CVE Database

54613+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-39322
5.5 MEDIUM

aimeos/ai-admin-jsonadm is the Aimeos e-commerce JSON API for administrative tasks. In versions prior to 2020.10.13, 2021.10.6, 2022.10.3, 2023.10.4, and 2024.4.2, improper access control allows editors …

Jul 2, 2024
CVE-2024-6452
6.3 MEDIUM

A vulnerability classified as critical was found in linlinjava litemall up to 1.8.0. Affected by this vulnerability is an unknown functionality of the file AdminGoodscontroller.java. …

Jul 2, 2024
CVE-2024-39315
5.7 MEDIUM

Pomerium is an identity and context-aware access proxy. Prior to version 0.26.1, the Pomerium user info page (at `/.pomerium`) unintentionally included serialized OAuth2 access and …

Jul 2, 2024
CVE-2022-25479
5.5 MEDIUM

Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 allows for …

Jul 2, 2024
CVE-2022-25477
5.5 MEDIUM

Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 leaks driver …

Jul 2, 2024
CVE-2024-6382
6.4 MEDIUM

Incorrect handling of certain string inputs may result in MongoDB Rust driver constructing unintended server commands. This may cause unexpected application behavior including data modification. …

Jul 2, 2024
CVE-2024-6381
4.0 MEDIUM

The bson_strfreev function in the MongoDB C driver library may be susceptible to an integer overflow where the function will try to free memory at …

Jul 2, 2024
CVE-2024-39891
5.3 MEDIUM KEV

In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to certain phone-number data, …

Jul 2, 2024
CVE-2024-5866
5.0 MEDIUM

Vulnerability in Delinea Centrify PAS v. 21.3 and possibly others. The application is prone to the path traversal vulnerability allowing listing of arbitrary directory outside …

Jul 2, 2024
CVE-2024-39316
6.5 MEDIUM

Rack is a modular Ruby web server interface. Starting in version 3.1.0 and prior to version 3.1.5, Regular Expression Denial of Service (ReDoS) vulnerability exists …

Jul 2, 2024
CVE-2024-25087
5.5 MEDIUM

Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.7.0 allows local attackers to cause a Windows blue screen error.

Jul 2, 2024
CVE-2024-22105
5.5 MEDIUM

Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.5.1 allows local attackers to cause a Windows blue screen error.

Jul 2, 2024
CVE-2024-32932
6.8 MEDIUM

Under certain circumstances the web interface users credentials may be recovered by an authenticated user.

Jul 2, 2024
CVE-2024-22104
5.5 MEDIUM

Out-of-Bounds Write vulnerability in Jungo WinDriver before 12.5.1 allows local attackers to cause a Windows blue screen error and Denial of Service (DoS).

Jul 2, 2024
CVE-2024-22103
5.5 MEDIUM

Out-of-Bounds Write vulnerability in Jungo WinDriver before 12.6.0 allows local attackers to cause a Windows blue screen error and Denial of Service (DoS).

Jul 2, 2024
CVE-2024-22102
5.5 MEDIUM

Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.6.0 allows local attackers to cause a Windows blue screen error.

Jul 2, 2024
CVE-2023-51778
5.5 MEDIUM

Out-of-Bounds Write vulnerability in Jungo WinDriver before 12.1.0 allows local attackers to cause a Windows blue screen error and Denial of Service (DoS).

Jul 2, 2024
CVE-2023-51777
5.5 MEDIUM

Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.1.0 allows local attackers to cause a Windows blue screen error.

Jul 2, 2024
CVE-2024-39143
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in ResidenceCMS 2.10.1 that allows a low-privilege user to create malicious property content with HTML inside which acts …

Jul 2, 2024
CVE-2024-32757
6.8 MEDIUM

Under certain circumstances unnecessary user details are provided within system logs

Jul 2, 2024
CVE-2024-32756
6.8 MEDIUM

Under certain circumstances the Linux users credentials may be recovered by an authenticated user.

Jul 2, 2024
CVE-2024-39119
5.4 MEDIUM

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/info_deal.php?mudi=rev&nohrefStr=close.

Jul 2, 2024
CVE-2024-6441
6.3 MEDIUM

A vulnerability was found in ORIPA up to 1.72. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the …

Jul 2, 2024
CVE-2024-6440
6.3 MEDIUM

A vulnerability was found in SourceCodester Home Owners Collection Management System 1.0. It has been classified as critical. Affected is an unknown function of the …

Jul 2, 2024
CVE-2024-6439
6.3 MEDIUM

A vulnerability was found in SourceCodester Home Owners Collection Management System 1.0 and classified as critical. This issue affects some unknown processing of the file …

Jul 2, 2024
CVE-2024-6438
6.3 MEDIUM

A vulnerability has been found in Hitout Carsale 1.0 and classified as critical. This vulnerability affects unknown code of the file OrderController.java. The manipulation of …

Jul 2, 2024
CVE-2024-6264
6.4 MEDIUM

The Post Meta Data Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘$meta_key’ parameter in all versions up to, and including, …

Jul 2, 2024
CVE-2024-6099
5.3 MEDIUM

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthenticated bypass to user registration in versions up to, and including, 4.2.6.8.1. This …

Jul 2, 2024
CVE-2024-6088
5.3 MEDIUM

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to unauthorized user registration due to a missing capability check on the 'register' function …

Jul 2, 2024
CVE-2024-4268
6.4 MEDIUM

The Ultimate Blocks – WordPress Blocks Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blocks in all versions up to, …

Jul 2, 2024
CVE-2024-6012
4.3 MEDIUM

The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'embed-create-page' and 'embed-insert-pages' …

Jul 2, 2024
CVE-2024-6011
4.4 MEDIUM

The Cost Calculator Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘textarea.description’ parameter in all versions up to, and including, 3.2.12 …

Jul 2, 2024
CVE-2024-34601
5.9 MEDIUM

Improper verification of intent by broadcast receiver vulnerability in GalaxyStore prior to version 4.5.81.0 allows local attackers to launch unexported activities of GalaxyStore.

Jul 2, 2024
CVE-2024-34600
4.4 MEDIUM

Improper verification of intent by broadcast receiver vulnerability in Samsung Flow prior to version 4.9.13.0 allows local attackers to copy image files to external storage.

Jul 2, 2024
CVE-2024-34599
4.0 MEDIUM

Improper input validation in Tips prior to version 6.2.9.4 in Android 14 allows local attacker to send broadcast with Tips' privilege.

Jul 2, 2024
CVE-2024-34597
4.4 MEDIUM

Improper input validation in Samsung Health prior to version 6.27.0.113 allows local attackers to write arbitrary document files to the sandbox of Samsung Health. User …

Jul 2, 2024
CVE-2024-34596
5.9 MEDIUM

Improper authentication in SmartThings prior to version 1.8.17 allows remote attackers to bypass the expiration date for members set by the owner.

Jul 2, 2024
CVE-2024-34594
5.5 MEDIUM

Exposure of sensitive information in proc file system prior to SMR Jul-2024 Release 1 allows local attackers to read kernel memory address.

Jul 2, 2024
CVE-2024-34592
5.3 MEDIUM

Improper input validation in parsing RTCP SDES packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service. …

Jul 2, 2024
CVE-2024-34591
5.3 MEDIUM

Improper input validation in parsing an item data from RTCP SDES packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger …

Jul 2, 2024
CVE-2024-34590
5.3 MEDIUM

Improper input validation혻in parsing an item type from RTCP SDES packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary …

Jul 2, 2024
CVE-2024-34589
5.3 MEDIUM

Improper input validation in parsing RTCP RR packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service. …

Jul 2, 2024
CVE-2024-34588
5.3 MEDIUM

Improper input validation혻in parsing RTCP SR packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service. User …

Jul 2, 2024
CVE-2024-34586
5.9 MEDIUM

Improper access control in KnoxCustomManagerService prior to SMR Jul-2024 Release 1 allows local attackers to configure Knox privacy policy.

Jul 2, 2024
CVE-2024-34583
4.0 MEDIUM

Improper access control in system property prior to SMR Jul-2024 Release 1 allows local attackers to get device identifier.

Jul 2, 2024
CVE-2024-20901
5.9 MEDIUM

Improper input validation in copying data to buffer cache in libsaped prior to SMR Jul-2024 Release 1 allows local attackers to write out-of-bounds memory.

Jul 2, 2024
CVE-2024-20900
4.0 MEDIUM

Improper authentication in MTP application prior to SMR Jul-2024 Release 1 allows local attackers to enter MTP mode without proper authentication.

Jul 2, 2024
CVE-2024-20899
4.0 MEDIUM

Use of implicit intent for sensitive communication in RCS function in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive …

Jul 2, 2024
CVE-2024-20898
4.0 MEDIUM

Use of implicit intent for sensitive communication in SoftphoneClient in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.

Jul 2, 2024
CVE-2024-20897
4.0 MEDIUM

Use of implicit intent for sensitive communication in FCM function in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive …

Jul 2, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.