CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-11096
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in code-projects Task Manager 1.0. This affects an unknown part of the file /newProject.php. The manipulation …

Nov 12, 2024
CVE-2024-11079
5.5 MEDIUM

A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. …

Nov 12, 2024
CVE-2024-52533
9.8 CRITICAL

gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not sufficient for a trailing '\0' character.

Nov 11, 2024
CVE-2024-51213
6.1 MEDIUM

Cross Site Scripting vulnerability in Online Shop Store v.1.0 allows a remote attacker to execute arbitrary code via the login.php component.

Nov 11, 2024
CVE-2024-50636
9.8 CRITICAL

PyMOL 2.5.0 contains a vulnerability in its "Run Script" function, which allows the execution of arbitrary Python code embedded within .PYM files. Attackers can craft …

Nov 11, 2024
CVE-2024-50601
6.1 MEDIUM

Persistent and reflected XSS vulnerabilities in the themeMode cookie and _h URL parameter of Axigen Mail Server up to version 10.5.28 allow attackers to execute …

Nov 11, 2024
CVE-2024-25255
9.8 CRITICAL

Sublime Text 4 was discovered to contain a command injection vulnerability via the New Build System module. NOTE: multiple third parties report that this is …

Nov 11, 2024
CVE-2024-25254
9.8 CRITICAL

SuperScan v4.1 was discovered to contain a buffer overflow via the Hostname/IP parameter.

Nov 11, 2024
CVE-2024-25253
7.5 HIGH

Driver Booster v10.6 was discovered to contain a buffer overflow via the Host parameter under the Customize proxy module.

Nov 11, 2024
CVE-2024-23983

Improper handling of canonical URL-encoding may lead to bypass not properly constrained by request rules.

Nov 11, 2024
CVE-2024-51026
5.4 MEDIUM

The NetAdmin IAM system (version 4.0.30319) has a Cross Site Scripting (XSS) vulnerability in the /BalloonSave.ashx endpoint, where it is possible to inject a malicious …

Nov 11, 2024
CVE-2024-46966
8.1 HIGH

The Ikhgur mn.ikhgur.khotoch (aka Video Downloader Pro & Browser) application through 1.0.42 for Android allows an attacker to execute arbitrary JavaScript code via the mn.ikhgur.khotoch.MainActivity …

Nov 11, 2024
CVE-2024-46964
8.1 HIGH

The com.video.downloader.all (aka All Video Downloader) application through 11.28 for Android allows an attacker to execute arbitrary JavaScript code via the com.video.downloader.all.StartActivity component.

Nov 11, 2024
CVE-2024-46963
8.1 HIGH

The com.superfast.video.downloader (aka Super Unlimited Video Downloader - All in One) application through 5.1.9 for Android allows an attacker to execute arbitrary JavaScript code via …

Nov 11, 2024
CVE-2024-46962
9.1 CRITICAL

The SYQ com.downloader.video.fast (aka Master Video Downloader) application through 2.0 for Android allows an attacker to execute arbitrary JavaScript code via the com.downloader.video.fast.SpeedMainAct component.

Nov 11, 2024
CVE-2024-44546
9.8 CRITICAL

Powerjob >= 3.20 is vulnerable to SQL injection via the version parameter.

Nov 11, 2024
CVE-2024-52532
7.5 HIGH

GNOME libsoup before 3.6.1 has an infinite loop, and memory consumption. during the reading of certain patterns of WebSocket data from clients.

Nov 11, 2024
CVE-2024-52531
6.5 MEDIUM

GNOME libsoup before 3.6.1 allows a buffer overflow in applications that perform conversion to UTF-8 in soup_header_parse_param_list_strict. There is a plausible way to reach this …

Nov 11, 2024
CVE-2024-52530
7.5 HIGH

GNOME libsoup before 3.6.0 allows HTTP request smuggling in some configurations because '\0' characters at the end of header names are ignored, i.e., a "Transfer-Encoding\0: …

Nov 11, 2024
CVE-2024-52288
5.1 MEDIUM

libosdp is an implementation of IEC 60839-11-5 OSDP (Open Supervised Device Protocol) and provides a C library with support for C++, Rust and Python3. In …

Nov 11, 2024
CVE-2024-52286

Stirling-PDF is a locally hosted web application that allows you to perform various operations on PDF files. In affected versions the Merge functionality takes untrusted …

Nov 11, 2024
CVE-2024-51992
4.1 MEDIUM

Orchid is a @laravel package that allows for rapid application development of back-office applications, admin/user panels, and dashboards. This vulnerability is a method exposure issue …

Nov 11, 2024
CVE-2024-51748
9.1 CRITICAL

Kanboard is project management software that focuses on the Kanban methodology. An authenticated Kanboard admin can run arbitrary php code on the server in combination …

Nov 11, 2024
CVE-2024-51747
9.1 CRITICAL

Kanboard is project management software that focuses on the Kanban methodology. An authenticated Kanboard admin can read and delete arbitrary files from the server. File …

Nov 11, 2024
CVE-2024-51490
5.5 MEDIUM

Ampache is a web based audio/video streaming application and file manager. This vulnerability exists in the interface section of the Ampache menu, where users can …

Nov 11, 2024
CVE-2024-51489
5.4 MEDIUM

Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing does not adequately validate CSRF tokens when users …

Nov 11, 2024
CVE-2024-51488
5.4 MEDIUM

Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing does not adequately validate CSRF tokens when users …

Nov 11, 2024
CVE-2024-51487
8.1 HIGH

Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing fails to properly validate CSRF tokens when activating …

Nov 11, 2024
CVE-2024-51486
5.5 MEDIUM

Ampache is a web based audio/video streaming application and file manager. The vulnerability exists in the interface section of the Ampache menu, where users can …

Nov 11, 2024
CVE-2024-51485
8.1 HIGH

Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing fails to properly validate CSRF tokens when activating …

Nov 11, 2024
CVE-2024-51484
8.1 HIGH

Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing fails to properly validate CSRF tokens when activating …

Nov 11, 2024
CVE-2024-51190
4.8 MEDIUM

TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS) vulnerability via the ptRule_ApplicationName_1.1.6.0.0 parameter on the /special_ap.htm page.

Nov 11, 2024
CVE-2024-51189
4.8 MEDIUM

TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS) vulnerability via the macList_Name_1.1.1.0.0 parameter on the /filters.htm page.

Nov 11, 2024
CVE-2024-51188
4.8 MEDIUM

TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS) vulnerability via the vsRule_VirtualServerName_1.1.10.0.0 parameter on the /virtual_server.htm page.

Nov 11, 2024
CVE-2024-51187
4.8 MEDIUM

TRENDnet TEW-651BR 2.04B1, TEW-652BRP 3.04b01, and TEW-652BRU 1.00b12 devices contain a Store Cross-site scripting (XSS) vulnerability via the firewallRule_Name_1.1.1.0.0 parameter on the /firewall_setting.htm page.

Nov 11, 2024
CVE-2024-51186
8.0 HIGH

D-Link DIR-820L 1.05b03 was discovered to contain a remote code execution (RCE) vulnerability via the ping_addr parameter in the ping_v4 and ping_v6 functions.

Nov 11, 2024
CVE-2024-48322
8.1 HIGH

UsersController.php in Run.codes 1.5.2 and older has a reset password race condition vulnerability.

Nov 11, 2024
CVE-2024-46965
5.4 MEDIUM

The DS allvideo.downloader.browser (aka Fast Video Downloader: Browser) application through 1.6-RC1 for Android allows an attacker to execute arbitrary JavaScript code via the allvideo.downloader.browser.DefaultBrowserActivity component.

Nov 11, 2024
CVE-2024-36061
9.8 CRITICAL

EnGenius EWS356-FIT devices through 1.1.30 allow blind OS command injection. This allows an attacker to execute arbitrary OS commands via shell metacharacters to the Ping …

Nov 11, 2024
CVE-2024-11078
3.5 LOW

A vulnerability has been found in code-projects Job Recruitment 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file …

Nov 11, 2024
CVE-2024-10315

In Gliffy Online an insecure configuration was discovered in versions before 4.14.0-6. Reported by Alpha Inferno PVT LTD.

Nov 11, 2024
CVE-2024-51135
9.8 CRITICAL

An XML External Entity (XXE) vulnerability in the component DocumentBuilderFactory of powertac-server v1.9.0 allows attackers to access sensitive information or execute arbitrary code via supplying …

Nov 11, 2024
CVE-2024-50667
9.8 CRITICAL

The boa httpd of Trendnet TEW-820AP 1.01.B01 has a stack overflow vulnerability in /boafrm/formIPv6Addr, /boafrm/formIpv6Setup, /boafrm/formDnsv6. The reason is that the check of ipv6 address …

Nov 11, 2024
CVE-2024-11077
7.3 HIGH

A vulnerability, which was classified as critical, was found in code-projects Job Recruitment 1.0. Affected is an unknown function of the file /index.php. The manipulation …

Nov 11, 2024
CVE-2024-11076
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in code-projects Job Recruitment 1.0. This issue affects some unknown processing of the file /activation.php. …

Nov 11, 2024
CVE-2024-11074
6.3 MEDIUM

A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0. This vulnerability affects unknown code of the file /incadd.php. The manipulation of …

Nov 11, 2024
CVE-2024-45087
4.8 MEDIUM

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the …

Nov 11, 2024
CVE-2024-11073
4.3 MEDIUM

A vulnerability classified as problematic has been found in SourceCodester Hospital Management System 1.0. This affects an unknown part of the file /vm/patient/delete-account.php. The manipulation …

Nov 11, 2024
CVE-2024-10917
3.7 LOW

In Eclipse OpenJ9 versions up to 0.47, the JNI function GetStringUTFLength may return an incorrect value which has wrapped around. From 0.48 the value is …

Nov 11, 2024
CVE-2024-45088
6.4 MEDIUM

IBM Maximo Asset Management 7.6.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI …

Nov 11, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.