CVE Database

38969+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-34659
7.5 HIGH

Exposure of sensitive information in GroupSharing prior to version 13.6.13.3 allows remote attackers can force the victim to join the group.

Sep 4, 2024
CVE-2024-34657
8.6 HIGH

Stack-based out-of-bounds write in Samsung Notes prior to version 4.4.21.62 allows remote attackers to execute arbitrary code.

Sep 4, 2024
CVE-2024-34656
7.3 HIGH

Path traversal in Samsung Notes prior to version 4.4.21.62 allows local attackers to execute arbitrary code.

Sep 4, 2024
CVE-2024-39921
7.5 HIGH

Observable timing discrepancy issue exists in IPCOM EX2 Series V01L02NF0001 to V01L06NF0401, V01L20NF0001 to V01L20NF0401, V02L20NF0001 to V02L21NF0301, and IPCOM VE2 Series V01L04NF0001 to V01L06NF0112. …

Sep 4, 2024
CVE-2024-41716
8.1 HIGH

Cleartext storage of sensitive information vulnerability exists in WindLDR and WindO/I-NV4. If this vulnerability is exploited, an attacker who obtained the product's project file may …

Sep 4, 2024
CVE-2024-8362
8.8 HIGH

Use after free in WebAudio in Google Chrome prior to 128.0.6613.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Sep 3, 2024
CVE-2024-7970
8.8 HIGH

Out of bounds write in V8 in Google Chrome prior to 128.0.6613.119 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

Sep 3, 2024
CVE-2024-45394
8.8 HIGH

Authenticator is a browser extension that generates two-step verification codes. In versions 7.0.0 and below, encryption keys for user data were stored encrypted at-rest using …

Sep 3, 2024
CVE-2024-45391
7.5 HIGH

Tina is an open-source content management system (CMS). Sites building with Tina CMS's command line interface (CLI) prior to version 1.6.2 that use a search …

Sep 3, 2024
CVE-2024-45390
7.3 HIGH

@blakeembrey/template is a string template library. Prior to version 1.2.0, it is possible to inject and run code within the template if the attacker has …

Sep 3, 2024
CVE-2024-45307
8.8 HIGH

SudoBot, a Discord moderation bot, is vulnerable to privilege escalation and exploit of the `-config` command in versions prior to 9.26.7. Anyone is theoretically able …

Sep 3, 2024
CVE-2024-41436
7.5 HIGH

ClickHouse v24.3.3.102 was discovered to contain a buffer overflow via the component DB::evaluateConstantExpressionImpl.

Sep 3, 2024
CVE-2024-41435
7.5 HIGH

YugabyteDB v2.21.1.0 was discovered to contain a buffer overflow via the "insert into" parameter.

Sep 3, 2024
CVE-2024-42902
8.8 HIGH

An issue in the js_localize.php function of LimeSurvey v6.6.2 and before allows attackers to execute arbitrary code via injecting a crafted payload into the lng …

Sep 3, 2024
CVE-2024-38456
7.8 HIGH

HIGH-LEIT V05.08.01.03 and HIGH-LEIT V04.25.00.00 to 4.25.01.01 for Windows from Vivavis contain an insecure file and folder permissions vulnerability in prunsrv.exe. A regular user (non-admin) …

Sep 3, 2024
CVE-2023-49233
8.8 HIGH

Insufficient access checks in Visual Planning Admin Center 8 before v.1 Build 240207 allow attackers in possession of a non-administrative Visual Planning account to utilize …

Sep 3, 2024
CVE-2024-6119
7.5 HIGH

Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination …

Sep 3, 2024
CVE-2024-42991
8.1 HIGH

MCMS v5.4.1 has front-end file upload vulnerability which can lead to remote command execution.

Sep 3, 2024
CVE-2024-7654
8.3 HIGH

An ActiveMQ Discovery service was reachable by default from an OpenEdge Management installation when an OEE/OEM auto-discovery feature was activated. Unauthorized access to the discovery …

Sep 3, 2024
CVE-2024-7346
7.2 HIGH

Host name validation for TLS certificates is bypassed when the installed OpenEdge default certificates are used to perform the TLS handshake for a networked connection. …

Sep 3, 2024
CVE-2024-7345
8.3 HIGH

Local ABL Client bypass of the required PASOE security checks may allow an attacker to commit unauthorized code injection into Multi-Session Agents on supported OpenEdge …

Sep 3, 2024
CVE-2024-8383
7.5 HIGH

Firefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that the browser does not support. It …

Sep 3, 2024
CVE-2024-8382
8.8 HIGH

Internal browser event interfaces were exposed to web content when privileged EventHandler listener callbacks ran for those events. Web content that tried to use those …

Sep 3, 2024
CVE-2024-6232
7.5 HIGH

There is a MEDIUM severity vulnerability affecting CPython. Regular expressions that allowed excessive backtracking during tarfile.TarFile header parsing are vulnerable to ReDoS via specifically-crafted tar …

Sep 3, 2024
CVE-2024-6473
7.8 HIGH

Yandex Browser for Desktop before 24.7.1.380 has a DLL Hijacking Vulnerability because an untrusted search path is used.

Sep 3, 2024
CVE-2024-45588
8.1 HIGH

This vulnerability exists in Symphony XTS Web Trading platform version 2.0.0.1_P160 due to improper access controls on APIs in the Preference module of the application. …

Sep 3, 2024
CVE-2024-8374
7.8 HIGH

UltiMaker Cura slicer versions 5.7.0-beta.1 through 5.7.2 are vulnerable to code injection via the 3MF format reader (/plugins/ThreeMFReader.py). The vulnerability arises from improper handling of …

Sep 3, 2024
CVE-2024-45587
8.8 HIGH

This vulnerability exists in Symphony XTS Web Trading platform version 2.0.0.1_P160 due to improper access controls on APIs in the Transaction module of vulnerable application. …

Sep 3, 2024
CVE-2024-45586
8.8 HIGH

This vulnerability exists due to improper access controls on APIs in the Authentication module of Symphony XTS Web Trading and Mobile Trading platforms (version 2.0.0.1_P160). …

Sep 3, 2024
CVE-2024-3655
7.8 HIGH

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel …

Sep 3, 2024
CVE-2024-38811
8.8 HIGH

VMware Fusion (13.x before 13.6) contains a code-execution vulnerability due to the usage of an insecure environment variable. A malicious actor with standard user privileges …

Sep 3, 2024
CVE-2024-7203
7.2 HIGH

A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.60 through V5.38 and USG FLEX series firmware versions from V4.60 through V5.38 …

Sep 3, 2024
CVE-2024-5412
7.5 HIGH

A buffer overflow vulnerability in the library "libclinkc" of the Zyxel VMG8825-T50K firmware version 5.50(ABOM.8)C0 could allow an unauthenticated attacker to cause denial of service …

Sep 3, 2024
CVE-2024-42060
7.2 HIGH

A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG …

Sep 3, 2024
CVE-2024-42059
7.2 HIGH

A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V5.00 through V5.38, USG FLEX series firmware versions from V5.00 through V5.38, USG …

Sep 3, 2024
CVE-2024-42058
7.5 HIGH

A null pointer dereference vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, USG …

Sep 3, 2024
CVE-2024-42057
8.1 HIGH

A command injection vulnerability in the IPSec VPN feature of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from …

Sep 3, 2024
CVE-2024-1621
7.5 HIGH

The registration process of uniFLOW Online (NT-ware product) apps, prior to and including version 2024.1.0, can be compromised when email login is enabled on the …

Sep 2, 2024
CVE-2024-6921
7.5 HIGH

Cleartext Storage of Sensitive Information vulnerability in NAC Telecommunication Systems Inc. NACPremium allows Retrieve Embedded Sensitive Data.This issue affects NACPremium: through 01082024.

Sep 2, 2024
CVE-2024-45388
7.5 HIGH

Hoverfly is a lightweight service virtualization/ API simulation / API mocking tool for developers and testers. The `/api/v2/simulation` POST handler allows users to create new …

Sep 2, 2024
CVE-2024-45311
7.5 HIGH

Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. As of quinn-proto 0.11, it is possible for a server to `accept()`, `retry()`, …

Sep 2, 2024
CVE-2024-42471
7.3 HIGH

actions/artifact is the GitHub ToolKit for developing GitHub Actions. Versions of `actions/artifact` on the 2.x branch before 2.1.2 are vulnerable to arbitrary file write when …

Sep 2, 2024
CVE-2024-28100
8.9 HIGH

eLabFTW is an open source electronic lab notebook for research labs. By uploading specially crafted files, a regular user can create a circumstance where a …

Sep 2, 2024
CVE-2024-8004
8.7 HIGH

A stored Cross-site Scripting (XSS) vulnerability affecting ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary …

Sep 2, 2024
CVE-2024-7939
8.7 HIGH

A stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser …

Sep 2, 2024
CVE-2024-7938
8.7 HIGH

A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script …

Sep 2, 2024
CVE-2024-7932
8.7 HIGH

A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer on Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser …

Sep 2, 2024
CVE-2024-5148
7.5 HIGH

A flaw was found in the gnome-remote-desktop package. The gnome-remote-desktop system daemon performs inadequate validation of session agents using D-Bus methods related to transitioning a …

Sep 2, 2024
CVE-2024-38402
7.8 HIGH

Memory corruption while processing IOCTL call for getting group info.

Sep 2, 2024
CVE-2024-38401
7.8 HIGH

Memory corruption while processing concurrent IOCTL calls.

Sep 2, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.