CVE Database

38971+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-36462
7.5 HIGH

Uncontrolled resource consumption refers to a software vulnerability where a attacker or system uses excessive resources, such as CPU, memory, or network bandwidth, without proper …

Aug 12, 2024
CVE-2024-36460
8.1 HIGH

The front-end audit log allows viewing of unprotected plaintext passwords, where the passwords are displayed in plain text.

Aug 12, 2024
CVE-2024-36035
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection in user session recording.

Aug 12, 2024
CVE-2024-36034
8.3 HIGH

Zohocorp ManageEngine ADAudit Plus versions below 8003 are vulnerable to authenticated SQL Injection in aggregate reports' search option.

Aug 12, 2024
CVE-2024-30188
8.1 HIGH

File read and write vulnerability in Apache DolphinScheduler , authenticated users can illegally access additional resource files. This issue affects Apache DolphinScheduler: from 3.1.0 before …

Aug 12, 2024
CVE-2024-29831
8.8 HIGH

Improper Input Validation vulnerability in Apache DolphinScheduler. An authenticated user can cause arbitrary, unsandboxed javascript to be executed on the server. If you are using …

Aug 12, 2024
CVE-2024-29082
8.6 HIGH

Improper access control vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9 and prior, enables an unauthenticated remote attacker to …

Aug 12, 2024
CVE-2024-21880
7.2 HIGH

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability via the url parameter of an authenticated enpoint in Enphase IQ Gateway (formerly …

Aug 12, 2024
CVE-2024-21879
8.8 HIGH

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability through an url parameter of an authenticated enpoint in Enphase IQ Gateway (formerly …

Aug 12, 2024
CVE-2024-0113
7.5 HIGH

NVIDIA Mellanox OS, ONYX, Skyway, and MetroX-3 XCC contain a vulnerability in the web support, where an attacker can cause a CGI path traversal by …

Aug 12, 2024
CVE-2023-50809
7.8 HIGH

In certain Sonos products before S1 Release 11.12 and S2 release 15.9, the mt_7615.ko wireless driver does not properly validate an information element during negotiation …

Aug 12, 2024
CVE-2023-31315
7.5 HIGH

Improper validation in a model specific register (MSR) could allow a malicious program with ring0 access to modify SMM configuration while SMI lock is enabled, …

Aug 12, 2024
CVE-2024-41161
7.5 HIGH

Use of hard-coded credentials vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9 and prior, enables an unauthenticated remote attacker …

Aug 8, 2024
CVE-2024-37382
7.2 HIGH

An issue discovered in import host feature in Ab Initio Metadata Hub and Authorization Gateway before 4.3.1.1 allows attackers to run arbitrary code via crafted …

Aug 8, 2024
CVE-2024-42365
7.4 HIGH

Asterisk is an open source private branch exchange (PBX) and telephony toolkit. Prior to asterisk versions 18.24.2, 20.9.2, and 21.4.2 and certified-asterisk versions 18.9-cert11 and …

Aug 8, 2024
CVE-2024-0108
8.7 HIGH

NVIDIA Jetson Linux contains a vulnerability in NvGPU where error handling paths in GPU MMU mapping code fail to clean up a failed mapping attempt. …

Aug 8, 2024
CVE-2024-0107
7.8 HIGH

NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A …

Aug 8, 2024
CVE-2024-0101
7.5 HIGH

NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in ipfilter, where improper ipfilter definitions could enable an attacker to cause a …

Aug 8, 2024
CVE-2024-42357
7.3 HIGH

Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, the Shopware application API contains a search functionality which enables users to search …

Aug 8, 2024
CVE-2024-42356
8.3 HIGH

Shopware is an open commerce platform. Prior to versions 6.6.5.1 and 6.5.8.13, the `context` variable is injected into almost any Twig Template and allows to …

Aug 8, 2024
CVE-2024-42355
8.3 HIGH

Shopware, an open ecommerce platform, has a new Twig Tag `sw_silent_feature_call` which silences deprecation messages while triggered in this tag. Prior to versions 6.6.5.1 and …

Aug 8, 2024
CVE-2024-41942
7.2 HIGH

JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to versions 4.1.6 and 5.1.0, if a user is granted …

Aug 8, 2024
CVE-2024-7348
8.8 HIGH

Time-of-check Time-of-use (TOCTOU) race condition in pg_dump in PostgreSQL allows an object creator to execute arbitrary SQL functions as the user running pg_dump, which is …

Aug 8, 2024
CVE-2024-3659
7.2 HIGH

Firmware in KAON AR2140 routers, prior to versions 3.2.50 and 4.2.16, is vulnerable to a shell command injection via sending a crafted request to one …

Aug 8, 2024
CVE-2024-42038
8.8 HIGH

Vulnerability of PIN enhancement failures in the screen lock module Impact: Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.

Aug 8, 2024
CVE-2024-42035
8.4 HIGH

Permission control vulnerability in the App Multiplier module Impact:Successful exploitation of this vulnerability may affect functionality and confidentiality.

Aug 8, 2024
CVE-2024-42257
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ext4: use memtostr_pad() for s_volume_name As with the other strings in struct ext4_super_block, s_volume_name is …

Aug 8, 2024
CVE-2024-42031
7.5 HIGH

Access permission verification vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Aug 8, 2024
CVE-2024-22069
7.1 HIGH

There is a permission and access control vulnerability of ZTE's ZXV10 XT802/ET301 product.Attackers with common permissions can log in the terminal web and change the …

Aug 8, 2024
CVE-2024-7548
8.8 HIGH

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the 'order' parameter in all versions up to, and …

Aug 8, 2024
CVE-2024-7150
8.8 HIGH

The Slider by 10Web – Responsive Image Slider plugin for WordPress is vulnerable to time-based SQL Injection via the 'id' parameter in all versions up …

Aug 8, 2024
CVE-2024-7492
8.8 HIGH

The MainWP Child Reports plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2. This is due to …

Aug 8, 2024
CVE-2024-7561
8.8 HIGH

The The Next theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.0 via deserialization of untrusted input …

Aug 8, 2024
CVE-2024-7560
7.2 HIGH

The News Flash theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.1.0 via deserialization of untrusted input …

Aug 8, 2024
CVE-2024-7486
8.8 HIGH

The MultiPurpose theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.2.0 via deserialization of untrusted input through …

Aug 8, 2024
CVE-2024-38202
7.3 HIGH

Summary Microsoft was notified that an elevation of privilege vulnerability exists in Windows Update, potentially enabling an attacker with basic user privileges to reintroduce previously …

Aug 8, 2024
CVE-2024-6893
7.5 HIGH

The "soap_cgi.pyc" API handler allows the XML body of SOAP requests to contain references to external entities. This allows an unauthenticated attacker to read local …

Aug 8, 2024
CVE-2024-6891
8.8 HIGH

Attackers with a valid username and password can exploit a python code injection vulnerability during the natural login flow.

Aug 8, 2024
CVE-2024-6890
8.8 HIGH

Password reset tokens are generated using an insecure source of randomness. Attackers who know the username of the Journyx installation user can bruteforce the password …

Aug 7, 2024
CVE-2024-6707
8.8 HIGH

Attacker controlled files can be uploaded to arbitrary locations on the web server's filesystem by abusing a path traversal vulnerability.

Aug 7, 2024
CVE-2024-7585
8.8 HIGH

A vulnerability has been found in Tenda i22 1.0.0.3(4687) and classified as critical. Affected by this vulnerability is the function formApPortalWebAuth of the file /goform/apPortalAuth. …

Aug 7, 2024
CVE-2024-7584
8.8 HIGH

A vulnerability, which was classified as critical, was found in Tenda i22 1.0.0.3(4687). Affected is the function formApPortalPhoneAuth of the file /goform/apPortalPhoneAuth. The manipulation of …

Aug 7, 2024
CVE-2024-7143
8.3 HIGH

A flaw was found in the Pulp package. When a role-based access control (RBAC) object in Pulp is set to assign permissions on its creation, …

Aug 7, 2024
CVE-2024-20451
7.5 HIGH

Multiple vulnerabilities in the web-based management interface of Cisco Small Business SPA300 Series IP Phones and Cisco Small Business SPA500 Series IP Phones could allow …

Aug 7, 2024
CVE-2024-7583
8.8 HIGH

A vulnerability, which was classified as critical, has been found in Tenda i22 1.0.0.3(4687). This issue affects the function formApPortalOneKeyAuth of the file /goform/apPortalOneKeyAuth. The …

Aug 7, 2024
CVE-2024-7582
8.8 HIGH

A vulnerability classified as critical was found in Tenda i22 1.0.0.3(4687). This vulnerability affects the function formApPortalAccessCodeAuth of the file /goform/apPortalAccessCodeAuth. The manipulation of the …

Aug 7, 2024
CVE-2024-41309
7.8 HIGH

An issue in the Hardware info module of IT Solutions Enjay CRM OS v1.0 allows attackers to escape the restricted terminal environment and gain root-level …

Aug 7, 2024
CVE-2024-41308
7.8 HIGH

An issue in the Ping feature of IT Solutions Enjay CRM OS v1.0 allows attackers to escape the restricted terminal environment and gain root-level privileges …

Aug 7, 2024
CVE-2024-7581
8.8 HIGH

A vulnerability classified as critical has been found in Tenda A301 15.13.08.12. This affects the function formWifiBasicSet of the file /goform/WifiBasicSet. The manipulation of the …

Aug 7, 2024
CVE-2024-42005
7.3 HIGH

An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. QuerySet.values() and values_list() methods on models with a JSONField are subject to …

Aug 7, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.