CVE Database

38976+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-36538
8.8 HIGH

Insecure permissions in chaos-mesh v2.6.3 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.

Jul 24, 2024
CVE-2024-36537
7.2 HIGH

Insecure permissions in cert-manager v1.14.4 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.

Jul 24, 2024
CVE-2024-41672
7.5 HIGH

DuckDB is a SQL database management system. In versions 1.0.0 and prior, content in filesystem is accessible for reading using `sniff_csv`, even with `enable_external_access=false`. This …

Jul 24, 2024
CVE-2024-41667
8.8 HIGH

OpenAM is an open access management solution. In versions 15.0.3 and prior, the `getCustomLoginUrlTemplate` method in RealmOAuth2ProviderSettings.java is vulnerable to template injection due to its …

Jul 24, 2024
CVE-2024-41662
8.6 HIGH

VNote is a note-taking platform. A Cross-Site Scripting (XSS) vulnerability has been identified in the Markdown rendering functionality of versions 3.18.1 and prior of the …

Jul 24, 2024
CVE-2024-36541
8.8 HIGH

Insecure permissions in logging-operator v4.6.0 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.

Jul 24, 2024
CVE-2024-31970
8.8 HIGH

AdTran SRG 834-5 HDC17600021F1 devices (with SmartOS 11.1.1.1 and fixed in Version 12.1.3.1) have SSH enabled by default, accessible both over the LAN and the …

Jul 24, 2024
CVE-2024-41914
8.1 HIGH

A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack …

Jul 24, 2024
CVE-2024-39345
7.2 HIGH

AdTran 834-5 HDC17600021F1 (SmartOS 11.1.1.1) devices enable the SSH service by default and have a hidden, undocumented, hard-coded support account whose password is based on …

Jul 24, 2024
CVE-2024-31977
8.8 HIGH

Adtran 834-5 11.1.0.101-202106231430, and fixed as of SmartOS Version 12.6.3.1, devices allow OS Command Injection via shell metacharacters to the Ping or Traceroute utility.

Jul 24, 2024
CVE-2024-22443
7.2 HIGH

A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a server-side prototype pollution attack. Successful …

Jul 24, 2024
CVE-2024-6096
8.8 HIGH

In Progress® Telerik® Reporting versions prior to 18.1.24.709, a code execution attack is possible through object injection via an insecure type resolution vulnerability.

Jul 24, 2024
CVE-2024-7066
7.3 HIGH

A vulnerability was found in F-logic DataCube3 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file …

Jul 24, 2024
CVE-2024-6197
7.5 HIGH

libcurl's ASN1 parser has this utf8asn1str() function used for parsing an ASN.1 UTF-8 string. Itcan detect an invalid field and return error. Unfortunately, when doing …

Jul 24, 2024
CVE-2024-39676
7.5 HIGH

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Pinot. This issue affects Apache Pinot: from 0.1 before 1.0.0. Users are recommended to …

Jul 24, 2024
CVE-2023-48362
8.8 HIGH

XXE in the XML Format Plugin in Apache Drill version 1.19.0 and greater allows a user to read any file on a remote file system …

Jul 24, 2024
CVE-2024-7027
7.3 HIGH

The WooCommerce - PDF Vouchers plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 4.9.3. This is due to insufficient …

Jul 24, 2024
CVE-2024-6756
8.8 HIGH

The Social Auto Poster plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpw_auto_poster_get_image_path' function in all …

Jul 24, 2024
CVE-2024-6753
7.2 HIGH

The Social Auto Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mapTypes’ parameter in the 'wpw_auto_poster_map_wordpress_post_type' AJAX function in all versions …

Jul 24, 2024
CVE-2024-6750
7.3 HIGH

The Social Auto Poster plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple …

Jul 24, 2024
CVE-2024-41656
7.1 HIGH

Sentry is an error tracking and performance monitoring platform. Starting in version 10.0.0 and prior to version 24.7.1, an unsanitized payload sent by an Integration …

Jul 23, 2024
CVE-2024-38176
8.1 HIGH

An improper restriction of excessive authentication attempts in GroupMe allows a unauthenticated attacker to elevate privileges over a network.

Jul 23, 2024
CVE-2024-0981
7.1 HIGH

Okta Browser Plugin versions 6.5.0 through 6.31.0 (Chrome/Edge/Firefox/Safari) are vulnerable to cross-site scripting. This issue occurs when the plugin prompts the user to save these …

Jul 23, 2024
CVE-2024-41668
8.3 HIGH

The cBioPortal for Cancer Genomics provides visualization, analysis, and download of large-scale cancer genomics data sets. When running a publicly exposed proxy endpoint without authentication, …

Jul 23, 2024
CVE-2020-11640
8.8 HIGH

AdvaBuild uses a command queue to launch certain operations. An attacker who gains access to the command queue can use it to launch an attack …

Jul 23, 2024
CVE-2020-11639
7.8 HIGH

An attacker could exploit the vulnerability by injecting garbage data or specially crafted data. Depending on the data injected each process might be affected differently. …

Jul 23, 2024
CVE-2024-41178
7.5 HIGH

Exposure of temporary credentials in logs in Apache Arrow Rust Object Store (`object_store` crate), version 0.10.1 and earlier on all platforms using AWS WebIdentityTokens. On …

Jul 23, 2024
CVE-2024-6714
8.8 HIGH

An issue was discovered in provd before version 0.1.5 with a setuid binary, which allows a local attacker to escalate their privilege.

Jul 23, 2024
CVE-2024-4076
7.5 HIGH

Client queries that trigger serving stale data and that also require lookups in local authoritative zone data may result in an assertion failure. This issue …

Jul 23, 2024
CVE-2024-41655
7.5 HIGH

TF2 Item Format helps users format TF2 items to the community standards. Versions of `tf2-item-format` since at least `4.2.6` and prior to `5.9.14` are vulnerable …

Jul 23, 2024
CVE-2024-40060
7.5 HIGH

go-chart v2.1.1 was discovered to contain an infinite loop via the drawCanvas() function.

Jul 23, 2024
CVE-2024-1975
7.5 HIGH

If a server hosts a zone containing a "KEY" Resource Record, or a resolver DNSSEC-validates a "KEY" Resource Record from a DNSSEC-signed domain in cache, …

Jul 23, 2024
CVE-2024-1737
7.5 HIGH

Resolver caches and authoritative zone databases that hold significant numbers of RRs for the same hostname (of any RTYPE) can suffer from degraded performance as …

Jul 23, 2024
CVE-2024-0760
7.5 HIGH

A malicious client can send many DNS messages over TCP, potentially causing the server to become unstable while the attack is in progress. The server …

Jul 23, 2024
CVE-2024-5602
7.8 HIGH

A stack-based buffer overflow vulnerability due to a missing bounds check in the NI I/O Trace Tool may result in arbitrary code execution. Successful exploitation …

Jul 23, 2024
CVE-2024-4081
7.8 HIGH

A memory corruption issue due to an improper length check in NI LabVIEW may disclose information or result in arbitrary code execution. Successful exploitation requires …

Jul 23, 2024
CVE-2024-4080
7.8 HIGH

A memory corruption issue due to an improper length check in LabVIEW tdcore.dll may disclose information or result in arbitrary code execution. Successful exploitation requires …

Jul 23, 2024
CVE-2024-4079
7.8 HIGH

An out of bounds read due to a missing bounds check in LabVIEW may disclose information or result in arbitrary code execution. Successful exploitation requires …

Jul 23, 2024
CVE-2024-7014
8.1 HIGH

EvilVideo vulnerability allows sending malicious apps disguised as videos in Telegram for Android application affecting versions 10.14.4 and older.

Jul 23, 2024
CVE-2024-6420
8.6 HIGH

The Hide My WP Ghost WordPress plugin before 5.2.02 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated …

Jul 23, 2024
CVE-2024-6885
8.1 HIGH

The MaxiBlocks: 2200+ Patterns, 190 Pages, 14.2K Icons & 100 Styles plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path …

Jul 23, 2024
CVE-2024-6828
7.2 HIGH

The Redux Framework plugin for WordPress is vulnerable to unauthenticated JSON file uploads due to missing authorization and capability checks on the Redux_Color_Scheme_Import function in …

Jul 23, 2024
CVE-2024-6717
7.7 HIGH

HashiCorp Nomad and Nomad Enterprise 1.6.12 up to 1.7.9, and 1.8.1 archive unpacking during migration is vulnerable to path escaping of the allocation directory. This …

Jul 23, 2024
CVE-2024-6913
8.8 HIGH

Execution with unnecessary privileges in PerkinElmer ProcessPlus allows an attacker to spawn a remote shell on the windows system.This issue affects ProcessPlus: through 1.11.6507.0.

Jul 22, 2024
CVE-2024-6911
7.5 HIGH

Files on the Windows system are accessible without authentication to external parties due to a local file inclusion in PerkinElmer ProcessPlus.This issue affects ProcessPlus: through …

Jul 22, 2024
CVE-2024-6805
7.5 HIGH

The NI VeriStand Gateway is missing authorization checks when an actor attempts to access File Transfer resources. These missing checks may result in information disclosure …

Jul 22, 2024
CVE-2024-6791
7.8 HIGH

A directory path traversal vulnerability exists when loading a vsmodel file in NI VeriStand that may result in remote code execution. Successful exploitation requires an …

Jul 22, 2024
CVE-2024-6675
7.8 HIGH

A deserialization of untrusted data vulnerability exists in NI VeriStand that may result in remote code execution. Successful exploitation requires an attacker to get a …

Jul 22, 2024
CVE-2024-6121
7.8 HIGH

An out-of-date version of Redis shipped with NI SystemLink Server is susceptible to multiple vulnerabilities, including CVE-2022-24834. This affects NI SystemLink Server 2024 Q1 and …

Jul 22, 2024
CVE-2024-34329
8.4 HIGH

Insecure permissions in Entrust Datacard XPS Card Printer Driver 8.5 and earlier without the dxp1-patch-E24-004 patch allows unauthenticated attackers to execute arbitrary code as SYSTEM …

Jul 22, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.