CVE Database

122268+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-30799
4.4 MEDIUM

An issue in PX4 Autopilot v1.14 and before allows a remote attacker to execute arbitrary code and cause a denial of service via the Breach …

Apr 22, 2024
CVE-2024-28722
6.3 MEDIUM

Cross Site Scripting vulnerability in Innovaphone myPBX v.14r1, v.13r3, v.12r2 allows a remote attacker to execute arbitrary code via the query parameter to the /CMD0/xml_modes.xml …

Apr 22, 2024
CVE-2015-10132
3.5 LOW

A vulnerability classified as problematic was found in Thimo Grauerholz WP-Spreadplugin up to 3.8.6.1 on WordPress. This vulnerability affects unknown code of the file spreadplugin.php. …

Apr 21, 2024
CVE-2024-29733
2.7 LOW

Improper Certificate Validation vulnerability in Apache Airflow FTP Provider. The FTP hook lacks complete certificate validation in FTP_TLS connections, which can potentially be leveraged. Implementing …

Apr 21, 2024
CVE-2024-29217
4.6 MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Answer.This issue affects Apache Answer: before 1.3.0. XSS attack when user changes …

Apr 21, 2024
CVE-2024-4022
5.3 MEDIUM

A vulnerability was found in Keenetic KN-1010, KN-1410, KN-1711, KN-1810 and KN-1910 up to 4.1.2.15. It has been rated as problematic. Affected by this issue …

Apr 21, 2024
CVE-2024-4021
5.3 MEDIUM

A vulnerability was found in Keenetic KN-1010, KN-1410, KN-1711, KN-1810 and KN-1910 up to 4.1.2.15. It has been declared as problematic. Affected by this vulnerability …

Apr 21, 2024
CVE-2024-4020
8.8 HIGH

A vulnerability was found in Tenda FH1206 1.2.0.8(8155) and classified as critical. This issue affects the function fromAddressNat of the file /goform/addressNat. The manipulation of …

Apr 20, 2024
CVE-2024-4019
6.3 MEDIUM

A vulnerability classified as critical has been found in Byzoro Smart S80 Management Platform up to 20240411. Affected is an unknown function of the file …

Apr 20, 2024
CVE-2024-4014
6.4 MEDIUM

The hCaptcha for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cf7-hcaptcha shortcode in all versions up to, and including, …

Apr 20, 2024
CVE-2024-1730
5.4 MEDIUM

The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Media Slider, Drag Drop Slider, Video Slider, Product Slider, Ecommerce Slider) plugin …

Apr 20, 2024
CVE-2024-1057
6.4 MEDIUM

The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +10 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Stored …

Apr 20, 2024
CVE-2024-31994
6.5 MEDIUM

Mealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, an attacker can point the image request to an arbitrarily large file. …

Apr 19, 2024
CVE-2024-1480
7.5 HIGH

Unitronics Vision Standard line of controllers allow the Information Mode password to be retrieved without authentication.

Apr 19, 2024
CVE-2024-4018
8.8 HIGH

Improper Privilege Management vulnerability in BeyondTrust U-Series Appliance on Windows, 64 bit (local appliance api modules) allows Privilege Escalation.This issue affects U-Series Appliance: from 3.4 …

Apr 19, 2024
CVE-2024-4017
8.8 HIGH

Improper Privilege Management vulnerability in BeyondTrust U-Series Appliance on Windows, 64 bit (filesystem modules) allows DLL Side-Loading.This issue affects U-Series Appliance: from 3.4 before 4.0.3.

Apr 19, 2024
CVE-2024-32392
4.5 MEDIUM

Cross Site Scripting vulnerability in CmSimple v.5.15 allows a remote attacker to execute arbitrary code via the functions.php component.

Apr 19, 2024
CVE-2024-32391
7.3 HIGH

Cross Site Scripting vulnerability in MacCMS v.10 v.2024.1000.3000 allows a remote attacker to execute arbitrary code via a crafted payload.

Apr 19, 2024
CVE-2024-31993
6.2 MEDIUM

Mealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, the scrape_image function will retrieve an image based on a user-provided URL, …

Apr 19, 2024
CVE-2024-31992
6.5 MEDIUM

Mealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, the safe_scrape_html function utilizes a user-controlled URL to issue a request to …

Apr 19, 2024
CVE-2024-31991
4.1 MEDIUM

Mealie is a self hosted recipe manager and meal planner. Prior to 1.4.0, the safe_scrape_html function utilizes a user-controlled URL to issue a request to …

Apr 19, 2024
CVE-2024-31584
5.5 MEDIUM

Pytorch before v2.2.0 has an Out-of-bounds Read vulnerability via the component torch/csrc/jit/mobile/flatbuffer_loader.cpp.

Apr 19, 2024
CVE-2024-30974
7.3 HIGH

SQL Injection vulnerability in autoexpress v.1.3.0 allows attackers to run arbitrary SQL commands via the carId parameter.

Apr 19, 2024
CVE-2024-22905
7.0 HIGH

Buffer Overflow vulnerability in ARM mbed-os v.6.17.0 allows a remote attacker to execute arbitrary code via a crafted script to the hciTrSerialRxIncoming function.

Apr 19, 2024
CVE-2024-1681
5.3 MEDIUM

corydolphin/flask-cors is vulnerable to log injection when the log level is set to debug. An attacker can inject fake log entries into the log file …

Apr 19, 2024
CVE-2024-32652
7.5 HIGH

The adapter @hono/node-server allows you to run your Hono application on Node.js. Prior to 1.10.1, the application hangs when receiving a Host header with a …

Apr 19, 2024
CVE-2024-31450
2.7 LOW

Owncast is an open source, self-hosted, decentralized, single user live video streaming and chat server. The Owncast application exposes an administrator API at the URL …

Apr 19, 2024
CVE-2024-3979
4.4 MEDIUM

A vulnerability, which was classified as problematic, has been found in COVESA vsomeip up to 3.4.10. Affected by this issue is some unknown functionality. The …

Apr 19, 2024
CVE-2024-31547
9.1 CRITICAL

Computer Laboratory Management System v1.0 is vulnerable to SQL Injection via the "id" parameter of /admin/item/view_item.php.

Apr 19, 2024
CVE-2024-31546
9.8 CRITICAL

Computer Laboratory Management System v1.0 is vulnerable to SQL Injection via the "id" parameter of /admin/damage/view_damage.php.

Apr 19, 2024
CVE-2023-47435
9.8 CRITICAL

An issue in the verifyPassword function of hexo-theme-matery v2.0.0 allows attackers to bypass authentication and access password protected pages.

Apr 19, 2024
CVE-2024-31552
7.1 HIGH

CuteHttpFileServer v.3.1 version has an arbitrary file download vulnerability, which allows attackers to download arbitrary files on the server and obtain sensitive information.

Apr 19, 2024
CVE-2024-2440
5.5 MEDIUM

A race condition in GitHub Enterprise Server allowed an existing admin to maintain permissions on a detached repository by making a GraphQL mutation to alter …

Apr 19, 2024
CVE-2024-29991
5.0 MEDIUM

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

Apr 19, 2024
CVE-2023-51798
7.8 HIGH

Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via a floating point exception (FPE) error at libavfilter/vf_minterpolate.c:1078:60 in interpolate.

Apr 19, 2024
CVE-2023-51797
6.7 MEDIUM

Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/avf_showwaves.c:722:24 in showwaves_filter_frame

Apr 19, 2024
CVE-2023-51796
3.6 LOW

Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/f_reverse.c:269:26 in areverse_request_frame.

Apr 19, 2024
CVE-2023-51795
8.0 HIGH

Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/avf_showspectrum.c:1789:52 component in showspectrumpic_request_frame

Apr 19, 2024
CVE-2023-51793
7.8 HIGH

Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavutil/imgutils.c:353:9 in image_copy_plane.

Apr 19, 2024
CVE-2023-51792
3.3 LOW

Buffer Overflow vulnerability in libde265 v1.0.12 allows a local attacker to cause a denial of service via the allocation size exceeding the maximum supported size …

Apr 19, 2024
CVE-2023-51791
7.8 HIGH

Buffer Overflow vulenrability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavcodec/jpegxl_parser.c in gen_alias_map.

Apr 19, 2024
CVE-2023-50010
7.8 HIGH

FFmpeg v.n6.1-3-g466799d4f5 allows a buffer over-read at ff_gradfun_blur_line_movdqa_sse2, as demonstrated by a call to the set_encoder_id function in /fftools/ffmpeg_enc.c component.

Apr 19, 2024
CVE-2023-50009
8.0 HIGH

FFmpeg v.n6.1-3-g466799d4f5 allows a heap-based buffer overflow via the ff_gaussian_blur_8 function in libavfilter/edge_template.c:116:5 component.

Apr 19, 2024
CVE-2023-50008
7.8 HIGH

FFmpeg v.n6.1-3-g466799d4f5 allows memory consumption when using the colorcorrect filter, in the av_malloc function in libavutil/mem.c:105:9 component.

Apr 19, 2024
CVE-2023-50007
4.0 MEDIUM

FFmpeg v.n6.1-3-g466799d4f5 allows an attacker to trigger use of a parameter of negative size in the av_samples_set_silence function in thelibavutil/samplefmt.c:260:9 component.

Apr 19, 2024
CVE-2023-49963
8.8 HIGH

DYMO LabelWriter Print Server through 2.366 contains a backdoor hard-coded password that could allow an attacker to take control.

Apr 19, 2024
CVE-2023-49502
8.8 HIGH

Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the ff_bwdif_filter_intra_c function in the libavfilter/bwdifdsp.c:125:5 component.

Apr 19, 2024
CVE-2023-49501
8.0 HIGH

Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the config_eq_output function in the libavfilter/asrc_afirsrc.c:495:30 component.

Apr 19, 2024
CVE-2023-37397
3.6 LOW

IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain or modify sensitive information due to improper encryption of certain data. IBM …

Apr 19, 2024
CVE-2023-27279
6.5 MEDIUM

IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a user to cause a denial of service due to missing API rate limiting. IBM X-Force ID: …

Apr 19, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.