CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-52886
6.4 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: USB: core: Fix race by not overwriting udev->descriptor in hub_port_init() Syzbot reported an out-of-bounds read …

Jul 16, 2024
CVE-2024-6570
5.3 MEDIUM

The Glossary plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.2.26. This is due the plugin utilizing …

Jul 16, 2024
CVE-2024-6565
5.3 MEDIUM

The AForms — Form Builder for Price Calculator & Cost Estimation plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, …

Jul 16, 2024
CVE-2024-5852
4.3 MEDIUM

The WordPress File Upload plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.24.7 via the 'uploadpath' parameter of …

Jul 16, 2024
CVE-2024-3779
6.1 MEDIUM

Denial of service vulnerability present shortly after product installation or upgrade, potentially allowed an attacker to render ESET’s security product inoperable, provided non-default preconditions were …

Jul 16, 2024
CVE-2024-3587
6.4 MEDIUM

The Premium Portfolio Features for Phlox theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Grid Portfolios Widget in all versions …

Jul 16, 2024
CVE-2024-2691
6.4 MEDIUM

The WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'events' …

Jul 16, 2024
CVE-2024-1937
7.1 HIGH

The Brizy – Page Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_item' function …

Jul 16, 2024
CVE-2024-41008
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: change vm->task_info handling This patch changes the handling and lifecycle of vm->task_info object. The …

Jul 16, 2024
CVE-2023-52290
8.1 HIGH

In streampark-console the list pages(e.g: application pages), users can sort page by field. This sort field is sent from the front-end to the back-end, and …

Jul 16, 2024
CVE-2024-6559
5.3 MEDIUM

The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, …

Jul 16, 2024
CVE-2024-4780
6.4 MEDIUM

The Image Hover Effects – Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘eihe_link’ parameter in all versions up to, …

Jul 16, 2024
CVE-2024-6557
5.3 MEDIUM

The SchedulePress – Auto Post & Publish, Auto Social Share, Schedule Posts with Editorial Calendar & Missed Schedule Post Publisher plugin for WordPress is vulnerable …

Jul 16, 2024
CVE-2024-6780
3.3 LOW

Improper permission control in the mobile application (com.android.server.telecom) may lead to user information security risks.

Jul 16, 2024
CVE-2024-40524
9.8 CRITICAL

Directory Traversal vulnerability in xmind2testcase v.1.5 allows a remote attacker to execute arbitrary code via the webtool\application.py component.

Jul 15, 2024
CVE-2024-4143
9.8 CRITICAL

A potential security vulnerability has been identified in certain HP PC products using AMI BIOS, which might allow arbitrary code execution. AMI has released firmware …

Jul 15, 2024
CVE-2024-40632
3.7 LOW

Linkerd is an open source, ultralight, security-first service mesh for Kubernetes. In affected versions when the application being run by linkerd is susceptible to SSRF, …

Jul 15, 2024
CVE-2024-4224
5.4 MEDIUM

An authenticated stored cross-site scripting (XSS) exists in the TP-Link TL-SG1016DE affecting version TL-SG1016DE(UN) V7.6_1.0.0 Build 20230616, which could allow an adversary to run JavaScript …

Jul 15, 2024
CVE-2024-40630
4.3 MEDIUM

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation via a format-agnostic API …

Jul 15, 2024
CVE-2024-40627
5.8 MEDIUM

Fastapi OPA is an opensource fastapi middleware which includes auth flow. HTTP `OPTIONS` requests are always allowed by `OpaMiddleware`, even when they lack authentication, and …

Jul 15, 2024
CVE-2024-40624
9.8 CRITICAL

TorrentPier is an open source BitTorrent Public/Private tracker engine, written in php. In `torrentpier/library/includes/functions.php`, `get_tracks()` uses the unsafe native PHP serialization format to deserialize user-controlled …

Jul 15, 2024
CVE-2024-39919
3.1 LOW

@jmondi/url-to-png is an open source URL to PNG utility featuring parallel rendering using Playwright for screenshots and with storage caching via Local, S3, or CouchDB. …

Jul 15, 2024
CVE-2024-39918
4.3 MEDIUM

@jmondi/url-to-png is an open source URL to PNG utility featuring parallel rendering using Playwright for screenshots and with storage caching via Local, S3, or CouchDB. …

Jul 15, 2024
CVE-2024-39915
9.9 CRITICAL

Thruk is a multibackend monitoring webinterface for Naemon, Nagios, Icinga and Shinken using the Livestatus API. This authenticated RCE in Thruk allows authorized users with …

Jul 15, 2024
CVE-2024-39912
5.3 MEDIUM

web-auth/webauthn-lib is an open source set of PHP libraries and a Symfony bundle to allow developers to integrate that authentication mechanism into their web applications. …

Jul 15, 2024
CVE-2024-38360
4.9 MEDIUM

Discourse is an open source platform for community discussion. In affected versions by creating replacement words with an almost unlimited number of characters, a moderator …

Jul 15, 2024
CVE-2024-40631
8.1 HIGH

Plate media is an open source, rich-text editor for React. Editors that use `MediaEmbedElement` and pass custom `urlParsers` to the `useMediaState` hook may be vulnerable …

Jul 15, 2024
CVE-2024-37386
4.2 MEDIUM

An issue was discovered in Stormshield Network Security (SNS) 4.0.0 through 4.3.25, 4.4.0 through 4.7.5, and 4.8.0. Certain manipulations allow restarting in single-user mode despite …

Jul 15, 2024
CVE-2024-36438
7.3 HIGH

eLinkSmart Hidden Smart Cabinet Lock 2024-05-22 has Incorrect Access Control and fails to perform an authorization check which can lead to card duplication and other …

Jul 15, 2024
CVE-2024-36434
7.5 HIGH

An SMM callout vulnerability was discovered in Supermicro X11DPH-T, X11DPH-Tq, and X11DPH-i motherboards with BIOS firmware before 4.4.

Jul 15, 2024
CVE-2024-36433
7.5 HIGH

An arbitrary memory write vulnerability was discovered in Supermicro X11DPH-T, X11DPH-Tq, and X11DPH-i motherboards with BIOS firmware before 4.4.

Jul 15, 2024
CVE-2024-36432
7.5 HIGH

An arbitrary memory write vulnerability was discovered in Supermicro X11DPG-HGX2, X11PDG-QT, X11PDG-OT, and X11PDG-SN motherboards with BIOS firmware before 4.4.

Jul 15, 2024
CVE-2024-31946
4.2 MEDIUM

An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.41, 3.10.0 through 3.11.29, 4.0 through 4.3.24, and 4.4.0 through 4.7.4. A user who …

Jul 15, 2024
CVE-2024-40416
9.8 CRITICAL

A vulnerability in /goform/SetVirtualServerCfg in the sub_6320C function in Tenda AX1806 1.0.0.1 firmware leads to stack-based buffer overflow.

Jul 15, 2024
CVE-2024-40415
9.8 CRITICAL

A vulnerability in /goform/SetStaticRouteCfg in the sub_519F4 function in Tenda AX1806 1.0.0.1 firmware leads to stack-based buffer overflow.

Jul 15, 2024
CVE-2024-39827
5.5 MEDIUM

Improper input validation in the installer for Zoom Workplace Desktop App for Windows before version 6.0.10 may allow an authenticated user to conduct a denial …

Jul 15, 2024
CVE-2024-39826
6.8 MEDIUM

Race condition in Team Chat for some Zoom Workplace Apps and SDKs for Windows may allow an authenticated user to conduct information disclosure via network …

Jul 15, 2024
CVE-2024-39821
6.6 MEDIUM

Race condition in the installer for Zoom Workplace App for Windows and Zoom Rooms App for Windows may allow an authenticated user to conduct a …

Jul 15, 2024
CVE-2024-39820
6.6 MEDIUM

Uncontrolled search path element in the installer for Zoom Workplace Desktop App for macOS before version 6.0.10 may allow an authenticated user to conduct a …

Jul 15, 2024
CVE-2024-39819
6.7 MEDIUM

Integrity check in the installer for some Zoom Workplace Apps and SDKs for Windows may allow an authenticated user to conduct a privilege escalation via …

Jul 15, 2024
CVE-2024-37016
6.8 MEDIUM

Mengshen Wireless Door Alarm M70 2024-05-24 allows Authentication Bypass via a Capture-Replay approach.

Jul 15, 2024
CVE-2024-27241
5.3 MEDIUM

Improper input validation in some Zoom Apps and SDKs may allow an authenticated user to conduct a denial of service via network access.

Jul 15, 2024
CVE-2024-27240
7.1 HIGH

Improper input validation in the installer for some Zoom Apps for Windows may allow an authenticated user to conduct a privilege escalation via local access.

Jul 15, 2024
CVE-2024-27238
7.1 HIGH

Race condition in the installer for some Zoom Apps and SDKs for Windows before version 6.0.0 may allow an authenticated user to conduct a privilege …

Jul 15, 2024
CVE-2024-40414
9.8 CRITICAL

A vulnerability in /goform/SetNetControlList in the sub_656BC function in Tenda AX1806 1.0.0.1 firmware leads to stack-based buffer overflow.

Jul 15, 2024
CVE-2024-40560
7.3 HIGH

Tmall_demo before v2024.07.03 was discovered to contain a SQL injection vulnerability.

Jul 15, 2024
CVE-2024-40555
5.3 MEDIUM

Tmall_demo v2024.07.03 was discovered to contain an arbitrary file upload vulnerability.

Jul 15, 2024
CVE-2024-40554
7.5 HIGH

An access control issue in Tmall_demo v2024.07.03 allows attackers to obtain sensitive information.

Jul 15, 2024
CVE-2024-40553
4.9 MEDIUM

Tmall_demo v2024.07.03 was discovered to contain an arbitrary file upload via the component uploadUserHeadImage.

Jul 15, 2024
CVE-2024-6716

Rejected reason: Invalid security issue.

Jul 15, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.