CVE Database

38976+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-36960
7.1 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix invalid reads in fence signaled events Correctly set the length of the drm_event …

Jun 3, 2024
CVE-2024-20066
7.5 HIGH

In modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote denial of service with …

Jun 3, 2024
CVE-2024-36390
7.5 HIGH

MileSight DeviceHub - CWE-20 Improper Input Validation may allow Denial of Service

Jun 2, 2024
CVE-2024-2178
7.5 HIGH

A path traversal vulnerability exists in the parisneo/lollms-webui, specifically within the 'copy_to_custom_personas' endpoint in the 'lollms_personalities_infos.py' file. This vulnerability allows attackers to read arbitrary files …

Jun 2, 2024
CVE-2024-4148
7.5 HIGH

A Regular Expression Denial of Service (ReDoS) vulnerability exists in the lunary-ai/lunary application, version 1.2.10. An attacker can exploit this vulnerability by maliciously manipulating regular …

Jun 1, 2024
CVE-2024-5348
8.8 HIGH

The Elements For Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.1 via the 'beforeafter_layout' attribute …

Jun 1, 2024
CVE-2024-3821
7.3 HIGH

The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability …

Jun 1, 2024
CVE-2024-4958
7.1 HIGH

The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data due …

Jun 1, 2024
CVE-2024-3564
8.8 HIGH

The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.0 via the …

Jun 1, 2024
CVE-2024-5138
8.1 HIGH

The snapctl component within snapd allows a confined snap to interact with the snapd daemon to take certain privileged actions on behalf of the snap. …

May 31, 2024
CVE-2024-34009
7.5 HIGH

Insufficient checks whether ReCAPTCHA was enabled made it possible to bypass the checks on the login page. This did not affect other pages where ReCAPTCHA …

May 31, 2024
CVE-2024-34008
8.8 HIGH

Actions in the admin management of analytics models did not include the necessary token to prevent a CSRF risk.

May 31, 2024
CVE-2024-34007
8.8 HIGH

The logout option within MFA did not include the necessary token to avoid the risk of users inadvertently being logged out via CSRF.

May 31, 2024
CVE-2024-36844
7.5 HIGH

libmodbus v3.1.6 was discovered to contain a use-after-free via the ctx->backend pointer. This vulnerability allows attackers to cause a Denial of Service (DoS) via a …

May 31, 2024
CVE-2024-36843
7.5 HIGH

libmodbus v3.1.6 was discovered to contain a heap overflow via the modbus_mapping_free() function.

May 31, 2024
CVE-2024-34001
8.4 HIGH

Actions in the admin preset tool did not include the necessary token to prevent a CSRF risk.

May 31, 2024
CVE-2024-5564
8.1 HIGH

A vulnerability was found in libndp. This flaw allows a local malicious user to cause a buffer overflow in NetworkManager, triggered by sending a malformed …

May 31, 2024
CVE-2024-29848
7.2 HIGH

An unrestricted file upload vulnerability in web component of Ivanti Avalanche before 6.4.x allows an authenticated, privileged user to execute arbitrary commands as SYSTEM.

May 31, 2024
CVE-2024-29846
8.0 HIGH

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute …

May 31, 2024
CVE-2024-29830
8.0 HIGH

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute …

May 31, 2024
CVE-2024-29829
8.0 HIGH

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute …

May 31, 2024
CVE-2024-29828
8.0 HIGH

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute …

May 31, 2024
CVE-2024-29827
8.8 HIGH

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute …

May 31, 2024
CVE-2024-29826
8.8 HIGH

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute …

May 31, 2024
CVE-2024-29825
8.8 HIGH

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute …

May 31, 2024
CVE-2024-29824
8.8 HIGH KEV

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute …

May 31, 2024
CVE-2024-29823
8.8 HIGH

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute …

May 31, 2024
CVE-2024-29822
8.8 HIGH

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute …

May 31, 2024
CVE-2024-22059
8.8 HIGH

A SQL injection vulnerability in web component of Ivanti Neurons for ITSM allows a remote authenticated user to read/modify/delete information in the underlying database. This …

May 31, 2024
CVE-2024-22058
7.8 HIGH

A buffer overflow allows a low privilege user on the local machine that has the EPM Agent installed to execute arbitrary code with elevated permissions …

May 31, 2024
CVE-2023-46810
7.3 HIGH

A local privilege escalation vulnerability in Ivanti Secure Access Client for Linux before 22.7R1, allows a low privileged user to execute code as root.

May 31, 2024
CVE-2023-38551
8.2 HIGH

A CRLF Injection vulnerability in Ivanti Connect Secure (9.x, 22.x) allows an authenticated high-privileged user to inject malicious code on a victim’s browser, thereby leading …

May 31, 2024
CVE-2023-38042
7.8 HIGH

A local privilege escalation vulnerability in Ivanti Secure Access Client for Windows allows a low privileged user to execute code as SYSTEM.

May 31, 2024
CVE-2024-36120
8.1 HIGH

javascript-deobfuscator removes common JavaScript obfuscation techniques. In affected versions crafted payloads targeting expression simplification can lead to code execution. This issue has been patched in …

May 31, 2024
CVE-2024-35142
8.4 HIGH

IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to execution of unnecessary privileges. IBM X-Force …

May 31, 2024
CVE-2024-35140
7.7 HIGH

IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to improper certificate validation. IBM X-Force ID: …

May 31, 2024
CVE-2024-28736
7.1 HIGH

An issue in Debezium Community debezium-ui v.2.5 allows a local attacker to execute arbitrary code via the refresh page function.

May 31, 2024
CVE-2024-5565
8.1 HIGH

The Vanna library uses a prompt function to present the user with visualized results, it is possible to alter the prompt using prompt injection and …

May 31, 2024
CVE-2024-5525
8.3 HIGH

Improper privilege management vulnerability in Astrotalks affecting version 10/03/2023. This vulnerability allows a local user to access the application as an administrator without any provided …

May 31, 2024
CVE-2024-5523
8.8 HIGH

SQL injection vulnerability in Astrotalks affecting version 10/03/2023. This vulnerability could allow an authenticated local user to send a specially crafted SQL query to the …

May 31, 2024
CVE-2024-4469
7.5 HIGH

The WP STAGING WordPress Backup Plugin WordPress plugin before 3.5.0 does not prevent users with the administrator role from pinging conducting SSRF attacks, which may …

May 31, 2024
CVE-2024-2793
7.2 HIGH

The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to Stored Cross-Site Scripting via comments in all versions up …

May 31, 2024
CVE-2024-37032
8.8 HIGH

Ollama before 0.1.34 does not validate the format of the digest (sha256 with 64 hex digits) when getting the model path, and thus mishandles the …

May 31, 2024
CVE-2024-5345
8.8 HIGH

The Responsive Owl Carousel for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.2.0 via the …

May 31, 2024
CVE-2024-37017
8.1 HIGH

asdcplib (aka AS-DCP Lib) 2.13.1 has a heap-based buffer over-read in ASDCP::TimedText::MXFReader::h__Reader::MD_to_TimedText_TDesc in AS_DCP_TimedText.cpp in libasdcp.so.

May 31, 2024
CVE-2024-5499
8.8 HIGH

Out of bounds write in Streams API in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to execute arbitrary code inside a sandbox via …

May 30, 2024
CVE-2024-5498
8.8 HIGH

Use after free in Presentation API in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML …

May 30, 2024
CVE-2024-5497
8.8 HIGH

Out of bounds memory access in Browser UI in Google Chrome prior to 125.0.6422.141 allowed a remote attacker who convinced a user to engage in …

May 30, 2024
CVE-2024-5496
8.8 HIGH

Use after free in Media Session in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to execute arbitrary code inside a sandbox via a …

May 30, 2024
CVE-2024-5495
8.8 HIGH

Use after free in Dawn in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

May 30, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.