CVE Database

38976+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-37905
8.8 HIGH

authentik is an open-source Identity Provider that emphasizes flexibility and versatility. Authentik API-Access-Token mechanism can be exploited to gain admin user privileges. A successful exploit …

Jun 28, 2024
CVE-2024-31912
7.5 HIGH

IBM MQ 9.3 LTS and 9.3 CD could allow an authenticated user to escalate their privileges under certain configurations due to incorrect privilege assignment. IBM …

Jun 28, 2024
CVE-2024-38521
8.8 HIGH

Hush Line is a free and open-source, anonymous-tip-line-as-a-service for organizations or individuals. There is a stored XSS in the Inbox. The input is displayed using …

Jun 28, 2024
CVE-2024-5736
7.5 HIGH

Server Side Request Forgery (SSRF) vulnerability in AdmirorFrames Joomla! extension in afGdStream.php script allows to access local files or server pages available only from localhost. …

Jun 28, 2024
CVE-2024-5735
7.5 HIGH

Full Path Disclosure vulnerability in AdmirorFrames Joomla! extension in afHelper.php script allows an unauthorised attacker to retrieve location of web root folder. This issue affects …

Jun 28, 2024
CVE-2024-39350
7.5 HIGH

A vulnerability regarding authentication bypass by spoofing is found in the RTSP functionality. This allows man-in-the-middle attackers to obtain privileges without consent via unspecified vectors. …

Jun 28, 2024
CVE-2024-39348
7.5 HIGH

Download of code without integrity check vulnerability in AirPrint functionality in Synology Router Manager (SRM) before 1.2.5-8227-11 and 1.3.1-9346-8 allows man-in-the-middle attackers to execute arbitrary …

Jun 28, 2024
CVE-2024-39351
7.2 HIGH

A vulnerability regarding improper neutralization of special elements used in an OS command ('OS Command Injection') is found in the NTP configuration. This allows remote …

Jun 28, 2024
CVE-2023-47802
7.2 HIGH

A vulnerability regarding improper neutralization of special elements used in an OS command ('OS Command Injection') is found in the IP block functionality. This allows …

Jun 28, 2024
CVE-2024-37282
8.1 HIGH

It was identified that under certain specific preconditions, an API key that was originally created with a specific privileges could be subsequently used to create …

Jun 28, 2024
CVE-2024-39708
7.0 HIGH

An issue was discovered in the Agent in Delinea Privilege Manager (formerly Thycotic Privilege Manager) before 12.0.1096 on Windows. Sometimes, a non-administrator user can copy …

Jun 28, 2024
CVE-2016-20022
8.4 HIGH

In the Linux kernel before 4.8, usb_parse_endpoint in drivers/usb/core/config.c does not validate the wMaxPacketSize field of an endpoint descriptor. NOTE: This vulnerability only affects products …

Jun 27, 2024
CVE-2024-4395
7.8 HIGH

The XPC service within the audit functionality of Jamf Compliance Editor before version 1.3.1 on macOS can lead to local privilege escalation.

Jun 27, 2024
CVE-2023-52892
7.5 HIGH

In phpseclib before 1.0.22, 2.x before 2.0.46, and 3.x before 3.0.33, some characters in Subject Alternative Name fields in TLS certificates are incorrectly allowed to …

Jun 27, 2024
CVE-2024-39134
7.5 HIGH

A Stack Buffer Overflow vulnerability in zziplibv 0.13.77 allows attackers to cause a denial of service via the __zzip_fetch_disk_trailer() function at /zzip/zip.c.

Jun 27, 2024
CVE-2024-36074
7.2 HIGH

Netwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys Unify through 7.0.6 contain a remote code execution vulnerability in the Endpoint Protector and Unify agent in …

Jun 27, 2024
CVE-2024-36073
7.2 HIGH

Netwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys Unify through 7.0.6 contain a remote code execution vulnerability in the shadowing component of the Endpoint Protector …

Jun 27, 2024
CVE-2024-39207
8.2 HIGH

lua-shmem v1.0-1 was discovered to contain a buffer overflow via the shmem_write function.

Jun 27, 2024
CVE-2024-39130
7.5 HIGH

A NULL Pointer Dereference discovered in DumpTS v0.1.0-nightly allows attackers to cause a denial of service via the function DumpOneStream() at /src/DumpStream.cpp.

Jun 27, 2024
CVE-2024-38523
7.5 HIGH

Hush Line is a free and open-source, anonymous-tip-line-as-a-service for organizations or individuals. The TOTP authentication flow has multiple issues that weakens its one-time nature. Specifically, …

Jun 27, 2024
CVE-2024-6250
7.5 HIGH

An absolute path traversal vulnerability exists in parisneo/lollms-webui v9.6, specifically in the `open_file` endpoint of `lollms_advanced.py`. The `sanitize_path` function with `allow_absolute_path=True` allows an attacker to …

Jun 27, 2024
CVE-2024-6139
7.3 HIGH

A path traversal vulnerability exists in the XTTS server of the parisneo/lollms package version v9.6. This vulnerability allows an attacker to write audio files to …

Jun 27, 2024
CVE-2024-6090
7.5 HIGH

A path traversal vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410, allowing any user to delete other users' chat histories. This vulnerability can also be exploited to …

Jun 27, 2024
CVE-2024-6085
8.6 HIGH

A path traversal vulnerability exists in the XTTS server included in the lollms package, version v9.6. This vulnerability arises from the ability to perform an …

Jun 27, 2024
CVE-2024-6038
7.5 HIGH

A Regular Expression Denial of Service (ReDoS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability is located in the filter_history function within the …

Jun 27, 2024
CVE-2024-5979
7.5 HIGH

In h2oai/h2o-3 version 3.46.0, the `run_tool` command in the `rapids` component allows the `main` function of any class under the `water.tools` namespace to be called. …

Jun 27, 2024
CVE-2024-5885
8.6 HIGH

stangirard/quivr version 0.0.236 contains a Server-Side Request Forgery (SSRF) vulnerability. The application does not provide sufficient controls when crawling a website, allowing an attacker to …

Jun 27, 2024
CVE-2024-5824
7.4 HIGH

A path traversal vulnerability in the `/set_personality_config` endpoint of parisneo/lollms version 9.4.0 allows an attacker to overwrite the `configs/config.yaml` file. This can lead to remote …

Jun 27, 2024
CVE-2024-5820
8.8 HIGH

An unprotected WebSocket connection in the latest version of stitionai/devika (commit ecee79f) allows a malicious website to connect to the backend and issue commands on …

Jun 27, 2024
CVE-2024-4578
8.4 HIGH

This Advisory describes an issue that impacts Arista Wireless Access Points. Any entity with the ability to authenticate via SSH to an affected AP as …

Jun 27, 2024
CVE-2024-3043
7.5 HIGH

An unauthenticated IEEE 802.15.4 'co-ordinator realignment' packet can be used to force Zigbee nodes to change their network identifier (pan ID), leading to a denial …

Jun 27, 2024
CVE-2023-38370
7.5 HIGH

IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1, under certain configurations, could allow a user on the network to install malicious packages. IBM X-Force ID: …

Jun 27, 2024
CVE-2023-30998
7.8 HIGH

IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain root access due to improper access controls. IBM X-Force ID: …

Jun 27, 2024
CVE-2023-30997
7.8 HIGH

IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain root access due to improper access controls. IBM X-Force ID: …

Jun 27, 2024
CVE-2024-5548
7.5 HIGH

A directory traversal vulnerability exists in the stitionai/devika repository, specifically within the /api/download-project endpoint. Attackers can exploit this vulnerability by manipulating the 'project_name' parameter in …

Jun 27, 2024
CVE-2024-5547
7.5 HIGH

A directory traversal vulnerability exists in the /api/download-project-pdf endpoint of the stitionai/devika repository, affecting the latest version. The vulnerability arises due to insufficient sanitization of …

Jun 27, 2024
CVE-2024-5334
7.5 HIGH

A local file read vulnerability exists in the stitionai/devika repository, affecting the latest version. The vulnerability is due to improper handling of the 'snapshot_path' parameter …

Jun 27, 2024
CVE-2024-35260
8.0 HIGH

An authenticated attacker can exploit an untrusted search path vulnerability in Microsoft Dataverse to execute code over a network.

Jun 27, 2024
CVE-2024-31916
7.5 HIGH

IBM OpenBMC FW1050.00 through FW1050.10 BMCWeb HTTPS server component could disclose sensitive URI content to an unauthorized actor that bypasses authentication channels. IBM X-ForceID: 290026.

Jun 27, 2024
CVE-2024-24792
7.5 HIGH

Parsing a corrupt or malicious image with invalid color indices can cause a panic.

Jun 27, 2024
CVE-2024-39373
7.2 HIGH

TELSAT marKoni FM Transmitters are vulnerable to a command injection vulnerability through the manipulation of settings and could allow an attacker to gain unauthorized access …

Jun 27, 2024
CVE-2024-39158
8.8 HIGH

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/userSys_deal.php?mudi=infoSet.

Jun 27, 2024
CVE-2024-39154
8.8 HIGH

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/keyWord_deal.php?mudi=del&dataType=word&dataTypeCN.

Jun 27, 2024
CVE-2024-6373
7.3 HIGH

A vulnerability has been found in itsourcecode Online Food Ordering System up to 1.0 and classified as critical. This vulnerability affects unknown code of the …

Jun 27, 2024
CVE-2024-6371
7.3 HIGH

A vulnerability, which was classified as critical, has been found in itsourcecode Pool of Bethesda Online Reservation System 1.0. Affected by this issue is some …

Jun 27, 2024
CVE-2024-22232
7.7 HIGH

A specially crafted url can be created which leads to a directory traversal in the salt file server. A malicious user can read an arbitrary …

Jun 27, 2024
CVE-2024-6054
8.8 HIGH

The Auto Featured Image plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'create_post_attachment_from_url' function in all …

Jun 27, 2024
CVE-2024-6323
7.5 HIGH

Improper authorization in global search in GitLab EE affecting all versions from 16.11 prior to 16.11.5 and 17.0 prior to 17.0.3 and 17.1 prior to …

Jun 27, 2024
CVE-2024-4901
8.7 HIGH

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from …

Jun 27, 2024
CVE-2024-28984
8.8 HIGH

Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.1.0.0 and 9.3.0.7, including 8.3.x allow a malicious URL to inject content into the Analyzer plugin …

Jun 26, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.