CVE Database

38976+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-39689
7.5 HIGH

Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi starting in …

Jul 5, 2024
CVE-2024-39023
8.8 HIGH

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via admin/info_deal.php?mudi=add&nohrefStr=close

Jul 5, 2024
CVE-2024-39022
8.8 HIGH

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/infoSys_deal.php?mudi=deal

Jul 5, 2024
CVE-2024-34361
8.5 HIGH

Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. A vulnerability in versions prior to 5.18.3 allows an …

Jul 5, 2024
CVE-2024-39687
7.2 HIGH

Fedify is a TypeScript library for building federated server apps powered by ActivityPub and other standards. At present, when Fedify needs to retrieve an object …

Jul 5, 2024
CVE-2024-39321
7.5 HIGH

Traefik is an HTTP reverse proxy and load balancer. Versions prior to 2.11.6, 3.0.4, and 3.1.0-rc3 have a vulnerability that allows bypassing IP allow-lists via …

Jul 5, 2024
CVE-2024-37903
8.2 HIGH

Mastodon is a self-hosted, federated microblogging platform. Starting in version 2.6.0 and prior to versions 4.1.18 and 4.2.10, by crafting specific activities, an attacker can …

Jul 5, 2024
CVE-2024-37767
7.5 HIGH

Insecure permissions in the component /api/admin/user of 14Finger v1.1 allows attackers to access all user information via a crafted GET request.

Jul 5, 2024
CVE-2024-27715
8.2 HIGH

An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via a crafted request to the …

Jul 5, 2024
CVE-2024-27713
8.8 HIGH

An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via the HTTP Response Header Settings …

Jul 5, 2024
CVE-2024-27711
8.8 HIGH

An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via the Sin-up process function in …

Jul 5, 2024
CVE-2024-39210
7.5 HIGH

Best House Rental Management System v1.0 was discovered to contain an arbitrary file read vulnerability via the Page parameter at index.php. This vulnerability allows attackers …

Jul 5, 2024
CVE-2024-37769
8.8 HIGH

Insecure permissions in 14Finger v1.1 allow attackers to escalate privileges from normal user to Administrator via a crafted POST request.

Jul 5, 2024
CVE-2024-39027
7.5 HIGH

SeaCMS v12.9 has an unauthorized SQL injection vulnerability. The vulnerability is caused by the SQL injection through the cid parameter at /js/player/dmplayer/dmku/index.php?ac=edit, which can cause …

Jul 5, 2024
CVE-2024-39480
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: kdb: Fix buffer overflow during tab-complete Currently, when the user attempts symbol completion with the …

Jul 5, 2024
CVE-2024-39479
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/i915/hwmon: Get rid of devm When both hwmon and hwmon drvdata (on which hwmon depends) …

Jul 5, 2024
CVE-2024-36041
7.8 HIGH

KSmserver in KDE Plasma Workspace (aka plasma-workspace) before 5.27.11.1 and 6.x before 6.0.5.1 allows connections via ICE based purely on the host, i.e., all local …

Jul 5, 2024
CVE-2023-52340
7.5 HIGH

The IPv6 implementation in the Linux kernel before 6.3 has a net/ipv6/route.c max_size threshold that can be consumed easily, e.g., leading to a denial of …

Jul 5, 2024
CVE-2024-39937
8.6 HIGH

supOS 5.0 allows api/image/download?fileName=../ directory traversal for reading files.

Jul 4, 2024
CVE-2024-39936
8.6 HIGH

An issue was discovered in HTTP2 in Qt before 5.15.18, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.7, and 6.6.x through 6.7.x before 6.7.3. Code …

Jul 4, 2024
CVE-2024-39935
8.8 HIGH

jc21 NGINX Proxy Manager before 2.11.3 allows backend/internal/certificate.js OS command injection by an authenticated user (with certificate management privileges) via untrusted input to the DNS …

Jul 4, 2024
CVE-2024-39934
7.8 HIGH

Robotmk before 2.0.1 allows a local user to escalate privileges (e.g., to SYSTEM) if automated Python environment setup is enabled, because the "shared holotree usage" …

Jul 4, 2024
CVE-2024-37472
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WofficeIO Woffice woffice.This issue affects Woffice: from n/a through <= 5.4.8.

Jul 4, 2024
CVE-2024-37471
7.1 HIGH

Cross Site Scripting (XSS) vulnerability in WofficeIO Woffice Core allows Reflected XSS.This issue affects Woffice Core: from n/a through 5.4.8.

Jul 4, 2024
CVE-2024-39933
7.7 HIGH

Gogs through 0.13.0 allows argument injection during the tagging of a new release.

Jul 4, 2024
CVE-2024-6506
8.2 HIGH

Information exposure vulnerability in the MRW plugin, in its 5.4.3 version, affecting the "mrw_log" functionality. This vulnerability could allow a remote attacker to obtain other …

Jul 4, 2024
CVE-2024-6507
8.1 HIGH

Command injection when ingesting a remote Kaggle dataset due to a lack of input sanitization in the ingest_kaggle() API

Jul 4, 2024
CVE-2024-5943
8.8 HIGH

The Nested Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.7. This is due to missing …

Jul 4, 2024
CVE-2024-6319
8.8 HIGH

The IMGspider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload' function in all versions up …

Jul 4, 2024
CVE-2024-6318
8.8 HIGH

The IMGspider plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload_img_file' function in all versions up …

Jul 4, 2024
CVE-2024-3904
8.8 HIGH

Incorrect Default Permissions vulnerability in Smart Device Communication Gateway preinstalled on MELIPC Series MI5122-VW firmware versions "05" to "07" allows a local attacker to execute …

Jul 4, 2024
CVE-2024-1182
7.0 HIGH

Uncontrolled Search Path Element vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.3 and prior, Mitsubishi Electric Hyper Historian …

Jul 4, 2024
CVE-2024-2385
8.8 HIGH

The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.4 via several of …

Jul 4, 2024
CVE-2024-38345
8.1 HIGH

A cross-site request forgery vulnerability exists in Sola Testimonials versions prior to 3.0.0. If this vulnerability is exploited, an attacker allows a user who logs …

Jul 4, 2024
CVE-2024-6284
7.3 HIGH

In https://github.com/google/nftables IP addresses were encoded in the wrong byte order, resulting in an nftables configuration which does not work as intended (might block or …

Jul 3, 2024
CVE-2024-34750
7.5 HIGH

Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When processing an HTTP/2 stream, Tomcat did not handle some cases of excessive …

Jul 3, 2024
CVE-2024-33871
8.8 HIGH

An issue was discovered in Artifex Ghostscript before 10.03.1. contrib/opvp/gdevopvp.c allows arbitrary code execution via a custom Driver library, exploitable via a crafted PostScript document. …

Jul 3, 2024
CVE-2024-29511
7.5 HIGH

Artifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a directory traversal issue that allows arbitrary file reading (and writing of error messages …

Jul 3, 2024
CVE-2024-35227
7.5 HIGH

Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta3 on the `tests-passed` branch, Oneboxing against a carefully …

Jul 3, 2024
CVE-2024-29509
8.8 HIGH

Artifex Ghostscript before 10.03.0 has a heap-based overflow when PDFPassword (e.g., for runpdf) has a \000 byte in the middle.

Jul 3, 2024
CVE-2024-29506
8.8 HIGH

Artifex Ghostscript before 10.03.0 has a stack-based buffer overflow in the pdfi_apply_filter() function via a long PDF filter name.

Jul 3, 2024
CVE-2023-52169
8.2 HIGH

The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains an out-of-bounds read that allows an attacker to read beyond the intended buffer. The …

Jul 3, 2024
CVE-2023-52168
8.4 HIGH

The NtfsHandler.cpp NTFS handler in 7-Zip before 24.01 (for 7zz) contains a heap-based buffer overflow that allows an attacker to overwrite two bytes at multiple …

Jul 3, 2024
CVE-2024-32937
8.1 HIGH

An os command injection vulnerability exists in the CWMP SelfDefinedTimeZone functionality of Grandstream GXP2135 1.0.9.129, 1.0.11.74 and 1.0.11.79. A specially crafted network packet can lead …

Jul 3, 2024
CVE-2024-5672
7.2 HIGH

A high privileged remote attacker can execute arbitrary system commands via GET requests due to improper neutralization of special elements used in an OS command.

Jul 3, 2024
CVE-2024-6427
7.5 HIGH

Uncontrolled Resource Consumption vulnerability in MESbook 20221021.03 version. An unauthenticated remote attacker can use the "message" parameter to inject a payload with dangerous JavaScript code, …

Jul 3, 2024
CVE-2024-6426
8.1 HIGH

Information exposure vulnerability in MESbook 20221021.03 version, the exploitation of which could allow a local attacker, with user privileges, to access different resources by changing …

Jul 3, 2024
CVE-2024-39830
8.1 HIGH

Mattermost versions 9.8.x <= 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5, when shared channels are enabled, fail to use constant time …

Jul 3, 2024
CVE-2024-38453
7.5 HIGH

The Avalara for Salesforce CPQ app before 7.0 for Salesforce allows attackers to read an API key. NOTE: the current version is 11 as of …

Jul 3, 2024
CVE-2024-2376
8.8 HIGH

The WPQA Builder WordPress plugin before 6.1.1 does not have CSRF checks in some places, which could allow attackers to make logged in users perform …

Jul 3, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.