CVE Database

4634+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-26015
3.4 LOW

An incorrect parsing of numbers with different radices vulnerability [CWE-1389] in FortiProxy version 7.4.3 and below, version 7.2.10 and below, version 7.0.17 and below and …

Jul 9, 2024
CVE-2024-37996
3.3 LOW

A vulnerability has been identified in JT Open (All versions < V11.5), JT2Go (All versions < V2406.0003), PLM XML SDK (All versions < V7.1.0.014), Teamcenter …

Jul 9, 2024
CVE-2024-37442
3.8 LOW

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Photo Gallery Team Photo Gallery by Ays allows Code Injection.This …

Jul 9, 2024
CVE-2024-37253
2.7 LOW

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in WpDirectoryKit WP Directory Kit allows Code Injection.This issue affects WP …

Jul 9, 2024
CVE-2024-35777
3.5 LOW

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Automattic WooCommerce allows Content Spoofing.This issue affects WooCommerce: from n/a …

Jul 9, 2024
CVE-2024-34692
3.3 LOW

Due to missing verification of file type or content, SAP Enable Now allows an authenticated attacker to upload arbitrary files. These files include executables which …

Jul 9, 2024
CVE-2024-38372
2.0 LOW

Undici is an HTTP/1.1 client, written from scratch for Node.js. Depending on network and process conditions of a `fetch()` request, `response.arrayBuffer()` might include portion of …

Jul 8, 2024
CVE-2024-34602
3.3 LOW

Use of implicit intent for sensitive communication in Samsung Messages prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information. User interaction …

Jul 8, 2024
CVE-2024-6539
3.5 LOW

A vulnerability classified as problematic has been found in heyewei SpringBootCMS up to 2024-05-28. Affected is an unknown function of the file /guestbook of the …

Jul 7, 2024
CVE-2024-37234
3.5 LOW

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Kodezen Limited Academy LMS.This issue affects Academy LMS: from n/a through 2.0.4.

Jul 6, 2024
CVE-2024-40594
2.3 LOW

The OpenAI ChatGPT app before 2024-07-05 for macOS opts out of the sandbox, and stores conversations in cleartext in a location accessible to other apps.

Jul 6, 2024
CVE-2024-6526
3.5 LOW

A vulnerability classified as problematic has been found in CodeIgniter Ecommerce-CodeIgniter-Bootstrap up to 1998845073cf433bc6c250b0354461fbd84d0e03. This affects an unknown part. The manipulation of the argument search_title/catName/sub/name/categorie …

Jul 5, 2024
CVE-2024-6525
2.7 LOW

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000 up to 20230922. It has been rated as problematic. Affected by this issue …

Jul 5, 2024
CVE-2024-6523
3.5 LOW

A vulnerability was found in ZKTeco BioTime up to 9.5.2. It has been classified as problematic. Affected is an unknown function of the component system-group-add …

Jul 5, 2024
CVE-2024-6511
3.5 LOW

A vulnerability classified as problematic was found in y_project RuoYi up to 4.7.9. Affected by this vulnerability is the function isJsonRequest of the component Content-Type …

Jul 4, 2024
CVE-2024-32754
3.1 LOW

Under certain circumstances, when the controller is in factory reset mode waiting for initial setup, it will broadcast its MAC address, serial number, and firmware …

Jul 4, 2024
CVE-2024-6434
3.1 LOW

The Premium Addons for Elementor plugin for WordPress is vulnerable to Regular Expression Denial of Service (ReDoS) in all versions up to, and including, 4.10.35. …

Jul 4, 2024
CVE-2024-36122
2.4 LOW

Discourse is an open-source discussion platform. Prior to version 3.2.3 on the `stable` branch and version 3.3.0.beta4 on the `beta` and `tests-passed` branches, moderators using …

Jul 3, 2024
CVE-2024-29508
3.3 LOW

Artifex Ghostscript before 10.03.0 has a heap-based pointer disclosure (observable in a constructed BaseFont name) in the function pdf_base_font_alloc.

Jul 3, 2024
CVE-2024-6126
3.2 LOW

A flaw was found in the cockpit package. This flaw allows an authenticated user to kill any process when enabling the pam_env's user_readenv option, which …

Jul 3, 2024
CVE-2024-6470
2.7 LOW

A vulnerability was found in playSMS 1.4.3. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /index.php?app=main&inc=feature_inboxgroup&op=list …

Jul 3, 2024
CVE-2024-6469
2.7 LOW

A vulnerability was found in playSMS 1.4.3. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php?app=main&inc=feature_firewall&op=firewall_list …

Jul 3, 2024
CVE-2024-39807
3.1 LOW

Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 fail to properly sanitize the recipients of a webhook event which allows an attacker monitoring webhook events to …

Jul 3, 2024
CVE-2024-39361
3.1 LOW

Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5 fail to prevent users from specifying a RemoteId for their posts which …

Jul 3, 2024
CVE-2024-39353
2.7 LOW

Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 fail to sanitize the RemoteClusterFrame payloads before audit logging them which allows a high privileged attacker with access …

Jul 3, 2024
CVE-2024-36257
2.7 LOW

Mattermost versions 9.5.x <= 9.5.5 and 9.8.0, when using shared channels with multiple remote servers connected, fail to check that the remote server A requesting …

Jul 3, 2024
CVE-2024-39324
3.8 LOW

aimeos/ai-admin-graphql is the Aimeos GraphQL API admin interface. Starting in version 2022.04.1 and prior to versions 2022.10.10, 2023.10.6, and 2024.4.2, improper access control allows a …

Jul 2, 2024
CVE-2024-36278
3.3 LOW

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause apps crash through type confusion.

Jul 2, 2024
CVE-2024-31071
3.3 LOW

in OpenHarmony v4.0.0 and prior versions allow a local attacker cause apps crash through type confusion.

Jul 2, 2024
CVE-2023-35022
3.3 LOW

IBM InfoSphere Information Server 11.7 could allow a local user to update projects that they do not have the authorization to access. IBM X-Force ID: …

Jun 30, 2024
CVE-2024-6415
2.4 LOW

A vulnerability classified as problematic was found in Ingenico Estate Manager 2023. Affected by this vulnerability is an unknown functionality of the file /emgui/rest/preferences/PREF_HOME_PAGE/sponsor/3/ of …

Jun 30, 2024
CVE-2024-39846
3.5 LOW

NewPass before 1.2.0 stores passwords (rather than password hashes) directly, which makes it easier to obtain unauthorized access to sensitive information. NOTE: in each case, …

Jun 29, 2024
CVE-2024-39307
3.5 LOW

Kavita is a cross platform reading server. Opening an ebook with malicious scripts inside leads to code execution inside the browsing context. Kavita doesn't sanitize …

Jun 28, 2024
CVE-2024-39302
3.7 LOW

BigBlueButton is an open-source virtual classroom designed to help teachers teach and learners learn. An attacker may be able to exploit the overly elevated file …

Jun 28, 2024
CVE-2024-38531
3.6 LOW

Nix is a package manager for Linux and other Unix systems that makes package management reliable and reproducible. A build process has access to and …

Jun 28, 2024
CVE-2024-30135
3.3 LOW

HCL DRYiCE AEX is potentially impacted by disclosure of sensitive information in the mobile application when a snapshot is taken.

Jun 28, 2024
CVE-2024-30111
3.3 LOW

HCL DRYiCE AEX product is impacted by Missing Root Detection vulnerability in the mobile application. The mobile app can be installed in the rooted device …

Jun 28, 2024
CVE-2024-30110
3.7 LOW

HCL DRYiCE AEX product is impacted by lack of input validation vulnerability in a particular web application. A malicious script can be injected into a …

Jun 28, 2024
CVE-2024-30109
3.7 LOW

HCL DRYiCE AEX is impacted by a lack of clickjacking protection in the AEX web application. An attacker can use multiple transparent or opaque layers …

Jun 28, 2024
CVE-2024-37137
3.8 LOW

Dell Key Trust Platform, v3.0.6 and prior, contains Use of a Cryptographic Primitive with a Risky Implementation vulnerability. A local privileged attacker could potentially exploit …

Jun 28, 2024
CVE-2024-6374
3.5 LOW

A vulnerability was found in lahirudanushka School Management System 1.0.0/1.0.1 and classified as problematic. This issue affects some unknown processing of the file /subject.php of …

Jun 27, 2024
CVE-2024-39157
3.8 LOW

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ipRecord_deal.php?mudi=del&dataType=&dataID=1.

Jun 27, 2024
CVE-2024-39156
3.8 LOW

idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/keyWord_deal.php?mudi=add.

Jun 27, 2024
CVE-2024-6370
3.5 LOW

A vulnerability classified as problematic was found in LabVantage LIMS 2017. Affected by this vulnerability is an unknown functionality of the file /labvantage/rc?command=file&file=WEB-OPAL/pagetypes/bulletins/sendbulletin.jsp of the …

Jun 27, 2024
CVE-2024-6369
3.5 LOW

A vulnerability classified as problematic has been found in LabVantage LIMS 2017. Affected is an unknown function of the file /labvantage/rc?command=page&sdcid=LV_ReagentLot of the component POST …

Jun 27, 2024
CVE-2024-6368
3.5 LOW

A vulnerability was found in LabVantage LIMS 2017. It has been rated as problematic. This issue affects some unknown processing of the file /labvantage/rc?command=page of …

Jun 27, 2024
CVE-2024-6367
3.5 LOW

A vulnerability was found in LabVantage LIMS 2017. It has been declared as problematic. This vulnerability affects unknown code of the file /labvantage/rc?command=file&file=WEB-CORE/elements/files/filesembedded.jsp of the …

Jun 27, 2024
CVE-2024-4011
3.1 LOW

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from …

Jun 27, 2024
CVE-2024-39458
3.1 LOW

When Jenkins Structs Plugin 337.v1b_04ea_4df7c8 and earlier fails to configure a build step, it logs a warning message containing diagnostic information that may contain secrets …

Jun 26, 2024
CVE-2024-25637
3.1 LOW

October is a self-hosted CMS platform based on the Laravel PHP Framework. The X-October-Request-Handler Header does not sanitize the AJAX handler name and allows unescaped …

Jun 26, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.