CVE Database

121173+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-39721
7.5 HIGH

An issue was discovered in Ollama before 0.1.34. The CreateModelHandler function uses os.Open to read a file until completion. The req.Path parameter is user-controlled and …

Oct 31, 2024
CVE-2024-39720
8.2 HIGH

An issue was discovered in Ollama before 0.1.46. An attacker can use two HTTP requests to upload a malformed GGUF file containing just 4 bytes …

Oct 31, 2024
CVE-2024-39719
7.5 HIGH

An issue was discovered in Ollama through 0.3.14. File existence disclosure can occur via api/create. When calling the CreateModel route with a path parameter that …

Oct 31, 2024
CVE-2024-51066
7.5 HIGH

An Insecure Direct Object Reference (IDOR) vulnerability in appointment-detail.php in Phpgurukul's Beauty Parlour Management System v1.1 allows unauthorized access to the Personally Identifiable Information (PII) …

Oct 31, 2024
CVE-2024-51065
9.8 CRITICAL

Phpgurukul Beauty Parlour Management System v1.1 is vulnerable to SQL Injection in admin/index.php via the the username parameter.

Oct 31, 2024
CVE-2024-51064
9.8 CRITICAL

Phpgurukul Teachers Record Management System v2.1 is vulnerable to SQL Injection via the tid parameter to admin/queries.php.

Oct 31, 2024
CVE-2024-51063
9.1 CRITICAL

Phpgurukul Teachers Record Management System v2.1 is vulnerable to SQL Injection in add-teacher.php via the mobile number or email parameter.

Oct 31, 2024
CVE-2024-51060
9.1 CRITICAL

Projectworlds Online Admission System v1 is vulnerable to SQL Injection in index.php via the 'a_id' parameter.

Oct 31, 2024
CVE-2024-50802
6.0 MEDIUM

A SQL Injection vulnerability was discovered in AbanteCart 1.4.0 in the update() function in public_html/admin/controller/responses/listing_grid/email_templates.php. The vulnerability is exploitable via the id parameter.

Oct 31, 2024
CVE-2024-50801
6.0 MEDIUM

A SQL Injection vulnerability was discovered in AbanteCart 1.4.0 in the update() function in public_html/admin/controller/responses/listing_grid/collections.php. The vulnerability is exploitable via the id parameter.

Oct 31, 2024
CVE-2024-48200
8.4 HIGH

An issue in MobaXterm v24.2 allows a local attacker to escalate privileges and execute arbitrary code via the remove function of the MobaXterm MSI is …

Oct 31, 2024
CVE-2024-42515
9.9 CRITICAL

Glossarizer through 1.5.2 improperly tries to convert text into HTML. Even though the application itself escapes special characters (e.g., <>), the underlying library converts these …

Oct 31, 2024
CVE-2024-39332
9.8 CRITICAL

Webswing 23.2.2 allows remote attackers to modify client-side JavaScript code to achieve path traversal, likely leading to remote code execution via modification of shell scripts …

Oct 31, 2024
CVE-2024-10573
6.7 MEDIUM

An out-of-bounds write flaw was found in mpg123 when handling crafted streams. When decoding PCM, the libmpg123 may write past the end of a heap-located …

Oct 31, 2024
CVE-2023-52045
6.1 MEDIUM

Studio-42 eLfinder 2.1.62 contains a filename restriction bypass leading to a persistent Cross-site Scripting (XSS) vulnerability.

Oct 31, 2024
CVE-2023-52044
9.8 CRITICAL

Studio-42 eLfinder 2.1.62 is vulnerable to Remote Code Execution (RCE) as there is no restriction for uploading files with the .php8 extension.

Oct 31, 2024
CVE-2024-51482
9.9 CRITICAL

ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder v1.37.* <= 1.37.64 is vulnerable to boolean-based SQL Injection in function of web/ajax/event.php. This …

Oct 31, 2024
CVE-2024-50356
0.0 NONE

Press, a Frappe custom app that runs Frappe Cloud, manages infrastructure, subscription, marketplace, and software-as-a-service (SaaS). The password could be reset by anyone who have …

Oct 31, 2024
CVE-2024-50347

Laravel Reverb provides a real-time WebSocket communication backend for Laravel applications. Prior to 1.4.0, there is an issue where verification signatures for requests sent to …

Oct 31, 2024
CVE-2024-7883
3.7 LOW

When using Arm Cortex-M Security Extensions (CMSE), Secure stack contents can be leaked to Non-secure state via floating-point registers when a Secure to Non-secure function …

Oct 31, 2024
CVE-2024-51481

Nix is a package manager for Linux and other Unix systems. On macOS, built-in builders (such as `builtin:fetchurl`, exposed to users with `import <nix/fetchurl.nix>`) were …

Oct 31, 2024
CVE-2024-51478
9.9 CRITICAL

YesWiki is a wiki system written in PHP. Prior to 4.4.5, the use of a weak cryptographic algorithm and a hard-coded salt to hash the …

Oct 31, 2024
CVE-2024-51430
6.4 MEDIUM

Cross Site Scripting vulnerability in online diagnostic lab management system using php v.1.0 allows a remote attacker to execute arbitrary code via the Test Name …

Oct 31, 2024
CVE-2024-8185
7.5 HIGH

Vault Community and Vault Enterprise (“Vault”) clusters using Vault’s Integrated Storage backend are vulnerable to a denial-of-service (DoS) attack through memory exhaustion through a Raft …

Oct 31, 2024
CVE-2024-51260
9.8 CRITICAL

DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the acme_process function.

Oct 31, 2024
CVE-2024-51255
9.8 CRITICAL

DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the ruequest_certificate function.

Oct 31, 2024
CVE-2024-50354
5.5 MEDIUM

gnark is a fast zk-SNARK library that offers a high-level API to design circuits. In gnark 0.11.0 and earlier, deserialization of Groth16 verification keys allocate …

Oct 31, 2024
CVE-2024-8553
6.3 MEDIUM

A vulnerability was found in Foreman's loader macros introduced with report templates. These macros may allow an authenticated user with permissions to view and create …

Oct 31, 2024
CVE-2024-48910
9.1 CRITICAL

DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify was vulnerable to prototype pollution. This vulnerability is fixed in 2.4.2.

Oct 31, 2024
CVE-2024-51259
9.8 CRITICAL

DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the setup_cacertificate function.

Oct 31, 2024
CVE-2024-51254
8.8 HIGH

DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the sign_cacertificate function.

Oct 31, 2024
CVE-2024-42835
9.8 CRITICAL

langflow v1.0.12 was discovered to contain a remote code execution (RCE) vulnerability via the PythonCodeTool component.

Oct 31, 2024
CVE-2024-8934
6.5 MEDIUM

A local user with administrative access rights can enter specialy crafted values for settings at the user interface (UI) of the TwinCAT Package Manager which …

Oct 31, 2024
CVE-2024-10454
6.1 MEDIUM

Clickjacking vulnerability in Clibo Manager v1.1.9.12 in the '/public/login' directory, a login panel. This vulnerability occurs due to the absence of an X-Frame-Options server-side header. …

Oct 31, 2024
CVE-2024-49685
5.4 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Syed Balkhi Custom Twitter Feeds (Tweets Widget) custom-twitter-feeds allows Cross Site Request Forgery.This issue affects Custom Twitter Feeds (Tweets …

Oct 31, 2024
CVE-2024-49674
9.6 CRITICAL

Cross-Site Request Forgery (CSRF) vulnerability in lukashuser EKC Tournament Manager ekc-tournament-manager allows Upload a Web Shell to a Web Server.This issue affects EKC Tournament Manager: …

Oct 31, 2024
CVE-2024-43984
9.6 CRITICAL

Cross-Site Request Forgery (CSRF) vulnerability in Podlove Podlove Podcast Publisher allows Code Injection.This issue affects Podlove Podcast Publisher: from n/a through 4.1.13.

Oct 31, 2024
CVE-2024-43933
4.3 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Amauri WPMobile.App wpappninja allows Stored XSS.This issue affects WPMobile.App: from n/a through <= …

Oct 31, 2024
CVE-2024-43930
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in eyecix JobSearch allows Cross Site Request Forgery.This issue affects JobSearch: from n/a through 2.5.3.

Oct 31, 2024
CVE-2024-43383
8.0 HIGH

Deserialization of Untrusted Data vulnerability in Apache Lucene.Net.Replicator. This issue affects Apache Lucene.NET's Replicator library: from 4.8.0-beta00005 through 4.8.0-beta00016. An attacker that can intercept traffic …

Oct 31, 2024
CVE-2024-30149
4.8 MEDIUM

HCL AppScan Source <= 10.6.0 does not properly validate a TLS/SSL certificate for an executable.

Oct 31, 2024
CVE-2024-9446
6.4 MEDIUM

The WP Simple Anchors Links plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpanchor shortcode in all versions up to, and …

Oct 31, 2024
CVE-2024-9434
6.1 MEDIUM

The WPGlobus Translate Options plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due to …

Oct 31, 2024
CVE-2024-9430
5.3 MEDIUM

The Get Quote For Woocommerce – Request A Quote For Woocommerce plugin for WordPress is vulnerable to unauthorized access of Quote data due to a …

Oct 31, 2024
CVE-2024-9165
6.4 MEDIUM

The Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions …

Oct 31, 2024
CVE-2024-9700
5.3 MEDIUM

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions …

Oct 31, 2024
CVE-2024-10392
9.8 CRITICAL

The AI Power: Complete AI Pack plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'handle_image_upload' function …

Oct 31, 2024
CVE-2024-21537
8.8 HIGH

Versions of the package lilconfig from 3.1.0 and before 3.1.1 are vulnerable to Arbitrary Code Execution due to the insecure usage of eval in the …

Oct 31, 2024
CVE-2024-9708
6.4 MEDIUM

The Easy SVG Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.1 …

Oct 31, 2024
CVE-2024-48311
8.8 HIGH

Piwigo v14.5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Edit album function.

Oct 31, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.