CVE Database

38976+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-37818
8.6 HIGH

Strapi v4.24.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /strapi.io/_next/image. This vulnerability allows attackers to scan for open ports or …

Jun 20, 2024
CVE-2024-37626
8.8 HIGH

A command injection issue in TOTOLINK A6000R V1.0.1-B20201211.2000 firmware allows a remote attacker to execute arbitrary code via the iface parameter in the vif_enable function.

Jun 20, 2024
CVE-2022-45929
8.8 HIGH

Northern.tech Mender 3.3.x before 3.3.2, 3.5.x before 3.5.0, and 3.6.x before 3.6.0 has Incorrect Access Control and allows users to change their roles and could …

Jun 20, 2024
CVE-2024-6196
7.3 HIGH

A vulnerability was found in itsourcecode Banking Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Jun 20, 2024
CVE-2024-6193
7.3 HIGH

A vulnerability, which was classified as critical, has been found in itsourcecode Vehicle Management System 1.0. This issue affects some unknown processing of the file …

Jun 20, 2024
CVE-2024-37676
8.4 HIGH

An issue in htop-dev htop v.2.20 allows a local attacker to cause an out-of-bounds access in the Header_populateFromSettings function.

Jun 20, 2024
CVE-2024-6192
7.3 HIGH

A vulnerability classified as critical was found in itsourcecode Loan Management System 1.0. This vulnerability affects unknown code of the file login.php of the component …

Jun 20, 2024
CVE-2024-6191
7.3 HIGH

A vulnerability classified as critical has been found in itsourcecode Student Management System 1.0. This affects an unknown part of the file login.php of the …

Jun 20, 2024
CVE-2024-6190
7.3 HIGH

A vulnerability was found in itsourcecode Farm Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Jun 20, 2024
CVE-2024-6162
7.5 HIGH

A vulnerability was found in Undertow, where URL-encoded request paths can be mishandled during concurrent requests on the AJP listener. This issue arises because the …

Jun 20, 2024
CVE-2024-37222
7.1 HIGH

Cross Site Scripting (XSS) vulnerability in Averta Master Slider allows Reflected XSS.This issue affects Master Slider: from n/a through 3.10.0.

Jun 20, 2024
CVE-2024-6189
8.8 HIGH

A vulnerability was found in Tenda A301 15.13.08.12. It has been classified as critical. Affected is the function fromSetWirelessRepeat of the file /goform/WifiExtraSet. The manipulation …

Jun 20, 2024
CVE-2024-37532
8.8 HIGH

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to identity spoofing by an authenticated user due to improper signature validation. IBM X-Force ID: 294721.

Jun 20, 2024
CVE-2023-49113
7.8 HIGH

The Kiuwan Local Analyzer (KLA) Java scanning application contains several hard-coded secrets in plain text format. In some cases, this can potentially compromise the confidentiality …

Jun 20, 2024
CVE-2023-49110
7.2 HIGH

When the Kiuwan Local Analyzer uploads the scan results to the Kiuwan SAST web application (either on-premises or cloud/SaaS solution), the transmitted data consists of …

Jun 20, 2024
CVE-2023-52883
7.5 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix possible null pointer dereference abo->tbo.resource may be NULL in amdgpu_vm_bo_update.

Jun 20, 2024
CVE-2022-48771
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix stale file descriptors on failed usercopy A failing usercopy of the fence_rep object …

Jun 20, 2024
CVE-2022-48760
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: USB: core: Fix hang in usb_kill_urb by adding memory barriers The syzbot fuzzer has identified …

Jun 20, 2024
CVE-2022-48759
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: rpmsg: char: Fix race between the release of rpmsg_ctrldev and cdev struct rpmsg_ctrldev contains a …

Jun 20, 2024
CVE-2022-48757
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: fix information leakage in /proc/net/ptype In one net namespace, after creating a packet socket …

Jun 20, 2024
CVE-2022-48754
8.4 HIGH

In the Linux kernel, the following vulnerability has been resolved: phylib: fix potential use-after-free Commit bafbdd527d56 ("phylib: Add device reset GPIO support") added call to …

Jun 20, 2024
CVE-2022-48748
7.5 HIGH

In the Linux kernel, the following vulnerability has been resolved: net: bridge: vlan: fix memory leak in __allowed_ingress When using per-vlan state, if vlan snooping …

Jun 20, 2024
CVE-2022-48747
7.5 HIGH

In the Linux kernel, the following vulnerability has been resolved: block: Fix wrong offset in bio_truncate() bio_truncate() clears the buffer outside of last block of …

Jun 20, 2024
CVE-2022-48744
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Avoid field-overflowing memcpy() In preparation for FORTIFY_SOURCE performing compile-time and run-time field bounds checking …

Jun 20, 2024
CVE-2022-48742
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: rtnetlink: make sure to refresh master_dev/m_ops in __rtnl_newlink() While looking at one unrelated syzbot bug, …

Jun 20, 2024
CVE-2022-48740
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: selinux: fix double free of cond_list on error paths On error path from cond_read_list() and …

Jun 20, 2024
CVE-2022-48739
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: ASoC: hdmi-codec: Fix OOB memory accesses Correct size of iec_status array by changing it to …

Jun 20, 2024
CVE-2022-48738
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: ASoC: ops: Reject out of bounds values in snd_soc_put_volsw() We don't currently validate that the …

Jun 20, 2024
CVE-2022-48735
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: Fix UAF of leds class devs at unbinding The LED class devices that …

Jun 20, 2024
CVE-2022-48733
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix use-after-free after failure to create a snapshot At ioctl.c:create_snapshot(), we allocate a pending …

Jun 20, 2024
CVE-2022-48732
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: fix off by one in BIOS boundary checking Bounds checking when parsing init scripts …

Jun 20, 2024
CVE-2022-48726
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: RDMA/ucma: Protect mc during concurrent multicast leaves Partially revert the commit mentioned in the Fixes …

Jun 20, 2024
CVE-2021-4439
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: isdn: cpai: check ctr->cnr to avoid array index out of bound The cmtp_add_connection() would add …

Jun 20, 2024
CVE-2024-28147
7.4 HIGH

An authenticated user can upload arbitrary files in the upload function for collection preview images. An attacker may upload an HTML file that includes malicious …

Jun 20, 2024
CVE-2022-48717
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ASoC: max9759: fix underflow in speaker_gain_control_put() Check for negative values of "priv->gain" to prevent an …

Jun 20, 2024
CVE-2022-48714
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: bpf: Use VM_MAP instead of VM_ALLOC for ringbuf After commit 2fd3fb0be1d1 ("kasan, vmalloc: unpoison VM_ALLOC …

Jun 20, 2024
CVE-2022-48712
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: ext4: fix error handling in ext4_fc_record_modified_inode() Current code does not fully takes care of krealloc() …

Jun 20, 2024
CVE-2024-29012
7.5 HIGH

Stack-based buffer overflow vulnerability in the SonicOS HTTP server allows an authenticated remote attacker to cause Denial of Service (DoS) via sscanf function.

Jun 20, 2024
CVE-2023-25646
7.1 HIGH

There is an unauthorized access vulnerability in ZTE H388X. If H388X is caused by brute-force serial port cracking,attackers with common user permissions can use this …

Jun 20, 2024
CVE-2024-6113
7.3 HIGH

A vulnerability was found in itsourcecode Monbela Tourist Inn Online Reservation System 1.0. It has been rated as critical. This issue affects some unknown processing …

Jun 20, 2024
CVE-2024-5605
8.8 HIGH

The Media Library Assistant plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter within the mla_tag_cloud Shortcode in all versions up …

Jun 20, 2024
CVE-2024-3597
7.1 HIGH

The Export WP Page to Static HTML/CSS plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 2.2.2. This is …

Jun 20, 2024
CVE-2024-3562
8.8 HIGH

The Custom Field Suite plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 2.6.7 via the Loop custom …

Jun 20, 2024
CVE-2024-3561
8.8 HIGH

The Custom Field Suite plugin for WordPress is vulnerable to SQL Injection via the the 'Term' custom field in all versions up to, and including, …

Jun 20, 2024
CVE-2024-6103
8.8 HIGH

Use after free in Dawn in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Jun 20, 2024
CVE-2024-6102
8.8 HIGH

Out of bounds memory access in Dawn in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to potentially exploit heap corruption via a crafted …

Jun 20, 2024
CVE-2024-6101
8.8 HIGH

Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to perform out of bounds memory access via a crafted HTML …

Jun 20, 2024
CVE-2024-6100
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security …

Jun 20, 2024
CVE-2024-36680
7.5 HIGH

In the module "Facebook" (pkfacebook) <=1.0.1 from Promokit.eu for PrestaShop, a guest can perform SQL injection. The ajax script facebookConnect.php have a sensitive SQL call …

Jun 19, 2024
CVE-2024-36677
7.5 HIGH

In the module "Login as customer PRO" (loginascustomerpro) <1.2.7 from Weblir for PrestaShop, a guest can access direct link to connect to each customer account …

Jun 19, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.