CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-36072
9.8 CRITICAL

Netwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys Unify through 7.0.6 contain a remote code execution vulnerability in the logging component of the Endpoint Protector …

Jun 27, 2024
CVE-2024-2973
10.0 CRITICAL

An Authentication Bypass Using an Alternate Path or Channel vulnerability in Juniper Networks Session Smart Router or conductor running with a redundant peer allows a …

Jun 27, 2024
CVE-2024-22276
5.3 MEDIUM

VMware Cloud Director Object Storage Extension contains an Insertion of Sensitive Information vulnerability. A malicious actor with adjacent access to web/proxy server logging may be …

Jun 27, 2024
CVE-2024-22272
4.9 MEDIUM

VMware Cloud Director contains an Improper Privilege Management vulnerability. An authenticated tenant administrator for a given organization within VMware Cloud Director may be able to …

Jun 27, 2024
CVE-2024-22260
6.8 MEDIUM

VMware Workspace One UEM update addresses an information exposure vulnerability. A malicious actor with network access to the Workspace One UEM may be able to …

Jun 27, 2024
CVE-2024-6127
9.8 CRITICAL

BC Security Empire before 5.9.3 is vulnerable to a path traversal issue that can lead to remote code execution. A remote, unauthenticated attacker can exploit …

Jun 27, 2024
CVE-2024-39208
9.8 CRITICAL

luci-app-lucky v2.8.3 was discovered to contain hardcoded credentials.

Jun 27, 2024
CVE-2024-39207
8.2 HIGH

lua-shmem v1.0-1 was discovered to contain a buffer overflow via the shmem_write function.

Jun 27, 2024
CVE-2024-39133
4.3 MEDIUM

Heap Buffer Overflow vulnerability in zziplib v0.13.77 allows attackers to cause a denial of service via the __zzip_parse_root_directory() function at /zzip/zip.c.

Jun 27, 2024
CVE-2024-39130
7.5 HIGH

A NULL Pointer Dereference discovered in DumpTS v0.1.0-nightly allows attackers to cause a denial of service via the function DumpOneStream() at /src/DumpStream.cpp.

Jun 27, 2024
CVE-2024-39129
5.3 MEDIUM

Heap Buffer Overflow vulnerability in DumpTS v0.1.0-nightly allows attackers to cause a denial of service via the function PushTSBuf() at /src/PayloadBuf.cpp.

Jun 27, 2024
CVE-2024-38523
7.5 HIGH

Hush Line is a free and open-source, anonymous-tip-line-as-a-service for organizations or individuals. The TOTP authentication flow has multiple issues that weakens its one-time nature. Specifically, …

Jun 27, 2024
CVE-2024-31802
6.3 MEDIUM

DESIGNA ABACUS v.18 and before allows an attacker to bypass the payment process via a crafted QR code.

Jun 27, 2024
CVE-2024-6250
7.5 HIGH

An absolute path traversal vulnerability exists in parisneo/lollms-webui v9.6, specifically in the `open_file` endpoint of `lollms_advanced.py`. The `sanitize_path` function with `allow_absolute_path=True` allows an attacker to …

Jun 27, 2024
CVE-2024-6139
7.3 HIGH

A path traversal vulnerability exists in the XTTS server of the parisneo/lollms package version v9.6. This vulnerability allows an attacker to write audio files to …

Jun 27, 2024
CVE-2024-6090
7.5 HIGH

A path traversal vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410, allowing any user to delete other users' chat histories. This vulnerability can also be exploited to …

Jun 27, 2024
CVE-2024-6086
4.3 MEDIUM

In version 1.2.7 of lunary-ai/lunary, any authenticated user, regardless of their role, can change the name of an organization due to improper access control. The …

Jun 27, 2024
CVE-2024-6085
8.6 HIGH

A path traversal vulnerability exists in the XTTS server included in the lollms package, version v9.6. This vulnerability arises from the ability to perform an …

Jun 27, 2024
CVE-2024-6038
7.5 HIGH

A Regular Expression Denial of Service (ReDoS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability is located in the filter_history function within the …

Jun 27, 2024
CVE-2024-5980
9.8 CRITICAL

A vulnerability in the /v1/runs API endpoint of lightning-ai/pytorch-lightning v2.2.4 allows attackers to exploit path traversal when extracting tar.gz files. When the LightningApp is running …

Jun 27, 2024
CVE-2024-5979
7.5 HIGH

In h2oai/h2o-3 version 3.46.0, the `run_tool` command in the `rapids` component allows the `main` function of any class under the `water.tools` namespace to be called. …

Jun 27, 2024
CVE-2024-5936
6.1 MEDIUM

An open redirect vulnerability exists in imartinez/privategpt version 0.5.0 due to improper handling of the 'file' parameter. This vulnerability allows attackers to redirect users to …

Jun 27, 2024
CVE-2024-5935
5.4 MEDIUM

A Cross-Site Request Forgery (CSRF) vulnerability in version 0.5.0 of imartinez/privategpt allows an attacker to delete all uploaded files on the server. This can lead …

Jun 27, 2024
CVE-2024-5933
5.4 MEDIUM

A Cross-site Scripting (XSS) vulnerability exists in the chat functionality of parisneo/lollms-webui in the latest version. This vulnerability allows an attacker to inject malicious scripts …

Jun 27, 2024
CVE-2024-5885
8.6 HIGH

stangirard/quivr version 0.0.236 contains a Server-Side Request Forgery (SSRF) vulnerability. The application does not provide sufficient controls when crawling a website, allowing an attacker to …

Jun 27, 2024
CVE-2024-5826
9.8 CRITICAL

In the latest version of vanna-ai/vanna, the `vanna.ask` function is vulnerable to remote code execution due to prompt injection. The root cause is the lack …

Jun 27, 2024
CVE-2024-5824
7.4 HIGH

A path traversal vulnerability in the `/set_personality_config` endpoint of parisneo/lollms version 9.4.0 allows an attacker to overwrite the `configs/config.yaml` file. This can lead to remote …

Jun 27, 2024
CVE-2024-5822
9.8 CRITICAL

A Server-Side Request Forgery (SSRF) vulnerability exists in the upload processing interface of gaizhenbiao/ChuanhuChatGPT versions <= ChuanhuChatGPT-20240410-git.zip. This vulnerability allows attackers to send crafted requests …

Jun 27, 2024
CVE-2024-5820
8.8 HIGH

An unprotected WebSocket connection in the latest version of stitionai/devika (commit ecee79f) allows a malicious website to connect to the backend and issue commands on …

Jun 27, 2024
CVE-2024-5755
5.3 MEDIUM

In lunary-ai/lunary versions <=v1.2.11, an attacker can bypass email validation by using a dot character ('.') in the email address. This allows the creation of …

Jun 27, 2024
CVE-2024-5751
9.8 CRITICAL

BerriAI/litellm version v1.35.8 contains a vulnerability where an attacker can achieve remote code execution. The vulnerability exists in the `add_deployment` function, which decodes and decrypts …

Jun 27, 2024
CVE-2024-5714
6.8 MEDIUM

In lunary-ai/lunary version 1.2.4, an improper access control vulnerability allows members with team management permissions to manipulate project identifiers in requests, enabling them to invite …

Jun 27, 2024
CVE-2024-5710
6.5 MEDIUM

berriai/litellm version 1.34.34 is vulnerable to improper access control in its team management functionality. This vulnerability allows attackers to perform unauthorized actions such as creating, …

Jun 27, 2024
CVE-2024-4578
8.4 HIGH

This Advisory describes an issue that impacts Arista Wireless Access Points. Any entity with the ability to authenticate via SSH to an affected AP as …

Jun 27, 2024
CVE-2024-3331
6.8 MEDIUM

Vulnerability in Spotfire Spotfire Enterprise Runtime for R - Server Edition, Spotfire Spotfire Statistics Services, Spotfire Spotfire Analyst, Spotfire Spotfire Desktop, Spotfire Spotfire Server allows …

Jun 27, 2024
CVE-2024-3330
9.9 CRITICAL

Vulnerability in Spotfire Spotfire Analyst, Spotfire Spotfire Server, Spotfire Spotfire for AWS Marketplace allows In the case of the installed Windows client: Successful execution of …

Jun 27, 2024
CVE-2024-3043
7.5 HIGH

An unauthenticated IEEE 802.15.4 'co-ordinator realignment' packet can be used to force Zigbee nodes to change their network identifier (pan ID), leading to a denial …

Jun 27, 2024
CVE-2024-3017
6.5 MEDIUM

In a Silicon Labs multi-protocol gateway, a corrupt pointer to buffered data on a multi-protocol radio co-processor (RCP) causes the OpenThread Border Router(OTBR) application task …

Jun 27, 2024
CVE-2024-2882

SDG Technologies PnPSCADA allows a remote attacker to attach various entities without requiring system authentication. This breach could potentially lead to unauthorized control, data manipulation, …

Jun 27, 2024
CVE-2023-38370
7.5 HIGH

IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1, under certain configurations, could allow a user on the network to install malicious packages. IBM X-Force ID: …

Jun 27, 2024
CVE-2023-38368
5.5 MEDIUM

IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could disclose sensitive information to a local user to do improper permission controls. IBM X-Force ID: 261195.

Jun 27, 2024
CVE-2023-30998
7.8 HIGH

IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain root access due to improper access controls. IBM X-Force ID: …

Jun 27, 2024
CVE-2023-30997
7.8 HIGH

IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain root access due to improper access controls. IBM X-Force ID: …

Jun 27, 2024
CVE-2024-5548
7.5 HIGH

A directory traversal vulnerability exists in the stitionai/devika repository, specifically within the /api/download-project endpoint. Attackers can exploit this vulnerability by manipulating the 'project_name' parameter in …

Jun 27, 2024
CVE-2024-5547
7.5 HIGH

A directory traversal vulnerability exists in the /api/download-project-pdf endpoint of the stitionai/devika repository, affecting the latest version. The vulnerability arises due to insufficient sanitization of …

Jun 27, 2024
CVE-2024-5334
7.5 HIGH

A local file read vulnerability exists in the stitionai/devika repository, affecting the latest version. The vulnerability is due to improper handling of the 'snapshot_path' parameter …

Jun 27, 2024
CVE-2024-35260
8.0 HIGH

An authenticated attacker can exploit an untrusted search path vulnerability in Microsoft Dataverse to execute code over a network.

Jun 27, 2024
CVE-2024-35153
4.8 MEDIUM

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the …

Jun 27, 2024
CVE-2024-31916
7.5 HIGH

IBM OpenBMC FW1050.00 through FW1050.10 BMCWeb HTTPS server component could disclose sensitive URI content to an unauthorized actor that bypasses authentication channels. IBM X-ForceID: 290026.

Jun 27, 2024
CVE-2024-24792
7.5 HIGH

Parsing a corrupt or malicious image with invalid color indices can cause a panic.

Jun 27, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.