CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-38306
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: protect folio::private when attaching extent buffer folios [BUG] Since v6.8 there are rare kernel …

Jun 25, 2024
CVE-2024-37354
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix crash on racing fsync and size-extending write into prealloc We have been seeing …

Jun 25, 2024
CVE-2024-37087
5.3 MEDIUM

The vCenter Server contains a denial-of-service vulnerability. A malicious actor with network access to vCenter Server may create a denial-of-service condition.

Jun 25, 2024
CVE-2024-37086
6.8 MEDIUM

VMware ESXi contains an out-of-bounds read vulnerability. A malicious actor with local administrative privileges on a virtual machine with an existing snapshot may trigger an …

Jun 25, 2024
CVE-2024-37085
6.8 MEDIUM KEV

VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that …

Jun 25, 2024
CVE-2024-37078
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix potential kernel bug due to lack of writeback flag waiting Destructive writes to …

Jun 25, 2024
CVE-2023-37541
3.5 LOW

HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios.

Jun 25, 2024
CVE-2022-48772
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: media: lgdt3306a: Add a check against null-pointer-def The driver should check whether the client provides …

Jun 25, 2024
CVE-2021-4440
8.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: x86/xen: Drop USERGS_SYSRET64 paravirt call commit afd30525a659ac0ae0904f0cb4a2ca75522c3123 upstream. USERGS_SYSRET64 is used to return from a …

Jun 25, 2024
CVE-2024-5451
6.4 MEDIUM

The The7 — Website and eCommerce Builder for WordPress theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' attribute within the plugin's …

Jun 25, 2024
CVE-2024-38952
7.5 HIGH

PX4-Autopilot v1.14.3 was discovered to contain a buffer overflow via the topic_name parameter at /logger/logged_topics.cpp.

Jun 25, 2024
CVE-2024-38951
6.5 MEDIUM

A buffer overflow in PX4-Autopilot v1.12.3 allows attackers to cause a Denial of Service (DoS) via a crafted MavLink message.

Jun 25, 2024
CVE-2024-32111
5.0 MEDIUM

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Automattic WordPress allows Relative Path Traversal.This issue affects WordPress: from 6.5 through …

Jun 25, 2024
CVE-2024-21827
7.2 HIGH

A leftover debug code vulnerability exists in the cli_server debug functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.4.1 Build 20240117 Rel.57421. A specially crafted …

Jun 25, 2024
CVE-2024-6303
9.9 CRITICAL

Missing authorization in Client-Server API in Conduit <=0.7.0, allowing for any alias to be removed and added to another room, which can be used for …

Jun 25, 2024
CVE-2024-6302
8.1 HIGH

Lack of privilege checking when processing a redaction in Conduit versions v0.6.0 and lower, allowing a local user to redact any message from users on …

Jun 25, 2024
CVE-2024-6301
5.3 MEDIUM

Lack of validation of origin in federation API in Conduit, allowing any remote server to impersonate any user from any server in most EDUs

Jun 25, 2024
CVE-2024-6300
3.7 LOW

Incomplete cleanup when performing redactions in Conduit, allowing an attacker to check whether certain strings were present in the PDU before redaction

Jun 25, 2024
CVE-2024-6299
4.8 MEDIUM

Lack of consideration of key expiry when validating signatures in Conduit, allowing an attacker which has compromised an expired key to forge requests as the …

Jun 25, 2024
CVE-2024-5261
9.8 CRITICAL

Improper Certificate Validation vulnerability in LibreOffice "LibreOfficeKit" mode disables TLS certification verification LibreOfficeKit can be used for accessing LibreOffice functionality through C/C++. Typically this is …

Jun 25, 2024
CVE-2024-4846
6.3 MEDIUM

Authentication bypass in the 2FA feature in Devolutions Server 2024.1.14.0 and earlier allows an authenticated attacker to authenticate to another user without being asked for …

Jun 25, 2024
CVE-2024-31111
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Automattic WordPress allows Stored XSS.This issue affects WordPress: from 6.5 through …

Jun 25, 2024
CVE-2024-28832
4.8 MEDIUM

Stored XSS in the Crash Report page in Checkmk before versions 2.3.0p7, 2.2.0p28, 2.1.0p45, and 2.0.0 (EOL) allows users with permission to change Global Settings …

Jun 25, 2024
CVE-2024-28831
5.4 MEDIUM

Stored XSS in some confirmation pop-ups in Checkmk before versions 2.3.0p7 and 2.2.0p28 allows Checkmk users to execute arbitrary scripts by injecting HTML elements into …

Jun 25, 2024
CVE-2024-6307
6.4 MEDIUM

WordPress Core is vulnerable to Stored Cross-Site Scripting via the HTML API in various versions prior to 6.5.5 due to insufficient input sanitization and output …

Jun 25, 2024
CVE-2024-6306

Rejected reason: **REJECT** Accidental Reservation making this a duplicate. Please use CVE-2024-32111.

Jun 25, 2024
CVE-2024-6305

Rejected reason: **REJECT** Accidental Reservation making this a duplicate. Please use CVE-2024-31111.

Jun 25, 2024
CVE-2024-5216
7.5 HIGH

A vulnerability in mintplex-labs/anything-llm allows for a Denial of Service (DoS) condition due to uncontrolled resource consumption. Specifically, the issue arises from the application's failure …

Jun 25, 2024
CVE-2024-4641
6.3 MEDIUM

OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to accepting a format string from an external source as an …

Jun 25, 2024
CVE-2024-4640
7.1 HIGH

OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to missing bounds checking on buffer operations. An attacker could write …

Jun 25, 2024
CVE-2024-4639
7.1 HIGH

OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to a lack of neutralized inputs in IPSec configuration. An attacker …

Jun 25, 2024
CVE-2024-6028
9.8 CRITICAL

The Quiz Maker plugin for WordPress is vulnerable to time-based SQL Injection via the 'ays_questions' parameter in all versions up to, and including, 6.5.8.3 due …

Jun 25, 2024
CVE-2024-4638
7.1 HIGH

OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to a lack of neutralized inputs in the web key upload …

Jun 25, 2024
CVE-2024-34142
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to …

Jun 25, 2024
CVE-2024-34141
5.4 MEDIUM

Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to …

Jun 25, 2024
CVE-2024-3249
4.3 MEDIUM

The Zita Elementor Site Library plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the import_xml_data, xml_data_import, …

Jun 25, 2024
CVE-2024-5431
8.8 HIGH

The WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions …

Jun 25, 2024
CVE-2024-4759
5.5 MEDIUM

The Mime Types Extended WordPress plugin through 0.11 does not sanitise uploaded SVG files, which could allow users with a role as low as Author …

Jun 25, 2024
CVE-2024-4757
8.1 HIGH

The Logo Manager For Enamad WordPress plugin through 0.7.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, …

Jun 25, 2024
CVE-2024-6297
10.0 CRITICAL

Several plugins for WordPress hosted on WordPress.org have been compromised and injected with malicious PHP scripts. A malicious threat actor compromised the source code of …

Jun 25, 2024
CVE-2024-4197
9.9 CRITICAL

An unrestricted file upload vulnerability in Avaya IP Office was discovered that could allow remote command or code execution via the One-X component. Affected versions …

Jun 25, 2024
CVE-2024-4196
10.0 CRITICAL

An improper input validation vulnerability was discovered in Avaya IP Office that could allow remote command or code execution via a specially crafted web request …

Jun 25, 2024
CVE-2024-37007
7.8 HIGH

A maliciously crafted X_B and X_T file, when parsed in pskernel.DLL through Autodesk applications, can cause a use-after-free vulnerability. This vulnerability, along with other vulnerabilities, …

Jun 25, 2024
CVE-2024-37006
7.8 HIGH

A maliciously crafted CATPRODUCT file, when parsed in CC5Dll.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, …

Jun 25, 2024
CVE-2024-37005
7.8 HIGH

A maliciously crafted X_B file, when parsed in pskernel.DLL through Autodesk applications, can force an Out-of-Bound Read. A malicious actor can leverage this vulnerability to …

Jun 25, 2024
CVE-2024-37004
7.8 HIGH

A maliciously crafted SLDPRT file, when parsed in ASMKERN229A.dll through Autodesk applications, can cause a use-after-free vulnerability. This vulnerability, along with other vulnerabilities, could lead …

Jun 25, 2024
CVE-2024-37003
7.8 HIGH

A maliciously crafted DWG and SLDPRT file, when parsed in opennurbs.dll and ODXSW_DLL.dll through Autodesk applications, can be used to cause a Stack-based Overflow. A …

Jun 25, 2024
CVE-2024-36999
7.8 HIGH

A maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk applications, can force an Out-of-Bounds Write. A malicious actor can leverage this vulnerability to …

Jun 25, 2024
CVE-2024-32855
3.8 LOW

Dell Client Platform BIOS contains an Out-of-bounds Write vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this …

Jun 25, 2024
CVE-2024-23159
7.8 HIGH

A maliciously crafted STP file, when parsed in stp_aim_x64_vc15d.dll through Autodesk applications, can be used to uninitialized variables. This vulnerability, along with other vulnerabilities, can …

Jun 25, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.