CVE Database

122339+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-0778
8.0 HIGH

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in Uniview ISC 2500-S up to 20210930. Affected by this …

Jan 22, 2024
CVE-2024-22895
8.8 HIGH

DedeCMS 5.7.112 has a File Upload vulnerability via uploads/dede/module_upload.php.

Jan 22, 2024
CVE-2024-0706

Rejected reason: ***REJECT*** This was a false positive report.

Jan 22, 2024
CVE-2023-44395
4.9 MEDIUM

Autolab is a course management service that enables instructors to offer autograded programming assignments to their students over the Web. Path traversal vulnerabilities were discovered …

Jan 22, 2024
CVE-2020-36772
4.4 MEDIUM

CloudLinux CageFS 7.0.8-2 or below insufficiently restricts file paths supplied to the sendmail proxy command. This allows local users to read and write arbitrary files …

Jan 22, 2024
CVE-2020-36771
7.8 HIGH

CloudLinux CageFS 7.1.1-1 or below passes the authentication token as a command line argument. In some configurations this allows local users to view the authentication …

Jan 22, 2024
CVE-2024-22233
7.5 HIGH

In Spring Framework versions 6.0.15 and 6.1.2, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) …

Jan 22, 2024
CVE-2024-0775
6.7 MEDIUM

A use-after-free flaw was found in the __ext4_remount in fs/ext4/super.c in ext4 in the Linux kernel. This flaw allows a local user to cause an …

Jan 22, 2024
CVE-2023-52354
7.5 HIGH

chasquid before 1.13 allows SMTP smuggling because LF-terminated lines are accepted.

Jan 22, 2024
CVE-2017-20189
9.8 CRITICAL

In Clojure before 1.9.0, classes can be used to construct a serialized object that executes arbitrary code upon deserialization. This is relevant if a server …

Jan 22, 2024
CVE-2024-22113
6.1 MEDIUM

Open redirect vulnerability in Access analysis CGI An-Analyzer released in 2023 December 31 and earlier allows a remote unauthenticated attacker to redirect users to arbitrary …

Jan 22, 2024
CVE-2024-21484
7.5 HIGH

Versions of the package jsrsasign before 11.0.0 are vulnerable to Observable Discrepancy via the RSA PKCS1.5 or RSAOAEP decryption process. An attacker can decrypt ciphertexts …

Jan 22, 2024
CVE-2023-47352
8.8 HIGH

Technicolor TC8715D devices have predictable default WPA2 security passwords. An attacker who scans for SSID and BSSID values may be able to predict these passwords.

Jan 22, 2024
CVE-2024-23771
9.8 CRITICAL

darkhttpd before 1.15 uses strcmp (which is not constant time) to verify authentication, which makes it easier for remote attackers to bypass authentication via a …

Jan 22, 2024
CVE-2024-23770
5.5 MEDIUM

darkhttpd through 1.15 allows local users to discover credentials (for --auth) by listing processes and their arguments.

Jan 22, 2024
CVE-2024-23768
8.8 HIGH

Dremio before 24.3.1 allows path traversal. An authenticated user who has no privileges on certain folders (and the files and datasets in these folders) can …

Jan 22, 2024
CVE-2024-23752
9.8 CRITICAL

GenerateSDFPipeline in synthetic_dataframe in PandasAI (aka pandas-ai) through 1.5.17 allows attackers to trigger the generation of arbitrary Python code that is executed by SDFCodeExecutor. An …

Jan 22, 2024
CVE-2024-23751
9.8 CRITICAL

LlamaIndex (aka llama_index) through 0.9.34 allows SQL injection via the Text-to-SQL feature in NLSQLTableQueryEngine, SQLTableRetrieverQueryEngine, NLSQLRetriever, RetrieverQueryEngine, and PGVectorSQLQueryEngine. For example, an attacker might be …

Jan 22, 2024
CVE-2024-23750
8.8 HIGH

MetaGPT through 0.6.4 allows the QaEngineer role to execute arbitrary code because RunCode.run_script() passes shell metacharacters to subprocess.Popen.

Jan 22, 2024
CVE-2024-0776
3.5 LOW

A vulnerability, which was classified as problematic, has been found in LinZhaoguan pb-cms 2.0. Affected by this issue is some unknown functionality of the component …

Jan 22, 2024
CVE-2024-0774
5.3 MEDIUM

A vulnerability was found in Any-Capture Any Sound Recorder 2.93. It has been declared as problematic. This vulnerability affects unknown code of the component Registration …

Jan 22, 2024
CVE-2024-0773
3.5 LOW

A vulnerability classified as problematic was found in CodeAstro Internet Banking System 1.0. Affected by this vulnerability is an unknown functionality of the file pages_client_signup.php. …

Jan 22, 2024
CVE-2024-0772
5.3 MEDIUM

A vulnerability was found in Nsasoft ShareAlarmPro 2.1.4 and classified as problematic. Affected by this issue is some unknown functionality of the component Registration Handler. …

Jan 22, 2024
CVE-2024-23744
7.5 HIGH

An issue was discovered in Mbed TLS 3.5.1. There is persistent handshake denial if a client sends a TLS 1.3 ClientHello without extensions.

Jan 21, 2024
CVE-2024-0771
5.3 MEDIUM

A vulnerability has been found in Nsasoft Product Key Explorer 4.0.9 and classified as problematic. Affected by this vulnerability is an unknown functionality of the …

Jan 21, 2024
CVE-2024-0770
4.4 MEDIUM

A vulnerability, which was classified as critical, was found in European Chemicals Agency IUCLID 7.10.3 on Windows. Affected is an unknown function of the file …

Jan 21, 2024
CVE-2023-52353
7.5 HIGH

An issue was discovered in Mbed TLS through 3.5.1. In mbedtls_ssl_session_reset, the maximum negotiable TLS version is mishandled. For example, if the last connection negotiated …

Jan 21, 2024
CVE-2024-23732
7.5 HIGH

The JSON loader in Embedchain before 0.1.57 allows a ReDoS (regular expression denial of service) via a long string to json.py.

Jan 21, 2024
CVE-2024-23731
9.8 CRITICAL

The OpenAPI loader in Embedchain before 0.1.57 allows attackers to execute arbitrary code, related to the openapi.py yaml.load function argument.

Jan 21, 2024
CVE-2024-23730
9.8 CRITICAL

The OpenAPI and ChatGPT plugin loaders in LlamaHub (aka llama-hub) before 0.0.67 allow attackers to execute arbitrary code because safe_load is not used for YAML.

Jan 21, 2024
CVE-2023-6531
7.0 HIGH

A use-after-free flaw was found in the Linux Kernel due to a race problem in the unix garbage collector's deletion of SKB races with unix_stream_read_generic() …

Jan 21, 2024
CVE-2024-0769
5.3 MEDIUM KEV

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DIR-859 1.06B01. It has been rated as critical. Affected by this issue is some …

Jan 21, 2024
CVE-2016-15037
2.4 LOW

A vulnerability, which was classified as problematic, has been found in go4rayyan Scumblr up to 2.0.1a. Affected by this issue is some unknown functionality of …

Jan 21, 2024
CVE-2024-23726
8.8 HIGH

Ubee DDW365 XCNDDW365 devices have predictable default WPA2 PSKs that could lead to unauthorized remote access. A remote attacker (in proximity to a Wi-Fi network) …

Jan 21, 2024
CVE-2024-23725
6.1 MEDIUM

Ghost before 5.76.0 allows XSS via a post excerpt in excerpt.js. An XSS payload can be rendered in post summaries.

Jan 21, 2024
CVE-2024-0521
7.8 HIGH

Code Injection in paddlepaddle/paddle

Jan 20, 2024
CVE-2023-7063
7.2 HIGH

The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission parameters in all versions up to, and including, 1.8.5.3 due …

Jan 20, 2024
CVE-2024-0679
6.5 MEDIUM

The ColorMag theme for WordPress is vulnerable to unauthorized access due to a missing capability check on the plugin_action_callback() function in all versions up to, …

Jan 20, 2024
CVE-2024-0623
4.3 MEDIUM

The VK Block Patterns plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.31.1.1. This is due to …

Jan 20, 2024
CVE-2023-46447
4.3 MEDIUM

The POPS! Rebel application 5.0 for Android, in POPS! Rebel Bluetooth Glucose Monitoring System, sends unencrypted glucose measurements over BLE.

Jan 20, 2024
CVE-2023-51925
9.8 CRITICAL

An arbitrary file upload vulnerability in the nccloud.web.arcp.taskmonitor.action.ArcpUploadAction.doAction() method of YonBIP v3_23.05 allows attackers to execute arbitrary code via uploading a crafted file.

Jan 20, 2024
CVE-2023-51924
9.8 CRITICAL

An arbitrary file upload vulnerability in the uap.framework.rc.itf.IResourceManager interface of YonBIP v3_23.05 allows attackers to execute arbitrary code via uploading a crafted file.

Jan 20, 2024
CVE-2023-51906
9.8 CRITICAL

An issue in yonyou YonBIP v3_23.05 allows a remote attacker to execute arbitrary code via a crafted script to the ServiceDispatcherServlet uap.framework.rc.itf.IResourceManager component.

Jan 20, 2024
CVE-2023-47024
8.8 HIGH

Cross-Site Request Forgery (CSRF) in NCR Terminal Handler v.1.5.1 leads to a one-click account takeover. This is achieved by exploiting multiple vulnerabilities, including an undisclosed …

Jan 20, 2024
CVE-2023-51928
9.8 CRITICAL

An arbitrary file upload vulnerability in the nccloud.web.arcp.taskmonitor.action.ArcpUploadAction.doAction() method of YonBIP v3_23.05 allows attackers to execute arbitrary code via uploading a crafted file.

Jan 20, 2024
CVE-2023-51927
9.8 CRITICAL

YonBIP v3_23.05 was discovered to contain a SQL injection vulnerability via the com.yonyou.hrcloud.attend.web.AttendScriptController.runScript() method.

Jan 20, 2024
CVE-2023-51926
7.5 HIGH

YonBIP v3_23.05 was discovered to contain an arbitrary file read vulnerability via the nc.bs.framework.comn.serv.CommonServletDispatcher component.

Jan 20, 2024
CVE-2023-51892
9.8 CRITICAL

An issue in weaver e-cology v.10.0.2310.01 allows a remote attacker to execute arbitrary code via a crafted script to the FrameworkShellController component.

Jan 20, 2024
CVE-2021-31314
9.8 CRITICAL

File upload vulnerability in ejinshan v8+ terminal security system allows attackers to upload arbitrary files to arbitrary locations on the server.

Jan 20, 2024
CVE-2024-23332
4.0 MEDIUM

The Notary Project is a set of specifications and tools intended to provide a cross-industry standard for securing software supply chains by using authentic container …

Jan 19, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.