CVE Database

46624+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-49777
8.8 HIGH

A heap-based buffer overflow in tsMuxer version nightly-2024-03-14-01-51-12 allows attackers to cause Denial of Service (DoS), Information Disclosure and Code Execution via a crafted MKV …

Nov 14, 2024
CVE-2024-41209
8.8 HIGH

A heap-based buffer overflow in tsMuxer version nightly-2024-03-14-01-51-12 allows attackers to cause Denial of Service (DoS) and Code Execution via a crafted MOV video file.

Nov 14, 2024
CVE-2024-51679
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in gentlesource Appointmind appointmind allows Stored XSS.This issue affects Appointmind: from n/a through <= 4.0.0.

Nov 14, 2024
CVE-2024-51659
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in GeekRMX Twitter @Anywhere Plus twitter-anywhere-plus allows Stored XSS.This issue affects Twitter @Anywhere Plus: from n/a through <= 2.0.

Nov 14, 2024
CVE-2024-51658
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Henrik Hoff WP Course Manager wp-course-manager allows Stored XSS.This issue affects WP Course Manager: from n/a through <= 1.3.

Nov 14, 2024
CVE-2024-50968
7.5 HIGH

A business logic vulnerability exists in the Add to Cart function of itsourcecode Agri-Trading Online Shopping System 1.0, which allows remote attackers to manipulate the …

Nov 14, 2024
CVE-2024-51687
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Platform.ly Platform.ly Official platformly allows Stored XSS.This issue affects Platform.ly Official: from n/a through <= 1.1.3.

Nov 14, 2024
CVE-2024-51684
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in Ciprian Popescu W3P SEO wp-perfect-plugin allows Stored XSS.This issue affects W3P SEO: from n/a through < 1.8.6.

Nov 14, 2024
CVE-2024-51688
7.1 HIGH

Cross-Site Request Forgery (CSRF) vulnerability in fraudlabspro FraudLabs Pro SMS Verification fraudlabs-pro-sms-verification allows Stored XSS.This issue affects FraudLabs Pro SMS Verification: from n/a through <= …

Nov 14, 2024
CVE-2024-10397
7.8 HIGH

A malicious server can crash the OpenAFS cache manager and other client utilities, and possibly execute arbitrary code.

Nov 14, 2024
CVE-2024-10394
7.8 HIGH

A local user can bypass the OpenAFS PAG (Process Authentication Group) throttling mechanism in Unix clients, allowing the user to create a PAG using an …

Nov 14, 2024
CVE-2024-3760
7.5 HIGH

In lunary-ai/lunary version 1.2.7, there is a lack of rate limiting on the forgot password page, leading to an email bombing vulnerability. Attackers can exploit …

Nov 14, 2024
CVE-2024-5125
7.3 HIGH

parisneo/lollms-webui version 9.6 is vulnerable to Cross-Site Scripting (XSS) and Open Redirect due to inadequate input validation and processing of SVG files during the upload …

Nov 14, 2024
CVE-2024-52383
7.5 HIGH

Missing Authorization vulnerability in aitool Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in One ai-auto-tool allows Exploiting Incorrectly Configured Access Control …

Nov 14, 2024
CVE-2024-52381
8.1 HIGH

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Shoaib Rehmat ZIJ KART zij-kart allows PHP Local File …

Nov 14, 2024
CVE-2024-52378
7.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in labs64 DigiPass digipass allows Absolute Path Traversal.This issue affects DigiPass: from n/a …

Nov 14, 2024
CVE-2024-52371
8.6 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in DonnellC Global Gateway e4 | Payeezy Gateway | globe-gateway-e4.This issue affects Global …

Nov 14, 2024
CVE-2024-50831
7.2 HIGH

A SQL Injection was found in /admin/admin_user.php in kashipara E-learning Management System Project 1.0 via the username and password parameters.

Nov 14, 2024
CVE-2024-50830
7.2 HIGH

A SQL Injection vulnerability was found in /admin/calendar_of_events.php in kashipara E-learning Management System Project 1.0 via the date_start, date_end, and title parameters.

Nov 14, 2024
CVE-2024-50829
7.2 HIGH

A SQL Injection vulnerability was found in /admin/edit_subject.php in kashipara E-learning Management System Project 1.0 via the unit parameter.

Nov 14, 2024
CVE-2024-50828
7.2 HIGH

A SQL Injection vulnerability was found in /admin/edit_department.php in kashipara E-learning Management System Project 1.0 via the d parameter.

Nov 14, 2024
CVE-2024-50827
7.2 HIGH

A SQL Injection vulnerability was found in /admin/add_subject.php in kashipara E-learning Management System Project 1.0 via the subject_code parameter.

Nov 14, 2024
CVE-2024-50826
7.2 HIGH

A SQL Injection vulnerability was found in /admin/add_content.php in kashipara E-learning Management System Project 1.0 via the title and content parameters.

Nov 14, 2024
CVE-2024-50825
7.2 HIGH

A SQL Injection vulnerability was found in /admin/school_year.php in kashipara E-learning Management System Project 1.0 via the school_year parameter.

Nov 14, 2024
CVE-2024-50824
7.2 HIGH

A SQL Injection vulnerability was found in /admin/class.php in kashipara E-learning Management System Project 1.0 via the class_name parameter.

Nov 14, 2024
CVE-2024-49362
7.7 HIGH

Joplin is a free, open source note taking and to-do application. Joplin-desktop has a vulnerability that leads to remote code execution (RCE) when a user …

Nov 14, 2024
CVE-2024-3502
8.1 HIGH

In lunary-ai/lunary versions up to and including 1.2.5, an information disclosure vulnerability exists where account recovery hashes of users are inadvertently exposed to unauthorized actors. …

Nov 14, 2024
CVE-2024-3501
8.1 HIGH

In lunary-ai/lunary versions up to and including 1.2.5, an information disclosure vulnerability exists due to the inclusion of single-use tokens in the responses of `GET …

Nov 14, 2024
CVE-2024-3379
8.1 HIGH

In lunary-ai/lunary versions 1.2.2 through 1.2.6, an incorrect authorization vulnerability allows unprivileged users to re-generate the private key for projects they do not have access …

Nov 14, 2024
CVE-2024-6068
7.3 HIGH

A memory corruption vulnerability exists in the affected products when parsing DFT files. Local threat actors can exploit this issue to disclose information and to …

Nov 14, 2024
CVE-2024-50835
7.2 HIGH

A SQL Injection vulnerability was found in /admin/edit_student.php in KASHIPARA E-learning Management System Project 1.0 via the cys, un, ln, fn, and id parameters.

Nov 14, 2024
CVE-2024-50834
7.2 HIGH

A SQL Injection was found in /admin/teachers.php in KASHIPARA E-learning Management System Project 1.0 via the firstname and lastname parameters.

Nov 14, 2024
CVE-2024-50832
7.2 HIGH

A SQL Injection vulnerability was found in /admin/edit_class.php in kashipara E-learning Management System Project 1.0 via the class_name parameter.

Nov 14, 2024
CVE-2022-2232
7.5 HIGH

A flaw was found in the Keycloak package. This flaw allows an attacker to utilize an LDAP injection to bypass the username lookup or potentially …

Nov 14, 2024
CVE-2024-10962
8.8 HIGH

The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 0.9.107 via deserialization …

Nov 14, 2024
CVE-2024-10979
8.8 HIGH

Incorrect control of environment variables in PostgreSQL PL/Perl allows an unprivileged database user to change sensitive process environment variables (e.g. PATH). That often suffices to …

Nov 14, 2024
CVE-2024-7730
7.4 HIGH

A heap buffer overflow was found in the virtio-snd device in QEMU. When reading input audio in the virtio-snd input callback, virtio_snd_pcm_in_cb, the function did …

Nov 14, 2024
CVE-2022-31671
7.4 HIGH

Harbor fails to validate user permissions when reading and updating job execution logs through the P2P preheat execution logs. By sending a request that attempts …

Nov 14, 2024
CVE-2022-31670
7.7 HIGH

Harbor fails to validate the user permissions when updating tag retention policies. By sending a request to update a tag retention policy with an id …

Nov 14, 2024
CVE-2022-31668
7.4 HIGH

Harbor fails to validate the user permissions when updating p2p preheat policies. By sending a request to update a p2p preheat policy with an id …

Nov 14, 2024
CVE-2022-31666
7.7 HIGH

Harbor fails to validate user permissions while deleting Webhook policies, allowing malicious users to view, update and delete Webhook policies of other users. The attacker …

Nov 14, 2024
CVE-2024-9693
8.5 HIGH

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.0 prior to 17.3.7, starting from 17.4 prior to 17.4.4, and starting from …

Nov 14, 2024
CVE-2024-50305
7.5 HIGH

Valid Host header field can cause Apache Traffic Server to crash on some platforms. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.5. Users …

Nov 14, 2024
CVE-2024-47916
7.5 HIGH

Boa web server - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Nov 14, 2024
CVE-2024-47915
7.5 HIGH

VaeMendis - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Nov 14, 2024
CVE-2024-45254
7.5 HIGH

VaeMendis - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Nov 14, 2024
CVE-2024-45253
7.5 HIGH

Avigilon – CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Nov 14, 2024
CVE-2024-38479
7.5 HIGH

Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.5. Users are recommended …

Nov 14, 2024
CVE-2024-2551
7.5 HIGH

A null pointer dereference vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to stop a core system service on the firewall by …

Nov 14, 2024
CVE-2024-2550
7.5 HIGH

A null pointer dereference vulnerability in the GlobalProtect gateway in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to stop the GlobalProtect service on …

Nov 14, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.