CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-21583
4.1 MEDIUM

Versions of the package github.com/gitpod-io/gitpod/components/server/go/pkg/lib before main-gha.27122; versions of the package github.com/gitpod-io/gitpod/components/ws-proxy/pkg/proxy before main-gha.27122; versions of the package github.com/gitpod-io/gitpod/install/installer/pkg/components/auth before main-gha.27122; versions of the package …

Jul 19, 2024
CVE-2024-21527
8.2 HIGH

Versions of the package github.com/gotenberg/gotenberg/v8/pkg/gotenberg before 8.1.0; versions of the package github.com/gotenberg/gotenberg/v8/pkg/modules/chromium before 8.1.0; versions of the package github.com/gotenberg/gotenberg/v8/pkg/modules/webhook before 8.1.0 are vulnerable to Server-side …

Jul 19, 2024
CVE-2024-6898
7.3 HIGH

A vulnerability was found in SourceCodester Record Management System 1.0. It has been classified as critical. This affects an unknown part of the file index.php. …

Jul 19, 2024
CVE-2024-38156
6.1 MEDIUM

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Jul 19, 2024
CVE-2024-35199
8.2 HIGH

TorchServe is a flexible and easy-to-use tool for serving and scaling PyTorch models in production. In affected versions the two gRPC ports 7070 and 7071, …

Jul 19, 2024
CVE-2024-35198
9.8 CRITICAL

TorchServe is a flexible and easy-to-use tool for serving and scaling PyTorch models in production. TorchServe 's check on allowed_urls configuration can be by-passed if …

Jul 19, 2024
CVE-2024-30130
3.7 LOW

HCL Nomad server on Domino is vulnerable to the cache containing sensitive information which could potentially give an attacker the ability to acquire the sensitive …

Jul 19, 2024
CVE-2024-41111
7.2 HIGH

Sliver is an open source cross-platform adversary emulation/red team framework, it can be used by organizations of all sizes to perform security testing. Sliver version …

Jul 18, 2024
CVE-2024-40642
8.1 HIGH

The netty incubator codec.bhttp is a java language binary http parser. In affected versions the `BinaryHttpParser` class does not properly validate input values thus giving …

Jul 18, 2024
CVE-2024-5997
4.3 MEDIUM

The Duplica – Duplicate Posts, Pages, Custom Posts or Users plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability …

Jul 18, 2024
CVE-2024-6455
5.3 MEDIUM

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.2.0 due to a missing capability …

Jul 18, 2024
CVE-2024-39173
9.8 CRITICAL

calculator-boilerplate v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the eval function at /routes/calculator.js. This vulnerability allows attackers to execute arbitrary …

Jul 18, 2024
CVE-2024-39090
6.1 MEDIUM

The PHPGurukul Online Shopping Portal Project version 2.0 contains a vulnerability that allows Cross-Site Request Forgery (CSRF) to lead to Stored Cross-Site Scripting (XSS). An …

Jul 18, 2024
CVE-2024-30126
4.7 MEDIUM

HCL BigFix Compliance is affected by a missing X-Frame-Options HTTP header which can allow an attacker to create a malicious website that embeds the target …

Jul 18, 2024
CVE-2024-5321
6.1 MEDIUM

A security issue was discovered in Kubernetes clusters with Windows nodes where BUILTIN\Users may be able to read container logs and NT AUTHORITY\Authenticated Users may …

Jul 18, 2024
CVE-2024-39152

Rejected reason: DO NOT USE THIS CVE RECORD. Consult IDs: CVE-2024-6655. Reason: This record is a reservation duplicate of CVE-2024-6655. Notes: All CVE users should …

Jul 18, 2024
CVE-2024-38806
3.9 LOW

Failure to properly synchronize user's permissions in UAA in Cloud Foundry Foundation v40.17.0 https://github.com/cloudfoundry/cf-deployment/releases/tag/v40.17.0 , potentially resulting in users retaining access rights they should not …

Jul 18, 2024
CVE-2024-5625
6.5 MEDIUM

Improper Restriction of XML External Entity Reference vulnerability in PruvaSoft Informatics Apinizer Management Console allows Data Serialization External Entities Blowup.This issue affects Apinizer Management Console: …

Jul 18, 2024
CVE-2024-30125
6.2 MEDIUM

HCL BigFix Compliance server can respond with an HTTP status of 500, indicating a server-side error that may cause the server process to die.

Jul 18, 2024
CVE-2024-0857
9.8 CRITICAL

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Universal Software Inc. FlexWater Corporate Water Management allows SQL Injection.This issue …

Jul 18, 2024
CVE-2024-5620
6.5 MEDIUM

Authentication Bypass Using an Alternate Path or Channel vulnerability in PruvaSoft Informatics Apinizer Management Console allows Authentication Bypass.This issue affects Apinizer Management Console: before 2024.05.1.

Jul 18, 2024
CVE-2024-5619
9.6 CRITICAL

Authorization Bypass Through User-Controlled Key vulnerability in PruvaSoft Informatics Apinizer Management Console allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Apinizer Management Console: …

Jul 18, 2024
CVE-2024-5618
9.9 CRITICAL

Incorrect Permission Assignment for Critical Resource vulnerability in PruvaSoft Informatics Apinizer Management Console allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Apinizer Management …

Jul 18, 2024
CVE-2024-40648
5.4 MEDIUM

matrix-rust-sdk is an implementation of a Matrix client-server library in Rust. The `UserIdentity::is_verified()` method in the matrix-sdk-crypto crate before version 0.7.2 doesn't take into account …

Jul 18, 2024
CVE-2024-40647
5.3 MEDIUM

sentry-sdk is the official Python SDK for Sentry.io. A bug in Sentry's Python SDK < 2.8.0 allows the environment variables to be passed to subprocesses …

Jul 18, 2024
CVE-2024-40644
6.8 MEDIUM

gitoxide An idiomatic, lean, fast & safe pure Rust implementation of Git. `gix-path` can be tricked into running another `git.exe` placed in an untrusted location …

Jul 18, 2024
CVE-2024-40629
10.0 CRITICAL

JumpServer is an open-source Privileged Access Management (PAM) tool that provides DevOps and IT teams with on-demand and secure access to SSH, RDP, Kubernetes, Database …

Jul 18, 2024
CVE-2024-40628
10.0 CRITICAL

JumpServer is an open-source Privileged Access Management (PAM) tool that provides DevOps and IT teams with on-demand and secure access to SSH, RDP, Kubernetes, Database …

Jul 18, 2024
CVE-2023-40704
6.8 MEDIUM

The product does not require unique and complex passwords to be created during installation. Using Philips's default password could jeopardize the PACS system if the …

Jul 18, 2024
CVE-2023-40539

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 18, 2024
CVE-2023-40223

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 18, 2024
CVE-2023-40159

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Jul 18, 2024
CVE-2024-39911
10.0 CRITICAL

1Panel is a web-based linux server management control panel. 1Panel contains an unspecified sql injection via User-Agent handling. This issue has been addressed in version …

Jul 18, 2024
CVE-2024-39907
9.8 CRITICAL

1Panel is a web-based linux server management control panel. There are many sql injections in the project, and some of them are not well filtered, …

Jul 18, 2024
CVE-2024-38302
6.8 MEDIUM

Dell Data Lakehouse, version(s) 1.0.0.0, contain(s) a Missing Encryption of Sensitive Data vulnerability in the DDAE (Starburst). A low privileged attacker with adjacent network access …

Jul 18, 2024
CVE-2024-30473
4.9 MEDIUM

Dell ECS, versions prior to 3.8.1, contain a privilege elevation vulnerability in user management. A remote high privileged attacker could potentially exploit this vulnerability, gaining …

Jul 18, 2024
CVE-2023-50304
7.1 HIGH

IBM Engineering Requirements Management DOORS Web Access 9.7.2.8 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker …

Jul 18, 2024
CVE-2024-34013
7.8 HIGH

Local privilege escalation due to OS command injection vulnerability. The following products are affected: Acronis True Image (macOS) before build 41396, Acronis True Image OEM …

Jul 18, 2024
CVE-2024-31143
7.5 HIGH

An optional feature of PCI MSI called "Multiple Message" allows a device to use multiple consecutive interrupt vectors. Unlike for MSI-X, the setting up of …

Jul 18, 2024
CVE-2024-29178
8.8 HIGH

On versions before 2.1.4, a user could log in and perform a template injection attack resulting in Remote Code Execution on the server, The attacker …

Jul 18, 2024
CVE-2024-6504
4.3 MEDIUM

Rapid7 InsightVM Console versions below 6.6.260 suffer from a protection mechanism failure whereby an attacker with network access to the InsightVM Console can cause it …

Jul 18, 2024
CVE-2024-40898
7.5 HIGH

SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF and …

Jul 18, 2024
CVE-2024-40725
5.3 MEDIUM

A partial fix for CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignores some use of the legacy content-type based configuration of handlers. "AddType" …

Jul 18, 2024
CVE-2024-5555
6.4 MEDIUM

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Jul 18, 2024
CVE-2024-5554
6.4 MEDIUM

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via …

Jul 18, 2024
CVE-2024-3242
8.8 HIGH

The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file extension validation in the validateImageContent function called …

Jul 18, 2024
CVE-2024-40764
7.5 HIGH

Heap-based buffer overflow vulnerability in the SonicOS IPSec VPN allows an unauthenticated remote attacker to cause Denial of Service (DoS).

Jul 18, 2024
CVE-2024-29014
8.8 HIGH

Vulnerability in SonicWall SMA100 NetExtender Windows (32 and 64-bit) client 10.2.339 and earlier versions allows an attacker to arbitrary code execution when processing an EPC …

Jul 18, 2024
CVE-2024-41011
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: don't allow mapping the MMIO HDP page with large pages We don't get the …

Jul 18, 2024
CVE-2024-6164
9.8 CRITICAL

The Filter & Grids WordPress plugin before 2.8.33 is vulnerable to Local File Inclusion via the post_layout parameter. This makes it possible for an unauthenticated …

Jul 18, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.