CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2023-49441
7.5 HIGH

dnsmasq 2.9 is vulnerable to Integer Overflow via forward_query.

Jun 6, 2024
CVE-2024-36795
4.0 MEDIUM

Insecure permissions in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to access URLs and directories embedded within the firmware via unspecified vectors.

Jun 6, 2024
CVE-2024-32752
9.1 CRITICAL

The iSTAR door controllers running firmware prior to version 6.6.B, does not support authenticated communications with ICU, which may allow an attacker to gain unauthorized …

Jun 6, 2024
CVE-2024-22074
9.8 CRITICAL

Dynamsoft Service 1.8.1025 through 1.8.2013, 1.7.0330 through 1.7.2531, 1.6.0428 through 1.6.1112, 1.5.0625 through 1.5.3116, 1.4.0618 through 1.4.1230, and 1.0.516 through 1.3.0115 has Incorrect Access Control. …

Jun 6, 2024
CVE-2024-5552
7.5 HIGH

kubeflow/kubeflow is vulnerable to a Regular Expression Denial of Service (ReDoS) attack due to inefficient regular expression complexity in its email validation mechanism. An attacker …

Jun 6, 2024
CVE-2024-5550
5.3 MEDIUM

In h2oai/h2o-3 version 3.40.0.4, an exposure of sensitive information vulnerability exists due to an arbitrary system path lookup feature. This vulnerability allows any remote user …

Jun 6, 2024
CVE-2024-5480

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 6, 2024
CVE-2024-5478
6.1 MEDIUM

A Cross-site Scripting (XSS) vulnerability exists in the SAML metadata endpoint `/auth/saml/${org?.id}/metadata` of lunary-ai/lunary version 1.2.7. The vulnerability arises due to the application's failure to …

Jun 6, 2024
CVE-2024-5328
9.3 CRITICAL

A Server-Side Request Forgery (SSRF) vulnerability exists in the lunary-ai/lunary application, specifically within the endpoint '/auth/saml/tto/download-idp-xml'. The vulnerability arises due to the application's failure to …

Jun 6, 2024
CVE-2024-5307
3.3 LOW

Kofax Power PDF AcroForm Annotation Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Kofax Power …

Jun 6, 2024
CVE-2024-5306
7.8 HIGH

Kofax Power PDF PDF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Jun 6, 2024
CVE-2024-5305
7.8 HIGH

Kofax Power PDF PDF File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations …

Jun 6, 2024
CVE-2024-5304
7.8 HIGH

Kofax Power PDF TGA File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Jun 6, 2024
CVE-2024-5278
6.1 MEDIUM

gaizhenbiao/chuanhuchatgpt is vulnerable to an unrestricted file upload vulnerability due to insufficient validation of uploaded file types in its `/upload` endpoint. Specifically, the `handle_file_upload` function …

Jun 6, 2024
CVE-2024-5248
6.5 MEDIUM

In lunary-ai/lunary version 1.2.5, an improper access control vulnerability exists due to a missing permission check in the `GET /v1/users/me/org` endpoint. The platform's role definitions …

Jun 6, 2024
CVE-2024-5225
7.2 HIGH

An SQL Injection vulnerability exists in the berriai/litellm repository, specifically within the `/global/spend/logs` endpoint. The vulnerability arises due to improper neutralization of special elements used …

Jun 6, 2024
CVE-2024-5206
4.7 MEDIUM

A sensitive data leakage vulnerability was identified in scikit-learn's TfidfVectorizer, specifically in versions up to and including 1.4.1.post1, which was fixed in version 1.5.0. The …

Jun 6, 2024
CVE-2024-5187
8.8 HIGH

A vulnerability in the `download_model_with_test_data` function of the onnx/onnx framework, version 1.16.0, allows for arbitrary file overwrite due to inadequate prevention of path traversal attacks …

Jun 6, 2024
CVE-2024-5186
7.2 HIGH

A Server-Side Request Forgery (SSRF) vulnerability exists in the file upload section of imartinez/privategpt version 0.5.0. This vulnerability allows attackers to send crafted requests that …

Jun 6, 2024
CVE-2024-5133
8.1 HIGH

In lunary-ai/lunary version 1.2.4, an account takeover vulnerability exists due to the exposure of password recovery tokens in API responses. Specifically, when a user initiates …

Jun 6, 2024
CVE-2024-5132

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 6, 2024
CVE-2024-5131
6.5 MEDIUM

An Improper Access Control vulnerability exists in the lunary-ai/lunary repository, affecting versions up to and including 1.2.2. The vulnerability allows unauthorized users to view any …

Jun 6, 2024
CVE-2024-5130
7.5 HIGH

An Incorrect Authorization vulnerability exists in lunary-ai/lunary versions up to and including 1.2.2, which allows unauthenticated users to delete any dataset. The vulnerability is due …

Jun 6, 2024
CVE-2024-5129
8.2 HIGH

A Privilege Escalation Vulnerability exists in lunary-ai/lunary version 1.2.2, where any user can delete any datasets due to missing authorization checks. The vulnerability is present …

Jun 6, 2024
CVE-2024-5128
8.8 HIGH

An Insecure Direct Object Reference (IDOR) vulnerability was identified in lunary-ai/lunary, affecting versions up to and including 1.2.2. This vulnerability allows unauthorized users to view, …

Jun 6, 2024
CVE-2024-5126
6.5 MEDIUM

An improper access control vulnerability exists in the lunary-ai/lunary repository, specifically within the versions.patch functionality for updating prompts. Affected versions include 1.2.2 up to but …

Jun 6, 2024
CVE-2024-5124
7.5 HIGH

A timing attack vulnerability exists in the gaizhenbiao/chuanhuchatgpt repository, specifically within the password comparison logic. The vulnerability is present in version 20240310 of the software, …

Jun 6, 2024
CVE-2024-4890
4.9 MEDIUM

A blind SQL injection vulnerability exists in the berriai/litellm application, specifically within the '/team/update' process. The vulnerability arises due to the improper handling of the …

Jun 6, 2024
CVE-2024-4888
8.1 HIGH

BerriAI's litellm, in its latest version, is vulnerable to arbitrary file deletion due to improper input validation on the `/audio/transcriptions` endpoint. An attacker can exploit …

Jun 6, 2024
CVE-2024-4881
7.5 HIGH

A path traversal vulnerability exists in the parisneo/lollms application, affecting version 9.4.0 and potentially earlier versions, but fixed in version 5.9.0. The vulnerability arises due …

Jun 6, 2024
CVE-2024-4851
7.7 HIGH

A Server-Side Request Forgery (SSRF) vulnerability exists in the stangirard/quivr application, version 0.0.204, which allows attackers to access internal networks. The vulnerability is present in …

Jun 6, 2024
CVE-2024-4320
9.8 CRITICAL

A remote code execution (RCE) vulnerability exists in the '/install_extension' endpoint of the parisneo/lollms-webui application, specifically within the `@router.post("/install_extension")` route handler. The vulnerability arises due …

Jun 6, 2024
CVE-2024-3429
9.8 CRITICAL

A path traversal vulnerability exists in the parisneo/lollms application, specifically within the `sanitize_path_from_endpoint` and `sanitize_path` functions in `lollms_core\lollms\security.py`. This vulnerability allows for arbitrary file reading …

Jun 6, 2024
CVE-2024-3408
9.8 CRITICAL

man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulnerability arises from a hardcoded …

Jun 6, 2024
CVE-2024-3404
6.5 MEDIUM

In gaizhenbiao/chuanhuchatgpt, specifically the version tagged as 20240121, there exists a vulnerability due to improper access control mechanisms. This flaw allows an authenticated attacker to …

Jun 6, 2024
CVE-2024-3402
5.4 MEDIUM

A stored Cross-Site Scripting (XSS) vulnerability existed in version (20240121) of gaizhenbiao/chuanhuchatgpt due to inadequate sanitization and validation of model output data. Despite user-input validation …

Jun 6, 2024
CVE-2024-3322
9.8 CRITICAL

A path traversal vulnerability exists in the 'cyber_security/codeguard' native personality of the parisneo/lollms-webui, affecting versions up to 9.5. The vulnerability arises from the improper limitation …

Jun 6, 2024
CVE-2024-3234
9.8 CRITICAL

The gaizhenbiao/chuanhuchatgpt application is vulnerable to a path traversal attack due to its use of an outdated gradio component. The application is designed to restrict …

Jun 6, 2024
CVE-2024-3166
9.6 CRITICAL

A Cross-Site Scripting (XSS) vulnerability exists in mintplex-labs/anything-llm, affecting both the desktop application version 1.2.0 and the latest version of the web application. The vulnerability …

Jun 6, 2024
CVE-2024-3153
6.5 MEDIUM

mintplex-labs/anything-llm is affected by an uncontrolled resource consumption vulnerability in its upload file endpoint, leading to a denial of service (DOS) condition. Specifically, the server …

Jun 6, 2024
CVE-2024-3150
8.8 HIGH

In mintplex-labs/anything-llm, a vulnerability exists in the thread update process that allows users with Default or Manager roles to escalate their privileges to Administrator. The …

Jun 6, 2024
CVE-2024-3149
8.8 HIGH

A Server-Side Request Forgery (SSRF) vulnerability exists in the upload link feature of mintplex-labs/anything-llm. This feature, intended for users with manager or admin roles, processes …

Jun 6, 2024
CVE-2024-3110
8.7 HIGH

A stored Cross-Site Scripting (XSS) vulnerability exists in the mintplex-labs/anything-llm application, affecting versions up to and including the latest before 1.0.0. The vulnerability arises from …

Jun 6, 2024
CVE-2024-3102
5.3 MEDIUM

A JSON Injection vulnerability exists in the `mintplex-labs/anything-llm` application, specifically within the username parameter during the login process at the `/api/request-token` endpoint. The vulnerability arises …

Jun 6, 2024
CVE-2024-3099
5.4 MEDIUM

A vulnerability in mlflow/mlflow version 2.11.1 allows attackers to create multiple models with the same name by exploiting URL encoding. This flaw can lead to …

Jun 6, 2024
CVE-2024-3095
7.7 HIGH

A Server-Side Request Forgery (SSRF) vulnerability exists in the Web Research Retriever component of langchain-ai/langchain version 0.1.5. The vulnerability arises because the Web Research Retriever …

Jun 6, 2024
CVE-2024-37364
6.8 MEDIUM

Ariane Allegro Scenario Player through 2024-03-05, when Ariane Duo kiosk mode is used, allows physically proximate attackers to obtain sensitive information (such as hotel invoice …

Jun 6, 2024
CVE-2024-37154
5.3 MEDIUM

Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. Users are able to delegate tokens that have not yet been vested. This …

Jun 6, 2024
CVE-2024-37153
7.5 HIGH

Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. There is an issue with how to liquid stake using Safe which itself …

Jun 6, 2024
CVE-2024-36740
7.5 HIGH

An issue in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) when index as a negative number exceeds the range of …

Jun 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.