CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2020-35158

Rejected reason: CVE ID was once reserved, but never used.

Jun 21, 2024
CVE-2020-35157

Rejected reason: CVE ID was once reserved, but never used.

Jun 21, 2024
CVE-2020-35156

Rejected reason: CVE ID was once reserved, but never used.

Jun 21, 2024
CVE-2020-35155

Rejected reason: CVE ID was once reserved, but never used.

Jun 21, 2024
CVE-2019-15798

Rejected reason: CVE ID was once reserved, but never used.

Jun 21, 2024
CVE-2019-15797

Rejected reason: CVE ID was once reserved, but never used.

Jun 21, 2024
CVE-2024-38361
3.7 LOW

Spicedb is an Open Source, Google Zanzibar-inspired permissions database to enable fine-grained authorization for customer applications. Use of an exclusion under an arrow that has …

Jun 20, 2024
CVE-2024-38359
6.5 MEDIUM

The Lightning Network Daemon (lnd) - is a complete implementation of a Lightning Network node. A parsing vulnerability in lnd's onion processing logic and lead …

Jun 20, 2024
CVE-2024-37899
9.0 CRITICAL

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When an admin disables a user account, the …

Jun 20, 2024
CVE-2024-35246
7.5 HIGH

An attacker may be able to cause a denial-of-service condition by sending many packets repeatedly.

Jun 20, 2024
CVE-2024-32943
7.5 HIGH

An attacker may be able to cause a denial-of-service condition by sending many SSH packets repeatedly.

Jun 20, 2024
CVE-2024-5746
7.6 HIGH

A Server-Side Request Forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker with the Site Administrator role to gain arbitrary code execution …

Jun 20, 2024
CVE-2024-37183
5.7 MEDIUM

Plain text credentials and session ID can be captured with a network sniffer.

Jun 20, 2024
CVE-2024-36071
6.3 MEDIUM

Samsung Magician 8.0.0 on Windows allows an admin to escalate privileges by tampering with the directory and DLL files used during the installation process. This …

Jun 20, 2024
CVE-2024-31586
6.1 MEDIUM

A Cross Site Scripting (XSS) vulnerability exists in Computer Laboratory Management System version 1.0. This vulnerability allows a remote attacker to execute arbitrary code via …

Jun 20, 2024
CVE-2024-30848
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability in SilverSky E-mail service version 5.0.3126 allows remote attackers to inject arbitrary web script or HTML via the version parameter.

Jun 20, 2024
CVE-2024-29390
7.3 HIGH

Daily Expenses Management System version 1.0, developed by PHP Gurukul, contains a time-based blind SQL injection vulnerability in the 'add-expense.php' page. An attacker can exploit …

Jun 20, 2024
CVE-2024-6154
6.7 MEDIUM

Parallels Desktop Toolgate Heap-based Buffer Overflow Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop. An …

Jun 20, 2024
CVE-2024-6153
7.8 HIGH

Parallels Desktop Updater Protection Mechanism Failure Software Downgrade Vulnerability. This vulnerability allows local attackers to downgrade Parallels software on affected installations of Parallels Desktop. An …

Jun 20, 2024
CVE-2024-6147
7.8 HIGH

Poly Plantronics Hub Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Poly Plantronics Hub. An …

Jun 20, 2024
CVE-2024-38093
4.3 MEDIUM

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Jun 20, 2024
CVE-2024-38082
4.7 MEDIUM

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Jun 20, 2024
CVE-2024-37818
8.6 HIGH

Strapi v4.24.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /strapi.io/_next/image. This vulnerability allows attackers to scan for open ports or …

Jun 20, 2024
CVE-2024-37897
5.4 MEDIUM

SFTPGo is a full-featured and highly configurable SFTP, HTTP/S, FTP/S and WebDAV server - S3, Google Cloud Storage, Azure Blob. SFTPGo WebAdmin and WebClient support …

Jun 20, 2024
CVE-2024-37699
9.8 CRITICAL

An issue in DataLife Engine v.17.1 and before is vulnerable to SQL Injection in dboption.

Jun 20, 2024
CVE-2024-37674
5.5 MEDIUM

Cross Site Scripting vulnerability in Moodle CMS v3.10 allows a remote attacker to execute arbitrary code via the Field Name (name parameter) of a new …

Jun 20, 2024
CVE-2024-37352
4.5 MEDIUM

There is a cross-site scripting vulnerability in the management UI of Absolute Secure Access prior to version 13.06 that allows attackers with system administrator permissions …

Jun 20, 2024
CVE-2024-37351
4.5 MEDIUM

There is a cross-site scripting vulnerability in the management UI of Absolute Secure Access prior to version 13.06. Attackers with system administrator permissions can interfere …

Jun 20, 2024
CVE-2024-37350
6.5 MEDIUM

There is a cross-site scripting vulnerability in the policy management UI of Absolute Secure Access prior to version 13.06. Attackers can interfere with a system …

Jun 20, 2024
CVE-2024-37349
4.5 MEDIUM

There is a cross-site scripting vulnerability in the management UI of Absolute Secure Access prior to version 13.06. Attackers with system administrator permissions can interfere …

Jun 20, 2024
CVE-2024-37626
8.8 HIGH

A command injection issue in TOTOLINK A6000R V1.0.1-B20201211.2000 firmware allows a remote attacker to execute arbitrary code via the iface parameter in the vif_enable function.

Jun 20, 2024
CVE-2024-37348
4.5 MEDIUM

There is a cross-site scripting vulnerability in the management UI of Absolute Secure Access prior to version 13.06. Attackers with system administrator permissions can interfere …

Jun 20, 2024
CVE-2024-37347
4.5 MEDIUM

There is a cross-site scripting vulnerability in the pool configuration component of the management UI of Absolute Secure Access prior to 13.06. Attackers with system …

Jun 20, 2024
CVE-2024-37346
4.9 MEDIUM

There is an insufficient input validation vulnerability in the Warehouse component of Absolute Secure Access prior to 13.06. Attackers with system administrator permissions can impair …

Jun 20, 2024
CVE-2024-37345
5.3 MEDIUM

There is a cross-site scripting vulnerability in the Secure Access administrative UI of Absolute Secure Access prior to version 13.06. Attackers can pass a limited-length …

Jun 20, 2024
CVE-2024-37344
4.5 MEDIUM

There is a cross-site scripting vulnerability in the Policy management UI of Absolute Secure Access prior to version 13.06. Attackers with system administrator permissions can …

Jun 20, 2024
CVE-2024-37343
4.8 MEDIUM

There is a cross-site scripting vulnerability in the Secure Access administrative console of Absolute Secure Access prior to version 13.06. Attackers with valid tunnel credentials …

Jun 20, 2024
CVE-2024-33335
6.3 MEDIUM

SQL Injection vulnerability in H3C technology company SeaSQL DWS V2.0 allows a remote attacker to execute arbitrary code via a crafted file.

Jun 20, 2024
CVE-2024-28397
5.3 MEDIUM

An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a crafted API call.

Jun 20, 2024
CVE-2022-45929
8.8 HIGH

Northern.tech Mender 3.3.x before 3.3.2, 3.5.x before 3.5.0, and 3.6.x before 3.6.0 has Incorrect Access Control and allows users to change their roles and could …

Jun 20, 2024
CVE-2022-41324
6.5 MEDIUM

Northern.tech Mender 3.3.x before 3.3.2 and 3.4.x before 3.4.0 has Incorrect Access Control and allows low-privileged users default read access to some sensitive device information.

Jun 20, 2024
CVE-2024-6196
7.3 HIGH

A vulnerability was found in itsourcecode Banking Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file …

Jun 20, 2024
CVE-2024-6195
6.3 MEDIUM

A vulnerability has been found in itsourcecode Tailoring Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the …

Jun 20, 2024
CVE-2024-6194
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in itsourcecode Tailoring Management System 1.0. Affected is an unknown function of the file editmeasurement.php. The …

Jun 20, 2024
CVE-2024-6193
7.3 HIGH

A vulnerability, which was classified as critical, has been found in itsourcecode Vehicle Management System 1.0. This issue affects some unknown processing of the file …

Jun 20, 2024
CVE-2024-37676
8.4 HIGH

An issue in htop-dev htop v.2.20 allows a local attacker to cause an out-of-bounds access in the Header_populateFromSettings function.

Jun 20, 2024
CVE-2024-6192
7.3 HIGH

A vulnerability classified as critical was found in itsourcecode Loan Management System 1.0. This vulnerability affects unknown code of the file login.php of the component …

Jun 20, 2024
CVE-2024-6191
7.3 HIGH

A vulnerability classified as critical has been found in itsourcecode Student Management System 1.0. This affects an unknown part of the file login.php of the …

Jun 20, 2024
CVE-2024-6190
7.3 HIGH

A vulnerability was found in itsourcecode Farm Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Jun 20, 2024
CVE-2024-6162
7.5 HIGH

A vulnerability was found in Undertow, where URL-encoded request paths can be mishandled during concurrent requests on the AJP listener. This issue arises because the …

Jun 20, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.