CVE Database

39204+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-3067
7.2 HIGH

The WooCommerce Google Feed Manager plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 2.4.2 …

Apr 16, 2024
CVE-2024-32631
7.2 HIGH

Out-of-Bounds read in ciCCIOTOPT in ASR180X will cause incorrect computations.

Apr 16, 2024
CVE-2024-22262
8.1 HIGH

Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed …

Apr 16, 2024
CVE-2024-3574
7.5 HIGH

In scrapy version 2.10.1, an issue was identified where the Authorization header, containing credentials for server authentication, is leaked to a third-party site during a …

Apr 16, 2024
CVE-2024-3572
7.5 HIGH

The scrapy/scrapy project is vulnerable to XML External Entity (XXE) attacks due to the use of lxml.etree.fromstring for parsing untrusted XML data without proper validation. …

Apr 16, 2024
CVE-2024-3571
8.8 HIGH

langchain-ai/langchain is vulnerable to path traversal due to improper limitation of a pathname to a restricted directory ('Path Traversal') in its LocalFileStore functionality. An attacker …

Apr 16, 2024
CVE-2024-3029
8.0 HIGH

In mintplex-labs/anything-llm, an attacker can exploit improper input validation by sending a malformed JSON payload to the '/system/enable-multi-user' endpoint. This triggers an error that is …

Apr 16, 2024
CVE-2024-3028
7.2 HIGH

mintplex-labs/anything-llm is vulnerable to improper input validation, allowing attackers to read and delete arbitrary files on the server. By manipulating the 'logo_filename' parameter in the …

Apr 16, 2024
CVE-2024-1961
8.8 HIGH

vertaai/modeldb is vulnerable to a path traversal attack due to improper sanitization of user-supplied file paths in its file upload functionality. Attackers can exploit this …

Apr 16, 2024
CVE-2024-1738
7.5 HIGH

An incorrect authorization vulnerability exists in the lunary-ai/lunary repository, specifically within the evaluations.get route in the evaluations API endpoint. This vulnerability allows unauthorized users to …

Apr 16, 2024
CVE-2024-1646
8.2 HIGH

parisneo/lollms-webui is vulnerable to authentication bypass due to insufficient protection over sensitive endpoints. The application checks if the host parameter is not '0.0.0.0' to restrict …

Apr 16, 2024
CVE-2024-1626
8.1 HIGH

An Insecure Direct Object Reference (IDOR) vulnerability exists in the lunary-ai/lunary repository, version 0.3.0, within the project update endpoint. The vulnerability allows authenticated users to …

Apr 16, 2024
CVE-2024-1594
7.5 HIGH

A path traversal vulnerability exists in the mlflow/mlflow repository, specifically within the handling of the `artifact_location` parameter when creating an experiment. Attackers can exploit this …

Apr 16, 2024
CVE-2024-1593
7.5 HIGH

A path traversal vulnerability exists in the mlflow/mlflow repository due to improper handling of URL parameters. By smuggling path traversal sequences using the ';' character …

Apr 16, 2024
CVE-2024-1569
7.5 HIGH

parisneo/lollms-webui is vulnerable to a denial of service (DoS) attack due to uncontrolled resource consumption. Attackers can exploit the `/open_code_in_vs_code` and similar endpoints without authentication …

Apr 16, 2024
CVE-2024-1561
7.5 HIGH

An issue was discovered in gradio-app/gradio, where the `/component_server` endpoint improperly allows the invocation of any method on a `Component` class with attacker-controlled arguments. Specifically, …

Apr 16, 2024
CVE-2024-1560
8.1 HIGH

A path traversal vulnerability exists in the mlflow/mlflow repository, specifically within the artifact deletion functionality. Attackers can bypass path validation by exploiting the double decoding …

Apr 16, 2024
CVE-2024-1558
7.5 HIGH

A path traversal vulnerability exists in the `_create_model_version()` function within `server/handlers.py` of the mlflow/mlflow repository, due to improper validation of the `source` parameter. Attackers can …

Apr 16, 2024
CVE-2024-1483
7.5 HIGH

A path traversal vulnerability exists in mlflow/mlflow version 2.9.2, allowing attackers to access arbitrary files on the server. By crafting a series of HTTP POST …

Apr 16, 2024
CVE-2024-1456
7.1 HIGH

An S3 bucket takeover vulnerability was identified in the h2oai/h2o-3 repository. The issue involves the S3 bucket 'http://s3.amazonaws.com/h2o-training', which was found to be vulnerable to …

Apr 16, 2024
CVE-2024-1135
7.5 HIGH

Gunicorn fails to properly validate Transfer-Encoding headers, leading to HTTP Request Smuggling (HRS) vulnerabilities. By crafting requests with conflicting Transfer-Encoding headers, attackers can bypass security …

Apr 16, 2024
CVE-2024-0549
8.1 HIGH

mintplex-labs/anything-llm is vulnerable to a relative path traversal attack, allowing unauthorized attackers with a default role account to delete files and folders within the filesystem, …

Apr 16, 2024
CVE-2023-33806
7.8 HIGH

Insecure default configurations in Hikvision Interactive Tablet DS-D5B86RB/B V2.3.0 build220119, allows attackers to execute arbitrary commands.

Apr 15, 2024
CVE-2024-3493
8.6 HIGH

A specific malformed fragmented packet type (fragmented packets may be generated automatically by devices that send large amounts of data) can cause a major nonrecoverable …

Apr 15, 2024
CVE-2024-30656
7.5 HIGH

An issue in Fireboltt Dream Wristphone BSW202_FB_AAC_v2.0_20240110-20240110-1956 allows attackers to cause a Denial of Service (DoS) via a crafted deauth frame.

Apr 15, 2024
CVE-2024-2424
7.5 HIGH

An input validation vulnerability exists in the Rockwell Automation 5015-AENFTXT that causes the secondary adapter to result in a major nonrecoverable fault (MNRF) when malicious …

Apr 15, 2024
CVE-2020-22539
7.2 HIGH

An arbitrary file upload vulnerability in the Add Category function of Codoforum v4.9 allows attackers to execute arbitrary code via uploading a crafted file.

Apr 15, 2024
CVE-2024-28558
8.8 HIGH

SQL Injection vulnerability in sourcecodester Petrol pump management software v1.0, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via crafted …

Apr 15, 2024
CVE-2024-24485
7.5 HIGH

An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to obtain sensitive information via the GET EEP_DATA command.

Apr 15, 2024
CVE-2024-2659
7.2 HIGH

A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevated privileges to execute system commands when performing …

Apr 15, 2024
CVE-2024-22014
8.8 HIGH

An issue discovered in 360 Total Security Antivirus through 11.0.0.1061 for Windows allows attackers to gain escalated privileges via Symbolic Link Follow to Arbitrary File …

Apr 15, 2024
CVE-2023-4857
7.5 HIGH

An authentication bypass vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user to execute certain IPMI calls that could lead to …

Apr 15, 2024
CVE-2023-4856
8.8 HIGH

A format string vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user to execute arbitrary commands on a specific API endpoint.

Apr 15, 2024
CVE-2023-4855
7.2 HIGH

A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevated privileges to execute unauthorized commands via IPMI.

Apr 15, 2024
CVE-2023-48709
8.0 HIGH

iTop is an IT service management platform. When exporting data from backoffice or portal in CSV or Excel files, users' inputs may include malicious formulas …

Apr 15, 2024
CVE-2023-47626
8.8 HIGH

iTop is an IT service management platform. When displaying/editing the user's personal tokens, XSS attacks are possible. This vulnerability is fixed in 3.1.1.

Apr 15, 2024
CVE-2023-47622
8.8 HIGH

iTop is an IT service management platform. When dashlet are refreshed, XSS attacks are possible. This vulnerability is fixed in 3.0.4 and 3.1.1.

Apr 15, 2024
CVE-2023-47123
8.7 HIGH

iTop is an IT service management platform. By filling malicious code in an object friendlyname / complementary name, an XSS attack can be performed when …

Apr 15, 2024
CVE-2024-3783
7.7 HIGH

The Backup Agents section in WBSAirback 21.02.04 is affected by a Path Traversal vulnerability, allowing a user with low privileges to download files from the …

Apr 15, 2024
CVE-2024-3782
8.8 HIGH

Cross-Site Request Forgery vulnerability in WBSAirback 21.02.04, which could allow an attacker to create a manipulated HTML form to perform privileged actions once it is …

Apr 15, 2024
CVE-2024-3780
7.8 HIGH

A vulnerability of Information Exposure has been found on Technicolor CGA2121 affecting the version 1.01, this vulnerability allows a local attacker to obtain sensitive information …

Apr 15, 2024
CVE-2024-30220
8.8 HIGH

Command injection vulnerability in PLANEX COMMUNICATIONS wireless LAN routers allows a network-adjacent unauthenticated attacker to execute an arbitrary command by sending a specially crafted request …

Apr 15, 2024
CVE-2024-29219
7.8 HIGH

Out-of-bounds read vulnerability exists in KV STUDIO Ver.11.64 and earlier and KV REPLAY VIEWER Ver.2.64 and earlier, and VT5-WX15/WX12 Ver.6.02 and earlier, which may lead …

Apr 15, 2024
CVE-2024-29218
8.8 HIGH

Out-of-bounds write vulnerability exists in KV STUDIO Ver.11.64 and earlier, KV REPLAY VIEWER Ver.2.64 and earlier, and VT5-WX15/WX12 Ver.6.02 and earlier, which may lead to …

Apr 15, 2024
CVE-2024-28099
7.8 HIGH

VT STUDIO Ver.8.32 and earlier contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, …

Apr 15, 2024
CVE-2024-23911
7.5 HIGH

Out-of-bounds read vulnerability caused by improper checking of the option length values in IPv6 NDP packets exists in Cente middleware TCP/IP Network Series, which may …

Apr 15, 2024
CVE-2024-31424
8.8 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Hamid Alinia Login with phone number login-with-phone-number.This issue affects Login with phone number: from n/a through <= 1.6.93.

Apr 15, 2024
CVE-2024-22437
7.3 HIGH

A potential security vulnerability has been identified in VSS Provider and CAPI Proxy software for certain HPE MSA storage products. This vulnerability could be exploited …

Apr 15, 2024
CVE-2024-22435
8.3 HIGH

A potential security vulnerability has been identified in Web ViewPoint Enterprise software. This vulnerability could be exploited to allow unauthorized users to access some resources …

Apr 15, 2024
CVE-2024-32139
8.5 HIGH

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher: from n/a …

Apr 15, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.