CVE Database

9973+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-22718
9.6 CRITICAL

Cross Site Scripting (XSS) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary code via the client_id parameter in the application URL.

Apr 11, 2024
CVE-2024-31678
9.8 CRITICAL

Sourcecodester Loan Management System v1.0 is vulnerable to SQL Injection via the "password" parameter in the "login.php" file.

Apr 11, 2024
CVE-2024-21508
9.8 CRITICAL

Versions of the package mysql2 before 3.9.4 are vulnerable to Remote Code Execution (RCE) via the readCodeFor function due to improper validation of the supportBigNumbers …

Apr 11, 2024
CVE-2024-29937
9.8 CRITICAL

NFS in a BSD derived codebase, as used in OpenBSD through 7.4 and FreeBSD through 14.0-RELEASE, allows remote attackers to execute arbitrary code via a …

Apr 11, 2024
CVE-2024-27683
9.8 CRITICAL

D-Link Go-RT-AC750 GORTAC750_A1_FW_v101b03 contains a stack-based buffer overflow via the function hnap_main. An attacker can send a POST request to trigger the vulnerablilify.

Apr 11, 2024
CVE-2024-25912
9.8 CRITICAL

Missing Authorization vulnerability in Skymoonlabs MoveTo.This issue affects MoveTo: from n/a through 6.2.

Apr 11, 2024
CVE-2024-31997
9.9 CRITICAL

XWiki Platform is a generic wiki platform. Prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, parameters of UI extensions are always interpreted as Velocity code and …

Apr 10, 2024
CVE-2024-31996
10.0 CRITICAL

XWiki Platform is a generic wiki platform. Starting in version 3.0.1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, the HTML escaping of escaping tool …

Apr 10, 2024
CVE-2024-31988
9.6 CRITICAL

XWiki Platform is a generic wiki platform. Starting in version 13.9-rc-1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, when the realtime editor is installed …

Apr 10, 2024
CVE-2024-31987
9.9 CRITICAL

XWiki Platform is a generic wiki platform. Starting in version 6.4-milestone-1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, any user who can edit any …

Apr 10, 2024
CVE-2024-31986
9.0 CRITICAL

XWiki Platform is a generic wiki platform. Starting in version 3.1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, by creating a document with a …

Apr 10, 2024
CVE-2024-31984
9.9 CRITICAL

XWiki Platform is a generic wiki platform. Starting in version 7.2-rc-1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, by creating a document with a …

Apr 10, 2024
CVE-2024-31983
9.9 CRITICAL

XWiki Platform is a generic wiki platform. In multilingual wikis, translations can be edited by any user who has edit right, circumventing the rights that …

Apr 10, 2024
CVE-2024-31982
10.0 CRITICAL

XWiki Platform is a generic wiki platform. Starting in version 2.4-milestone-1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, XWiki's database search allows remote code …

Apr 10, 2024
CVE-2024-31981
9.9 CRITICAL

XWiki Platform is a generic wiki platform. Starting in version 3.0.1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, remote code execution is possible via …

Apr 10, 2024
CVE-2024-31819
9.8 CRITICAL

An issue in WWBN AVideo v.12.4 through v.14.2 allows a remote attacker to execute arbitrary code via the systemRootPath parameter of the submitIndex.php component.

Apr 10, 2024
CVE-2024-31465
9.9 CRITICAL

XWiki Platform is a generic wiki platform. Starting in version 5.0-rc-1 and prior to versions 14.10.20, 15.5.4, and 15.9-rc-1, any user with edit right on …

Apr 10, 2024
CVE-2024-29500
9.8 CRITICAL

An issue in the kiosk mode of Secure Lockdown Multi Application Edition v2.00.219 allows attackers to execute arbitrary code via running a ClickOnce application instance.

Apr 10, 2024
CVE-2024-3157
9.6 CRITICAL

Out of bounds memory access in Compositing in Google Chrome prior to 123.0.6312.122 allowed a remote attacker who had compromised the GPU process to potentially …

Apr 10, 2024
CVE-2024-31461
9.1 CRITICAL

Plane, an open-source project management tool, has a Server-Side Request Forgery (SSRF) vulnerability in versions prior to 0.17-dev. This issue may allow an attacker to …

Apr 10, 2024
CVE-2024-31214
9.6 CRITICAL

Traccar is an open source GPS tracking system. Traccar versions 5.1 through 5.12 allow arbitrary files to be uploaded through the device image upload API. …

Apr 10, 2024
CVE-2024-3568
9.6 CRITICAL

The huggingface/transformers library is vulnerable to arbitrary code execution through deserialization of untrusted data within the `load_repo_checkpoint()` function of the `TFPreTrainedModel()` class. Attackers can execute …

Apr 10, 2024
CVE-2024-3098
9.8 CRITICAL

A vulnerability was identified in the `exec_utils` class of the `llama_index` package, specifically within the `safe_eval` function, allowing for prompt injection leading to arbitrary code …

Apr 10, 2024
CVE-2024-3025
9.9 CRITICAL

mintplex-labs/anything-llm is vulnerable to path traversal attacks due to insufficient validation of user-supplied input in the logo filename functionality. Attackers can exploit this vulnerability by …

Apr 10, 2024
CVE-2024-2952
9.8 CRITICAL

BerriAI/litellm is vulnerable to Server-Side Template Injection (SSTI) via the `/completions` endpoint. The vulnerability arises from the `hf_chat_template` method processing the `chat_template` parameter from the …

Apr 10, 2024
CVE-2024-2221
9.8 CRITICAL

qdrant/qdrant is vulnerable to a path traversal and arbitrary file upload vulnerability via the `/collections/{COLLECTION}/snapshots/upload` endpoint, specifically through the `snapshot` parameter. This vulnerability allows attackers …

Apr 10, 2024
CVE-2024-2195
9.8 CRITICAL

A critical Remote Code Execution (RCE) vulnerability was identified in the aimhubio/aim project, specifically within the `/api/runs/search/run/` endpoint, affecting versions >= 3.0.0. The vulnerability resides …

Apr 10, 2024
CVE-2024-2029
9.8 CRITICAL

A command injection vulnerability exists in the `TranscriptEndpoint` of mudler/localai, specifically within the `audioToWav` function used for converting audio files to WAV format for transcription. …

Apr 10, 2024
CVE-2024-1741
9.1 CRITICAL

lunary-ai/lunary version 1.0.1 is vulnerable to improper authorization, allowing removed members to read, create, modify, and delete prompt templates using an old authorization token. Despite …

Apr 10, 2024
CVE-2024-1740
9.1 CRITICAL

In lunary-ai/lunary version 1.0.1, a vulnerability exists where a user removed from an organization can still read, create, modify, and delete logs by re-using an …

Apr 10, 2024
CVE-2024-1643
9.1 CRITICAL

By knowing an organization's ID, an attacker can join the organization without permission and gain the ability to read and modify all data within that …

Apr 10, 2024
CVE-2024-1600
9.3 CRITICAL

A Local File Inclusion (LFI) vulnerability exists in the parisneo/lollms-webui application, specifically within the `/personalities` route. An attacker can exploit this vulnerability by crafting a …

Apr 10, 2024
CVE-2024-1520
9.8 CRITICAL

An OS Command Injection vulnerability exists in the '/open_code_folder' endpoint of the parisneo/lollms-webui application, due to improper validation of user-supplied input in the 'discussion_id' parameter. …

Apr 10, 2024
CVE-2024-1511
9.8 CRITICAL

The parisneo/lollms-webui repository is susceptible to a path traversal vulnerability due to inadequate validation of user-supplied file paths. This flaw allows an unauthenticated attacker to …

Apr 10, 2024
CVE-2024-3566
9.8 CRITICAL

A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess function when the specific conditions …

Apr 10, 2024
CVE-2024-23080
9.1 CRITICAL

Joda Time v2.12.5 was discovered to contain a NullPointerException via the component org.joda.time.format.PeriodFormat::wordBased(Locale). NOTE: this is disputed by multiple third parties who believe there was …

Apr 10, 2024
CVE-2024-20758
9.0 CRITICAL

Adobe Commerce versions 2.4.6-p4, 2.4.5-p6, 2.4.4-p7, 2.4.7-beta3 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution on …

Apr 10, 2024
CVE-2024-3120
9.0 CRITICAL

A stack-buffer overflow vulnerability exists in all versions of sngrep since v1.4.1. The flaw is due to inadequate bounds checking when copying 'Content-Length' and 'Warning' …

Apr 10, 2024
CVE-2024-3119
9.0 CRITICAL

A buffer overflow vulnerability exists in all versions of sngrep since v0.4.2, due to improper handling of 'Call-ID' and 'X-Call-ID' SIP headers. The functions sip_get_callid …

Apr 10, 2024
CVE-2024-3136
9.8 CRITICAL

The MasterStudy LMS plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.3.3 via the 'template' parameter. This …

Apr 9, 2024
CVE-2024-2804
9.8 CRITICAL

The Network Summary plugin for WordPress is vulnerable to SQL Injection via the 'category' parameter in all versions up to, and including, 2.0.11 due to …

Apr 9, 2024
CVE-2024-1813
9.8 CRITICAL

The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.11.0 via deserialization of untrusted …

Apr 9, 2024
CVE-2024-24576
10.0 CRITICAL

Rust is a programming language. The Rust Security Response WG was notified that the Rust standard library prior to version 1.77.2 did not properly escape …

Apr 9, 2024
CVE-2024-29990
9.0 CRITICAL

Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability

Apr 9, 2024
CVE-2024-31866
9.8 CRITICAL

Improper Encoding or Escaping of Output vulnerability in Apache Zeppelin. The attackers can execute shell scripts or malicious code by overriding configuration like ZEPPELIN_INTP_CLASSPATH_OVERRIDES. This …

Apr 9, 2024
CVE-2024-31864
9.8 CRITICAL

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Zeppelin. The attacker can inject sensitive configuration or malicious code when connecting MySQL database …

Apr 9, 2024
CVE-2023-45590
9.6 CRITICAL

An improper control of generation of code ('code injection') in Fortinet FortiClientLinux version 7.2.0, 7.0.6 through 7.0.10 and 7.0.3 through 7.0.4 allows attacker to execute …

Apr 9, 2024
CVE-2023-6320
9.1 CRITICAL

A command injection vulnerability exists in the com.webos.service.connectionmanager/tv/setVlanStaticAddress endpoint on webOS versions 5 and 6. A series of specially crafted requests can lead to command …

Apr 9, 2024
CVE-2023-6319
9.1 CRITICAL

A command injection vulnerability exists in the getAudioMetadata method from the com.webos.service.attachedstoragemanager service on webOS version 4 through 7. A series of specially crafted requests …

Apr 9, 2024
CVE-2023-6318
9.1 CRITICAL

A command injection vulnerability exists in the processAnalyticsReport method from the com.webos.service.cloudupload service on webOS version 5 through 7. A series of specially crafted requests …

Apr 9, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.