Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.1
CVE-2024-42914
A host header injection vulnerability exists in the forgot password functionality of ArrowCMS version 1.0.0. By sending a specially crafted host head…
Arrowcms
No fix yet
CRITICAL 9.8
CVE-2024-43782
This openedx-translations repository contains translation files from Open edX repositories to be kept in sync with Transifex. Before moving to pullin…
Openedx
Patch available
CRITICAL 10.0
CVE-2024-42472
Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.14.0 and 1.15.10, a malicious or compromised Flatpak app us…
Debian Linux
1.14.10 / 1.15.10+
MEDIUM 6.5
CVE-2024-31882
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a denial of service, under specific non default conf…
Db2
after 11.5.9
HIGH 8.8
CVE-2024-42489
Pro Macros provides XWiki rendering macros. Missing escaping in the Viewpdf macro allows any user with view right on the `CKEditor.HTMLConverter` pag…
Pro Macros
1.10.1+
CRITICAL 9.8
CVE-2024-39227
GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4…
Mt6000 Firmware
No fix yet
MEDIUM 6.5
CVE-2024-6331
stitionai/devika main branch as of commit cdfb782b0e634b773b10963c8034dc9207ba1f9f is vulnerable to Local File Read (LFI) by Prompt Injection. The in…
Devika
No fix yet
CRITICAL 9.6
CVE-2024-41127
Monkeytype is a minimalistic and customizable typing test. Monkeytype is vulnerable to Poisoned Pipeline Execution through Code Injection in its ci-f…
Monkeytype
24.30.0+
MEDIUM 6.1
CVE-2024-39320
Discourse is an open source discussion platform. Prior to 3.2.5 and 3.3.0.beta5, the vulnerability allows an attacker to inject iframes from any doma…
Discourse
3.2.5+
CRITICAL 9.8
CVE-2024-7221
A vulnerability was determined in SourceCodester/Campcodes School Log Management System 1.0. This affects an unknown part of the file /admin/manage_u…
School Log Management System
No fix yet
CRITICAL 9.8
CVE-2024-7219
A vulnerability has been found in SourceCodester/Campcodes School Log Management System 1.0. Affected by this vulnerability is an unknown functionali…
School Log Management System
No fix yet
CRITICAL 9.8
CVE-2024-7220
A vulnerability was found in SourceCodester/Campcodes School Log Management System 1.0. Affected by this issue is some unknown functionality of the f…
School Log Management System
No fix yet
MEDIUM 5.4
CVE-2024-40324
A CRLF injection vulnerability in E-Staff v5.1 allows attackers to insert Carriage Return (CR) and Line Feed (LF) characters into input fields, leadi…
E Staff
No fix yet
MEDIUM 5.5
CVE-2024-40137
Dolibarr ERP CRM before 19.0.2-php8.2 was discovered to contain a remote code execution (RCE) vulnerability via the Computed field parameter under th…
Mitigation only
HIGH 8.8
CVE-2024-26020EPSS 15%
An arbitrary script execution vulnerability exists in the MPV functionality of Ankitects Anki 24.04. A specially crafted flashcard can lead to a arbi…
Anki
No fix yet
CRITICAL 9.8
CVE-2024-6933
A flaw has been found in LimeSurvey 6.5.14-240624. Affected by this issue is the function actionUpdateSurveyLocaleSettingsGeneralSettings of the file…
Limesurvey
6.6.2+
HIGH 8.8
CVE-2024-41121
Woodpecker is a simple yet powerful CI/CD engine with great extensibility. The server allow to create any user who can trigger a pipeline run malicio…
Woodpecker
2.7.0+
HIGH 8.8
CVE-2024-41122
Woodpecker is a simple yet powerful CI/CD engine with great extensibility. The server allow to create any user who can trigger a pipeline run malicio…
Woodpecker
2.7.0+
HIGH 8.3
CVE-2024-39906
A command injection vulnerability was found in the IndieAuth functionality of the Ruby on Rails based Haven blog web application. The affected functi…
Patch available
HIGH 7.2
CVE-2024-41111
Sliver is an open source cross-platform adversary emulation/red team framework, it can be used by organizations of all sizes to perform security test…
Patch available
HIGH 7.2
CVE-2024-20429
A vulnerability in the web-based management interface of Cisco AsyncOS for Secure Email Gateway could allow an authenticated, remote attacker to exec…
Asyncos
Mitigation only
HIGH 7.8
CVE-2024-40637
dbt enables data analysts and engineers to transform their data using the same practices that software engineers use to build applications. When a us…
Dbt Core
1.6.14 / 1.7.14+
MEDIUM 6.5
CVE-2024-38700
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in realmag777 WPCS allows Code Injec…
Mitigation only
CRITICAL 9.8
CVE-2024-36522
The default configuration of XSLTResourceStream.java is vulnerable to remote code execution via XSLT injection when processing input from an untruste…
Wicket
8.16.0 / 9.18.0+
MEDIUM 5.5
CVE-2024-37442
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Photo Gallery Team Photo Gallery …
Photo Gallery
5.7.1+
HIGH 8.8
CVE-2024-6469
A vulnerability was found in playSMS 1.4.3. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the fi…
Playsms
No fix yet
CRITICAL 10.0
CVE-2024-38366EPSS 18%
trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. The part of trunk which verifies whether a user has a real em…
Trunk.cocoapods.org
2023-09-22+
HIGH 7.5
CVE-2024-36420
Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, the `/api/v1/openai-assistants-…
Flowise
No fix yet
CRITICAL 9.8
CVE-2024-39704
Soft Circle French-Bread Melty Blood: Actress Again: Current Code through 1.07 Rev. 1.4.0 allows a remote attacker to execute arbitrary code on a cli…
Melty Blood Actress Again Current Code
after 1.07
CRITICAL 9.8
CVE-2024-39243
An issue discovered in skycaiji 2.8 allows attackers to run arbitrary code via crafted POST request to /index.php?s=/admin/develop/editor_save.
Skycaiji
Mitigation only