CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-39920
4.3 MEDIUM

The TCP protocol in RFC 9293 has a timing side channel that makes it easier for remote attackers to infer the content of one TCP …

Jul 3, 2024
CVE-2024-32673
5.5 MEDIUM

Improper Validation of Array Index vulnerability in Samsung Open Source Walrus Webassembly runtime engine allows a segmentation fault issue. This issue affects Walrus: before 72c7230f32a0b791355bbdfc78669701024b0956.

Jul 3, 2024
CVE-2024-4708
9.8 CRITICAL

mySCADA myPRO uses a hard-coded password which could allow an attacker to remotely execute code on the affected device.

Jul 2, 2024
CVE-2024-6453
6.3 MEDIUM

A vulnerability was found in itsourcecode Farm Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Jul 2, 2024
CVE-2024-24791
7.5 HIGH

The net/http HTTP/1.1 client mishandled the case where a server responds to a request with an "Expect: 100-continue" header with a non-informational (200 or higher) …

Jul 2, 2024
CVE-2024-39326
4.4 MEDIUM

SkillTree is a micro-learning gamification platform. Prior to version 2.12.6, the endpoint `/admin/projects/{projectname}/skills/{skillname}/video` (and probably others) is open to a cross-site request forgery (CSRF) vulnerability. …

Jul 2, 2024
CVE-2024-39325
5.3 MEDIUM

aimeos/ai-controller-frontend is the Aimeos frontend controller. Prior to versions 2024.04.2, 2023.10.9, 2022.10.8, 2021.10.8, and 2020.10.15, aimeos/ai-controller-frontend doesn't reset the payment status of a user's basket …

Jul 2, 2024
CVE-2024-39324
3.8 LOW

aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.1 and prior to versions 2022.10.10, 2023.10.6, and 2024.4.2, improper access control allows a …

Jul 2, 2024
CVE-2024-39322
5.5 MEDIUM

aimeos/ai-admin-jsonadm is the Aimeos e-commerce JSON API for administrative tasks. In versions prior to 2020.10.13, 2021.10.6, 2022.10.3, 2023.10.4, and 2024.4.2, improper access control allows editors …

Jul 2, 2024
CVE-2024-6452
6.3 MEDIUM

A vulnerability classified as critical was found in linlinjava litemall up to 1.8.0. Affected by this vulnerability is an unknown functionality of the file AdminGoodscontroller.java. …

Jul 2, 2024
CVE-2024-39315
5.7 MEDIUM

Pomerium is an identity and context-aware access proxy. Prior to version 0.26.1, the Pomerium user info page (at `/.pomerium`) unintentionally included serialized OAuth2 access and …

Jul 2, 2024
CVE-2024-38537
0.0 NONE

Fides is an open-source privacy engineering platform. `fides.js`, a client-side script used to interact with the consent management features of Fides, used the `polyfill.io` domain …

Jul 2, 2024
CVE-2023-24531
9.8 CRITICAL

Command go env is documented as outputting a shell script containing the Go environment. However, go env doesn't sanitize values, so executing its output as …

Jul 2, 2024
CVE-2022-30636
7.5 HIGH

httpTokenCacheKey uses path.Base to extract the expected HTTP-01 token value to lookup in the DirCache implementation. On Windows, path.Base acts differently to filepath.Base, since Windows …

Jul 2, 2024
CVE-2022-25480
7.8 HIGH

Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 allows writing …

Jul 2, 2024
CVE-2022-25479
5.5 MEDIUM

Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 allows for …

Jul 2, 2024
CVE-2022-25478
7.8 HIGH

Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 provides read …

Jul 2, 2024
CVE-2022-25477
5.5 MEDIUM

Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 leaks driver …

Jul 2, 2024
CVE-2024-6382
6.4 MEDIUM

Incorrect handling of certain string inputs may result in MongoDB Rust driver constructing unintended server commands. This may cause unexpected application behavior including data modification. …

Jul 2, 2024
CVE-2024-6381
4.0 MEDIUM

The bson_strfreev function in the MongoDB C driver library may be susceptible to an integer overflow where the function will try to free memory at …

Jul 2, 2024
CVE-2024-39894
7.5 HIGH

OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) because of an ObscureKeystrokeTiming logic error. …

Jul 2, 2024
CVE-2024-39891
5.3 MEDIUM KEV

In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to certain phone-number data, …

Jul 2, 2024
CVE-2024-39206
7.5 HIGH

An issue discovered in MSP360 Backup Agent v7.8.5.15 and v7.9.4.84 allows attackers to obtain network share credentials used in a backup due to enginesettings.list being …

Jul 2, 2024
CVE-2023-39324

Rejected reason: reserved but not needed

Jul 2, 2024
CVE-2022-41730

Rejected reason: reserved but not needed

Jul 2, 2024
CVE-2022-41729

Rejected reason: reserved but not needed

Jul 2, 2024
CVE-2022-41728

Rejected reason: reserved but not needed

Jul 2, 2024
CVE-2022-41726

Rejected reason: reserved but not needed

Jul 2, 2024
CVE-2022-41718

Rejected reason: reserved but not needed

Jul 2, 2024
CVE-2022-3428

Rejected reason: reserved but not needed

Jul 2, 2024
CVE-2022-32191

Rejected reason: reserved but not needed

Jul 2, 2024
CVE-2022-32147

Rejected reason: reserved but not needed

Jul 2, 2024
CVE-2024-5866
5.0 MEDIUM

Vulnerability in Delinea Centrify PAS v. 21.3 and possibly others. The application is prone to the path traversal vulnerability allowing listing of arbitrary directory outside …

Jul 2, 2024
CVE-2024-5865
7.7 HIGH

Vulnerability in Delinea Centrify PAS v. 21.3 and possibly others. The application is prone to the path traversal vulnerability allowing arbitrary files reading outside the …

Jul 2, 2024
CVE-2024-4467
7.8 HIGH

A flaw was found in the QEMU disk image utility (qemu-img) 'info' command. A specially crafted image file containing a `json:{}` value describing block devices …

Jul 2, 2024
CVE-2024-3826

In versions of Akana in versions prior to and including 2022.1.3 validation is broken when using the SAML Single Sign-On (SSO) functionality.

Jul 2, 2024
CVE-2024-39323
7.1 HIGH

aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.01 and prior to versions 2022.10.10, 2023.10.6, and 2024.04.6, an improper access control vulnerability …

Jul 2, 2024
CVE-2024-39316
6.5 MEDIUM

Rack is a modular Ruby web server interface. Starting in version 3.1.0 and prior to version 3.1.5, Regular Expression Denial of Service (ReDoS) vulnerability exists …

Jul 2, 2024
CVE-2024-26314
7.8 HIGH

Improper privilege management in Jungo WinDriver 6.0.0 through 16.1.0 allows local attackers to escalate privileges and execute arbitrary code.

Jul 2, 2024
CVE-2024-25088
7.8 HIGH

Improper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges and execute arbitrary code.

Jul 2, 2024
CVE-2024-25087
5.5 MEDIUM

Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.7.0 allows local attackers to cause a Windows blue screen error.

Jul 2, 2024
CVE-2024-25086
7.8 HIGH

Improper privilege management in Jungo WinDriver before 12.2.0 allows local attackers to escalate privileges and execute arbitrary code.

Jul 2, 2024
CVE-2024-22106
7.8 HIGH

Improper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges, execute arbitrary code, or cause a Denial of Service (DoS).

Jul 2, 2024
CVE-2024-22105
5.5 MEDIUM

Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.5.1 allows local attackers to cause a Windows blue screen error.

Jul 2, 2024
CVE-2024-4897
8.4 HIGH

parisneo/lollms-webui, in its latest version, is vulnerable to remote code execution due to an insecure dependency on llama-cpp-python version llama_cpp_python-0.2.61+cpuavx2-cp311-cp311-manylinux_2_31_x86_64. The vulnerability arises from the …

Jul 2, 2024
CVE-2024-32932
6.8 MEDIUM

Under certain circumstances the web interface users credentials may be recovered by an authenticated user.

Jul 2, 2024
CVE-2024-22104
5.5 MEDIUM

Out-of-Bounds Write vulnerability in Jungo WinDriver before 12.5.1 allows local attackers to cause a Windows blue screen error and Denial of Service (DoS).

Jul 2, 2024
CVE-2024-22103
5.5 MEDIUM

Out-of-Bounds Write vulnerability in Jungo WinDriver before 12.6.0 allows local attackers to cause a Windows blue screen error and Denial of Service (DoS).

Jul 2, 2024
CVE-2024-22102
5.5 MEDIUM

Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.6.0 allows local attackers to cause a Windows blue screen error.

Jul 2, 2024
CVE-2023-51778
5.5 MEDIUM

Out-of-Bounds Write vulnerability in Jungo WinDriver before 12.1.0 allows local attackers to cause a Windows blue screen error and Denial of Service (DoS).

Jul 2, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.