CVE Database

38976+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-2024
8.8 HIGH

The Folders Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'handle_folders_file_upload' function in all versions …

Jun 14, 2024
CVE-2024-5685
7.6 HIGH

Users with "User:edit" and "Self:api" permissions can promote or demote themselves or other users by performing changes to the group's memberships via API call.This issue …

Jun 14, 2024
CVE-2024-5995
8.8 HIGH

The notification emails sent by Soar Cloud HR Portal contain a link with a embedded session. The expiration of the session is not properly configured, …

Jun 14, 2024
CVE-2024-36503
7.3 HIGH

Memory management vulnerability in the Gralloc module Impact: Successful exploitation of this vulnerability will affect availability.

Jun 14, 2024
CVE-2024-36502
7.9 HIGH

Out-of-bounds read vulnerability in the audio module Impact: Successful exploitation of this vulnerability will affect availability.

Jun 14, 2024
CVE-2024-36500
7.8 HIGH

Privilege escalation vulnerability in the AMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Jun 14, 2024
CVE-2024-31163
7.2 HIGH

ASUS Download Master has a buffer overflow vulnerability. An unauthenticated remote attacker with administrative privileges can exploit this vulnerability to execute arbitrary system commands on …

Jun 14, 2024
CVE-2024-31162
7.2 HIGH

The specific function parameter of ASUS Download Master does not properly filter user input. An unauthenticated remote attacker with administrative privileges can exploit this vulnerability …

Jun 14, 2024
CVE-2024-5551
7.5 HIGH

The WP STAGING Pro WordPress Backup Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.6.0. This …

Jun 14, 2024
CVE-2024-4404
8.5 HIGH

The ElementsKit PRO plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 3.6.2 via the 'render_raw' function. This can …

Jun 14, 2024
CVE-2024-3498
7.8 HIGH

Attackers can then execute malicious files by enabling certain services of the printer via the web configuration page and elevate its privileges to root. As …

Jun 14, 2024
CVE-2024-3497
8.8 HIGH

Path traversal vulnerability in the web server of the Toshiba printer enables attacker to overwrite orginal files or add new ones to the printer. As …

Jun 14, 2024
CVE-2024-3496
8.8 HIGH

Attackers can bypass the web login authentication process to gain access to the printer's system information and upload malicious drivers to the printer. As for …

Jun 14, 2024
CVE-2024-1094
7.3 HIGH

The Timetics- AI-powered Appointment Booking with Visual Seat Plan and ultimate Calendar Scheduling plugin for WordPress is vulnerable to unauthorized modification of data due to …

Jun 14, 2024
CVE-2024-31161
7.2 HIGH

The upload functionality of ASUS Download Master does not properly filter user input. Remote attackers with administrative privilege can exploit this vulnerability to upload any …

Jun 14, 2024
CVE-2024-27178
7.2 HIGH

An attacker can get Remote Code Execution by overwriting files. Overwriting files is enable by falsifying file name variable. This vulnerability can be executed in …

Jun 14, 2024
CVE-2024-27177
7.2 HIGH

An attacker can get Remote Code Execution by overwriting files. Overwriting files is enable by falsifying package name variable. This vulnerability can be executed in …

Jun 14, 2024
CVE-2024-27176
7.2 HIGH

An attacker can get Remote Code Execution by overwriting files. Overwriting files is enable by falsifying session ID variable. This vulnerability can be executed in …

Jun 14, 2024
CVE-2024-27171
7.4 HIGH

A remote attacker using the insecure upload functionality will be able to overwrite any Python file and get Remote Code Execution. As for the affected …

Jun 14, 2024
CVE-2024-27170
7.4 HIGH

It was observed that all the Toshiba printers contain credentials used for WebDAV access in the readable file. Then, it is possible to get a …

Jun 14, 2024
CVE-2024-27169
8.4 HIGH

Toshiba printers provides API without authentication for internal access. A local attacker can bypass authentication in applications, providing administrative access. As for the affected products/models/versions, …

Jun 14, 2024
CVE-2024-27168
7.1 HIGH

It appears that some hardcoded keys are used for authentication to internal API. Knowing these private keys may allow attackers to bypass authentication and reach …

Jun 14, 2024
CVE-2024-27167
7.4 HIGH

Toshiba printers use Sendmail to send emails to recipients. Sendmail is used with several insecure directories. A local attacker can inject a malicious Sendmail configuration …

Jun 14, 2024
CVE-2024-27166
7.4 HIGH

Coredump binaries in Toshiba printers have incorrect permissions. A local attacker can steal confidential information. As for the affected products/models/versions, see the reference URL.

Jun 14, 2024
CVE-2024-27165
7.8 HIGH

Toshiba printers contain a suidperl binary and it has a Local Privilege Escalation vulnerability. A local attacker can get root privileges. As for the affected …

Jun 14, 2024
CVE-2024-27164
7.1 HIGH

Toshiba printers contain hardcoded credentials. As for the affected products/models/versions, see the reference URL.

Jun 14, 2024
CVE-2024-27158
7.4 HIGH

All the Toshiba printers share the same hardcoded root password. As for the affected products/models/versions, see the reference URL.

Jun 14, 2024
CVE-2024-27155
7.7 HIGH

The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. The programs can be replaced by …

Jun 14, 2024
CVE-2024-3079
7.2 HIGH

Certain models of ASUS routers have buffer overflow vulnerabilities, allowing remote attackers with administrative privileges to execute arbitrary commands on the device.

Jun 14, 2024
CVE-2024-27153
7.4 HIGH

The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. As for the affected products/models/versions, see …

Jun 14, 2024
CVE-2024-27152
7.4 HIGH

The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. As for the affected products/models/versions, see …

Jun 14, 2024
CVE-2024-27151
7.4 HIGH

The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. The programs can be replaced by …

Jun 14, 2024
CVE-2024-27150
7.4 HIGH

The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. As for the affected products/models/versions, see …

Jun 14, 2024
CVE-2024-27149
7.4 HIGH

The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. As for the affected products/models/versions, see …

Jun 14, 2024
CVE-2024-27148
7.4 HIGH

The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. As for the affected products/models/versions, see …

Jun 14, 2024
CVE-2024-27147
7.4 HIGH

The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. As for the affected products/models/versions, see …

Jun 14, 2024
CVE-2024-5984
7.3 HIGH

A vulnerability was found in itsourcecode Online Bookstore 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the …

Jun 14, 2024
CVE-2024-5983
7.3 HIGH

A vulnerability was found in itsourcecode Online Bookstore 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the …

Jun 14, 2024
CVE-2024-0099
7.8 HIGH

NVIDIA vGPU software for Linux contains a vulnerability in the Virtual GPU Manager, where the guest OS could cause buffer overrun in the host. A …

Jun 13, 2024
CVE-2024-0091
7.8 HIGH

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where a user can cause an untrusted pointer dereference by executing a driver API. …

Jun 13, 2024
CVE-2024-0090
7.8 HIGH

NVIDIA GPU driver for Windows and Linux contains a vulnerability where a user can cause an out-of-bounds write. A successful exploit of this vulnerability might …

Jun 13, 2024
CVE-2024-0089
7.8 HIGH

NVIDIA GPU Display Driver for Windows contains a vulnerability where the information from a previous client or another process could be disclosed. A successful exploit …

Jun 13, 2024
CVE-2024-0084
7.8 HIGH

NVIDIA vGPU software for Linux contains a vulnerability in the Virtual GPU Manager, where the guest OS could execute privileged operations. A successful exploit of …

Jun 13, 2024
CVE-2024-5976
7.3 HIGH

A vulnerability was found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. It has been classified as critical. Affected is the function log_employee …

Jun 13, 2024
CVE-2024-32929
8.1 HIGH

In gpu_slc_get_region of pixel_gpu_slc.c, there is a possible EoP due to a use after free. This could lead to local escalation of privilege with no …

Jun 13, 2024
CVE-2024-32925
8.8 HIGH

In dhd_prot_txstatus_process of dhd_msgbuf.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution …

Jun 13, 2024
CVE-2024-32924
7.5 HIGH

In DeregAcceptProcINT of cn_NrmmStateDeregInit.cpp, there is a possible denial of service due to a logic error in the code. This could lead to remote denial …

Jun 13, 2024
CVE-2024-32922
7.4 HIGH

In gpu_pm_power_on_top_nolock of pixel_gpu_power.c, there is a possible compromise of protected memory due to a logic error in the code. This could lead to local …

Jun 13, 2024
CVE-2024-32921
7.4 HIGH

In lwis_initialize_transaction_fences of lwis_fence.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of …

Jun 13, 2024
CVE-2024-32920
7.1 HIGH

In set_secure_reg of sac_handler.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure …

Jun 13, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.