CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-25970
6.5 MEDIUM

Dell PowerScale OneFS versions 8.2.x through 9.7.0.1 contains an improper input validation vulnerability. A low privileged remote attacker could potentially exploit this vulnerability, leading to …

May 14, 2024
CVE-2024-25969
6.2 MEDIUM

Dell PowerScale OneFS versions 8.2.x through 9.7.0.1 contains an allocation of resources without limits or throttling vulnerability. A local unauthenticated attacker could potentially exploit this …

May 14, 2024
CVE-2024-25968
5.9 MEDIUM

Dell PowerScale OneFS versions 8.2.x through 9.7.0.2 contains a use of a broken or risky cryptographic algorithm vulnerability. A remote unauthenticated attacker could potentially exploit …

May 14, 2024
CVE-2024-25967
6.7 MEDIUM

Dell PowerScale OneFS versions 8.2.x through 9.7.0.1 contains an execution with unnecessary privileges vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading …

May 14, 2024
CVE-2024-25966
5.3 MEDIUM

Dell PowerScale OneFS versions 8.2.x through 9.7.0.2 contains an improper handling of unexpected data type vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, …

May 14, 2024
CVE-2024-25965
6.1 MEDIUM

Dell PowerScale OneFS versions 8.2.x through 9.7.0.2 contains an external control of file name or path vulnerability. A local high privilege attacker could potentially exploit …

May 14, 2024
CVE-2024-22270
7.1 HIGH

VMware Workstation and Fusion contain an information disclosure vulnerability in the Host Guest File Sharing (HGFS) functionality. A malicious actor with local administrative privileges on …

May 14, 2024
CVE-2024-22269
7.1 HIGH

VMware Workstation and Fusion contain an information disclosure vulnerability in the vbluetooth device. A malicious actor with local administrative privileges on a virtual machine may …

May 14, 2024
CVE-2024-22268
7.1 HIGH

VMware Workstation and Fusion contain a heap buffer-overflow vulnerability in the Shader functionality. A malicious actor with non-administrative access to a virtual machine with 3D …

May 14, 2024
CVE-2024-22267
9.3 CRITICAL

VMware Workstation and Fusion contain a use-after-free vulnerability in the vbluetooth device. A malicious actor with local administrative privileges on a virtual machine may exploit …

May 14, 2024
CVE-2024-1914
6.5 MEDIUM

An attacker who successfully exploited these vulnerabilities could cause the robot to stop, make the robot controller inaccessible. The vulnerability could potentially be exploited to …

May 14, 2024
CVE-2024-1913
7.6 HIGH

An attacker who successfully exploited these vulnerabilities could cause the robot to stop, make the robot controller inaccessible, or execute arbitrary code. The vulnerability could …

May 14, 2024
CVE-2024-1628
8.4 HIGH

OS command injection vulnerabilities in GE HealthCare ultrasound devices

May 14, 2024
CVE-2024-1598
7.5 HIGH

Potential buffer overflow in unsafe UEFI variable handling in Phoenix SecureCore™ for Intel Gemini Lake.This issue affects: SecureCore™ for Intel Gemini Lake: from 4.1.0.1 before …

May 14, 2024
CVE-2024-1486
7.4 HIGH

Elevation of privileges via misconfigured access control list in GE HealthCare ultrasound devices

May 14, 2024
CVE-2024-0870
5.3 MEDIUM

The YITH WooCommerce Gift Cards plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_mail_status' and …

May 14, 2024
CVE-2024-0762
7.5 HIGH

Potential buffer overflow in unsafe UEFI variable handling in Phoenix SecureCore™ for select Intel platforms This issue affects: Phoenix SecureCore™ for Intel Kaby Lake: from …

May 14, 2024
CVE-2023-6812
4.3 MEDIUM

The WP Compress – Image Optimizer [All-In-One plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 6.20.01. This is …

May 14, 2024
CVE-2023-46280
6.5 MEDIUM

A vulnerability has been identified in Security Configuration Tool (SCT) (All versions), SIMATIC Automation Tool (All versions < V5.0 SP2), SIMATIC BATCH V9.1 (All versions …

May 14, 2024
CVE-2023-35841
7.8 HIGH

Exposed IOCTL with Insufficient Access Control in Phoenix WinFlash Driver on Windows allows Privilege Escalation which allows for modification of system firmware.This issue affects WinFlash …

May 14, 2024
CVE-2024-4855
3.6 LOW

Use after free issue in editcap could cause denial of service via crafted capture file

May 14, 2024
CVE-2024-4854
6.4 MEDIUM

MONGO and ZigBee TLV dissector infinite loops in Wireshark 4.2.0 to 4.2.4, 4.0.0 to 4.0.14, and 3.6.0 to 3.6.22 allow denial of service via packet …

May 14, 2024
CVE-2024-4853
3.6 LOW

Memory handling issue in editcap could cause denial of service via crafted capture file

May 14, 2024
CVE-2024-4840
5.5 MEDIUM

An flaw was found in the OpenStack Platform (RHOSP) director, a toolset for installing and managing a complete RHOSP environment. Plaintext passwords may be stored …

May 14, 2024
CVE-2024-4825
9.8 CRITICAL

A vulnerability has been discovered in Agentejo Cockpit CMS v0.5.5 that consists in an arbitrary file upload in ‘/media/api’ parameter via post request. An attacker …

May 14, 2024
CVE-2024-4824
9.8 CRITICAL

Vulnerability in School ERP Pro+Responsive 1.0 that allows SQL injection through the '/SchoolERP/office_admin/' index in the parameters groups_id, examname, classes_id, es_voucherid, es_class, etc. This vulnerability …

May 14, 2024
CVE-2024-4823
6.5 MEDIUM

Vulnerability in School ERP Pro+Responsive 1.0 that allows XSS via the index '/schoolerp/office_admin/' in the parameters es_bankacc, es_bank_name, es_bank_pin, es_checkno, es_teller_number, dc1 and dc2. An …

May 14, 2024
CVE-2024-4822
6.5 MEDIUM

Vulnerability in School ERP Pro+Responsive 1.0 that allows XSS via the username and password parameters in '/index.php'. This vulnerability allows an attacker to partially take …

May 14, 2024
CVE-2024-4820
6.3 MEDIUM

A vulnerability was found in SourceCodester Online Computer and Laptop Store 1.0. It has been declared as critical. Affected by this vulnerability is an unknown …

May 14, 2024
CVE-2024-4819
4.3 MEDIUM

A vulnerability was found in Campcodes Online Laundry Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file …

May 14, 2024
CVE-2024-4818
5.3 MEDIUM

A vulnerability was found in Campcodes Online Laundry Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /index.php. …

May 14, 2024
CVE-2024-4817
6.3 MEDIUM

A vulnerability has been found in Campcodes Online Laundry Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file manage_user.php …

May 14, 2024
CVE-2024-4816
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Ruijie RG-UAC up to 20240506. This affects an unknown part of the file /view/networkConfig/GRE/gre_add_commit.php. The …

May 14, 2024
CVE-2024-4815
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Ruijie RG-UAC up to 20240506. Affected by this issue is some unknown functionality of …

May 14, 2024
CVE-2024-4814
6.3 MEDIUM

A vulnerability classified as critical was found in Ruijie RG-UAC up to 20240506. Affected by this vulnerability is an unknown functionality of the file /view/networkConfig/RouteConfig/StaticRoute/static_route_edit_commit.php. …

May 14, 2024
CVE-2024-4813
6.3 MEDIUM

A vulnerability classified as critical has been found in Ruijie RG-UAC up to 20240506. Affected is an unknown function of the file /view/networkConfig/physicalInterface/interface_commit.php. The manipulation …

May 14, 2024
CVE-2024-4809
6.3 MEDIUM

A vulnerability has been found in SourceCodester Open Source Clinic Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality …

May 14, 2024
CVE-2024-4808
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Kashipara College Management System 1.0. Affected is an unknown function of the file delete_faculty.php. The …

May 14, 2024
CVE-2024-4807
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Kashipara College Management System 1.0. This issue affects some unknown processing of the file …

May 14, 2024
CVE-2024-4806
6.3 MEDIUM

A vulnerability classified as critical was found in Kashipara College Management System 1.0. This vulnerability affects unknown code of the file each_extracurricula_activities.php. The manipulation of …

May 14, 2024
CVE-2024-4805
6.3 MEDIUM

A vulnerability classified as critical has been found in Kashipara College Management System 1.0. This affects an unknown part of the file edit_faculty.php. The manipulation …

May 14, 2024
CVE-2024-4804
6.3 MEDIUM

A vulnerability was found in Kashipara College Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

May 14, 2024
CVE-2024-4803
6.3 MEDIUM

A vulnerability was found in Kashipara College Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

May 14, 2024
CVE-2024-4802
6.3 MEDIUM

A vulnerability was found in Kashipara College Management System 1.0. It has been classified as critical. Affected is an unknown function of the file submit_extracurricular_activity.php. …

May 14, 2024
CVE-2024-4801
6.3 MEDIUM

A vulnerability was found in Kashipara College Management System 1.0 and classified as critical. This issue affects some unknown processing of the file submit_new_faculty.php. The …

May 14, 2024
CVE-2024-4800
6.3 MEDIUM

A vulnerability has been found in Kashipara College Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file submit_student.php. The …

May 14, 2024
CVE-2024-4799
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Kashipara College Management System 1.0. This affects an unknown part of the file view_each_faculty.php. The …

May 14, 2024
CVE-2024-4798
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Online Computer and Laptop Store 1.0. Affected by this issue is some unknown …

May 14, 2024
CVE-2024-4797
3.5 LOW

A vulnerability was found in Campcodes Online Laundry Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file …

May 14, 2024
CVE-2024-4796
6.3 MEDIUM

A vulnerability was found in Campcodes Online Laundry Management System 1.0. It has been classified as critical. This affects an unknown part of the file …

May 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.