CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-39174
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in the Publish Article function of yzmcms v7.1 allows attackers to execute arbitrary web scripts or HTML via a crafted …

Jul 5, 2024
CVE-2024-37903
8.2 HIGH

Mastodon is a self-hosted, federated microblogging platform. Starting in version 2.6.0 and prior to versions 4.1.18 and 4.2.10, by crafting specific activities, an attacker can …

Jul 5, 2024
CVE-2024-39178
5.4 MEDIUM

MyPower vc8100 V100R001C00B030 was discovered to contain an arbitrary file read vulnerability via the component /tcpdump/tcpdump.php?menu_uuid.

Jul 5, 2024
CVE-2024-39150
5.9 MEDIUM

vditor v.3.9.8 and before is vulnerable to Arbitrary file read via a crafted data packet.

Jul 5, 2024
CVE-2024-37767
7.5 HIGH

Insecure permissions in the component /api/admin/user of 14Finger v1.1 allows attackers to access all user information via a crafted GET request.

Jul 5, 2024
CVE-2024-27717
6.5 MEDIUM

Cross Site Request Forgery vulnerability in Eskooly Free Online School Management Software v.3.0 and before allows a remote attacker to escalate privileges via the Token …

Jul 5, 2024
CVE-2024-27716
5.4 MEDIUM

Cross Site Scripting vulnerability in Eskooly Web Product v.3.0 and before allows a remote attacker to execute arbitrary code via the message sending and user …

Jul 5, 2024
CVE-2024-27715
8.2 HIGH

An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via a crafted request to the …

Jul 5, 2024
CVE-2024-27713
8.8 HIGH

An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via the HTTP Response Header Settings …

Jul 5, 2024
CVE-2024-27712
9.8 CRITICAL

An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via the User Account Mangemnt component …

Jul 5, 2024
CVE-2024-27711
8.8 HIGH

An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via the Sin-up process function in …

Jul 5, 2024
CVE-2024-27710
9.8 CRITICAL

An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via the authentication mechanism.

Jul 5, 2024
CVE-2024-27709
9.8 CRITICAL

SQL Injection vulnerability in Eskooly Web Product v.3.0 allows a remote attacker to execute arbitrary code via the searchby parameter of the allstudents.php component and …

Jul 5, 2024
CVE-2024-39210
7.5 HIGH

Best House Rental Management System v1.0 was discovered to contain an arbitrary file read vulnerability via the Page parameter at index.php. This vulnerability allows attackers …

Jul 5, 2024
CVE-2024-37769
8.8 HIGH

Insecure permissions in 14Finger v1.1 allow attackers to escalate privileges from normal user to Administrator via a crafted POST request.

Jul 5, 2024
CVE-2024-37768
9.1 CRITICAL

14Finger v1.1 was discovered to contain an arbitrary user deletion vulnerability via the component /api/admin/user?id.

Jul 5, 2024
CVE-2024-29319
9.8 CRITICAL

Volmarg Personal Management System 1.4.64 is vulnerable to SSRF (Server Side Request Forgery) via uploading a SVG file. The server can make unintended HTTP and …

Jul 5, 2024
CVE-2024-29318
5.4 MEDIUM

Volmarg Personal Management System 1.4.64 is vulnerable to stored cross site scripting (XSS) via upload of a SVG file with embedded javascript code.

Jul 5, 2024
CVE-2024-23998
9.6 CRITICAL

goanother Another Redis Desktop Manager =<1.6.1 is vulnerable to Cross Site Scripting (XSS) via src/components/Setting.vue.

Jul 5, 2024
CVE-2024-23997
9.6 CRITICAL

Lukas Bach yana =<1.0.16 is vulnerable to Cross Site Scripting (XSS) via src/electron-main.ts.

Jul 5, 2024
CVE-2024-6526
3.5 LOW

A vulnerability classified as problematic has been found in CodeIgniter Ecommerce-CodeIgniter-Bootstrap up to 1998845073cf433bc6c250b0354461fbd84d0e03. This affects an unknown part. The manipulation of the argument search_title/catName/sub/name/categorie …

Jul 5, 2024
CVE-2024-6505
6.8 MEDIUM

A flaw was found in the virtio-net device in QEMU. When enabling the RSS feature on the virtio-net network card, the indirections_table data within RSS …

Jul 5, 2024
CVE-2024-39864
9.8 CRITICAL

The CloudStack integration API service allows running its unauthenticated API server (usually on port 8096 when configured and enabled via integration.api.port global setting) for internal …

Jul 5, 2024
CVE-2024-39028
9.8 CRITICAL

An issue was discovered in SeaCMS <=12.9 which allows remote attackers to execute arbitrary code via admin_ping.php.

Jul 5, 2024
CVE-2024-39027
7.5 HIGH

SeaCMS v12.9 has an unauthorized SQL injection vulnerability. The vulnerability is caused by the SQL injection through the cid parameter at /js/player/dmplayer/dmku/index.php?ac=edit, which can cause …

Jul 5, 2024
CVE-2024-38346
9.8 CRITICAL

The CloudStack cluster service runs on unauthenticated port (default 9090) that can be misused to run arbitrary commands on targeted hypervisors and CloudStack management server …

Jul 5, 2024
CVE-2024-23588
5.3 MEDIUM

HCL Nomad server on Domino fails to properly handle users configured with limited Domino access resulting in a possible denial of service vulnerability.

Jul 5, 2024
CVE-2024-6525
2.7 LOW

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000 up to 20230922. It has been rated as problematic. Affected by this issue …

Jul 5, 2024
CVE-2024-6524
5.5 MEDIUM

A vulnerability was found in ShopXO up to 6.1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the …

Jul 5, 2024
CVE-2024-6523
3.5 LOW

A vulnerability was found in ZKTeco BioTime up to 9.5.2. It has been classified as problematic. Affected is an unknown function of the component system-group-add …

Jul 5, 2024
CVE-2024-6298
10.0 CRITICAL

Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to execute arbitrary code …

Jul 5, 2024
CVE-2024-6209
10.0 CRITICAL

Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to access files unauthorized

Jul 5, 2024
CVE-2024-39485
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: v4l: async: Properly re-initialise notifier entry in unregister The notifier_entry of a notifier is …

Jul 5, 2024
CVE-2024-39484
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mmc: davinci: Don't strip remove function when driver is builtin Using __exit for the remove …

Jul 5, 2024
CVE-2024-39483
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: WARN on vNMI + NMI window iff NMIs are outright masked When requesting …

Jul 5, 2024
CVE-2024-39482
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bcache: fix variable length array abuse in btree_iter btree_iter is used in two ways: either …

Jul 5, 2024
CVE-2024-39481
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: mc: Fix graph walk in media_pipeline_start The graph walk tries to follow all links, …

Jul 5, 2024
CVE-2024-39480
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: kdb: Fix buffer overflow during tab-complete Currently, when the user attempts symbol completion with the …

Jul 5, 2024
CVE-2024-39479
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/i915/hwmon: Get rid of devm When both hwmon and hwmon drvdata (on which hwmon depends) …

Jul 5, 2024
CVE-2024-39478
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: crypto: starfive - Do not free stack buffer RSA text data uses variable length buffer …

Jul 5, 2024
CVE-2024-39477
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: do not call vma_add_reservation upon ENOMEM sysbot reported a splat [1] on __unmap_hugepage_range(). This …

Jul 5, 2024
CVE-2024-39476
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: md/raid5: fix deadlock that raid5d() wait for itself to clear MD_SB_CHANGE_PENDING Xiao reported that lvm2 …

Jul 5, 2024
CVE-2024-39475
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: fbdev: savage: Handle err return when savagefb_check_var failed The commit 04e5eac8f3ab("fbdev: savage: Error out if …

Jul 5, 2024
CVE-2024-39474
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/vmalloc: fix vmalloc which may return null if called with __GFP_NOFAIL commit a421ef303008 ("mm: allow …

Jul 5, 2024
CVE-2024-39473
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc4-topology: Fix input format query of process modules without base extension If a …

Jul 5, 2024
CVE-2024-39472
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: xfs: fix log recovery buffer allocation for the legacy h_size fixup Commit a70f9fe52daa ("xfs: detect …

Jul 5, 2024
CVE-2024-36041
7.8 HIGH

KSmserver in KDE Plasma Workspace (aka plasma-workspace) before 5.27.11.1 and 6.x before 6.0.5.1 allows connections via ICE based purely on the host, i.e., all local …

Jul 5, 2024
CVE-2024-34481
6.1 MEDIUM

drupal-wiki.com Drupal Wiki before 8.31.1 allows XSS via comments, captions, and image titles of a Wiki page.

Jul 5, 2024
CVE-2024-32498
6.5 MEDIUM

An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external …

Jul 5, 2024
CVE-2023-52340
7.5 HIGH

The IPv6 implementation in the Linux kernel before 6.3 has a net/ipv6/route.c max_size threshold that can be consumed easily, e.g., leading to a denial of …

Jul 5, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.