CVE Database

10843+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-1643
9.1 CRITICAL

By knowing an organization's ID, an attacker can join the organization without permission and gain the ability to read and modify all data within that …

Apr 10, 2024
CVE-2024-1600
9.3 CRITICAL

A Local File Inclusion (LFI) vulnerability exists in the parisneo/lollms-webui application, specifically within the `/personalities` route. An attacker can exploit this vulnerability by crafting a …

Apr 10, 2024
CVE-2024-1520
9.8 CRITICAL

An OS Command Injection vulnerability exists in the '/open_code_folder' endpoint of the parisneo/lollms-webui application, due to improper validation of user-supplied input in the 'discussion_id' parameter. …

Apr 10, 2024
CVE-2024-1511
9.8 CRITICAL

The parisneo/lollms-webui repository is susceptible to a path traversal vulnerability due to inadequate validation of user-supplied file paths. This flaw allows an unauthenticated attacker to …

Apr 10, 2024
CVE-2024-3566
9.8 CRITICAL

A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess function when the specific conditions …

Apr 10, 2024
CVE-2024-23080
9.1 CRITICAL

Joda Time v2.12.5 was discovered to contain a NullPointerException via the component org.joda.time.format.PeriodFormat::wordBased(Locale). NOTE: this is disputed by multiple third parties who believe there was …

Apr 10, 2024
CVE-2024-20758
9.0 CRITICAL

Adobe Commerce versions 2.4.6-p4, 2.4.5-p6, 2.4.4-p7, 2.4.7-beta3 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution on …

Apr 10, 2024
CVE-2024-3120
9.0 CRITICAL

A stack-buffer overflow vulnerability exists in all versions of sngrep since v1.4.1. The flaw is due to inadequate bounds checking when copying 'Content-Length' and 'Warning' …

Apr 10, 2024
CVE-2024-3119
9.0 CRITICAL

A buffer overflow vulnerability exists in all versions of sngrep since v0.4.2, due to improper handling of 'Call-ID' and 'X-Call-ID' SIP headers. The functions sip_get_callid …

Apr 10, 2024
CVE-2024-3136
9.8 CRITICAL

The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.3 via the 'template' parameter. This …

Apr 9, 2024
CVE-2024-2804
9.8 CRITICAL

The Network Summary plugin for WordPress is vulnerable to SQL Injection via the 'category' parameter in all versions up to, and including, 2.0.11 due to …

Apr 9, 2024
CVE-2024-1813
9.8 CRITICAL

The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.11.0 via deserialization of untrusted …

Apr 9, 2024
CVE-2024-24576
10.0 CRITICAL

Rust is a programming language. The Rust Security Response WG was notified that the Rust standard library prior to version 1.77.2 did not properly escape …

Apr 9, 2024
CVE-2024-29990
9.0 CRITICAL

Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability

Apr 9, 2024
CVE-2024-31866
9.8 CRITICAL

Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin. The attackers can execute shell scripts or malicious code by overriding configuration like ZEPPELIN_INTP_CLASSPATH_OVERRIDES. This …

Apr 9, 2024
CVE-2024-31864
9.8 CRITICAL

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Zeppelin. The attacker can inject sensitive configuration or malicious code when connecting MySQL database …

Apr 9, 2024
CVE-2023-45590
9.6 CRITICAL

An improper control of generation of code ('code injection') in Fortinet FortiClientLinux version 7.2.0, 7.0.6 through 7.0.10 and 7.0.3 through 7.0.4 allows attacker to execute …

Apr 9, 2024
CVE-2023-6320
9.1 CRITICAL

A command injection vulnerability exists in the com.webos.service.connectionmanager/tv/setVlanStaticAddress endpoint on webOS versions 5 and 6. A series of specially crafted requests can lead to command …

Apr 9, 2024
CVE-2023-6319
9.1 CRITICAL

A command injection vulnerability exists in the getAudioMetadata method from the com.webos.service.attachedstoragemanager service on webOS version 4 through 7. A series of specially crafted requests …

Apr 9, 2024
CVE-2023-6318
9.1 CRITICAL

A command injection vulnerability exists in the processAnalyticsReport method from the com.webos.service.cloudupload service on webOS version 5 through 7. A series of specially crafted requests …

Apr 9, 2024
CVE-2023-1083
9.8 CRITICAL

An unauthenticated remote attacker who is aware of a MQTT topic name can send and receive messages, including GET/SET configuration commands, reboot commands and firmware …

Apr 9, 2024
CVE-2024-22949
9.1 CRITICAL

JFreeChart v1.5.4 was discovered to contain a NullPointerException via the component /chart/annotations/CategoryLineAnnotation. NOTE: this is disputed by multiple third parties who believe there was not …

Apr 8, 2024
CVE-2024-23086
9.8 CRITICAL

Apfloat v1.10.1 was discovered to contain a stack overflow via the component org.apfloat.internal.DoubleModMath::modPow(double. NOTE: this is disputed by multiple third parties who believe there was …

Apr 8, 2024
CVE-2024-23078
9.1 CRITICAL

JGraphT Core v1.5.2 was discovered to contain a NullPointerException via the component org.jgrapht.alg.util.ToleranceDoubleComparator::compare(Double, Double). NOTE: this is disputed by multiple third parties who believe there …

Apr 8, 2024
CVE-2024-31224
9.8 CRITICAL

GPT Academic provides interactive interfaces for large language models. A vulnerability was found in gpt_academic versions 3.64 through 3.73. The server deserializes untrustworthy data from …

Apr 8, 2024
CVE-2024-31815
9.1 CRITICAL

In TOTOLINK EX200 V4.0.3c.7314_B20191204, an attacker can obtain the configuration file without authorization through /cgi-bin/ExportSettings.sh

Apr 8, 2024
CVE-2024-31807
9.8 CRITICAL

TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the hostTime parameter in the NTPSyncWithHost function.

Apr 8, 2024
CVE-2022-43216
9.1 CRITICAL

AbrhilSoft Employee's Portal before v5.6.2 was discovered to contain a SQL injection vulnerability in the login page.

Apr 8, 2024
CVE-2023-52538
9.1 CRITICAL

Vulnerability of package name verification being bypassed in the HwIms module. Impact: Successful exploitation of this vulnerability will affect availability.

Apr 8, 2024
CVE-2024-31022
9.8 CRITICAL

An issue was discovered in CandyCMS version 1.0.0, allows remote attackers to execute arbitrary code via the install.php component.

Apr 8, 2024
CVE-2024-27488
9.8 CRITICAL

Incorrect Access Control vulnerability in ZLMediaKit versions 1.0 through 8.0, allows remote attackers to escalate privileges and obtain sensitive information. The application system enables the …

Apr 8, 2024
CVE-2024-31345
9.1 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Sukhchain Singh Auto Poster.This issue affects Auto Poster: from n/a through 1.2.

Apr 7, 2024
CVE-2024-31286
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This issue affects WP Photo Album Plus: from n/a …

Apr 7, 2024
CVE-2024-31280
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.1.5.

Apr 7, 2024
CVE-2024-30415
9.1 CRITICAL

Vulnerability of improper permission control in the window management module. Impact: Successful exploitation of this vulnerability will affect availability.

Apr 7, 2024
CVE-2024-25029
9.0 CRITICAL

IBM Personal Communications 14.0.6 through 15.0.1 includes a Windows service that is vulnerable to remote code execution (RCE) and local privilege escalation (LPE). The vulnerability …

Apr 6, 2024
CVE-2024-29756
9.8 CRITICAL

In afe_callback of q6afe.c, there is a possible out of bounds write due to a buffer overflow. This could lead to local escalation of privilege …

Apr 5, 2024
CVE-2024-31849
9.8 CRITICAL

A path traversal vulnerability exists in the Java version of CData Connect < 23.4.8846 when running using the embedded Jetty server, which could allow an …

Apr 5, 2024
CVE-2024-31848
9.8 CRITICAL

A path traversal vulnerability exists in the Java version of CData API Server < 23.4.8844 when running using the embedded Jetty server, which could allow …

Apr 5, 2024
CVE-2024-22004
10.0 CRITICAL

Due to length check, an attacker with privilege access on a Linux Nonsecure operating system can trigger a vulnerability and leak the secure memory from …

Apr 5, 2024
CVE-2023-48426
10.0 CRITICAL

u-boot bug that allows for u-boot shell and interrupt over UART

Apr 5, 2024
CVE-2024-31218
9.8 CRITICAL

Webhood is a self-hosted URL scanner used analyzing phishing and malicious sites. Webhood's backend container images in versions 0.9.0 and earlier are subject to Missing …

Apr 5, 2024
CVE-2024-30849
9.8 CRITICAL

Arbitrary file upload vulnerability in Sourcecodester Complete E-Commerce Site v1.0, allows remote attackers to execute arbitrary code via filename parameter in admin/products_photo.php.

Apr 5, 2024
CVE-2024-27448
9.1 CRITICAL

MailDev 2 through 2.1.0 allows Remote Code Execution via a crafted Content-ID header for an e-mail attachment, leading to lib/mailserver.js writing arbitrary code into the …

Apr 5, 2024
CVE-2024-27981
9.8 CRITICAL

A Command Injection vulnerability found in a Self-Hosted UniFi Network Servers (Linux) with UniFi Network Application (Version 8.0.28 and earlier) allows a malicious actor with …

Apr 4, 2024
CVE-2024-21894
9.8 CRITICAL

A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user to send specially …

Apr 4, 2024
CVE-2024-25693
9.9 CRITICAL

There is a path traversal in Esri Portal for ArcGIS versions <= 11.2. Successful exploitation may allow a remote, authenticated attacker to traverse the file …

Apr 4, 2024
CVE-2023-36645
9.1 CRITICAL

SQL injection vulnerability in ITB-GmbH TradePro v9.5, allows remote attackers to run SQL queries via oordershow component in customer function.

Apr 4, 2024
CVE-2024-29006
9.8 CRITICAL

By default the CloudStack management server honours the x-forwarded-for HTTP header and logs it as the source IP of an API request. This could lead …

Apr 4, 2024
CVE-2024-29375
9.8 CRITICAL

CSV Injection vulnerability in Addactis IBNRS v.3.10.3.107 allows a remote attacker to execute arbitrary code via a crafted .ibnrs file to the Project Description, Identifiers, …

Apr 4, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.