CVE Database

39885+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-39928
7.5 HIGH

In Apache Linkis <= 1.5.0, a Random string security vulnerability in Spark EngineConn, random string generated by the Token when starting Py4j uses the Commons …

Sep 25, 2024
CVE-2024-21545
8.2 HIGH

Proxmox Virtual Environment is an open-source server management platform for enterprise virtualization. Insufficient safeguards against malicious API response values allow authenticated attackers with 'Sys.Audit' or …

Sep 25, 2024
CVE-2023-26691
7.2 HIGH

Directory Traversal vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via crafted zip file when installing a new add-on.

Sep 25, 2024
CVE-2023-26690
8.8 HIGH

File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via File Manager/Editor component in the vendor or admin menu.

Sep 25, 2024
CVE-2023-26687
8.8 HIGH

Directory Traversal vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to obtain sensitive information via the product_data parameter in the PDF Add-on.

Sep 25, 2024
CVE-2021-38963
8.0 HIGH

IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by a CSV injection vulnerability. …

Sep 25, 2024
CVE-2024-8623
7.3 HIGH

The The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, …

Sep 24, 2024
CVE-2022-2439
7.2 HIGH

The Easy Digital Downloads – Simple eCommerce for Selling Digital Files plugin for WordPress is vulnerable to deserialization of untrusted input via the 'upload[file]' parameter …

Sep 24, 2024
CVE-2024-8795
8.8 HIGH

The BA Book Everything plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6.20. This is due to …

Sep 24, 2024
CVE-2024-7023
8.8 HIGH

Insufficient data validation in Updater in Google Chrome prior to 128.0.6537.0 allowed a remote attacker to perform privilege escalation via a malicious file. (Chromium security …

Sep 23, 2024
CVE-2024-7018
7.8 HIGH

Heap buffer overflow in PDF in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. …

Sep 23, 2024
CVE-2021-38023
8.8 HIGH

Use after free in Extensions in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. …

Sep 23, 2024
CVE-2018-20072
7.8 HIGH

Insufficient data validation in PDF in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform out of bounds memory access via a crafted …

Sep 23, 2024
CVE-2024-42861
7.5 HIGH

An issue in IEEE 802.1AS linuxptp v.4.2 and before allowing a remote attacker to cause a denial of service via a crafted Pdelay_Req message to …

Sep 23, 2024
CVE-2024-46639
7.6 HIGH

A cross-site scripting (XSS) vulnerability in HelpDeskZ v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name …

Sep 23, 2024
CVE-2024-43201
8.8 HIGH

The Planet Fitness Workouts iOS and Android mobile apps fail to properly validate TLS certificates, allowing an attacker with appropriate network access to obtain session …

Sep 23, 2024
CVE-2024-37779
8.8 HIGH

WoodWing Elvis DAM v6.98.1 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the Apache Ant script functionality.

Sep 23, 2024
CVE-2024-39842
7.2 HIGH

A SQL injection vulnerability in Centreon 24.04.2 allows a remote high-privileged attacker to execute arbitrary SQL command via user massive changes inputs.

Sep 23, 2024
CVE-2024-40442
7.2 HIGH

An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pipeline module to annotate a document automatically v.0.1.23 …

Sep 23, 2024
CVE-2024-46985
7.5 HIGH

DataEase is an open source data visualization analysis tool. Prior to version 2.10.1, there is an XML external entity injection vulnerability in the static resource …

Sep 23, 2024
CVE-2024-41228
7.6 HIGH

A symlink following vulnerability in the pouch cp function of AliyunContainerService pouch v1.3.1 allows attackers to escalate privileges and write arbitrary files.

Sep 23, 2024
CVE-2024-23934
8.8 HIGH

Sony XAV-AX5500 WMV/ASF Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sony …

Sep 23, 2024
CVE-2024-8606
8.8 HIGH

Bypass of two factor authentication in RestAPI in Checkmk < 2.3.0p16 and < 2.2.0p34 allows authenticated users to bypass two factor authentication

Sep 23, 2024
CVE-2024-9091
7.3 HIGH

A vulnerability was found in code-projects Student Record System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of …

Sep 23, 2024
CVE-2024-43989
7.5 HIGH

Server-Side Request Forgery (SSRF) vulnerability in Firsh Justified Image Grid justified-image-grid.This issue affects Justified Image Grid: from n/a through <= 4.6.1.

Sep 23, 2024
CVE-2024-9087
7.3 HIGH

A vulnerability, which was classified as critical, was found in code-projects Vehicle Management 1.0. This affects an unknown part of the file /edit1.php. The manipulation …

Sep 22, 2024
CVE-2024-9085
7.3 HIGH

A vulnerability was found in code-projects Restaurant Reservation System 1.0. It has been rated as critical. This issue affects some unknown processing of the file …

Sep 22, 2024
CVE-2024-9080
7.3 HIGH

A vulnerability was found in code-projects Student Record System 1.0. It has been classified as critical. Affected is an unknown function of the file /pincode-verification.php. …

Sep 22, 2024
CVE-2024-9079
7.3 HIGH

A vulnerability was found in code-projects Student Record System 1.0 and classified as critical. This issue affects some unknown processing of the file /marks.php. The …

Sep 22, 2024
CVE-2024-9078
7.3 HIGH

A vulnerability has been found in code-projects Student Record System 1.0 and classified as critical. This vulnerability affects unknown code of the file /course.php. The …

Sep 22, 2024
CVE-2024-47221
7.5 HIGH

CheckUser in ScadaServerEngine/MainLogic.cs in Rapid SCADA through 5.8.4 allows an empty password.

Sep 22, 2024
CVE-2024-47210
8.8 HIGH

Gladys Assistant before 4.45.1 allows Privilege Escalation (a user changing their own role) because req.body.role can be used in updateMySelf in server/api/controllers/user.controller.js.

Sep 21, 2024
CVE-2024-42323
8.8 HIGH

SnakeYaml Deser Load Malicious xml rce vulnerability in Apache HertzBeat (incubating). This vulnerability can only be exploited by authorized attackers. This issue affects Apache HertzBeat …

Sep 21, 2024
CVE-2024-46649
7.5 HIGH

eNMS up to 4.7.1 is vulnerable to Directory Traversal via download/folder.

Sep 20, 2024
CVE-2024-46648
7.5 HIGH

eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via scan_folder.

Sep 20, 2024
CVE-2024-46645
7.5 HIGH

eNMS 4.0.0 is vulnerable to Directory Traversal via get_tree_files.

Sep 20, 2024
CVE-2024-47062
8.8 HIGH

Navidrome is an open source web-based music collection server and streamer. Navidrome automatically adds parameters in the URL to SQL queries. This can be exploited …

Sep 20, 2024
CVE-2024-47061
8.3 HIGH

Plate is a javascript toolkit that makes it easier for you to develop with Slate, a popular framework for building text editors. One longstanding feature …

Sep 20, 2024
CVE-2024-42346
7.6 HIGH

Galaxy is a free, open-source system for analyzing data, authoring workflows, training and education, publishing tools, managing infrastructure, and more. The editor visualization, /visualizations endpoint, …

Sep 20, 2024
CVE-2023-47480
8.4 HIGH

An issue in Pure Data 0.54-0 and fixed in 0.54-1 allows a local attacker to escalate privileges via the set*id () function.

Sep 20, 2024
CVE-2024-9039
7.3 HIGH

A vulnerability, which was classified as critical, has been found in SourceCodester Best House Rental Management System 1.0. Affected by this issue is some unknown …

Sep 20, 2024
CVE-2024-9037
7.3 HIGH

A vulnerability classified as critical has been found in Codezips Internal Marks Calculation 1.0. Affected is an unknown function of the file index.php. The manipulation …

Sep 20, 2024
CVE-2024-9035
7.3 HIGH

A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been classified as critical. This affects an unknown part of the file …

Sep 20, 2024
CVE-2024-9034
7.3 HIGH

A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the …

Sep 20, 2024
CVE-2024-41721
8.1 HIGH

An insufficient boundary validation in the USB code could lead to an out-of-bounds read on the heap, which could potentially lead to an arbitrary write …

Sep 20, 2024
CVE-2024-47000
8.1 HIGH

Zitadel is an open source identity management platform. ZITADEL's user account deactivation mechanism did not work correctly with service accounts. Deactivated service accounts retained the …

Sep 20, 2024
CVE-2024-46999
7.3 HIGH

Zitadel is an open source identity management platform. ZITADEL's user grants deactivation mechanism did not work correctly. Deactivated user grants were still provided in token, …

Sep 20, 2024
CVE-2024-45807
7.5 HIGH

Envoy is a cloud-native high-performance edge/middle/service proxy. Envoy's 1.31 is using `oghttp` as the default HTTP/2 codec, and there are potential bugs around stream management …

Sep 20, 2024
CVE-2024-46984
8.6 HIGH

The reference validator is a tool to perform advanced validation of FHIR resources for TI applications and interoperability standards. The profile location routine in the …

Sep 19, 2024
CVE-2024-38016
7.8 HIGH

Microsoft Office Visio Remote Code Execution Vulnerability

Sep 19, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.