CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-1961
8.8 HIGH

vertaai/modeldb is vulnerable to a path traversal attack due to improper sanitization of user-supplied file paths in its file upload functionality. Attackers can exploit this …

Apr 16, 2024
CVE-2024-1739
9.1 CRITICAL

lunary-ai/lunary is vulnerable to an authentication issue due to improper validation of email addresses during the signup process. Specifically, the server fails to treat email …

Apr 16, 2024
CVE-2024-1738
7.5 HIGH

An incorrect authorization vulnerability exists in the lunary-ai/lunary repository, specifically within the evaluations.get route in the evaluations API endpoint. This vulnerability allows unauthorized users to …

Apr 16, 2024
CVE-2024-1666
5.3 MEDIUM

In lunary-ai/lunary version 1.0.0, an authorization flaw exists that allows unauthorized radar creation. The vulnerability stems from the lack of server-side checks to verify if …

Apr 16, 2024
CVE-2024-1665

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Apr 16, 2024
CVE-2024-1646
8.2 HIGH

parisneo/lollms-webui is vulnerable to authentication bypass due to insufficient protection over sensitive endpoints. The application checks if the host parameter is not '0.0.0.0' to restrict …

Apr 16, 2024
CVE-2024-1626
8.1 HIGH

An Insecure Direct Object Reference (IDOR) vulnerability exists in the lunary-ai/lunary repository, version 0.3.0, within the project update endpoint. The vulnerability allows authenticated users to …

Apr 16, 2024
CVE-2024-1601
9.8 CRITICAL

An SQL injection vulnerability exists in the `delete_discussion()` function of the parisneo/lollms-webui application, allowing an attacker to delete all discussions and message data. The vulnerability …

Apr 16, 2024
CVE-2024-1594
7.5 HIGH

A path traversal vulnerability exists in the mlflow/mlflow repository, specifically within the handling of the `artifact_location` parameter when creating an experiment. Attackers can exploit this …

Apr 16, 2024
CVE-2024-1593
7.5 HIGH

A path traversal vulnerability exists in the mlflow/mlflow repository due to improper handling of URL parameters. By smuggling path traversal sequences using the ';' character …

Apr 16, 2024
CVE-2024-1569
7.5 HIGH

parisneo/lollms-webui is vulnerable to a denial of service (DoS) attack due to uncontrolled resource consumption. Attackers can exploit the `/open_code_in_vs_code` and similar endpoints without authentication …

Apr 16, 2024
CVE-2024-1561
7.5 HIGH

An issue was discovered in gradio-app/gradio, where the `/component_server` endpoint improperly allows the invocation of any method on a `Component` class with attacker-controlled arguments. Specifically, …

Apr 16, 2024
CVE-2024-1560
8.1 HIGH

A path traversal vulnerability exists in the mlflow/mlflow repository, specifically within the artifact deletion functionality. Attackers can bypass path validation by exploiting the double decoding …

Apr 16, 2024
CVE-2024-1558
7.5 HIGH

A path traversal vulnerability exists in the `_create_model_version()` function within `server/handlers.py` of the mlflow/mlflow repository, due to improper validation of the `source` parameter. Attackers can …

Apr 16, 2024
CVE-2024-1483
7.5 HIGH

A path traversal vulnerability exists in mlflow/mlflow version 2.9.2, allowing attackers to access arbitrary files on the server. By crafting a series of HTTP POST …

Apr 16, 2024
CVE-2024-1456
7.1 HIGH

An S3 bucket takeover vulnerability was identified in the h2oai/h2o-3 repository. The issue involves the S3 bucket 'http://s3.amazonaws.com/h2o-training', which was found to be vulnerable to …

Apr 16, 2024
CVE-2024-1183
6.5 MEDIUM

An SSRF (Server-Side Request Forgery) vulnerability exists in the gradio-app/gradio repository, allowing attackers to scan and identify open ports within an internal network. By manipulating …

Apr 16, 2024
CVE-2024-1135
7.5 HIGH

Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security …

Apr 16, 2024
CVE-2024-0549
8.1 HIGH

mintplex-labs/anything-llm is vulnerable to a relative path traversal attack, allowing unauthorized attackers with a default role account to delete files and folders within the filesystem, …

Apr 16, 2024
CVE-2024-0404
9.1 CRITICAL

A mass assignment vulnerability exists in the `/api/invite/:code` endpoint of the mintplex-labs/anything-llm repository, allowing unauthorized creation of high-privileged accounts. By intercepting and modifying the HTTP …

Apr 16, 2024
CVE-2024-27794
6.1 MEDIUM

Claris FileMaker Server before version 20.3.2 was susceptible to a reflected Cross-Site Scripting vulnerability due to an improperly handled parameter in the FileMaker WebDirect login …

Apr 15, 2024
CVE-2023-33806
7.8 HIGH

Insecure default configurations in Hikvision Interactive Tablet DS-D5B86RB/B V2.3.0 build220119, allows attackers to execute arbitrary commands.

Apr 15, 2024
CVE-2020-22540
5.4 MEDIUM

Stored Cross-Site Scripting (XSS) vulnerability in Codoforum v4.9, allows attackers to execute arbitrary code and obtain sensitive information via crafted payload to Category name component.

Apr 15, 2024
CVE-2024-3493
8.6 HIGH

A specific malformed fragmented packet type (fragmented packets may be generated automatically by devices that send large amounts of data) can cause a major nonrecoverable …

Apr 15, 2024
CVE-2024-31651
6.1 MEDIUM

A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload …

Apr 15, 2024
CVE-2024-30656
7.5 HIGH

An issue in Fireboltt Dream Wristphone BSW202_FB_AAC_v2.0_20240110-20240110-1956 allows attackers to cause a Denial of Service (DoS) via a crafted deauth frame.

Apr 15, 2024
CVE-2024-2424
7.5 HIGH

An input validation vulnerability exists in the Rockwell Automation 5015-AENFTXT that causes the secondary adapter to result in a major nonrecoverable fault (MNRF) when malicious …

Apr 15, 2024
CVE-2020-22539
7.2 HIGH

An arbitrary file upload vulnerability in the Add Category function of Codoforum v4.9 allows attackers to execute arbitrary code via uploading a crafted file.

Apr 15, 2024
CVE-2024-31652
6.1 MEDIUM

A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload …

Apr 15, 2024
CVE-2024-31650
9.6 CRITICAL

A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload …

Apr 15, 2024
CVE-2024-31649
5.4 MEDIUM

A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload …

Apr 15, 2024
CVE-2024-31648
6.1 MEDIUM

Cross Site Scripting (XSS) in Insurance Management System v1.0, allows remote attackers to execute arbitrary web scripts or HTML via a crafted payload injected into …

Apr 15, 2024
CVE-2024-23561
4.3 MEDIUM

HCL DevOps Deploy / HCL Launch is vulnerable to sensitive information disclosure vulnerability due to insufficient obfuscation of sensitive values.

Apr 15, 2024
CVE-2024-23558
6.3 MEDIUM

HCL DevOps Deploy / HCL Launch does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.

Apr 15, 2024
CVE-2024-3804
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Vesystem Cloud Desktop up to 20240408. This issue affects some unknown processing of the …

Apr 15, 2024
CVE-2024-32036
5.3 MEDIUM

ImageSharp is a 2D graphics API. A data leakage flaw was found in ImageSharp's JPEG and TGA decoders. This vulnerability is triggered when an attacker …

Apr 15, 2024
CVE-2024-32035
5.3 MEDIUM

ImageSharp is a 2D graphics API. A vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory …

Apr 15, 2024
CVE-2024-31990
4.8 MEDIUM

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. The API server does not enforce project sourceNamespaces which allows attackers to use the …

Apr 15, 2024
CVE-2024-31497
5.9 MEDIUM

In PuTTY 0.68 through 0.80 before 0.81, biased ECDSA nonce generation allows an attacker to recover a user's NIST P-521 secret key via a quick …

Apr 15, 2024
CVE-2024-30840
6.5 MEDIUM

A Stack Overflow vulnerability in Tenda AC15 v15.03.05.18 allows attackers to cause a denial of service via the LISTEN parameter in the fromDhcpListClient function.

Apr 15, 2024
CVE-2024-23560
4.4 MEDIUM

HCL DevOps Deploy / HCL Launch could be vulnerable to incomplete revocation of permissions when deleting a custom security resource type.

Apr 15, 2024
CVE-2023-45503
5.3 MEDIUM

SQL Injection vulnerability in Macrob7 Macs CMS 1.1.4f, allows remote attackers to execute arbitrary code, cause a denial of service (DoS), escalate privileges, and obtain …

Apr 15, 2024
CVE-2024-3803
6.3 MEDIUM

A vulnerability classified as critical was found in Vesystem Cloud Desktop up to 20240408. This vulnerability affects unknown code of the file /Public/webuploader/0.1.5/server/fileupload.php. The manipulation …

Apr 15, 2024
CVE-2024-28558
8.8 HIGH

SQL Injection vulnerability in sourcecodester Petrol pump management software v1.0, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via crafted …

Apr 15, 2024
CVE-2024-28557
9.8 CRITICAL

SQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via crafted …

Apr 15, 2024
CVE-2024-28556
9.8 CRITICAL

SQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via crafted …

Apr 15, 2024
CVE-2024-24487
6.8 MEDIUM

An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to cause a denial of service via crafted UDP packets using the …

Apr 15, 2024
CVE-2024-24486
9.1 CRITICAL

An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to edit device settings via the SAVE EEP_DATA command.

Apr 15, 2024
CVE-2024-24485
7.5 HIGH

An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to obtain sensitive information via the GET EEP_DATA command.

Apr 15, 2024
CVE-2024-31219
4.3 MEDIUM

Discourse-reactions is a plugin that allows user to add their reactions to the post. When whispers are enabled on a site via `whispers_allowed_groups` and reactions …

Apr 15, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.