CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2020-35154

Rejected reason: CVE ID was once reserved, but never used.

Jun 5, 2024
CVE-2020-35153

Rejected reason: CVE ID was once reserved, but never used.

Jun 5, 2024
CVE-2020-27355

Rejected reason: CVE ID was once reserved, but never used.

Jun 5, 2024
CVE-2020-27354

Rejected reason: CVE ID was once reserved, but never used.

Jun 5, 2024
CVE-2020-27353

Rejected reason: CVE ID was once reserved, but never used.

Jun 4, 2024
CVE-2024-5635
6.3 MEDIUM

A vulnerability was found in itsourcecode Bakery Online Ordering System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Jun 4, 2024
CVE-2024-36675
9.1 CRITICAL

LyLme_spage v1.9.5 is vulnerable to Server-Side Request Forgery (SSRF) via the get_head function.

Jun 4, 2024
CVE-2024-36121
5.9 MEDIUM

netty-incubator-codec-ohttp is the OHTTP implementation for netty. BoringSSLAEADContext keeps track of how many OHTTP responses have been sent and uses this sequence number to calculate …

Jun 4, 2024
CVE-2024-30889
5.4 MEDIUM

Cross Site Scripting vulnerability in audimex audimexEE v.15.1.2 and fixed in 15.1.3.9 allows a remote attacker to execute arbitrary code via the service, method, widget_type, …

Jun 4, 2024
CVE-2022-28658
5.5 MEDIUM

Apport argument parsing mishandles filename splitting on older kernels resulting in argument spoofing

Jun 4, 2024
CVE-2022-28657
7.8 HIGH

Apport does not disable python crash handler before entering chroot

Jun 4, 2024
CVE-2022-28656
5.5 MEDIUM

is_closing_session() allows users to consume RAM in the Apport process

Jun 4, 2024
CVE-2022-28655
7.1 HIGH

is_closing_session() allows users to create arbitrary tcp dbus connections

Jun 4, 2024
CVE-2022-28654
5.5 MEDIUM

is_closing_session() allows users to fill up apport.log

Jun 4, 2024
CVE-2022-28652
5.5 MEDIUM

~/.config/apport/settings parsing is vulnerable to "billion laughs" attack

Jun 4, 2024
CVE-2024-4220
4.3 MEDIUM

Prior to 23.1, an information disclosure vulnerability exists within BeyondInsight which can allow an attacker to enumerate usernames.

Jun 4, 2024
CVE-2024-4219
4.8 MEDIUM

Prior to 23.2, it is possible to perform arbitrary Server-Side requests via HTTP-based connectors within BeyondInsight, resulting in a server-side request forgery vulnerability.

Jun 4, 2024
CVE-2024-34364
5.7 MEDIUM

Envoy is a cloud-native, open source edge and service proxy. Envoy exposed an out-of-memory (OOM) vector from the mirror response, since async HTTP client will …

Jun 4, 2024
CVE-2024-34363
7.5 HIGH

Envoy is a cloud-native, open source edge and service proxy. Due to how Envoy invoked the nlohmann JSON library, the library could throw an uncaught …

Jun 4, 2024
CVE-2024-34362
5.9 MEDIUM

Envoy is a cloud-native, open source edge and service proxy. There is a use-after-free in `HttpConnectionManager` (HCM) with `EnvoyQuicServerStream` that can crash Envoy. An attacker …

Jun 4, 2024
CVE-2024-32976
7.5 HIGH

Envoy is a cloud-native, open source edge and service proxy. Envoyproxy with a Brotli filter can get into an endless loop during decompression of Brotli …

Jun 4, 2024
CVE-2024-32975
5.9 MEDIUM

Envoy is a cloud-native, open source edge and service proxy. There is a crash at `QuicheDataReader::PeekVarInt62Length()`. It is caused by integer underflow in the `QuicStreamSequencerBuffer::PeekRegion()` …

Jun 4, 2024
CVE-2024-32974
5.9 MEDIUM

Envoy is a cloud-native, open source edge and service proxy. A crash was observed in `EnvoyQuicServerStream::OnInitialHeadersComplete()` with following call stack. It is a use-after-free caused …

Jun 4, 2024
CVE-2024-23326
5.9 MEDIUM

Envoy is a cloud-native, open source edge and service proxy. A theoretical request smuggling vulnerability exists through Envoy if a server can be tricked into …

Jun 4, 2024
CVE-2024-4520
7.5 HIGH

An improper access control vulnerability exists in the gaizhenbiao/chuanhuchatgpt application, specifically in version 20240410. This vulnerability allows any user on the server to access the …

Jun 4, 2024
CVE-2024-32464
6.1 MEDIUM

Action Text brings rich text content and editing to Rails. Instances of ActionText::Attachable::ContentAttachment included within a rich_text_area tag could potentially contain unsanitized HTML. This vulnerability …

Jun 4, 2024
CVE-2024-30528
5.4 MEDIUM

Missing Authorization vulnerability in Spiffy Plugins Spiffy Calendar.This issue affects Spiffy Calendar: from n/a through 4.9.10.

Jun 4, 2024
CVE-2024-30525
5.3 MEDIUM

Missing Authorization vulnerability in moveaddons Move Addons for Elementor.This issue affects Move Addons for Elementor: from n/a through 1.2.9.

Jun 4, 2024
CVE-2024-28103
5.4 MEDIUM

Action Pack is a framework for handling and responding to web requests. Since 6.1.0, the application configurable Permissions-Policy is only served on responses with an …

Jun 4, 2024
CVE-2024-37273
9.8 CRITICAL

An arbitrary file upload vulnerability in the /v1/app/appendFileSync interface of Jan v0.4.12 allows attackers to execute arbitrary code via uploading a crafted file.

Jun 4, 2024
CVE-2024-36858
9.8 CRITICAL

An arbitrary file upload vulnerability in the /v1/app/writeFileSync interface of Jan v0.4.12 allows attackers to execute arbitrary code via uploading a crafted file.

Jun 4, 2024
CVE-2024-36857
7.5 HIGH

Jan v0.4.12 was discovered to contain an arbitrary file read vulnerability via the /v1/app/readFileSync interface.

Jun 4, 2024
CVE-2024-36604
9.8 CRITICAL

Tenda O3V2 v1.0.0.12(3880) was discovered to contain a Blind Command Injection via stpEn parameter in the SetStp function. This vulnerability allows attackers to execute arbitrary …

Jun 4, 2024
CVE-2024-35672
7.5 HIGH

Missing Authorization vulnerability in Netgsm.This issue affects Netgsm: from n/a through 2.9.19.

Jun 4, 2024
CVE-2024-35670
5.3 MEDIUM

Broken Authentication vulnerability in SoftLab Integrate Google Drive.This issue affects Integrate Google Drive: from n/a through 1.3.93.

Jun 4, 2024
CVE-2024-34759
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in VideoWhisper Picture Gallery allows Stored XSS.This issue affects Picture Gallery: from …

Jun 4, 2024
CVE-2024-30484
4.3 MEDIUM

Missing Authorization vulnerability in RT Easy Builder – Advanced addons for Elementor.This issue affects RT Easy Builder – Advanced addons for Elementor: from n/a through …

Jun 4, 2024
CVE-2024-29152
5.9 MEDIUM

An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, Exynos 990, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos …

Jun 4, 2024
CVE-2024-25095
7.5 HIGH

Insertion of Sensitive Information into Log File vulnerability in Code Parrots Easy Forms for Mailchimp.This issue affects Easy Forms for Mailchimp: from n/a through 6.9.0.

Jun 4, 2024
CVE-2024-36550
8.8 HIGH

idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/vpsCompany_deal.php?mudi=add&nohrefStr=close

Jun 4, 2024
CVE-2024-36549
8.8 HIGH

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/vpsCompany_deal.php?mudi=rev&nohrefStr=close

Jun 4, 2024
CVE-2024-36548
8.8 HIGH

idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/vpsCompany_deal.php?mudi=del

Jun 4, 2024
CVE-2024-36547
8.8 HIGH

idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/vpsClass_deal.php?mudi=add

Jun 4, 2024
CVE-2024-36400
9.4 CRITICAL

nano-id is a unique string ID generator for Rust. Affected versions of the nano-id crate incorrectly generated IDs using a reduced character set in the …

Jun 4, 2024
CVE-2024-35653
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visual Composer Visual Composer Website Builder visualcomposer.This issue affects Visual Composer Website Builder: …

Jun 4, 2024
CVE-2024-35652
7.1 HIGH

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Saso Nikolov Event Tickets with Ticket Scanner allows Reflected XSS.This issue …

Jun 4, 2024
CVE-2024-35651
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Spiffy Plugins WP Flow Plus allows Stored XSS.This issue affects WP …

Jun 4, 2024
CVE-2024-35649
6.5 MEDIUM

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Pdfcrowd Save as PDF plugin by Pdfcrowd allows Stored XSS.This issue …

Jun 4, 2024
CVE-2024-32871
7.5 HIGH

Pimcore is an Open Source Data & Experience Management Platform. The Pimcore thumbnail generation can be used to flood the server with large files. By …

Jun 4, 2024
CVE-2024-29004
7.1 HIGH

The SolarWinds Platform was determined to be affected by a stored cross-site scripting vulnerability affecting the web console. A high-privileged user and user interaction is …

Jun 4, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.