CVE Database

9973+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-35213
9.0 CRITICAL

An improper input validation vulnerability in the SGI Image Codec of QNX SDP version(s) 6.6, 7.0, and 7.1 could allow an attacker to potentially cause …

Jun 11, 2024
CVE-2024-34405
9.1 CRITICAL

Improper deep link validation in McAfee Security: Antivirus VPN for Android before 8.3.0 could allow an attacker to launch an arbitrary URL within the app.

Jun 11, 2024
CVE-2024-30080
9.8 CRITICAL

Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

Jun 11, 2024
CVE-2024-2013
10.0 CRITICAL

An authentication bypass vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway component that if exploited allows attackers without any access to interact with the …

Jun 11, 2024
CVE-2024-2012
9.1 CRITICAL

vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway that if exploited an attacker could use to allow unintended commands or code to be executed …

Jun 11, 2024
CVE-2024-5701
9.8 CRITICAL

Memory safety bugs present in Firefox 126. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of …

Jun 11, 2024
CVE-2024-5699
9.8 CRITICAL

In violation of spec, cookie prefixes such as `__Secure` were being ignored if they were not correctly capitalized - by spec they should be checked …

Jun 11, 2024
CVE-2024-5695
9.8 CRITICAL

If an out-of-memory condition occurs at a specific point using allocations in the probabilistic heap checker, an assertion could have been triggered, and in rarer …

Jun 11, 2024
CVE-2024-36266
9.3 CRITICAL

A vulnerability has been identified in PowerSys (All versions < V3.11). The affected application insufficiently protects responses to authentication requests. This could allow a local …

Jun 11, 2024
CVE-2024-3549
9.9 CRITICAL

The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to SQL Injection via the 'b2sSortPostType' parameter in all versions up to, …

Jun 11, 2024
CVE-2024-36360
9.8 CRITICAL

OS command injection vulnerability exists in awkblog v0.0.1 (commit hash:7b761b192d0e0dc3eef0f30630e00ece01c8d552) and earlier. If a remote unauthenticated attacker sends a specially crafted HTTP request, an arbitrary …

Jun 11, 2024
CVE-2024-31401
9.0 CRITICAL

Cross-site scripting vulnerability in Cybozu Garoon 5.0.0 to 5.15.2 allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script on the …

Jun 11, 2024
CVE-2024-29855
9.0 CRITICAL

Hard-coded JWT secret allows authentication bypass in Veeam Recovery Orchestrator

Jun 11, 2024
CVE-2024-37014
9.8 CRITICAL

Langflow through 0.6.19 allows remote code execution if untrusted users are able to reach the "POST /api/v1/custom_component" endpoint and provide a Python script.

Jun 10, 2024
CVE-2024-36415
9.1 CRITICAL

SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in uploaded file verification in products allows …

Jun 10, 2024
CVE-2024-36412
10.0 CRITICAL

SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in events response entry point allows for …

Jun 10, 2024
CVE-2024-36411
9.6 CRITICAL

SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, poor input validation allows for SQL Injection in …

Jun 10, 2024
CVE-2024-32167
9.1 CRITICAL

Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Arbitrary file deletion vulnerability as the backend settings have the function of deleting pictures to delete …

Jun 10, 2024
CVE-2024-36410
9.6 CRITICAL

SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, poor input validation allows for SQL Injection in …

Jun 10, 2024
CVE-2024-36409
9.6 CRITICAL

SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, poor input validation allows for SQL Injection in …

Jun 10, 2024
CVE-2024-36408
9.6 CRITICAL

SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, poor input validation allows for SQL Injection in …

Jun 10, 2024
CVE-2024-35746
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Asghar Hatampoor BuddyPress Cover allows Code Injection.This issue affects BuddyPress Cover: from n/a through 2.1.4.2.

Jun 10, 2024
CVE-2024-31611
9.1 CRITICAL

SeaCMS 12.9 has a file deletion vulnerability via admin_template.php.

Jun 10, 2024
CVE-2024-37051
9.3 CRITICAL

GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 …

Jun 10, 2024
CVE-2024-35677
9.0 CRITICAL

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in StylemixThemes MegaMenu allows PHP Local File Inclusion.This issue affects MegaMenu: from n/a …

Jun 10, 2024
CVE-2024-34762
9.9 CRITICAL

Vulnerability discovered by executing a planned security audit. Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPENGINE INC Advanced Custom …

Jun 10, 2024
CVE-2024-35307
9.8 CRITICAL

Argument Injection Leading to Remote Code Execution in Realtime Graph Extension, allowing unauthenticated attackers to execute arbitrary code on the server. This issue affects Pandora …

Jun 10, 2024
CVE-2024-35306
9.8 CRITICAL

OS Command injection in Ajax PHP files via HTTP Request, allows to execute system commands by exploiting variables. This issue affects Pandora FMS: from 700 …

Jun 10, 2024
CVE-2024-35305
9.8 CRITICAL

Unauth Time-Based SQL Injection in API allows to exploit HTTP request Authorization header. This issue affects Pandora FMS: from 700 through <777.

Jun 10, 2024
CVE-2024-35304
9.8 CRITICAL

System command injection through Netflow function due to improper input validation, allowing attackers to execute arbitrary system commands. This issue affects Pandora FMS: from 700 …

Jun 10, 2024
CVE-2024-3700
9.8 CRITICAL

Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among …

Jun 10, 2024
CVE-2024-3699
9.8 CRITICAL

Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among …

Jun 10, 2024
CVE-2024-1228
9.8 CRITICAL

Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among …

Jun 10, 2024
CVE-2024-4577
9.8 CRITICAL KEV

In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up …

Jun 9, 2024
CVE-2024-33565
9.1 CRITICAL

Missing Authorization vulnerability in UkrSolution Barcode Scanner with Inventory & Order Manager.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through 1.5.3.

Jun 9, 2024
CVE-2024-31244
9.8 CRITICAL

Missing Authorization vulnerability in Bricksforge.This issue affects Bricksforge: from n/a through 2.0.17.

Jun 9, 2024
CVE-2024-4146
9.8 CRITICAL

In lunary-ai/lunary version v1.2.13, an incorrect authorization vulnerability exists that allows unauthorized users to access and manipulate projects within an organization they should not have …

Jun 8, 2024
CVE-2024-37407
9.1 CRITICAL

Libarchive before 3.7.4 allows name out-of-bounds access when a ZIP archive has an empty-name file and mac-ext is enabled. This occurs in slurp_central_directory in archive_read_support_format_zip.c.

Jun 8, 2024
CVE-2024-37388
9.1 CRITICAL

An XML External Entity (XXE) vulnerability in the ebookmeta.get_metadata function of lxml before v4.9.1 allows attackers to access sensitive information or cause a Denial of …

Jun 7, 2024
CVE-2024-30163
9.8 CRITICAL

Invision Community before 4.7.16 allow SQL injection via the applications/nexus/modules/front/store/store.php IPS\nexus\modules\front\store\_store::_categoryView() method, where user input passed through the filter request parameter is not properly sanitized …

Jun 7, 2024
CVE-2024-36673
9.8 CRITICAL

Sourcecodester Pharmacy/Medical Store Point of Sale System 1.0 is vulnerable SQL Injection via login.php. This vulnerability stems from inadequate validation of user inputs for the …

Jun 7, 2024
CVE-2024-4620
9.8 CRITICAL

The ARForms - Premium WordPress Form Builder Plugin WordPress plugin before 6.6 allows unauthenticated users to modify uploaded files in such a way that PHP …

Jun 7, 2024
CVE-2024-3592
9.9 CRITICAL

The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'question_id' …

Jun 7, 2024
CVE-2024-37385
9.8 CRITICAL

Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_identify_path. NOTE: this issue exists because of an incomplete …

Jun 7, 2024
CVE-2024-24192
9.1 CRITICAL

robdns commit d76d2e6 was discovered to contain a heap overflow via the component block->filename at /src/zonefile-insertion.c.

Jun 6, 2024
CVE-2024-32752
9.1 CRITICAL

The iSTAR door controllers running firmware prior to version 6.6.B, does not support authenticated communications with ICU, which may allow an attacker to gain unauthorized …

Jun 6, 2024
CVE-2024-22074
9.8 CRITICAL

Dynamsoft Service 1.8.1025 through 1.8.2013, 1.7.0330 through 1.7.2531, 1.6.0428 through 1.6.1112, 1.5.0625 through 1.5.3116, 1.4.0618 through 1.4.1230, and 1.0.516 through 1.3.0115 has Incorrect Access Control. …

Jun 6, 2024
CVE-2024-5328
9.3 CRITICAL

A Server-Side Request Forgery (SSRF) vulnerability exists in the lunary-ai/lunary application, specifically within the endpoint '/auth/saml/tto/download-idp-xml'. The vulnerability arises due to the application's failure to …

Jun 6, 2024
CVE-2024-4320
9.8 CRITICAL

A remote code execution (RCE) vulnerability exists in the '/install_extension' endpoint of the parisneo/lollms-webui application, specifically within the `@router.post("/install_extension")` route handler. The vulnerability arises due …

Jun 6, 2024
CVE-2024-3429
9.8 CRITICAL

A path traversal vulnerability exists in the parisneo/lollms application, specifically within the `sanitize_path_from_endpoint` and `sanitize_path` functions in `lollms_core\lollms\security.py`. This vulnerability allows for arbitrary file reading …

Jun 6, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.