CVE Database

122268+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-3931
3.5 LOW

A vulnerability was found in Totara LMS up to 18.7. It has been rated as problematic. Affected by this issue is some unknown functionality of …

Apr 18, 2024
CVE-2024-3928
4.3 MEDIUM

A vulnerability was found in Dromara open-capacity-platform 2.0.1. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file …

Apr 18, 2024
CVE-2023-4509
4.3 MEDIUM

It is possible for an API key to be logged in clear text in the audit log file after an invalid login attempt.

Apr 18, 2024
CVE-2023-4235
8.1 HIGH

A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_deliver_report() function during the SMS …

Apr 17, 2024
CVE-2023-4234
8.1 HIGH

A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_submit_report() function during the SMS …

Apr 17, 2024
CVE-2023-4233
8.1 HIGH

A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the sms_decode_address_field() function during the SMS …

Apr 17, 2024
CVE-2023-4232
8.1 HIGH

A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_status_report() function during the SMS …

Apr 17, 2024
CVE-2024-32472
6.1 MEDIUM

excalidraw is an open source virtual hand-drawn style whiteboard. A stored XSS vulnerability in Excalidraw's web embeddable component. This allows arbitrary JavaScript to be run …

Apr 17, 2024
CVE-2024-29955
5.0 MEDIUM

A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a could allow a privileged user to print the SANnav encrypted key in PostgreSQL startup logs. This …

Apr 17, 2024
CVE-2024-29952
5.5 MEDIUM

A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a could allow an authenticated user to print the Auth, Priv, and SSL key store passwords in …

Apr 17, 2024
CVE-2024-32746
4.6 MEDIUM

A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload …

Apr 17, 2024
CVE-2024-32745
5.9 MEDIUM

A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload …

Apr 17, 2024
CVE-2024-32744
4.6 MEDIUM

A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload …

Apr 17, 2024
CVE-2024-32743
5.5 MEDIUM

A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload …

Apr 17, 2024
CVE-2024-32345
7.2 HIGH

A cross-site scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary web scripts or HTML via a crafted payload …

Apr 17, 2024
CVE-2024-32344
6.8 MEDIUM

A cross-site scripting (XSS) vulnerability in the Settings menu of CMSimple v5.15 allows attackers to execute arbitrary web scripts or HTML via a crafted payload …

Apr 17, 2024
CVE-2024-32343
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in the Create Page of Boid CMS v2.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted …

Apr 17, 2024
CVE-2024-32342
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in the Create Page of Boid CMS v2.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted …

Apr 17, 2024
CVE-2024-32341
5.4 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in the Home page of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload …

Apr 17, 2024
CVE-2024-32340
9.6 CRITICAL

A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload …

Apr 17, 2024
CVE-2024-32339
6.1 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in the HOW TO page of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or HTML via a crafted …

Apr 17, 2024
CVE-2024-32338
5.4 MEDIUM

A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload …

Apr 17, 2024
CVE-2024-32337
6.1 MEDIUM

A cross-site scripting (XSS) vulnerability in the Settings section of WonderCMS v3.4.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload …

Apr 17, 2024
CVE-2024-3817
9.8 CRITICAL

HashiCorp’s go-getter library is vulnerable to argument injection when executing Git to discover remote branches. This vulnerability does not affect the go-getter/v2 branch and package.

Apr 17, 2024
CVE-2024-29951
5.7 MEDIUM

Brocade SANnav before v2.3.1 and v2.3.0a uses the SHA-1 hash in internal SSH ports that are not open to remote connection.

Apr 17, 2024
CVE-2024-21990
5.4 MEDIUM

ONTAP Select Deploy administration utility versions 9.12.1.x, 9.13.1.x and 9.14.1.x contain hard-coded credentials that could allow an attacker to view Deploy configuration information and modify …

Apr 17, 2024
CVE-2024-21989
8.1 HIGH

ONTAP Select Deploy administration utility versions 9.12.1.x, 9.13.1.x and 9.14.1.x are susceptible to a vulnerability which when successfully exploited could allow a read-only user to …

Apr 17, 2024
CVE-2024-0257
3.3 LOW

RoboDK v5.5.4 is vulnerable to heap-based buffer overflow while processing a specific project file. The resulting memory corruption may crash the application.

Apr 17, 2024
CVE-2024-3900
2.9 LOW

Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by long Unicode sequence in ActualText.

Apr 17, 2024
CVE-2024-3323
8.3 HIGH

Cross Site Scripting in UI Request/Response Validation in TIBCO JasperReports Server 8.0.4 and 8.2.0 allows allows for the injection of malicious executable scripts into the …

Apr 17, 2024
CVE-2024-32163
6.4 MEDIUM

CMSeasy 7.7.7.9 is vulnerable to code execution.

Apr 17, 2024
CVE-2024-32162
4.3 MEDIUM

CMSeasy 7.7.7.9 is vulnerable to Arbitrary file deletion.

Apr 17, 2024
CVE-2024-31585
5.3 MEDIUM

FFmpeg version n5.1 to n6.1 was discovered to contain an Off-by-one Error vulnerability in libavfilter/avf_showspectrum.c. This vulnerability allows attackers to cause a Denial of Service …

Apr 17, 2024
CVE-2024-31583
7.8 HIGH

Pytorch before version v2.2.0 was discovered to contain a use-after-free vulnerability in torch/csrc/jit/mobile/interpreter.cpp.

Apr 17, 2024
CVE-2024-31582
7.8 HIGH

FFmpeg version n6.1 was discovered to contain a heap buffer overflow vulnerability in the draw_block_rectangle function of libavfilter/vf_codecview.c. This vulnerability allows attackers to cause undefined …

Apr 17, 2024
CVE-2024-31581
9.8 CRITICAL

FFmpeg version n6.1 was discovered to contain an improper validation of array index vulnerability in libavcodec/cbs_h266_syntax_template.c. This vulnerability allows attackers to cause undefined behavior within …

Apr 17, 2024
CVE-2024-31580
4.0 MEDIUM

PyTorch before v2.2.0 was discovered to contain a heap buffer overflow vulnerability in the component /runtime/vararg_functions.cpp. This vulnerability allows attackers to cause a Denial of …

Apr 17, 2024
CVE-2024-31041
7.5 HIGH

Null Pointer Dereference vulnerability in topic_filtern function in mqtt_parser.c in NanoMQ 0.21.7 allows attackers to cause a denial of service.

Apr 17, 2024
CVE-2024-31040
2.7 LOW

Buffer Overflow vulnerability in the get_var_integer function in mqtt_parser.c in NanoMQ 0.21.7 allows remote attackers to cause a denial of service via a series of …

Apr 17, 2024
CVE-2024-31031
7.5 HIGH

An issue in `coap_pdu.c` in libcoap 4.3.4 allows attackers to cause undefined behavior via a sequence of messages leading to unsigned integer overflow.

Apr 17, 2024
CVE-2024-30990
9.8 CRITICAL

SQL Injection vulnerability in the "Invoices" page in phpgurukul Client Management System using PHP & MySQL 1.1 allows attacker to execute arbitrary SQL commands via …

Apr 17, 2024
CVE-2024-30989
5.4 MEDIUM

Cross Site Scripting vulnerability in /edit-client-details.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows attackers to execute arbitrary code via the "cname", …

Apr 17, 2024
CVE-2024-30953
6.1 MEDIUM

A stored cross-site scripting (XSS) vulnerability in Htmly v2.9.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the …

Apr 17, 2024
CVE-2024-30950
3.5 LOW

A stored cross-site scripting (XSS) vulnerability in FUDforum v3.1.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the …

Apr 17, 2024
CVE-2024-29950
7.5 HIGH

The class FileTransfer implemented in Brocade SANnav before v2.3.1, v2.3.0a, uses the ssh-rsa signature scheme, which has a SHA-1 hash. The vulnerability could allow a …

Apr 17, 2024
CVE-2024-3914
6.5 MEDIUM

Use after free in V8 in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Apr 17, 2024
CVE-2024-32161
9.8 CRITICAL

jizhiCMS 2.5 suffers from a File upload vulnerability.

Apr 17, 2024
CVE-2024-30988
6.8 MEDIUM

Cross Site Scripting vulnerability in /search-invoices.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows attackers to execute arbitrary code and obtain sensitive …

Apr 17, 2024
CVE-2024-30987
6.8 MEDIUM

Cross Site Scripting vulnerability in /bwdates-reports-ds.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows attackers to execute arbitrary code and obtain sensitive …

Apr 17, 2024
CVE-2024-30986
6.5 MEDIUM

Cross Site Scripting vulnerability in /edit-services-details.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows attackers to execute arbitrary code and via "price" …

Apr 17, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.