CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-34024
6.3 MEDIUM

Observable response discrepancy issue exists in ID Link Manager and FUJITSU Software TIME CREATOR. If this vulnerability is exploited, an unauthenticated remote attacker may determine …

Jun 18, 2024
CVE-2024-33622
6.5 MEDIUM

Missing authentication for critical function vulnerability exists in ID Link Manager and FUJITSU Software TIME CREATOR. If this vulnerability is exploited, sensitive information may be …

Jun 18, 2024
CVE-2024-33620
8.6 HIGH

Absolute path traversal vulnerability exists in ID Link Manager and FUJITSU Software TIME CREATOR. If this vulnerability is exploited, the file contents including sensitive information …

Jun 18, 2024
CVE-2024-0066
5.3 MEDIUM

Johan Fagerström, member of the AXIS OS Bug Bounty Program, has found that a O3C feature may expose sensitive traffic between the client (Axis device) …

Jun 18, 2024
CVE-2023-5527
7.4 HIGH

The Business Directory Plugin plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 6.4.3 via the class-csv-exporter.php file. This allows …

Jun 18, 2024
CVE-2024-5860
4.3 MEDIUM

The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the tc_dl_delete_tickets …

Jun 18, 2024
CVE-2024-5541
5.3 MEDIUM

The Ibtana – WordPress Website Builder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ibtana_visual_editor_register_ajax_json_endpont' …

Jun 18, 2024
CVE-2024-4375
6.4 MEDIUM

The Master Slider – Responsive Touch Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ms_layer' shortcode in all versions up …

Jun 18, 2024
CVE-2024-1634
6.5 MEDIUM

The Scheduling Plugin – Online Booking for WordPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on …

Jun 18, 2024
CVE-2024-0845
6.4 MEDIUM

The PDF Viewer for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the render function in all versions up to, and including, …

Jun 18, 2024
CVE-2024-6084
7.3 HIGH

A vulnerability has been found in itsourcecode Pool of Bethesda Online Reservation System up to 1.0 and classified as critical. Affected by this vulnerability is …

Jun 18, 2024
CVE-2024-6083
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in PHPVibe 11.0.46. Affected is an unknown function of the file /app/uploading/upload-mp3.php of the component Media …

Jun 18, 2024
CVE-2024-6082
2.4 LOW

A vulnerability, which was classified as problematic, has been found in PHPVibe 11.0.46. This issue affects some unknown processing of the file functionalities.global.php of the …

Jun 17, 2024
CVE-2024-6080
7.8 HIGH

A vulnerability classified as critical was found in Intelbras InControl 2.21.56. This vulnerability affects unknown code of the component incontrolWebcam Service. The manipulation leads to …

Jun 17, 2024
CVE-2024-6067
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Music Class Enrollment System 1.0. Affected by this vulnerability is an unknown functionality of the file …

Jun 17, 2024
CVE-2024-6066
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Best House Rental Management System 1.0. Affected is an unknown function of the file payment_report.php. …

Jun 17, 2024
CVE-2024-6065
7.3 HIGH

A vulnerability was found in itsourcecode Bakery Online Ordering System 1.0. It has been rated as critical. This issue affects some unknown processing of the …

Jun 17, 2024
CVE-2024-6064
5.3 MEDIUM

A vulnerability was found in GPAC 2.5-DEV-rev228-g11067ea92-master. It has been declared as problematic. This vulnerability affects the function xmt_node_end of the file src/scene_manager/loader_xmt.c of the …

Jun 17, 2024
CVE-2024-6063
3.3 LOW

A vulnerability was found in GPAC 2.5-DEV-rev228-g11067ea92-master. It has been classified as problematic. This affects the function m2tsdmx_on_event of the file src/filters/dmx_m2ts.c of the component …

Jun 17, 2024
CVE-2024-37828
4.8 MEDIUM

A stored cross-site scripting (XSS) in Vermeg Agile Reporter v23.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into …

Jun 17, 2024
CVE-2024-37798
5.9 MEDIUM

Cross-site scripting (XSS) vulnerability in search-appointment.php in the Admin Panel in Phpgurukul Beauty Parlour Management System 1.0 allows remote attackers to inject arbitrary web script …

Jun 17, 2024
CVE-2024-34833
9.8 CRITICAL

Sourcecodester Payroll Management System v1.0 is vulnerable to File Upload. Users can upload images via the "save_settings" page. An unauthenticated attacker can leverage this functionality …

Jun 17, 2024
CVE-2023-37058
9.8 CRITICAL

Insecure Permissions vulnerability in JLINK Unionman Technology Co. Ltd Jlink AX1800 v.1.0 allows a remote attacker to escalate privileges via a crafted command.

Jun 17, 2024
CVE-2023-37057
9.8 CRITICAL

An issue in JLINK Unionman Technology Co. Ltd Jlink AX1800 v.1.0 allows a remote attacker to execute arbitrary code via the router's authentication mechanism.

Jun 17, 2024
CVE-2024-6062
3.3 LOW

A vulnerability was found in GPAC 2.5-DEV-rev228-g11067ea92-master and classified as problematic. Affected by this issue is the function swf_svg_add_iso_sample of the file src/filters/load_text.c of the …

Jun 17, 2024
CVE-2024-6061
3.3 LOW

A vulnerability has been found in GPAC 2.5-DEV-rev228-g11067ea92-master and classified as problematic. Affected by this vulnerability is the function isoffin_process of the file src/filters/isoffin_read.c of …

Jun 17, 2024
CVE-2024-37902
10.0 CRITICAL

DeepJavaLibrary(DJL) is an Engine-Agnostic Deep Learning Framework in Java. DJL versions 0.1.0 through 0.27.0 do not prevent absolute path archived artifacts from inserting archived files …

Jun 17, 2024
CVE-2024-37896
8.8 HIGH

Gin-vue-admin is a backstage management system based on vue and gin. Gin-vue-admin <= v2.6.5 has SQL injection vulnerability. The SQL injection vulnerabilities occur when a …

Jun 17, 2024
CVE-2024-37895
5.7 MEDIUM

Lobe Chat is an open-source LLMs/AI chat framework. In affected versions if an attacker can successfully authenticate through SSO/Access Code, they can obtain the real …

Jun 17, 2024
CVE-2024-37893
5.9 MEDIUM

Firefly III is a free and open source personal finance manager. In affected versions an MFA bypass in the Firefly III OAuth flow may allow …

Jun 17, 2024
CVE-2024-37891
4.4 MEDIUM

urllib3 is a user-friendly HTTP client library for Python. When using urllib3's proxy support with `ProxyManager`, the `Proxy-Authorization` header is only sent to the configured …

Jun 17, 2024
CVE-2024-37890
7.5 HIGH

ws is an open source WebSocket client and server for Node.js. A request with a number of headers exceeding theserver.maxHeadersCount threshold could be used to …

Jun 17, 2024
CVE-2024-37305
8.2 HIGH

oqs-provider is a provider for the OpenSSL 3 cryptography library that adds support for post-quantum cryptography in TLS, X.509, and S/MIME using post-quantum algorithms from …

Jun 17, 2024
CVE-2024-6059
2.4 LOW

A vulnerability, which was classified as problematic, has been found in Ingenico Estate Manager 2023. This issue affects some unknown processing of the file /emgui/rest/ums/messages …

Jun 17, 2024
CVE-2024-38449
7.7 HIGH

A Directory Traversal vulnerability in KasmVNC 1.3.1.230e50f7b89663316c70de7b0e3db6f6b9340489 and possibly earlier versions allows remote authenticated attackers to browse parent directories and read the content of files …

Jun 17, 2024
CVE-2024-37840
8.8 HIGH

SQL injection vulnerability in processscore.php in Itsourcecode Learning Management System Project In PHP With Source Code v1.0 allows remote attackers to execute arbitrary SQL commands …

Jun 17, 2024
CVE-2024-36543
9.8 CRITICAL

Incorrect access control in the Kafka Connect REST API in the STRIMZI Project 0.41.0 and earlier allows an attacker to deny the service for Kafka …

Jun 17, 2024
CVE-2024-6058
3.5 LOW

A vulnerability classified as problematic has been found in LabVantage LIMS 2017. This affects an unknown part of the file /labvantage/rc?command=page&page=SampleHistoricalList&_iframename=list&__crc=crc_1701669816260. The manipulation of the …

Jun 17, 2024
CVE-2024-6056
3.7 LOW

A vulnerability was found in nasirkhan Laravel Starter up to 11.8.0. It has been rated as problematic. Affected by this issue is some unknown functionality …

Jun 17, 2024
CVE-2024-37795
7.5 HIGH

A segmentation fault in CVC5 Solver v1.1.3 allows attackers to cause a Denial of Service (DoS) via a crafted SMT-LIB input file containing the `set-logic` …

Jun 17, 2024
CVE-2024-37794
7.5 HIGH

Improper input validation in CVC5 Solver v1.1.3 allows attackers to cause a Denial of Service (DoS) via a crafted SMT2 input file.

Jun 17, 2024
CVE-2024-37664
5.2 MEDIUM

Redmi router RB03 v1.0.57 is vulnerable to TCP DoS or hijacking attacks. An attacker in the same WLAN as the victim can disconnect or hijack …

Jun 17, 2024
CVE-2024-37663
4.1 MEDIUM

Redmi router RB03 v1.0.57 is vulnerable to forged ICMP redirect message attacks. An attacker in the same WLAN as the victim can hijack the traffic …

Jun 17, 2024
CVE-2024-37662
6.3 MEDIUM

TP-LINK TL-7DR5130 v1.0.23 is vulnerable to TCP DoS or hijacking attacks. An attacker in the same WLAN as the victim can disconnect or hijack the …

Jun 17, 2024
CVE-2024-37661
6.3 MEDIUM

TP-LINK TL-7DR5130 v1.0.23 is vulnerable to forged ICMP redirect message attacks. An attacker in the same WLAN as the victim can hijack the traffic between …

Jun 17, 2024
CVE-2024-36973
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: misc: microchip: pci1xxxx: fix double free in the error handling of gp_aux_bus_probe() When auxiliary_device_add() returns …

Jun 17, 2024
CVE-2024-36527
6.5 MEDIUM

puppeteer-renderer v.3.2.0 and before is vulnerable to Directory Traversal. Attackers can exploit the URL parameter using the file protocol to read sensitive information from the …

Jun 17, 2024
CVE-2018-25103
5.3 MEDIUM

There exists use-after-free vulnerabilities in lighttpd <= 1.4.50 request parsing which might read from invalid pointers to memory used in the same request, not from …

Jun 17, 2024
CVE-2024-36578
5.9 MEDIUM

akbr update 1.0.0 is vulnerable to Prototype Pollution via update/index.js.

Jun 17, 2024
CVE-2024-36577
8.3 HIGH

apphp js-object-resolver < 3.1.1 is vulnerable to Prototype Pollution via Module.setNestedProperty.

Jun 17, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.