CVE Database

39885+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-45823
8.1 HIGH

CVE-2024-45823 IMPACT An authentication bypass vulnerability exists in the affected product. The vulnerability exists due to shared secrets across accounts and could allow a threat …

Sep 12, 2024
CVE-2024-45857
7.8 HIGH

Deserialization of untrusted data can occur in versions 2.4.0 or newer of the Cleanlab project, enabling a maliciously crafted datalab.pkl file to run arbitrary code …

Sep 12, 2024
CVE-2024-45855
7.1 HIGH

Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code …

Sep 12, 2024
CVE-2024-45854
7.1 HIGH

Deserialization of untrusted data can occur in versions 23.10.3.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code …

Sep 12, 2024
CVE-2024-45853
7.1 HIGH

Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code …

Sep 12, 2024
CVE-2024-45852
8.8 HIGH

Deserialization of untrusted data can occur in versions 23.3.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded model to run arbitrary code on …

Sep 12, 2024
CVE-2024-45851
8.8 HIGH

An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the …

Sep 12, 2024
CVE-2024-45850
8.8 HIGH

An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the …

Sep 12, 2024
CVE-2024-45849
8.8 HIGH

An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the …

Sep 12, 2024
CVE-2024-45848
8.8 HIGH

An arbitrary code execution vulnerability exists in versions 23.12.4.0 up to 24.7.4.1 of the MindsDB platform, when the ChromaDB integration is installed on the server. …

Sep 12, 2024
CVE-2024-45847
8.8 HIGH

An arbitrary code execution vulnerability exists in versions 23.11.4.2 up to 24.7.4.1 of the MindsDB platform, when one of several integrations is installed on the …

Sep 12, 2024
CVE-2024-45846
8.8 HIGH

An arbitrary code execution vulnerability exists in versions 23.10.3.0 up to 24.7.4.1 of the MindsDB platform, when the Weaviate integration is installed on the server. …

Sep 12, 2024
CVE-2024-3306
7.5 HIGH

Authorization Bypass Through User-Controlled Key vulnerability in Utarit Information SoliClub allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SoliClub: before 4.4.0 for iOS, …

Sep 12, 2024
CVE-2024-3305
7.5 HIGH

Authorization Bypass Through User-Controlled Key, Missing Authorization vulnerability in Utarit Information SoliClub allows Retrieve Embedded Sensitive Data. This issue affects SoliClub: before 4.4.0 for iOS, …

Sep 12, 2024
CVE-2024-27321
7.8 HIGH

An arbitrary code execution vulnerability exists in versions 0.0.8 and newer of the Refuel Autolabel library because of the way its multilabel classification tasks handle …

Sep 12, 2024
CVE-2024-27320
7.8 HIGH

An arbitrary code execution vulnerability exists in versions 0.0.8 and newer of the Refuel Autolabel library because of the way its classification tasks handle provided …

Sep 12, 2024
CVE-2021-38133
7.4 HIGH

Possible External Service Interaction attack in eDirectory has been discovered in OpenText™ eDirectory. This impact all version before 9.2.6.0000.

Sep 12, 2024
CVE-2021-22532
7.6 HIGH

Possible NLDAP Denial of Service attack Vulnerability in eDirectory has been discovered in OpenText™ eDirectory before 9.2.4.0000.

Sep 12, 2024
CVE-2024-8749
8.8 HIGH

SQL injection vulnerability in idoit pro version 28. This vulnerability could allow an attacker to send a specially crafted query to the ID parameter in …

Sep 12, 2024
CVE-2024-7766
7.2 HIGH

The Adicon Server WordPress plugin through 1.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform …

Sep 12, 2024
CVE-2024-45624
7.5 HIGH

Exposure of sensitive information due to incompatible policies issue exists in Pgpool-II. If a database user accesses a query cache, table data unauthorized for the …

Sep 12, 2024
CVE-2024-37397
8.2 HIGH

An External XML Entity (XXE) vulnerability in the provisioning web service of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote …

Sep 12, 2024
CVE-2024-34785
7.2 HIGH

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve …

Sep 12, 2024
CVE-2024-34783
7.2 HIGH

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve …

Sep 12, 2024
CVE-2024-34779
7.2 HIGH

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve …

Sep 12, 2024
CVE-2024-32848
7.2 HIGH

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve …

Sep 12, 2024
CVE-2024-32846
7.2 HIGH

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve …

Sep 12, 2024
CVE-2024-32845
7.2 HIGH

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve …

Sep 12, 2024
CVE-2024-32843
7.2 HIGH

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve …

Sep 12, 2024
CVE-2024-32842
7.2 HIGH

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve …

Sep 12, 2024
CVE-2024-32840
7.2 HIGH

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve …

Sep 12, 2024
CVE-2024-28981
8.5 HIGH

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.8, including 8.3.x, discloses database passwords when searching metadata injectable fields.

Sep 12, 2024
CVE-2024-7890
7.3 HIGH

Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows

Sep 11, 2024
CVE-2024-7889
7.3 HIGH

Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows

Sep 11, 2024
CVE-2024-42760
7.5 HIGH

SQL Injection vulnerability in Ellevo v.6.2.0.38160 allows a remote attacker to obtain sensitive information via the /api/mob/instrucao/conta/destinatarios component.

Sep 11, 2024
CVE-2024-8691
7.1 HIGH

A vulnerability in the GlobalProtect portal in Palo Alto Networks PAN-OS software enables a malicious authenticated GlobalProtect user to impersonate another GlobalProtect user. Active GlobalProtect …

Sep 11, 2024
CVE-2024-8687
7.1 HIGH

An information exposure vulnerability exists in Palo Alto Networks PAN-OS software that enables a GlobalProtect end user to learn both the configured GlobalProtect uninstall password …

Sep 11, 2024
CVE-2024-8686
7.2 HIGH

A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as root on …

Sep 11, 2024
CVE-2024-44577
8.8 HIGH

RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the time_date function.

Sep 11, 2024
CVE-2024-44574
8.8 HIGH

RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the sys_conf function.

Sep 11, 2024
CVE-2024-44572
8.8 HIGH

RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the sys_mgmt function.

Sep 11, 2024
CVE-2024-44571
8.8 HIGH

RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain incorrect access control in the mService function at phpinf.php.

Sep 11, 2024
CVE-2024-44570
8.8 HIGH

RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a code injection vulnerability via the getParams function in phpinf.php.

Sep 11, 2024
CVE-2024-20489
8.4 HIGH

A vulnerability in the storage method of the PON Controller configuration file could allow an authenticated, local attacker with low privileges to obtain the MongoDB …

Sep 11, 2024
CVE-2024-20483
7.2 HIGH

Multiple vulnerabilities in Cisco Routed PON Controller Software, which runs as a docker container on hardware that is supported by Cisco IOS XR Software, could …

Sep 11, 2024
CVE-2024-20406
7.4 HIGH

A vulnerability in the segment routing feature for the Intermediate System-to-Intermediate System (IS-IS) protocol of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker …

Sep 11, 2024
CVE-2024-20398
8.8 HIGH

A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to obtain read/write file system access on the underlying …

Sep 11, 2024
CVE-2024-20381
8.8 HIGH

A vulnerability in the JSON-RPC API feature in Cisco Crosswork Network Services Orchestrator (NSO) and ConfD that is used by the web-based management interfaces of …

Sep 11, 2024
CVE-2024-20317
7.4 HIGH

A vulnerability in the handling of specific Ethernet frames by Cisco IOS XR Software for various Cisco Network Convergence System (NCS) platforms could allow an …

Sep 11, 2024
CVE-2024-20304
8.6 HIGH

A vulnerability in the multicast traceroute version 2 (Mtrace2) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to exhaust the UDP …

Sep 11, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.