CVE Database

9973+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-30990
9.8 CRITICAL

SQL Injection vulnerability in the "Invoices" page in phpgurukul Client Management System using PHP & MySQL 1.1 allows attacker to execute arbitrary SQL commands via …

Apr 17, 2024
CVE-2024-32161
9.8 CRITICAL

jizhiCMS 2.5 suffers from a File upload vulnerability.

Apr 17, 2024
CVE-2024-30985
9.8 CRITICAL

SQL Injection vulnerability in "B/W Dates Reports" page in phpgurukul Client Management System using PHP & MySQL 1.1 allows attacker to execute arbitrary SQL commands …

Apr 17, 2024
CVE-2024-30982
9.8 CRITICAL

SQL Injection vulnerability in phpgurukul Cyber Cafe Management System Using PHP & MySQL 1.0 allows attackers to run arbitrary SQL commands via the upid parameter …

Apr 17, 2024
CVE-2024-30981
9.8 CRITICAL

SQL Injection vulnerability in /edit-computer-detail.php in phpgurukul Cyber Cafe Management System Using PHP & MySQL v1.0 allows attackers to run arbitrary SQL commands via editid …

Apr 17, 2024
CVE-2024-30980
9.8 CRITICAL

SQL Injection vulnerability in phpgurukul Cyber Cafe Management System Using PHP & MySQL 1.0 allows attackers to run arbitrary SQL commands via the Computer Location …

Apr 17, 2024
CVE-2024-32318
9.8 CRITICAL

Tenda AC500 V2.0.1.9(1307) firmware has a stack overflow vulnerability via the vlan parameter in the formSetVlanInfo function.

Apr 17, 2024
CVE-2024-32286
9.8 CRITICAL

Tenda W30E v1.0 V1.0.1.25(633) firmware has a stack overflow vulnerability located via the page parameter in the fromVirtualSer function.

Apr 17, 2024
CVE-2024-32301
9.8 CRITICAL

Tenda AC7V1.0 v15.03.06.44 firmware has a stack overflow vulnerability via the PPW parameter in the fromWizardHandle function.

Apr 17, 2024
CVE-2023-39367
9.1 CRITICAL

An OS command injection vulnerability exists in the web interface mac2name functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted HTTP request can …

Apr 17, 2024
CVE-2024-32514
9.9 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Poll Maker & Voting Plugin Team (InfoTheme) WP Poll Maker.This issue affects WP Poll Maker: from …

Apr 17, 2024
CVE-2024-21082
9.8 CRITICAL

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: XML Services). Supported versions that are affected are 7.0.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability …

Apr 16, 2024
CVE-2024-21071
9.1 CRITICAL

Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Admin Screens and Grants UI). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable …

Apr 16, 2024
CVE-2024-21014
9.8 CRITICAL

Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: Simphony Enterprise Server). Supported versions that are affected are 19.1.0-19.5.4. Easily …

Apr 16, 2024
CVE-2024-21010
9.9 CRITICAL

Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: Simphony Enterprise Server). Supported versions that are affected are 19.1.0-19.5.4. Easily …

Apr 16, 2024
CVE-2024-20997
9.9 CRITICAL

Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: Simphony Enterprise Server). Supported versions that are affected are 19.1.0-19.5.4. Easily …

Apr 16, 2024
CVE-2024-3660
9.8 CRITICAL

A arbitrary code injection vulnerability in TensorFlow's Keras framework (<2.13) allows attackers to execute arbitrary code with the same permissions as the application using a …

Apr 16, 2024
CVE-2024-3863
9.8 CRITICAL

The executable file warning was not presented when downloading .xrm-ms files. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.* This …

Apr 16, 2024
CVE-2024-32027
9.1 CRITICAL

Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss v22.6.1 is vulnerable to command injection in `finetune_gui.py` This vulnerability is fixed in 23.1.5.

Apr 16, 2024
CVE-2024-32026
9.1 CRITICAL

Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to a command injection in `git_caption_gui.py`. This vulnerability is fixed in 23.1.5.

Apr 16, 2024
CVE-2024-32025
9.1 CRITICAL

Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to a command injection in `group_images_gui.py`. This vulnerability is fixed in 23.1.5.

Apr 16, 2024
CVE-2024-32022
9.1 CRITICAL

Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to command injection in basic_caption_gui.py. This vulnerability is fixed in 23.1.5.

Apr 16, 2024
CVE-2024-3871
9.8 CRITICAL

The Delta Electronics DVW-W02W2-E2 devices expose a web administration interface to users. This interface implements multiple features that are affected by command injections and stack …

Apr 16, 2024
CVE-2024-3573
9.3 CRITICAL

mlflow/mlflow is vulnerable to Local File Inclusion (LFI) due to improper parsing of URIs, allowing attackers to bypass checks and read arbitrary files on the …

Apr 16, 2024
CVE-2024-3271
9.8 CRITICAL

A command injection vulnerability exists in the run-llama/llama_index repository, specifically within the safe_eval function. Attackers can bypass the intended security mechanism, which checks for the …

Apr 16, 2024
CVE-2024-2912
10.0 CRITICAL

An insecure deserialization vulnerability exists in the BentoML framework, allowing remote code execution (RCE) by sending a specially crafted POST request. By exploiting this vulnerability, …

Apr 16, 2024
CVE-2024-2083
9.9 CRITICAL

A directory traversal vulnerability exists in the zenml-io/zenml repository, specifically within the /api/v1/steps endpoint. Attackers can exploit this vulnerability by manipulating the 'logs' URI path …

Apr 16, 2024
CVE-2024-1739
9.1 CRITICAL

lunary-ai/lunary is vulnerable to an authentication issue due to improper validation of email addresses during the signup process. Specifically, the server fails to treat email …

Apr 16, 2024
CVE-2024-1601
9.8 CRITICAL

An SQL injection vulnerability exists in the `delete_discussion()` function of the parisneo/lollms-webui application, allowing an attacker to delete all discussions and message data. The vulnerability …

Apr 16, 2024
CVE-2024-0404
9.1 CRITICAL

A mass assignment vulnerability exists in the `/api/invite/:code` endpoint of the mintplex-labs/anything-llm repository, allowing unauthorized creation of high-privileged accounts. By intercepting and modifying the HTTP …

Apr 16, 2024
CVE-2024-31650
9.6 CRITICAL

A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload …

Apr 15, 2024
CVE-2024-28557
9.8 CRITICAL

SQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via crafted …

Apr 15, 2024
CVE-2024-28556
9.8 CRITICAL

SQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via crafted …

Apr 15, 2024
CVE-2024-24486
9.1 CRITICAL

An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to edit device settings via the SAVE EEP_DATA command.

Apr 15, 2024
CVE-2024-28056
9.8 CRITICAL

Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify projects. When the Authentication component is removed …

Apr 15, 2024
CVE-2023-48710
9.8 CRITICAL

iTop is an IT service management platform. Files from the `env-production` folder can be retrieved even though they should have restricted access. Hopefully, there is …

Apr 15, 2024
CVE-2024-3781
9.1 CRITICAL

Command injection vulnerability in the operating system. Improper neutralisation of special elements in Active Directory integration allows the intended command to be modified when sent …

Apr 15, 2024
CVE-2024-23486
9.8 CRITICAL

Plaintext storage of a password issue exists in BUFFALO wireless LAN routers, which may allow a network-adjacent unauthenticated attacker with access to the product's login …

Apr 15, 2024
CVE-2024-3701
9.8 CRITICAL

The system application (com.transsion.kolun.aiservice) component does not perform an authentication check, which allows attackers to perform malicious exploitations and affect system services.

Apr 15, 2024
CVE-2024-32128
9.3 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Realtyna Realtyna Organic IDX plugin.This issue affects Realtyna Organic IDX plugin: …

Apr 15, 2024
CVE-2024-3777
9.8 CRITICAL

The password reset feature of Ai3 QbiBot lacks proper access control, allowing unauthenticated remote attackers to reset any user's password.

Apr 15, 2024
CVE-2024-29844
9.8 CRITICAL

Default credentials on the Web Interface of Evolution Controller 2.x allows anyone to log in to the server directly to perform administrative functions. Upon installation …

Apr 15, 2024
CVE-2024-29836
9.8 CRITICAL

The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below contains poorly configured access control, allowing for an unauthenticated attacker to update and add user …

Apr 15, 2024
CVE-2024-3765
9.8 CRITICAL

A vulnerability classified as critical was found in Xiongmai AHB7804R-MH-V2, AHB8004T-GL, AHB8008T-GL, AHB7004T-GS-V3, AHB7004T-MHV2, AHB8032F-LME and XM530_R80X30-PQ_8M. Affected by this vulnerability is an unknown functionality …

Apr 14, 2024
CVE-2024-28878
9.6 CRITICAL

IO-1020 Micro ELD downloads source code or an executable from an adjacent location and executes the code without sufficiently verifying the origin or integrity of …

Apr 12, 2024
CVE-2024-3704
9.8 CRITICAL

SQL Injection Vulnerability has been found on OpenGnsys product affecting version 1.1.1d (Espeto). This vulnerability allows an attacker to inject malicious SQL code into login …

Apr 12, 2024
CVE-2023-51409
10.0 CRITICAL

Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 1.9.98.

Apr 12, 2024
CVE-2024-31818
9.8 CRITICAL

Directory Traversal vulnerability in DerbyNet v.9.0 allows a remote attacker to execute arbitrary code via the page parameter of the kiosk.php component.

Apr 12, 2024
CVE-2024-28718
9.8 CRITICAL

An issue in OpenStack magnum yoga-eom version allows a remote attacker to execute arbitrary code via the cert_manager.py. component.

Apr 12, 2024
CVE-2024-3400
10.0 CRITICAL KEV

A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions …

Apr 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.