CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-28200
9.1 CRITICAL

The N-central server is vulnerable to an authentication bypass of the user interface. This vulnerability is present in all deployments of N-central prior to 2024.2. …

Jul 1, 2024
CVE-2024-39249
7.5 HIGH

Async <= 2.6.4 and <= 3.2.5 are vulnerable to ReDoS (Regular Expression Denial of Service) while parsing function in autoinject function. NOTE: this is disputed …

Jul 1, 2024
CVE-2024-39573
7.5 HIGH

Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL's to be handled …

Jul 1, 2024
CVE-2024-39303
4.4 MEDIUM

Weblate is a web based localization tool. Prior to version 5.6.2, Weblate didn't correctly validate filenames when restoring project backup. It may be possible to …

Jul 1, 2024
CVE-2024-39251
10.0 CRITICAL

An issue in the component ControlCenter.sys/ControlCenter64.sys of ThundeRobot Control Center v2.0.0.10 allows attackers to access sensitive information, execute arbitrary code, or escalate privileges via sending …

Jul 1, 2024
CVE-2024-39236
9.8 CRITICAL

Gradio v4.36.1 was discovered to contain a code injection vulnerability via the component /gradio/component_meta.py. This vulnerability is triggered via a crafted input. NOTE: the supplier …

Jul 1, 2024
CVE-2024-38513
10.0 CRITICAL

Fiber is an Express-inspired web framework written in Go A vulnerability present in versions prior to 2.52.5 is a session middleware issue in GoFiber versions …

Jul 1, 2024
CVE-2024-38477
7.5 HIGH

null pointer dereference in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows an attacker to crash the server via a malicious request. Users are …

Jul 1, 2024
CVE-2024-38476
9.8 CRITICAL

Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response …

Jul 1, 2024
CVE-2024-38475
9.1 CRITICAL KEV

Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted …

Jul 1, 2024
CVE-2024-38474
9.8 CRITICAL

Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not …

Jul 1, 2024
CVE-2024-38473
8.1 HIGH

Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing …

Jul 1, 2024
CVE-2024-38472
7.5 HIGH

SSRF in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content Users …

Jul 1, 2024
CVE-2024-37298
7.5 HIGH

gorilla/schema converts structs to and from form values. Prior to version 1.4.1 Running `schema.Decoder.Decode()` on a struct that has a field of type `[]struct{...}` opens …

Jul 1, 2024
CVE-2024-37146
6.1 MEDIUM

Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a reflected cross-site scripting …

Jul 1, 2024
CVE-2024-37145
6.1 MEDIUM

Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a reflected cross-site scripting …

Jul 1, 2024
CVE-2024-36423
6.1 MEDIUM

Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a reflected cross-site scripting …

Jul 1, 2024
CVE-2024-36387
5.4 MEDIUM

Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, degrading performance.

Jul 1, 2024
CVE-2024-39879
5.0 MEDIUM

In JetBrains TeamCity before 2024.03.3 application token could be exposed in EC2 Cloud Profile settings

Jul 1, 2024
CVE-2024-39878
4.1 MEDIUM

In JetBrains TeamCity before 2024.03.3 private key could be exposed via testing GitHub App Connection

Jul 1, 2024
CVE-2024-36997
8.1 HIGH

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312, an admin user could store and execute arbitrary JavaScript …

Jul 1, 2024
CVE-2024-36996
5.3 MEDIUM

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109, an attacker could determine whether or not another user …

Jul 1, 2024
CVE-2024-36995
5.4 MEDIUM

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9.1.2308.207, a low-privileged user that does not hold …

Jul 1, 2024
CVE-2024-36994
5.4 MEDIUM

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9.1.2308.207, a low-privileged user that does not hold …

Jul 1, 2024
CVE-2024-36993
5.4 MEDIUM

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9.1.2308.207, a low-privileged user that does not hold …

Jul 1, 2024
CVE-2024-36992
5.4 MEDIUM

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9.1.2308.207, a low-privileged user that does not hold …

Jul 1, 2024
CVE-2024-36991
7.5 HIGH

In Splunk Enterprise on Windows versions below 9.2.2, 9.1.5, and 9.0.10, an attacker could perform a path traversal on the /modules/messaging/ endpoint in Splunk Enterprise …

Jul 1, 2024
CVE-2024-36990
6.5 MEDIUM

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.2.2403.100, an authenticated, low-privileged user that does not hold the …

Jul 1, 2024
CVE-2024-36989
7.1 HIGH

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200, a low-privileged user that does not hold the admin …

Jul 1, 2024
CVE-2024-36987
4.3 MEDIUM

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200, an authenticated, low-privileged user who does not hold the …

Jul 1, 2024
CVE-2024-36986
6.3 MEDIUM

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9.1.2308.207, an authenticated user could run risky commands …

Jul 1, 2024
CVE-2024-36985
8.8 HIGH

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10, a low-privileged user that does not hold the admin or power Splunk roles could cause a …

Jul 1, 2024
CVE-2024-36984
8.8 HIGH

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 on Windows, an authenticated user could execute a specially crafted query that they could then use …

Jul 1, 2024
CVE-2024-36983
8.0 HIGH

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109 and 9.1.2308.207, an authenticated user could create an external …

Jul 1, 2024
CVE-2024-36982
7.5 HIGH

In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109 and 9.1.2308.207, an attacker could trigger a null pointer …

Jul 1, 2024
CVE-2024-21586
7.5 HIGH

An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX Series and NFX …

Jul 1, 2024
CVE-2024-20399
6.0 MEDIUM KEV

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession of Administrator credentials to execute arbitrary commands as root …

Jul 1, 2024
CVE-2024-36422
6.1 MEDIUM

Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a reflected cross-site scripting …

Jul 1, 2024
CVE-2024-36421
7.5 HIGH

Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, A CORS misconfiguration sets …

Jul 1, 2024
CVE-2024-36420
7.5 HIGH

Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, the `/api/v1/openai-assistants-file` endpoint in …

Jul 1, 2024
CVE-2024-36401
9.8 CRITICAL KEV

GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.22.6, 2.23.6, 2.24.4, and 2.25.2, multiple OGC …

Jul 1, 2024
CVE-2024-6376
7.0 HIGH

MongoDB Compass may be susceptible to code injection due to insufficient sandbox protection settings with the usage of ejson shell parser in Compass' connection handling. …

Jul 1, 2024
CVE-2024-6375
5.4 MEDIUM

A command for refining a collection shard key is missing an authorization check. This may cause the command to run directly on a shard, leading …

Jul 1, 2024
CVE-2024-34696
4.5 MEDIUM

GeoServer is an open source server that allows users to share and edit geospatial data. Starting in version 2.10.0 and prior to versions 2.24.4 and …

Jul 1, 2024
CVE-2024-23380
8.4 HIGH

Memory corruption while handling user packets during VBO bind operation.

Jul 1, 2024
CVE-2024-23373
8.4 HIGH

Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released.

Jul 1, 2024
CVE-2024-23372
8.4 HIGH

Memory corruption while invoking IOCTL call for GPU memory allocation and size param is greater than expected size.

Jul 1, 2024
CVE-2024-23368
7.8 HIGH

Memory corruption when allocating and accessing an entry in an SMEM partition.

Jul 1, 2024
CVE-2024-21482
6.8 MEDIUM

Memory corruption during the secure boot process, when the `bootm` command is used, it bypasses the authentication of the kernel/rootfs image.

Jul 1, 2024
CVE-2024-21469
7.3 HIGH

Memory corruption when an invoke call and a TEE call are bound for the same trusted application.

Jul 1, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.