CVE Database

38969+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-42340
8.3 HIGH

CyberArk - CWE-602: Client-Side Enforcement of Server-Side Security

Aug 25, 2024
CVE-2024-45240
7.4 HIGH

The TikTok (aka com.zhiliaoapp.musically) application before 34.5.5 for Android allows the takeover of Lynxview JavaScript interfaces via deeplink traversal (in the application's exposed WebView). (On …

Aug 24, 2024
CVE-2024-45239
7.5 HIGH

An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) …

Aug 24, 2024
CVE-2024-45238
7.5 HIGH

An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) …

Aug 24, 2024
CVE-2024-45236
7.5 HIGH

An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) …

Aug 24, 2024
CVE-2024-45235
7.5 HIGH

An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) …

Aug 24, 2024
CVE-2024-45234
7.5 HIGH

An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) …

Aug 24, 2024
CVE-2024-7656
8.8 HIGH

The Image Hotspot by DevVN plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.2.5 via deserialization of …

Aug 24, 2024
CVE-2024-7351
7.2 HIGH

The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.12.3 via deserialization of untrusted …

Aug 24, 2024
CVE-2024-45187
7.1 HIGH

Guest users in the Mage AI framework that remain logged in after their accounts are deleted, are mistakenly given high privileges and specifically given access …

Aug 23, 2024
CVE-2024-42845
8.0 HIGH

An eval Injection vulnerability in the component invesalius/reader/dicom.py of InVesalius 3.1.99991 through 3.1.99998 allows attackers to execute arbitrary code via loading a crafted DICOM file.

Aug 23, 2024
CVE-2024-44390
8.8 HIGH

Tenda FH1206 V1.2.0.8(8155)_EN contains a Buffer Overflow vulnerability via the function formWrlsafeset.

Aug 23, 2024
CVE-2024-39841
8.8 HIGH

A SQL Injection vulnerability exists in the service configuration functionality in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before …

Aug 23, 2024
CVE-2024-44386
7.3 HIGH

Tenda FH1206 V1.2.0.8(8155)_EN contains a Buffer Overflow vulnerability via the function fromSetIpBind.

Aug 23, 2024
CVE-2024-42756
8.8 HIGH

An issue in Netgear DGN1000WW v.1.1.00.45 allows a remote attacker to execute arbitrary code via the Diagnostics page

Aug 23, 2024
CVE-2024-42636
7.2 HIGH

DedeCMS V5.7.115 has a command execution vulnerability via file_manage_view.php?fmdo=newfile&activepath.

Aug 23, 2024
CVE-2024-42523
7.2 HIGH

publiccms V4.0.202302.e and before is vulnerable to Any File Upload via publiccms/admin/cmsTemplate/saveMetaData

Aug 23, 2024
CVE-2024-43791
7.8 HIGH

RequestStore provides per-request global storage for Rack. The files published as part of request_store 1.3.2 have 0666 permissions, meaning that they are world-writable, which allows …

Aug 23, 2024
CVE-2024-43782
7.7 HIGH

This openedx-translations repository contains translation files from Open edX repositories to be kept in sync with Transifex. Before moving to pulling translations from the openedx-translations …

Aug 23, 2024
CVE-2024-42915
8.0 HIGH

A host header injection vulnerability in Staff Appraisal System v1.0 allows attackers to obtain the password reset token via user interaction with a crafted password …

Aug 23, 2024
CVE-2024-42040
8.1 HIGH

Buffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from its initial commit in 2002 (3861aa5) up to today on any platform allows an attacker …

Aug 23, 2024
CVE-2024-38869
8.3 HIGH

Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability in remote office deploy configurations.This issue affects Endpoint Central: before 11.3.2416.04 and before 11.3.2400.25.

Aug 23, 2024
CVE-2024-37311
8.2 HIGH

Collabora Online is a collaborative online office suite based on LibreOffice. In affected versions of Collabora Online, https connections from coolwsd to other hosts may …

Aug 23, 2024
CVE-2024-5586
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injection in extranet lockouts report option.

Aug 23, 2024
CVE-2024-5556
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in reports module.

Aug 23, 2024
CVE-2024-5490
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in aggregate reports option.

Aug 23, 2024
CVE-2024-5467
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injection in account lockout report.

Aug 23, 2024
CVE-2024-5466
8.8 HIGH

Zohocorp ManageEngine OpManager and Remote Monitoring and Management versions 128329 and below are vulnerable to the authenticated remote code execution in the deploy agent option.

Aug 23, 2024
CVE-2024-36517
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in alerts module.

Aug 23, 2024
CVE-2024-36516
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in dashboard. Note: This vulnerability is different from another vulnerability (CVE-2024-36515), …

Aug 23, 2024
CVE-2024-36515
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in dashboard. Note: This vulnerability is different from another vulnerability (CVE-2024-36516), …

Aug 23, 2024
CVE-2024-36514
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8000 are vulnerable to the authenticated SQL injection in file summary option.

Aug 23, 2024
CVE-2024-43883
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: usb: vhci-hcd: Do not drop references before new references are gained At a few places …

Aug 23, 2024
CVE-2024-7986
7.5 HIGH

A vulnerability exists in the Rockwell Automation ThinManager® ThinServer that allows a threat actor to disclose sensitive information. A threat actor can exploit this vulnerability …

Aug 23, 2024
CVE-2024-7258
8.8 HIGH

The WooCommerce Google Feed Manager plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'wppfm_removeFeedFile' function …

Aug 23, 2024
CVE-2024-7559
8.8 HIGH

The File Manager Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and capability checks in the mk_file_folder_manager …

Aug 23, 2024
CVE-2024-43477
7.5 HIGH

Improper access control in Decentralized Identity Services resulted in a vulnerability that allows an unauthenticated attacker to disable Verifiable ID's on another tenant.

Aug 23, 2024
CVE-2024-8086
7.3 HIGH

A vulnerability has been found in SourceCodester E-Commerce System 1.0 and classified as critical. This vulnerability affects unknown code of the file /ecommerce/admin/login.php of the …

Aug 22, 2024
CVE-2024-38210
7.8 HIGH

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Aug 22, 2024
CVE-2024-38209
7.8 HIGH

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Aug 22, 2024
CVE-2024-8081
7.3 HIGH

A vulnerability classified as critical was found in itsourcecode Payroll Management System 1.0. Affected by this vulnerability is an unknown functionality of the file login.php. …

Aug 22, 2024
CVE-2024-8079
8.8 HIGH

A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.862_B20230228. It has been rated as critical. This issue affects the function exportOvpn. The manipulation leads to …

Aug 22, 2024
CVE-2024-8078
8.8 HIGH

A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.862_B20230228. It has been declared as critical. This vulnerability affects the function setTracerouteCfg. The manipulation leads to …

Aug 22, 2024
CVE-2023-7260
7.5 HIGH

Path Traversal vulnerability discovered in OpenText™ CX-E Voice, affecting all version through 22.4. The vulnerability could allow arbitrarily access files on the system.

Aug 22, 2024
CVE-2024-8076
8.8 HIGH

A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.862_B20230228 and classified as critical. Affected by this issue is the function setDiagnosisCfg. The manipulation leads to …

Aug 22, 2024
CVE-2024-45201
8.8 HIGH

An issue was discovered in llama_index before 0.10.38. download/integration.py includes an exec call for import {cls_name}.

Aug 22, 2024
CVE-2024-42599
8.8 HIGH

SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_files.php imposes restrictions on edited files, attackers can still …

Aug 22, 2024
CVE-2024-42418
7.5 HIGH

Avtec Outpost uses a default cryptographic key that can be used to decrypt sensitive information.

Aug 22, 2024
CVE-2024-39776
7.5 HIGH

Avtec Outpost stores sensitive information in an insecure location without proper access controls in place.

Aug 22, 2024
CVE-2024-39717
7.2 HIGH KEV

The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user …

Aug 22, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.