CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-36575
9.8 CRITICAL

A Prototype Pollution issue in getsetprop 1.1.0 allows an attacker to execute arbitrary code via global.accessor.

Jun 17, 2024
CVE-2024-36574
6.3 MEDIUM

A Prototype Pollution issue in flatten-json 1.0.1 allows an attacker to execute arbitrary code via module.exports.unflattenJSON (flatten-json/index.js:42)

Jun 17, 2024
CVE-2024-36573
9.8 CRITICAL

almela obx before v.0.0.4 has a Prototype Pollution issue which allows arbitrary code execution via the obx/build/index.js:656), reduce (@almela/obx/build/index.js:470), Object.set (obx/build/index.js:269) component.

Jun 17, 2024
CVE-2024-0397
7.4 HIGH

A defect was discovered in the Python “ssl” module where there is a memory race condition with the ssl.SSLContext methods “cert_store_stats()” and “get_ca_certs()”. The race …

Jun 17, 2024
CVE-2024-4032
7.5 HIGH

The “ipaddress” module contained incorrect information about whether certain IPv4 and IPv6 addresses were designated as “globally reachable” or “private”. This affected the is_private and …

Jun 17, 2024
CVE-2024-36582
9.8 CRITICAL

alexbinary object-deep-assign 1.0.11 is vulnerable to Prototype Pollution via the extend() method of Module.deepAssign (/src/index.js)

Jun 17, 2024
CVE-2024-36581
7.6 HIGH

A Prototype Pollution issue in abw badger-database 1.2.1 allows an attacker to execute arbitrary code via dist/badger-database.esm.

Jun 17, 2024
CVE-2024-38470
6.1 MEDIUM

zhimengzhe iBarn v1.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the $search parameter at /own.php.

Jun 17, 2024
CVE-2024-38469
6.3 MEDIUM

zhimengzhe iBarn v1.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the $search parameter at /pay.php.

Jun 17, 2024
CVE-2024-37848
8.4 HIGH

SQL Injection vulnerability in Online-Bookstore-Project-In-PHP v1.0 allows a local attacker to execute arbitrary code via the admin_delete.php component.

Jun 17, 2024
CVE-2024-37625
6.1 MEDIUM

zhimengzhe iBarn v1.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the $search parameter at /index.php.

Jun 17, 2024
CVE-2024-37624
6.1 MEDIUM

Xinhu RockOA v2.6.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the /chajian/inputChajian.php. component.

Jun 17, 2024
CVE-2024-37623
6.1 MEDIUM

Xinhu RockOA v2.6.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the /kaoqin/tpl_kaoqin_locationchange.html component.

Jun 17, 2024
CVE-2024-37622
6.1 MEDIUM

Xinhu RockOA v2.6.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the num parameter at /flow/flow.php.

Jun 17, 2024
CVE-2024-37621
7.2 HIGH

StrongShop v1.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the component /shippingOptionConfig/index.blade.php.

Jun 17, 2024
CVE-2024-37620
6.1 MEDIUM

PHPVOD v4.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the id parameter at /view/admin/view.php.

Jun 17, 2024
CVE-2024-37619
6.1 MEDIUM

StrongShop v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the spec_group_id parameter at /spec/index.blade.php.

Jun 17, 2024
CVE-2024-37159
3.5 LOW

Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. This vulnerability allowed a user to create a validator using vested tokens to …

Jun 17, 2024
CVE-2024-37158
3.5 LOW

Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. Preliminary checks on actions computed by the clawback vesting accounts are performed in …

Jun 17, 2024
CVE-2024-36583
8.1 HIGH

A Prototype Pollution issue in byondreal accessor <= 1.0.0 allows an attacker to execute arbitrary code via @byondreal/accessor/index.

Jun 17, 2024
CVE-2024-36580
9.8 CRITICAL

A Prototype Pollution issue in cdr0 sg 1.0.10 allows an attacker to execute arbitrary code.

Jun 17, 2024
CVE-2024-6057
9.8 CRITICAL

Improper authentication in the vault password feature in Devolutions Remote Desktop Manager 2024.1.31.0 and earlier allows an attacker that has compromised an access to an …

Jun 17, 2024
CVE-2024-6055
4.7 MEDIUM

Improper removal of sensitive information in data source export feature in Devolutions Remote Desktop Manager 2024.1.32.0 and earlier on Windows allows an attacker that obtains …

Jun 17, 2024
CVE-2024-5741
6.5 MEDIUM

Stored XSS in inventory tree rendering in Checkmk before 2.3.0p7, 2.2.0p28, 2.1.0p45 and 2.0.0 (EOL)

Jun 17, 2024
CVE-2024-6048
9.8 CRITICAL

Openfind's MailGates and MailAudit fail to properly filter user input when analyzing email attachments. An unauthenticated remote attacker can exploit this vulnerability to inject system …

Jun 17, 2024
CVE-2024-36289
5.3 MEDIUM

Reusing a nonce, key pair in encryption issue exists in "FreeFrom - the nostr client" App versions prior to 1.3.5 for Android and iOS. If …

Jun 17, 2024
CVE-2024-36279
5.3 MEDIUM

Reliance on obfuscation or encryption of security-relevant inputs without integrity checking issue exists in "FreeFrom - the nostr client" App versions prior to 1.3.5 for …

Jun 17, 2024
CVE-2024-36277
5.3 MEDIUM

Improper verification of cryptographic signature issue exists in "FreeFrom - the nostr client" App versions prior to 1.3.5 for Android and iOS. The affected app …

Jun 17, 2024
CVE-2024-5650
8.5 HIGH

DLL Hijacking vulnerability has been found in CENTUM CAMS Log server provided by Yokogawa Electric Corporation. If an attacker is somehow able to intrude into …

Jun 17, 2024
CVE-2024-6047
9.8 CRITICAL KEV

Certain EOL GeoVision devices fail to properly filter user input for the specific functionality. Unauthenticated remote attackers can exploit this vulnerability to inject and execute …

Jun 17, 2024
CVE-2024-4305
6.8 MEDIUM

The Post Grid Gutenberg Blocks and WordPress Blog Plugin WordPress plugin before 4.1.0 does not validate and escape some of its block options before outputting …

Jun 17, 2024
CVE-2024-3236
5.4 MEDIUM

The Popup Builder WordPress plugin before 1.1.33 does not sanitise and escape some of its Notification fields, which could allow users such as contributor and …

Jun 17, 2024
CVE-2024-6046

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 17, 2024
CVE-2024-6045
8.8 HIGH

Certain models of D-Link wireless routers contain an undisclosed factory testing backdoor. Unauthenticated attackers on the local area network can force the device to enable …

Jun 17, 2024
CVE-2024-6044
6.5 MEDIUM

Certain models of D-Link wireless routers have a path traversal vulnerability. Unauthenticated attackers on the same local area network can read arbitrary system files by …

Jun 17, 2024
CVE-2024-5163
9.8 CRITICAL

Improper permission settings for mobile applications (com.transsion.carlcare) may lead to user password and account security risks.

Jun 17, 2024
CVE-2024-6043
7.3 HIGH

A vulnerability classified as critical has been found in SourceCodester Best House Rental Management System 1.0. This affects the function login of the file admin_class.php. …

Jun 17, 2024
CVE-2024-6042
7.3 HIGH

A vulnerability was found in itsourcecode Real Estate Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

Jun 17, 2024
CVE-2024-6041
6.3 MEDIUM

A vulnerability was found in itsourcecode Gym Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Jun 16, 2024
CVE-2024-6039
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in Feng Office 3.11.1.2. Affected is an unknown function of the component Workspaces. The manipulation of …

Jun 16, 2024
CVE-2024-34451
9.1 CRITICAL

Ghost through 5.85.1 allows remote attackers to bypass an authentication rate-limit protection mechanism by using many X-Forwarded-For headers with different values. NOTE: the vendor's position …

Jun 16, 2024
CVE-2024-38396
9.8 CRITICAL

An issue was discovered in iTerm2 3.5.x before 3.5.2. Unfiltered use of an escape sequence to report a window title, in combination with the built-in …

Jun 16, 2024
CVE-2023-27636
5.4 MEDIUM

Progress Sitefinity before 15.0.0 allows XSS by authenticated users via the content form in the SF Editor.

Jun 16, 2024
CVE-2024-38468
9.8 CRITICAL

Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized password resets via the resetPassword API.

Jun 16, 2024
CVE-2024-38467
7.5 HIGH

Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized user information retrieval via the queryUser API.

Jun 16, 2024
CVE-2024-38466
9.8 CRITICAL

Shenzhen Guoxin Synthesis image system before 8.3.0 has a 123456Qw default password.

Jun 16, 2024
CVE-2024-38465
5.3 MEDIUM

Shenzhen Guoxin Synthesis image system before 8.3.0 allows username enumeration because of the response discrepancy of incorrect versus error.

Jun 16, 2024
CVE-2024-38462
9.8 CRITICAL

iRODS before 4.3.2 provides an msiSendMail function with a problematic dependency on the mail binary, such as in the mailMS.cpp#L94-L106 reference.

Jun 16, 2024
CVE-2024-38461
7.5 HIGH

irodsServerMonPerf in iRODS before 4.3.2 attempts to proceed with use of a path even if it is not a directory.

Jun 16, 2024
CVE-2024-38460
4.9 MEDIUM

In SonarQube before 10.4 and 9.9.4 LTA, encrypted values generated using the Settings Encryption feature are potentially exposed in cleartext as part of the URL …

Jun 16, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.