CVE Database

38976+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-30280
7.8 HIGH

Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read …

May 23, 2024
CVE-2024-30279
7.8 HIGH

Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

May 23, 2024
CVE-2024-4835
8.0 HIGH

A XSS condition exists within GitLab in versions 15.11 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1. By leveraging this condition, an attacker can …

May 23, 2024
CVE-2024-36012
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: msft: fix slab-use-after-free in msft_do_close() Tying the msft->data lifetime to hdev by freeing it …

May 23, 2024
CVE-2024-2038
7.5 HIGH

The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, …

May 23, 2024
CVE-2024-4388
7.5 HIGH

This does not validate a path generated with user input when downloading files, allowing unauthenticated user to download arbitrary files from the server

May 23, 2024
CVE-2024-4347
7.2 HIGH

The WP Fastest Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.2.6 via the specificDeleteCache function. This …

May 23, 2024
CVE-2024-3594
8.7 HIGH

The IDonate WordPress plugin through 1.9.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

May 23, 2024
CVE-2024-4662
8.8 HIGH

The Oxygen Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.8.2 via post metadata. This is …

May 23, 2024
CVE-2024-4978
8.4 HIGH KEV

Justice AV Solutions Viewer Setup 8.3.7.250-1 contains a malicious binary when executed and is signed with an unexpected authenticode signature. A remote, privileged threat actor …

May 23, 2024
CVE-2024-29853
7.8 HIGH

An authentication bypass vulnerability in Veeam Agent for Microsoft Windows allows for local privilege escalation.

May 22, 2024
CVE-2024-29851
7.2 HIGH

Veeam Backup Enterprise Manager allows high-privileged users to steal NTLM hash of Enterprise manager service account.

May 22, 2024
CVE-2024-29850
8.8 HIGH

Veeam Backup Enterprise Manager allows account takeover via NTLM relay.

May 22, 2024
CVE-2024-4454
7.8 HIGH

WithSecure Elements Endpoint Protection Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of WithSecure Elements Endpoint …

May 22, 2024
CVE-2024-4453
7.8 HIGH

GStreamer EXIF Metadata Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction …

May 22, 2024
CVE-2024-27264
7.4 HIGH

IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated privileges due to an unqualified library call. …

May 22, 2024
CVE-2023-51636
7.8 HIGH

Avira Prime Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Avira Prime. An attacker must …

May 22, 2024
CVE-2024-20360
8.8 HIGH

A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct SQL injection attacks …

May 22, 2024
CVE-2024-36077
8.8 HIGH

Qlik Sense Enterprise for Windows before 14.187.4 allows a remote attacker to elevate their privilege due to improper validation. The attacker can elevate their privilege …

May 22, 2024
CVE-2024-5160
8.8 HIGH

Heap buffer overflow in Dawn in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to perform an out of bounds memory write via a …

May 22, 2024
CVE-2024-5159
8.8 HIGH

Heap buffer overflow in ANGLE in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to perform an out of bounds memory read via a …

May 22, 2024
CVE-2024-5158
8.1 HIGH

Type Confusion in V8 in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to potentially perform arbitrary read/write via a crafted HTML page. (Chromium …

May 22, 2024
CVE-2024-5157
8.8 HIGH

Use after free in Scheduling in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted …

May 22, 2024
CVE-2024-34448
8.8 HIGH

Ghost before 5.82.0 allows CSV Injection during a member CSV export.

May 22, 2024
CVE-2024-33228
8.4 HIGH

An issue in the component segwindrvx64.sys of Insyde Software Corp SEG Windows Driver v100.00.07.02 allows attackers to escalate privileges and execute arbitrary code via sending …

May 22, 2024
CVE-2024-33227
8.8 HIGH

An issue in the component ddcdrv.sys of Nicomsoft WinI2C/DDC v3.7.4.0 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.

May 22, 2024
CVE-2024-33225
7.8 HIGH

An issue in the component RTKVHD64.sys of Realtek Semiconductor Corp Realtek(r) High Definition Audio Function Driver v6.0.9549.1 allows attackers to escalate privileges and execute arbitrary …

May 22, 2024
CVE-2024-33224
8.4 HIGH

An issue in the component rtkio64.sys of Realtek Semiconductor Corp Realtek lO Driver v1.008.0823.2017 allows attackers to escalate privileges and execute arbitrary code via sending …

May 22, 2024
CVE-2024-33223
8.8 HIGH

An issue in the component IOMap64.sys of ASUSTeK Computer Inc ASUS GPU TweakII v1.4.5.2 allows attackers to escalate privileges and execute arbitrary code via sending …

May 22, 2024
CVE-2024-33222
8.4 HIGH

An issue in the component ATSZIO64.sys of ASUSTeK Computer Inc ASUS ATSZIO Driver v0.2.1.7 allows attackers to escalate privileges and execute arbitrary code via sending …

May 22, 2024
CVE-2024-33221
7.8 HIGH

An issue in the component AsusBSItf.sys of ASUSTeK Computer Inc ASUS BIOS Flash Driver v3.2.12.0 allows attackers to escalate privileges and execute arbitrary code via …

May 22, 2024
CVE-2024-33220
8.8 HIGH

An issue in the component AslO3_64.sys of ASUSTeK Computer Inc AISuite3 v3.03.36 3.03.36 allows attackers to escalate privileges and execute arbitrary code via sending crafted …

May 22, 2024
CVE-2024-33219
7.8 HIGH

An issue in the component AsIO64.sys of ASUSTeK Computer Inc ASUS SABERTOOTH X99 Driver v1.0.1.0 allows attackers to escalate privileges and execute arbitrary code via …

May 22, 2024
CVE-2024-33218
7.8 HIGH

An issue in the component AsUpIO64.sys of ASUSTeK Computer Inc ASUS USB 3.0 Boost Storage Driver 5.30.20.0 allows attackers to escalate privileges and execute arbitrary …

May 22, 2024
CVE-2024-35559
8.8 HIGH

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoMove_deal.php?mudi=rev&nohrefStr=close.

May 22, 2024
CVE-2024-35558
8.8 HIGH

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ca_deal.php?mudi=rev&nohrefStr=close.

May 22, 2024
CVE-2024-35556
8.8 HIGH

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/vpsSys_deal.php?mudi=infoSet.

May 22, 2024
CVE-2024-35553
8.3 HIGH

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoMove_deal.php?mudi=add&nohrefStr=close.

May 22, 2024
CVE-2024-35552
8.8 HIGH

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoMove_deal.php?mudi=del&dataType=logo&dataTypeCN.

May 22, 2024
CVE-2024-5031
8.5 HIGH

The Memberpress plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 1.11.29 via the 'mepr-user-file' shortcode. This …

May 22, 2024
CVE-2021-47497
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: nvmem: Fix shift-out-of-bound (UBSAN) with byte size cells If a cell has 'nbits' equal to …

May 22, 2024
CVE-2021-47496
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: net/tls: Fix flipped sign in tls_err_abort() calls sk->sk_err appears to expect a positive value, a …

May 22, 2024
CVE-2021-47489
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix even more out of bound writes from debugfs CVE-2021-42327 was fixed by: commit …

May 22, 2024
CVE-2021-47486
7.5 HIGH

In the Linux kernel, the following vulnerability has been resolved: riscv, bpf: Fix potential NULL dereference The bpf_jit_binary_free() function requires a non-NULL argument. When the …

May 22, 2024
CVE-2021-47485
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: IB/qib: Protect from buffer overflow in struct qib_user_sdma_pkt fields Overflowing either addrlimit or bytes_togo can …

May 22, 2024
CVE-2021-47483
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: regmap: Fix possible double-free in regcache_rbtree_exit() In regcache_rbtree_insert_to_block(), when 'present' realloc failed, the 'blk' which …

May 22, 2024
CVE-2021-47479
7.0 HIGH

In the Linux kernel, the following vulnerability has been resolved: staging: rtl8712: fix use-after-free in rtl8712_dl_fw Syzbot reported use-after-free in rtl8712_dl_fw(). The problem was in …

May 22, 2024
CVE-2021-47477
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: comedi: dt9812: fix DMA buffers on stack USB transfer buffers are typically mapped for DMA …

May 22, 2024
CVE-2021-47475
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: comedi: vmk80xx: fix transfer-buffer overflows The driver uses endpoint-sized USB transfer buffers but up until …

May 22, 2024
CVE-2021-47474
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: comedi: vmk80xx: fix bulk-buffer overflow The driver is using endpoint-sized buffers but must not assume …

May 22, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.