CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-48423
7.8 HIGH

An issue in assimp v.5.4.3 allows a local attacker to execute arbitrary code via the CallbackToLogRedirector function within the Assimp library.

Oct 24, 2024
CVE-2024-48208
8.6 HIGH

pure-ftpd before 1.0.52 is vulnerable to Buffer Overflow. There is an out of bounds read in the domlsd() function of the ls.c file.

Oct 24, 2024
CVE-2024-47883
9.1 CRITICAL

The OpenRefine fork of the MIT Simile Butterfly server is a modular web application framework. The Butterfly framework uses the `java.net.URL` class to refer to …

Oct 24, 2024
CVE-2024-47882
5.9 MEDIUM

OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the built-in "Something went wrong!" error page includes the …

Oct 24, 2024
CVE-2024-47881
8.1 HIGH

OpenRefine is a free, open source tool for working with messy data. Starting in version 3.4-beta and prior to version 3.8.3, in the `database` extension, …

Oct 24, 2024
CVE-2024-47880
8.1 HIGH

OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the `export-rows` command can be used in such a …

Oct 24, 2024
CVE-2024-47879
7.6 HIGH

OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, lack of cross-site request forgery protection on the `preview-expression` …

Oct 24, 2024
CVE-2024-47878
8.1 HIGH

OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, the `/extension/gdata/authorized` endpoint includes the `state` GET parameter verbatim …

Oct 24, 2024
CVE-2024-45263
8.8 HIGH

An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The upload interface allows the uploading of arbitrary files …

Oct 24, 2024
CVE-2024-45262
8.8 HIGH

An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The params parameter in the call method of the …

Oct 24, 2024
CVE-2024-45261
8.0 HIGH

An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The SID generated for a specific user is not …

Oct 24, 2024
CVE-2024-45260
8.0 HIGH

An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. Users who belong to unauthorized groups can invoke any …

Oct 24, 2024
CVE-2024-10327
8.1 HIGH

A vulnerability in Okta Verify for iOS versions 9.25.1 (beta) and 9.27.0 (including beta) allows push notification responses through the iOS ContextExtension feature allowing the …

Oct 24, 2024
CVE-2024-45259
6.5 MEDIUM

An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. By intercepting an HTTP request and changing the filename …

Oct 24, 2024
CVE-2024-45242
7.8 HIGH

EnGenius ENH1350EXT A8J-ENH1350EXT devices through 3.9.3.2_c1.9.51 allow (blind) OS Command Injection via shell metacharacters to the Ping or Speed Test utility. During the time of …

Oct 24, 2024
CVE-2024-48454
7.2 HIGH

An issue in SourceCodester Purchase Order Management System v1.0 allows a remote attacker to execute arbitrary code via the /admin?page=user component

Oct 24, 2024
CVE-2024-48427
8.8 HIGH

A SQL injection vulnerability in Sourcecodester Packers and Movers Management System v1.0 allows remote authenticated users to execute arbitrary SQL commands via the id parameter …

Oct 24, 2024
CVE-2024-48145
9.1 CRITICAL

A prompt injection vulnerability in the chatbox of Netangular Technologies ChatNet AI Version v1.0 allows attackers to access and exfiltrate all previous and subsequent chat …

Oct 24, 2024
CVE-2024-48144
9.1 CRITICAL

A prompt injection vulnerability in the chatbox of Fusion Chat Chat AI Assistant Ask Me Anything v1.2.4.0 allows attackers to access and exfiltrate all previous …

Oct 24, 2024
CVE-2024-48143
9.1 CRITICAL

A lack of rate limiting in the OTP validation component of Digitory Multi Channel Integrated POS v1.0 allows attackers to gain access to the ordering …

Oct 24, 2024
CVE-2024-48142
7.5 HIGH

A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica ChatGPT AI Assistant v2.4.0 allows attackers to access and exfiltrate all previous and …

Oct 24, 2024
CVE-2024-48141
7.5 HIGH

A prompt injection vulnerability in the chatbox of Zhipu AI CodeGeeX v2.17.0 allows attackers to access and exfiltrate all previous and subsequent chat data between …

Oct 24, 2024
CVE-2024-48140
7.5 HIGH

A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica Your AI Copilot powered by ChatGPT4 v6.3.0 allows attackers to access and exfiltrate …

Oct 24, 2024
CVE-2024-48139
7.5 HIGH

A prompt injection vulnerability in the chatbox of Blackbox AI v1.3.95 allows attackers to access and exfiltrate all previous and subsequent chat data between the …

Oct 24, 2024
CVE-2024-47173
5.5 MEDIUM

Aimeos is an e-commerce framework. All SaaS and marketplace setups using the Aimeos GraphQL API admin interface version from 2024.04 up to 2024.07.1 are affected …

Oct 24, 2024
CVE-2024-46998
7.1 HIGH

baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in the Edit Email Form Settings Feature. Version 5.1.2 fixes …

Oct 24, 2024
CVE-2024-46996
6.3 MEDIUM

baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in the Blog posts feature. Version 5.1.2 fixes this issue.

Oct 24, 2024
CVE-2024-46995
6.1 MEDIUM

baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in HTTP 400 Bad Request. Version 5.1.2 fixes this issue.

Oct 24, 2024
CVE-2024-46994
5.4 MEDIUM

baserCMS is a website development framework. Versions prior to 5.1.2 have a cross-site scripting vulnerability in Blog posts and Contents list Feature. Version 5.1.2 fixes …

Oct 24, 2024
CVE-2024-48514
9.8 CRITICAL

php-heic-to-jpg <= 1.0.5 is vulnerable to code injection (fixed in 1.0.6). An attacker who can upload heic images is able to execute code on the …

Oct 24, 2024
CVE-2024-48442
6.5 MEDIUM

Incorrect access control in Shenzhen Tuoshi Network Communications Co.,Ltd 5G CPE Router NR500-EA RG500UEAABxCOMSLICv3.2.2543.12.18 allows attackers to access the SSH protocol without authentication.

Oct 24, 2024
CVE-2024-48441
8.8 HIGH

Wuhan Tianyu Information Industry Co., Ltd Tianyu CPE Router CommonCPExCPETS_v3.2.468.11.04_P4 was discovered to contain a command injection vulnerability via the component at_command.asp.

Oct 24, 2024
CVE-2024-48440
8.8 HIGH

Shenzhen Tuoshi Network Communications Co.,Ltd 5G CPE Router NR500-EA RG500UEAABxCOMSLICv3.2.2543.12.18 was discovered to contain a command injection vulnerability via the component at_command.asp.

Oct 24, 2024
CVE-2024-46478
9.8 CRITICAL

HTMLDOC v1.9.18 contains a buffer overflow in parse_pre function,ps-pdf.cxx:5681.

Oct 24, 2024
CVE-2024-38314
5.9 MEDIUM

IBM Maximo Application Suite - Monitor Component 8.10, 8.11, and 9.0 could disclose information in the form of the hard-coded cryptographic key to an attacker …

Oct 24, 2024
CVE-2024-10338
4.7 MEDIUM

A vulnerability classified as critical was found in SourceCodeHero Clothes Recommendation System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/home.php. …

Oct 24, 2024
CVE-2024-10337
4.7 MEDIUM

A vulnerability classified as critical has been found in SourceCodeHero Clothes Recommendation System 1.0. Affected is an unknown function of the file /admin/home.php?con=add. The manipulation …

Oct 24, 2024
CVE-2024-10313
8.0 HIGH

iniNet Solutions SpiderControl SCADA PC HMI Editor has a path traversal vulnerability. When the software loads a malicious ‘ems' project template file constructed by an …

Oct 24, 2024
CVE-2024-10295
7.5 HIGH

A flaw was found in Gateway. Sending a non-base64 'basic' auth with special characters can cause APICast to incorrectly authenticate a request. A malformed basic …

Oct 24, 2024
CVE-2024-9692

VIMESA VHF/FM Transmitter Blue Plus is suffering from a Denial-of-Service (DoS) vulnerability. An unauthenticated attacker can issue an unauthorized HTTP GET request to the unprotected …

Oct 24, 2024
CVE-2024-48548
9.3 CRITICAL

The APK file in Cloud Smart Lock v2.0.1 has a leaked a URL that can call an API for binding physical devices. This vulnerability allows …

Oct 24, 2024
CVE-2024-48547
8.4 HIGH

Incorrect access control in the firmware update and download processes of DreamCatcher Life v1.8.7 allows attackers to access sensitive information by analyzing the code and …

Oct 24, 2024
CVE-2024-48546
8.4 HIGH

Incorrect access control in the firmware update and download processes of Wear Sync v1.2.0 allows attackers to access sensitive information by analyzing the code and …

Oct 24, 2024
CVE-2024-48545
8.4 HIGH

Incorrect access control in the firmware update and download processes of IVY Smart v4.5.0 allows attackers to access sensitive information by analyzing the code and …

Oct 24, 2024
CVE-2024-48544
8.4 HIGH

Incorrect access control in the firmware update and download processes of Sylvania Smart Home v3.0.3 allows attackers to access sensitive information by analyzing the code …

Oct 24, 2024
CVE-2024-48542
8.4 HIGH

Incorrect access control in the firmware update and download processes of Yamaha Headphones Controller v1.6.7 allows attackers to access sensitive information by analyzing the code …

Oct 24, 2024
CVE-2024-48541
8.4 HIGH

Incorrect access control in the firmware update and download processes of Ruochan Smart v4.4.7 allows attackers to access sensitive information by analyzing the code and …

Oct 24, 2024
CVE-2024-48540
6.2 MEDIUM

Incorrect access control in XIAO HE Smart 4.3.1 allows attackers to access sensitive information by analyzing the code and data within the APK file.

Oct 24, 2024
CVE-2024-48539
9.8 CRITICAL

Neye3C v4.5.2.0 was discovered to contain a hardcoded encryption key in the firmware update mechanism.

Oct 24, 2024
CVE-2024-44206
9.3 CRITICAL

An issue in the handling of URL protocols was addressed with improved logic. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, …

Oct 24, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.