CVE Database

39204+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-3355
7.3 HIGH

A vulnerability was found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0. It has been declared as critical. Affected by this vulnerability is an …

Apr 5, 2024
CVE-2024-30977
7.8 HIGH

An issue in Secnet Security Network Intelligent AC Management System v.1.02.040 allows a local attacker to escalate privileges via the password component.

Apr 5, 2024
CVE-2024-27912
7.5 HIGH

A denial of service vulnerability was reported in some Lenovo Printers that could allow an attacker to cause the device to crash by sending crafted …

Apr 5, 2024
CVE-2024-27911
7.5 HIGH

A vulnerability was reported in some Lenovo Printers that could allow an unauthenticated attacker to obtain the administrator password.

Apr 5, 2024
CVE-2024-3354
7.3 HIGH

A vulnerability was found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0. It has been classified as critical. Affected is an unknown function of …

Apr 5, 2024
CVE-2024-3353
7.3 HIGH

A vulnerability was found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0 and classified as critical. This issue affects some unknown processing of the …

Apr 5, 2024
CVE-2024-29757
7.3 HIGH

there is a possible permission bypass due to Debug certs being allowlisted. This could lead to local escalation of privilege with no additional execution privileges …

Apr 5, 2024
CVE-2024-29753
7.7 HIGH

In tmu_set_control_temp_step of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of …

Apr 5, 2024
CVE-2024-29752
7.8 HIGH

In tmu_set_tr_num_thresholds of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of …

Apr 5, 2024
CVE-2024-29749
8.4 HIGH

In tmu_set_tr_thresholds of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of …

Apr 5, 2024
CVE-2024-29748
7.8 HIGH KEV

there is a possible way to bypass due to a logic error in the code. This could lead to local escalation of privilege with no …

Apr 5, 2024
CVE-2024-29746
8.4 HIGH

In lpm_req_handler of lpm.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege …

Apr 5, 2024
CVE-2024-29743
7.7 HIGH

In tmu_set_temp_lut of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of …

Apr 5, 2024
CVE-2024-29741
7.8 HIGH

In pblS2mpuResume of s2mpu.c, there is a possible mitigation bypass due to a logic error in the code. This could lead to local escalation of …

Apr 5, 2024
CVE-2024-29740
7.4 HIGH

In tmu_set_table of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of …

Apr 5, 2024
CVE-2024-3352
7.3 HIGH

A vulnerability has been found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0 and classified as critical. This vulnerability affects unknown code of the …

Apr 5, 2024
CVE-2024-0081
8.6 HIGH

NVIDIA NeMo framework for Ubuntu contains a vulnerability in tools/asr_webapp where an attacker may cause an allocation of resources without limits or throttling. A successful …

Apr 5, 2024
CVE-2024-3351
7.3 HIGH

A vulnerability, which was classified as critical, was found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0. This affects an unknown part of the …

Apr 5, 2024
CVE-2024-3350
7.3 HIGH

A vulnerability, which was classified as critical, has been found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0. Affected by this issue is some …

Apr 5, 2024
CVE-2024-31851
8.6 HIGH

A path traversal vulnerability exists in the Java version of CData Sync < 23.4.8843 when running using the embedded Jetty server, which could allow an …

Apr 5, 2024
CVE-2024-31850
8.6 HIGH

A path traversal vulnerability exists in the Java version of CData Arc < 23.4.8839 when running using the embedded Jetty server, which could allow an …

Apr 5, 2024
CVE-2024-3349
7.3 HIGH

A vulnerability classified as critical was found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0. Affected by this vulnerability is an unknown functionality of …

Apr 5, 2024
CVE-2024-3348
7.3 HIGH

A vulnerability classified as critical has been found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0. Affected is an unknown function of the file …

Apr 5, 2024
CVE-2024-3347
7.3 HIGH

A vulnerability was found in SourceCodester Airline Ticket Reservation System 1.0. It has been rated as critical. This issue affects some unknown processing of the …

Apr 5, 2024
CVE-2024-31220
7.3 HIGH

Sunshine is a self-hosted game stream host for Moonlight. Starting in version 0.16.0 and prior to version 0.18.0, an attacker may be able to remotely …

Apr 5, 2024
CVE-2024-31083
7.8 HIGH

A use-after-free vulnerability was found in the ProcRenderAddGlyphs() function of Xorg servers. This issue occurs when AllocateGlyph() is called to store new glyphs sent by …

Apr 5, 2024
CVE-2023-6523
8.8 HIGH

Authorization Bypass Through User-Controlled Key vulnerability in ExtremePacs Extreme XDS allows Authentication Abuse.This issue affects Extreme XDS: before 3914.

Apr 5, 2024
CVE-2023-6522
7.2 HIGH

Incorrect Use of Privileged APIs vulnerability in ExtremePacs Extreme XDS allows Collect Data as Provided by Users.This issue affects Extreme XDS: before 3914.

Apr 5, 2024
CVE-2024-3217
8.8 HIGH

The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'attribute_value' and 'attribute_id' parameters in all versions up to, and including, …

Apr 5, 2024
CVE-2024-30891
8.8 HIGH

A command injection vulnerability exists in /goform/exeCommand in Tenda AC18 v15.03.05.05, which allows attackers to construct cmdinput parameters for arbitrary command execution.

Apr 5, 2024
CVE-2024-2115
8.8 HIGH

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.0.0. This is …

Apr 5, 2024
CVE-2024-29863
7.8 HIGH

A race condition in the installer executable in Qlik Qlikview before versions May 2022 SR3 (12.70.20300) and May 2023 SR2 (12,80.20200) may allow an existing …

Apr 5, 2024
CVE-2024-29672
8.8 HIGH

Directory Traversal vulnerability in zly2006 Reden before v.0.2.514 allows a remote attacker to execute arbitrary code via the DEBUG_RTC_REQUEST_SYNC_DATA in KeyCallbacks.kt.

Apr 5, 2024
CVE-2024-22363
7.5 HIGH

SheetJS Community Edition before 0.20.2 is vulnerable.to Regular Expression Denial of Service (ReDoS).

Apr 5, 2024
CVE-2023-52235
8.8 HIGH

SpaceX Starlink Wi-Fi router GEN 2 before 2023.53.0 and Starlink Dish before 07dd2798-ff15-4722-a9ee-de28928aed34 allow CSRF (e.g., for a reboot) via a DNS Rebinding attack.

Apr 5, 2024
CVE-2024-31498
8.8 HIGH

Yubico ykman-gui (aka YubiKey Manager GUI) before 1.2.6 on Windows, when Edge is not used, allows privilege escalation because browser windows can open as Administrator.

Apr 4, 2024
CVE-2024-31210
7.6 HIGH

WordPress is an open publishing platform for the Web. It's possible for a file of a type other than a zip file to be submitted …

Apr 4, 2024
CVE-2024-31206
8.2 HIGH

dectalk-tts is a Node package to interact with the aeiou Dectalk web API. In `[email protected]`, network requests to the third-party API are sent over HTTP, …

Apr 4, 2024
CVE-2024-30264
8.1 HIGH

Typebot is an open-source chatbot builder. A reflected cross-site scripting (XSS) in the sign-in page of typebot.io prior to version 2.24.0 may allow an attacker …

Apr 4, 2024
CVE-2023-45288
7.5 HIGH

An attacker may cause an HTTP/2 endpoint to read arbitrary amounts of header data by sending an excessive number of CONTINUATION frames. Maintaining HPACK state …

Apr 4, 2024
CVE-2024-29387
8.8 HIGH

projeqtor up to 11.2.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /view/print.php.

Apr 4, 2024
CVE-2024-27316
7.5 HIGH

HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not …

Apr 4, 2024
CVE-2024-22053
8.2 HIGH

A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user to send specially …

Apr 4, 2024
CVE-2024-22052
7.5 HIGH

A null pointer dereference vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user to send …

Apr 4, 2024
CVE-2023-38709
7.3 HIGH

Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses. This issue affects Apache HTTP Server: through …

Apr 4, 2024
CVE-2024-30249
8.6 HIGH

Cloudburst Network provides network components used within Cloudburst projects. A vulnerability in versions prior to `1.0.0.CR1-20240330.101522-15` impacts publicly accessible software depending on the affected versions …

Apr 4, 2024
CVE-2024-25007
7.1 HIGH

Ericsson Network Manager (ENM), versions prior to 23.1, contains a vulnerability in the export function of application log where Improper Neutralization of Formula Elements in …

Apr 4, 2024
CVE-2024-29192
8.8 HIGH

gotortc is a camera streaming application. Versions 1.8.5 and prior are vulnerable to Cross-Site Request Forgery. The `/api/config` endpoint allows one to modify the existing …

Apr 4, 2024
CVE-2024-28787
8.7 HIGH

IBM Security Verify Access 10.0.0 through 10.0.7 and IBM Application Gateway 20.01 through 24.03 could allow a remote attacker to obtain highly sensitive private information …

Apr 4, 2024
CVE-2024-25699
8.5 HIGH

There is a difficult‑to‑exploit improper authentication issue in the Home application for Esri Portal for ArcGIS versions 11.2 and below on Windows and Linux, and …

Apr 4, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.