CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-35236
4.8 MEDIUM

Audiobookshelf is a self-hosted audiobook and podcast server. Prior to version 2.10.0, opening an ebook with malicious scripts inside leads to code execution inside the …

May 27, 2024
CVE-2024-35231
8.6 HIGH

rack-contrib provides contributed rack middleware and utilities for Rack, a Ruby web server interface. Versions of rack-contrib prior to 2.5.0 are vulnerable to denial of …

May 27, 2024
CVE-2024-35229
5.3 MEDIUM

ZKsync Era is a layer 2 rollup that uses zero-knowledge proofs to scale Ethereum. Prior to version 1.3.10, there is a very specific pattern `f(a(),b()); …

May 27, 2024
CVE-2022-4969
5.3 MEDIUM

A vulnerability, which was classified as critical, has been found in bwoodsend rockhopper up to 0.1.2. Affected by this issue is the function count_rows of …

May 27, 2024
CVE-2024-35219
8.3 HIGH

OpenAPI Generator allows generation of API client libraries (SDK generation), server stubs, documentation and configuration automatically given an OpenAPI Spec. Prior to version 7.6.0, attackers …

May 27, 2024
CVE-2024-32978
6.6 MEDIUM

Kaminari is a paginator for web app frameworks and object relational mappings. A security vulnerability involving insecure file permissions has been identified in the Kaminari …

May 27, 2024
CVE-2024-0851

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Grup Arge Energy and Control Systems Smartpower allows SQL Injection.This issue …

May 27, 2024
CVE-2024-34477
7.8 HIGH

configureNFS in lib/common/functions.sh in FOG through 1.5.10 allows local users to gain privileges by mounting a crafted NFS share (because of no_root_squash and insecure). In …

May 27, 2024
CVE-2023-50977

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not …

May 27, 2024
CVE-2024-5409
7.1 HIGH

RhinOS 3.0-1190 is vulnerable to an XSS via the "tamper" parameter in /admin/lib/phpthumb/phpthumb.php. An attacker could create a malicious URL and send it to a …

May 27, 2024
CVE-2024-5408
7.1 HIGH

Vulnerability in RhinOS 3.0-1190 consisting of an XSS through the "search" parameter of /portal/search.htm. This vulnerability could allow a remote attacker to steal details of …

May 27, 2024
CVE-2024-5407
10.0 CRITICAL

A vulnerability in RhinOS 3.0-1190 could allow PHP code injection through the "search" parameter in /portal/search.htm. This vulnerability could allow a remote attacker to perform …

May 27, 2024
CVE-2024-3381

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

May 27, 2024
CVE-2024-5406
6.3 MEDIUM

A vulnerability had been discovered in WinNMP 19.02 consisting of an XSS attack via index page in from, subject, text and hash parameters. This vulnerability …

May 27, 2024
CVE-2024-5405
6.3 MEDIUM

A vulnerability had been discovered in WinNMP 19.02 consisting of an XSS attack via /tools/redis.php page in the k, hash, key and p parameters. This …

May 27, 2024
CVE-2023-6349
7.5 HIGH

A heap overflow vulnerability exists in libvpx - Encoding a frame that has larger dimensions than the originally configured size with VP9 may result in …

May 27, 2024
CVE-2024-36383
5.3 MEDIUM

An issue was discovered in Logpoint SAML Authentication before 6.0.3. An attacker can place a crafted filename in the state field of a SAML SSO-URL …

May 27, 2024
CVE-2024-5035

The affected device expose a network service called "rftest" that is vulnerable to unauthenticated command injection on ports TCP/8888, TCP/8889, and TCP/8890. By successfully exploiting …

May 27, 2024
CVE-2024-5403
7.2 HIGH

ASKEY 5G NR Small Cell fails to properly filter user input for certain functionality, allowing remote attackers with administrator privilege to execute arbitrary system commands …

May 27, 2024
CVE-2024-27314
2.4 LOW

Zoho ManageEngine ServiceDesk Plus versions below 14730, ServiceDesk Plus MSP below 14720 and SupportCenter Plus below 14720 are vulnerable to stored XSS in the Custom …

May 27, 2024
CVE-2024-26289
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in PMB Services PMB allows Remote Code Inclusion.This issue affects PMB: from 7.5.1 before 7.5.6-2, from 7.4.1 before 7.4.9, from …

May 27, 2024
CVE-2024-5400
8.8 HIGH

Openfind Mail2000 does not properly filter parameters of specific CGI. Remote attackers with regular privileges can exploit this vulnerability to execute arbitrary system commands on …

May 27, 2024
CVE-2024-4535
8.8 HIGH

The KKProgressbar2 Free WordPress plugin through 1.1.4.2 does not have CSRF checks in some places, which could allow attackers to make logged in users perform …

May 27, 2024
CVE-2024-4534
6.1 MEDIUM

The KKProgressbar2 Free WordPress plugin through 1.1.4.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could …

May 27, 2024
CVE-2024-4533
6.5 MEDIUM

The KKProgressbar2 Free WordPress plugin through 1.1.4.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admin users to …

May 27, 2024
CVE-2024-4532
6.4 MEDIUM

The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform …

May 27, 2024
CVE-2024-4531
7.1 HIGH

The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform …

May 27, 2024
CVE-2024-4530
6.3 MEDIUM

The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform …

May 27, 2024
CVE-2024-4529
5.0 MEDIUM

The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform …

May 27, 2024
CVE-2024-3939
5.4 MEDIUM

The Ditty WordPress plugin before 3.1.36 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to …

May 27, 2024
CVE-2024-3933
5.3 MEDIUM

In Eclipse OpenJ9 release versions prior to 0.44.0 and after 0.13.0, when running with JVM option -Xgc:concurrentScavenge, the sequence generated for System.arrayCopy on the IBM …

May 27, 2024
CVE-2024-35297
4.7 MEDIUM

Cross-site scripting vulnerability exists in WP Booking versions prior to 2.4.5. If this vulnerability is exploited, an arbitrary script may be executed on the web …

May 27, 2024
CVE-2024-35291
6.1 MEDIUM

Cross-site scripting vulnerability exists in Splunk Config Explorer versions prior to 1.7.16. If this vulnerability is exploited, an arbitrary script may be executed on the …

May 27, 2024
CVE-2024-5399
7.2 HIGH

Openfind Mail2000 does not properly filter parameters of specific API. Remote attackers with administrative privileges can exploit this vulnerability to execute arbitrary system commands on …

May 27, 2024
CVE-2024-36384
6.1 MEDIUM

Pointsharp Cryptshare Server before 7.0.0 has an XSS issue that is related to notification messages.

May 27, 2024
CVE-2024-5397
6.3 MEDIUM

A vulnerability classified as critical was found in itsourcecode Online Student Enrollment System 1.0. Affected by this vulnerability is an unknown functionality of the file …

May 27, 2024
CVE-2024-5396
6.3 MEDIUM

A vulnerability classified as critical has been found in itsourcecode Online Student Enrollment System 1.0. Affected is an unknown function of the file newfaculty.php. The …

May 27, 2024
CVE-2024-5395
6.3 MEDIUM

A vulnerability was found in itsourcecode Online Student Enrollment System 1.0. It has been rated as critical. This issue affects some unknown processing of the …

May 27, 2024
CVE-2024-5394
6.3 MEDIUM

A vulnerability was found in itsourcecode Online Student Enrollment System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file …

May 27, 2024
CVE-2024-5393
6.3 MEDIUM

A vulnerability was found in itsourcecode Online Student Enrollment System 1.0. It has been classified as critical. This affects an unknown part of the file …

May 27, 2024
CVE-2024-5392
6.3 MEDIUM

A vulnerability was found in itsourcecode Online Student Enrollment System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

May 27, 2024
CVE-2024-5391
6.3 MEDIUM

A vulnerability has been found in itsourcecode Online Student Enrollment System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of …

May 27, 2024
CVE-2024-5390
6.3 MEDIUM

A vulnerability, which was classified as critical, was found in itsourcecode Online Student Enrollment System 1.0. Affected is an unknown function of the file listofstudent.php. …

May 27, 2024
CVE-2024-5385
2.4 LOW

A vulnerability, which was classified as problematic, has been found in oretnom23 Online Car Wash Booking System 1.0. This issue affects some unknown processing of …

May 27, 2024
CVE-2024-5384
7.3 HIGH

A vulnerability classified as critical was found in SourceCodester Facebook News Feed Like 1.0. This vulnerability affects unknown code of the file index.php. The manipulation …

May 27, 2024
CVE-2024-30658

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not …

May 27, 2024
CVE-2024-30657

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not …

May 27, 2024
CVE-2024-5383
3.5 LOW

A vulnerability classified as problematic has been found in lakernote EasyAdmin up to 20240324. This affects an unknown part of the file /sys/file/upload. The manipulation …

May 26, 2024
CVE-2024-5381
6.3 MEDIUM

A vulnerability classified as critical was found in itsourcecode Student Information Management System 1.0. Affected by this vulnerability is an unknown functionality of the file …

May 26, 2024
CVE-2024-5380
3.5 LOW

A vulnerability classified as problematic has been found in jsy-1 short-url 1.0.0. Affected is an unknown function of the file admin.php. The manipulation of the …

May 26, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.