CVE Database

38976+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-39521
7.8 HIGH

An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved commands allows a local, authenticated attacker with low privileges to escalate their …

Jul 11, 2024
CVE-2024-39520
7.8 HIGH

An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved commands allows a local, authenticated attacker with low privileges to escalate their …

Jul 11, 2024
CVE-2024-38536
7.5 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. A memory allocation failure due to `http.memcap` being reached leads …

Jul 11, 2024
CVE-2024-38535
7.5 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Suricata can run out of memory when parsing crafted HTTP/2 …

Jul 11, 2024
CVE-2024-38534
7.5 HIGH

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Crafted modbus traffic can lead to unlimited resource accumulation within …

Jul 11, 2024
CVE-2024-28872
8.9 HIGH

The TLS certificate validation code is flawed. An attacker can obtain a TLS certificate from the Stork server and use it to connect to the …

Jul 11, 2024
CVE-2024-5681
7.8 HIGH

CWE-20: Improper Input Validation vulnerability exists that could cause local denial-of-service, privilege escalation, and potentially kernel execution when a malicious actor with local user access …

Jul 11, 2024
CVE-2024-5680
7.1 HIGH

CWE-129: Improper Validation of Array Index vulnerability exists that could cause local denial-of-service when a malicious actor with local user access crafts a script/program using …

Jul 11, 2024
CVE-2024-5679
7.1 HIGH

CWE-787: Out-of-Bounds Write vulnerability exists that could cause local denial-of-service, or kernel memory leak when a malicious actor with local user access crafts a script/program …

Jul 11, 2024
CVE-2024-2602
7.3 HIGH

CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could result in remote code execution when an authenticated user …

Jul 11, 2024
CVE-2024-6666
8.8 HIGH

The WP ERP plugin for WordPress is vulnerable to SQL Injection via the ‘vendor_id’ and 'status' parameter in all versions up to, and including, 1.13.0 …

Jul 11, 2024
CVE-2024-1845
8.8 HIGH

The VikRentCar Car Rental Management System WordPress plugin before 1.3.2 does not have CSRF checks in some places, which could allow attackers to make logged …

Jul 11, 2024
CVE-2024-22280
8.5 HIGH

VMware Aria Automation does not apply correct input validation which allows for SQL-injection in the product. An authenticated malicious user could enter specially crafted SQL …

Jul 11, 2024
CVE-2024-6653
7.3 HIGH

A vulnerability was found in code-projects Simple Task List 1.0. It has been declared as critical. This vulnerability affects unknown code of the file loginForm.php …

Jul 11, 2024
CVE-2024-6447
7.2 HIGH

The FULL – Cliente plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the license plan parameter in all versions up to, and including, …

Jul 11, 2024
CVE-2024-39565
8.8 HIGH

An Improper Neutralization of Data within XPath Expressions ('XPath Injection') vulnerability in J-Web shipped with Juniper Networks Junos OS allows an unauthenticated, network-based attacker to …

Jul 10, 2024
CVE-2024-39562
7.5 HIGH

A Missing Release of Resource after Effective Lifetime vulnerability the xinetd process, responsible for spawning SSH daemon (sshd) instances, of Juniper Networks Junos OS Evolved …

Jul 10, 2024
CVE-2024-39555
7.5 HIGH

An Improper Handling of Exceptional Conditions vulnerability in the Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an attacker …

Jul 10, 2024
CVE-2024-39518
7.5 HIGH

A Heap-based Buffer Overflow vulnerability in the telemetry sensor process (sensord) of Juniper Networks Junos OS on MX240, MX480, MX960 platforms using MPC10E causes a …

Jul 10, 2024
CVE-2024-6286
7.8 HIGH

Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows

Jul 10, 2024
CVE-2024-6236
7.5 HIGH

Denial of Service in NetScaler Console (formerly NetScaler ADM), NetScaler Agent, and NetScaler SDX

Jul 10, 2024
CVE-2024-6151
7.8 HIGH

Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Virtual Delivery Agent for Windows used by Citrix Virtual Apps and Desktops and …

Jul 10, 2024
CVE-2024-6148
8.8 HIGH

Bypass of GACS Policy Configuration settings in Citrix Workspace app for HTML5

Jul 10, 2024
CVE-2024-39693
7.5 HIGH

Next.js is a React framework. A Denial of Service (DoS) condition was identified in Next.js. Exploitation of the bug can trigger a crash, affecting the …

Jul 10, 2024
CVE-2024-38354
8.1 HIGH

CodiMD allows realtime collaborative markdown notes on all platforms. The notebook feature of Hackmd.io permits the rendering of iframe `HTML` tags with an improperly sanitized …

Jul 10, 2024
CVE-2024-37149
7.2 HIGH

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An authenticated technician user …

Jul 10, 2024
CVE-2024-37148
8.1 HIGH

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An authenticated user can …

Jul 10, 2024
CVE-2024-6235
8.8 HIGH

Sensitive information disclosure in NetScaler Console

Jul 10, 2024
CVE-2024-5491
7.5 HIGH

Denial of Service in NetScaler ADC and NetScaler Gateway in NetScaler

Jul 10, 2024
CVE-2024-32469
7.1 HIGH

Decidim is a participatory democracy framework. The pagination feature used in searches and filters is subject to potential XSS attack through a malformed URL using …

Jul 10, 2024
CVE-2024-37115
7.5 HIGH

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Automattic Newspack Blocks.This issue affects Newspack Blocks: from n/a through 3.0.8.

Jul 10, 2024
CVE-2024-37110
7.5 HIGH

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Membership Software WishList Member X.This issue affects WishList Member X: from n/a before 3.26.7.

Jul 10, 2024
CVE-2024-3325
7.2 HIGH

Vulnerability in Jaspersoft JasperReport Servers.This issue affects JasperReport Servers: from 8.0.4 through 9.0.0.

Jul 10, 2024
CVE-2024-40332
8.8 HIGH

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/moneyRecord_deal.php?mudi=delRecord

Jul 10, 2024
CVE-2024-40331
8.8 HIGH

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/dbBakMySQL_deal.php?mudi=backup

Jul 10, 2024
CVE-2024-40334
8.8 HIGH

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/serverFile_deal.php?mudi=upFileDel&dataID=3

Jul 10, 2024
CVE-2024-40333
8.8 HIGH

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/softBak_deal.php?mudi=del&dataID=2

Jul 10, 2024
CVE-2024-40329
8.8 HIGH

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/softBak_deal.php?mudi=backup

Jul 10, 2024
CVE-2024-28828
8.8 HIGH

Cross-Site request forgery in Checkmk < 2.3.0p8, < 2.2.0p29, < 2.1.0p45, and <= 2.0.0p39 (EOL) could lead to 1-click compromize of the site.

Jul 10, 2024
CVE-2024-28827
8.8 HIGH

Incorrect permissions on the Checkmk Windows Agent's data directory in Checkmk < 2.3.0p8, < 2.2.0p29, < 2.1.0p45, and <= 2.0.0p39 (EOL) allows a local attacker …

Jul 10, 2024
CVE-2024-6421
7.5 HIGH

An unauthenticated remote attacker can read out sensitive device information through a incorrectly configured FTP service.

Jul 10, 2024
CVE-2024-39492
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: mailbox: mtk-cmdq: Fix pm_runtime_get_sync() warning in mbox shutdown The return value of pm_runtime_get_sync() in cmdq_mbox_shutdown() …

Jul 10, 2024
CVE-2024-39927
8.2 HIGH

Out-of-bounds write vulnerability exists in Ricoh MFPs and printers. If a remote attacker sends a specially crafted request to the affected products, the products may …

Jul 10, 2024
CVE-2024-36451
8.8 HIGH

Improper handling of insufficient permissions or privileges vulnerability exists in ajaxterm module of Webmin prior to 2.003. If this vulnerability is exploited, a console session …

Jul 10, 2024
CVE-2024-6411
8.8 HIGH

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 5.8.9. This …

Jul 10, 2024
CVE-2024-39614
7.5 HIGH

An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. get_supported_language_variant() was subject to a potential denial-of-service attack when used with very …

Jul 10, 2024
CVE-2024-38875
7.5 HIGH

An issue was discovered in Django 4.2 before 4.2.14 and 5.0 before 5.0.7. urlize and urlizetrunc were subject to a potential denial of service attack …

Jul 10, 2024
CVE-2024-21526
7.5 HIGH

All versions of the package speaker are vulnerable to Denial of Service (DoS) when providing unexpected input types to the channels property of the Speaker …

Jul 10, 2024
CVE-2024-21525
8.3 HIGH

All versions of the package node-twain are vulnerable to Improper Check or Handling of Exceptional Conditions due to the length of the source data not …

Jul 10, 2024
CVE-2024-21524
8.2 HIGH

All versions of the package node-stringbuilder are vulnerable to Out-of-bounds Read due to incorrect memory length calculation, by calling ToBuffer, ToString, or CharAt on a …

Jul 10, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.