CVE Database

122268+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-25646
7.7 HIGH

Due to improper validation, SAP BusinessObject Business Intelligence Launch Pad allows an authenticated attacker to access operating system information using crafted document. On successful exploitation …

Apr 9, 2024
CVE-2024-31047
3.3 LOW

An issue in Academy Software Foundation openexr v.3.2.3 and before allows a local attacker to cause a denial of service (DoS) via the convert function …

Apr 8, 2024
CVE-2024-23584
6.6 MEDIUM

The NMAP Importer service​ may expose data store credentials to authorized users of the Windows Registry.

Apr 8, 2024
CVE-2024-23084
7.5 HIGH

Apfloat v1.10.1 was discovered to contain an ArrayIndexOutOfBoundsException via the component org.apfloat.internal.DoubleCRTMath::add(double[], double[]). NOTE: this is disputed by multiple third parties who believe there was …

Apr 8, 2024
CVE-2024-23081
3.3 LOW

ThreeTen Backport v1.6.8 was discovered to contain a NullPointerException via the component org.threeten.bp.LocalDate::compareTo(ChronoLocalDate). NOTE: this is disputed by multiple third parties who believe there was …

Apr 8, 2024
CVE-2024-23079
6.2 MEDIUM

JGraphT Core v1.5.2 was discovered to contain a NullPointerException via the component org.jgrapht.alg.util.ToleranceDoubleComparator::compare(Double, Double). NOTE: this is disputed by multiple third parties who believe there …

Apr 8, 2024
CVE-2024-22949
9.1 CRITICAL

JFreeChart v1.5.4 was discovered to contain a NullPointerException via the component /chart/annotations/CategoryLineAnnotation. NOTE: this is disputed by multiple third parties who believe there was not …

Apr 8, 2024
CVE-2024-27632
8.8 HIGH

An issue in GNU Savane v.3.12 and before allows a remote attacker to escalate privileges via the form_id in the form_header() function.

Apr 8, 2024
CVE-2024-0083
6.5 MEDIUM

NVIDIA ChatRTX for Windows contains a vulnerability in the UI, where an attacker can cause a cross-site scripting error by network by running malicious scripts …

Apr 8, 2024
CVE-2024-0082
8.2 HIGH

NVIDIA ChatRTX for Windows contains a vulnerability in the UI, where an attacker can cause improper privilege management by sending open file requests to the …

Apr 8, 2024
CVE-2024-3466
5.5 MEDIUM

A vulnerability was found in SourceCodester Laundry Management System 1.0. It has been declared as critical. Affected by this vulnerability is the function laporan_filter of …

Apr 8, 2024
CVE-2024-3465
6.3 MEDIUM

A vulnerability was found in SourceCodester Laundry Management System 1.0. It has been classified as critical. Affected is the function laporan_filter of the file /application/controller/Transaki.php. …

Apr 8, 2024
CVE-2024-27631
6.0 MEDIUM

Cross Site Request Forgery vulnerability in GNU Savane v.3.12 and before allows a remote attacker to escalate privileges via siteadmin/usergroup.php

Apr 8, 2024
CVE-2024-27630
7.5 HIGH

Insecure Direct Object Reference (IDOR) in GNU Savane v.3.12 and before allows a remote attacker to delete arbitrary files via crafted input to the trackers_data_delete_file …

Apr 8, 2024
CVE-2024-3464
6.3 MEDIUM

A vulnerability was found in SourceCodester Laundry Management System 1.0 and classified as critical. This issue affects the function laporan_filter of the file /application/controller/Pelanggan.php. The …

Apr 8, 2024
CVE-2024-3463
3.5 LOW

A vulnerability has been found in SourceCodester Laundry Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /karyawan/edit. The …

Apr 8, 2024
CVE-2024-24279
8.8 HIGH

An issue in secdiskapp 1.5.1 (management program for NewQ Fingerprint Encryption Super Speed Flash Disk) allows attackers to gain escalated privileges via vsVerifyPassword and vsSetFingerPrintPower …

Apr 8, 2024
CVE-2024-23086
9.8 CRITICAL

Apfloat v1.10.1 was discovered to contain a stack overflow via the component org.apfloat.internal.DoubleModMath::modPow(double. NOTE: this is disputed by multiple third parties who believe there was …

Apr 8, 2024
CVE-2024-23085
7.5 HIGH

Apfloat v1.10.1 was discovered to contain a NullPointerException via the component org.apfloat.internal.DoubleScramble::scramble(double[], int, int[]). NOTE: this is disputed by multiple third parties who believe there …

Apr 8, 2024
CVE-2024-23078
9.1 CRITICAL

JGraphT Core v1.5.2 was discovered to contain a NullPointerException via the component org.jgrapht.alg.util.ToleranceDoubleComparator::compare(Double, Double). NOTE: this is disputed by multiple third parties who believe there …

Apr 8, 2024
CVE-2024-28270
8.1 HIGH

An issue discovered in web-flash v3.0 allows attackers to reset passwords for arbitrary users via crafted POST request to /prod-api/user/resetPassword.

Apr 8, 2024
CVE-2024-28224
6.6 MEDIUM

Ollama before 0.1.29 has a DNS rebinding vulnerability that can inadvertently allow remote access to the full API, thereby letting an unauthorized user chat with …

Apr 8, 2024
CVE-2024-3458
6.3 MEDIUM

A vulnerability classified as critical was found in Netentsec NS-ASG Application Security Gateway 6.3. This vulnerability affects unknown code of the file /admin/add_ikev2.php. The manipulation …

Apr 8, 2024
CVE-2024-3457
6.3 MEDIUM

A vulnerability classified as critical has been found in Netentsec NS-ASG Application Security Gateway 6.3. This affects an unknown part of the file /admin/config_ISCGroupNoCache.php. The …

Apr 8, 2024
CVE-2024-23082

ThreeTen Backport v1.6.8 was discovered to contain an integer overflow via the component org.threeten.bp.format.DateTimeFormatter::parse(CharSequence, ParsePosition). NOTE: this is disputed by multiple third parties who believe …

Apr 8, 2024
CVE-2023-7164
7.5 HIGH

The BackWPup WordPress plugin before 4.0.4 does not prevent Directory Listing in its temporary backup folder, allowing unauthenticated attackers to download backups of a site's …

Apr 8, 2024
CVE-2024-3456
6.3 MEDIUM

A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been rated as critical. Affected by this issue is some unknown functionality …

Apr 8, 2024
CVE-2024-3455
6.3 MEDIUM

A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Apr 8, 2024
CVE-2024-3445
6.3 MEDIUM

A vulnerability was found in SourceCodester Laundry Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /karyawan/laporan_filter. …

Apr 8, 2024
CVE-2024-31447
5.3 MEDIUM

Shopware 6 is an open commerce platform based on Symfony Framework and Vue. Starting in version 6.3.5.0 and prior to versions 6.6.1.0 and 6.5.8.8, when …

Apr 8, 2024
CVE-2024-31442
8.8 HIGH

Redon Hub is a Roblox Product Delivery Bot, also known as a Hub. In all hubs before version 1.0.2, all commands are capable of being …

Apr 8, 2024
CVE-2024-31224
9.8 CRITICAL

GPT Academic provides interactive interfaces for large language models. A vulnerability was found in gpt_academic versions 3.64 through 3.73. The server deserializes untrustworthy data from …

Apr 8, 2024
CVE-2024-3444
4.7 MEDIUM

A vulnerability was found in Wangshen SecGate 3600 up to 20240408. It has been classified as critical. This affects an unknown part of the file …

Apr 8, 2024
CVE-2024-3443
3.5 LOW

A vulnerability classified as problematic was found in SourceCodester Prison Management System 1.0. This vulnerability affects unknown code of the file /Employee/apply_leave.php. The manipulation of …

Apr 8, 2024
CVE-2024-3442
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Prison Management System 1.0. This affects an unknown part of the file /Employee/delete_leave.php. The manipulation …

Apr 8, 2024
CVE-2024-31221
5.9 MEDIUM

Sunshine is a self-hosted game stream host for Moonlight. Starting in version 0.10.0 and prior to version 0.23.0, after unpairing all devices in the web …

Apr 8, 2024
CVE-2024-31205
4.2 MEDIUM

Saleor is an e-commerce platform. Starting in version 3.10.0 and prior to versions 3.14.64, 3.15.39, 3.16.39, 3.17.35, 3.18.31, and 3.19.19, an attacker may bypass cross-set …

Apr 8, 2024
CVE-2024-30269
5.3 MEDIUM

DataEase, an open source data visualization and analysis tool, has a database configuration information exposure vulnerability prior to version 2.5.0. Visiting the `/de2api/engine/getEngine;.js` path via …

Apr 8, 2024
CVE-2024-3441
6.3 MEDIUM

A vulnerability was found in SourceCodester Prison Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of …

Apr 8, 2024
CVE-2024-3440
4.7 MEDIUM

A vulnerability was found in SourceCodester Prison Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Apr 8, 2024
CVE-2024-2511
5.9 MEDIUM

Issue summary: Some non-default TLS server configurations can cause unbounded memory growth when processing TLSv1.3 sessions Impact summary: An attacker may exploit certain server configurations …

Apr 8, 2024
CVE-2024-28732
7.5 HIGH

An issue was discovered in OFPMatch in parser.py in Faucet SDN Ryu version 4.34, allows remote attackers to cause a denial of service (DoS) (infinite …

Apr 8, 2024
CVE-2024-31817
7.5 HIGH

In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getSysStatusCfg.

Apr 8, 2024
CVE-2024-31816
7.5 HIGH

In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getEasyWizardCfg.

Apr 8, 2024
CVE-2024-31815
9.1 CRITICAL

In TOTOLINK EX200 V4.0.3c.7314_B20191204, an attacker can obtain the configuration file without authorization through /cgi-bin/ExportSettings.sh

Apr 8, 2024
CVE-2024-31814
8.8 HIGH

TOTOLINK EX200 V4.0.3c.7646_B20201211 allows attackers to bypass login through the Form_Login function.

Apr 8, 2024
CVE-2024-31813
8.4 HIGH

TOTOLINK EX200 V4.0.3c.7646_B20201211 does not contain an authentication mechanism by default.

Apr 8, 2024
CVE-2024-31812
6.5 MEDIUM

In TOTOLINK EX200 V4.0.3c.7646_B20201211, an attacker can obtain sensitive information without authorization through the function getWiFiExtenderConfig.

Apr 8, 2024
CVE-2024-31811
8.0 HIGH

TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the langType parameter in the setLanguageCfg function.

Apr 8, 2024
CVE-2024-31809
8.8 HIGH

TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the FileName parameter in the setUpgradeFW function.

Apr 8, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.