CVE Database

38976+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-36991
7.5 HIGH

In Splunk Enterprise on Windows versions below 9.2.2, 9.1.5, and 9.0.10, an attacker could perform a path traversal on the /modules/messaging/ endpoint in Splunk Enterprise …

Jul 1, 2024
CVE-2024-36989
7.1 HIGH

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200, a low-privileged user that does not hold the admin …

Jul 1, 2024
CVE-2024-36985
8.8 HIGH

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10, a low-privileged user that does not hold the admin or power Splunk roles could cause a …

Jul 1, 2024
CVE-2024-36984
8.8 HIGH

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 on Windows, an authenticated user could execute a specially crafted query that they could then use …

Jul 1, 2024
CVE-2024-36983
8.0 HIGH

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109 and 9.1.2308.207, an authenticated user could create an external …

Jul 1, 2024
CVE-2024-36982
7.5 HIGH

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109 and 9.1.2308.207, an attacker could trigger a null pointer …

Jul 1, 2024
CVE-2024-21586
7.5 HIGH

An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX Series and NFX …

Jul 1, 2024
CVE-2024-36421
7.5 HIGH

Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, A CORS misconfiguration sets …

Jul 1, 2024
CVE-2024-36420
7.5 HIGH

Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, the `/api/v1/openai-assistants-file` endpoint in …

Jul 1, 2024
CVE-2024-6376
7.0 HIGH

MongoDB Compass may be susceptible to code injection due to insufficient sandbox protection settings with the usage of ejson shell parser in Compass' connection handling. …

Jul 1, 2024
CVE-2024-23380
8.4 HIGH

Memory corruption while handling user packets during VBO bind operation.

Jul 1, 2024
CVE-2024-23373
8.4 HIGH

Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released.

Jul 1, 2024
CVE-2024-23372
8.4 HIGH

Memory corruption while invoking IOCTL call for GPU memory allocation and size param is greater than expected size.

Jul 1, 2024
CVE-2024-23368
7.8 HIGH

Memory corruption when allocating and accessing an entry in an SMEM partition.

Jul 1, 2024
CVE-2024-21469
7.3 HIGH

Memory corruption when an invoke call and a TEE call are bound for the same trusted application.

Jul 1, 2024
CVE-2024-21465
7.8 HIGH

Memory corruption while processing key blob passed by the user.

Jul 1, 2024
CVE-2024-21462
7.1 HIGH

Transient DOS while loading the TA ELF file.

Jul 1, 2024
CVE-2024-21461
8.4 HIGH

Memory corruption while performing finish HMAC operation when context is freed by keymaster.

Jul 1, 2024
CVE-2024-21460
7.1 HIGH

Information disclosure when ASLR relocates the IMEM and Secure DDR portions as one chunk in virtual address space.

Jul 1, 2024
CVE-2023-43554
8.4 HIGH

Memory corruption while processing IOCTL handler in FastRPC.

Jul 1, 2024
CVE-2024-24749
7.5 HIGH

GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.23.5 and 2.24.3, if GeoServer is deployed …

Jul 1, 2024
CVE-2024-6387
8.1 HIGH

A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an …

Jul 1, 2024
CVE-2024-4007
8.8 HIGH

Default credential in install package in ABB ASPECT; NEXUS Series; MATRIX Series version 3.07 allows attacker to login to product instances wrongly configured.

Jul 1, 2024
CVE-2024-39016
8.1 HIGH

che3vinci c3/utils-1 1.0.131 was discovered to contain a prototype pollution via the function assign. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024
CVE-2024-39003
7.3 HIGH

amoyjs amoy common v1.0.10 was discovered to contain a prototype pollution via the function setValue. This vulnerability allows attackers to execute arbitrary code or cause …

Jul 1, 2024
CVE-2024-38994
7.3 HIGH

amoyjs amoy common v1.0.10 was discovered to contain a prototype pollution via the function extend. This vulnerability allows attackers to execute arbitrary code or cause …

Jul 1, 2024
CVE-2024-38992
8.8 HIGH

airvertco frappejs v0.0.11 was discovered to contain a prototype pollution via the function registerView. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024
CVE-2024-38991
8.8 HIGH

akbr patch-into v1.0.1 was discovered to contain a prototype pollution via the function patchInto. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024
CVE-2024-0153
7.8 HIGH

Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Arm Ltd Valhall GPU Firmware, Arm Ltd Arm 5th Gen GPU Architecture …

Jul 1, 2024
CVE-2024-3123
7.2 HIGH

CHANGING Mobile One Time Password's uploading function in a hidden page does not filter file type properly. Remote attackers with administrator privilege can exploit this …

Jul 1, 2024
CVE-2024-20077
7.5 HIGH

In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service with no additional execution …

Jul 1, 2024
CVE-2024-20076
7.5 HIGH

In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service with no additional execution …

Jul 1, 2024
CVE-2024-6418
7.3 HIGH

A vulnerability classified as critical has been found in SourceCodester Medicine Tracker System 1.0. This affects an unknown part of the file /classes/Users.php?f=register_user. The manipulation …

Jun 30, 2024
CVE-2024-34703
7.5 HIGH

Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier or using explicit encoding of the parameters. Prior …

Jun 30, 2024
CVE-2024-28798
7.2 HIGH

IBM InfoSphere Information Server 11.7 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus …

Jun 30, 2024
CVE-2024-39840
8.8 HIGH

Factorio before 1.1.101 allows a crafted server to execute arbitrary code on clients via a custom map that leverages the ability of certain Lua base …

Jun 29, 2024
CVE-2024-2386
8.8 HIGH

The WordPress Plugin for Google Maps – WP MAPS plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'put_wpgm' shortcode …

Jun 29, 2024
CVE-2024-25943
7.6 HIGH

iDRAC9, versions prior to 7.00.00.172 for 14th Generation and 7.10.50.00 for 15th and 16th Generations, contains a session hijacking vulnerability in IPMI. A remote attacker …

Jun 29, 2024
CVE-2024-5598
7.5 HIGH

The Advanced File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.2.4 via the 'fma_local_file_system' function. …

Jun 29, 2024
CVE-2024-38532
7.1 HIGH

The NXP Data Co-Processor (DCP) is a built-in hardware module for specific NXP SoCs¹ that implements a dedicated AES cryptographic engine for encryption/decryption operations. The …

Jun 28, 2024
CVE-2024-38525
7.5 HIGH

dd-trace-cpp is the Datadog distributed tracing for C++. When the library fails to extract trace context due to malformed unicode, it logs the list of …

Jun 28, 2024
CVE-2024-37370
7.5 HIGH

In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS krb5 wrap token, causing …

Jun 28, 2024
CVE-2024-5712
8.1 HIGH

A Cross-Site Request Forgery (CSRF) vulnerability was identified in the stitionai/devika application, affecting the latest version. This vulnerability allows attackers to perform unauthorized actions in …

Jun 28, 2024
CVE-2024-38528
7.5 HIGH

nptd-rs is a tool for synchronizing your computer's clock, implementing the NTP and NTS protocols. There is a missing limit for accepted NTS-KE connections. This …

Jun 28, 2024
CVE-2024-38514
7.4 HIGH

NextChat is a cross-platform ChatGPT/Gemini UI. There is a Server-Side Request Forgery (SSRF) vulnerability due to a lack of validation of the `endpoint` GET parameter …

Jun 28, 2024
CVE-2024-27629
7.8 HIGH

An issue in dc2niix before v.1.0.20240202 allows a local attacker to execute arbitrary code via the generated file name is not properly escaped and injected …

Jun 28, 2024
CVE-2024-27628
8.1 HIGH

Buffer Overflow vulnerability in DCMTK v.3.6.8 allows an attacker to execute arbitrary code via the EctEnhancedCT method component.

Jun 28, 2024
CVE-2022-27540
7.8 HIGH

A potential Time-of-Check to Time-of Use (TOCTOU) vulnerability has been identified in the HP BIOS for certain HP PC products, which might allow arbitrary code …

Jun 28, 2024
CVE-2024-38374
7.5 HIGH

The CycloneDX core module provides a model representation of the SBOM along with utilities to assist in creating, validating, and parsing SBOMs. Before deserializing CycloneDX …

Jun 28, 2024
CVE-2024-38371
8.6 HIGH

authentik is an open-source Identity Provider. Access restrictions assigned to an application were not checked when using the OAuth2 Device code flow. This could potentially …

Jun 28, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.