CVE Database

121775+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-6067
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Music Class Enrollment System 1.0. Affected by this vulnerability is an unknown functionality of the file …

Jun 17, 2024
CVE-2024-6066
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Best House Rental Management System 1.0. Affected is an unknown function of the file payment_report.php. …

Jun 17, 2024
CVE-2024-6065
7.3 HIGH

A vulnerability was found in itsourcecode Bakery Online Ordering System 1.0. It has been rated as critical. This issue affects some unknown processing of the …

Jun 17, 2024
CVE-2024-6064
5.3 MEDIUM

A vulnerability was found in GPAC 2.5-DEV-rev228-g11067ea92-master. It has been declared as problematic. This vulnerability affects the function xmt_node_end of the file src/scene_manager/loader_xmt.c of the …

Jun 17, 2024
CVE-2024-6063
3.3 LOW

A vulnerability was found in GPAC 2.5-DEV-rev228-g11067ea92-master. It has been classified as problematic. This affects the function m2tsdmx_on_event of the file src/filters/dmx_m2ts.c of the component …

Jun 17, 2024
CVE-2024-37828
4.8 MEDIUM

A stored cross-site scripting (XSS) in Vermeg Agile Reporter v23.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into …

Jun 17, 2024
CVE-2024-37798
5.9 MEDIUM

Cross-site scripting (XSS) vulnerability in search-appointment.php in the Admin Panel in Phpgurukul Beauty Parlour Management System 1.0 allows remote attackers to inject arbitrary web script …

Jun 17, 2024
CVE-2024-34833
9.8 CRITICAL

Sourcecodester Payroll Management System v1.0 is vulnerable to File Upload. Users can upload images via the "save_settings" page. An unauthenticated attacker can leverage this functionality …

Jun 17, 2024
CVE-2023-37058
9.8 CRITICAL

Insecure Permissions vulnerability in JLINK Unionman Technology Co. Ltd Jlink AX1800 v.1.0 allows a remote attacker to escalate privileges via a crafted command.

Jun 17, 2024
CVE-2023-37057
9.8 CRITICAL

An issue in JLINK Unionman Technology Co. Ltd Jlink AX1800 v.1.0 allows a remote attacker to execute arbitrary code via the router's authentication mechanism.

Jun 17, 2024
CVE-2024-6062
3.3 LOW

A vulnerability was found in GPAC 2.5-DEV-rev228-g11067ea92-master and classified as problematic. Affected by this issue is the function swf_svg_add_iso_sample of the file src/filters/load_text.c of the …

Jun 17, 2024
CVE-2024-6061
3.3 LOW

A vulnerability has been found in GPAC 2.5-DEV-rev228-g11067ea92-master and classified as problematic. Affected by this vulnerability is the function isoffin_process of the file src/filters/isoffin_read.c of …

Jun 17, 2024
CVE-2024-37902
10.0 CRITICAL

DeepJavaLibrary(DJL) is an Engine-Agnostic Deep Learning Framework in Java. DJL versions 0.1.0 through 0.27.0 do not prevent absolute path archived artifacts from inserting archived files …

Jun 17, 2024
CVE-2024-37896
8.8 HIGH

Gin-vue-admin is a backstage management system based on vue and gin. Gin-vue-admin <= v2.6.5 has SQL injection vulnerability. The SQL injection vulnerabilities occur when a …

Jun 17, 2024
CVE-2024-37895
5.7 MEDIUM

Lobe Chat is an open-source LLMs/AI chat framework. In affected versions if an attacker can successfully authenticate through SSO/Access Code, they can obtain the real …

Jun 17, 2024
CVE-2024-37893
5.9 MEDIUM

Firefly III is a free and open source personal finance manager. In affected versions an MFA bypass in the Firefly III OAuth flow may allow …

Jun 17, 2024
CVE-2024-37891
4.4 MEDIUM

urllib3 is a user-friendly HTTP client library for Python. When using urllib3's proxy support with `ProxyManager`, the `Proxy-Authorization` header is only sent to the configured …

Jun 17, 2024
CVE-2024-37890
7.5 HIGH

ws is an open source WebSocket client and server for Node.js. A request with a number of headers exceeding theserver.maxHeadersCount threshold could be used to …

Jun 17, 2024
CVE-2024-37305
8.2 HIGH

oqs-provider is a provider for the OpenSSL 3 cryptography library that adds support for post-quantum cryptography in TLS, X.509, and S/MIME using post-quantum algorithms from …

Jun 17, 2024
CVE-2024-6059
2.4 LOW

A vulnerability, which was classified as problematic, has been found in Ingenico Estate Manager 2023. This issue affects some unknown processing of the file /emgui/rest/ums/messages …

Jun 17, 2024
CVE-2024-38449
7.7 HIGH

A Directory Traversal vulnerability in KasmVNC 1.3.1.230e50f7b89663316c70de7b0e3db6f6b9340489 and possibly earlier versions allows remote authenticated attackers to browse parent directories and read the content of files …

Jun 17, 2024
CVE-2024-37840
8.8 HIGH

SQL injection vulnerability in processscore.php in Itsourcecode Learning Management System Project In PHP With Source Code v1.0 allows remote attackers to execute arbitrary SQL commands …

Jun 17, 2024
CVE-2024-36543
9.8 CRITICAL

Incorrect access control in the Kafka Connect REST API in the STRIMZI Project 0.41.0 and earlier allows an attacker to deny the service for Kafka …

Jun 17, 2024
CVE-2024-6058
3.5 LOW

A vulnerability classified as problematic has been found in LabVantage LIMS 2017. This affects an unknown part of the file /labvantage/rc?command=page&page=SampleHistoricalList&_iframename=list&__crc=crc_1701669816260. The manipulation of the …

Jun 17, 2024
CVE-2024-6056
3.7 LOW

A vulnerability was found in nasirkhan Laravel Starter up to 11.8.0. It has been rated as problematic. Affected by this issue is some unknown functionality …

Jun 17, 2024
CVE-2024-37795
7.5 HIGH

A segmentation fault in CVC5 Solver v1.1.3 allows attackers to cause a Denial of Service (DoS) via a crafted SMT-LIB input file containing the `set-logic` …

Jun 17, 2024
CVE-2024-37794
7.5 HIGH

Improper input validation in CVC5 Solver v1.1.3 allows attackers to cause a Denial of Service (DoS) via a crafted SMT2 input file.

Jun 17, 2024
CVE-2024-37664
5.2 MEDIUM

Redmi router RB03 v1.0.57 is vulnerable to TCP DoS or hijacking attacks. An attacker in the same WLAN as the victim can disconnect or hijack …

Jun 17, 2024
CVE-2024-37663
4.1 MEDIUM

Redmi router RB03 v1.0.57 is vulnerable to forged ICMP redirect message attacks. An attacker in the same WLAN as the victim can hijack the traffic …

Jun 17, 2024
CVE-2024-37662
6.3 MEDIUM

TP-LINK TL-7DR5130 v1.0.23 is vulnerable to TCP DoS or hijacking attacks. An attacker in the same WLAN as the victim can disconnect or hijack the …

Jun 17, 2024
CVE-2024-37661
6.3 MEDIUM

TP-LINK TL-7DR5130 v1.0.23 is vulnerable to forged ICMP redirect message attacks. An attacker in the same WLAN as the victim can hijack the traffic between …

Jun 17, 2024
CVE-2024-36973
7.8 HIGH

In the Linux kernel, the following vulnerability has been resolved: misc: microchip: pci1xxxx: fix double free in the error handling of gp_aux_bus_probe() When auxiliary_device_add() returns …

Jun 17, 2024
CVE-2024-36527
6.5 MEDIUM

puppeteer-renderer v.3.2.0 and before is vulnerable to Directory Traversal. Attackers can exploit the URL parameter using the file protocol to read sensitive information from the …

Jun 17, 2024
CVE-2018-25103
5.3 MEDIUM

There exists use-after-free vulnerabilities in lighttpd <= 1.4.50 request parsing which might read from invalid pointers to memory used in the same request, not from …

Jun 17, 2024
CVE-2024-36578
5.9 MEDIUM

akbr update 1.0.0 is vulnerable to Prototype Pollution via update/index.js.

Jun 17, 2024
CVE-2024-36577
8.3 HIGH

apphp js-object-resolver < 3.1.1 is vulnerable to Prototype Pollution via Module.setNestedProperty.

Jun 17, 2024
CVE-2024-36575
9.8 CRITICAL

A Prototype Pollution issue in getsetprop 1.1.0 allows an attacker to execute arbitrary code via global.accessor.

Jun 17, 2024
CVE-2024-36574
6.3 MEDIUM

A Prototype Pollution issue in flatten-json 1.0.1 allows an attacker to execute arbitrary code via module.exports.unflattenJSON (flatten-json/index.js:42)

Jun 17, 2024
CVE-2024-36573
9.8 CRITICAL

almela obx before v.0.0.4 has a Prototype Pollution issue which allows arbitrary code execution via the obx/build/index.js:656), reduce (@almela/obx/build/index.js:470), Object.set (obx/build/index.js:269) component.

Jun 17, 2024
CVE-2024-0397
7.4 HIGH

A defect was discovered in the Python “ssl” module where there is a memory race condition with the ssl.SSLContext methods “cert_store_stats()” and “get_ca_certs()”. The race …

Jun 17, 2024
CVE-2024-4032
7.5 HIGH

The “ipaddress” module contained incorrect information about whether certain IPv4 and IPv6 addresses were designated as “globally reachable” or “private”. This affected the is_private and …

Jun 17, 2024
CVE-2024-36582
9.8 CRITICAL

alexbinary object-deep-assign 1.0.11 is vulnerable to Prototype Pollution via the extend() method of Module.deepAssign (/src/index.js)

Jun 17, 2024
CVE-2024-36581
7.6 HIGH

A Prototype Pollution issue in abw badger-database 1.2.1 allows an attacker to execute arbitrary code via dist/badger-database.esm.

Jun 17, 2024
CVE-2024-38470
6.1 MEDIUM

zhimengzhe iBarn v1.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the $search parameter at /own.php.

Jun 17, 2024
CVE-2024-38469
6.3 MEDIUM

zhimengzhe iBarn v1.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the $search parameter at /pay.php.

Jun 17, 2024
CVE-2024-37848
8.4 HIGH

SQL Injection vulnerability in Online-Bookstore-Project-In-PHP v1.0 allows a local attacker to execute arbitrary code via the admin_delete.php component.

Jun 17, 2024
CVE-2024-37625
6.1 MEDIUM

zhimengzhe iBarn v1.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the $search parameter at /index.php.

Jun 17, 2024
CVE-2024-37624
6.1 MEDIUM

Xinhu RockOA v2.6.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the /chajian/inputChajian.php. component.

Jun 17, 2024
CVE-2024-37623
6.1 MEDIUM

Xinhu RockOA v2.6.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the /kaoqin/tpl_kaoqin_locationchange.html component.

Jun 17, 2024
CVE-2024-37622
6.1 MEDIUM

Xinhu RockOA v2.6.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the num parameter at /flow/flow.php.

Jun 17, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.