CVE Database

38976+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-34103
8.1 HIGH

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could …

Jun 13, 2024
CVE-2024-26029
7.5 HIGH

Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker …

Jun 13, 2024
CVE-2024-4145
7.2 HIGH

The Search & Replace WordPress plugin before 3.2.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to …

Jun 13, 2024
CVE-2024-2098
7.5 HIGH

The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to an improper authorization check on the 'protectMediaLibrary' function in all …

Jun 13, 2024
CVE-2024-3467
7.8 HIGH

There is a vulnerability in AVEVA PI Asset Framework Client that could allow malicious code to execute on the PI System Explorer environment under the …

Jun 12, 2024
CVE-2024-37665
8.8 HIGH

An access control issue in Wvp GB28181 Pro 2.0 allows authenticated attackers to escalate privileges to Administrator via a crafted POST request.

Jun 12, 2024
CVE-2024-2747
7.8 HIGH

CWE-428: Unquoted search path or element vulnerability exists in Easergy Studio, which could cause privilege escalation when a valid user replaces a trusted file name …

Jun 12, 2024
CVE-2024-0865
7.8 HIGH

CWE-798: Use of hard-coded credentials vulnerability exists that could cause local privilege escalation when logged in as a non-administrative user.

Jun 12, 2024
CVE-2024-5908
7.5 HIGH

A problem with the Palo Alto Networks GlobalProtect app can result in exposure of encrypted user credentials, used for connecting to GlobalProtect, in application logs. …

Jun 12, 2024
CVE-2024-5907
7.0 HIGH

A privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XDR agent on Windows devices enables a local user to execute programs with elevated …

Jun 12, 2024
CVE-2024-37038
7.5 HIGH

CWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated user with access to the device’s web interface to perform unauthorized file and firmware …

Jun 12, 2024
CVE-2024-37037
8.1 HIGH

CWE-22: Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability exists that could allow an authenticated user with access to the device’s …

Jun 12, 2024
CVE-2024-5896
7.3 HIGH

A vulnerability, which was classified as critical, was found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. Affected is the function save_users of …

Jun 12, 2024
CVE-2024-37300
8.1 HIGH

OAuthenticator is software that allows OAuth2 identity providers to be plugged in and used with JupyterHub. JupyterHub < 5.0, when used with `GlobusOAuthenticator`, could be …

Jun 12, 2024
CVE-2024-5894
7.3 HIGH

A vulnerability classified as critical was found in SourceCodester Online Eyewear Shop 1.0. This vulnerability affects unknown code of the file manage_product.php. The manipulation of …

Jun 12, 2024
CVE-2024-34065
7.1 HIGH

Strapi is an open-source content management system. By combining two vulnerabilities (an `Open Redirect` and `session token sent as URL query parameter`) in @strapi/plugin-users-permissions before …

Jun 12, 2024
CVE-2024-28964
7.8 HIGH

Dell Common Event Enabler, version 8.9.10.0 and prior, contain an insecure deserialization vulnerability in CAVATools. A local unauthenticated attacker could potentially exploit this vulnerability, leading …

Jun 12, 2024
CVE-2024-36263
8.1 HIGH

** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Submarine Server Core. This issue …

Jun 12, 2024
CVE-2024-25949
8.8 HIGH

Dell OS10 Networking Switches, versions10.5.6.x, 10.5.5.x, 10.5.4.x and 10.5.3.x ,contain an improper authorization vulnerability. A remote authenticated attacker could potentially exploit this vulnerability leading to …

Jun 12, 2024
CVE-2024-5211
7.2 HIGH

A path traversal vulnerability in mintplex-labs/anything-llm allowed a manager to bypass the `normalizePath()` function, intended to defend against path traversal attacks. This vulnerability enables the …

Jun 12, 2024
CVE-2024-4845
8.8 HIGH

The Icegram Express plugin for WordPress is vulnerable to SQL Injection via the ‘options[list_id]’ parameter in all versions up to, and including, 5.7.22 due to …

Jun 12, 2024
CVE-2023-48280
7.5 HIGH

Missing Authorization vulnerability in Consensu.IO Consensu.Io.This issue affects Consensu.Io: from n/a through 1.0.1.

Jun 12, 2024
CVE-2024-5154
8.1 HIGH

A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary files on the host via directory traversal (“../“). This …

Jun 12, 2024
CVE-2024-3183
8.1 HIGH

A vulnerability was found in FreeIPA in a way when a Kerberos TGS-REQ is encrypted using the client’s session key. This key is different for …

Jun 12, 2024
CVE-2024-2698
8.8 HIGH

A vulnerability was found in FreeIPA in how the initial implementation of MS-SFU by MIT Kerberos was missing a condition for granting the "forwardable" flag …

Jun 12, 2024
CVE-2024-36856
7.5 HIGH

RMQTT Broker 0.4.0 is vulnerable to Denial of Service (DoS) due to improper session resource management. An attacker can exhaust system memory and crash the …

Jun 12, 2024
CVE-2024-5543
8.1 HIGH

The Slideshow Gallery LITE plugin for WordPress is vulnerable to time-based SQL Injection via the id parameter in all versions up to, and including, 1.8.1 …

Jun 12, 2024
CVE-2024-5847
8.8 HIGH

Use after free in PDFium in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. …

Jun 11, 2024
CVE-2024-5846
8.8 HIGH

Use after free in PDFium in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. …

Jun 11, 2024
CVE-2024-5845
8.8 HIGH

Use after free in Audio in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. …

Jun 11, 2024
CVE-2024-5844
8.8 HIGH

Heap buffer overflow in Tab Strip in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to perform an out of bounds memory read via …

Jun 11, 2024
CVE-2024-5842
8.8 HIGH

Use after free in Browser UI in Google Chrome prior to 126.0.6478.54 allowed a remote attacker who convinced a user to engage in specific UI …

Jun 11, 2024
CVE-2024-5841
8.8 HIGH

Use after free in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Jun 11, 2024
CVE-2024-5838
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to perform out of bounds memory access via a crafted HTML …

Jun 11, 2024
CVE-2024-5837
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially perform out of bounds memory access via a crafted …

Jun 11, 2024
CVE-2024-5836
8.8 HIGH

Inappropriate Implementation in DevTools in Google Chrome prior to 126.0.6478.54 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary …

Jun 11, 2024
CVE-2024-5835
8.8 HIGH

Heap buffer overflow in Tab Groups in Google Chrome prior to 126.0.6478.54 allowed a remote attacker who convinced a user to engage in specific UI …

Jun 11, 2024
CVE-2024-5834
8.8 HIGH

Inappropriate implementation in Dawn in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security …

Jun 11, 2024
CVE-2024-5833
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially perform out of bounds memory access via a crafted …

Jun 11, 2024
CVE-2024-5832
8.8 HIGH

Use after free in Dawn in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Jun 11, 2024
CVE-2024-5831
8.8 HIGH

Use after free in Dawn in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Jun 11, 2024
CVE-2024-5830
8.8 HIGH

Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to perform an out of bounds memory write via a crafted …

Jun 11, 2024
CVE-2024-33606
8.8 HIGH

An attacker could retrieve sensitive files (medical images) as well as plant new medical images or overwrite existing medical images on a MicroDicom DICOM Viewer …

Jun 11, 2024
CVE-2024-28877
8.8 HIGH

MicroDicom DICOM Viewer is vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code on affected installations of DICOM Viewer. …

Jun 11, 2024
CVE-2023-4727
7.5 HIGH

A flaw was found in dogtag-pki and pki-core. The token authentication scheme can be bypassed with a LDAP injection. By passing the query string parameter …

Jun 11, 2024
CVE-2024-37301
7.2 HIGH

Document Merge Service is a document template merge service providing an API to manage templates and merge them with given data. Versions 6.5.1 and prior …

Jun 11, 2024
CVE-2024-36702
7.4 HIGH

libiec61850 v1.5 was discovered to contain a heap overflow via the BerEncoder_encodeLength function at /asn1/ber_encoder.c.

Jun 11, 2024
CVE-2024-28020
8.0 HIGH

A user/password reuse vulnerability exists in the FOXMAN-UN/UNEM application and server management. If exploited a malicious high-privileged user could use the passwords and login information …

Jun 11, 2024
CVE-2024-4190
8.1 HIGH

Stored Cross-Site Scripting (XSS) vulnerabilities have been identified in OpenText ArcSight Logger. The vulnerabilities could be remotely exploited.

Jun 11, 2024
CVE-2024-37325
8.1 HIGH

Azure Science Virtual Machine (DSVM) Elevation of Privilege Vulnerability

Jun 11, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.