CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-50824
7.2 HIGH

A SQL Injection vulnerability was found in /admin/class.php in kashipara E-learning Management System Project 1.0 via the class_name parameter.

Nov 14, 2024
CVE-2024-50823
9.8 CRITICAL

A SQL Injection vulnerability was found in /admin/login.php in kashipara E-learning Management System Project 1.0 via the username and password parameters.

Nov 14, 2024
CVE-2024-4343
9.8 CRITICAL

A Python command injection vulnerability exists in the `SagemakerLLM` class's `complete()` method within `./private_gpt/components/llm/custom/sagemaker.py` of the imartinez/privategpt application, versions up to and including 0.3.0. The …

Nov 14, 2024
CVE-2024-4311
5.4 MEDIUM

zenml-io/zenml version 0.56.4 is vulnerable to an account takeover due to the lack of rate-limiting in the password change function. An attacker can brute-force the …

Nov 14, 2024
CVE-2024-49362
7.7 HIGH

Joplin is a free, open source note taking and to-do application. Joplin-desktop has a vulnerability that leads to remote code execution (RCE) when a user …

Nov 14, 2024
CVE-2024-48284
4.8 MEDIUM

A Reflected Cross-Site Scripting (XSS) vulnerability was found in the /search-result.php page of the PHPGurukul User Registration & Login and User Management System 3.2. This …

Nov 14, 2024
CVE-2024-3502
8.1 HIGH

In lunary-ai/lunary versions up to and including 1.2.5, an information disclosure vulnerability exists where account recovery hashes of users are inadvertently exposed to unauthorized actors. …

Nov 14, 2024
CVE-2024-3501
8.1 HIGH

In lunary-ai/lunary versions up to and including 1.2.5, an information disclosure vulnerability exists due to the inclusion of single-use tokens in the responses of `GET …

Nov 14, 2024
CVE-2024-3379
8.1 HIGH

In lunary-ai/lunary versions 1.2.2 through 1.2.6, an incorrect authorization vulnerability allows unprivileged users to re-generate the private key for projects they do not have access …

Nov 14, 2024
CVE-2024-1682
4.3 MEDIUM

An unclaimed Amazon S3 bucket, 'codeconf', is referenced in an audio file link within the .rst documentation file. This bucket has been claimed by an …

Nov 14, 2024
CVE-2024-6068
7.3 HIGH

A memory corruption vulnerability exists in the affected products when parsing DFT files. Local threat actors can exploit this issue to disclose information and to …

Nov 14, 2024
CVE-2024-50836
4.8 MEDIUM

A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/teachers.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary …

Nov 14, 2024
CVE-2024-50835
7.2 HIGH

A SQL Injection vulnerability was found in /admin/edit_student.php in KASHIPARA E-learning Management System Project 1.0 via the cys, un, ln, fn, and id parameters.

Nov 14, 2024
CVE-2024-50834
7.2 HIGH

A SQL Injection was found in /admin/teachers.php in KASHIPARA E-learning Management System Project 1.0 via the firstname and lastname parameters.

Nov 14, 2024
CVE-2024-50833
9.8 CRITICAL

A SQL Injection vulnerability was found in /login.php in KASHIPARA E-learning Management System Project 1.0 via the username and password parameters.

Nov 14, 2024
CVE-2024-50832
7.2 HIGH

A SQL Injection vulnerability was found in /admin/edit_class.php in kashipara E-learning Management System Project 1.0 via the class_name parameter.

Nov 14, 2024
CVE-2024-37285
9.1 CRITICAL

A deserialization issue in Kibana can lead to arbitrary code execution when Kibana attempts to parse a YAML document containing a crafted payload. A successful …

Nov 14, 2024
CVE-2024-52505
5.4 MEDIUM

matrix-appservice-irc is a Node.js IRC bridge for the Matrix messaging protocol. The provisioning API of the matrix-appservice-irc bridge up to version 3.0.2 contains a vulnerability …

Nov 14, 2024
CVE-2024-52302

common-user-management is a robust Spring Boot application featuring user management services designed to control user access dynamically. There is a critical security vulnerability in the …

Nov 14, 2024
CVE-2024-42188
3.7 LOW

HCL Connections is vulnerable to a broken access control vulnerability that may allow an unauthorized user to update data in certain scenarios.

Nov 14, 2024
CVE-2024-11214
4.7 MEDIUM

A vulnerability has been found in SourceCodester Best Employee Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/profile.php. …

Nov 14, 2024
CVE-2024-11213
4.7 MEDIUM

A vulnerability, which was classified as critical, was found in SourceCodester Best Employee Management System 1.0. This affects an unknown part of the file /admin/edit_role.php. …

Nov 14, 2024
CVE-2024-11136

The default TCL Camera application exposes a provider vulnerable to path traversal vulnerability. Malicious application can supply malicious URI path and delete arbitrary files from …

Nov 14, 2024
CVE-2024-10921
6.8 MEDIUM

An authorized user may trigger crashes or receive the contents of buffer over-reads of Server memory by issuing specially crafted requests that construct malformed BSON …

Nov 14, 2024
CVE-2024-7124

Improper Neutralization of Input During Web Page Generation vulnerability in DInGO dLibra software in the parameter 'filter' in the endpoint 'indexsearch' allows a Reflected Cross-Site …

Nov 14, 2024
CVE-2024-50838
5.4 MEDIUM

A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/department.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary …

Nov 14, 2024
CVE-2024-50837
5.4 MEDIUM

A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/admin_user.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary …

Nov 14, 2024
CVE-2024-11212
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Best Employee Management System 1.0. Affected by this issue is some unknown functionality …

Nov 14, 2024
CVE-2024-11211
4.7 MEDIUM

A vulnerability classified as critical has been found in EyouCMS up to 1.6.7. Affected is an unknown function of the component Website Logo Handler. The …

Nov 14, 2024
CVE-2024-11210
5.4 MEDIUM

A vulnerability was found in EyouCMS 1.51. It has been rated as critical. This issue affects the function editFile of the file application/admin/logic/FilemanagerLogic.php. The manipulation …

Nov 14, 2024
CVE-2022-2232
7.5 HIGH

A flaw was found in the Keycloak package. This flaw allows an attacker to utilize an LDAP injection to bypass the username lookup or potentially …

Nov 14, 2024
CVE-2024-9633
3.1 LOW

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.3 before 17.4.2, all versions starting from 17.5 before 17.5.4, all versions …

Nov 14, 2024
CVE-2024-50843
5.3 MEDIUM

A Directory listing issue was found in PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers attacker to access sensitive …

Nov 14, 2024
CVE-2024-50842
5.4 MEDIUM

A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/school_year.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary …

Nov 14, 2024
CVE-2024-50841
5.4 MEDIUM

A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/calendar_of_events.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary …

Nov 14, 2024
CVE-2024-50840
5.4 MEDIUM

A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/class.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary …

Nov 14, 2024
CVE-2024-50839
5.4 MEDIUM

A Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/add_subject.php in KASHIPARA E-learning Management System Project 1.0. This vulnerability allows remote attackers to execute arbitrary …

Nov 14, 2024
CVE-2024-11215
6.5 MEDIUM

Absolute path traversal (incorrect restriction of a path to a restricted directory) vulnerability in the EasyPHP web server, affecting version 14.1. This vulnerability could allow …

Nov 14, 2024
CVE-2024-11209
6.3 MEDIUM

A vulnerability was found in Apereo CAS 6.6. It has been classified as critical. This affects an unknown part of the file /login?service of the …

Nov 14, 2024
CVE-2024-11208
3.7 LOW

A vulnerability was found in Apereo CAS 6.6 and classified as problematic. Affected by this issue is some unknown functionality of the file /login?service. The …

Nov 14, 2024
CVE-2024-10962
8.8 HIGH

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0.9.107 via deserialization …

Nov 14, 2024
CVE-2024-8648
6.1 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 16 before 17.3.7, 17.4 before 17.4.4, and 17.5 before 17.5.2. The vulnerability could …

Nov 14, 2024
CVE-2024-7404
6.8 MEDIUM

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 prior to 17.3.7, starting from 17.4 prior to 17.4.4 and starting from …

Nov 14, 2024
CVE-2024-11207
4.3 MEDIUM

A vulnerability has been found in Apereo CAS 6.6 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /login. …

Nov 14, 2024
CVE-2024-10979
8.8 HIGH

Incorrect control of environment variables in PostgreSQL PL/Perl allows an unprivileged database user to change sensitive process environment variables (e.g. PATH). That often suffices to …

Nov 14, 2024
CVE-2024-10978
4.2 MEDIUM

Incorrect privilege assignment in PostgreSQL allows a less-privileged application user to view or change different rows from those intended. An attack requires the application to …

Nov 14, 2024
CVE-2024-10977
3.1 LOW

Client use of server error message in PostgreSQL allows a server not trusted under current SSL or GSS settings to furnish arbitrary non-NUL bytes to …

Nov 14, 2024
CVE-2024-10976
4.2 MEDIUM

Incomplete tracking in PostgreSQL of tables with row security allows a reused query to view or change different rows from those intended. CVE-2023-2455 and CVE-2016-2193 …

Nov 14, 2024
CVE-2024-7730
7.4 HIGH

A heap buffer overflow was found in the virtio-snd device in QEMU. When reading input audio in the virtio-snd input callback, virtio_snd_pcm_in_cb, the function did …

Nov 14, 2024
CVE-2024-45670
5.6 MEDIUM

IBM Security SOAR 51.0.1.0 and earlier contains a mechanism for users to recover or change their passwords without knowing the original password, but the user …

Nov 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.