CVE Database

9973+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-36401
9.8 CRITICAL KEV

GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.22.6, 2.23.6, 2.24.4, and 2.25.2, multiple OGC …

Jul 1, 2024
CVE-2024-6425
9.1 CRITICAL

Incorrect Provision of Specified Functionality vulnerability in MESbook 20221021.03 version. An unauthenticated remote attacker can register user accounts without being authenticated from the route "/account/Register/" …

Jul 1, 2024
CVE-2024-6424
9.3 CRITICAL

External server-side request vulnerability in MESbook 20221021.03 version, which could allow a remote, unauthenticated attacker to exploit the endpoint "/api/Proxy/Post?userName=&password=&uri=<FILE|INTERNAL URL|IP/HOST" or "/api/Proxy/Get?userName=&password=&uri=<ARCHIVO|URL INTERNA|IP/HOST" to …

Jul 1, 2024
CVE-2024-39017
9.8 CRITICAL

agreejs shared v0.0.1 was discovered to contain a prototype pollution via the function mergeInternalComponents. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024
CVE-2024-39015
9.8 CRITICAL

cafebazaar hod v0.4.14 was discovered to contain a prototype pollution via the function request. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024
CVE-2024-39014
9.8 CRITICAL

ahilfoley cahil/utils v2.3.2 was discovered to contain a prototype pollution via the function set. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024
CVE-2024-39013
9.8 CRITICAL

2o3t-utility v0.1.2 was discovered to contain a prototype pollution via the function extend. This vulnerability allows attackers to execute arbitrary code or cause a Denial …

Jul 1, 2024
CVE-2024-39008
10.0 CRITICAL

robinweser fast-loops v1.1.3 was discovered to contain a prototype pollution via the function objectMergeDeep. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024
CVE-2024-38999
10.0 CRITICAL

jrburke requirejs v2.3.6 was discovered to contain a prototype pollution via the function s.contexts._.configure. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024
CVE-2024-38996
9.8 CRITICAL

ag-grid-community v31.3.2 and ag-grid-enterprise v31.3.2 were discovered to contain a prototype pollution via the _.mergeDeep function. This vulnerability allows attackers to execute arbitrary code or …

Jul 1, 2024
CVE-2024-38993
9.8 CRITICAL

rjrodger jsonic-next v2.12.1 was discovered to contain a prototype pollution via the function empty. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 1, 2024
CVE-2024-20080
9.8 CRITICAL

In gnss service, there is a possible escalation of privilege due to improper certificate validation. This could lead to remote escalation of privilege with no …

Jul 1, 2024
CVE-2024-20078
9.8 CRITICAL

In venc, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege with System execution …

Jul 1, 2024
CVE-2024-5926
9.1 CRITICAL

A path traversal vulnerability in the get-project-files functionality of stitionai/devika allows attackers to read arbitrary files from the filesystem and cause a Denial of Service …

Jun 30, 2024
CVE-2024-39848
9.1 CRITICAL

Internet2 Grouper before 5.6 allows authentication bypass when LDAP authentication is used in certain ways. This is related to internet2.middleware.grouper.ws.security.WsGrouperLdapAuthentication and the use of the …

Jun 29, 2024
CVE-2024-6265
9.8 CRITICAL

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress plugin for WordPress is vulnerable to time-based SQL Injection …

Jun 29, 2024
CVE-2019-25211
9.1 CRITICAL

parseWildcardRules in Gin-Gonic CORS middleware before 1.6.0 mishandles a wildcard at the end of an origin string, e.g., https://example.community/* is allowed when the intention is …

Jun 29, 2024
CVE-2024-37371
9.1 CRITICAL

In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can cause invalid memory reads during GSS message token handling by sending message tokens with …

Jun 28, 2024
CVE-2024-5827
9.8 CRITICAL

Vanna v0.3.4 is vulnerable to SQL injection in its DuckDB integration exposed to its Flask Web APIs. Attackers can inject malicious SQL training data and …

Jun 28, 2024
CVE-2024-29039
9.0 CRITICAL

tpm2 is the source repository for the Trusted Platform Module (TPM2.0) tools. This vulnerability allows attackers to manipulate tpm2_checkquote outputs by altering the TPML_PCR_SELECTION in …

Jun 28, 2024
CVE-2024-3816
9.8 CRITICAL

Sites managed in S@M CMS (Concept Intermedia) might be vulnerable to a blind SQL Injection executed using the search bar. Only a part of observed …

Jun 28, 2024
CVE-2024-39704
9.8 CRITICAL

Soft Circle French-Bread Melty Blood: Actress Again: Current Code through 1.07 Rev. 1.4.0 allows a remote attacker to execute arbitrary code on a client's machine …

Jun 28, 2024
CVE-2024-39349
9.8 CRITICAL

A vulnerability regarding buffer copy without checking size of input ('Classic Buffer Overflow') is found in the libjansson component and it does not affect the …

Jun 28, 2024
CVE-2024-6071
10.0 CRITICAL

PTC Creo Elements/Direct License Server exposes a web interface which can be used by unauthenticated remote attackers to execute arbitrary OS commands on the server.

Jun 27, 2024
CVE-2024-39705
9.8 CRITICAL

NLTK through 3.8.1 allows remote code execution if untrusted packages have pickled Python code, and the integrated data package download functionality is used. This affects, …

Jun 27, 2024
CVE-2024-36059
9.4 CRITICAL

Directory Traversal vulnerability in Kalkitech ASE ASE61850 IEDSmart upto and including version 2.3.5 allows attackers to read/write arbitrary files via the IEC61850 File Transfer protocol.

Jun 27, 2024
CVE-2024-36072
9.8 CRITICAL

Netwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys Unify through 7.0.6 contain a remote code execution vulnerability in the logging component of the Endpoint Protector …

Jun 27, 2024
CVE-2024-2973
10.0 CRITICAL

An Authentication Bypass Using an Alternate Path or Channel vulnerability in Juniper Networks Session Smart Router or conductor running with a redundant peer allows a …

Jun 27, 2024
CVE-2024-6127
9.8 CRITICAL

BC Security Empire before 5.9.3 is vulnerable to a path traversal issue that can lead to remote code execution. A remote, unauthenticated attacker can exploit …

Jun 27, 2024
CVE-2024-39208
9.8 CRITICAL

luci-app-lucky v2.8.3 was discovered to contain hardcoded credentials.

Jun 27, 2024
CVE-2024-5980
9.8 CRITICAL

A vulnerability in the /v1/runs API endpoint of lightning-ai/pytorch-lightning v2.2.4 allows attackers to exploit path traversal when extracting tar.gz files. When the LightningApp is running …

Jun 27, 2024
CVE-2024-5826
9.8 CRITICAL

In the latest version of vanna-ai/vanna, the `vanna.ask` function is vulnerable to remote code execution due to prompt injection. The root cause is the lack …

Jun 27, 2024
CVE-2024-5822
9.8 CRITICAL

A Server-Side Request Forgery (SSRF) vulnerability exists in the upload processing interface of gaizhenbiao/ChuanhuChatGPT versions <= ChuanhuChatGPT-20240410-git.zip. This vulnerability allows attackers to send crafted requests …

Jun 27, 2024
CVE-2024-5751
9.8 CRITICAL

BerriAI/litellm version v1.35.8 contains a vulnerability where an attacker can achieve remote code execution. The vulnerability exists in the `add_deployment` function, which decodes and decrypts …

Jun 27, 2024
CVE-2024-3330
9.9 CRITICAL

Vulnerability in Spotfire Spotfire Analyst, Spotfire Spotfire Server, Spotfire Spotfire for AWS Marketplace allows In the case of the installed Windows client: Successful execution of …

Jun 27, 2024
CVE-2024-39669
9.8 CRITICAL

In the Console in Soffid IAM before 3.5.39, necessary checks were not applied to some Java objects. A malicious agent could possibly execute arbitrary code …

Jun 27, 2024
CVE-2024-39376
9.8 CRITICAL

TELSAT marKoni FM Transmitters are vulnerable to users gaining unauthorized access to sensitive information or performing actions beyond their designated permissions.

Jun 27, 2024
CVE-2024-39375
9.8 CRITICAL

TELSAT marKoni FM Transmitters are vulnerable to an attacker bypassing authentication and gaining administrator privileges.

Jun 27, 2024
CVE-2024-39374
9.8 CRITICAL

TELSAT marKoni FM Transmitters are vulnerable to an attacker exploiting a hidden admin account that can be accessed through the use of hard-coded credentials.

Jun 27, 2024
CVE-2024-1107
9.8 CRITICAL

Authorization Bypass Through User-Controlled Key vulnerability in Talya Informatics Travel APPS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Travel APPS: before v17.0.68.

Jun 27, 2024
CVE-2024-5535
9.1 CRITICAL

Issue summary: Calling the OpenSSL API function SSL_select_next_proto with an empty supported client protocols buffer may cause a crash or memory contents to be sent …

Jun 27, 2024
CVE-2024-0949
9.8 CRITICAL

Missing Authentication, Files or Directories Accessible to External Parties, Use of Hard-coded Credentials vulnerability in Talya Informatics Elektraweb allows Authentication Bypass.This issue affects Elektraweb: before …

Jun 27, 2024
CVE-2024-0947
9.8 CRITICAL

Reliance on Cookies without Validation and Integrity Checking vulnerability in Talya Informatics Elektraweb allows Session Credential Falsification through Manipulation, Accessing/Intercepting/Modifying HTTP Cookies, Manipulating Opaque Client-based …

Jun 27, 2024
CVE-2024-5655
9.6 CRITICAL

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from …

Jun 27, 2024
CVE-2024-37734
9.8 CRITICAL

An issue in OpenEMR 7.0.2 allows a remote attacker to escalate privileges viaa crafted POST request using the noteid parameter.

Jun 26, 2024
CVE-2024-1839
10.0 CRITICAL

Intrado 911 Emergency Gateway login form is vulnerable to an unauthenticated blind time-based SQL injection, which may allow an unauthenticated remote attacker to execute malicious …

Jun 26, 2024
CVE-2024-39243
9.8 CRITICAL

An issue discovered in skycaiji 2.8 allows attackers to run arbitrary code via crafted POST request to /index.php?s=/admin/develop/editor_save.

Jun 26, 2024
CVE-2024-4228
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 200 - Exposure of Sensitive Information to an Unauthorized Actor, CWE …

Jun 26, 2024
CVE-2024-37252
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Icegram Email Subscribers & Newsletters allows SQL Injection.This issue affects Email …

Jun 26, 2024
CVE-2024-5181
9.8 CRITICAL

A command injection vulnerability exists in the mudler/localai version 2.14.0. The vulnerability arises from the application's handling of the backend parameter in the configuration file, …

Jun 26, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.