CVE Database

47087+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-36547
8.8 HIGH

idccms V1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component admin/vpsClass_deal.php?mudi=add

Jun 4, 2024
CVE-2024-35652
7.1 HIGH

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Saso Nikolov Event Tickets with Ticket Scanner allows Reflected XSS.This issue …

Jun 4, 2024
CVE-2024-32871
7.5 HIGH

Pimcore is an Open Source Data & Experience Management Platform. The Pimcore thumbnail generation can be used to flood the server with large files. By …

Jun 4, 2024
CVE-2024-29004
7.1 HIGH

The SolarWinds Platform was determined to be affected by a stored cross-site scripting vulnerability affecting the web console. A high-privileged user and user interaction is …

Jun 4, 2024
CVE-2024-28996
7.5 HIGH

The SolarWinds Platform was determined to be affected by a SWQL Injection Vulnerability. Attack complexity is high for this vulnerability.

Jun 4, 2024
CVE-2024-35668
7.1 HIGH

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Brevo Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue allows …

Jun 4, 2024
CVE-2024-35664
7.1 HIGH

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpvividplugins WPvivid Backup for MainWP wpvivid-backup-mainwp allows Reflected XSS.This issue affects WPvivid Backup …

Jun 4, 2024
CVE-2024-34554
8.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Select-Themes Stockholm Core allows PHP Local File Inclusion.This issue affects Stockholm Core: …

Jun 4, 2024
CVE-2024-34552
8.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Select-Themes Stockholm allows PHP Local File Inclusion.This issue affects Stockholm: from n/a …

Jun 4, 2024
CVE-2024-33628
8.8 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in XforWooCommerce allows PHP Local File Inclusion.This issue affects XforWooCommerce: from n/a through …

Jun 4, 2024
CVE-2024-33568
8.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Deserialization of Untrusted Data vulnerability in BdThemes Element Pack Pro allows Path Traversal, Object …

Jun 4, 2024
CVE-2024-36800
7.5 HIGH

A SQL injection vulnerability in SEMCMS v.4.8, allows a remote attacker to obtain sensitive information via the ID parameter in Download.php.

Jun 4, 2024
CVE-2024-33557
8.5 HIGH

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in 8theme XStore Core allows PHP Local File Inclusion.This issue affects XStore Core: …

Jun 4, 2024
CVE-2024-29170
8.1 HIGH

Dell PowerScale OneFS versions 8.2.x through 9.8.0.x contain a use of hard coded credentials vulnerability. An adjacent network unauthenticated attacker could potentially exploit this vulnerability, …

Jun 4, 2024
CVE-2024-4254
7.1 HIGH

The 'deploy-website.yml' workflow in the gradio-app/gradio repository, specifically in the 'main' branch, is vulnerable to secrets exfiltration due to improper authorization. The vulnerability arises from …

Jun 4, 2024
CVE-2024-37065
7.8 HIGH

Deserialization of untrusted data can occur in versions 0.6 or newer of the skops python library, enabling a maliciously crafted model to run arbitrary code …

Jun 4, 2024
CVE-2024-37064
7.8 HIGH

Deseriliazation of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a maliciously crafted dataset to run arbitrary code …

Jun 4, 2024
CVE-2024-37063
7.8 HIGH

A cross-site scripting (XSS) vulnerability in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library allows for payloads to be run when a maliocusly crafted …

Jun 4, 2024
CVE-2024-37062
7.8 HIGH

Deserialization of untrusted data can occur in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library, enabling a malicously crafted report to run arbitrary code …

Jun 4, 2024
CVE-2024-37061
8.8 HIGH

Remote Code Execution can occur in versions of the MLflow platform running version 1.11.0 or newer, enabling a maliciously crafted MLproject to execute arbitrary code …

Jun 4, 2024
CVE-2024-37060
8.8 HIGH

Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.27.0 or newer, enabling a maliciously crafted Recipe to execute arbitrary …

Jun 4, 2024
CVE-2024-37059
8.8 HIGH

Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.5.0 or newer, enabling a maliciously uploaded PyTorch model to run …

Jun 4, 2024
CVE-2024-37058
8.8 HIGH

Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.5.0 or newer, enabling a maliciously uploaded Langchain AgentExecutor model to …

Jun 4, 2024
CVE-2024-37057
8.8 HIGH

Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.0.0rc0 or newer, enabling a maliciously uploaded Tensorflow model to run …

Jun 4, 2024
CVE-2024-37056
8.8 HIGH

Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.23.0 or newer, enabling a maliciously uploaded LightGBM scikit-learn model to …

Jun 4, 2024
CVE-2024-37055
8.8 HIGH

Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.24.0 or newer, enabling a maliciously uploaded pmdarima model to run …

Jun 4, 2024
CVE-2024-37054
8.8 HIGH

Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.9.0 or newer, enabling a maliciously uploaded PyFunc model to run …

Jun 4, 2024
CVE-2024-37053
8.8 HIGH

Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling a maliciously uploaded scikit-learn model to run …

Jun 4, 2024
CVE-2024-37052
8.8 HIGH

Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling a maliciously uploaded scikit-learn model to run …

Jun 4, 2024
CVE-2023-47837
8.3 HIGH

Improper Privilege Management vulnerability in Repute Infosystems ARMember allows Privilege Escalation.This issue affects ARMember: from n/a through 4.0.10.

Jun 4, 2024
CVE-2023-46630
7.5 HIGH

Improper Authentication vulnerability in wpase Admin and Site Enhancements (ASE) allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Admin and Site Enhancements (ASE): …

Jun 4, 2024
CVE-2024-5000
7.5 HIGH

An unauthenticated remote attacker can use a malicious OPC UA client to send a crafted request to affected CODESYS products which can cause a DoS …

Jun 4, 2024
CVE-2023-5751
7.8 HIGH

A local attacker with low privileges can read and modify any users files and cause a DoS in the working directory of the affected products …

Jun 4, 2024
CVE-2024-20878
7.3 HIGH

Heap out-of-bound write vulnerability in parsing grid image in libsavscmn.so prior to SMR June-2024 Release 1 allows local attackers to execute arbitrary code.

Jun 4, 2024
CVE-2024-20877
7.3 HIGH

Heap out-of-bound write vulnerability in parsing grid image header in libsavscmn.so prior to SMR Jun-2024 Release 1 allows local attackers to execute arbitrary code.

Jun 4, 2024
CVE-2024-20874
7.9 HIGH

Improper access control vulnerability in SmartManagerCN prior to SMR Jun-2024 Release 1 allows local attackers to launch privileged activities.

Jun 4, 2024
CVE-2024-4856
8.2 HIGH

The FS Product Inquiry WordPress plugin through 1.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a …

Jun 4, 2024
CVE-2024-4749
8.3 HIGH

The wp-eMember WordPress plugin before 10.3.9 does not sanitize and escape the "fieldId" parameter before outputting it back in the page, leading to a Reflected …

Jun 4, 2024
CVE-2024-3555
7.2 HIGH

The Social Link Pages: link-in-bio landing pages for your social media profiles plugin for WordPress is vulnerable to unauthorized access due to a missing capability …

Jun 4, 2024
CVE-2024-2019
7.5 HIGH

The WP-DB-Table-Editor plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to lack of a default …

Jun 4, 2024
CVE-2024-4870
7.2 HIGH

The Frontend Registration – Contact Form 7 plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.1 due to insufficient …

Jun 4, 2024
CVE-2022-1242
7.8 HIGH

Apport can be tricked into connecting to arbitrary sockets as the root user

Jun 3, 2024
CVE-2022-0555
8.4 HIGH

Subiquity Shows Guided Storage Passphrase in Plaintext with Read-all Permissions

Jun 3, 2024
CVE-2021-3899
7.8 HIGH

There is a race condition in the 'replaced executable' detection that, with the correct local configuration, allow an attacker to execute arbitrary code as root.

Jun 3, 2024
CVE-2024-4540
7.5 HIGH

A flaw was found in Keycloak in OAuth 2.0 Pushed Authorization Requests (PAR). Client-provided parameters were found to be included in plain text in the …

Jun 3, 2024
CVE-2024-32983
8.2 HIGH

Misskey is an open source, decentralized microblogging platform. Misskey doesn't perform proper normalization on the JSON structures of incoming signed ActivityPub activity objects before processing …

Jun 3, 2024
CVE-2024-36128
7.5 HIGH

Directus is a real-time API and App dashboard for managing SQL database content. Prior to 10.11.2, providing a non-numeric length value to the random string …

Jun 3, 2024
CVE-2024-36127
7.5 HIGH

apko is an apk-based OCI image builder. apko exposures HTTP basic auth credentials from repository and keyring URLs in log output. This vulnerability is fixed …

Jun 3, 2024
CVE-2024-36728
8.1 HIGH

TRENDnet TEW-827DRU devices through 2.06B04 contain a stack-based buffer overflow in the ssi binary. The overflow allows an authenticated user to execute arbitrary code by …

Jun 3, 2024
CVE-2024-36569
8.1 HIGH

Sourcecodester Gas Agency Management System v1.0 is vulnerable to arbitrary code execution via editClientImage.php.

Jun 3, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.