CVE Database

38971+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-39776
7.5 HIGH

Avtec Outpost stores sensitive information in an insecure location without proper access controls in place.

Aug 22, 2024
CVE-2024-39717
7.2 HIGH KEV

The Versa Director GUI provides an option to customize the look and feel of the user interface. This option is only available for a user …

Aug 22, 2024
CVE-2024-42767
7.2 HIGH

Kashipara Hotel Management System v1.0 is vulnerable to Unrestricted File Upload RCE via /admin/add_room_controller.php.

Aug 22, 2024
CVE-2024-42776
7.2 HIGH

Kashipara Hotel Management System v1.0 is vulnerable to Incorrect Access Control via /admin/users.php.

Aug 22, 2024
CVE-2024-42774
7.5 HIGH

An Incorrect Access Control vulnerability was found in /admin/delete_room.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to delete valid hotel room …

Aug 22, 2024
CVE-2024-42772
7.5 HIGH

An Incorrect Access Control vulnerability was found in /admin/rooms.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to view valid hotel room …

Aug 22, 2024
CVE-2024-42490
7.5 HIGH

authentik is an open-source Identity Provider. Several API endpoints can be accessed by users without correct authentication/authorization. The main API endpoints affected by this are …

Aug 22, 2024
CVE-2024-36444
8.1 HIGH

cgi-bin/fdmcgiwebv2.cgi on Swissphone DiCal-RED 4009 devices allows an unauthenticated attacker to gain access to device logs.

Aug 22, 2024
CVE-2024-36442
8.8 HIGH

cgi-bin/fdmcgiwebv2.cgi on Swissphone DiCal-RED 4009 devices allows an authenticated attacker to gain access to arbitrary files on the device's file system.

Aug 22, 2024
CVE-2024-36443
7.6 HIGH

Swissphone DiCal-RED 4009 devices allow a remote attacker to gain read access to almost the whole file system via anonymous FTP.

Aug 22, 2024
CVE-2022-48943
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: make apf token non-zero to fix bug In current async pagefault logic, when …

Aug 22, 2024
CVE-2022-48927
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: iio: adc: tsc2046: fix memory corruption by preventing array overflow On one side we have …

Aug 22, 2024
CVE-2022-48926
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: rndis: add spinlock for rndis response list There's no lock for rndis response …

Aug 22, 2024
CVE-2024-7384
7.5 HIGH

The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing …

Aug 22, 2024
CVE-2024-39576
8.8 HIGH

Dell Power Manager (DPM), versions 3.15.0 and prior, contains an Incorrect Privilege Assignment vulnerability. A low privileged attacker with local access could potentially exploit this …

Aug 22, 2024
CVE-2022-48925
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: RDMA/cma: Do not change route.addr.src_addr outside state checks If the state is not idle then …

Aug 22, 2024
CVE-2022-48919
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: cifs: fix double free race when mount fails in cifs_get_root() When cifs_get_root() fails during cifs_smb3_do_mount() …

Aug 22, 2024
CVE-2022-48913
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: blktrace: fix use after free for struct blk_trace When tracing the whole disk, 'dropped' and …

Aug 22, 2024
CVE-2022-48912
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: netfilter: fix use-after-free in __nf_register_net_hook() We must not dereference @new_hooks after nf_hook_mutex has been released, …

Aug 22, 2024
CVE-2024-43033
8.8 HIGH

JPress through 5.1.1 on Windows has an arbitrary file upload vulnerability that could cause arbitrary code execution via ::$DATA to AttachmentController, such as a .jsp::$DATA …

Aug 22, 2024
CVE-2024-7980
7.8 HIGH

Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to perform privilege escalation via a crafted symbolic …

Aug 21, 2024
CVE-2024-7979
7.8 HIGH

Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to perform privilege escalation via a crafted symbolic …

Aug 21, 2024
CVE-2024-7977
7.8 HIGH

Insufficient data validation in Installer in Google Chrome on Windows prior to 128.0.6613.84 allowed a local attacker to perform privilege escalation via a malicious file. …

Aug 21, 2024
CVE-2024-7974
8.8 HIGH

Insufficient data validation in V8 API in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted Chrome …

Aug 21, 2024
CVE-2024-7973
8.8 HIGH

Heap buffer overflow in PDFium in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to perform an out of bounds memory read via a …

Aug 21, 2024
CVE-2024-7972
8.8 HIGH

Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially perform out of bounds memory access via a crafted …

Aug 21, 2024
CVE-2024-7969
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 128.0.6613.113 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Aug 21, 2024
CVE-2024-7968
8.8 HIGH

Use after free in Autofill in Google Chrome prior to 128.0.6613.84 allowed a remote attacker who had convinced the user to engage in specific UI …

Aug 21, 2024
CVE-2024-7967
8.8 HIGH

Heap buffer overflow in Fonts in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Aug 21, 2024
CVE-2024-7966
8.8 HIGH

Out of bounds memory access in Skia in Google Chrome prior to 128.0.6613.84 allowed a remote attacker who had compromised the renderer process to perform …

Aug 21, 2024
CVE-2024-7965
8.8 HIGH KEV

Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium …

Aug 21, 2024
CVE-2024-7964
8.8 HIGH

Use after free in Passwords in Google Chrome on Android prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted …

Aug 21, 2024
CVE-2024-42786
8.8 HIGH

A SQL injection vulnerability in "/music/view_user.php" in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "id" parameter of …

Aug 21, 2024
CVE-2024-42785
8.8 HIGH

A SQL injection vulnerability in /music/index.php?page=view_playlist in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "id" parameter.

Aug 21, 2024
CVE-2024-42780
8.8 HIGH

An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_genre" in Kashipara Music Management System v1.0. This allows attackers to execute arbitrary code via uploading a …

Aug 21, 2024
CVE-2024-42779
8.8 HIGH

An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_music" in Kashipara Music Management System v1.0. This allows attackers to execute arbitrary code via uploading a …

Aug 21, 2024
CVE-2024-42778
8.8 HIGH

An Unrestricted file upload vulnerability was found in "/music/ajax.php?action=save_playlist" in Kashipara Music Management System v1.0. This allows attackers to execute arbitrary code via uploading a …

Aug 21, 2024
CVE-2023-29929
7.5 HIGH

Buffer Overflow vulnerability found in Kemptechnologies Loadmaster before v.7.2.60.0 allows a remote attacker to casue a denial of service via the libkemplink.so, isreverse library.

Aug 21, 2024
CVE-2024-7448
8.0 HIGH

Magnet Forensics AXIOM Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Magnet Forensics AXIOM. …

Aug 21, 2024
CVE-2024-6141
7.8 HIGH

Windscribe Directory Traversal Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Windscribe. An attacker must first obtain …

Aug 21, 2024
CVE-2024-5930
7.8 HIGH

VIPRE Advanced Security Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Advanced Security. …

Aug 21, 2024
CVE-2024-5929
7.8 HIGH

VIPRE Advanced Security PMAgent Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE …

Aug 21, 2024
CVE-2024-5928
7.8 HIGH

VIPRE Advanced Security PMAgent Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of VIPRE Advanced Security. …

Aug 21, 2024
CVE-2024-5762
8.1 HIGH

Zen Cart findPluginAdminPage Local File Inclusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Zen Cart. …

Aug 21, 2024
CVE-2024-5725
8.8 HIGH

Centreon initCurveList SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required …

Aug 21, 2024
CVE-2024-5723
8.8 HIGH

Centreon updateServiceHost SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Centreon. Authentication is required …

Aug 21, 2024
CVE-2024-43022
7.5 HIGH

An issue in the downloader.php component of TOSEI online store management system v4.02, v4.03, and v4.04 allows attackers to execute a directory traversal.

Aug 21, 2024
CVE-2024-33657
7.8 HIGH

This SMM vulnerability affects certain modules, allowing privileged attackers to execute arbitrary code, manipulate stack memory, and leak information from SMRAM to kernel space, potentially …

Aug 21, 2024
CVE-2024-33656
7.8 HIGH

The DXE module SmmComputrace contains a vulnerability that allows local attackers to leak stack or global memory. This could lead to privilege escalation, arbitrary code …

Aug 21, 2024
CVE-2024-20375
8.6 HIGH

A vulnerability in the SIP call processing function of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM …

Aug 21, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.