CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-48573
9.8 CRITICAL

A NoSQL injection vulnerability in AquilaCMS 1.409.20 and prior allows unauthenticated attackers to reset user and administrator account passwords via the "Reset password" feature.

Oct 29, 2024
CVE-2024-48572
5.3 MEDIUM

A User enumeration vulnerability in AquilaCMS 1.409.20 and prior allows unauthenticated attackers to obtain email addresses via the "Add a user" feature. The vulnerability occurs …

Oct 29, 2024
CVE-2024-48138
9.8 CRITICAL

A remote code execution (RCE) vulnerability in the component /PluXml/core/admin/parametres_edittpl.php of PluXml v5.8.16 and lower allows attackers to execute arbitrary code via injecting a crafted …

Oct 29, 2024
CVE-2024-44081
9.8 CRITICAL

In Jitsi Meet before 2.0.9779, the functionality to share a video file was implemented in an insecure way, resulting in clients loading videos from an …

Oct 29, 2024
CVE-2024-44080
7.5 HIGH

In Jitsi Meet before 2.0.9779, the functionality to share an image using giphy was implemented in an insecure way, resulting in clients loading GIFs from …

Oct 29, 2024
CVE-2024-10488
8.8 HIGH

Use after free in WebRTC in Google Chrome prior to 130.0.6723.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Oct 29, 2024
CVE-2024-10487
8.8 HIGH

Out of bounds write in Dawn in Google Chrome prior to 130.0.6723.92 allowed a remote attacker to perform out of bounds memory access via a …

Oct 29, 2024
CVE-2024-10228
3.8 LOW

The Vagrant VMWare Utility Windows installer targeted a custom location with a non-protected path that could be modified by an unprivileged user, introducing potential for …

Oct 29, 2024
CVE-2024-8587
7.8 HIGH

A maliciously crafted SLDPRT file when parsed in odxsw_dll.dll through Autodesk AutoCAD can force a Heap Based Buffer Overflow vulnerability. A malicious actor can leverage …

Oct 29, 2024
CVE-2024-50456
5.4 MEDIUM

Missing Authorization vulnerability in Benjamin Denis SEOPress wp-seopress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SEOPress: from n/a through <= 8.1.1.

Oct 29, 2024
CVE-2024-50455
4.3 MEDIUM

Missing Authorization vulnerability in Benjamin Denis SEOPress wp-seopress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SEOPress: from n/a through <= 8.1.1.

Oct 29, 2024
CVE-2024-48461
4.8 MEDIUM

Cross Site Scripting vulnerability in TeslaLogger Admin Panel before v.1.59.6 allows a remote attacker to execute arbitrary code via the New Journey field.

Oct 29, 2024
CVE-2024-48206
9.8 CRITICAL

A Deserialization of Untrusted Data vulnerability in chainer v7.8.1.post1 leads to execution of arbitrary code.

Oct 29, 2024
CVE-2024-48063
9.8 CRITICAL

In PyTorch <=2.4.1, the RemoteModule has Deserialization RCE. NOTE: this is disputed by multiple parties because this is intended behavior in PyTorch distributed computing.

Oct 29, 2024
CVE-2024-48955
8.1 HIGH

Broken access control in NetAdmin 4.030319 returns data with functionalities on the endpoint that "assembles" the functionalities menus, the return of this call is not …

Oct 29, 2024
CVE-2024-9990
8.8 HIGH

The Crypto plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.15. This is due to missing nonce validation …

Oct 29, 2024
CVE-2024-9989
9.8 CRITICAL

The Crypto plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.18. This is due to a limited arbitrary method …

Oct 29, 2024
CVE-2024-9988
9.8 CRITICAL

The Crypto plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.19. This is due to missing validation on the …

Oct 29, 2024
CVE-2024-8924
7.5 HIGH

ServiceNow has addressed a blind SQL injection vulnerability that was identified in the Now Platform. This vulnerability could enable an unauthenticated user to extract unauthorized …

Oct 29, 2024
CVE-2024-50466
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in DarkMySite DarkMySite – Advanced Dark Mode Plugin for WordPress darkmysite allows Cross Site Request Forgery.This issue affects DarkMySite – …

Oct 29, 2024
CVE-2024-50459
5.3 MEDIUM

Missing Authorization vulnerability in Hossni Mubarak AidWP wp-stripe-donation allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AidWP: from n/a through <= 3.2.3.

Oct 29, 2024
CVE-2024-10491
4.0 MEDIUM

A vulnerability has been identified in the Express response.links function, allowing for arbitrary resource injection in the Link header when unsanitized data is used. The …

Oct 29, 2024
CVE-2019-25219
7.5 HIGH

Asio C++ Library before 1.13.0 lacks a fallback error code in the case of SSL_ERROR_SYSCALL with no associated error information from the SSL library being …

Oct 29, 2024
CVE-2024-8923
9.8 CRITICAL

ServiceNow has addressed an input validation vulnerability that was identified in the Now Platform. This vulnerability could enable an unauthenticated user to remotely execute code …

Oct 29, 2024
CVE-2024-7985
7.5 HIGH

The FileOrganizer – Manage WordPress and Website Files plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the …

Oct 29, 2024
CVE-2024-25566
6.1 MEDIUM

An Open-Redirect vulnerability exists in PingAM where well-crafted requests may cause improper validation of redirect URLs. This could allow an attacker to redirect end-users to …

Oct 29, 2024
CVE-2024-10452
2.2 LOW

Organization admins can delete pending invites created in an organization they are not part of.

Oct 29, 2024
CVE-2024-50334
5.3 MEDIUM

Scoold is a Q&A and a knowledge sharing platform for teams. A semicolon path injection vulnerability was found on the /api;/config endpoint. By appending a …

Oct 29, 2024
CVE-2024-49769
7.5 HIGH

Waitress is a Web Server Gateway Interface server for Python 2 and 3. When a remote client closes the connection before waitress has had the …

Oct 29, 2024
CVE-2024-49768
9.1 CRITICAL

Waitress is a Web Server Gateway Interface server for Python 2 and 3. A remote client may send a request that is exactly recv_bytes (defaults …

Oct 29, 2024
CVE-2024-48921
2.7 LOW

Kyverno is a policy engine designed for Kubernetes. A kyverno ClusterPolicy, ie. "disallow-privileged-containers," can be overridden by the creation of a PolicyException in a random …

Oct 29, 2024
CVE-2024-9505
6.4 MEDIUM

The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Button widget in all versions up …

Oct 29, 2024
CVE-2024-51076
6.1 MEDIUM

A Reflected Cross Site Scripting (XSS) vulnerability was found in /odms/admin/booking-search.php in PHPGurukul Online DJ Booking Management System 1.0, which allows remote attackers to execute …

Oct 29, 2024
CVE-2024-51075
6.1 MEDIUM

A Reflected Cross Site Scripting (XSS) vulnerability was found in /odms/admin/user-search.php in PHPGurukul Online DJ Booking Management System v1.0, which allows remote attackers to execute …

Oct 29, 2024
CVE-2024-49634
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rimon Habib BP Member Type Manager bp-member-type-manager allows Reflected XSS.This issue affects BP …

Oct 29, 2024
CVE-2024-49632
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Senthil Vel CWD 3D Image Gallery cwd-3d-image-gallery allows Reflection Injection.This issue affects CWD …

Oct 29, 2024
CVE-2024-47640
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weDevs WP ERP erp allows Reflected XSS.This issue affects WP ERP: from n/a …

Oct 29, 2024
CVE-2024-10226
6.4 MEDIUM

The Arconix Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'box' shortcode in all versions up to, and including, 2.1.13 …

Oct 29, 2024
CVE-2024-8309
9.8 CRITICAL

A vulnerability in the GraphCypherQAChain class of langchain-ai/langchain version 0.2.5 allows for SQL injection through prompt injection. This vulnerability can lead to unauthorized data manipulation, …

Oct 29, 2024
CVE-2024-8143
4.3 MEDIUM

In the latest version (20240628) of gaizhenbiao/chuanhuchatgpt, an issue exists in the /file endpoint that allows authenticated users to access the chat history of other …

Oct 29, 2024
CVE-2024-7962
7.5 HIGH

An arbitrary file read vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240628 due to insufficient validation when loading prompt template files. An attacker can read any file …

Oct 29, 2024
CVE-2024-7807
7.5 HIGH

A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240628 allows for a Denial of Service (DOS) attack. When uploading a file, if an attacker appends a large number …

Oct 29, 2024
CVE-2024-7783
7.5 HIGH

mintplex-labs/anything-llm version latest contains a vulnerability where sensitive information, specifically a password, is improperly stored within a JWT (JSON Web Token) used as a bearer …

Oct 29, 2024
CVE-2024-7774
9.1 CRITICAL

A path traversal vulnerability exists in the `getFullPath` method of langchain-ai/langchainjs version 0.2.5. This vulnerability allows attackers to save files anywhere in the filesystem, overwrite …

Oct 29, 2024
CVE-2024-7475
9.1 CRITICAL

An improper access control vulnerability in lunary-ai/lunary version 1.3.2 allows an attacker to update the SAML configuration without authorization. This vulnerability can lead to manipulation …

Oct 29, 2024
CVE-2024-7474
8.1 HIGH

In version 1.3.2 of lunary-ai/lunary, an Insecure Direct Object Reference (IDOR) vulnerability exists. A user can view or delete external users by manipulating the 'id' …

Oct 29, 2024
CVE-2024-7473
6.5 MEDIUM

An IDOR vulnerability exists in the 'Evaluations' function of the 'umgws datasets' section in lunary-ai/lunary versions 1.3.2. This vulnerability allows an authenticated user to update …

Oct 29, 2024
CVE-2024-7472
6.5 MEDIUM

lunary-ai/lunary v1.2.26 contains an email injection vulnerability in the Send email verification API (/v1/users/send-verification) and Sign up API (/auth/signup). An unauthenticated attacker can inject data …

Oct 29, 2024
CVE-2024-7042
9.8 CRITICAL

A vulnerability in the GraphCypherQAChain class of langchain-ai/langchainjs versions 0.2.5 and all versions with this class allows for prompt injection, leading to SQL injection. This …

Oct 29, 2024
CVE-2024-7010
5.9 MEDIUM

mudler/localai version 2.17.1 is vulnerable to a Timing Attack. This type of side-channel attack allows an attacker to compromise the cryptosystem by analyzing the time …

Oct 29, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.