CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-32007
7.5 HIGH

An improper input validation of the p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform a …

Jul 19, 2024
CVE-2024-29736
9.1 CRITICAL

A SSRF vulnerability in WADL service description in versions of Apache CXF before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform SSRF style attacks …

Jul 19, 2024
CVE-2024-6903
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in SourceCodester Record Management System 1.0. Affected by this issue is some unknown functionality of …

Jul 19, 2024
CVE-2024-6902
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Record Management System 1.0. Affected by this vulnerability is an unknown functionality of the file sort_user.php. …

Jul 19, 2024
CVE-2024-6799
4.3 MEDIUM

The YITH Essential Kit for WooCommerce #1 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the …

Jul 19, 2024
CVE-2024-6338
8.8 HIGH

The FV Flowplayer Video Player plugin for WordPress is vulnerable to time-based SQL Injection via the ‘exclude’ parameter in all versions up to, and including, …

Jul 19, 2024
CVE-2024-40724
7.8 HIGH

Heap-based buffer overflow vulnerability in Assimp versions prior to 5.4.2 allows a local attacker to execute arbitrary code by inputting a specially crafted file into …

Jul 19, 2024
CVE-2024-6901
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Record Management System 1.0. Affected is an unknown function of the file entry.php. The manipulation …

Jul 19, 2024
CVE-2024-6900
6.3 MEDIUM

A vulnerability was found in SourceCodester Record Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file …

Jul 19, 2024
CVE-2024-6205
9.8 CRITICAL

The PayPlus Payment Gateway WordPress plugin before 6.6.9 does not properly sanitise and escape a parameter before using it in a SQL statement via a …

Jul 19, 2024
CVE-2024-5604
5.9 MEDIUM

The Bug Library WordPress plugin before 2.1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin …

Jul 19, 2024
CVE-2023-7269
7.5 HIGH

The ArtPlacer Widget WordPress plugin before 2.21.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could …

Jul 19, 2024
CVE-2023-7268
6.5 MEDIUM

The ArtPlacer Widget WordPress plugin before 2.21.2 does not have authorisation check in place when deleting widgets, allowing ay authenticated users, such as subscriber, to …

Jul 19, 2024
CVE-2024-6899
6.3 MEDIUM

A vulnerability was found in SourceCodester Record Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file view_info.php. …

Jul 19, 2024
CVE-2024-21583
4.1 MEDIUM

Versions of the package github.com/gitpod-io/gitpod/components/server/go/pkg/lib before main-gha.27122; versions of the package github.com/gitpod-io/gitpod/components/ws-proxy/pkg/proxy before main-gha.27122; versions of the package github.com/gitpod-io/gitpod/install/installer/pkg/components/auth before main-gha.27122; versions of the package …

Jul 19, 2024
CVE-2024-21527
8.2 HIGH

Versions of the package github.com/gotenberg/gotenberg/v8/pkg/gotenberg before 8.1.0; versions of the package github.com/gotenberg/gotenberg/v8/pkg/modules/chromium before 8.1.0; versions of the package github.com/gotenberg/gotenberg/v8/pkg/modules/webhook before 8.1.0 are vulnerable to Server-side …

Jul 19, 2024
CVE-2024-6898
7.3 HIGH

A vulnerability was found in SourceCodester Record Management System 1.0. It has been classified as critical. This affects an unknown part of the file index.php. …

Jul 19, 2024
CVE-2024-38156
6.1 MEDIUM

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Jul 19, 2024
CVE-2024-35199
8.2 HIGH

TorchServe is a flexible and easy-to-use tool for serving and scaling PyTorch models in production. In affected versions the two gRPC ports 7070 and 7071, …

Jul 19, 2024
CVE-2024-35198
9.8 CRITICAL

TorchServe is a flexible and easy-to-use tool for serving and scaling PyTorch models in production. TorchServe 's check on allowed_urls configuration can be by-passed if …

Jul 19, 2024
CVE-2024-30130
3.7 LOW

HCL Nomad server on Domino is vulnerable to the cache containing sensitive information which could potentially give an attacker the ability to acquire the sensitive …

Jul 19, 2024
CVE-2024-41111
7.2 HIGH

Sliver is an open source cross-platform adversary emulation/red team framework, it can be used by organizations of all sizes to perform security testing. Sliver version …

Jul 18, 2024
CVE-2024-40642
8.1 HIGH

The netty incubator codec.bhttp is a java language binary http parser. In affected versions the `BinaryHttpParser` class does not properly validate input values thus giving …

Jul 18, 2024
CVE-2024-5997
4.3 MEDIUM

The Duplica – Duplicate Posts, Pages, Custom Posts or Users plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability …

Jul 18, 2024
CVE-2024-6455
5.3 MEDIUM

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.2.0 due to a missing capability …

Jul 18, 2024
CVE-2024-39173
9.8 CRITICAL

calculator-boilerplate v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the eval function at /routes/calculator.js. This vulnerability allows attackers to execute arbitrary …

Jul 18, 2024
CVE-2024-39090
6.1 MEDIUM

The PHPGurukul Online Shopping Portal Project version 2.0 contains a vulnerability that allows Cross-Site Request Forgery (CSRF) to lead to Stored Cross-Site Scripting (XSS). An …

Jul 18, 2024
CVE-2024-30126
4.7 MEDIUM

HCL BigFix Compliance is affected by a missing X-Frame-Options HTTP header which can allow an attacker to create a malicious website that embeds the target …

Jul 18, 2024
CVE-2024-5321
6.1 MEDIUM

A security issue was discovered in Kubernetes clusters with Windows nodes where BUILTIN\Users may be able to read container logs and NT AUTHORITY\Authenticated Users may …

Jul 18, 2024
CVE-2024-39152

Rejected reason: DO NOT USE THIS CVE RECORD. Consult IDs: CVE-2024-6655. Reason: This record is a reservation duplicate of CVE-2024-6655. Notes: All CVE users should …

Jul 18, 2024
CVE-2024-38806
3.9 LOW

Failure to properly synchronize user's permissions in UAA in Cloud Foundry Foundation v40.17.0 https://github.com/cloudfoundry/cf-deployment/releases/tag/v40.17.0 , potentially resulting in users retaining access rights they should not …

Jul 18, 2024
CVE-2024-5625
6.5 MEDIUM

Improper Restriction of XML External Entity Reference vulnerability in PruvaSoft Informatics Apinizer Management Console allows Data Serialization External Entities Blowup.This issue affects Apinizer Management Console: …

Jul 18, 2024
CVE-2024-30125
6.2 MEDIUM

HCL BigFix Compliance server can respond with an HTTP status of 500, indicating a server-side error that may cause the server process to die.

Jul 18, 2024
CVE-2024-0857
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Universal Software Inc. FlexWater Corporate Water Management allows SQL Injection.This issue …

Jul 18, 2024
CVE-2024-5620
6.5 MEDIUM

Authentication Bypass Using an Alternate Path or Channel vulnerability in PruvaSoft Informatics Apinizer Management Console allows Authentication Bypass.This issue affects Apinizer Management Console: before 2024.05.1.

Jul 18, 2024
CVE-2024-5619
9.6 CRITICAL

Authorization Bypass Through User-Controlled Key vulnerability in PruvaSoft Informatics Apinizer Management Console allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Apinizer Management Console: …

Jul 18, 2024
CVE-2024-5618
9.9 CRITICAL

Incorrect Permission Assignment for Critical Resource vulnerability in PruvaSoft Informatics Apinizer Management Console allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Apinizer Management …

Jul 18, 2024
CVE-2024-40648
5.4 MEDIUM

matrix-rust-sdk is an implementation of a Matrix client-server library in Rust. The `UserIdentity::is_verified()` method in the matrix-sdk-crypto crate before version 0.7.2 doesn't take into account …

Jul 18, 2024
CVE-2024-40647
5.3 MEDIUM

sentry-sdk is the official Python SDK for Sentry.io. A bug in Sentry's Python SDK < 2.8.0 allows the environment variables to be passed to subprocesses …

Jul 18, 2024
CVE-2024-40644
6.8 MEDIUM

gitoxide An idiomatic, lean, fast & safe pure Rust implementation of Git. `gix-path` can be tricked into running another `git.exe` placed in an untrusted location …

Jul 18, 2024
CVE-2024-40629
10.0 CRITICAL

JumpServer is an open-source Privileged Access Management (PAM) tool that provides DevOps and IT teams with on-demand and secure access to SSH, RDP, Kubernetes, Database …

Jul 18, 2024
CVE-2024-40628
10.0 CRITICAL

JumpServer is an open-source Privileged Access Management (PAM) tool that provides DevOps and IT teams with on-demand and secure access to SSH, RDP, Kubernetes, Database …

Jul 18, 2024
CVE-2023-40704
6.8 MEDIUM

The product does not require unique and complex passwords to be created during installation. Using Philips's default password could jeopardize the PACS system if the …

Jul 18, 2024
CVE-2023-40539

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 18, 2024
CVE-2023-40223

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 18, 2024
CVE-2023-40159

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 18, 2024
CVE-2024-39911
10.0 CRITICAL

1Panel is a web-based linux server management control panel. 1Panel contains an unspecified sql injection via User-Agent handling. This issue has been addressed in version …

Jul 18, 2024
CVE-2024-39907
9.8 CRITICAL

1Panel is a web-based linux server management control panel. There are many sql injections in the project, and some of them are not well filtered, …

Jul 18, 2024
CVE-2024-38302
6.8 MEDIUM

Dell Data Lakehouse, version(s) 1.0.0.0, contain(s) a Missing Encryption of Sensitive Data vulnerability in the DDAE (Starburst). A low privileged attacker with adjacent network access …

Jul 18, 2024
CVE-2024-30473
4.9 MEDIUM

Dell ECS, versions prior to 3.8.1, contain a privilege elevation vulnerability in user management. A remote high privileged attacker could potentially exploit this vulnerability, gaining …

Jul 18, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.