CVE Database

38976+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-36800
7.5 HIGH

A SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the ID parameter in Download.php.

Jun 4, 2024
CVE-2024-33557
8.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in 8theme XStore Core allows PHP Local File Inclusion.This issue affects XStore Core: …

Jun 4, 2024
CVE-2024-29170
8.1 HIGH

Dell PowerScale OneFS versions 8.2.x through 9.8.0.x contain a use of hard coded credentials vulnerability. An adjacent network unauthenticated attacker could potentially exploit this vulnerability, …

Jun 4, 2024
CVE-2024-4254
7.1 HIGH

The 'deploy-website.yml' workflow in the gradio-app/gradio repository, specifically in the 'main' branch, is vulnerable to secrets exfiltration due to improper authorization. The vulnerability arises from …

Jun 4, 2024
CVE-2024-37065
7.8 HIGH

Deserialization of untrusted data can occur in versions 0.6 or newer of the skops python library, enabling a maliciously crafted model to run arbitrary code …

Jun 4, 2024
CVE-2024-37064
7.8 HIGH

Deseriliazation of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a maliciously crafted dataset to run arbitrary code …

Jun 4, 2024
CVE-2024-37063
7.8 HIGH

A cross-site scripting (XSS) vulnerability in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library allows for payloads to be run when a maliocusly crafted …

Jun 4, 2024
CVE-2024-37062
7.8 HIGH

Deserialization of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a malicously crafted report to run arbitrary code …

Jun 4, 2024
CVE-2024-37061
8.8 HIGH

Remote Code Execution can occur in versions of the MLflow platform running version 1.11.0 or newer, enabling a maliciously crafted MLproject to execute arbitrary code …

Jun 4, 2024
CVE-2024-37060
8.8 HIGH

Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.27.0 or newer, enabling a maliciously crafted Recipe to execute arbitrary …

Jun 4, 2024
CVE-2024-37059
8.8 HIGH

Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.5.0 or newer, enabling a maliciously uploaded PyTorch model to run …

Jun 4, 2024
CVE-2024-37058
8.8 HIGH

Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.5.0 or newer, enabling a maliciously uploaded Langchain AgentExecutor model to …

Jun 4, 2024
CVE-2024-37057
8.8 HIGH

Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.0.0rc0 or newer, enabling a maliciously uploaded Tensorflow model to run …

Jun 4, 2024
CVE-2024-37056
8.8 HIGH

Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.23.0 or newer, enabling a maliciously uploaded LightGBM scikit-learn model to …

Jun 4, 2024
CVE-2024-37055
8.8 HIGH

Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.24.0 or newer, enabling a maliciously uploaded pmdarima model to run …

Jun 4, 2024
CVE-2024-37054
8.8 HIGH

Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.9.0 or newer, enabling a maliciously uploaded PyFunc model to run …

Jun 4, 2024
CVE-2024-37053
8.8 HIGH

Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling a maliciously uploaded scikit-learn model to run …

Jun 4, 2024
CVE-2024-37052
8.8 HIGH

Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling a maliciously uploaded scikit-learn model to run …

Jun 4, 2024
CVE-2023-47837
8.3 HIGH

Improper Privilege Management vulnerability in Repute Infosystems ARMember allows Privilege Escalation.This issue affects ARMember: from n/a through 4.0.10.

Jun 4, 2024
CVE-2023-46630
7.5 HIGH

Improper Authentication vulnerability in wpase Admin and Site Enhancements (ASE) allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Admin and Site Enhancements (ASE): …

Jun 4, 2024
CVE-2024-5000
7.5 HIGH

An unauthenticated remote attacker can use a malicious OPC UA client to send a crafted request to affected CODESYS products which can cause a DoS …

Jun 4, 2024
CVE-2023-5751
7.8 HIGH

A local attacker with low privileges can read and modify any users files and cause a DoS in the working directory of the affected products …

Jun 4, 2024
CVE-2024-20878
7.3 HIGH

Heap out-of-bound write vulnerability in parsing grid image in libsavscmn.so prior to SMR June-2024 Release 1 allows local attackers to execute arbitrary code.

Jun 4, 2024
CVE-2024-20877
7.3 HIGH

Heap out-of-bound write vulnerability in parsing grid image header in libsavscmn.so prior to SMR Jun-2024 Release 1 allows local attackers to execute arbitrary code.

Jun 4, 2024
CVE-2024-20874
7.9 HIGH

Improper access control vulnerability in SmartManagerCN prior to SMR Jun-2024 Release 1 allows local attackers to launch privileged activities.

Jun 4, 2024
CVE-2024-4856
8.2 HIGH

The FS Product Inquiry WordPress plugin through 1.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Jun 4, 2024
CVE-2024-4749
8.3 HIGH

The wp-eMember WordPress plugin before 10.3.9 does not sanitize and escape the "fieldId" parameter before outputting it back in the page, leading to a Reflected …

Jun 4, 2024
CVE-2024-3555
7.2 HIGH

The Social Link Pages: link-in-bio landing pages for your social media profiles plugin for WordPress is vulnerable to unauthorized access due to a missing capability …

Jun 4, 2024
CVE-2024-2019
7.5 HIGH

The WP-DB-Table-Editor plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to lack of a default …

Jun 4, 2024
CVE-2024-4870
7.2 HIGH

The Frontend Registration – Contact Form 7 plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1 due to insufficient …

Jun 4, 2024
CVE-2022-1242
7.8 HIGH

Apport can be tricked into connecting to arbitrary sockets as the root user

Jun 3, 2024
CVE-2022-0555
8.4 HIGH

Subiquity Shows Guided Storage Passphrase in Plaintext with Read-all Permissions

Jun 3, 2024
CVE-2021-3899
7.8 HIGH

There is a race condition in the 'replaced executable' detection that, with the correct local configuration, allow an attacker to execute arbitrary code as root.

Jun 3, 2024
CVE-2024-4540
7.5 HIGH

A flaw was found in Keycloak in OAuth 2.0 Pushed Authorization Requests (PAR). Client-provided parameters were found to be included in plain text in the …

Jun 3, 2024
CVE-2024-32983
8.2 HIGH

Misskey is an open source, decentralized microblogging platform. Misskey doesn't perform proper normalization on the JSON structures of incoming signed ActivityPub activity objects before processing …

Jun 3, 2024
CVE-2024-36128
7.5 HIGH

Directus is a real-time API and App dashboard for managing SQL database content. Prior to 10.11.2, providing a non-numeric length value to the random string …

Jun 3, 2024
CVE-2024-36127
7.5 HIGH

apko is an apk-based OCI image builder. apko exposures HTTP basic auth credentials from repository and keyring URLs in log output. This vulnerability is fixed …

Jun 3, 2024
CVE-2024-36728
8.1 HIGH

TRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary. The overflow allows an authenticated user to execute arbitrary code by …

Jun 3, 2024
CVE-2024-36569
8.1 HIGH

Sourcecodester Gas Agency Management System v1.0 is vulnerable to arbitrary code execution via editClientImage.php.

Jun 3, 2024
CVE-2024-35631
7.1 HIGH

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Foliovision FV Flowplayer Video Player allows Reflected XSS.This issue affects FV …

Jun 3, 2024
CVE-2024-35630
7.6 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LJ Apps WP TripAdvisor Review Slider allows Blind SQL Injection.This issue …

Jun 3, 2024
CVE-2024-34794
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tainacan Tainacan tainacan.This issue affects Tainacan: from n/a through <= 0.21.3.

Jun 3, 2024
CVE-2024-23670
7.8 HIGH

An improper authorization in Fortinet FortiWebManager version 7.2.0 and 7.0.0 through 7.0.4 and 6.3.0 and 6.2.3 through 6.2.4 and 6.0.2 allows attacker to execute unauthorized …

Jun 3, 2024
CVE-2024-23668
8.8 HIGH

An improper authorization in Fortinet FortiWebManager version 7.2.0 and 7.0.0 through 7.0.4 and 6.3.0 and 6.2.3 through 6.2.4 and 6.0.2 allows attacker to execute unauthorized …

Jun 3, 2024
CVE-2024-23667
7.8 HIGH

An improper authorization in Fortinet FortiWebManager version 7.2.0 and 7.0.0 through 7.0.4 and 6.3.0 and 6.2.3 through 6.2.4 and 6.0.2 allows attacker to execute unauthorized …

Jun 3, 2024
CVE-2024-23363
7.5 HIGH

Transient DOS while processing an improperly formatted Fine Time Measurement (FTM) management frame.

Jun 3, 2024
CVE-2024-23360
8.4 HIGH

Memory corruption while creating a LPAC client as LPAC engine was allowed to access GPU registers.

Jun 3, 2024
CVE-2023-43555
8.2 HIGH

Information disclosure in Video while parsing mp2 clip with invalid section length.

Jun 3, 2024
CVE-2023-43542
7.8 HIGH

Memory corruption while copying a keyblob`s material when the key material`s size is not accurately checked.

Jun 3, 2024
CVE-2024-36963
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: tracefs: Reset permissions on remount if permissions are options There's an inconsistency with the way …

Jun 3, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.