CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-37855
8.4 HIGH

An issue in Nepstech Wifi Router xpon (terminal) NTPL-Xpon1GFEVN, hardware verstion 1.0 firmware 2.0.1 allows a remote attacker to execute arbitrary code via the router's …

Jun 25, 2024
CVE-2024-37843
9.8 CRITICAL

Craft CMS up to v3.7.31 was discovered to contain a SQL injection vulnerability via the GraphQL API endpoint.

Jun 25, 2024
CVE-2024-35526
5.9 MEDIUM

An issue in Daemon PTY Limited FarCry Core framework before 7.2.14 allows attackers to access sensitive information in the /facade directory.

Jun 25, 2024
CVE-2024-34400
6.1 MEDIUM

An issue was discovered in VirtoSoftware Virto Kanban Board Web Part before 5.3.5.1 for SharePoint 2019. There is /_layouts/15/Virto.KanbanTaskManager/api/KanbanData.ashx LinkTitle2 XSS.

Jun 25, 2024
CVE-2024-21741
9.8 CRITICAL

GigaDevice GD32E103C8T6 devices have Incorrect Access Control.

Jun 25, 2024
CVE-2024-21740
7.4 HIGH

Artery AT32F415CBT7 and AT32F421C8T7 devices have Incorrect Access Control.

Jun 25, 2024
CVE-2024-21739
5.3 MEDIUM

Geehy APM32F103CCT6, APM32F103RCT6, APM32F103RCT7, and APM32F103VCT6 devices have Incorrect Access Control.

Jun 25, 2024
CVE-2024-6206
7.5 HIGH

A security vulnerability has been identified in HPE Athonet Mobile Core software. The core application contains a code injection vulnerability where a threat actor could …

Jun 25, 2024
CVE-2024-5276
9.8 CRITICAL

A SQL Injection vulnerability in Fortra FileCatalyst Workflow allows an attacker to modify application data. Likely impacts include creation of administrative users and deletion or …

Jun 25, 2024
CVE-2024-5011
7.5 HIGH

In WhatsUp Gold versions released before 2023.1.3, an uncontrolled resource consumption vulnerability exists. A specially crafted unauthenticated HTTP request to the TestController Chart functionality can …

Jun 25, 2024
CVE-2024-5010
7.5 HIGH

In WhatsUp Gold versions released before 2023.1.3, a vulnerability exists in the TestController functionality. A specially crafted unauthenticated HTTP request can lead to a disclosure …

Jun 25, 2024
CVE-2024-5009
8.4 HIGH

In WhatsUp Gold versions released before 2023.1.3, an Improper Access Control vulnerability in Wug.UI.Controllers.InstallController.SetAdminPassword allows local attackers to modify admin's password.

Jun 25, 2024
CVE-2024-5008
8.8 HIGH

In WhatsUp Gold versions released before 2023.1.3, an authenticated user with certain permissions can upload an arbitrary file and obtain RCE using Apm.UI.Areas.APM.Controllers.Api.Applications.AppProfileImportController.

Jun 25, 2024
CVE-2024-4885
9.8 CRITICAL KEV

In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold. The WhatsUp.ExportUtilities.Export.GetFileWithoutZip allows execution of commands with iisapppool\nmconsole privileges.

Jun 25, 2024
CVE-2024-4884
9.8 CRITICAL

In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold. The Apm.UI.Areas.APM.Controllers.CommunityController allows execution of commands with iisapppool\nmconsole privileges.

Jun 25, 2024
CVE-2024-4883
9.8 CRITICAL

In WhatsUp Gold versions released before 2023.1.3, a Remote Code Execution issue exists in Progress WhatsUp Gold. This vulnerability allows an unauthenticated attacker to achieve …

Jun 25, 2024
CVE-2024-4498
7.7 HIGH

A Path Traversal and Remote File Inclusion (RFI) vulnerability exists in the parisneo/lollms-webui application, affecting versions v9.7 to the latest. The vulnerability arises from insufficient …

Jun 25, 2024
CVE-2024-37894
6.3 MEDIUM

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to an Out-of-bounds Write error when assigning ESI variables, Squid …

Jun 25, 2024
CVE-2024-37167
4.3 MEDIUM

Tuleap is an Open Source Suite to improve management of software developments and collaboration. Users are able to see backlog items that they should not …

Jun 25, 2024
CVE-2024-37820
5.4 MEDIUM

A nil pointer dereference in PingCAP TiDB v8.2.0-alpha-216-gfe5858b allows attackers to crash the application via expression.inferCollation.

Jun 25, 2024
CVE-2024-36819
5.4 MEDIUM

MAP-OS 4.45.0 and earlier is vulnerable to Cross-Site Scripting (XSS). This vulnerability allows malicious users to insert a malicious payload into the "Client Name" input. …

Jun 25, 2024
CVE-2024-6308
7.3 HIGH

A vulnerability was found in itsourcecode Simple Online Hotel Reservation System 1.0. It has been declared as critical. This vulnerability affects unknown code of the …

Jun 25, 2024
CVE-2024-6257
8.4 HIGH

HashiCorp’s go-getter library can be coerced into executing Git update on an existing maliciously modified Git Configuration, potentially leading to arbitrary code execution.

Jun 25, 2024
CVE-2024-6238
7.4 HIGH

pgAdmin <= 8.8 has an installation Directory permission issue. Because of this issue, attackers can gain unauthorised access to the installation directory on the Debian …

Jun 25, 2024
CVE-2024-5990
7.5 HIGH

Due to an improper input validation, an unauthenticated threat actor can send a malicious message to a monitor thread within Rockwell Automation ThinServer™ and cause …

Jun 25, 2024
CVE-2024-5989
9.8 CRITICAL

Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke SQL injection into the program and cause a …

Jun 25, 2024
CVE-2024-5988
9.8 CRITICAL

Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke a local or remote executable and cause a …

Jun 25, 2024
CVE-2024-0171
5.3 MEDIUM

Dell PowerEdge Server BIOS contains an TOCTOU race condition vulnerability. A local low privileged attacker could potentially exploit this vulnerability to gain access to otherwise …

Jun 25, 2024
CVE-2024-5806
9.1 CRITICAL

Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.11, from 2023.1.0 before …

Jun 25, 2024
CVE-2024-5805
9.1 CRITICAL

Improper Authentication vulnerability in Progress MOVEit Gateway (SFTP modules) allows Authentication Bypass.This issue affects MOVEit Gateway: 2024.0.0.

Jun 25, 2024
CVE-2024-39471
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: add error handle to avoid out-of-bounds if the sdma_v4_0_irq_id_to_seq return -EINVAL, the process should …

Jun 25, 2024
CVE-2024-39470
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: eventfs: Fix a possible null pointer dereference in eventfs_find_events() In function eventfs_find_events,there is a potential …

Jun 25, 2024
CVE-2024-39469
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix nilfs_empty_dir() misjudgment and long loop on I/O errors The error handling in nilfs_empty_dir() …

Jun 25, 2024
CVE-2024-39468
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix deadlock in smb2_find_smb_tcon() Unlock cifs_tcp_ses_lock before calling cifs_put_smb_ses() to avoid such deadlock.

Jun 25, 2024
CVE-2024-39467
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to do sanity check on i_xattr_nid in sanity_check_inode() syzbot reports a kernel bug …

Jun 25, 2024
CVE-2024-39466
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: thermal/drivers/qcom/lmh: Check for SCM availability at probe Up until now, the necessary scm availability check …

Jun 25, 2024
CVE-2024-39465
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: mgb4: Fix double debugfs remove Fixes an error where debugfs_remove_recursive() is called first on …

Jun 25, 2024
CVE-2024-39464
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: v4l: async: Fix notifier list entry init struct v4l2_async_notifier has several list_head members, but …

Jun 25, 2024
CVE-2024-39463
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: 9p: add missing locking around taking dentry fid list Fix a use-after-free on dentry's d_fsdata …

Jun 25, 2024
CVE-2024-39462
9.8 CRITICAL

In the Linux kernel, the following vulnerability has been resolved: clk: bcm: dvp: Assign ->num before accessing ->hws Commit f316cdff8d67 ("clk: Annotate struct clk_hw_onecell_data with …

Jun 25, 2024
CVE-2024-39461
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: clk: bcm: rpi: Assign ->num before accessing ->hws Commit f316cdff8d67 ("clk: Annotate struct clk_hw_onecell_data with …

Jun 25, 2024
CVE-2024-39371
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: io_uring: check for non-NULL file pointer in io_file_can_poll() In earlier kernels, it was possible to …

Jun 25, 2024
CVE-2024-39362

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 25, 2024
CVE-2024-39301
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net/9p: fix uninit-value in p9_client_rpc() Syzbot with the help of KMSAN reported the following error: …

Jun 25, 2024
CVE-2024-39298
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/memory-failure: fix handling of dissolved but not taken off from buddy pages When I did …

Jun 25, 2024
CVE-2024-39296
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bonding: fix oops during rmmod "rmmod bonding" causes an oops ever since commit cc317ea3d927 ("bonding: …

Jun 25, 2024
CVE-2024-39293
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: Revert "xsk: Support redirect to any socket bound to the same umem" This reverts commit …

Jun 25, 2024
CVE-2024-39276
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ext4: fix mb_cache_entry's e_refcnt leak in ext4_xattr_block_cache_find() Syzbot reports a warning as follows: ============================================ WARNING: …

Jun 25, 2024
CVE-2024-38661
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: s390/ap: Fix crash in AP internal function modify_bitmap() A system crash like this Failing address: …

Jun 25, 2024
CVE-2024-38385
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: genirq/irqdesc: Prevent use-after-free in irq_find_at_or_after() irq_find_at_or_after() dereferences the interrupt descriptor which is returned by mt_find() …

Jun 25, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.