CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-20399
6.0 MEDIUM KEV

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession of Administrator credentials to execute arbitrary commands as root …

Jul 1, 2024
CVE-2024-36422
6.1 MEDIUM

Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a reflected cross-site scripting …

Jul 1, 2024
CVE-2024-36421
7.5 HIGH

Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, A CORS misconfiguration sets …

Jul 1, 2024
CVE-2024-36420
7.5 HIGH

Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, the `/api/v1/openai-assistants-file` endpoint in …

Jul 1, 2024
CVE-2024-36401
9.8 CRITICAL KEV

GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.22.6, 2.23.6, 2.24.4, and 2.25.2, multiple OGC …

Jul 1, 2024
CVE-2024-6376
7.0 HIGH

MongoDB Compass may be susceptible to code injection due to insufficient sandbox protection settings with the usage of ejson shell parser in Compass' connection handling. …

Jul 1, 2024
CVE-2024-6375
5.4 MEDIUM

A command for refining a collection shard key is missing an authorization check. This may cause the command to run directly on a shard, leading …

Jul 1, 2024
CVE-2024-34696
4.5 MEDIUM

GeoServer is an open source server that allows users to share and edit geospatial data. Starting in version 2.10.0 and prior to versions 2.24.4 and …

Jul 1, 2024
CVE-2024-23380
8.4 HIGH

Memory corruption while handling user packets during VBO bind operation.

Jul 1, 2024
CVE-2024-23373
8.4 HIGH

Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released.

Jul 1, 2024
CVE-2024-23372
8.4 HIGH

Memory corruption while invoking IOCTL call for GPU memory allocation and size param is greater than expected size.

Jul 1, 2024
CVE-2024-23368
7.8 HIGH

Memory corruption when allocating and accessing an entry in an SMEM partition.

Jul 1, 2024
CVE-2024-21482
6.8 MEDIUM

Memory corruption during the secure boot process, when the `bootm` command is used, it bypasses the authentication of the kernel/rootfs image.

Jul 1, 2024
CVE-2024-21469
7.3 HIGH

Memory corruption when an invoke call and a TEE call are bound for the same trusted application.

Jul 1, 2024
CVE-2024-21466
6.5 MEDIUM

Information disclosure while parsing sub-IE length during new IE generation.

Jul 1, 2024
CVE-2024-21465
7.8 HIGH

Memory corruption while processing key blob passed by the user.

Jul 1, 2024
CVE-2024-21462
7.1 HIGH

Transient DOS while loading the TA ELF file.

Jul 1, 2024
CVE-2024-21461
8.4 HIGH

Memory corruption while performing finish HMAC operation when context is freed by keymaster.

Jul 1, 2024
CVE-2024-21460
7.1 HIGH

Information disclosure when ASLR relocates the IMEM and Secure DDR portions as one chunk in virtual address space.

Jul 1, 2024
CVE-2024-21458
6.5 MEDIUM

Information disclosure while handling SA query action frame.

Jul 1, 2024
CVE-2024-21457
6.5 MEDIUM

INformation disclosure while handling Multi-link IE in beacon frame.

Jul 1, 2024
CVE-2024-21456
6.5 MEDIUM

Information Disclosure while parsing beacon frame in STA.

Jul 1, 2024
CVE-2023-43554
8.4 HIGH

Memory corruption while processing IOCTL handler in FastRPC.

Jul 1, 2024
CVE-2024-6050
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation vulnerability in SOKRATES-software SOWA OPAC allows a Reflected Cross-Site Scripting (XSS). An attacker might trick somebody into …

Jul 1, 2024
CVE-2024-38953
6.1 MEDIUM

phpok 6.4.003 contains a Cross Site Scripting (XSS) vulnerability in the ok_f() method under the framework/api/upload_control.php file.

Jul 1, 2024
CVE-2024-24749
7.5 HIGH

GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.23.5 and 2.24.3, if GeoServer is deployed …

Jul 1, 2024
CVE-2024-6425
9.1 CRITICAL

Incorrect Provision of Specified Functionality vulnerability in MESbook 20221021.03 version. An unauthenticated remote attacker can register user accounts without being authenticated from the route "/account/Register/" …

Jul 1, 2024
CVE-2024-6424
9.3 CRITICAL

External server-side request vulnerability in MESbook 20221021.03 version, which could allow a remote, unauthenticated attacker to exploit the endpoint "/api/Proxy/Post?userName=&password=&uri=<FILE|INTERNAL URL|IP/HOST" or "/api/Proxy/Get?userName=&password=&uri=<ARCHIVO|URL INTERNA|IP/HOST" to …

Jul 1, 2024
CVE-2024-6387
8.1 HIGH

A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an …

Jul 1, 2024
CVE-2024-4007
8.8 HIGH

Default credential in install package in ABB ASPECT; NEXUS Series; MATRIX Series version 3.07 allows attacker to login to product instances wrongly configured.

Jul 1, 2024
CVE-2024-39853
6.5 MEDIUM

adolph_dudu ratio-swiper 0.0.2 was discovered to contain a prototype pollution via the function parse. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024
CVE-2024-39018
6.3 MEDIUM

harvey-woo cat5th/key-serializer v0.2.5 was discovered to contain a prototype pollution via the function "query". This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024
CVE-2024-39017
9.8 CRITICAL

agreejs shared v0.0.1 was discovered to contain a prototype pollution via the function mergeInternalComponents. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024
CVE-2024-39016
8.1 HIGH

che3vinci c3/utils-1 1.0.131 was discovered to contain a prototype pollution via the function assign. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024
CVE-2024-39015
9.8 CRITICAL

cafebazaar hod v0.4.14 was discovered to contain a prototype pollution via the function request. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024
CVE-2024-39014
9.8 CRITICAL

ahilfoley cahil/utils v2.3.2 was discovered to contain a prototype pollution via the function set. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024
CVE-2024-39013
9.8 CRITICAL

2o3t-utility v0.1.2 was discovered to contain a prototype pollution via the function extend. This vulnerability allows attackers to execute arbitrary code or cause a Denial …

Jul 1, 2024
CVE-2024-39008
10.0 CRITICAL

robinweser fast-loops v1.1.3 was discovered to contain a prototype pollution via the function objectMergeDeep. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024
CVE-2024-39003
7.3 HIGH

amoyjs amoy common v1.0.10 was discovered to contain a prototype pollution via the function setValue. This vulnerability allows attackers to execute arbitrary code or cause …

Jul 1, 2024
CVE-2024-39002
6.3 MEDIUM

rjrodger jsonic-next v2.12.1 was discovered to contain a prototype pollution via the function util.clone. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024
CVE-2024-39001
6.3 MEDIUM

ag-grid-enterprise v31.3.2 was discovered to contain a prototype pollution via the component _ModuleSupport.jsonApply. This vulnerability allows attackers to execute arbitrary code or cause a Denial …

Jul 1, 2024
CVE-2024-39000
6.5 MEDIUM

adolph_dudu ratio-swiper v0.0.2 was discovered to contain a prototype pollution via the function parse. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024
CVE-2024-38999
10.0 CRITICAL

jrburke requirejs v2.3.6 was discovered to contain a prototype pollution via the function s.contexts._.configure. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024
CVE-2024-38998

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not …

Jul 1, 2024
CVE-2024-38997
6.5 MEDIUM

adolph_dudu ratio-swiper v0.0.2 was discovered to contain a prototype pollution via the function extendDefaults. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024
CVE-2024-38996
9.8 CRITICAL

ag-grid-community v31.3.2 and ag-grid-enterprise v31.3.2 were discovered to contain a prototype pollution via the _.mergeDeep function. This vulnerability allows attackers to execute arbitrary code or …

Jul 1, 2024
CVE-2024-38994
7.3 HIGH

amoyjs amoy common v1.0.10 was discovered to contain a prototype pollution via the function extend. This vulnerability allows attackers to execute arbitrary code or cause …

Jul 1, 2024
CVE-2024-38993
9.8 CRITICAL

rjrodger jsonic-next v2.12.1 was discovered to contain a prototype pollution via the function empty. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024
CVE-2024-38992
8.8 HIGH

airvertco frappejs v0.0.11 was discovered to contain a prototype pollution via the function registerView. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024
CVE-2024-38991
8.8 HIGH

akbr patch-into v1.0.1 was discovered to contain a prototype pollution via the function patchInto. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.