CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-41655
7.5 HIGH

TF2 Item Format helps users format TF2 items to the community standards. Versions of `tf2-item-format` since at least `4.2.6` and prior to `5.9.14` are vulnerable …

Jul 23, 2024
CVE-2024-41319
9.8 CRITICAL

TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the cmd parameter in the webcmd function.

Jul 23, 2024
CVE-2024-40060
7.5 HIGH

go-chart v2.1.1 was discovered to contain an infinite loop via the drawCanvas() function.

Jul 23, 2024
CVE-2024-1975
7.5 HIGH

If a server hosts a zone containing a "KEY" Resource Record, or a resolver DNSSEC-validates a "KEY" Resource Record from a DNSSEC-signed domain in cache, …

Jul 23, 2024
CVE-2024-1737
7.5 HIGH

Resolver caches and authoritative zone databases that hold significant numbers of RRs for the same hostname (of any RTYPE) can suffer from degraded performance as …

Jul 23, 2024
CVE-2024-0760
7.5 HIGH

A malicious client can send many DNS messages over TCP, potentially causing the server to become unstable while the attack is in progress. The server …

Jul 23, 2024
CVE-2024-5602
7.8 HIGH

A stack-based buffer overflow vulnerability due to a missing bounds check in the NI I/O Trace Tool may result in arbitrary code execution. Successful exploitation …

Jul 23, 2024
CVE-2024-4081
7.8 HIGH

A memory corruption issue due to an improper length check in NI LabVIEW may disclose information or result in arbitrary code execution. Successful exploitation requires …

Jul 23, 2024
CVE-2024-4080
7.8 HIGH

A memory corruption issue due to an improper length check in LabVIEW tdcore.dll may disclose information or result in arbitrary code execution. Successful exploitation requires …

Jul 23, 2024
CVE-2024-4079
7.8 HIGH

An out of bounds read due to a missing bounds check in LabVIEW may disclose information or result in arbitrary code execution. Successful exploitation requires …

Jul 23, 2024
CVE-2024-41839
3.5 LOW

Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Input Validation vulnerability that could lead to a security feature bypass. A low-privileged …

Jul 23, 2024
CVE-2024-41836
5.5 MEDIUM

InDesign Desktop versions ID18.5.2, ID19.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to an application denial-of-service (DoS) condition. An …

Jul 23, 2024
CVE-2024-34128
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to …

Jul 23, 2024
CVE-2024-7014
8.1 HIGH

EvilVideo vulnerability allows sending malicious apps disguised as videos in Telegram for Android application affecting versions 10.14.4 and older.

Jul 23, 2024
CVE-2024-29070
9.1 CRITICAL

On versions before 2.1.4, session is not invalidated after logout. When the user logged in successfully, the Backend service returns "Authorization" as the front-end authentication …

Jul 23, 2024
CVE-2024-41012
6.3 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: filelock: Remove locks reliably when fcntl/close race is detected When fcntl_setlk() races with close(), it …

Jul 23, 2024
CVE-2024-6420
8.6 HIGH

The Hide My WP Ghost WordPress plugin before 5.2.02 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated …

Jul 23, 2024
CVE-2024-6231
5.9 MEDIUM

The Request a Quote WordPress plugin before 2.4.1 does not sanitise and escape some of its settings, which could allow high privilege users such as …

Jul 23, 2024
CVE-2024-4260
6.5 MEDIUM

The Page Builder Gutenberg Blocks WordPress plugin before 3.1.12 does not prevent users from pinging arbitrary hosts via some of its shortcodes, which could allow …

Jul 23, 2024
CVE-2024-6885
8.1 HIGH

The MaxiBlocks: 2200+ Patterns, 190 Pages, 14.2K Icons & 100 Styles plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path …

Jul 23, 2024
CVE-2024-6828
7.2 HIGH

The Redux Framework plugin for WordPress is vulnerable to unauthenticated JSON file uploads due to missing authorization and capability checks on the Redux_Color_Scheme_Import function in …

Jul 23, 2024
CVE-2024-1575
6.5 MEDIUM

The improper privilege management vulnerability in the Zyxel WBE660S firmware version 6.70(ACGG.3) and earlier versions could allow an authenticated user to escalate privileges and download …

Jul 23, 2024
CVE-2024-6717
7.7 HIGH

HashiCorp Nomad and Nomad Enterprise 1.6.12 up to 1.7.9, and 1.8.1 archive unpacking during migration is vulnerable to path escaping of the allocation directory. This …

Jul 23, 2024
CVE-2024-24507
6.1 MEDIUM

Cross Site Scripting vulnerability in Act-On 2023 allows a remote attacker to execute arbitrary code via the newUser parameter in the login.jsp component.

Jul 22, 2024
CVE-2024-6913
8.8 HIGH

Execution with unnecessary privileges in PerkinElmer ProcessPlus allows an attacker to spawn a remote shell on the windows system.This issue affects ProcessPlus: through 1.11.6507.0.

Jul 22, 2024
CVE-2024-6912
9.8 CRITICAL

Use of hard-coded MSSQL credentials in PerkinElmer ProcessPlus on Windows allows an attacker to login remove on all prone installations.This issue affects ProcessPlus: through 1.11.6507.0.

Jul 22, 2024
CVE-2024-6911
7.5 HIGH

Files on the Windows system are accessible without authentication to external parties due to a local file inclusion in PerkinElmer ProcessPlus.This issue affects ProcessPlus: through …

Jul 22, 2024
CVE-2024-6806
9.8 CRITICAL

The NI VeriStand Gateway is missing authorization checks when an actor attempts to access Project resources. These missing checks may result in remote code execution. …

Jul 22, 2024
CVE-2024-6805
7.5 HIGH

The NI VeriStand Gateway is missing authorization checks when an actor attempts to access File Transfer resources. These missing checks may result in information disclosure …

Jul 22, 2024
CVE-2024-6794
9.8 CRITICAL

A deserialization of untrusted data vulnerability exists in NI VeriStand Waveform Streaming Server that may result in remote code execution. Successful exploitation requires an attacker …

Jul 22, 2024
CVE-2024-6793
9.8 CRITICAL

A deserialization of untrusted data vulnerability exists in NI VeriStand DataLogging Server that may result in remote code execution. Successful exploitation requires an attacker to …

Jul 22, 2024
CVE-2024-6791
7.8 HIGH

A directory path traversal vulnerability exists when loading a vsmodel file in NI VeriStand that may result in remote code execution. Successful exploitation requires an …

Jul 22, 2024
CVE-2024-40502
9.8 CRITICAL

SQL injection vulnerability in Hospital Management System Project in ASP.Net MVC 1 allows aremote attacker to execute arbitrary code via the btn_login_b_Click function of the …

Jul 22, 2024
CVE-2024-6675
7.8 HIGH

A deserialization of untrusted data vulnerability exists in NI VeriStand that may result in remote code execution. Successful exploitation requires an attacker to get a …

Jul 22, 2024
CVE-2024-6638
5.5 MEDIUM

An integer overflow vulnerability due to improper input validation when reading TDMS files in LabVIEW may result in an infinite loop. Successful exploitation requires an …

Jul 22, 2024
CVE-2024-6122
5.5 MEDIUM

An incorrect permission in the installation directory for the shared NI SystemLink Server KeyValueDatabase service may result in information disclosure via local access. This affects …

Jul 22, 2024
CVE-2024-6121
7.8 HIGH

An out-of-date version of Redis shipped with NI SystemLink Server is susceptible to multiple vulnerabilities, including CVE-2022-24834. This affects NI SystemLink Server 2024 Q1 and …

Jul 22, 2024
CVE-2024-39250
9.8 CRITICAL

EfroTech Timetrax v8.3 was discovered to contain an unauthenticated SQL injection vulnerability via the q parameter in the search web interface.

Jul 22, 2024
CVE-2024-34329
8.4 HIGH

Insecure permissions in Entrust Datacard XPS Card Printer Driver 8.5 and earlier without the dxp1-patch-E24-004 patch allows unauthenticated attackers to execute arbitrary code as SYSTEM …

Jul 22, 2024
CVE-2024-41880
5.3 MEDIUM

In veilid-core in Veilid before 0.3.4, the protocol's ping function can be misused in a way that decreases the effectiveness of safety and private routes.

Jul 22, 2024
CVE-2024-40075
4.3 MEDIUM

Laravel v11.x was discovered to contain an XML External Entity (XXE) vulnerability.

Jul 22, 2024
CVE-2024-38944
9.8 CRITICAL

An issue in Intelight X-1L Traffic controller Maxtime v.1.9.6 allows a remote attacker to execute arbitrary code via the /cgi-bin/generateForm.cgi?formID=142 component.

Jul 22, 2024
CVE-2024-37380
5.3 MEDIUM

A misconfiguration on UniFi U6+ Access Point could cause an incorrect VLAN traffic forwarding to APs meshed to UniFi U6+ Access Point. Affected Products: UniFi …

Jul 22, 2024
CVE-2024-41130
5.4 MEDIUM

llama.cpp provides LLM inference in C/C++. Prior to b3427, llama.cpp contains a null pointer dereference in gguf_init_from_file. This vulnerability is fixed in b3427.

Jul 22, 2024
CVE-2024-40634
7.5 HIGH

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. This report details a security vulnerability in Argo CD, where an unauthenticated attacker can …

Jul 22, 2024
CVE-2024-40051
7.5 HIGH

IP Guard v4.81.0307.0 was discovered to contain an arbitrary file read vulnerability via the file name parameter.

Jul 22, 2024
CVE-2024-28698
9.8 CRITICAL

Directory Traversal vulnerability in Marimer LLC CSLA .Net before 8.0 allows a remote attacker to execute arbitrary code via a crafted script to the MobileFormatter …

Jul 22, 2024
CVE-2020-24102
7.6 HIGH

Directory Traversal vulnerability in Punkbuster pbsv.d64 2.351, allows remote attackers to execute arbitrary code.

Jul 22, 2024
CVE-2024-39688
6.5 MEDIUM

Bert-VITS2 is the VITS2 Backbone with multilingual bert. User input supplied to the data_dir variable is concatenated with other folders and used to open a …

Jul 22, 2024
CVE-2024-39686
9.8 CRITICAL

Bert-VITS2 is the VITS2 Backbone with multilingual bert. User input supplied to the data_dir variable is used directly in a command executed with subprocess.run(cmd, shell=True) …

Jul 22, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.