CVE Database

38976+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-24791
7.5 HIGH

The net/http HTTP/1.1 client mishandled the case where a server responds to a request with an "Expect: 100-continue" header with a non-informational (200 or higher) …

Jul 2, 2024
CVE-2022-30636
7.5 HIGH

httpTokenCacheKey uses path.Base to extract the expected HTTP-01 token value to lookup in the DirCache implementation. On Windows, path.Base acts differently to filepath.Base, since Windows …

Jul 2, 2024
CVE-2022-25480
7.8 HIGH

Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 allows writing …

Jul 2, 2024
CVE-2022-25478
7.8 HIGH

Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 provides read …

Jul 2, 2024
CVE-2024-39894
7.5 HIGH

OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) because of an ObscureKeystrokeTiming logic error. …

Jul 2, 2024
CVE-2024-39206
7.5 HIGH

An issue discovered in MSP360 Backup Agent v7.8.5.15 and v7.9.4.84 allows attackers to obtain network share credentials used in a backup due to enginesettings.list being …

Jul 2, 2024
CVE-2024-5865
7.7 HIGH

Vulnerability in Delinea Centrify PAS v. 21.3 and possibly others. The application is prone to the path traversal vulnerability allowing arbitrary files reading outside the …

Jul 2, 2024
CVE-2024-4467
7.8 HIGH

A flaw was found in the QEMU disk image utility (qemu-img) 'info' command. A specially crafted image file containing a `json:{}` value describing block devices …

Jul 2, 2024
CVE-2024-39323
7.1 HIGH

aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.01 and prior to versions 2022.10.10, 2023.10.6, and 2024.04.6, an improper access control vulnerability …

Jul 2, 2024
CVE-2024-26314
7.8 HIGH

Improper privilege management in Jungo WinDriver 6.0.0 through 16.1.0 allows local attackers to escalate privileges and execute arbitrary code.

Jul 2, 2024
CVE-2024-25088
7.8 HIGH

Improper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges and execute arbitrary code.

Jul 2, 2024
CVE-2024-25086
7.8 HIGH

Improper privilege management in Jungo WinDriver before 12.2.0 allows local attackers to escalate privileges and execute arbitrary code.

Jul 2, 2024
CVE-2024-22106
7.8 HIGH

Improper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges, execute arbitrary code, or cause a Denial of Service (DoS).

Jul 2, 2024
CVE-2024-4897
8.4 HIGH

parisneo/lollms-webui, in its latest version, is vulnerable to remote code execution due to an insecure dependency on llama-cpp-python version llama_cpp_python-0.2.61+cpuavx2-cp311-cp311-manylinux_2_31_x86_64. The vulnerability arises from the …

Jul 2, 2024
CVE-2023-51776
7.8 HIGH

Improper privilege management in Jungo WinDriver before 12.1.0 allows local attackers to escalate privileges and execute arbitrary code.

Jul 2, 2024
CVE-2024-38519
7.8 HIGH

`yt-dlp` and `youtube-dl` are command-line audio/video downloaders. Prior to the fixed versions, `yt-dlp` and `youtube-dl` do not limit the extensions of downloaded files, which could …

Jul 2, 2024
CVE-2024-34122
7.8 HIGH

Acrobat for Edge versions 126.0.2592.68 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read …

Jul 2, 2024
CVE-2024-34595
7.8 HIGH

Improper access control in clickAdapterItem of SystemUI prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities.

Jul 2, 2024
CVE-2024-34593
7.5 HIGH

Improper input validation in parsing and distributing RTCP packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to execute arbitrary code with …

Jul 2, 2024
CVE-2024-34587
7.5 HIGH

Improper input validation in parsing application information from RTCP packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to execute arbitrary code …

Jul 2, 2024
CVE-2024-34585
7.8 HIGH

Improper access control in launchApp of SystemUI prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities.

Jul 2, 2024
CVE-2024-20895
7.7 HIGH

Improper access control in Dar service prior to SMR Jul-2024 Release 1 allows local attackers to bypass restriction for calling SDP features.

Jul 2, 2024
CVE-2024-20891
7.8 HIGH

Improper access control in launchFullscreenIntent of SystemUI prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities.

Jul 2, 2024
CVE-2024-20888
7.8 HIGH

Improper access control in OneUIHome prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities. User interaction is required for triggering this …

Jul 2, 2024
CVE-2024-4836
7.5 HIGH

Web services managed by Edito CMS (Content Management System) in versions from 3.5 through 3.25 leak sensitive data as they allow downloading configuration files by …

Jul 2, 2024
CVE-2024-37185
8.2 HIGH

in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds write.

Jul 2, 2024
CVE-2024-37077
8.2 HIGH

in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds write.

Jul 2, 2024
CVE-2024-37030
8.2 HIGH

in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through use after free.

Jul 2, 2024
CVE-2024-36260
8.2 HIGH

in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds write.

Jul 2, 2024
CVE-2024-36243
8.2 HIGH

in OpenHarmony v4.0.0 and prior versions allow a remote attacker arbitrary code execution in pre-installed apps through out-of-bounds read and write.

Jul 2, 2024
CVE-2024-37479
8.5 HIGH

Local File Inclusion vulnerability in LA-Studio LA-Studio Element Kit for Elementor via "LaStudioKit Progress Bar" widget in New Post, specifically in the "progress_type" attribute.This issue …

Jul 2, 2024
CVE-2023-41926
8.8 HIGH

The webserver utilizes basic authentication for its user login to the configuration interface. As encryption is disabled on port 80, it enables potential eavesdropping on …

Jul 2, 2024
CVE-2023-41923
7.2 HIGH

The user management section of the web application permits the creation of user accounts with excessively weak passwords, including single-character passwords.

Jul 2, 2024
CVE-2023-41922
7.2 HIGH

A 'Cross-site Scripting' (XSS) vulnerability, characterized by improper input neutralization during web page generation, has been discovered. This vulnerability allows for Stored XSS attacks to …

Jul 2, 2024
CVE-2024-5767
8.8 HIGH

The sitetweet WordPress plugin through 0.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow …

Jul 2, 2024
CVE-2024-5606
8.8 HIGH

The Quiz and Survey Master (QSM) WordPress plugin before 9.0.2 is vulnerable does not validate and escape the question_id parameter in the qsm_bulk_delete_question_from_database AJAX action, …

Jul 2, 2024
CVE-2024-5349
8.8 HIGH

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.8.1 via the …

Jul 2, 2024
CVE-2024-4679
7.8 HIGH

Incorrect Default Permissions vulnerability in Hitachi JP1/Extensible SNMP Agent for Windows, Hitachi JP1/Extensible SNMP Agent on Windows, Hitachi Job Management Partner1/Extensible SNMP Agent on Windows …

Jul 2, 2024
CVE-2024-37765
8.8 HIGH

Machform up to version 19 is affected by an authenticated Blind SQL injection in the user account settings page.

Jul 1, 2024
CVE-2024-23736
8.8 HIGH

Cross Site Request Forgery (CSRF) vulnerability in savignano S/Notify before 4.0.2 for Confluence allows attackers to manipulate a user's S/MIME certificate of PGP key via …

Jul 1, 2024
CVE-2024-38367
8.2 HIGH

trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. Prior to commit d4fa66f49cedab449af9a56a21ab40697b9f7b97, the trunk sessions verification step could be manipulated for owner session …

Jul 1, 2024
CVE-2024-32230
7.8 HIGH

FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a negative-size-param bug at libavcodec/mpegvideo_enc.c:1216:21 in load_input_picture in FFmpeg7.0

Jul 1, 2024
CVE-2024-32229
8.4 HIGH

FFmpeg 7.0 contains a heap-buffer-overflow at libavfilter/vf_tiltandshift.c:189:5 in copy_column.

Jul 1, 2024
CVE-2024-39249
7.5 HIGH

Async <= 2.6.4 and <= 3.2.5 are vulnerable to ReDoS (Regular Expression Denial of Service) while parsing function in autoinject function. NOTE: this is disputed …

Jul 1, 2024
CVE-2024-39573
7.5 HIGH

Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL's to be handled …

Jul 1, 2024
CVE-2024-38477
7.5 HIGH

null pointer dereference in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows an attacker to crash the server via a malicious request. Users are …

Jul 1, 2024
CVE-2024-38473
8.1 HIGH

Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing …

Jul 1, 2024
CVE-2024-38472
7.5 HIGH

SSRF in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content Users …

Jul 1, 2024
CVE-2024-37298
7.5 HIGH

gorilla/schema converts structs to and from form values. Prior to version 1.4.1 Running `schema.Decoder.Decode()` on a struct that has a field of type `[]struct{...}` opens …

Jul 1, 2024
CVE-2024-36997
8.1 HIGH

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312, an admin user could store and execute arbitrary JavaScript …

Jul 1, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.