CVE Database

122268+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-5413
7.1 HIGH

A vulnerability have been discovered in PhpMyBackupPro affecting version 2.3 that could allow an attacker to execute XSS through /phpmybackuppro/scheduled.php, all parameters. This vulnerabilities could …

May 28, 2024
CVE-2024-3657
7.5 HIGH

A flaw was found in 389-ds-base. A specially-crafted LDAP query can potentially cause a failure on the directory server, leading to a denial of service

May 28, 2024
CVE-2024-2199
5.7 MEDIUM

A denial of service vulnerability was found in 389-ds-base ldap server. This issue may allow an authenticated user to cause a server crash while modifying …

May 28, 2024
CVE-2024-28793
4.9 MEDIUM

IBM Engineering Workflow Management 7.0.2 and 7.0.3 is vulnerable to stored cross-site scripting. Under certain configurations, this vulnerability allows users to embed arbitrary JavaScript code …

May 28, 2024
CVE-2023-37411
4.8 MEDIUM

IBM Aspera Faspex 5.0.0 through 5.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus …

May 28, 2024
CVE-2024-5411
8.8 HIGH

Missing input validation and OS command integration of the input in the ORing IAP-420 web-interface allows authenticated command injection.This issue affects IAP-420 version 2.01e and …

May 28, 2024
CVE-2024-5410
5.4 MEDIUM

Missing input validation in the ORing IAP-420 web-interface allows stored Cross-Site Scripting (XSS).This issue affects IAP-420 version 2.01e and below.

May 28, 2024
CVE-2023-52712
7.8 HIGH

Various Issues Due To Exposed SMI Handler in AmdPspP2CmboxV2. The first issue can be leveraged to bypass the protections that have been put in place …

May 28, 2024
CVE-2023-52711
7.8 HIGH

Various Issues Due To Exposed SMI Handler in AmdPspP2CmboxV2. The first issue can be leveraged to bypass the protections that have been put in place …

May 28, 2024
CVE-2023-52710
7.8 HIGH

Huawei Matebook D16(Model: CREM-WXX9, BIOS: v2.26), As the communication buffer size hasn’t been properly validated to be of the expected size, it can partially overlap …

May 28, 2024
CVE-2023-52548
7.8 HIGH

Huawei Matebook D16(Model: CREM-WXX9, BIOS: v2.26) Arbitrary Memory Corruption in SMI Handler of ThisiServicesSmm SMM module. This can be leveraged by a malicious OS attacker …

May 28, 2024
CVE-2023-52547
7.8 HIGH

Huawei Matebook D16(Model: CREM-WXX9, BIOS: v2.26. Memory Corruption in SMI Handler of HddPassword SMM Module. This can be leveraged by a malicious OS attacker to …

May 28, 2024
CVE-2022-48681
7.2 HIGH

Some Huawei smart speakers have a memory overflow vulnerability. Successful exploitation of this vulnerability may cause certain functions to fail.

May 28, 2024
CVE-2024-32944
3.3 LOW

Path traversal vulnerability exists in UTAU versions prior to v0.4.19. If a user of the product installs a crafted UTAU voicebank installer (.uar file, .zip …

May 28, 2024
CVE-2024-28886
8.4 HIGH

OS command injection vulnerability exists in UTAU versions prior to v0.4.19. If a user of the product opens a crafted UTAU project file (.ust file), …

May 28, 2024
CVE-2024-29078
7.5 HIGH

Incorrect permission assignment for critical resource issue exists in MosP kintai kanri V4.6.6 and earlier, which may allow a remote unauthenticated attacker with access to …

May 28, 2024
CVE-2024-28880
6.5 MEDIUM

Path traversal vulnerability in MosP kintai kanri V4.6.6 and earlier allows a remote attacker who can log in to the product to obtain sensitive information …

May 28, 2024
CVE-2024-36428
8.1 HIGH

OrangeHRM 3.3.3 allows admin/viewProjects sortOrder SQL injection.

May 27, 2024
CVE-2024-36426
7.5 HIGH

In TARGIT Decision Suite 23.2.15007.0 before Autumn 2023, the session token is part of the URL and may be sent in a cleartext HTTP session.

May 27, 2024
CVE-2024-34923
6.1 MEDIUM

In Avocent DSR2030 Appliance firmware 03.04.00.07 before 03.07.01.23, and SVIP1020 Appliance firmware 01.06.00.03 before 01.07.00.00, there is reflected cross-site scripting (XSS).

May 27, 2024
CVE-2024-29415
8.1 HIGH

The ip package through 2.0.1 for Node.js might allow SSRF because some IP addresses (such as 127.1, 01200034567, 012.1.2.3, 000:0:0000::01, and ::fFFf:127.0.0.1) are improperly categorized …

May 27, 2024
CVE-2024-35182
5.9 MEDIUM

Meshery is an open source, cloud native manager that enables the design and management of Kubernetes-based infrastructure and applications. A SQL injection vulnerability in Meshery …

May 27, 2024
CVE-2024-35181
5.9 MEDIUM

Meshery is an open source, cloud native manager that enables the design and management of Kubernetes-based infrastructure and applications. A SQL injection vulnerability in Meshery …

May 27, 2024
CVE-2024-36105
5.3 MEDIUM

dbt enables data analysts and engineers to transform their data using the same practices that software engineers use to build applications. Prior to versions 1.6.15, …

May 27, 2024
CVE-2024-36037
5.5 MEDIUM

Zoho ManageEngine ADAudit Plus versions 7260 and below allows unauthorized local agent machine users to view the session recordings.

May 27, 2024
CVE-2024-36036
4.2 MEDIUM

Zoho ManageEngine ADAudit Plus versions 7260 and below allows unauthorized local agent machine users to access sensitive information and modifying the agent configuration.

May 27, 2024
CVE-2024-35238
5.3 MEDIUM

Minder by Stacklok is an open source software supply chain security platform. Minder prior to version 0.0.51 is vulnerable to a denial-of-service (DoS) attack which …

May 27, 2024
CVE-2024-27310
5.3 MEDIUM

Zoho ManageEngine ADSelfService Plus versions below 6401 are vulnerable to the DOS attack due to the malicious LDAP input.

May 27, 2024
CVE-2024-35237
7.5 HIGH

MIT IdentiBot is an open-source Discord bot written in Node.js that verifies individuals' affiliations with MIT, grants them roles in a Discord server, and stores …

May 27, 2024
CVE-2024-35236
4.8 MEDIUM

Audiobookshelf is a self-hosted audiobook and podcast server. Prior to version 2.10.0, opening an ebook with malicious scripts inside leads to code execution inside the …

May 27, 2024
CVE-2024-35231
8.6 HIGH

rack-contrib provides contributed rack middleware and utilities for Rack, a Ruby web server interface. Versions of rack-contrib prior to 2.5.0 are vulnerable to denial of …

May 27, 2024
CVE-2024-35229
5.3 MEDIUM

ZKsync Era is a layer 2 rollup that uses zero-knowledge proofs to scale Ethereum. Prior to version 1.3.10, there is a very specific pattern `f(a(),b()); …

May 27, 2024
CVE-2022-4969
5.3 MEDIUM

A vulnerability, which was classified as critical, has been found in bwoodsend rockhopper up to 0.1.2. Affected by this issue is the function count_rows of …

May 27, 2024
CVE-2024-35219
8.3 HIGH

OpenAPI Generator allows generation of API client libraries (SDK generation), server stubs, documentation and configuration automatically given an OpenAPI Spec. Prior to version 7.6.0, attackers …

May 27, 2024
CVE-2024-32978
6.6 MEDIUM

Kaminari is a paginator for web app frameworks and object relational mappings. A security vulnerability involving insecure file permissions has been identified in the Kaminari …

May 27, 2024
CVE-2024-0851

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Grup Arge Energy and Control Systems Smartpower allows SQL Injection.This issue …

May 27, 2024
CVE-2024-34477
7.8 HIGH

configureNFS in lib/common/functions.sh in FOG through 1.5.10 allows local users to gain privileges by mounting a crafted NFS share (because of no_root_squash and insecure). In …

May 27, 2024
CVE-2023-50977

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not …

May 27, 2024
CVE-2024-5409
7.1 HIGH

RhinOS 3.0-1190 is vulnerable to an XSS via the "tamper" parameter in /admin/lib/phpthumb/phpthumb.php. An attacker could create a malicious URL and send it to a …

May 27, 2024
CVE-2024-5408
7.1 HIGH

Vulnerability in RhinOS 3.0-1190 consisting of an XSS through the "search" parameter of /portal/search.htm. This vulnerability could allow a remote attacker to steal details of …

May 27, 2024
CVE-2024-5407
10.0 CRITICAL

A vulnerability in RhinOS 3.0-1190 could allow PHP code injection through the "search" parameter in /portal/search.htm. This vulnerability could allow a remote attacker to perform …

May 27, 2024
CVE-2024-3381

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

May 27, 2024
CVE-2024-5406
6.3 MEDIUM

A vulnerability had been discovered in WinNMP 19.02 consisting of an XSS attack via index page in from, subject, text and hash parameters. This vulnerability …

May 27, 2024
CVE-2024-5405
6.3 MEDIUM

A vulnerability had been discovered in WinNMP 19.02 consisting of an XSS attack via /tools/redis.php page in the k, hash, key and p parameters. This …

May 27, 2024
CVE-2023-6349
7.5 HIGH

A heap overflow vulnerability exists in libvpx - Encoding a frame that has larger dimensions than the originally configured size with VP9 may result in …

May 27, 2024
CVE-2024-36383
5.3 MEDIUM

An issue was discovered in Logpoint SAML Authentication before 6.0.3. An attacker can place a crafted filename in the state field of a SAML SSO-URL …

May 27, 2024
CVE-2024-5035

The affected device expose a network service called "rftest" that is vulnerable to unauthenticated command injection on ports TCP/8888, TCP/8889, and TCP/8890. By successfully exploiting …

May 27, 2024
CVE-2024-5403
7.2 HIGH

ASKEY 5G NR Small Cell fails to properly filter user input for certain functionality, allowing remote attackers with administrator privilege to execute arbitrary system commands …

May 27, 2024
CVE-2024-27314
2.4 LOW

Zoho ManageEngine ServiceDesk Plus versions below 14730, ServiceDesk Plus MSP below 14720 and SupportCenter Plus below 14720 are vulnerable to stored XSS in the Custom …

May 27, 2024
CVE-2024-26289
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in PMB Services PMB allows Remote Code Inclusion.This issue affects PMB: from 7.5.1 before 7.5.6-2, from 7.4.1 before 7.4.9, from …

May 27, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.