CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-31480
5.3 MEDIUM

Unauthenticated Denial of Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability …

May 14, 2024
CVE-2024-31479
5.3 MEDIUM

Unauthenticated Denial of Service (DoS) vulnerabilities exist in the Central Communications service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the …

May 14, 2024
CVE-2024-31478
5.3 MEDIUM

Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exists in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilites result in the ability …

May 14, 2024
CVE-2024-31477
7.2 HIGH

Multiple authenticated command injection vulnerabilities exist in the command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as …

May 14, 2024
CVE-2024-31476
7.2 HIGH

Multiple authenticated command injection vulnerabilities exist in the command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as …

May 14, 2024
CVE-2024-31475
8.2 HIGH

There is an arbitrary file deletion vulnerability in the Central Communications service accessed by PAPI (Aruba's access point management protocol). Successful exploitation of this vulnerability …

May 14, 2024
CVE-2024-31474
8.2 HIGH

There is an arbitrary file deletion vulnerability in the CLI service accessed by PAPI (Aruba's Access Point management protocol). Successful exploitation of this vulnerability results …

May 14, 2024
CVE-2024-31473
9.8 CRITICAL

There is a command injection vulnerability in the underlying deauthentication service that could lead to unauthenticated remote code execution by sending specially crafted packets destined …

May 14, 2024
CVE-2024-31472
9.8 CRITICAL

There are command injection vulnerabilities in the underlying Soft AP Daemon service that could lead to unauthenticated remote code execution by sending specially crafted packets …

May 14, 2024
CVE-2024-31471
9.8 CRITICAL

There is a command injection vulnerability in the underlying Central Communications service that could lead to unauthenticated remote code execution by sending specially crafted packets …

May 14, 2024
CVE-2024-31470
9.8 CRITICAL

There is a buffer overflow vulnerability in the underlying SAE (Simultaneous Authentication of Equals) service that could lead to unauthenticated remote code execution by sending …

May 14, 2024
CVE-2024-31469
9.8 CRITICAL

There are buffer overflow vulnerabilities in the underlying Central Communications service that could lead to unauthenticated remote code execution by sending specially crafted packets destined …

May 14, 2024
CVE-2024-31468
9.8 CRITICAL

There are buffer overflow vulnerabilities in the underlying Central Communications service that could lead to unauthenticated remote code execution by sending specially crafted packets destined …

May 14, 2024
CVE-2024-31467
9.8 CRITICAL

There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to …

May 14, 2024
CVE-2024-35175
5.3 MEDIUM

sshpiper is a reverse proxy for sshd. Starting in version 1.0.50 and prior to version 1.3.0, the way the proxy protocol listener is implemented in …

May 14, 2024
CVE-2024-31466
9.8 CRITICAL

There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to …

May 14, 2024
CVE-2023-33327
8.8 HIGH

Improper Privilege Management vulnerability in Teplitsa of social technologies Leyka allows Privilege Escalation.This issue affects Leyka: from n/a through 3.30.2.

May 14, 2024
CVE-2024-4562
5.4 MEDIUM

In WhatsUp Gold versions released before 2023.1.2 , an SSRF vulnerability exists in Whatsup Gold's Issue exists in the HTTP Monitoring functionality. Due to the …

May 14, 2024
CVE-2024-4561
4.2 MEDIUM

In WhatsUp Gold versions released before 2023.1.2 , a blind SSRF vulnerability exists in Whatsup Gold's FaviconController that allows an attacker to send arbitrary HTTP …

May 14, 2024
CVE-2024-3044
6.5 MEDIUM

Unchecked script execution in Graphic on-click binding in affected LibreOffice versions allows an attacker to create a document which without prompt will execute scripts built-into …

May 14, 2024
CVE-2024-31556
7.8 HIGH

An issue in Reportico Web before v.8.1.0 allows a local attacker to execute arbitrary code and obtain sensitive information via the sessionid function.

May 14, 2024
CVE-2022-28132
7.2 HIGH

The T-Soft E-Commerce 4 web application is susceptible to SQL injection (SQLi) attacks when authenticated as an admin or privileged user. This vulnerability allows attackers …

May 14, 2024
CVE-2020-26312
8.1 HIGH

Dotmesh is a git-like command-line interface for capturing, organizing and sharing application states. In versions 0.8.1 and prior, the unsafe handling of symbolic links in …

May 14, 2024
CVE-2024-32465
7.3 HIGH

Git is a revision control system. The Git project recommends to avoid working in untrusted repositories, and instead to clone it first with `git clone …

May 14, 2024
CVE-2024-32021
3.9 LOW

Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, when cloning a local source repository that contains …

May 14, 2024
CVE-2021-22280
7.2 HIGH

Improper DLL loading algorithms in B&R Automation Studio versions >=4.0 and <4.12 may allow an authenticated local attacker to execute code in the context of …

May 14, 2024
CVE-2024-3676
7.5 HIGH

The Proofpoint Encryption endpoint of Proofpoint Enterprise Protection contains an Improper Input Validation vulnerability that allows an unauthenticated remote attacker with a specially crafted HTTP …

May 14, 2024
CVE-2024-32020
3.9 LOW

Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, local clones may end up hardlinking files into …

May 14, 2024
CVE-2024-32004
8.1 HIGH

Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, an attacker can prepare a local repository in …

May 14, 2024
CVE-2024-32002
9.0 CRITICAL

Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, repositories with submodules can be crafted in a …

May 14, 2024
CVE-2024-2637
7.2 HIGH

An Uncontrolled Search Path Element vulnerability in B&R Industrial Automation Scene Viewer, B&R Industrial Automation Automation Runtime, B&R Industrial Automation mapp Vision, B&R Industrial Automation …

May 14, 2024
CVE-2024-0862
5.0 MEDIUM

The Proofpoint Encryption endpoint of Proofpoint Enterprise Protection contains a Server-Side Request Forgery vulnerability that allows an authenticated user to relay HTTP requests from the …

May 14, 2024
CVE-2024-4778
9.8 CRITICAL

Memory safety bugs present in Firefox 125. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of …

May 14, 2024
CVE-2024-4777
8.8 HIGH

Memory safety bugs present in Firefox 125, Firefox ESR 115.10, and Thunderbird 115.10. Some of these bugs showed evidence of memory corruption and we presume …

May 14, 2024
CVE-2024-4776
8.2 HIGH

A file dialog shown while in full-screen mode could have resulted in the window remaining disabled. This vulnerability affects Firefox < 126.

May 14, 2024
CVE-2024-4775
5.9 MEDIUM

An iterator stop condition was missing when handling WASM code in the built-in profiler, potentially leading to invalid memory access and undefined behavior. *Note:* This …

May 14, 2024
CVE-2024-4774
6.5 MEDIUM

The `ShmemCharMapHashEntry()` code was susceptible to potentially undefined behavior by bypassing the move semantics for one of its data members. This vulnerability affects Firefox < …

May 14, 2024
CVE-2024-4773
7.5 HIGH

When a network error occurred during page load, the prior content could have remained in view with a blank URL bar. This could have been …

May 14, 2024
CVE-2024-4772
5.9 MEDIUM

An HTTP digest authentication nonce value was generated using `rand()` which could lead to predictable values. This vulnerability affects Firefox < 126.

May 14, 2024
CVE-2024-4771
8.6 HIGH

A memory allocation check was missing which would lead to a use-after-free if the allocation failed. This could have triggered a crash or potentially be …

May 14, 2024
CVE-2024-4770
8.8 HIGH

When saving a page to PDF, certain font styles could have led to a potential use-after-free crash. This vulnerability affects Firefox < 126, Firefox ESR …

May 14, 2024
CVE-2024-4769
5.9 MEDIUM

When importing resources using Web Workers, error messages would distinguish the difference between `application/javascript` responses and non-script responses. This could have been abused to learn …

May 14, 2024
CVE-2024-4768
6.1 MEDIUM

A bug in popup notifications' interaction with WebAuthn made it easier for an attacker to trick a user into granting permissions. This vulnerability affects Firefox …

May 14, 2024
CVE-2024-4767
4.3 MEDIUM

If the `browser.privatebrowsing.autostart` preference is enabled, IndexedDB files were not properly deleted when the window was closed. This preference is disabled by default in Firefox. …

May 14, 2024
CVE-2024-4766
4.3 MEDIUM

Different techniques existed to obscure the fullscreen notification in Firefox for Android. These could have led to potential user confusion and spoofing attacks. *This bug …

May 14, 2024
CVE-2024-4765
8.1 HIGH

Web application manifests were stored by using an insecure MD5 hash which allowed for a hash collision to overwrite another application's manifest. This could have …

May 14, 2024
CVE-2024-4764
9.8 CRITICAL

Multiple WebRTC threads could have claimed a newly connected audio input leading to use-after-free. This vulnerability affects Firefox < 126.

May 14, 2024
CVE-2024-4367
8.8 HIGH

A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < …

May 14, 2024
CVE-2024-33485
9.8 CRITICAL

SQL Injection vulnerability in CASAP Automated Enrollment System using PHP/MySQLi with Source Code V1.0 allows a remote attacker to obtain sensitive information via a crafted …

May 14, 2024
CVE-2024-27110
8.4 HIGH

Elevation of privilege vulnerability in GE HealthCare EchoPAC products

May 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.