CVE Database

117989+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-46892
4.9 MEDIUM

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly invalidate sessions when the …

Nov 12, 2024
CVE-2024-46891
5.3 MEDIUM

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly restrict the size of …

Nov 12, 2024
CVE-2024-46890
9.1 CRITICAL

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly validate input sent to …

Nov 12, 2024
CVE-2024-46889
5.3 MEDIUM

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application uses hard-coded cryptographic key material to obfuscate …

Nov 12, 2024
CVE-2024-46888
9.9 CRITICAL

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly sanitize user provided paths …

Nov 12, 2024
CVE-2024-44102
10.0 CRITICAL

A vulnerability has been identified in PP TeleControl Server Basic 1000 to 5000 V3.1 (6NH9910-0AA31-0AE1) (All versions < V3.1.2.1 with redundancy configured), PP TeleControl Server …

Nov 12, 2024
CVE-2024-36140
6.8 MEDIUM

A vulnerability has been identified in OZW672 (All versions < V5.2), OZW772 (All versions < V5.2). The user accounts tab of affected devices is vulnerable …

Nov 12, 2024
CVE-2024-29119
7.8 HIGH

A vulnerability has been identified in Spectrum Power 7 (All versions < V24Q3). The affected product contains several root-owned SUID binaries that could allow an …

Nov 12, 2024
CVE-2024-11123
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in 上海灵当信息科技有限公司 Lingdang CRM up to 8.6.4.3. This affects an unknown part of the file /crm/data/pdf.php. …

Nov 12, 2024
CVE-2024-11122
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in 上海灵当信息科技有限公司 Lingdang CRM up to 8.6.4.3. Affected by this issue is some unknown functionality …

Nov 12, 2024
CVE-2024-11121
6.3 MEDIUM

A vulnerability classified as critical was found in 上海灵当信息科技有限公司 Lingdang CRM up to 8.6.4.3. Affected by this vulnerability is an unknown functionality of the file …

Nov 12, 2024
CVE-2023-32736
7.3 HIGH

A vulnerability has been identified in SIMATIC S7-PLCSIM V16 (All versions), SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 Safety V16 (All versions), SIMATIC STEP …

Nov 12, 2024
CVE-2024-9998

Rejected reason: The vulnerability has no impact, so it has been deprecated.

Nov 12, 2024
CVE-2024-10245
9.8 CRITICAL

The Relais 2FA plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.0. This is due to incorrect authentication and …

Nov 12, 2024
CVE-2024-10323
6.4 MEDIUM

The JetWidgets For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and …

Nov 12, 2024
CVE-2024-10179
6.4 MEDIUM

The Slickstream: Engagement and Conversions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's slick-grid shortcode in all versions up to, and …

Nov 12, 2024
CVE-2024-9836
5.9 MEDIUM

The RSS Feed Widget WordPress plugin before 3.0.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post …

Nov 12, 2024
CVE-2024-9835
4.8 MEDIUM

The RSS Feed Widget WordPress plugin before 3.0.1 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to …

Nov 12, 2024
CVE-2024-9357
6.1 MEDIUM

The xili-tidy-tags plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'action' parameter in all versions up to, and including, 1.12.04 due to …

Nov 12, 2024
CVE-2024-47799
3.5 LOW

Exposure of sensitive system information to an unauthorized control sphere issue exists in Mesh Wi-Fi router RP562B firmware version v1.0.2 and earlier. If this vulnerability …

Nov 12, 2024
CVE-2024-45827
8.0 HIGH

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Mesh Wi-Fi router RP562B firmware version v1.0.2 and earlier. …

Nov 12, 2024
CVE-2024-29075
4.6 MEDIUM

Active debug code vulnerability exists in Mesh Wi-Fi router RP562B firmware version v1.0.2 and earlier. If this vulnerability is exploited, a network-adjacent authenticated attacker may …

Nov 12, 2024
CVE-2024-10790
5.4 MEDIUM

The Admin and Site Enhancements (ASE) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and …

Nov 12, 2024
CVE-2024-49560
7.8 HIGH

Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) a command injection vulnerability. A low privileged attacker with local access could potentially exploit this …

Nov 12, 2024
CVE-2024-49558
7.8 HIGH

Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) an Improper Privilege Management vulnerability. A low privileged attacker with local access could potentially exploit …

Nov 12, 2024
CVE-2024-49557
7.8 HIGH

Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low …

Nov 12, 2024
CVE-2024-48838
3.3 LOW

Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) a Files or Directories Accessible to External Parties vulnerability. A low privileged attacker with local …

Nov 12, 2024
CVE-2024-48837
7.8 HIGH

Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) an Execution with Unnecessary Privileges vulnerability. A low privileged attacker with local access could potentially …

Nov 12, 2024
CVE-2024-11102
3.5 LOW

A vulnerability was found in SourceCodester Hospital Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of …

Nov 12, 2024
CVE-2024-11101
4.7 MEDIUM

A vulnerability was found in 1000 Projects Beauty Parlour Management System 1.0. It has been classified as critical. Affected is an unknown function of the …

Nov 12, 2024
CVE-2024-11100
7.3 HIGH

A vulnerability was found in 1000 Projects Beauty Parlour Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown …

Nov 12, 2024
CVE-2024-10695
4.3 MEDIUM

The Futurio Extra plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.0.13 via the 'elementor-template' shortcode due to …

Nov 12, 2024
CVE-2024-10685
6.1 MEDIUM

The Contact Form 7 Redirect & Thank You Page plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions …

Nov 12, 2024
CVE-2024-10672
2.7 LOW

The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the mpg_upsert_project_source_block() …

Nov 12, 2024
CVE-2024-10538
6.4 MEDIUM

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the before_label parameter in the Image Comparison widget in all …

Nov 12, 2024
CVE-2024-49395
5.3 MEDIUM

In mutt and neomutt, PGP encryption does not use the --hidden-recipient mode which may leak the Bcc email header field by inferring from the recipients …

Nov 12, 2024
CVE-2024-49394
5.3 MEDIUM

In mutt and neomutt the In-Reply-To email header field is not protected by cryptographic signing which allows an attacker to reuse an unencrypted but signed …

Nov 12, 2024
CVE-2024-8882
4.5 MEDIUM

A buffer overflow vulnerability in the CGI program in the Zyxel GS1900-48 switch firmware version V2.80(AAHN.1)C0 and earlier could allow an authenticated, LAN-based attacker with …

Nov 12, 2024
CVE-2024-8881
6.8 MEDIUM

A post-authentication command injection vulnerability in the CGI program in the Zyxel GS1900-48 switch firmware version V2.80(AAHN.1)C0 and earlier could allow an authenticated, LAN-based attacker …

Nov 12, 2024
CVE-2024-49393
6.5 MEDIUM

In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercepts a message to …

Nov 12, 2024
CVE-2024-11099
7.3 HIGH

A vulnerability was found in code-projects Job Recruitment 1.0 and classified as critical. This issue affects some unknown processing of the file /login.php. The manipulation …

Nov 12, 2024
CVE-2024-11097
3.3 LOW

A vulnerability has been found in SourceCodester Student Record Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the component Main …

Nov 12, 2024
CVE-2024-47595
6.3 MEDIUM

An attacker who gains local membership to sapsys group could replace local files usually protected by privileged access. On successful exploitation the attacker could cause …

Nov 12, 2024
CVE-2024-47593
4.3 MEDIUM

SAP NetWeaver Application Server ABAP allows an unauthenticated attacker with network access to read files from the server, which otherwise would be restricted.This attack is …

Nov 12, 2024
CVE-2024-47592
5.3 MEDIUM

SAP NetWeaver AS Java allows an unauthenticated attacker to brute force the login functionality in order to identify the legitimate user IDs. This has an …

Nov 12, 2024
CVE-2024-47590
8.8 HIGH

An unauthenticated attacker can create a malicious link which they can make publicly available. When an authenticated victim clicks on this malicious link, input data …

Nov 12, 2024
CVE-2024-47588
4.7 MEDIUM

In SAP NetWeaver Java (Software Update Manager 1.1), under certain conditions when a software upgrade encounters errors, credentials are written in plaintext to a log …

Nov 12, 2024
CVE-2024-47587
3.5 LOW

Cash Operations does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges causing low impact to confidentiality to the application.

Nov 12, 2024
CVE-2024-47586
5.3 MEDIUM

SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated attacker to send a maliciously crafted http request which could cause a null …

Nov 12, 2024
CVE-2024-42372
6.5 MEDIUM

Due to missing authorization check in SAP NetWeaver AS Java (System Landscape Directory) an unauthorized user can read and modify some restricted global SLD configurations …

Nov 12, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.