CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-6772
8.8 HIGH

Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to perform out of bounds memory access via a crafted HTML …

Jul 16, 2024
CVE-2024-6395
5.3 MEDIUM

An exposure of sensitive information vulnerability in GitHub Enterprise Server would allow an attacker to enumerate the names of private repositories that utilize deploy keys. …

Jul 16, 2024
CVE-2024-6336
5.3 MEDIUM

A Security Misconfiguration vulnerability in GitHub Enterprise Server allowed sensitive information disclosure to unauthorized users in GitHub Enterprise Server by exploiting organization ruleset feature. This …

Jul 16, 2024
CVE-2024-5817
6.5 MEDIUM

An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed read access to issue content via GitHub Projects. This was only exploitable in …

Jul 16, 2024
CVE-2024-5816
5.3 MEDIUM

An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed a suspended GitHub App to retain access to the repository via a scoped …

Jul 16, 2024
CVE-2024-5815
6.5 MEDIUM

A Cross-Site Request Forgery vulnerability in GitHub Enterprise Server allowed write operations on a victim-owned repository by exploiting incorrect request types. A mitigating factor is …

Jul 16, 2024
CVE-2024-5795
7.7 HIGH

A Denial of Service vulnerability was identified in GitHub Enterprise Server that allowed an attacker to cause unbounded resource exhaustion by sending a large payload …

Jul 16, 2024
CVE-2024-5566
5.8 MEDIUM

An improper privilege management vulnerability allowed users to migrate private repositories without having appropriate scopes defined on the related Personal Access Token. This vulnerability affected …

Jul 16, 2024
CVE-2020-25836
6.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Access vulnerability in OpenText NetIQ Directory and Resource Administrator. This issue affects NetIQ Directory and Resource Administrator versions …

Jul 16, 2024
CVE-2024-40536
5.3 MEDIUM

Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 v3.2 were discovered to contain a stack overflow via the pin_3g_code parameter in the config_3g_para function.

Jul 16, 2024
CVE-2024-40535
9.8 CRITICAL

Shenzhen Libituo Technology Co., Ltd LBT-T300-T400 v3.2 was discovered to contain a stack overflow via the apn_name_3g parameter in the config_3g_para function.

Jul 16, 2024
CVE-2024-21687
8.1 HIGH

This High severity File Inclusion vulnerability was introduced in versions 9.0.0, 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0 and 9.6.0 of Bamboo Data Center and Server. This …

Jul 16, 2024
CVE-2024-40515
9.8 CRITICAL

An issue in SHENZHEN TENDA TECHNOLOGY CO.,LTD Tenda AX2pro V16.03.29.48_cn allows a remote attacker to execute arbitrary code via the Routing functionality.

Jul 16, 2024
CVE-2024-40505
9.3 CRITICAL

Directory Traversal vulnerability in D-Link DAP-1650 Firmware v.1.03 allows a local attacker to escalate privileges via the hedwig.cgi component.

Jul 16, 2024
CVE-2024-40456
9.8 CRITICAL

ThinkSAAS v3.7.0 was discovered to contain a SQL injection vulnerability via the name parameter at \system\action\update.php.

Jul 16, 2024
CVE-2024-40455
2.7 LOW

An arbitrary file deletion vulnerability in ThinkSAAS v3.7 allows attackers to delete arbitrary files via a crafted request.

Jul 16, 2024
CVE-2024-21686
8.7 HIGH

This High severity Stored XSS vulnerability was introduced in versions 7.13 of Confluence Data Center and Server. This Stored XSS vulnerability, with a CVSS Score …

Jul 16, 2024
CVE-2024-6492
7.4 HIGH

Exposure of Sensitive Information in edge browser session proxy feature in Devolutions Remote Desktop Manager 2024.2.14.0 and earlier on Windows allows an attacker to intercept …

Jul 16, 2024
CVE-2024-40516
8.8 HIGH

An issue in H3C Technologies Co., Limited H3C Magic RC3000 RC3000V100R009 allows a remote attacker to execute arbitrary code via the Routing functionality.

Jul 16, 2024
CVE-2024-40503
6.5 MEDIUM

An issue in Tenda AX12 v.16.03.49.18_cn+ allows a remote attacker to cause a denial of service via the Routing functionality and ICMP packet handling.

Jul 16, 2024
CVE-2024-40394
9.8 CRITICAL

Simple Library Management System Project Using PHP/MySQL v1.0 was discovered to contain an arbitrary file upload vulnerability via the component ajax.php.

Jul 16, 2024
CVE-2024-40393
9.8 CRITICAL

Online Clinic Management System In PHP With Free Source code v1.0 was discovered to contain a SQL injection vulnerability via the user parameter at login.php.

Jul 16, 2024
CVE-2024-40392
9.8 CRITICAL

SourceCodester Pharmacy/Medical Store Point of Sale System Using PHP/MySQL and Bootstrap Framework with Source Code 1.0 was discovered to contain a SQL injection vulnerability via …

Jul 16, 2024
CVE-2024-40130
9.8 CRITICAL

open5gs v2.6.4 is vulnerable to Buffer Overflow. via /lib/core/abts.c.

Jul 16, 2024
CVE-2024-40129
9.8 CRITICAL

Open5GS v2.6.4 is vulnerable to Buffer Overflow. via /lib/pfcp/context.c.

Jul 16, 2024
CVE-2024-39036
6.5 MEDIUM

SeaCMS v12.9 is vulnerable to Arbitrary File Read via admin_safe.php.

Jul 16, 2024
CVE-2024-40425
9.8 CRITICAL

File Upload vulnerability in Nanjin Xingyuantu Technology Co Sparkshop (Spark Mall B2C Mall v.1.1.6 and before allows a remote attacker to execute arbitrary code via …

Jul 16, 2024
CVE-2024-39908
4.3 MEDIUM

REXML is an XML toolkit for Ruby. The REXML gem before 3.3.1 has some DoS vulnerabilities when it parses an XML that has many specific …

Jul 16, 2024
CVE-2024-39700
9.9 CRITICAL

JupyterLab extension template is a `copier` template for JupyterLab extensions. Repositories created using this template with `test` option include `update-integration-tests.yml` workflow which has an RCE …

Jul 16, 2024
CVE-2024-33181
8.8 HIGH

Tenda AC18 V15.03.3.10_EN was discovered to contain a stack-based buffer overflow vulnerability via the deviceMac parameter at ip/goform/addWifiMacFilter.

Jul 16, 2024
CVE-2023-31456
5.4 MEDIUM

There is an SSRF vulnerability in the Fluid Topics platform that affects versions prior to 4.3, where the server can be forced to make arbitrary …

Jul 16, 2024
CVE-2024-6326
5.5 MEDIUM

An exposure of sensitive information vulnerability exists in the Rockwell Automation FactoryTalk® System Service. A malicious user could exploit this vulnerability by starting a back-up …

Jul 16, 2024
CVE-2024-6325
6.5 MEDIUM

The v6.40 release of Rockwell Automation FactoryTalk® Policy Manager CVE-2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html and CVE-2022-1161 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1585.html by implementing CIP security and did not update to the versions …

Jul 16, 2024
CVE-2024-6089
7.5 HIGH

An input validation vulnerability exists in the Rockwell Automation 5015 - AENFTXT when a manipulated PTP packet is sent, causing the secondary adapter to result …

Jul 16, 2024
CVE-2024-40626
7.3 HIGH

Outline is an open source, collaborative document editor. A type confusion issue was found in ProseMirror’s rendering process that leads to a Stored Cross-Site Scripting …

Jul 16, 2024
CVE-2024-3232
7.6 HIGH

A formula injection vulnerability exists in Tenable Identity Exposure where an authenticated remote attacker with administrative privileges could manipulate application form fields in order to …

Jul 16, 2024
CVE-2019-16641
8.4 HIGH

An issue was found on the Ruijie EG-2000 series gateway. There is a buffer overflow in client.so. Consequently, an attacker can use login.php to login …

Jul 16, 2024
CVE-2019-16640
7.5 HIGH

An issue was found in upload.php on the Ruijie EG-2000 series gateway. A parameter passed to the class UploadFile is mishandled (%00 and /var/./html are …

Jul 16, 2024
CVE-2019-16639
9.8 CRITICAL

An issue was found on the Ruijie EG-2000 series gateway. There is a newcli.php API interface without access control, which can allow an attacker (who …

Jul 16, 2024
CVE-2019-16638
7.5 HIGH

An issue was found on the Ruijie EG-2000 series gateway. An attacker can easily dump cleartext stored passwords in /data/config.text with simple XORs. This affects …

Jul 16, 2024
CVE-2024-40322
8.8 HIGH

An issue was discovered in JFinalCMS v.5.0.0. There is a SQL injection vulnerablity via /admin/div_data/data

Jul 16, 2024
CVE-2024-35338
9.8 CRITICAL

Tenda i29V1.0 V1.0.0.5 was discovered to contain a hardcoded password for root.

Jul 16, 2024
CVE-2024-33182
9.8 CRITICAL

Tenda AC18 V15.03.3.10_EN was discovered to contain a stack-based buffer overflow vulnerability via the deviceId parameter at ip/goform/addWifiMacFilter.

Jul 16, 2024
CVE-2024-33180
9.8 CRITICAL

Tenda AC18 V15.03.3.10_EN was discovered to contain a stack-based buffer overflow vulnerability via the deviceId parameter at ip/goform/saveParentControlInfo.

Jul 16, 2024
CVE-2024-22442
9.8 CRITICAL

The vulnerability could be remotely exploited to bypass authentication.

Jul 16, 2024
CVE-2024-6655
7.0 HIGH

A flaw was found in the GTK library. Under certain conditions, it is possible for a library to be injected into a GTK application from …

Jul 16, 2024
CVE-2024-32861
7.8 HIGH

Under certain circumstances the impacted Software House C•CURE 9000 installer will utilize unnecessarily wide permissions.

Jul 16, 2024
CVE-2022-45449
6.5 MEDIUM

Sensitive information disclosure due to excessive privileges assigned to Acronis Agent. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 30984.

Jul 16, 2024
CVE-2024-6435
8.8 HIGH

A privilege escalation vulnerability exists in the affected products which could allow a malicious user with basic privileges to access functions which should only be …

Jul 16, 2024
CVE-2022-48866
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: HID: hid-thrustmaster: fix OOB read in thrustmaster_interrupts Syzbot reported an slab-out-of-bounds Read in thrustmaster_probe() bug. …

Jul 16, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.