CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-38983
9.8 CRITICAL

Prototype Pollution in alykoshin mini-deep-assign v0.0.8 allows an attacker to execute arbitrary code or cause a Denial of Service (DoS) and cause other impacts via …

Jul 30, 2024
CVE-2024-41945
3.1 LOW

fuels-ts is a library for interacting with Fuel v2. The typescript SDK has no awareness of to-be-spent transactions causing some transactions to fail or silently …

Jul 30, 2024
CVE-2024-41611
9.8 CRITICAL

In D-Link DIR-860L REVA FIRMWARE PATCH 1.10..B04, the Telnet service contains hardcoded credentials, enabling attackers to log in remotely to the Telnet service and perform …

Jul 30, 2024
CVE-2024-41610
9.8 CRITICAL

D-Link DIR-820LW REVB FIRMWARE PATCH 2.03.B01_TC contains hardcoded credentials in the Telnet service, enabling attackers to log in remotely to the Telnet service and perform …

Jul 30, 2024
CVE-2024-39012
9.8 CRITICAL

ais-ltd strategyen v0.4.0 was discovered to contain a prototype pollution via the function mergeObjects. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 30, 2024
CVE-2024-39011
9.8 CRITICAL

Prototype Pollution in chargeover redoc v2.0.9-rc.69 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) and cause other impacts via the …

Jul 30, 2024
CVE-2024-39010
9.8 CRITICAL

chase-moskal snapstate v0.0.9 was discovered to contain a prototype pollution via the function attemptNestedProperty. This vulnerability allows attackers to execute arbitrary code or cause a …

Jul 30, 2024
CVE-2024-38986
9.8 CRITICAL

Prototype Pollution in 75lb deep-merge 1.1.1 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) and cause other impacts via merge …

Jul 30, 2024
CVE-2024-38984
9.8 CRITICAL

Prototype Pollution in lukebond json-override 0.2.0 allows attackers to to execute arbitrary code or cause a Denial of Service (DoS) via the __proto__ property.

Jul 30, 2024
CVE-2024-36572
9.8 CRITICAL

Prototype pollution in allpro form-manager 0.7.4 allows attackers to run arbitrary code and cause other impacts via the functions setDefaults, mergeBranch, and Object.setObjectValue.

Jul 30, 2024
CVE-2023-33976
7.5 HIGH

TensorFlow is an end-to-end open source platform for machine learning. `array_ops.upper_bound` causes a segfault when not given a rank 2 tensor. The fix will be …

Jul 30, 2024
CVE-2024-5250
3.5 LOW

In versions of Akana API Platform prior to 2024.1.0 overly verbose errors can be found in SAML integrations

Jul 30, 2024
CVE-2024-5249
5.4 MEDIUM

In versions of Akana API Platform prior to 2024.1.0, SAML tokens can be replayed.

Jul 30, 2024
CVE-2024-41443
5.5 MEDIUM

A stack overflow in the function cp_dynamic() (/vendor/cute_png.h) of hicolor v0.5.0 allows attackers to cause a Denial of Service (DoS) via a crafted PNG file.

Jul 30, 2024
CVE-2024-41440
6.2 MEDIUM

A heap buffer overflow in the function png_quantize() of hicolor v0.5.0 allows attackers to cause a Denial of Service (DoS) via a crafted PNG file.

Jul 30, 2024
CVE-2024-41439
5.5 MEDIUM

A heap buffer overflow in the function cp_block() (/vendor/cute_png.h) of hicolor v0.5.0 allows attackers to cause a Denial of Service (DoS) via a crafted PNG …

Jul 30, 2024
CVE-2024-41438
6.2 MEDIUM

A heap buffer overflow in the function cp_stored() (/vendor/cute_png.h) of hicolor v0.5.0 allows attackers to cause a Denial of Service (DoS) via a crafted PNG …

Jul 30, 2024
CVE-2024-41437
5.5 MEDIUM

A heap buffer overflow in the function cp_unfilter() (/vendor/cute_png.h) of hicolor v0.5.0 allows attackers to cause a Denial of Service (DoS) via a crafted PNG …

Jul 30, 2024
CVE-2024-3930
6.3 MEDIUM

In versions of Akana API Platform prior to 2024.1.0 a flaw resulting in XML External Entity (XXE) was discovered.

Jul 30, 2024
CVE-2024-41943
4.6 MEDIUM

I, Librarian is an open-source version of a PDF managing SaaS. PDF notes are displayed on the Item Summary page without any form of validation …

Jul 30, 2024
CVE-2024-41305
4.7 MEDIUM

A Server-Side Request Forgery (SSRF) in the Plugins Page of WonderCMS v3.4.3 allows attackers to force the application to make arbitrary requests via injection of …

Jul 30, 2024
CVE-2024-41304
5.4 MEDIUM

An arbitrary file upload vulnerability in the uploadFileAction() function of WonderCMS v3.4.3 allows attackers to execute arbitrary code via a crafted SVG file.

Jul 30, 2024
CVE-2024-7297
8.8 HIGH

Langflow versions prior to 1.0.13 suffer from a Privilege Escalation vulnerability, allowing a remote and low privileged attacker to gain super admin privileges by performing …

Jul 30, 2024
CVE-2024-7209
6.5 MEDIUM

A vulnerability exists in the use of shared SPF records in multi-tenant hosting providers, allowing attackers to use network authorization to be abused to spoof …

Jul 30, 2024
CVE-2024-7208
6.5 MEDIUM

A vulnerability in multi-tenant hosting allows an authenticated sender to spoof the identity of a shared, hosted domain, thus bypass security measures provided by DMARC …

Jul 30, 2024
CVE-2024-5486
5.8 MEDIUM

A vulnerability exists in ClearPass Policy Manager that allows for an attacker with administrative privileges to access sensitive information in a cleartext format. A successful …

Jul 30, 2024
CVE-2024-41944
6.5 MEDIUM

Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the `report/data/proofofplayReport` API route inside the CMS. This allows an authenticated …

Jul 30, 2024
CVE-2024-41916
6.8 MEDIUM

A vulnerability exists in ClearPass Policy Manager that allows for an attacker with administrative privileges to access sensitive information in a cleartext format. A successful …

Jul 30, 2024
CVE-2024-41915
7.2 HIGH

A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass …

Jul 30, 2024
CVE-2023-38001
6.5 MEDIUM

IBM Aspera Orchestrator 4.0.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user …

Jul 30, 2024
CVE-2023-26289
5.4 MEDIUM

IBM Aspera Orchestrator 4.0.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker …

Jul 30, 2024
CVE-2023-26288
5.5 MEDIUM

IBM Aspera Orchestrator 4.0.1 does not invalidate session after a password change which could allow an authenticated user to impersonate another user on the system. …

Jul 30, 2024
CVE-2022-33167
3.7 LOW

IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure …

Jul 30, 2024
CVE-2024-41804
6.5 MEDIUM

Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the API route inside the CMS responsible for Adding/Editing DataSet Column …

Jul 30, 2024
CVE-2024-41803
4.9 MEDIUM

Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the API routes inside the CMS responsible for Filtering DataSets. This …

Jul 30, 2024
CVE-2024-41802
8.1 HIGH

Xibo is a content management system (CMS). An SQL injection vulnerability was discovered in the API routes inside the CMS responsible for Filtering DataSets. This …

Jul 30, 2024
CVE-2024-4188

Unprotected Transport of Credentials vulnerability in OpenText™ Documentum™ Server could allow Credential Stuffing.This issue affects Documentum™ Server: from 16.7 through 23.4.

Jul 30, 2024
CVE-2024-41109
6.3 MEDIUM

Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. Navigating to `/admin/index/statistics` with a logged in Pimcore user exposes information about the Pimcore …

Jul 30, 2024
CVE-2024-39320
6.1 MEDIUM

Discourse is an open source discussion platform. Prior to 3.2.5 and 3.3.0.beta5, the vulnerability allows an attacker to inject iframes from any domain, bypassing the …

Jul 30, 2024
CVE-2024-37299
4.9 MEDIUM

Discourse is an open source discussion platform. Prior to 3.2.5 and 3.3.0.beta5, crafting requests to submit very long tag group names can reduce the availability …

Jul 30, 2024
CVE-2024-37165
6.3 MEDIUM

Discourse is an open source discussion platform. Prior to 3.2.3 and 3.3.0.beta3, improperly sanitized Onebox data could lead to an XSS vulnerability in some situations. …

Jul 30, 2024
CVE-2024-38909
9.8 CRITICAL

Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrary attacker to expose …

Jul 30, 2024
CVE-2024-23091
7.5 HIGH

Weak password hashing using MD5 in funzioni.php in HotelDruid before 1.32 allows an attacker to obtain plaintext passwords from hash values.

Jul 30, 2024
CVE-2024-6699
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mikafon Electronic Inc. Mikafon MA7 allows SQL Injection.This issue affects Mikafon …

Jul 30, 2024
CVE-2024-7127
6.1 MEDIUM

Improper Neutralization of Input During Web Page Generation vulnerability in Stackposts Social Marketing Tool allows Cross-site Scripting (XSS) attack. By submitting the payload in the …

Jul 30, 2024
CVE-2024-41702
9.8 CRITICAL

SiberianCMS - CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Jul 30, 2024
CVE-2024-41701
5.3 MEDIUM

AccuPOS - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Jul 30, 2024
CVE-2024-7226
4.3 MEDIUM

A vulnerability was found in SourceCodester Medicine Tracker System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /classes/Users.php?f=save_user …

Jul 30, 2024
CVE-2024-7225
3.5 LOW

A vulnerability was found in SourceCodester Insurance Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /Script/admin/core/update_policy …

Jul 30, 2024
CVE-2024-41924
7.2 HIGH

Acceptance of extraneous untrusted data with trusted data vulnerability exists in EC-CUBE 4 series. If this vulnerability is exploited, an attacker who obtained the administrative …

Jul 30, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.