CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-5847
8.8 HIGH

Use after free in PDFium in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. …

Jun 11, 2024
CVE-2024-5846
8.8 HIGH

Use after free in PDFium in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. …

Jun 11, 2024
CVE-2024-5845
8.8 HIGH

Use after free in Audio in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. …

Jun 11, 2024
CVE-2024-5844
8.8 HIGH

Heap buffer overflow in Tab Strip in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to perform an out of bounds memory read via …

Jun 11, 2024
CVE-2024-5843
6.5 MEDIUM

Inappropriate implementation in Downloads in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to obfuscate security UI via a malicious file. (Chromium security severity: …

Jun 11, 2024
CVE-2024-5842
8.8 HIGH

Use after free in Browser UI in Google Chrome prior to 126.0.6478.54 allowed a remote attacker who convinced a user to engage in specific UI …

Jun 11, 2024
CVE-2024-5841
8.8 HIGH

Use after free in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Jun 11, 2024
CVE-2024-5840
6.5 MEDIUM

Policy bypass in CORS in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium …

Jun 11, 2024
CVE-2024-5839
6.5 MEDIUM

Inappropriate Implementation in Memory Allocator in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Jun 11, 2024
CVE-2024-5838
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to perform out of bounds memory access via a crafted HTML …

Jun 11, 2024
CVE-2024-5837
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially perform out of bounds memory access via a crafted …

Jun 11, 2024
CVE-2024-5836
8.8 HIGH

Inappropriate Implementation in DevTools in Google Chrome prior to 126.0.6478.54 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary …

Jun 11, 2024
CVE-2024-5835
8.8 HIGH

Heap buffer overflow in Tab Groups in Google Chrome prior to 126.0.6478.54 allowed a remote attacker who convinced a user to engage in specific UI …

Jun 11, 2024
CVE-2024-5834
8.8 HIGH

Inappropriate implementation in Dawn in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security …

Jun 11, 2024
CVE-2024-5833
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially perform out of bounds memory access via a crafted …

Jun 11, 2024
CVE-2024-5832
8.8 HIGH

Use after free in Dawn in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Jun 11, 2024
CVE-2024-5831
8.8 HIGH

Use after free in Dawn in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Jun 11, 2024
CVE-2024-5830
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to perform an out of bounds memory write via a crafted …

Jun 11, 2024
CVE-2024-5646
6.4 MEDIUM

The Futurio Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘header_size’ attribute within the Advanced Text Block widget in all versions …

Jun 11, 2024
CVE-2024-4669
6.4 MEDIUM

The Events Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Basic Slider, Upcoming Events, and Schedule widgets in all …

Jun 11, 2024
CVE-2024-33606
8.8 HIGH

An attacker could retrieve sensitive files (medical images) as well as plant new medical images or overwrite existing medical images on a MicroDicom DICOM Viewer …

Jun 11, 2024
CVE-2024-28877
8.8 HIGH

MicroDicom DICOM Viewer is vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code on affected installations of DICOM Viewer. …

Jun 11, 2024
CVE-2023-4727
7.5 HIGH

A flaw was found in dogtag-pki and pki-core. The token authentication scheme can be bypassed with a LDAP injection. By passing the query string parameter …

Jun 11, 2024
CVE-2024-37301
7.2 HIGH

Document Merge Service is a document template merge service providing an API to manage templates and merge them with given data. Versions 6.5.1 and prior …

Jun 11, 2024
CVE-2024-36702
7.4 HIGH

libiec61850 v1.5 was discovered to contain a heap overflow via the BerEncoder_encodeLength function at /asn1/ber_encoder.c.

Jun 11, 2024
CVE-2024-35213
9.0 CRITICAL

An improper input validation vulnerability in the SGI Image Codec of QNX SDP version(s) 6.6, 7.0, and 7.1 could allow an attacker to potentially cause …

Jun 11, 2024
CVE-2024-34406
5.3 MEDIUM

Improper exception handling in McAfee Security: Antivirus VPN for Android before 8.3.0 could allow an attacker to cause a denial of service through the use …

Jun 11, 2024
CVE-2024-34405
9.1 CRITICAL

Improper deep link validation in McAfee Security: Antivirus VPN for Android before 8.3.0 could allow an attacker to launch an arbitrary URL within the app.

Jun 11, 2024
CVE-2024-28024
4.1 MEDIUM

A vulnerability exists in the FOXMAN-UN/UNEM in which sensitive information is stored in cleartext within a resource that might be accessible to another control sphere.

Jun 11, 2024
CVE-2024-28022
6.5 MEDIUM

A vulnerability exists in the UNEM server / APIGateway that if exploited allows a malicious user to perform an arbitrary number of authentication attempts using …

Jun 11, 2024
CVE-2024-28020
8.0 HIGH

A user/password reuse vulnerability exists in the FOXMAN-UN/UNEM application and server management. If exploited a malicious high-privileged user could use the passwords and login information …

Jun 11, 2024
CVE-2024-5851
3.5 LOW

A vulnerability classified as problematic has been found in playSMS up to 1.4.7. Affected is an unknown function of the file /index.php?app=main&inc=feature_schedule&op=list of the component …

Jun 11, 2024
CVE-2024-4190
8.1 HIGH

Stored Cross-Site Scripting (XSS) vulnerabilities have been identified in OpenText ArcSight Logger. The vulnerabilities could be remotely exploited.

Jun 11, 2024
CVE-2024-36821
6.8 MEDIUM

Insecure permissions in Linksys Velop WiFi 5 (WHW01v1) 1.1.13.202617 allows attackers to escalate privileges from Guest to root.

Jun 11, 2024
CVE-2024-37325
8.1 HIGH

Azure Science Virtual Machine (DSVM) Elevation of Privilege Vulnerability

Jun 11, 2024
CVE-2024-37293
7.5 HIGH

The AWS Deployment Framework (ADF) is a framework to manage and deploy resources across multiple AWS accounts and regions within an AWS Organization. ADF allows …

Jun 11, 2024
CVE-2024-35265
7.0 HIGH

Windows Perception Service Elevation of Privilege Vulnerability

Jun 11, 2024
CVE-2024-35263
5.7 MEDIUM

Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability

Jun 11, 2024
CVE-2024-35255
5.5 MEDIUM

Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability

Jun 11, 2024
CVE-2024-35254
7.1 HIGH

Azure Monitor Agent Elevation of Privilege Vulnerability

Jun 11, 2024
CVE-2024-35253
4.4 MEDIUM

Microsoft Azure File Sync Elevation of Privilege Vulnerability

Jun 11, 2024
CVE-2024-35252
7.5 HIGH

Azure Storage Movement Client Library Denial of Service Vulnerability

Jun 11, 2024
CVE-2024-35250
7.8 HIGH KEV

Windows Kernel-Mode Driver Elevation of Privilege Vulnerability

Jun 11, 2024
CVE-2024-35249
8.8 HIGH

Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability

Jun 11, 2024
CVE-2024-35248
7.3 HIGH

Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability

Jun 11, 2024
CVE-2024-34815
5.4 MEDIUM

Missing Authorization vulnerability in Javier Carazo Import and export users and customers import-users-from-csv-with-meta.This issue affects Import and export users and customers: from n/a through <= …

Jun 11, 2024
CVE-2024-34804
5.4 MEDIUM

Missing Authorization vulnerability in Tagembed.This issue affects Tagembed: from n/a through 5.8.

Jun 11, 2024
CVE-2024-34799
6.5 MEDIUM

Missing Authorization vulnerability in Repute Infosystems BookingPress.This issue affects BookingPress: from n/a through 1.0.82.

Jun 11, 2024
CVE-2024-34768
5.3 MEDIUM

Missing Authorization vulnerability in Fastly.This issue affects Fastly: from n/a through 1.2.25.

Jun 11, 2024
CVE-2024-34763
5.3 MEDIUM

Missing Authorization vulnerability in Saleswonder Team: Tobias Builder for WooCommerce reviews shortcodes – ReviewShort woo-product-reviews-shortcode.This issue affects Builder for WooCommerce reviews shortcodes – ReviewShort: from …

Jun 11, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.