CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-36743
7.5 HIGH

An issue in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) when an empty array is processed with oneflow.dot.

Jun 6, 2024
CVE-2024-36737
7.5 HIGH

Improper input validation in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) via inputting a negative value into the oneflow.full parameter.

Jun 6, 2024
CVE-2024-36736
9.8 CRITICAL

An issue in the oneflow.permute component of OneFlow-Inc. Oneflow v0.9.1 causes an incorrect calculation when the same dimension operation is performed.

Jun 6, 2024
CVE-2024-30375
7.8 HIGH

Luxion KeyShot Viewer KSP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Luxion …

Jun 6, 2024
CVE-2024-30374
7.8 HIGH

Luxion KeyShot Viewer KSP File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of …

Jun 6, 2024
CVE-2024-30369
7.8 HIGH

A10 Thunder ADC Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of A10 Thunder ADC. …

Jun 6, 2024
CVE-2024-30368
8.8 HIGH

A10 Thunder ADC CsrRequestView Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of A10 Thunder …

Jun 6, 2024
CVE-2024-2914
8.8 HIGH

A TarSlip vulnerability exists in the deepjavalibrary/djl, affecting version 0.26.0 and fixed in version 0.27.0. This vulnerability allows an attacker to manipulate file paths within …

Jun 6, 2024
CVE-2024-1879
8.8 HIGH

A Cross-Site Request Forgery (CSRF) vulnerability in significant-gravitas/autogpt version v0.5.0 allows attackers to execute arbitrary commands on the AutoGPT server. The vulnerability stems from the …

Jun 6, 2024
CVE-2024-36742
7.5 HIGH

An issue in the oneflow.scatter_nd parameter OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) when index parameter exceeds the range of …

Jun 6, 2024
CVE-2024-33655
7.5 HIGH

The DNS protocol in RFC 1035 and updates allows remote attackers to cause a denial of service (resource consumption) by arranging for DNS queries to …

Jun 6, 2024
CVE-2024-37156
6.1 MEDIUM

The SuluFormBundle adds support for creating dynamic forms in Sulu Admin. The TokenController get parameter formName is not sanitized in the returned input field which …

Jun 6, 2024
CVE-2024-37152
5.3 MEDIUM

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The vulnerability allows unauthorized access to the sensitive settings exposed by /api/v1/settings endpoint without …

Jun 6, 2024
CVE-2024-37150
7.6 HIGH

An issue in `.npmrc` support in Deno 1.44.0 was discovered where Deno would send `.npmrc` credentials for the scope to the tarball URL when the …

Jun 6, 2024
CVE-2024-36399
8.2 HIGH

Kanboard is project management software that focuses on the Kanban methodology. The vuln is in app/Controller/ProjectPermissionController.php function addUser(). The users permission to add users to …

Jun 6, 2024
CVE-2024-35178
7.5 HIGH

The Jupyter Server provides the backend for Jupyter web applications. Jupyter Server on Windows has a vulnerability that lets unauthenticated attackers leak the NTLMv2 password …

Jun 6, 2024
CVE-2024-36106
4.3 MEDIUM

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. It’s possible for authenticated users to enumerate clusters by name by inspecting error messages. …

Jun 6, 2024
CVE-2024-34832
9.8 CRITICAL

Directory Traversal vulnerability in CubeCart v.6.5.5 and before allows an attacker to execute arbitrary code via a crafted file uploaded to the _g and node …

Jun 6, 2024
CVE-2024-5684
6.3 MEDIUM

An attacker with access to the private network (the charger is connected to) or local access to the Ethernet-Interface can exploit a faulty implementation of …

Jun 6, 2024
CVE-2024-5675
10.0 CRITICAL

Untrusted data deserialization vulnerability has been found in Mentor - Employee Portal, affecting version 3.83.35. This vulnerability could allow an attacker to execute arbitrary code, …

Jun 6, 2024
CVE-2024-36779
9.8 CRITICAL

Sourcecodester Stock Management System v1.0 is vulnerable to SQL Injection via editCategories.php.

Jun 6, 2024
CVE-2024-5489
4.3 MEDIUM

The Wbcom Designs – Custom Font Uploader plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the …

Jun 6, 2024
CVE-2024-5673
6.1 MEDIUM

Vulnerability in Dulldusk's PHP File Manager affecting version 1.7.8. This vulnerability consists of an XSS through the fm_current_dir parameter of index.php. An attacker could send …

Jun 6, 2024
CVE-2024-5658
4.8 MEDIUM

The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period.

Jun 6, 2024
CVE-2024-5657
3.7 LOW

The CraftCMS plugin Two-Factor Authentication in versions 3.3.1, 3.3.2 and 3.3.3 discloses the password hash of the currently authenticated user after submitting a valid TOTP.

Jun 6, 2024
CVE-2024-5188
6.4 MEDIUM

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Jun 6, 2024
CVE-2024-5038
6.4 MEDIUM

The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.0.276 …

Jun 6, 2024
CVE-2024-5329
8.8 HIGH

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to blind SQL Injection via the ‘data[addonID]’ parameter in all versions …

Jun 6, 2024
CVE-2024-5259
6.4 MEDIUM

The MultiVendorX Marketplace – WooCommerce MultiVendor Marketplace Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘hover_animation’ parameter in all versions up …

Jun 6, 2024
CVE-2024-5221
6.4 MEDIUM

The Qi Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file uploader in all versions up to, and including, 1.2.9 …

Jun 6, 2024
CVE-2024-5089

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jun 6, 2024
CVE-2024-36394
9.1 CRITICAL

SysAid - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Jun 6, 2024
CVE-2024-36393
9.9 CRITICAL

SysAid - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Jun 6, 2024
CVE-2024-28995
8.6 HIGH KEV

SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine.

Jun 6, 2024
CVE-2024-5665
4.3 MEDIUM

The Login/Signup Popup ( Inline Form + Woocommerce ) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check …

Jun 6, 2024
CVE-2024-4177
8.1 HIGH

A host whitelist parser issue in the proxy service implemented in the GravityZone Update Server allows an attacker to cause a server-side request forgery. This …

Jun 6, 2024
CVE-2024-3049
5.9 MEDIUM

A flaw was found in Booth, a cluster ticket manager. If a specially-crafted hash is passed to gcry_md_get_algo_dlen(), it may allow an invalid HMAC to …

Jun 6, 2024
CVE-2024-5615
5.3 MEDIUM

The Open Graph plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.11.2 via the 'opengraph_default_description' function. This …

Jun 6, 2024
CVE-2024-5449
4.3 MEDIUM

The WP Dark Mode – WordPress Dark Mode Plugin for Improved Accessibility, Dark Theme, Night Mode, and Social Sharing plugin for WordPress is vulnerable to …

Jun 6, 2024
CVE-2024-5162
6.4 MEDIUM

The WordPress prettyPhoto plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 1.2.3 due …

Jun 6, 2024
CVE-2024-5161
6.4 MEDIUM

The Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

Jun 6, 2024
CVE-2024-5153
9.1 CRITICAL

The Startklar Elementor Addons plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.7.15 via the 'dropzone_hash' parameter. This …

Jun 6, 2024
CVE-2024-5152
6.4 MEDIUM

The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_id’ parameter in all versions up to, and including, …

Jun 6, 2024
CVE-2024-5141
6.4 MEDIUM

The Rotating Tweets (Twitter widget and shortcode) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's' 'rotatingtweets' in all versions up to, …

Jun 6, 2024
CVE-2024-4707
6.4 MEDIUM

The Materialis Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's materialis_contact_form shortcode in all versions up to, and including, 1.3.41 …

Jun 6, 2024
CVE-2024-4608
6.4 MEDIUM

The SellKit – Funnel builder and checkout optimizer for WooCommerce to sell more, faster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the …

Jun 6, 2024
CVE-2024-4459
6.4 MEDIUM

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget's titles in all versions up to, and …

Jun 6, 2024
CVE-2024-4458
6.4 MEDIUM

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in several widgets via URL parameters in all versions up to, …

Jun 6, 2024
CVE-2024-4364
6.4 MEDIUM

The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's button widgets in all versions up to, and …

Jun 6, 2024
CVE-2024-4212
6.4 MEDIUM

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's TF Group Image, TF Nav Menu, TF Posts, …

Jun 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.