CVE Database

38971+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-6770
7.2 HIGH

The Lifetime free Drag & Drop Contact Form Builder for WordPress VForm plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up …

Jul 31, 2024
CVE-2024-42381
8.3 HIGH

os/linux/elf.rb in Homebrew brew before 4.2.20 uses ldd to load ELF files obtained from untrusted sources, which allows attackers to achieve code execution via an …

Jul 31, 2024
CVE-2024-7286
7.3 HIGH

A vulnerability was found in SourceCodester Establishment Billing Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/ajax.php?action=login …

Jul 31, 2024
CVE-2024-39950
8.6 HIGH

A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities to initiate device initialization.

Jul 31, 2024
CVE-2024-39949
7.5 HIGH

A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities, causing the device to crash.

Jul 31, 2024
CVE-2024-39948
7.5 HIGH

A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities, causing the device to crash.

Jul 31, 2024
CVE-2024-39944
7.5 HIGH

A vulnerability has been found in Dahua products.Attackers can send carefully crafted data packets to the interface with vulnerabilities, causing the device to crash.

Jul 31, 2024
CVE-2024-7279
7.3 HIGH

A vulnerability was found in SourceCodester Lot Reservation Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file …

Jul 31, 2024
CVE-2024-6255
8.2 HIGH

A vulnerability in the JSON file handling of gaizhenbiao/chuanhuchatgpt version 20240410 allows any user to delete any JSON file on the server, including critical configuration …

Jul 31, 2024
CVE-2023-33976
7.5 HIGH

TensorFlow is an end-to-end open source platform for machine learning. `array_ops.upper_bound` causes a segfault when not given a rank 2 tensor. The fix will be …

Jul 30, 2024
CVE-2024-7297
8.8 HIGH

Langflow versions prior to 1.0.13 suffer from a Privilege Escalation vulnerability, allowing a remote and low privileged attacker to gain super admin privileges by performing …

Jul 30, 2024
CVE-2024-41915
7.2 HIGH

A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass …

Jul 30, 2024
CVE-2024-41802
8.1 HIGH

Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the API routes inside the CMS responsible for Filtering DataSets. This …

Jul 30, 2024
CVE-2024-23091
7.5 HIGH

Weak password hashing using MD5 in funzioni.php in HotelDruid before 1.32 allows an attacker to obtain plaintext passwords from hash values.

Jul 30, 2024
CVE-2024-41924
7.2 HIGH

Acceptance of extraneous untrusted data with trusted data vulnerability exists in EC-CUBE 4 series. If this vulnerability is exploited, an attacker who obtained the administrative …

Jul 30, 2024
CVE-2024-41696
7.5 HIGH

Priority PRI WEB Portal Add-On for Priority ERP on prem - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Jul 30, 2024
CVE-2024-41695
7.5 HIGH

Cybonet - CWE-22: Improper Limitation of a Pathname to a Restricted Directory

Jul 30, 2024
CVE-2024-38429
7.5 HIGH

Matrix Tafnit v8 - CWE-552: Files or Directories Accessible to External Parties

Jul 30, 2024
CVE-2024-42228
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Using uninitialized value *size when calling amdgpu_vce_cs_reloc Initialize the size before calling amdgpu_vce_cs_reloc, such …

Jul 30, 2024
CVE-2024-42225
7.5 HIGH

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: replace skb_put with skb_put_zero Avoid potentially reusing uninitialized data

Jul 30, 2024
CVE-2024-42162
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: gve: Account for stopped queues when reading NIC stats We now account for the fact …

Jul 30, 2024
CVE-2024-42160
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: f2fs: check validation of fault attrs in f2fs_build_fault_attr() - It missed to check validation of …

Jul 30, 2024
CVE-2024-42159
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: scsi: mpi3mr: Sanitise num_phys Information is stored in mr_sas_port->phy_mask, values larger then size of this …

Jul 30, 2024
CVE-2024-42148
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: bnx2x: Fix multiple UBSAN array-index-out-of-bounds Fix UBSAN warnings that occur when using a system with …

Jul 30, 2024
CVE-2024-42147
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/debugfs - Fix debugfs uninit process issue During the zip probe process, the debugfs …

Jul 30, 2024
CVE-2024-42138
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: mlxsw: core_linecards: Fix double memory deallocation in case of invalid INI file In case of …

Jul 30, 2024
CVE-2024-42136
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: cdrom: rearrange last_media_change check to avoid unintentional overflow When running syzkaller with the newly reintroduced …

Jul 30, 2024
CVE-2024-42132
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: bluetooth/hci: disallow setting handle bigger than HCI_CONN_HANDLE_MAX Syzbot hit warning in hci_conn_del() caused by freeing …

Jul 30, 2024
CVE-2024-42121
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Check index msg_id before read or write [WHAT] msg_id is used as an array …

Jul 30, 2024
CVE-2024-42120
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Check pipe offset before setting vblank pipe_ctx has a size of MAX_PIPES so checking …

Jul 30, 2024
CVE-2024-42119
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Skip finding free audio for unknown engine_id [WHY] ENGINE_ID_UNKNOWN = -1 and can not …

Jul 30, 2024
CVE-2024-42118
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Do not return negative stream id for array [WHY] resource_stream_to_stream_idx returns an array index …

Jul 30, 2024
CVE-2024-42117
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: ASSERT when failing to find index by plane/stream id [WHY] find_disp_cfg_idx_by_plane_id and find_disp_cfg_idx_by_stream_id returns …

Jul 30, 2024
CVE-2024-42112
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: txgbe: free isb resources at the right time When using MSI/INTx interrupt, the shared …

Jul 30, 2024
CVE-2024-42105
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix inode number range checks Patch series "nilfs2: fix potential issues related to reserved …

Jul 30, 2024
CVE-2024-42104
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: nilfs2: add missing check for inode numbers on directory entries Syzbot reported that mounting and …

Jul 30, 2024
CVE-2024-7219
7.3 HIGH

A vulnerability has been found in SourceCodester/Campcodes School Log Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/ajax.php?action=login. The …

Jul 30, 2024
CVE-2024-5807
7.2 HIGH

The Business Card WordPress plugin through 1.0.0 does not prevent high privilege users like administrators from uploading malicious PHP files, which could allow them to …

Jul 30, 2024
CVE-2024-7213
8.8 HIGH

A vulnerability, which was classified as critical, was found in TOTOLINK A7000R 9.1.0u.6268_B20220504. Affected is the function setWizardCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of …

Jul 30, 2024
CVE-2024-7212
8.8 HIGH

A vulnerability, which was classified as critical, has been found in TOTOLINK A7000R 9.1.0u.6268_B20220504. This issue affects the function loginauth of the file /cgi-bin/cstecgi.cgi. The …

Jul 30, 2024
CVE-2024-40828
7.8 HIGH

The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. A malicious app may …

Jul 29, 2024
CVE-2024-40821
7.1 HIGH

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. Third party …

Jul 29, 2024
CVE-2024-40815
7.5 HIGH

A race condition was addressed with additional validation. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, tvOS …

Jul 29, 2024
CVE-2024-40814
7.1 HIGH

A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sonoma 14.6, macOS Ventura 13.7. An app may be able …

Jul 29, 2024
CVE-2024-40812
7.8 HIGH

A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Monterey …

Jul 29, 2024
CVE-2024-40809
7.8 HIGH

A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Monterey …

Jul 29, 2024
CVE-2024-40805
7.1 HIGH

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, watchOS 10.6. …

Jul 29, 2024
CVE-2024-40803
7.5 HIGH

A type confusion issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. An attacker …

Jul 29, 2024
CVE-2024-40802
7.8 HIGH

The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. A local attacker may …

Jul 29, 2024
CVE-2024-40799
7.1 HIGH

An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, …

Jul 29, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.