CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-37765
8.8 HIGH

Machform up to version 19 is affected by an authenticated Blind SQL injection in the user account settings page.

Jul 1, 2024
CVE-2024-37764
5.4 MEDIUM

MachForm up to version 19 is affected by an authenticated stored cross-site scripting.

Jul 1, 2024
CVE-2024-37763
5.4 MEDIUM

MachForm up to version 19 is affected by an unauthenticated stored cross-site scripting which affects users with valid sessions whom can view compiled forms results.

Jul 1, 2024
CVE-2024-37762
9.9 CRITICAL

MachForm up to version 21 is affected by an authenticated unrestricted file upload which leads to a remote code execution.

Jul 1, 2024
CVE-2024-23737
5.4 MEDIUM

Cross Site Request Forgery (CSRF) vulnerability in savignano S/Notify before 4.0.2 for Jira allows attackers to allows attackers to manipulate a user's S/MIME certificate of …

Jul 1, 2024
CVE-2024-23736
8.8 HIGH

Cross Site Request Forgery (CSRF) vulnerability in savignano S/Notify before 4.0.2 for Confluence allows attackers to manipulate a user's S/MIME certificate of PGP key via …

Jul 1, 2024
CVE-2024-5322
9.1 CRITICAL

The N-central server is vulnerable to session rebinding of already authenticated users when using Entra SSO, which can lead to authentication bypass. This vulnerability is …

Jul 1, 2024
CVE-2024-39305
6.5 MEDIUM

Envoy is a cloud-native, open source edge and service proxy. Prior to versions 1.30.4, 1.29.7, 1.28.5, and 1.27.7. Envoy references already freed memory when route …

Jul 1, 2024
CVE-2024-38368
9.3 CRITICAL

trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. A vulnerability affected older pods which migrated from the pre-2014 pull request workflow to trunk. …

Jul 1, 2024
CVE-2024-38367
8.2 HIGH

trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. Prior to commit d4fa66f49cedab449af9a56a21ab40697b9f7b97, the trunk sessions verification step could be manipulated for owner session …

Jul 1, 2024
CVE-2024-38366
10.0 CRITICAL

trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. The part of trunk which verifies whether a user has a real email address on …

Jul 1, 2024
CVE-2024-32230
7.8 HIGH

FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a negative-size-param bug at libavcodec/mpegvideo_enc.c:1216:21 in load_input_picture in FFmpeg7.0

Jul 1, 2024
CVE-2024-32229
8.4 HIGH

FFmpeg 7.0 contains a heap-buffer-overflow at libavfilter/vf_tiltandshift.c:189:5 in copy_column.

Jul 1, 2024
CVE-2024-32228
6.6 MEDIUM

FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a SEGV at libavcodec/hevcdec.c:2947:22 in hevc_frame_end.

Jul 1, 2024
CVE-2024-28200
9.1 CRITICAL

The N-central server is vulnerable to an authentication bypass of the user interface. This vulnerability is present in all deployments of N-central prior to 2024.2. …

Jul 1, 2024
CVE-2024-39249
7.5 HIGH

Async <= 2.6.4 and <= 3.2.5 are vulnerable to ReDoS (Regular Expression Denial of Service) while parsing function in autoinject function. NOTE: this is disputed …

Jul 1, 2024
CVE-2024-39573
7.5 HIGH

Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL's to be handled …

Jul 1, 2024
CVE-2024-39303
4.4 MEDIUM

Weblate is a web based localization tool. Prior to version 5.6.2, Weblate didn't correctly validate filenames when restoring project backup. It may be possible to …

Jul 1, 2024
CVE-2024-39251
10.0 CRITICAL

An issue in the component ControlCenter.sys/ControlCenter64.sys of ThundeRobot Control Center v2.0.0.10 allows attackers to access sensitive information, execute arbitrary code, or escalate privileges via sending …

Jul 1, 2024
CVE-2024-39236
9.8 CRITICAL

Gradio v4.36.1 was discovered to contain a code injection vulnerability via the component /gradio/component_meta.py. This vulnerability is triggered via a crafted input. NOTE: the supplier …

Jul 1, 2024
CVE-2024-38513
10.0 CRITICAL

Fiber is an Express-inspired web framework written in Go A vulnerability present in versions prior to 2.52.5 is a session middleware issue in GoFiber versions …

Jul 1, 2024
CVE-2024-38477
7.5 HIGH

null pointer dereference in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows an attacker to crash the server via a malicious request. Users are …

Jul 1, 2024
CVE-2024-38476
9.8 CRITICAL

Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response …

Jul 1, 2024
CVE-2024-38475
9.1 CRITICAL KEV

Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted …

Jul 1, 2024
CVE-2024-38474
9.8 CRITICAL

Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not …

Jul 1, 2024
CVE-2024-38473
8.1 HIGH

Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing …

Jul 1, 2024
CVE-2024-38472
7.5 HIGH

SSRF in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content Users …

Jul 1, 2024
CVE-2024-37298
7.5 HIGH

gorilla/schema converts structs to and from form values. Prior to version 1.4.1 Running `schema.Decoder.Decode()` on a struct that has a field of type `[]struct{...}` opens …

Jul 1, 2024
CVE-2024-37146
6.1 MEDIUM

Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a reflected cross-site scripting …

Jul 1, 2024
CVE-2024-37145
6.1 MEDIUM

Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a reflected cross-site scripting …

Jul 1, 2024
CVE-2024-36423
6.1 MEDIUM

Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a reflected cross-site scripting …

Jul 1, 2024
CVE-2024-36387
5.4 MEDIUM

Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, degrading performance.

Jul 1, 2024
CVE-2024-39879
5.0 MEDIUM

In JetBrains TeamCity before 2024.03.3 application token could be exposed in EC2 Cloud Profile settings

Jul 1, 2024
CVE-2024-39878
4.1 MEDIUM

In JetBrains TeamCity before 2024.03.3 private key could be exposed via testing GitHub App Connection

Jul 1, 2024
CVE-2024-36997
8.1 HIGH

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312, an admin user could store and execute arbitrary JavaScript …

Jul 1, 2024
CVE-2024-36996
5.3 MEDIUM

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109, an attacker could determine whether or not another user …

Jul 1, 2024
CVE-2024-36995
5.4 MEDIUM

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9.1.2308.207, a low-privileged user that does not hold …

Jul 1, 2024
CVE-2024-36994
5.4 MEDIUM

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9.1.2308.207, a low-privileged user that does not hold …

Jul 1, 2024
CVE-2024-36993
5.4 MEDIUM

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9.1.2308.207, a low-privileged user that does not hold …

Jul 1, 2024
CVE-2024-36992
5.4 MEDIUM

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9.1.2308.207, a low-privileged user that does not hold …

Jul 1, 2024
CVE-2024-36991
7.5 HIGH

In Splunk Enterprise on Windows versions below 9.2.2, 9.1.5, and 9.0.10, an attacker could perform a path traversal on the /modules/messaging/ endpoint in Splunk Enterprise …

Jul 1, 2024
CVE-2024-36990
6.5 MEDIUM

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.2.2403.100, an authenticated, low-privileged user that does not hold the …

Jul 1, 2024
CVE-2024-36989
7.1 HIGH

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200, a low-privileged user that does not hold the admin …

Jul 1, 2024
CVE-2024-36987
4.3 MEDIUM

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200, an authenticated, low-privileged user who does not hold the …

Jul 1, 2024
CVE-2024-36986
6.3 MEDIUM

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9.1.2308.207, an authenticated user could run risky commands …

Jul 1, 2024
CVE-2024-36985
8.8 HIGH

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10, a low-privileged user that does not hold the admin or power Splunk roles could cause a …

Jul 1, 2024
CVE-2024-36984
8.8 HIGH

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 on Windows, an authenticated user could execute a specially crafted query that they could then use …

Jul 1, 2024
CVE-2024-36983
8.0 HIGH

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109 and 9.1.2308.207, an authenticated user could create an external …

Jul 1, 2024
CVE-2024-36982
7.5 HIGH

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109 and 9.1.2308.207, an attacker could trigger a null pointer …

Jul 1, 2024
CVE-2024-21586
7.5 HIGH

An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX Series and NFX …

Jul 1, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.