CVE Database

38976+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-6065
7.3 HIGH

A vulnerability was found in itsourcecode Bakery Online Ordering System 1.0. It has been rated as critical. This issue affects some unknown processing of the …

Jun 17, 2024
CVE-2024-37896
8.8 HIGH

Gin-vue-admin is a backstage management system based on vue and gin. Gin-vue-admin <= v2.6.5 has SQL injection vulnerability. The SQL injection vulnerabilities occur when a …

Jun 17, 2024
CVE-2024-37890
7.5 HIGH

ws is an open source WebSocket client and server for Node.js. A request with a number of headers exceeding theserver.maxHeadersCount threshold could be used to …

Jun 17, 2024
CVE-2024-37305
8.2 HIGH

oqs-provider is a provider for the OpenSSL 3 cryptography library that adds support for post-quantum cryptography in TLS, X.509, and S/MIME using post-quantum algorithms from …

Jun 17, 2024
CVE-2024-38449
7.7 HIGH

A Directory Traversal vulnerability in KasmVNC 1.3.1.230e50f7b89663316c70de7b0e3db6f6b9340489 and possibly earlier versions allows remote authenticated attackers to browse parent directories and read the content of files …

Jun 17, 2024
CVE-2024-37840
8.8 HIGH

SQL injection vulnerability in processscore.php in Itsourcecode Learning Management System Project In PHP With Source Code v1.0 allows remote attackers to execute arbitrary SQL commands …

Jun 17, 2024
CVE-2024-37795
7.5 HIGH

A segmentation fault in CVC5 Solver v1.1.3 allows attackers to cause a Denial of Service (DoS) via a crafted SMT-LIB input file containing the `set-logic` …

Jun 17, 2024
CVE-2024-37794
7.5 HIGH

Improper input validation in CVC5 Solver v1.1.3 allows attackers to cause a Denial of Service (DoS) via a crafted SMT2 input file.

Jun 17, 2024
CVE-2024-36973
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: misc: microchip: pci1xxxx: fix double free in the error handling of gp_aux_bus_probe() When auxiliary_device_add() returns …

Jun 17, 2024
CVE-2024-36577
8.3 HIGH

apphp js-object-resolver < 3.1.1 is vulnerable to Prototype Pollution via Module.setNestedProperty.

Jun 17, 2024
CVE-2024-0397
7.4 HIGH

A defect was discovered in the Python “ssl” module where there is a memory race condition with the ssl.SSLContext methods “cert_store_stats()” and “get_ca_certs()”. The race …

Jun 17, 2024
CVE-2024-4032
7.5 HIGH

The “ipaddress” module contained incorrect information about whether certain IPv4 and IPv6 addresses were designated as “globally reachable” or “private”. This affected the is_private and …

Jun 17, 2024
CVE-2024-36581
7.6 HIGH

A Prototype Pollution issue in abw badger-database 1.2.1 allows an attacker to execute arbitrary code via dist/badger-database.esm.

Jun 17, 2024
CVE-2024-37848
8.4 HIGH

SQL Injection vulnerability in Online-Bookstore-Project-In-PHP v1.0 allows a local attacker to execute arbitrary code via the admin_delete.php component.

Jun 17, 2024
CVE-2024-37621
7.2 HIGH

StrongShop v1.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the component /shippingOptionConfig/index.blade.php.

Jun 17, 2024
CVE-2024-36583
8.1 HIGH

A Prototype Pollution issue in byondreal accessor <= 1.0.0 allows an attacker to execute arbitrary code via @byondreal/accessor/index.

Jun 17, 2024
CVE-2024-5650
8.5 HIGH

DLL Hijacking vulnerability has been found in CENTUM CAMS Log server provided by Yokogawa Electric Corporation. If an attacker is somehow able to intrude into …

Jun 17, 2024
CVE-2024-6045
8.8 HIGH

Certain models of D-Link wireless routers contain an undisclosed factory testing backdoor. Unauthenticated attackers on the local area network can force the device to enable …

Jun 17, 2024
CVE-2024-6043
7.3 HIGH

A vulnerability classified as critical has been found in SourceCodester Best House Rental Management System 1.0. This affects the function login of the file admin_class.php. …

Jun 17, 2024
CVE-2024-6042
7.3 HIGH

A vulnerability was found in itsourcecode Real Estate Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality …

Jun 17, 2024
CVE-2024-38467
7.5 HIGH

Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized user information retrieval via the queryUser API.

Jun 16, 2024
CVE-2024-38461
7.5 HIGH

irodsServerMonPerf in iRODS before 4.3.2 attempts to proceed with use of a path even if it is not a directory.

Jun 16, 2024
CVE-2024-38459
7.8 HIGH

langchain_experimental (aka LangChain Experimental) before 0.0.61 for LangChain provides Python REPL access without an opt-in step. NOTE; this issue exists because of an incomplete fix …

Jun 16, 2024
CVE-2024-38458
8.8 HIGH

Xenforo before 2.2.16 allows code injection.

Jun 16, 2024
CVE-2024-38457
8.8 HIGH

Xenforo before 2.2.16 allows CSRF.

Jun 16, 2024
CVE-2024-38440
7.5 HIGH

Netatalk before 3.2.1 has an off-by-one error, and resultant heap-based buffer overflow and segmentation violation, because of incorrectly using FPLoginExt in BN_bin2bn in etc/uams/uams_dhx_pam.c. The …

Jun 16, 2024
CVE-2024-38427
8.8 HIGH

In International Color Consortium DemoIccMAX before 85ce74e, a logic flaw in CIccTagXmlProfileSequenceId::ParseXml in IccXML/IccLibXML/IccTagXml.cpp results in unconditionally returning false.

Jun 16, 2024
CVE-2024-27275
7.4 HIGH

IBM i 7.2, 7.3, 7.4, and 7.5 contains a local privilege escalation vulnerability caused by an insufficient authority requirement. A local user without administrator privilege …

Jun 15, 2024
CVE-2024-6000
7.1 HIGH

The FooEvents for WooCommerce plugin for WordPress is vulnerable to unauthorized arbitrary file uploads due to an improper capability setting on the 'display_ticket_themes_page' function in …

Jun 15, 2024
CVE-2024-3813
8.8 HIGH

The tagDiv Composer plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.8 via the 'td_block_title' shortcode 'block_template_id' …

Jun 15, 2024
CVE-2024-2544
7.4 HIGH

The Popup Builder plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on all …

Jun 15, 2024
CVE-2023-6696
8.1 HIGH

The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing …

Jun 15, 2024
CVE-2024-6003
7.3 HIGH

A vulnerability was found in Guangdong Baolun Electronics IP Network Broadcasting Service Platform 2.0. It has been classified as critical. Affected is an unknown function …

Jun 14, 2024
CVE-2024-36600
8.4 HIGH

Buffer Overflow Vulnerability in libcdio 2.2.0 (fixed in 2.3.0) allows an attacker to execute arbitrary code via a crafted ISO 9660 image file.

Jun 14, 2024
CVE-2024-36598
8.1 HIGH

An arbitrary file upload vulnerability in Aegon Life v1.0 allows attackers to execute arbitrary code via uploading a crafted image file.

Jun 14, 2024
CVE-2024-36597
8.8 HIGH

Aegon Life v1.0 was discovered to contain a SQL injection vulnerability via the client_id parameter at clientStatus.php.

Jun 14, 2024
CVE-2024-24320
8.8 HIGH

Directory Traversal vulnerability in Mgt-commerce CloudPanel v.2.0.0 thru v.2.4.0 allows a remote attacker to obtain sensitive information and execute arbitrary code via the service parameter …

Jun 14, 2024
CVE-2024-37369
8.8 HIGH

A privilege escalation vulnerability exists in the affected product. The vulnerability allows low-privilege users to edit scripts, bypassing Access Control Lists, and potentially gaining further …

Jun 14, 2024
CVE-2024-37882
8.1 HIGH

Nextcloud Server is a self hosted personal cloud system. A recipient of a share with read&share permissions could reshare the item with more permissions. It …

Jun 14, 2024
CVE-2024-37645
8.8 HIGH

TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a stack overflow vulnerability via the submit-url parameter at /formSysLog .

Jun 14, 2024
CVE-2024-37643
8.8 HIGH

TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a stack overflow vulnerability via the submit-url parameter at /formPasswordAuth .

Jun 14, 2024
CVE-2024-37641
8.8 HIGH

TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a stack overflow via the submit-url parameter at /formNewSchedule

Jun 14, 2024
CVE-2024-37644
8.8 HIGH

TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain a hardcoded password vulnerability in /etc/shadow.sample, which allows attackers to log in as root.

Jun 14, 2024
CVE-2024-37368
7.5 HIGH

A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE. The vulnerability allows a user from a remote system with FTView to send …

Jun 14, 2024
CVE-2024-37367
7.5 HIGH

A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE v12. The vulnerability allows a user from a remote system with FTView to …

Jun 14, 2024
CVE-2024-37313
7.3 HIGH

Nextcloud server is a self hosted personal cloud system. Under some circumstance it was possible to bypass the second factor of 2FA after successfully providing …

Jun 14, 2024
CVE-2024-34694
8.1 HIGH

LNbits is a Lightning wallet and accounts system. Paying invoices in Eclair that do not get settled within the internal timeout (about 30s) lead to …

Jun 14, 2024
CVE-2024-33377
8.1 HIGH

LB-LINK BL-W1210M v2.0 was discovered to contain a clickjacking vulnerability via the Administrator login page. Attackers can cause victim users to perform arbitrary operations via …

Jun 14, 2024
CVE-2024-37640
8.8 HIGH

TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via ssid5g in the function setWiFiEasyGuestCfg.

Jun 14, 2024
CVE-2024-37639
8.8 HIGH

TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to contain a stack overflow via eport in the function setIpPortFilterRules.

Jun 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.