CVE Database

4634+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-6344
2.4 LOW

A vulnerability, which was classified as problematic, was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. This affects an unknown part of the component Push Configuration …

Jun 26, 2024
CVE-2024-28830
2.7 LOW

Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p7, <2.2.0p28, <2.1.0p45 and <=2.0.0p39 (EOL) causes automation user secrets to be written …

Jun 26, 2024
CVE-2024-37141
3.5 LOW

Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain an open redirect vulnerability. A remote low privileged attacker could potentially …

Jun 26, 2024
CVE-2024-29177
2.7 LOW

Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain a disclosure of temporary sensitive information vulnerability. A remote high privileged …

Jun 26, 2024
CVE-2024-24764
3.5 LOW

October is a self-hosted CMS platform based on the Laravel PHP Framework. This issue affects authenticated administrators who may be redirected to an untrusted URL …

Jun 26, 2024
CVE-2024-38364
2.6 LOW

DSpace is an open source software is a turnkey repository application used by more than 2,000 organizations and institutions worldwide to provide durable access to …

Jun 26, 2024
CVE-2023-37541
3.5 LOW

HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios.

Jun 25, 2024
CVE-2024-6300
3.7 LOW

Incomplete cleanup when performing redactions in Conduit, allowing an attacker to check whether certain strings were present in the PDU before redaction

Jun 25, 2024
CVE-2024-32855
3.8 LOW

Dell Client Platform BIOS contains an Out-of-bounds Write vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this …

Jun 25, 2024
CVE-2024-6295
3.9 LOW

udn News Android APP stores the unencrypted user session in the local database when user log into the application. A malicious APP or an attacker …

Jun 25, 2024
CVE-2024-6294
3.9 LOW

udn News Android APP stores the user session in logcat file when user log into the APP. A malicious APP or an attacker with physical …

Jun 25, 2024
CVE-2024-4839
3.3 LOW

A Cross-Site Request Forgery (CSRF) vulnerability exists in the 'Servers Configurations' function of the parisneo/lollms-webui, versions 9.6 to the latest. The affected functions include Elastic …

Jun 24, 2024
CVE-2024-3121
3.3 LOW

A remote code execution vulnerability exists in the create_conda_env function of the parisneo/lollms repository, version 5.9.0. The vulnerability arises from the use of shell=True in …

Jun 24, 2024
CVE-2024-4841
3.3 LOW

A Path Traversal vulnerability exists in the parisneo/lollms-webui, specifically within the 'add_reference_to_local_mode' function due to the lack of input sanitization. This vulnerability affects versions v9.6 …

Jun 23, 2024
CVE-2024-6267
2.4 LOW

A vulnerability classified as problematic was found in SourceCodester Service Provider Management System 1.0. Affected by this vulnerability is an unknown functionality of the file …

Jun 23, 2024
CVE-2024-6252
2.4 LOW

A vulnerability has been found in Zorlan SkyCaiji up to 2.8 and classified as problematic. Affected by this vulnerability is an unknown functionality of the …

Jun 22, 2024
CVE-2024-6251
2.4 LOW

A vulnerability, which was classified as problematic, was found in playSMS 1.4.3. Affected is an unknown function of the file /index.php?app=main&inc=feature_phonebook&op=phonebook_list of the component New …

Jun 22, 2024
CVE-2022-44593
3.7 LOW

Use of Less Trusted Source vulnerability in SolidWP Solid Security allows HTTP DoS.This issue affects Solid Security: from n/a through 9.3.1.

Jun 21, 2024
CVE-2024-38388
3.3 LOW

In the Linux kernel, the following vulnerability has been resolved: ALSA: hda/cs_dsp_ctl: Use private_free for control cleanup Use the control private_free callback to free the …

Jun 21, 2024
CVE-2024-6212
3.5 LOW

A vulnerability was found in SourceCodester Simple Student Attendance System 1.0 and classified as problematic. Affected by this issue is the function get_student of the …

Jun 21, 2024
CVE-2024-38361
3.7 LOW

Spicedb is an Open Source, Google Zanzibar-inspired permissions database to enable fine-grained authorization for customer applications. Use of an exclusion under an arrow that has …

Jun 20, 2024
CVE-2024-6182
3.5 LOW

A vulnerability was found in LabVantage LIMS 2017. It has been rated as problematic. This issue affects some unknown processing of the file /labvantage/rc?command=page&page=LV_ViewSampleSpec&oosonly=Y&_sdialog=Y. The …

Jun 20, 2024
CVE-2024-6181
3.5 LOW

A vulnerability was found in LabVantage LIMS 2017. It has been declared as problematic. This vulnerability affects unknown code of the file /labvantage/rc?command=file&file=WEB-CORE/elements/files/filesembedded.jsp&size=32. The manipulation …

Jun 20, 2024
CVE-2024-38358
2.9 LOW

Wasmer is a web assembly (wasm) Runtime supporting WASIX, WASI and Emscripten. If the preopened directory has a symlink pointing outside, WASI programs can traverse …

Jun 19, 2024
CVE-2024-6129
3.7 LOW

A vulnerability, which was classified as problematic, was found in spa-cartcms 1.9.0.6. Affected is an unknown function of the file /login of the component Username …

Jun 18, 2024
CVE-2024-5967
2.7 LOW

A vulnerability was found in Keycloak. The LDAP testing endpoint allows changing the Connection URL independently without re-entering the currently configured LDAP bind credentials. This …

Jun 18, 2024
CVE-2024-38507
3.5 LOW

In JetBrains Hub before 2024.2.34646 stored XSS via project description was possible

Jun 18, 2024
CVE-2024-5899
3.3 LOW

When Bazel Plugin in intellij imports a project (either using "import project" or "Auto import") the dialog for trusting the project is not displayed. This …

Jun 18, 2024
CVE-2024-6082
2.4 LOW

A vulnerability, which was classified as problematic, has been found in PHPVibe 11.0.46. This issue affects some unknown processing of the file functionalities.global.php of the …

Jun 17, 2024
CVE-2024-6063
3.3 LOW

A vulnerability was found in GPAC 2.5-DEV-rev228-g11067ea92-master. It has been classified as problematic. This affects the function m2tsdmx_on_event of the file src/filters/dmx_m2ts.c of the component …

Jun 17, 2024
CVE-2024-6062
3.3 LOW

A vulnerability was found in GPAC 2.5-DEV-rev228-g11067ea92-master and classified as problematic. Affected by this issue is the function swf_svg_add_iso_sample of the file src/filters/load_text.c of the …

Jun 17, 2024
CVE-2024-6061
3.3 LOW

A vulnerability has been found in GPAC 2.5-DEV-rev228-g11067ea92-master and classified as problematic. Affected by this vulnerability is the function isoffin_process of the file src/filters/isoffin_read.c of …

Jun 17, 2024
CVE-2024-6059
2.4 LOW

A vulnerability, which was classified as problematic, has been found in Ingenico Estate Manager 2023. This issue affects some unknown processing of the file /emgui/rest/ums/messages …

Jun 17, 2024
CVE-2024-6058
3.5 LOW

A vulnerability classified as problematic has been found in LabVantage LIMS 2017. This affects an unknown part of the file /labvantage/rc?command=page&page=SampleHistoricalList&_iframename=list&__crc=crc_1701669816260. The manipulation of the …

Jun 17, 2024
CVE-2024-6056
3.7 LOW

A vulnerability was found in nasirkhan Laravel Starter up to 11.8.0. It has been rated as problematic. Affected by this issue is some unknown functionality …

Jun 17, 2024
CVE-2024-37159
3.5 LOW

Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. This vulnerability allowed a user to create a validator using vested tokens to …

Jun 17, 2024
CVE-2024-37158
3.5 LOW

Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. Preliminary checks on actions computed by the clawback vesting accounts are performed in …

Jun 17, 2024
CVE-2024-31870
3.3 LOW

IBM Db2 for i 7.2, 7.3, 7.4, and 7.5 supplies user defined table function is vulnerable to user enumeration by a local authenticated attacker, without …

Jun 15, 2024
CVE-2024-6006
3.5 LOW

A vulnerability was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of …

Jun 15, 2024
CVE-2024-6005
3.5 LOW

A vulnerability was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of …

Jun 15, 2024
CVE-2024-30120
2.9 LOW

HCL DRYiCE Optibot Reset Station is impacted by an Unused Parameter in the web application.

Jun 14, 2024
CVE-2024-30119
3.7 LOW

HCL DRYiCE Optibot Reset Station is impacted by a missing Strict Transport Security Header. This could allow an attacker to intercept or manipulate data during …

Jun 14, 2024
CVE-2024-37887
3.5 LOW

Nextcloud Server is a self hosted personal cloud system. Private shared calendar events' recurrence exceptions can be read by sharees. It is recommended that the …

Jun 14, 2024
CVE-2024-37885
3.8 LOW

The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. A code injection in Nextcloud Desktop Client for macOS …

Jun 14, 2024
CVE-2024-37884
3.5 LOW

Nextcloud Server is a self hosted personal cloud system. A malicious user was able to send delete requests for old versions of files they only …

Jun 14, 2024
CVE-2024-37315
3.5 LOW

Nextcloud Server is a self hosted personal cloud system. An attacker with read-only access to a file is able to restore older versions of a …

Jun 14, 2024
CVE-2024-37314
3.5 LOW

Nextcloud Photos is a photo management app. Users can remove photos from the album of registered users. It is recommended that the Nextcloud Server is …

Jun 14, 2024
CVE-2024-36287
3.8 LOW

Mattermost Desktop App versions <=5.7.0 fail to disable certain Electron debug flags which allows for bypassing TCC restrictions on macOS.

Jun 14, 2024
CVE-2024-5469
3.1 LOW

DoS in KAS in GitLab CE/EE affecting all versions from 16.10.0 prior to 16.10.6 and 16.11.0 prior to 16.11.3 allows an attacker to crash KAS …

Jun 14, 2024
CVE-2024-22333
3.3 LOW

IBM Maximo Asset Management 7.6.1.3 and IBM Maximo Application Suite 8.10 and 8.11 allows web pages to be stored locally which can be read by …

Jun 13, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.