CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-43489
5.5 MEDIUM

Improper access control for some Intel(R) CIP software before version 2.4.10717 may allow an authenticated user to potentially enable denial of service via local access.

Aug 14, 2024
CVE-2023-40067
5.7 MEDIUM

Unchecked return value in firmware for some Intel(R) CSME may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

Aug 14, 2024
CVE-2023-38655
6.8 MEDIUM

Improper buffer restrictions in firmware for some Intel(R) AMT and Intel(R) Standard Manageability may allow a privileged user to potentially enable denial of service via …

Aug 14, 2024
CVE-2023-35123
4.3 MEDIUM

Uncaught exception in OpenBMC Firmware for some Intel(R) Server Platforms before versions egs-1.14-0, bhs-0.27 may allow an authenticated user to potentially enable denial of service …

Aug 14, 2024
CVE-2023-34424
4.4 MEDIUM

Improper input validation in firmware for some Intel(R) CSME may allow a privileged user to potentially enable denial of service via local access.

Aug 14, 2024
CVE-2024-39419
4.3 MEDIUM

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A …

Aug 14, 2024
CVE-2024-39418
5.4 MEDIUM

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A …

Aug 14, 2024
CVE-2024-39417
4.3 MEDIUM

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A …

Aug 14, 2024
CVE-2024-39416
4.3 MEDIUM

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A …

Aug 14, 2024
CVE-2024-39415
4.3 MEDIUM

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A …

Aug 14, 2024
CVE-2024-39414
4.3 MEDIUM

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A …

Aug 14, 2024
CVE-2024-39413
4.3 MEDIUM

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A …

Aug 14, 2024
CVE-2024-39412
4.3 MEDIUM

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A …

Aug 14, 2024
CVE-2024-39411
4.3 MEDIUM

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A …

Aug 14, 2024
CVE-2024-39410
4.3 MEDIUM

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could allow an attacker to bypass …

Aug 14, 2024
CVE-2024-39409
4.3 MEDIUM

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could allow an attacker to bypass …

Aug 14, 2024
CVE-2024-39408
4.3 MEDIUM

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could allow an attacker to bypass …

Aug 14, 2024
CVE-2024-39407
4.3 MEDIUM

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A …

Aug 14, 2024
CVE-2024-39406
6.8 MEDIUM

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability …

Aug 14, 2024
CVE-2024-39405
4.3 MEDIUM

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A …

Aug 14, 2024
CVE-2024-39404
4.3 MEDIUM

Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A …

Aug 14, 2024
CVE-2024-6532
6.4 MEDIUM

The Sheet to Table Live Sync for Google Sheet plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's STWT_Sheet_Table shortcode in all …

Aug 14, 2024
CVE-2024-38483
5.8 MEDIUM

Dell BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, …

Aug 14, 2024
CVE-2024-41863
5.5 MEDIUM

Substance3D - Sampler versions 4.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Aug 14, 2024
CVE-2024-41862
5.5 MEDIUM

Substance3D - Sampler versions 4.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Aug 14, 2024
CVE-2024-41861
5.5 MEDIUM

Substance3D - Sampler versions 4.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Aug 14, 2024
CVE-2024-41860
5.5 MEDIUM

Substance3D - Sampler versions 4.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

Aug 14, 2024
CVE-2024-7588
6.4 MEDIUM

The Gutenberg Blocks, Page Builder – ComboBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Accordion block in all versions up …

Aug 14, 2024
CVE-2024-7754
6.3 MEDIUM

A vulnerability was found in SourceCodester Clinics Patient Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the …

Aug 14, 2024
CVE-2024-7753
5.3 MEDIUM

A vulnerability was found in SourceCodester Clinics Patient Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file …

Aug 14, 2024
CVE-2024-7751
6.3 MEDIUM

A vulnerability was found in SourceCodester Clinics Patient Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Aug 13, 2024
CVE-2024-7750
6.3 MEDIUM

A vulnerability has been found in SourceCodester Clinics Patient Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of …

Aug 13, 2024
CVE-2024-7748
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Accounts Manager App 1.0. This issue affects some unknown processing of the file …

Aug 13, 2024
CVE-2024-7741
5.3 MEDIUM

A vulnerability was found in wanglongcn ltcms 1.0.20 and classified as critical. This issue affects the function downloadFile of the file /api/file/downloadfile of the component …

Aug 13, 2024
CVE-2024-42368
6.5 MEDIUM

OpenTelemetry, also known as OTel, is a vendor-neutral open source Observability framework for instrumenting, generating, collecting, and exporting telemetry data such as traces, metrics, and …

Aug 13, 2024
CVE-2024-7739
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in yzane vscode-markdown-pdf 1.5.0. This affects an unknown part. The manipulation leads to cross site scripting. …

Aug 13, 2024
CVE-2024-38223
6.8 MEDIUM

Windows Initial Machine Configuration Elevation of Privilege Vulnerability

Aug 13, 2024
CVE-2024-38214
6.5 MEDIUM

Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

Aug 13, 2024
CVE-2024-38213
6.5 MEDIUM KEV

Windows Mark of the Web Security Feature Bypass Vulnerability

Aug 13, 2024
CVE-2024-38197
6.5 MEDIUM

Microsoft Teams for iOS Spoofing Vulnerability

Aug 13, 2024
CVE-2024-38173
6.7 MEDIUM

Microsoft Outlook Remote Code Execution Vulnerability

Aug 13, 2024
CVE-2024-38167
6.5 MEDIUM

.NET and Visual Studio Information Disclosure Vulnerability

Aug 13, 2024
CVE-2024-38165
6.5 MEDIUM

Windows Compressed Folder Tampering Vulnerability

Aug 13, 2024
CVE-2024-38161
6.8 MEDIUM

Windows Mobile Broadband Driver Remote Code Execution Vulnerability

Aug 13, 2024
CVE-2024-38155
5.5 MEDIUM

Security Center Broker Information Disclosure Vulnerability

Aug 13, 2024
CVE-2024-38151
5.5 MEDIUM

Windows Kernel Information Disclosure Vulnerability

Aug 13, 2024
CVE-2024-38143
4.2 MEDIUM

Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability

Aug 13, 2024
CVE-2024-38123
4.4 MEDIUM

Windows Bluetooth Driver Information Disclosure Vulnerability

Aug 13, 2024
CVE-2024-38122
5.5 MEDIUM

Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability

Aug 13, 2024
CVE-2024-38118
5.5 MEDIUM

Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability

Aug 13, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.