerability arises from the improper neutralization of input during web page generation, specifically …

Jul 29, 2024
CVE-2024-37859
6.1 MEDIUM

Cross Site Scripting vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via the page parameter to php-lfis/admin/index.php.

Jul 29, 2024
CVE-2024-37858
9.8 CRITICAL

SQL Injection vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via the id parameter to php-lfis/admin/categories/manage_category.php.

Jul 29, 2024
CVE-2024-37857
8.8 HIGH

SQL Injection vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via id parameter to php-lfis/admin/categories/view_category.php.

Jul 29, 2024
CVE-2024-37856
5.4 MEDIUM

Cross Site Scripting vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via the first, last, middle name fields …

Jul 29, 2024
CVE-2024-28806
7.5 HIGH

An issue was discovered in Italtel i-MCS NFV 12.1.0-20211215. Remote unauthenticated attackers can upload files at an arbitrary path.

Jul 29, 2024
CVE-2024-28805
9.1 CRITICAL

An issue was discovered in Italtel i-MCS NFV 12.1.0-20211215. There is Incorrect Access Control.

Jul 29, 2024
CVE-2024-28804
7.1 HIGH

An issue was discovered in Italtel i-MCS NFV 12.1.0-20211215. Stored Cross-site scripting (XSS) can occur via POST.

Jul 29, 2024
CVE-2024-6727
5.4 MEDIUM

A flaw in versions of Delphix Data Control Tower (DCT) prior to 19.0.0 results in broken authentication through the enable-scale-testing functionality of the application.

Jul 29, 2024
CVE-2024-6726
8.8 HIGH

Versions of Delphix Engine prior to Release 25.0.0.0 contain a flaw which results in Remote Code Execution (RCE).

Jul 29, 2024
CVE-2024-42098
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: crypto: ecdh - explicitly zeroize private_key private_key is overwritten with the key parameter passed in …

Jul 29, 2024
CVE-2024-42097
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ALSA: emux: improve patch ioctl data validation In load_data(), make the validation of and skipping …

Jul 29, 2024
CVE-2024-42096
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: x86: stop playing stack games in profile_pc() The 'profile_pc()' function is used for timer-based profiling, …

Jul 29, 2024
CVE-2024-42095
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: serial: 8250_omap: Implementation of Errata i2310 As per Errata i2310[0], Erroneous timeout can be triggered, …

Jul 29, 2024
CVE-2024-42094
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: net/iucv: Avoid explicit cpumask var allocation on stack For CONFIG_CPUMASK_OFFSTACK=y kernel, explicit allocation of cpumask …

Jul 29, 2024
CVE-2024-42093
7.3 HIGH

In the Linux kernel, the following vulnerability has been resolved: net/dpaa2: Avoid explicit cpumask var allocation on stack For CONFIG_CPUMASK_OFFSTACK=y kernel, explicit allocation of cpumask …

Jul 29, 2024
CVE-2024-42092
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: gpio: davinci: Validate the obtained number of IRQs Value of pdata->gpio_unbanked is taken from Device …

Jul 29, 2024
CVE-2024-42091
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/xe: Check pat.ops before dumping PAT settings We may leave pat.ops unset when running on …

Jul 29, 2024
CVE-2024-6748
8.3 HIGH

Zohocorp ManageEngine OpManager, OpManager Plus, OpManager MSP and RMM versions 128317 and below are vulnerable to authenticated SQL injection in the URL monitoring.

Jul 29, 2024
CVE-2024-42090
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: pinctrl: fix deadlock in create_pinctrl() when handling -EPROBE_DEFER In create_pinctrl(), pinctrl_maps_mutex is acquired before calling …

Jul 29, 2024
CVE-2024-42089
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ASoC: fsl-asoc-card: set priv->pdev before using it priv->pdev pointer was set after being used in …

Jul 29, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.