CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-10550
7.5 HIGH

A vulnerability in the `/3/ParseSetup` endpoint of h2oai/h2o-3 version 3.46.0.1 allows for a denial of service (DoS) attack. The endpoint applies a user-specified regular expression …

Mar 20, 2025
CVE-2024-10549
7.5 HIGH

A vulnerability in the `/3/Parse` endpoint of h2oai/h2o-3 version 3.46.0.1 allows for a denial of service (DoS) attack. The endpoint uses a user-specified string to …

Mar 20, 2025
CVE-2024-10513
7.2 HIGH

A path traversal vulnerability exists in the 'document uploads manager' feature of mintplex-labs/anything-llm, affecting the latest version prior to 1.2.2. This vulnerability allows users with …

Mar 20, 2025
CVE-2024-10481
6.5 MEDIUM

A CSRF vulnerability exists in comfyanonymous/comfyui versions up to v0.2.2. This vulnerability allows attackers to host malicious websites that, when visited by authenticated ComfyUI users, …

Mar 20, 2025
CVE-2024-10457
6.5 MEDIUM

Multiple Server-Side Request Forgery (SSRF) vulnerabilities were identified in the significant-gravitas/autogpt repository, specifically in the GitHub Integration and Web Search blocks. These vulnerabilities affect version …

Mar 20, 2025
CVE-2024-10366
6.5 MEDIUM

An improper access control vulnerability (IDOR) exists in the delete attachments functionality of danny-avila/librechat version v0.7.5-rc2. The endpoint does not verify whether the provided attachment …

Mar 20, 2025
CVE-2024-10363
5.4 MEDIUM

In version 0.7.5 of danny-avila/LibreChat, there is an improper access control vulnerability. Users can share, use, and create prompts without being granted permission by the …

Mar 20, 2025
CVE-2024-10361
9.1 CRITICAL

An arbitrary file deletion vulnerability exists in danny-avila/librechat version v0.7.5-rc2, specifically within the /api/files endpoint. This vulnerability arises from improper input validation, allowing path traversal …

Mar 20, 2025
CVE-2024-10359
4.6 MEDIUM

In danny-avila/librechat version v0.7.5-rc2, a vulnerability exists in the preset creation functionality where a user can manipulate the user ID field through mass assignment. This …

Mar 20, 2025
CVE-2024-10330
6.5 MEDIUM

In lunary-ai/lunary version 1.5.6, the `/v1/evaluators/` endpoint lacks proper access control, allowing any user associated with a project to fetch all evaluator data regardless of …

Mar 20, 2025
CVE-2024-10275
7.3 HIGH

In version 1.5.5 of lunary-ai/lunary, a vulnerability exists where admins, who do not have direct permissions to access billing resources, can change the permissions of …

Mar 20, 2025
CVE-2024-10274
6.5 MEDIUM

An improper authorization vulnerability exists in lunary-ai/lunary version 1.5.5. The /users/me/org endpoint lacks adequate access control mechanisms, allowing unauthorized users to access sensitive information about …

Mar 20, 2025
CVE-2024-10273
6.5 MEDIUM

In lunary-ai/lunary v1.5.0, improper privilege management in the models.ts file allows users with viewer roles to modify models owned by others. The PATCH endpoint for …

Mar 20, 2025
CVE-2024-10272
7.5 HIGH

lunary-ai/lunary is vulnerable to broken access control in the latest version. An attacker can view the content of any dataset without any kind of authorization …

Mar 20, 2025
CVE-2024-10267
7.5 HIGH

An information disclosure vulnerability exists in the latest version of transformeroptimus/superagi. An attacker can leak sensitive user information, including names, emails, and passwords, by attempting …

Mar 20, 2025
CVE-2024-10264
9.8 CRITICAL

HTTP Request Smuggling vulnerability in netease-youdao/qanything version 1.4.1 allows attackers to exploit inconsistencies in the interpretation of HTTP requests between a proxy and a server. …

Mar 20, 2025
CVE-2024-10252
7.2 HIGH

A vulnerability in langgenius/dify versions <=v0.9.1 allows for code injection via internal SSRF requests in the Dify sandbox service. This vulnerability enables an attacker to …

Mar 20, 2025
CVE-2024-10225
7.5 HIGH

A vulnerability in haotian-liu/llava v1.2.0 allows an attacker to cause a Denial of Service (DoS) by appending a large number of characters to the end …

Mar 20, 2025
CVE-2024-10190
9.8 CRITICAL

Horovod versions up to and including v0.28.1 are vulnerable to unauthenticated remote code execution. The vulnerability is due to improper handling of base64-encoded data in …

Mar 20, 2025
CVE-2024-10188
7.5 HIGH

A vulnerability in BerriAI/litellm, as of commit 26c03c9, allows unauthenticated users to cause a Denial of Service (DoS) by exploiting the use of ast.literal_eval to …

Mar 20, 2025
CVE-2024-10110
7.5 HIGH

In version 3.23.0 of aimhubio/aim, the ScheduledStatusReporter object can be instantiated to run on the main thread of the tracking server, leading to the main …

Mar 20, 2025
CVE-2024-10109
8.3 HIGH

A vulnerability in the mintplex-labs/anything-llm repository, as of commit 5c40419, allows low privilege users to access the sensitive API endpoint "/api/system/custom-models". This access enables them …

Mar 20, 2025
CVE-2024-10096

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Mar 20, 2025
CVE-2024-10051
7.5 HIGH

Realchar version v0.0.4 is vulnerable to an unauthenticated denial of service (DoS) attack. The vulnerability exists in the file upload request handling, where appending characters, …

Mar 20, 2025
CVE-2024-10047
5.3 MEDIUM

parisneo/lollms-webui versions v9.9 to the latest are vulnerable to a directory listing vulnerability. An attacker can list arbitrary directories on a Windows system by sending …

Mar 20, 2025
CVE-2024-10019
6.7 MEDIUM

A vulnerability in the `start_app_server` function of parisneo/lollms-webui V12 (Strawberry) allows for path traversal and OS command injection. The function does not properly sanitize the …

Mar 20, 2025
CVE-2024-0640
4.8 MEDIUM

A stored cross-site scripting (XSS) vulnerability exists in chatwoot/chatwoot versions 3.0.0 to 3.5.1. This vulnerability allows an admin user to inject malicious JavaScript code via …

Mar 20, 2025
CVE-2024-0245
5.5 MEDIUM

A misconfiguration in the AndroidManifest.xml file in hamza417/inure before build97 allows for task hijacking. This vulnerability permits malicious applications to inherit permissions of the vulnerable …

Mar 20, 2025
CVE-2024-54016
4.3 MEDIUM

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubating): through <=2.2.0. Users are recommended to …

Mar 20, 2025
CVE-2024-47552
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubating): from 2.0.0 before 2.2.0. Severity Justification: The Apache Seata security …

Mar 20, 2025
CVE-2025-2505
9.8 CRITICAL

The Age Gate plugin for WordPress is vulnerable to Local PHP File Inclusion in all versions up to, and including, 3.5.3 via the 'lang' parameter. …

Mar 20, 2025
CVE-2025-1385

When the library bridge feature is enabled, the clickhouse-library-bridge exposes an HTTP API on localhost. This allows clickhouse-server to dynamically load a library from a …

Mar 20, 2025
CVE-2024-12016
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CM Informatics CM News allows SQL Injection.This issue affects CM News: …

Mar 20, 2025
CVE-2025-2108
6.4 MEDIUM

The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Site Title’ widget's 'title_tag' …

Mar 20, 2025
CVE-2025-22228
7.4 HIGH

BCryptPasswordEncoder.matches(CharSequence,String) will incorrectly return true for passwords larger than 72 characters as long as the first 72 characters are the same.

Mar 20, 2025
CVE-2025-1770
8.8 HIGH

The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, …

Mar 20, 2025
CVE-2025-1766
5.3 MEDIUM

The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check …

Mar 20, 2025
CVE-2025-1314
4.3 MEDIUM

The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up …

Mar 20, 2025
CVE-2024-13881
7.1 HIGH

The Link My Posts WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Mar 20, 2025
CVE-2024-13880
7.1 HIGH

The My Quota WordPress plugin through 1.0.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected …

Mar 20, 2025
CVE-2024-13878
7.1 HIGH

The SpotBot WordPress plugin through 0.1.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Mar 20, 2025
CVE-2024-13877
7.1 HIGH

The Passbeemedia Web Push Notification WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to …

Mar 20, 2025
CVE-2024-13876
7.1 HIGH

The mEintopf WordPress plugin through 0.2.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Mar 20, 2025
CVE-2024-13875
7.1 HIGH

The WP-PManager WordPress plugin through 1.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site …

Mar 20, 2025
CVE-2025-30259
3.5 LOW

The WhatsApp cloud service before late 2024 did not block certain crafted PDF content that can defeat a sandbox protection mechanism and consequently allow remote …

Mar 20, 2025
CVE-2025-1628

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Mar 19, 2025
CVE-2025-30092
6.1 MEDIUM

Intrexx Portal Server 12.x <= 12.0.2 and 11.x <= 11.9.2 allows XSS in multiple Velocity scripts.

Mar 19, 2025
CVE-2025-27787
7.5 HIGH

Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to denial of service (DoS) in restart.py. `model_name` in train.py takes user input, …

Mar 19, 2025
CVE-2025-27786
9.1 CRITICAL

Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file removal in core.py. `output_tts_path` in tts.py takes arbitrary user input …

Mar 19, 2025
CVE-2025-27785
7.5 HIGH

Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file read in train.py's `export_index` function. This issue may lead to …

Mar 19, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.