CVE Database

38976+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-28983
8.8 HIGH

Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.1.0.0 and 9.3.0.7, including 8.3.x allow a malicious URL to inject content into the Analyzer plugin …

Jun 26, 2024
CVE-2024-28982
7.1 HIGH

Hitachi Vantara Pentaho Business Analytics Server versions before 10.1.0.0 and 9.3.0.7, including 8.3.x do not correctly protect the ACL service endpoint of the Pentaho User …

Jun 26, 2024
CVE-2024-36829
7.5 HIGH

Incorrect access control in Teldat M1 v11.00.05.50.01 allows attackers to obtain sensitive information via a crafted query string.

Jun 26, 2024
CVE-2024-23767
8.8 HIGH

An issue was discovered on HMS Anybus X-Gateway AB7832-F firmware version 3. The HICP protocol allows unauthenticated changes to a device's network configurations.

Jun 26, 2024
CVE-2024-23766
7.5 HIGH

An issue was discovered on HMS Anybus X-Gateway AB7832-F 3 devices. The gateway exposes a web interface on port 80. An unauthenticated GET request to …

Jun 26, 2024
CVE-2024-33329
7.5 HIGH

A hardcoded privileged ID within Lumisxp v15.0.x to v16.1.x allows attackers to bypass authentication and access internal pages and other sensitive information.

Jun 26, 2024
CVE-2024-6354
7.2 HIGH

Improper access control in PAM dashboard in Devolutions Remote Desktop Manager 2024.2.11 and earlier on Windows allows an authenticated user to bypass the execute permission …

Jun 26, 2024
CVE-2024-4758
7.6 HIGH

The Muslim Prayer Time BD WordPress plugin through 2.4 does not have CSRF check in place when reseting its settings, which could allow attackers to …

Jun 26, 2024
CVE-2024-34581
7.3 HIGH

The W3C XML Signature Syntax and Processing (XMLDsig) specification, starting with 1.0, was originally published with a "RetrievalMethod is a URI ... that may be …

Jun 26, 2024
CVE-2024-37140
8.8 HIGH

Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain an OS command injection vulnerability in an admin operation. A remote …

Jun 26, 2024
CVE-2024-29176
8.8 HIGH

Dell PowerProtect DD, version(s) 8.0, 7.13.1.0, 7.10.1.30, 7.7.5.40, contain(s) an Out-of-bounds Write vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, …

Jun 26, 2024
CVE-2024-5460
8.1 HIGH

A vulnerability in the default configuration of the Simple Network Management Protocol (SNMP) feature of Brocade Fabric OS versions before v9.0.0 could allow an authenticated, …

Jun 26, 2024
CVE-2024-4869
7.2 HIGH

The WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Client-IP’ header in …

Jun 26, 2024
CVE-2024-38526
7.2 HIGH

pdoc provides API Documentation for Python Projects. Documentation generated with `pdoc --math` linked to JavaScript files from polyfill.io. The polyfill.io CDN has been sold and …

Jun 26, 2024
CVE-2024-37742
8.2 HIGH

Insecure Access Control in Safe Exam Browser (SEB) = 3.5.0 on Windows. The vulnerability allows an attacker to share clipboard data between the SEB kiosk …

Jun 25, 2024
CVE-2024-5016
7.2 HIGH

In WhatsUp Gold versions released before 2023.1.3, Distributed Edition installations can be exploited by using a deserialization tool to achieve a Remote Code Execution as …

Jun 25, 2024
CVE-2024-5015
7.1 HIGH

In WhatsUp Gold versions released before 2023.1.3, an authenticated SSRF vulnerability in Wug.UI.Areas.Wug.Controllers.SessionControler.Update allows a low privileged user to chain this SSRF with an Improper …

Jun 25, 2024
CVE-2024-5014
7.1 HIGH

In WhatsUp Gold versions released before 2023.1.3, a Server Side Request Forgery vulnerability exists in the GetASPReport feature. This allows any authenticated user to retrieve …

Jun 25, 2024
CVE-2024-5013
7.5 HIGH

In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Denial of Service vulnerability was identified. An unauthenticated attacker can put the application into the SetAdminPassword …

Jun 25, 2024
CVE-2024-5012
8.6 HIGH

In WhatsUp Gold versions released before 2023.1.3, there is a missing authentication vulnerability in WUGDataAccess.Credentials. This vulnerability allows unauthenticated attackers to disclose Windows Credentials stored …

Jun 25, 2024
CVE-2024-38516
8.8 HIGH

ai-client-html is an Aimeos e-commerce HTML client component. Debug information revealed sensitive information from environment variables in error log. This issue has been patched in …

Jun 25, 2024
CVE-2024-37855
8.4 HIGH

An issue in Nepstech Wifi Router xpon (terminal) NTPL-Xpon1GFEVN, hardware verstion 1.0 firmware 2.0.1 allows a remote attacker to execute arbitrary code via the router's …

Jun 25, 2024
CVE-2024-21740
7.4 HIGH

Artery AT32F415CBT7 and AT32F421C8T7 devices have Incorrect Access Control.

Jun 25, 2024
CVE-2024-6206
7.5 HIGH

A security vulnerability has been identified in HPE Athonet Mobile Core software. The core application contains a code injection vulnerability where a threat actor could …

Jun 25, 2024
CVE-2024-5011
7.5 HIGH

In WhatsUp Gold versions released before 2023.1.3, an uncontrolled resource consumption vulnerability exists. A specially crafted unauthenticated HTTP request to the TestController Chart functionality can …

Jun 25, 2024
CVE-2024-5010
7.5 HIGH

In WhatsUp Gold versions released before 2023.1.3, a vulnerability exists in the TestController functionality. A specially crafted unauthenticated HTTP request can lead to a disclosure …

Jun 25, 2024
CVE-2024-5009
8.4 HIGH

In WhatsUp Gold versions released before 2023.1.3, an Improper Access Control vulnerability in Wug.UI.Controllers.InstallController.SetAdminPassword allows local attackers to modify admin's password.

Jun 25, 2024
CVE-2024-5008
8.8 HIGH

In WhatsUp Gold versions released before 2023.1.3, an authenticated user with certain permissions can upload an arbitrary file and obtain RCE using Apm.UI.Areas.APM.Controllers.Api.Applications.AppProfileImportController.

Jun 25, 2024
CVE-2024-4498
7.7 HIGH

A Path Traversal and Remote File Inclusion (RFI) vulnerability exists in the parisneo/lollms-webui application, affecting versions v9.7 to the latest. The vulnerability arises from insufficient …

Jun 25, 2024
CVE-2024-6308
7.3 HIGH

A vulnerability was found in itsourcecode Simple Online Hotel Reservation System 1.0. It has been declared as critical. This vulnerability affects unknown code of the …

Jun 25, 2024
CVE-2024-6257
8.4 HIGH

HashiCorp’s go-getter library can be coerced into executing Git update on an existing maliciously modified Git Configuration, potentially leading to arbitrary code execution.

Jun 25, 2024
CVE-2024-6238
7.4 HIGH

pgAdmin <= 8.8 has an installation Directory permission issue. Because of this issue, attackers can gain unauthorised access to the installation directory on the Debian …

Jun 25, 2024
CVE-2024-5990
7.5 HIGH

Due to an improper input validation, an unauthenticated threat actor can send a malicious message to a monitor thread within Rockwell Automation ThinServer™ and cause …

Jun 25, 2024
CVE-2024-39471
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: add error handle to avoid out-of-bounds if the sdma_v4_0_irq_id_to_seq return -EINVAL, the process should …

Jun 25, 2024
CVE-2024-39469
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix nilfs_empty_dir() misjudgment and long loop on I/O errors The error handling in nilfs_empty_dir() …

Jun 25, 2024
CVE-2024-39467
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to do sanity check on i_xattr_nid in sanity_check_inode() syzbot reports a kernel bug …

Jun 25, 2024
CVE-2024-39463
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: 9p: add missing locking around taking dentry fid list Fix a use-after-free on dentry's d_fsdata …

Jun 25, 2024
CVE-2024-37078
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix potential kernel bug due to lack of writeback flag waiting Destructive writes to …

Jun 25, 2024
CVE-2021-4440
8.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: x86/xen: Drop USERGS_SYSRET64 paravirt call commit afd30525a659ac0ae0904f0cb4a2ca75522c3123 upstream. USERGS_SYSRET64 is used to return from a …

Jun 25, 2024
CVE-2024-38952
7.5 HIGH

PX4-Autopilot v1.14.3 was discovered to contain a buffer overflow via the topic_name parameter at /logger/logged_topics.cpp.

Jun 25, 2024
CVE-2024-21827
7.2 HIGH

A leftover debug code vulnerability exists in the cli_server debug functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.4.1 Build 20240117 Rel.57421. A specially crafted …

Jun 25, 2024
CVE-2024-6302
8.1 HIGH

Lack of privilege checking when processing a redaction in Conduit versions v0.6.0 and lower, allowing a local user to redact any message from users on …

Jun 25, 2024
CVE-2024-5216
7.5 HIGH

A vulnerability in mintplex-labs/anything-llm allows for a Denial of Service (DoS) condition due to uncontrolled resource consumption. Specifically, the issue arises from the application's failure …

Jun 25, 2024
CVE-2024-4640
7.1 HIGH

OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to missing bounds checking on buffer operations. An attacker could write …

Jun 25, 2024
CVE-2024-4639
7.1 HIGH

OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to a lack of neutralized inputs in IPSec configuration. An attacker …

Jun 25, 2024
CVE-2024-4638
7.1 HIGH

OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to a lack of neutralized inputs in the web key upload …

Jun 25, 2024
CVE-2024-5431
8.8 HIGH

The WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions …

Jun 25, 2024
CVE-2024-4757
8.1 HIGH

The Logo Manager For Enamad WordPress plugin through 0.7.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, …

Jun 25, 2024
CVE-2024-37007
7.8 HIGH

A maliciously crafted X_B and X_T file, when parsed in pskernel.DLL through Autodesk applications, can cause a use-after-free vulnerability. This vulnerability, along with other vulnerabilities, …

Jun 25, 2024
CVE-2024-37006
7.8 HIGH

A maliciously crafted CATPRODUCT file, when parsed in CC5Dll.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, …

Jun 25, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.