CVE Database

38976+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-3968
7.8 HIGH

Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger remote code execution using custom file upload task.

May 15, 2024
CVE-2024-3967
7.6 HIGH

Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger remote code execution unisng unsafe java object deserialization.

May 15, 2024
CVE-2024-3892
7.2 HIGH

A local code execution vulnerability is possible in Telerik UI for WinForms beginning in v2021.1.122 but prior to v2024.2.514. This vulnerability could allow an untrusted …

May 15, 2024
CVE-2024-3486
7.8 HIGH

XML External Entity injection vulnerability found in OpenText™ iManager 3.2.6.0200. This could lead to information disclosure and remote code execution.

May 15, 2024
CVE-2024-3483
7.8 HIGH

Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger command injection and insecure deserialization issues.

May 15, 2024
CVE-2024-34082
8.5 HIGH

Grav is a file-based Web platform. Prior to version 1.7.46, a low privilege user account with page edit privilege can read any server files using …

May 15, 2024
CVE-2024-28042
8.4 HIGH

SUBNET Solutions Inc. has identified vulnerabilities in third-party components used in PowerSYSTEM Center.

May 15, 2024
CVE-2023-5938
8.0 HIGH

Multiple functions use archives without properly validating the filenames therein, rendering the application vulnerable to path traversal via 'zip slip' attacks. An administrator able to …

May 15, 2024
CVE-2023-5936
7.8 HIGH

On Unix systems (Linux, MacOS), Arc uses a temporary file with unsafe privileges. By tampering with such file, a malicious local user in the system …

May 15, 2024
CVE-2023-5935
7.4 HIGH

When configuring Arc (e.g. during the first setup), a local web interface is provided to ease the configuration process. Such web interface lacks authentication and …

May 15, 2024
CVE-2024-27353
7.4 HIGH

A memory corruption vulnerability in SdHost and SdMmcDevice in Insyde InsydeH2O kernel 5.2 before 05.29.09, kernel 5.3 before 05.38.09, kernel 5.4 before 05.46.09, kernel 5.5 …

May 15, 2024
CVE-2024-25079
7.4 HIGH

A memory corruption vulnerability in HddPassword in Insyde InsydeH2O kernel 5.2 before 05.29.09, kernel 5.3 before 05.38.09, kernel 5.4 before 05.46.09, kernel 5.5 before 05.54.09, …

May 15, 2024
CVE-2024-25078
7.4 HIGH

A memory corruption vulnerability in StorageSecurityCommandDxe in Insyde InsydeH2O before kernel 5.2: IB19130163 in 05.29.07, kernel 5.3: IB19130163 in 05.38.07, kernel 5.4: IB19130163 in 05.46.07, …

May 15, 2024
CVE-2024-4670
8.8 HIGH

The All-in-One Video Gallery plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.6.5 via the aiovg_search_form shortcode. …

May 15, 2024
CVE-2023-6324
8.1 HIGH

ThroughTek Kalay SDK uses a predictable PSK value in the DTLS session when encountering an unexpected PSK identity

May 15, 2024
CVE-2023-6322
7.2 HIGH

A stack-based buffer overflow vulnerability exists in the message parsing functionality of the Roku Indoor Camera SE version 3.0.2.4679 and Wyze Cam v3 version 4.36.11.5859. …

May 15, 2024
CVE-2023-6321
7.2 HIGH

A command injection vulnerability exists in the IOCTL that manages OTA updates. A specially crafted command can lead to command execution as the root user. …

May 15, 2024
CVE-2024-34100
7.8 HIGH

Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

May 15, 2024
CVE-2024-34099
7.8 HIGH

Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context …

May 15, 2024
CVE-2024-34098
7.8 HIGH

Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context …

May 15, 2024
CVE-2024-34097
7.8 HIGH

Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

May 15, 2024
CVE-2024-34096
7.8 HIGH

Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

May 15, 2024
CVE-2024-34095
7.8 HIGH

Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

May 15, 2024
CVE-2024-34094
7.8 HIGH

Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

May 15, 2024
CVE-2024-30310
7.8 HIGH

Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

May 15, 2024
CVE-2024-30284
7.8 HIGH

Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

May 15, 2024
CVE-2024-4010
8.8 HIGH

The Email Subscribers by Icegram Express plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to …

May 15, 2024
CVE-2024-3406
8.8 HIGH

The WP Prayer WordPress plugin through 2.0.9 does not have CSRF check in place when updating its email settings, which could allow attackers to make …

May 15, 2024
CVE-2024-3405
7.6 HIGH

The WP Prayer WordPress plugin through 2.0.9 does not have CSRF check in place when updating its settings, which could allow attackers to make a …

May 15, 2024
CVE-2024-4847
8.8 HIGH

The Alt Text AI – Automatically generate image alt text for SEO and accessibility plugin for WordPress is vulnerable to generic SQL Injection via the …

May 15, 2024
CVE-2024-35108
8.8 HIGH

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/homePro_deal.php?mudi=del&dataType=&dataTypeCN.

May 15, 2024
CVE-2024-31477
7.2 HIGH

Multiple authenticated command injection vulnerabilities exist in the command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as …

May 14, 2024
CVE-2024-31476
7.2 HIGH

Multiple authenticated command injection vulnerabilities exist in the command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as …

May 14, 2024
CVE-2024-31475
8.2 HIGH

There is an arbitrary file deletion vulnerability in the Central Communications service accessed by PAPI (Aruba's access point management protocol). Successful exploitation of this vulnerability …

May 14, 2024
CVE-2024-31474
8.2 HIGH

There is an arbitrary file deletion vulnerability in the CLI service accessed by PAPI (Aruba's Access Point management protocol). Successful exploitation of this vulnerability results …

May 14, 2024
CVE-2023-33327
8.8 HIGH

Improper Privilege Management vulnerability in Teplitsa of social technologies Leyka allows Privilege Escalation.This issue affects Leyka: from n/a through 3.30.2.

May 14, 2024
CVE-2024-31556
7.8 HIGH

An issue in Reportico Web before v.8.1.0 allows a local attacker to execute arbitrary code and obtain sensitive information via the sessionid function.

May 14, 2024
CVE-2022-28132
7.2 HIGH

The T-Soft E-Commerce 4 web application is susceptible to SQL injection (SQLi) attacks when authenticated as an admin or privileged user. This vulnerability allows attackers …

May 14, 2024
CVE-2020-26312
8.1 HIGH

Dotmesh is a git-like command-line interface for capturing, organizing and sharing application states. In versions 0.8.1 and prior, the unsafe handling of symbolic links in …

May 14, 2024
CVE-2024-32465
7.3 HIGH

Git is a revision control system. The Git project recommends to avoid working in untrusted repositories, and instead to clone it first with `git clone …

May 14, 2024
CVE-2021-22280
7.2 HIGH

Improper DLL loading algorithms in B&R Automation Studio versions >=4.0 and <4.12 may allow an authenticated local attacker to execute code in the context of …

May 14, 2024
CVE-2024-3676
7.5 HIGH

The Proofpoint Encryption endpoint of Proofpoint Enterprise Protection contains an Improper Input Validation vulnerability that allows an unauthenticated remote attacker with a specially crafted HTTP …

May 14, 2024
CVE-2024-32004
8.1 HIGH

Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, an attacker can prepare a local repository in …

May 14, 2024
CVE-2024-2637
7.2 HIGH

An Uncontrolled Search Path Element vulnerability in B&R Industrial Automation Scene Viewer, B&R Industrial Automation Automation Runtime, B&R Industrial Automation mapp Vision, B&R Industrial Automation …

May 14, 2024
CVE-2024-4777
8.8 HIGH

Memory safety bugs present in Firefox 125, Firefox ESR 115.10, and Thunderbird 115.10. Some of these bugs showed evidence of memory corruption and we presume …

May 14, 2024
CVE-2024-4776
8.2 HIGH

A file dialog shown while in full-screen mode could have resulted in the window remaining disabled. This vulnerability affects Firefox < 126.

May 14, 2024
CVE-2024-4773
7.5 HIGH

When a network error occurred during page load, the prior content could have remained in view with a blank URL bar. This could have been …

May 14, 2024
CVE-2024-4771
8.6 HIGH

A memory allocation check was missing which would lead to a use-after-free if the allocation failed. This could have triggered a crash or potentially be …

May 14, 2024
CVE-2024-4770
8.8 HIGH

When saving a page to PDF, certain font styles could have led to a potential use-after-free crash. This vulnerability affects Firefox < 126, Firefox ESR …

May 14, 2024
CVE-2024-4765
8.1 HIGH

Web application manifests were stored by using an insecure MD5 hash which allowed for a hash collision to overwrite another application's manifest. This could have …

May 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.