CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-23752
9.8 CRITICAL

GenerateSDFPipeline in synthetic_dataframe in PandasAI (aka pandas-ai) through 1.5.17 allows attackers to trigger the generation of arbitrary Python code that is executed by SDFCodeExecutor. An …

Jan 22, 2024
CVE-2024-23751
9.8 CRITICAL

LlamaIndex (aka llama_index) through 0.9.34 allows SQL injection via the Text-to-SQL feature in NLSQLTableQueryEngine, SQLTableRetrieverQueryEngine, NLSQLRetriever, RetrieverQueryEngine, and PGVectorSQLQueryEngine. For example, an attacker might be …

Jan 22, 2024
CVE-2024-23750
8.8 HIGH

MetaGPT through 0.6.4 allows the QaEngineer role to execute arbitrary code because RunCode.run_script() passes shell metacharacters to subprocess.Popen.

Jan 22, 2024
CVE-2024-0776
3.5 LOW

A vulnerability, which was classified as problematic, has been found in LinZhaoguan pb-cms 2.0. Affected by this issue is some unknown functionality of the component …

Jan 22, 2024
CVE-2024-0774
5.3 MEDIUM

A vulnerability was found in Any-Capture Any Sound Recorder 2.93. It has been declared as problematic. This vulnerability affects unknown code of the component Registration …

Jan 22, 2024
CVE-2024-0773
3.5 LOW

A vulnerability classified as problematic was found in CodeAstro Internet Banking System 1.0. Affected by this vulnerability is an unknown functionality of the file pages_client_signup.php. …

Jan 22, 2024
CVE-2024-0772
5.3 MEDIUM

A vulnerability was found in Nsasoft ShareAlarmPro 2.1.4 and classified as problematic. Affected by this issue is some unknown functionality of the component Registration Handler. …

Jan 22, 2024
CVE-2024-23744
7.5 HIGH

An issue was discovered in Mbed TLS 3.5.1. There is persistent handshake denial if a client sends a TLS 1.3 ClientHello without extensions.

Jan 21, 2024
CVE-2024-0771
5.3 MEDIUM

A vulnerability has been found in Nsasoft Product Key Explorer 4.0.9 and classified as problematic. Affected by this vulnerability is an unknown functionality of the …

Jan 21, 2024
CVE-2024-0770
4.4 MEDIUM

A vulnerability, which was classified as critical, was found in European Chemicals Agency IUCLID 7.10.3 on Windows. Affected is an unknown function of the file …

Jan 21, 2024
CVE-2023-52353
7.5 HIGH

An issue was discovered in Mbed TLS through 3.5.1. In mbedtls_ssl_session_reset, the maximum negotiable TLS version is mishandled. For example, if the last connection negotiated …

Jan 21, 2024
CVE-2024-23732
7.5 HIGH

The JSON loader in Embedchain before 0.1.57 allows a ReDoS (regular expression denial of service) via a long string to json.py.

Jan 21, 2024
CVE-2024-23731
9.8 CRITICAL

The OpenAPI loader in Embedchain before 0.1.57 allows attackers to execute arbitrary code, related to the openapi.py yaml.load function argument.

Jan 21, 2024
CVE-2024-23730
9.8 CRITICAL

The OpenAPI and ChatGPT plugin loaders in LlamaHub (aka llama-hub) before 0.0.67 allow attackers to execute arbitrary code because safe_load is not used for YAML.

Jan 21, 2024
CVE-2023-6531
7.0 HIGH

A use-after-free flaw was found in the Linux Kernel due to a race problem in the unix garbage collector's deletion of SKB races with unix_stream_read_generic() …

Jan 21, 2024
CVE-2024-0769
5.3 MEDIUM KEV

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DIR-859 1.06B01. It has been rated as critical. Affected by this issue is some …

Jan 21, 2024
CVE-2016-15037
2.4 LOW

A vulnerability, which was classified as problematic, has been found in go4rayyan Scumblr up to 2.0.1a. Affected by this issue is some unknown functionality of …

Jan 21, 2024
CVE-2024-23726
8.8 HIGH

Ubee DDW365 XCNDDW365 devices have predictable default WPA2 PSKs that could lead to unauthorized remote access. A remote attacker (in proximity to a Wi-Fi network) …

Jan 21, 2024
CVE-2024-23725
6.1 MEDIUM

Ghost before 5.76.0 allows XSS via a post excerpt in excerpt.js. An XSS payload can be rendered in post summaries.

Jan 21, 2024
CVE-2024-0521
7.8 HIGH

Code Injection in paddlepaddle/paddle

Jan 20, 2024
CVE-2023-7063
7.2 HIGH

The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission parameters in all versions up to, and including, 1.8.5.3 due …

Jan 20, 2024
CVE-2024-0679
6.5 MEDIUM

The ColorMag theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the plugin_action_callback() function in all versions up to, …

Jan 20, 2024
CVE-2024-0623
4.3 MEDIUM

The VK Block Patterns plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.31.1.1. This is due to …

Jan 20, 2024
CVE-2023-46447
4.3 MEDIUM

The POPS! Rebel application 5.0 for Android, in POPS! Rebel Bluetooth Glucose Monitoring System, sends unencrypted glucose measurements over BLE.

Jan 20, 2024
CVE-2023-51925
9.8 CRITICAL

An arbitrary file upload vulnerability in the nccloud.web.arcp.taskmonitor.action.ArcpUploadAction.doAction() method of YonBIP v3_23.05 allows attackers to execute arbitrary code via uploading a crafted file.

Jan 20, 2024
CVE-2023-51924
9.8 CRITICAL

An arbitrary file upload vulnerability in the uap.framework.rc.itf.IResourceManager interface of YonBIP v3_23.05 allows attackers to execute arbitrary code via uploading a crafted file.

Jan 20, 2024
CVE-2023-51906
9.8 CRITICAL

An issue in yonyou YonBIP v3_23.05 allows a remote attacker to execute arbitrary code via a crafted script to the ServiceDispatcherServlet uap.framework.rc.itf.IResourceManager component.

Jan 20, 2024
CVE-2023-47024
8.8 HIGH

Cross-Site Request Forgery (CSRF) in NCR Terminal Handler v.1.5.1 leads to a one-click account takeover. This is achieved by exploiting multiple vulnerabilities, including an undisclosed …

Jan 20, 2024
CVE-2023-51928
9.8 CRITICAL

An arbitrary file upload vulnerability in the nccloud.web.arcp.taskmonitor.action.ArcpUploadAction.doAction() method of YonBIP v3_23.05 allows attackers to execute arbitrary code via uploading a crafted file.

Jan 20, 2024
CVE-2023-51927
9.8 CRITICAL

YonBIP v3_23.05 was discovered to contain a SQL injection vulnerability via the com.yonyou.hrcloud.attend.web.AttendScriptController.runScript() method.

Jan 20, 2024
CVE-2023-51926
7.5 HIGH

YonBIP v3_23.05 was discovered to contain an arbitrary file read vulnerability via the nc.bs.framework.comn.serv.CommonServletDispatcher component.

Jan 20, 2024
CVE-2023-51892
9.8 CRITICAL

An issue in weaver e-cology v.10.0.2310.01 allows a remote attacker to execute arbitrary code via a crafted script to the FrameworkShellController component.

Jan 20, 2024
CVE-2021-31314
9.8 CRITICAL

File upload vulnerability in ejinshan v8+ terminal security system allows attackers to upload arbitrary files to arbitrary locations on the server.

Jan 20, 2024
CVE-2024-23332
4.0 MEDIUM

The Notary Project is a set of specifications and tools intended to provide a cross-industry standard for securing software supply chains by using authentic container …

Jan 19, 2024
CVE-2024-23688
5.3 MEDIUM

Consensys Discovery versions less than 0.4.5 uses the same AES/GCM nonce for the entire session. which should ideally be unique for every message. The node's …

Jan 19, 2024
CVE-2024-23687
9.1 CRITICAL

Hard-coded credentials in FOLIO mod-data-export-spring versions before 1.5.4 and from 2.0.0 to 2.0.2 allows unauthenticated users to access critical APIs, modify user data, modify configurations …

Jan 19, 2024
CVE-2024-23686
5.3 MEDIUM

DependencyCheck for Maven 9.0.0 to 9.0.6, for CLI version 9.0.0 to 9.0.5, and for Ant versions 9.0.0 to 9.0.5, when used in debug mode, allows …

Jan 19, 2024
CVE-2024-0739
7.3 HIGH

A vulnerability, which was classified as critical, was found in Hecheng Leadshop up to 1.4.20. Affected is an unknown function of the file /web/leadshop.php. The …

Jan 19, 2024
CVE-2024-0738
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in 个人开源 mldong 1.0. This issue affects the function ExpressionEngine of the file com/mldong/modules/wf/engine/model/DecisionModel.java. The …

Jan 19, 2024
CVE-2024-0737
5.3 MEDIUM

A vulnerability classified as problematic was found in Xlightftpd Xlight FTP Server 1.1. This vulnerability affects unknown code of the component Login. The manipulation of …

Jan 19, 2024
CVE-2024-23689
8.8 HIGH

Exposure of sensitive information in exceptions in ClichHouse's clickhouse-r2dbc, com.clickhouse:clickhouse-jdbc, and com.clickhouse:clickhouse-client versions less than 0.4.6 allows unauthorized users to gain access to client certificate …

Jan 19, 2024
CVE-2024-23685
5.3 MEDIUM

Hard-coded credentials in mod-remote-storage versions under 1.7.2 and from 2.0.0 to 2.0.3 allows unauthorized users to gain read access to mod-inventory-storage records including instances, holdings, …

Jan 19, 2024
CVE-2024-23684
7.5 HIGH

Inefficient algorithmic complexity in DecodeFromBytes function in com.upokecenter.cbor Java implementation of Concise Binary Object Representation (CBOR) versions 4.0.0 to 4.5.1 allows an attacker to cause …

Jan 19, 2024
CVE-2024-23683
8.2 HIGH

Artemis Java Test Sandbox versions less than 1.7.6 are vulnerable to a sandbox escape when an attacker crafts a special subclass of InvocationTargetException. An attacker …

Jan 19, 2024
CVE-2024-23682
8.2 HIGH

Artemis Java Test Sandbox versions before 1.8.0 are vulnerable to a sandbox escape when an attacker includes class files in a package that Ares trusts. …

Jan 19, 2024
CVE-2024-23681
8.2 HIGH

Artemis Java Test Sandbox versions before 1.11.2 are vulnerable to a sandbox escape when an attacker loads untrusted libraries using System.load or System.loadLibrary. An attacker …

Jan 19, 2024
CVE-2024-23680
5.3 MEDIUM

AWS Encryption SDK for Java versions 2.0.0 to 2.2.0 and less than 1.9.0 incorrectly validates some invalid ECDSA signatures.

Jan 19, 2024
CVE-2024-23679
9.8 CRITICAL

Enonic XP versions less than 7.7.4 are vulnerable to a session fixation issue. An remote and unauthenticated attacker can use prior sessions due to the …

Jan 19, 2024
CVE-2024-22421
7.6 HIGH

JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture. Users of JupyterLab who click on a malicious …

Jan 19, 2024
CVE-2024-22420
6.5 MEDIUM

JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture. This vulnerability depends on user interaction by opening …

Jan 19, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.