CVE Database

122268+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-30283
5.5 MEDIUM

Adobe Framemaker versions 2020.5, 2022.3 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker …

May 16, 2024
CVE-2024-4838
7.5 HIGH

The ConvertPlus plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.5.26 via deserialization of untrusted input from …

May 16, 2024
CVE-2024-4634
6.4 MEDIUM

The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘hfe_svg_mime_types’ function in versions up to, and including, …

May 16, 2024
CVE-2024-4617
6.4 MEDIUM

The Rank Math SEO with AI Best SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in versions up …

May 16, 2024
CVE-2024-4400
6.4 MEDIUM

The Post and Page Builder by BoldGrid – Visual Drag and Drop Editor plguin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown …

May 16, 2024
CVE-2024-4385
6.4 MEDIUM

The Envo Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 1.8.16 due to insufficient …

May 16, 2024
CVE-2024-4288
6.4 MEDIUM

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter in versions …

May 16, 2024
CVE-2024-35302
5.4 MEDIUM

In JetBrains TeamCity before 2023.11 stored XSS during restore from backup was possible

May 16, 2024
CVE-2024-35301
5.5 MEDIUM

In JetBrains TeamCity before 2024.03.1 commit status publisher didn't check project scope of the GitHub App token

May 16, 2024
CVE-2024-35300
3.5 LOW

In JetBrains TeamCity between 2024.03 and 2024.03.1 several stored XSS in the available updates page were possible

May 16, 2024
CVE-2024-35299
5.9 MEDIUM

In JetBrains YouTrack before 2024.1.29548 the SMTPS protocol communication lacked proper certificate hostname validation

May 16, 2024
CVE-2024-4975
3.5 LOW

A vulnerability, which was classified as problematic, has been found in code-projects Simple Chat System 1.0. This issue affects some unknown processing of the component …

May 16, 2024
CVE-2024-4974
3.5 LOW

A vulnerability, which was classified as problematic, was found in code-projects Simple Chat System 1.0. Affected is an unknown function of the file /register.php. The …

May 16, 2024
CVE-2024-4973
6.3 MEDIUM

A vulnerability classified as critical was found in code-projects Simple Chat System 1.0. This vulnerability affects unknown code of the file /register.php. The manipulation of …

May 16, 2024
CVE-2024-4352
8.8 HIGH

The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability …

May 16, 2024
CVE-2024-4351
8.8 HIGH

The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability …

May 16, 2024
CVE-2024-4222
7.3 HIGH

The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability …

May 16, 2024
CVE-2024-4972
6.3 MEDIUM

A vulnerability classified as critical has been found in code-projects Simple Chat System 1.0. This affects an unknown part of the file /login.php. The manipulation …

May 16, 2024
CVE-2024-4968
3.5 LOW

A vulnerability was found in SourceCodester Interactive Map with Marker 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality …

May 16, 2024
CVE-2024-4967
6.3 MEDIUM

A vulnerability was found in SourceCodester Interactive Map with Marker 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

May 16, 2024
CVE-2024-4642

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

May 16, 2024
CVE-2024-4391
6.4 MEDIUM

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Event Calendar widget in all versions up to, …

May 16, 2024
CVE-2024-4326
9.8 CRITICAL

A vulnerability in parisneo/lollms-webui versions up to 9.3 allows remote attackers to execute arbitrary code. The vulnerability stems from insufficient protection of the `/apply_settings` and …

May 16, 2024
CVE-2024-4322
7.5 HIGH

A path traversal vulnerability exists in the parisneo/lollms-webui application, specifically within the `/list_personalities` endpoint. By manipulating the `category` parameter, an attacker can traverse the directory …

May 16, 2024
CVE-2024-4321
7.5 HIGH

A Local File Inclusion (LFI) vulnerability exists in the gaizhenbiao/chuanhuchatgpt application, specifically within the functionality for uploading chat history. The vulnerability arises due to improper …

May 16, 2024
CVE-2024-4263
5.4 MEDIUM

A broken access control vulnerability exists in mlflow/mlflow versions before 2.10.1, where low privilege users with only EDIT permissions on an experiment can delete any …

May 16, 2024
CVE-2024-4223
9.8 CRITICAL

The Tutor LMS plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check …

May 16, 2024
CVE-2024-4181
8.8 HIGH

A command injection vulnerability exists in the RunGptLLM class of the llama_index library, version 0.9.47, used by the RunGpt framework from JinaAI to connect to …

May 16, 2024
CVE-2024-4078
9.8 CRITICAL

A vulnerability in the parisneo/lollms, specifically in the `/unInstall_binding` endpoint, allows for arbitrary code execution due to insufficient sanitization of user input. The issue arises …

May 16, 2024
CVE-2024-3887
5.4 MEDIUM

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Form Builder widget in all versions up to, …

May 16, 2024
CVE-2024-3851
5.4 MEDIUM

A stored Cross-Site Scripting (XSS) vulnerability exists in the 'imartinez/privategpt' repository due to improper validation of file uploads. Attackers can exploit this vulnerability by uploading …

May 16, 2024
CVE-2024-3848
7.5 HIGH

A path traversal vulnerability exists in mlflow/mlflow version 2.11.0, identified as a bypass for the previously addressed CVE-2023-6909. The vulnerability arises from the application's handling …

May 16, 2024
CVE-2024-3435
8.4 HIGH

A path traversal vulnerability exists in the 'save_settings' endpoint of the parisneo/lollms-webui application, affecting versions up to the latest release before 9.5. The vulnerability arises …

May 16, 2024
CVE-2024-3403
7.5 HIGH

imartinez/privategpt version 0.2.0 is vulnerable to a local file inclusion vulnerability that allows attackers to read arbitrary files from the filesystem. By manipulating file upload …

May 16, 2024
CVE-2024-3126
8.4 HIGH

A command injection vulnerability exists in the 'run_xtts_api_server' function of the parisneo/lollms-webui application, specifically within the 'lollms_xtts.py' script. The vulnerability arises due to the improper …

May 16, 2024
CVE-2024-30309
5.5 MEDIUM

Substance3D - Painter versions 9.1.2 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker …

May 16, 2024
CVE-2024-30308
5.5 MEDIUM

Substance3D - Painter versions 9.1.2 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker …

May 16, 2024
CVE-2024-30307
7.8 HIGH

Substance3D - Painter versions 9.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

May 16, 2024
CVE-2024-30298
5.5 MEDIUM

Animate versions 24.0.2, 23.0.5 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could …

May 16, 2024
CVE-2024-30297
7.8 HIGH

Animate versions 24.0.2, 23.0.5 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the …

May 16, 2024
CVE-2024-30296
7.8 HIGH

Animate versions 24.0.2, 23.0.5 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the …

May 16, 2024
CVE-2024-30295
7.8 HIGH

Animate versions 24.0.2, 23.0.5 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in arbitrary code execution in the context of …

May 16, 2024
CVE-2024-30294
7.8 HIGH

Animate versions 24.0.2, 23.0.5 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of …

May 16, 2024
CVE-2024-30293
7.8 HIGH

Animate versions 24.0.2, 23.0.5 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of …

May 16, 2024
CVE-2024-30282
7.8 HIGH

Animate versions 24.0.2, 23.0.5 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the …

May 16, 2024
CVE-2024-30281
5.5 MEDIUM

Substance3D - Designer versions 13.1.1 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker …

May 16, 2024
CVE-2024-30275
7.8 HIGH

Adobe Aero Desktop versions 23.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context …

May 16, 2024
CVE-2024-30274
7.8 HIGH

Substance3D - Painter versions 9.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of …

May 16, 2024
CVE-2024-2366
9.0 CRITICAL

A remote code execution vulnerability exists in the parisneo/lollms-webui application, specifically within the reinstall_binding functionality in lollms_core/lollms/server/endpoints/lollms_binding_infos.py of the latest version. The vulnerability arises due …

May 16, 2024
CVE-2024-2361
9.6 CRITICAL

A vulnerability in the parisneo/lollms-webui allows for arbitrary file upload and read due to insufficient sanitization of user-supplied input. Specifically, the issue resides in the …

May 16, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.