NVD Dashboard
CVEs Received and Processed
Time Period | New CVEs Received by NVD | New CVEs Analyzed by NVD | Modified CVEs Received by NVD | Modified CVEs Re-analyzed by NVD |
---|---|---|---|---|
Today | {{data.count}} | |||
This Week | {{data.count}} | |||
This Month | {{data.count}} | |||
Last Month | {{data.count}} | |||
This Year | {{data.count}} |
CVE Status Count
{{data.name}} | {{data.count}} |
NVD Contains
CVE Vulnerabilities | 268025 |
Checklists | 804 |
US-CERT Alerts | 249 |
US-CERT Vuln Notes | 4486 |
OVAL Queries | 10286 |
CPE Names | 1325525 |
CVSS V3 Score Distribution
Severity | Number of Vulns |
---|---|
{{data.name}} | {{data.count}} |
CVSS V2 Score Distribution
Severity | Number of Vulns |
---|---|
{{data.name}} | {{data.count}} |
For information on how to the cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.
-
CVE-2024-10595 - A vulnerability was found in ESAFENET CDG 5. It has been declared as critical. Affected by this vulnerability is the function delFile/delDifferCourseList of the file /com/esafenet/servlet/ajax/PublicDocInfoAjax.java. The manipulation leads to sql ... read CVE-2024-10595
Published: October 31, 2024; 5:15:15 PM -0400V3.1: 9.8 CRITICAL
-
CVE-2024-10509 - A vulnerability, which was classified as critical, has been found in Codezips Online Institute Management System 1.0. This issue affects some unknown processing of the file /login.php. The manipulation of the argument email leads to sql injection.... read CVE-2024-10509
Published: October 29, 2024; 11:15:04 PM -0400V3.1: 9.8 CRITICAL
-
CVE-2024-10556 - A vulnerability, which was classified as critical, was found in Codezips Pet Shop Management System 1.0. Affected is an unknown function of the file birdsadd.php. The manipulation of the argument id leads to sql injection. It is possible to launch... read CVE-2024-10556
Published: October 30, 2024; 9:15:14 PM -0400V3.1: 9.8 CRITICAL
-
CVE-2024-10557 - A vulnerability has been found in code-projects Blood Bank Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /file/updateprofile.php. The manipulation leads to cross-site re... read CVE-2024-10557
Published: October 30, 2024; 9:15:14 PM -0400V3.1: 6.5 MEDIUM
-
CVE-2024-10559 - A vulnerability was found in SourceCodester Airport Booking Management System 1.0 and classified as critical. Affected by this issue is the function details of the component Passport Number Handler. The manipulation leads to buffer overflow. The a... read CVE-2024-10559
Published: October 30, 2024; 10:15:03 PM -0400V3.1: 7.8 HIGH
-
CVE-2024-10561 - A vulnerability was found in Codezips Pet Shop Management System 1.0. It has been classified as critical. This affects an unknown part of the file birdsupdate.php. The manipulation of the argument id leads to sql injection. It is possible to initi... read CVE-2024-10561
Published: October 30, 2024; 10:15:03 PM -0400V3.1: 9.8 CRITICAL
-
CVE-2024-47121 - The goTenna Pro App uses a weak password for sharing encryption keys via the key broadcast method. If the broadcasted encryption key is captured over RF, and password is cracked via brute force attack, it is possible to decrypt it and use it to... read CVE-2024-47121
Published: September 26, 2024; 2:15:08 PM -0400V3.1: 5.3 MEDIUM
-
CVE-2024-6673 - A Cross-Site Request Forgery (CSRF) vulnerability exists in the `install_comfyui` endpoint of the `lollms_comfyui.py` file in the parisneo/lollms-webui repository, versions v9.9 to the latest. The endpoint uses the GET method without requiring a c... read CVE-2024-6673
Published: October 29, 2024; 9:15:08 AM -0400V3.1: 6.5 MEDIUM
-
CVE-2024-34121 - Illustrator versions 28.6, 27.9.5 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in... read CVE-2024-34121
Published: September 13, 2024; 5:15:02 AM -0400V3.1: 7.8 HIGH
-
CVE-2024-6674 - A CORS misconfiguration in parisneo/lollms-webui prior to version 10 allows attackers to steal sensitive information such as logs, browser sessions, and settings containing private API keys from other services. This vulnerability can also enable a... read CVE-2024-6674
Published: October 29, 2024; 9:15:08 AM -0400V3.1: 7.1 HIGH
-
CVE-2024-49659 - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Rami Yushuvaev Coub allows Stored XSS.This issue affects Coub: from n/a through 1.4.
Published: October 29, 2024; 8:15:05 AM -0400V3.1: 5.4 MEDIUM
-
CVE-2024-49654 - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Marian Heddesheimer Extra Privacy for Elementor allows Reflected XSS.This issue affects Extra Privacy for Elementor: from n/a through 0.1.3.
Published: October 29, 2024; 8:15:04 AM -0400V3.1: 6.1 MEDIUM
-
CVE-2024-49656 - Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Abdullah Irfan DocumentPress allows Reflected XSS.This issue affects DocumentPress: from n/a through 2.1.
Published: October 29, 2024; 8:15:05 AM -0400V3.1: 6.1 MEDIUM
-
CVE-2024-49972 - In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Deallocate DML memory if allocation fails [Why] When DC state create DML memory allocation fails, memory is not deallocated subsequently, resulting in uninitial... read CVE-2024-49972
Published: October 21, 2024; 2:15:18 PM -0400V3.1: 5.5 MEDIUM
-
CVE-2024-20300 - A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected d... read CVE-2024-20300
Published: October 23, 2024; 1:15:17 PM -0400V3.1: 5.4 MEDIUM
-
CVE-2024-49971 - In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Increase array size of dummy_boolean [WHY] dml2_core_shared_mode_support and dml_core_mode_support access the third element of dummy_boolean, i.e. hw_debug5 = &... read CVE-2024-49971
Published: October 21, 2024; 2:15:18 PM -0400V3.1: 5.5 MEDIUM
-
CVE-2024-20485 - A vulnerability in the VPN web server of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary code with root-level privileges. Administ... read CVE-2024-20485
Published: October 23, 2024; 2:15:12 PM -0400V3.1: 6.7 MEDIUM
-
CVE-2024-20482 - A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to elevate privileges on an affected devi... read CVE-2024-20482
Published: October 23, 2024; 2:15:12 PM -0400V3.1: 6.5 MEDIUM
-
CVE-2024-6581 - A vulnerability in the discussion image upload function of the Lollms application, version v9.9, allows for the uploading of SVG files. Due to incomplete filtering in the sanitize_svg function, this can lead to cross-site scripting (XSS) vulnerabi... read CVE-2024-6581
Published: October 29, 2024; 9:15:07 AM -0400V3.1: 9.0 CRITICAL
-
CVE-2024-8309 - A vulnerability in the GraphCypherQAChain class of langchain-ai/langchain version 0.2.5 allows for SQL injection through prompt injection. This vulnerability can lead to unauthorized data manipulation, data exfiltration, denial of service (DoS) by... read CVE-2024-8309
Published: October 29, 2024; 9:15:10 AM -0400V3.1: 9.8 CRITICAL